1 总体技术方案
2 可信链构建方法
2.1 基于vTPM建立虚拟机可信链
2.2 基于硬件TPM建立宿主机可信链接
表1 硬件PCR组 |
PCR索引值 | PCR用途 |
---|---|
0 | BIOS中的可信度量根,BIOS和平台扩展 |
1 | 平台配置 |
2 | 可选的ROM代码 |
3 | 可选的ROM配置和数据 |
4 | 引导代码(通常为MBR),系统启动时载入并允许 |
5 | 引导代码的配置和数据,有引导代码使用 |
6 | 状态转换和唤醒事件 |
7 | 预留待使用 |
Command Control and Simulation >
Trusted Migration Method for Virtual Machine Based on Trusted Chain
Received date: 2019-03-11
Revised date: 2019-05-27
Online published: 2022-05-05
Aiming at the problem that the trusted chain cannot be migrated during migration process of virtual machines between different physical platforms, a trusted migration method based on the trusted chain is proposed. This method adds a vTPM management center on the virtual layer to create and manage multiple vTPMs, builds a complete trusted chain from the hardware TPM to the virtual machine applications through vTPMs. During the VM migration process, we disconnects the complete trusted chain and migrated the VM trusted chain together with the VM to the target platform, and realizes the trusted migration of the VM and rapid recovery of the trusted chain. The method solves the problem well during the cross-physical platform migration process. Comparing with the original VM migration method, this method can ensure the security of the whole migration process, and high confidence and fast recovery characteristics.
HOU Jie , XUE Liang , WANG Yang . Trusted Migration Method for Virtual Machine Based on Trusted Chain[J]. Command Control and Simulation, 2019 , 41(6) : 120 -124 . DOI: 10.3969/j.issn.1673-3819.2019.06.022
表1 硬件PCR组 |
PCR索引值 | PCR用途 |
---|---|
0 | BIOS中的可信度量根,BIOS和平台扩展 |
1 | 平台配置 |
2 | 可选的ROM代码 |
3 | 可选的ROM配置和数据 |
4 | 引导代码(通常为MBR),系统启动时载入并允许 |
5 | 引导代码的配置和数据,有引导代码使用 |
6 | 状态转换和唤醒事件 |
7 | 预留待使用 |
[1] |
|
[2] |
|
[3] |
|
[4] |
|
[5] |
|
[6] |
|
[7] |
|
[8] |
|
[9] |
张焕国, 赵波. 可信计算[M]. 武汉: 武汉大学出版社, 2011:20.
|
[10] |
冯登国. 可信计算--理论与实践[M]. 北京: 清华大学出版社, 2013:53-62.
|
/
〈 |
|
〉 |