摘要
虚拟可信密码模块(vTCM)架构在安全和性能上均存在缺陷,不满足特殊应用场景下高安全性的需求.本文基于设备虚拟化技术提出了一种TCM硬件虚拟化的实现架构,利用该架构设计密钥结构,得到构建高安全可信虚拟环境的方法,为虚拟机提供硬件级的可信密码服务.可行性验证分析表明,本系统能够增强可信虚拟环境安全性,提高系统效率.
The current vTCM architecture has some flaws in security and performance, so it cannot meet the requirements of high security in the special application scenes. Based on the device virtualization SR-IOV(single root I/ O virtualization) technology, we propose a kind of framework of TCM hardware virtualization, and design the key structure . Then we find the method of constructing high security trusted virtual environment, which can provide trusted cryptographic service for virtual machine. As can be seen from the feasibility verification and analysis , the system can enhance the security of trusted virtual environment, and improve the efficiency of the system.
出处
《武汉大学学报(理学版)》
CAS
CSCD
北大核心
2017年第2期117-124,共8页
Journal of Wuhan University:Natural Science Edition
基金
国家科技重点专项"核高基"(2013ZX01029002-001)
关键词
单根设备虚拟化
TCM硬件虚拟化
可信虚拟环境
SR-IOV(single root I/O virtualization)
TCM hardware virtualization
trusted virtual environment