虚拟信任站台模块(vTPM ) 是造信任的云环境里的重要部分。在存在瞄准 vTPM 例子的有效安全保证的缺乏的补习虚拟 TPM 建筑学,这份报纸基于核为虚拟 TPM 论述一个改进安全的计划 -- 基于的虚拟机(KVM ) 。由在硬件和软件认识到 TPM2.0 说明,我们用 TPM 的不对称的加密算法为 vTPMs 秘密增加保护。这个计划与 vTPM 例子在为不同虚拟机(VM ) 的 VM-vTPM 移植和安全协会期间支持一把 TPM 钥匙的安全迁居。我们基于 KVM 虚拟基础结构与更高的安全实现一个虚拟信任平台。实验证明建议计划能提高虚拟信任站台的安全并且与 vTPM 为 VM 移植有更少另外的性能损失。
Virtual trusted platform module (vTPM) is an impor- tant part in building trusted cloud environment. Aiming at the remediation of lack of effective security assurances of vTPM in- stances in the existing virtual TPM architecture, this paper pre- sents a security-improved scheme for virtual TPM based on ker- nel-based virtual machine (KVM). By realizing the TPM2.0 speci- fication in hardware and software, we add protection for vTPM's secrets using the asymmetric encryption algorithm of TPM. This scheme supports the safety migration of a TPM key during VM-vTPM migration and the security association for different virtual machines (VMs) with vTPM instances. We implement a virtual trusted platform with higher security based on KVM virtual infrastructure. The experiments show that the proposed scheme can enhance the security of virtual trusted platform and has fewer additional performance loss for the VM migration with vTPM.