摘要
提出了一个多内核架构SmartMK来支撑不同安全等级和类别的应用。基于TPM和新的CPU安全技术,实现了多内核之间的强隔离与安全通信机制,以软硬件协同保护的方式实现安全的操作系统运行环境。在SmartMK架构上提出了分层次的强制访问控制方模型,进一步降低复杂环境中的访问控制复杂度。性能测试和实际应用都表明,SmartMK能够有效加强系统的安全性,同时很好地保证了系统的运行效率。
The emergence of general security hardware provides operating system and electronic equipment with a hardware-based security protection, but there were few studies about using the hardware to provide system-level security protection directly. A multi kernel structure SmartMK was proposed to support applications of different security levels and different types; based on the trusted platform module(TPM) and the new CPU security technology, the strong separation and secure communications rneehanisms between multi-kernel were realized and the security of the operating system operating environment was achieved by the hardware and software together. A mandatory access control model was offered to the SmartMK reduce the complexity of access control. Performance testing and application of SmartMK showed that it can effectively strengthen the system security while guaranteeing the system' s efficiency.
出处
《武汉大学学报(信息科学版)》
EI
CSCD
北大核心
2008年第10期1034-1037,共4页
Geomatics and Information Science of Wuhan University
基金
国家973计划资助项目(2007CB310900)
国家基础科研资助项目(A142008190)
关键词
TPM
多内核
可信操作系统
分层次强制访问控制
可信计算基
TPM
multi-kernel
trusted operating system
layered mandatory access control
trusted computing base