数据加解密、数据封装和数字信封是可信密码模块的三种数据安全保护方式。在可信计算环境下提出了一种数据封装方法。该方法将数据绑定于可信密码模块和特定的平台状态,使得受保护数据只能由特定用户在指定可信计算环境特定的平台状态下才能解密。实验表明,该方法在可信计算环境下以较小的代价实现了数据的封装.保护数据的安全性。
Cryptography, data encapsulation and digital envelope are methods of data protection in TCM ( trusted cryptography module) specification. This paper proposed a method of data encapsulation under trusted computing environment. In this method, bound private data with TCM and special platform status. Protected data could only be decrypted under specified trusted computing environment and platform status by specified user account. Experiment shows that this method can wrap data and protect privacy efficiently with little cost.