A formal analysis of Trusted Platform Module 2.0 hash-based message authentication code authorization under digital rights management scenario

A formal analysis of Trusted Platform Module 2.0 hash-based message authentication code authorization under digital rights management scenario
复制标题

DOI:
10.1002/sec.1193
复制
发表时间:
2016-10
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
Fajiang Yu;Huanguo Zhang;Bo Zhao;Juan Wang;Liqiang Zhang;Fei Yan;Zhenlin Chen
Fajiang Yu;Huanguo Zhang;Bo Zhao;Juan Wang;Liqiang Zhang;Fei Yan;Zhenlin Chen
中科院分区:
其他
文献类型:
--
作者:
Fajiang Yu;Huanguo Zhang;Bo Zhao;Juan Wang;Liqiang Zhang;Fei Yan;Zhenlin Chen

文献摘要

被引文献

相似文献

可信平台模块TPM是整个可信计算平台的“信任根”。TPM自身的安全保障非常重要。本文介绍了TPM 2.0基于哈希的消息认证码HMAC授权方案作为安全协议,并对TPM 2.0授权与TPM 1.2“对象独立授权协议”和“对象特定授权协议”进行了详细的比较。然后使用类型pi演算描述了TPM 2.0在数字版权管理DRM场景下的HMAC授权及其安全属性,并使用ProVerify推断TPM 2.0中不再存在针对TPM 1.2的密钥句柄操纵攻击,因为访问实体唯一名已经与HMAC值相关联,但TPM 2.0中仍然存在密钥blob替换的漏洞。版权所有©2015 John Wiley & Sons, Ltd
Trusted Platform Module TPM is the "root of trust" of the whole trusted computing platform. The TPM's own security assurance is very important. This paper describes the TPM 2.0 hash-based message authentication code HMAC authorization scheme as a security protocol and makes a detail comparison of the TPM 2.0 authorization to the TPM 1.2 "Object-Independent Authorization Protocol" and the "Object-Specific Authorization Protocol." Then the authors use the typed pi calculus to describe the TPM 2.0 HMAC authorization and its security properties under the Digital Rights Management DRM scenario and use ProVerify to reason that the key handle manipulation attack for TPM 1.2 does not exist any more in TPM 2.0, because the access entity unique name has been linked to the HMAC value, but the vulnerability of key blob substitution still exists in TPM 2.0. Copyright © 2015 John Wiley & Sons, Ltd.