中文摘要: 摘 要: 可信计算中的远程二进制平台完整性证明方式存在平台(软,硬件)配置泄露问题,导致针对性攻击、差别化服务和匿名性破坏。提出利用属性基签名(attribute based signature,ABS)构造远程证明中的属性证明方案(property based attestation,PBA)。将属性签名中的签名策略(属性树)映射到远程证明中的安全属性。利用属性签名的匿名性的特点,验证者无法得知证明方的具体配置,仅能得知证明者是否满足签名策略也就是安全属性,达到验证属性证明目的。方案中无需使用属性证书,由不同授权机构管理平台配置,共同生成属性签名。在标准模型下对方案进行了安全性证明,满足正确性、不可伪造性和隐私性。
Abstract
Abstract:Abstract: In trusted computing
the binary attestation scheme has some shortcomings that it reveals the information about the configuration of a platform which may lead to privacy issues such as discrimination services
anonymity violations and targeted attacks
etc. A property remote attestation based on attribute-based signature is proposed. The attribute signature’ policy (attribute tree) is mapped to security property in remote attestation. As anonymity of ABS
the verifier can’t know the specific configuration and the signature reveals no more than the fact that prover with some set of attributes satisfying the predicate(security property) has attested to the message. Multi authorities manage the platform configurations and generate attribute signature together without using property certificates. We prove the security of our scheme under standard model
that the scheme satisfies the correctness
unforgeability and configuration privacy.
关键词
可信计算远程证明属性证明属性基签名
Keywords
trusted computingremote attestationproperty based attestationattribute based signature