TRSF:一种移动存储设备主动防护框架

马俊;王志英;任江春;刘聪;伍江江;程勇;梅松竹

电子学报 ›› 2012, Vol. 40 ›› Issue (2) : 376-383.

PDF(820 KB)
PDF(820 KB)
电子学报 ›› 2012, Vol. 40 ›› Issue (2) : 376-383. DOI: 10.3969/j.issn.0372-2112.2012.02.027
科研通信

TRSF:一种移动存储设备主动防护框架

  • 马俊, 王志英, 任江春, 刘聪, 伍江江, 程勇, 梅松竹
作者信息 +

TRSF:Implementing Active Removable Storage Protection via Trusted Virtual Domains

  • MA Jun, WANG Zhi-ying, REN Jiang-chun, LIU Cong, WU Jiang-jiang, CHENG Yong, MEI Song-zhu
Author information +
文章历史 +

摘要

移动存储设备属于被动设备,其安全防护往往依赖于终端系统的安全机制,在提供安全性的同时会降低系统可用性.本文提出了一种基于可信虚拟域的移动存储设备结构框架TRSF(Trusted Removable Storage Framework)实现存储设备的主动防护.TRSF将智能卡芯片和动态隔离机制绑定到存储设备中,并由片上操作系统构建从底层可信平台模块到隔离运行环境的可信数据通道,从而为移动存储设备在非可信终端系统中被非可信进程访问和使用提供一个可信虚拟环境.最后基于TRSF实现了一款主动安全U盘UTrustDisk.与没有增加主动防护机制相比,增加该机制导致平均读写性能开销分别增加了7.5%和11.5%.

Abstract

As removable storage medias are passive devices,their security policies depend on mechanisms in connected terminal systems,which will reduce the availability while providing security.This paper presents TRSF,a framework of removable storage based on trust virtual domain to implement active protection.TRSF solidifies a smart card and an isolation mechanism into the storage device and builds trust data channels from the device to the isolated usage environment in terminal system.So TRSF is able to provide trust virtual environment for data access and usage of removable storage even in untrust terminal systems by untrust processes.We implement an intelligent USB disk based on TRSF called UTrustDisk to evaluate the framework.The average overhead on read and write caused by trust chain mechanism is 7.5% and 11.5%.

关键词

可信虚拟域 / 主动防护 / 可信存储 / 信任链 / 隔离 / 片上操作系统

Key words

trusted virtual domains (TVDs) / active protection / trusted storage / trust chain / isolation / chip operation system (COS)

引用本文

导出引用
马俊;王志英;任江春;刘聪;伍江江;程勇;梅松竹. TRSF:一种移动存储设备主动防护框架[J]. 电子学报, 2012, 40(2): 376-383. https://doi.org/10.3969/j.issn.0372-2112.2012.02.027
MA Jun;WANG Zhi-ying;REN Jiang-chun;LIU Cong;WU Jiang-jiang;CHENG Yong;MEI Song-zhu. TRSF:Implementing Active Removable Storage Protection via Trusted Virtual Domains[J]. Acta Electronica Sinica, 2012, 40(2): 376-383. https://doi.org/10.3969/j.issn.0372-2112.2012.02.027
中图分类号: TP309.2   

基金

国家自然科学基金青年基金 (No.60903240); 核高基重大专项 (No.2010ZX01045-001-002-5)
PDF(820 KB)

2361

Accesses

0

Citation

Detail

国家自然科学基金青年基金(No.60903240);核高基重大专项(No.2010ZX01045-001-002-5)
段落导航
相关文章

/