"斯诺登"事件再一次证明,采用国外关键软硬件的计算机具有不可控的漏洞和后门,信息系统采用非自主的计算机给国家、企业、军队带来安全威胁。文中设计并实现了一种安全可信计算机,采用国产龙芯处理器,减少了后门安全隐患,通过设计板载可信密码模块、端口控制电路和身份认证装置,实现了BIOS主动度量恢复,硬件级的端口控制和身份认证功能,同时实现了对硬件、MBR、操作系统的完整性保护功能。通过实验测试表明,文中设计实现的安全可信计算机原理样机具备身份认证、主动度量BIOS、端口控制、完整信任链保护等安全可信功能,大大提高了计算机的安全性。
The event of " Snow den" once again proved that using foreign computers has not controllable bug and backdoor,information system using foreign computer poses a security threat to the state,enterprises and troops. In this paper,design and implement a trust security computer,using Native Loongson CPU,reducing the security risks of back door,through the design of on-board trusted cryptographic module,port control circuit and authentication devices to achieve the initiative measurement of BIOS,BIOS restoring,hardware levels port control and authentication functions. M oreover,implement the integrity protection of the hardware,M BR and OS. The experiments indicated that the security trusted computer principle prototype designed and implemented in this paper has implemented the identity authentication,active measurement of BIOS,port control,complete chain of trust protection,which can greatly enhance the security of computer.