证明问题是可信计算的核心问题之一.TCG架构下的证明问题解决方案由于可扩展性差、不灵活、容易暴露平台隐私以及性能低,正在成为可信计算的应用、推广和普及的瓶颈,严重地阻碍了可信计算在更广的范围内进行延伸和拓展.介绍了证明的基本概念并给出形式化定义,详细阐述了三元和四元证明系统的基本架构及工作机制,并指出平台身份证明采用了“推”式四元证明系统,而平台配置证明仍然采用三元证明系统.分析了当前对TCG架构下的平台身份证明、平台环境状态配置信息证明以及平台动态环境状态(运行时环境状态)证明等三个方面开展的研究工作,并对这些工作进行了总结.结合已有的研究成果,探讨了TCG架构下的证明问题的研究方向及其面临的挑战.
Attestation is one of the critical problems to Trusted Computing. The solution project of attestation in TCG, due to bad extensibility, inflexibility, bad performance and leaking privacy, is becoming bottleneck to application, popularizing of Trusted Computing. In this paper, the formal concept of attestation is defined, functional structure and execution mechanism of the ternary and the quadruple attestation system are presented,and pointed out that the attestation of identity is a "push" quadruple attestation system, and the attestation of platform is still ternary attestation system, Moreover, the development about Attestation of Identity, Attestation of Platform and Attestation of Run-time Environment, and so on, are analyzed. This paper also presents a summary of the current state of these techniques, a discussion on the future research topics,and the challenges of attestation of TCG.