信任链的建立和传递是构建可信计算环境的核心,然而,当前的信任链模型仅仅是针对具体的可信计算环境进行的形式化建模,其不具有一般意义,不能够为构建可信计算环境(特别是基于动态可信度量根(DRTM)的可信环境)提供理论方面的指导,也难以胜任评估现有的可信计算环境的重任。为了解决上述问题,进而构建一个具有一般意义的信任链模型。首先将信任链模型转换为数学模型,然后,在分析实体依赖关系和安全逻辑系统的基础上,采用了数学逻辑的证明方法证明了该信任链模型满足的性质。该模型不仅可以评估现有的可信计算平台(包括基于静态可信度量根(SRTM)的可信计算平台和DRTM的可信计算平台),还可以为进一步研究信任链构建和可信计算环境构建等提供理论上的参考。
This paper provided a chain of trust model in line with the TCG trust concepts. This model gave a formal definition and proof of trust state, trust root and trust measurement and chain of trust by the concept of Smith' s entity dependence and the assumption that the authenticity could measure the entity' s conduct without any loss. The model was universal, which could provide a theoretical basis for assessing the existing trusted computing platform, and provided theoretical support for the follow-up research on how to build a more reasonable chain of trust.