提出了一个多内核架构SmartMK来支撑不同安全等级和类别的应用。基于TPM和新的CPU安全技术,实现了多内核之间的强隔离与安全通信机制,以软硬件协同保护的方式实现安全的操作系统运行环境。在SmartMK架构上提出了分层次的强制访问控制方模型,进一步降低复杂环境中的访问控制复杂度。性能测试和实际应用都表明,SmartMK能够有效加强系统的安全性,同时很好地保证了系统的运行效率。
The emergence of general security hardware provides operating system and electronic equipment with a hardware-based security protection, but there were few studies about using the hardware to provide system-level security protection directly. A multi kernel structure SmartMK was proposed to support applications of different security levels and different types; based on the trusted platform module(TPM) and the new CPU security technology, the strong separation and secure communications rneehanisms between multi-kernel were realized and the security of the operating system operating environment was achieved by the hardware and software together. A mandatory access control model was offered to the SmartMK reduce the complexity of access control. Performance testing and application of SmartMK showed that it can effectively strengthen the system security while guaranteeing the system' s efficiency.