针对单一第三方失效而影响云计算环境证明有效性问题,提出一种基于多重第三方远程证明机制。将单一第三方扩展为第三方验证者集群,保证了在部分验证者受到安全威胁情况下,仍然能够为证明请求者提供可靠的证明结果。同时提出第三方筛选算法和基于信誉权值策略应对多个第三方合谋攻击,避免由于恶意指控清白验证者而导致最终断言失效情形。实验结果表明,该机制相对于单一验证者更为安全可靠,在实际应用中能有效防御合谋攻击。
To overcome the invalidation problem due to single third-party attestation failures in cloud computing envi- ronments, we proposed a remote attestation mechanism based on multiple third-party by extending single third-party to third-party parties verifier cluster. The mechanism can ensure that sound attestation results is provided to the requester under the circumstance that part of the verifiers are invalid or attacked. In particular, considering multiple third-party collusion attack, we presented third-party filtering algorithms and credibility weight strategy to resist collusion attack, which minimizes ultimate assertion failures as a result of malicious innocence allegations simultaneously. Experimental results show that this mechanism, compared to the single verifier, is more reliable and better resisting collusion attack in practical applications.