针对直接匿名验证(DAA)协议中使用可变名字基时检测克隆可信平台模块(TPM)存在的困难,在保持TPM高匿名度的前提下,提出了一种基于Chord的完全分布式克隆TPM检测方案。将访问服务的TPM映射到Chord覆盖层中,在不依赖可信第三方(TTP)参与的情况下实现了对克隆TPM的有效检测。以服从泊松分布的TPM访问规律和服从负指数分布的服务时间为模型,对该方案和已有方案的性能进行了分析与仿真,结果表明该方案具有高检测率和零虚警率等特性。该检测方案思想可以在不增加额外开销的情况下部署到基于分布式哈希表(DHT)的完全分布式系统中。
According to the difficulties in detecting a clone trusted platform module (TPM) in the direct anonymous attestation (DAA) protocol using variable basename, the paper proposes a fully distributed method to detect clone TPMs based on Chord, which offers TPMs a high degree of anonymity. By mapping TPMs to the chord overlay, clone TPMs can be detected efficiently without a trusted third party (TTP). The analysis and simulation were conducted for the approach and existing proposals based on a model where the access follows the Poisson distribution and service time follows the negative exponential distribution. The results show that the proposed method has a high detection rate and a zero false alarm. The idea of the proposal can be deployed in the distributed hash table (DHT) based fully distributed systems without increasing additional overhead.