首先分析了可信计算环境下多远程证明实例执行的动态性、并发性、一致性等问题,提出了一个完整的可信计算环境多远程证明实例动态更新证明方案,以保证通信双方终端计算环境的可信。然后阐述了主要由计算环境组件度量算法、会话组件树计算算法和多远程证明实例证明协议组成可信计算环境证明方法。最后对该证明方法的安全性和效率进行分析,并构建原型系统论证证明方案的可行性和高性能。
At first, the authors analyze the problems of dynamic characteristic, concurrency and consistency for Multiple Remote Attestation Instance (Multi-RAI) in trust computing environment, and propose a complete dynamic update attestation scheme for Multi-RAI in trust computing environment, which guarantees the trustworthiness of endpoints' computing environment. Then the authors illustrate attestation method of trust computing environment which is comprised of measurement algorithm for computing environment, computing algorithm for session component tree and attestation protocol for Multi-RAI. At last the authors analyze the security and efficiency of Multi-RAI attestation method, and construct the prototype system for proving schemers feasibility and high-performance.