[Cloud Computing]Mechanisms: Trusted Platform Module

本文介绍了可信平台模块(TPM)的基本概念及其在确保计算平台信任度方面的作用。TPM是一种抗篡改集成电路,用于执行加密操作并保护敏感信息如密码等。它通过提供测量根来验证启动代码模块的准确性,并作为报告和存储测量值的信任根。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

Trusted Platform Module

A trusted platform module (TPM) is a tamper-resistant integrated circuit built into some computer motherboards that can perform cryptographic operations, such as key generation, and protect small amounts of sensitive information, such as passwords, measurement data for boot software and cryptographic keys. The TPM is used to store platform measurements that help ensure that the platform remains trustworthy. Authentication and attestation are necessary steps to attain trust to a policy-specified level of security assurance.

Figure 1 - An example of a trusted platform module as part of the resource’s hardware.

The compute platform must have a root of trust for measurement (RTM) that is implicitly trusted to provide an accurate validation of the boot code modules. The TPM provides root of trust for reporting and a root of trust storage for the RTMs. The TPM contains a set of registers that contain RTM measurements for launch modules of the boot software. The TPM uses an attestation identity key to sign messages to an attestation service, which must validate the signature and the register contents.

The TPM stores a set of "known good" measurements of boot components that are securely generated and stored. The attestation service stores the results of the platform trusted boot reported by the TPM. Maintenance of the known good measurements for different hypervisors, operating systems and various BIOS software and ensuring they are protected from tampering and spoofing is critical. For instance, based on security requirements, remote BIOS flashing should be disabled and separation of duties (SOD) by multiple administrators should be employed to establish a reasonable level of security assurance.

Related Patterns:

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值