【正文】
sic features: protected capabilities, integrity measurement and integrity reporting. (From section , TCG Architecture Overview ) 18 TCG的基石性原理 Fundamental rule of TCG ? 信任根就像 “ 公理 ” 一樣 , 是信任的基礎(chǔ) 。 ? Chains of trust – Transitive trust also known as ―Inductive Trust‖, is a process where the Root of Trust gives a trustworthy description of a second group of functions. 19 一個(gè)包含 TPM的 PC Reference PC platform containing a TCG TPM 20 TCG – 可信平臺(tái)模塊 TCG – Trusted Platform Module (TPM) ? 一個(gè)可信平臺(tái)常常擁有三個(gè)可信根 There are monly three Roots of Trust in a trusted platform – 測(cè)量可信根 root of trust for measurement (RTM) – 存儲(chǔ)可信根 root of trust for storage (RTS) – 報(bào)告可信根 root of trust for reporting (RTR) 21 證明協(xié)議和消息交換 Attestation protocol and message exchange 22 TPM – 存儲(chǔ)可信根的體系結(jié)構(gòu) TPM – Root of Trust for Storage (RTS) 23 TPM 部件體系結(jié)構(gòu) TPM ponent architecture 24 TCG 軟件分層 TCG software layering 25 可信平臺(tái)的生命周期 The trusted platform lifecycle 26 可信平臺(tái)上的用戶(hù)認(rèn)證 User authentication using trusted platforms 27 可信平臺(tái)上的用戶(hù)認(rèn)證 User authentication using trusted platforms 28 經(jīng)典的四角模型 The classical four corners model 29 四角模型的可信平臺(tái)實(shí)現(xiàn) Detailed TP deployment architecture 30 TCG對(duì)于可信計(jì)算平臺(tái)的劃分 8 categories of Trusted platform 體系結(jié)構(gòu) Architecture TPM 移動(dòng)設(shè)備 Mobile 客戶(hù)端 PC Client 服務(wù)器 Server 軟件包 Software Stack 存儲(chǔ) Storage 可信網(wǎng)絡(luò)連接 Trusted Network Connect 31 TCG的 IWG和 TNC的對(duì)應(yīng)關(guān)系 the IWG and TNC architecture 32 TNC體系結(jié)構(gòu) TNC architecture 33 TNC體系結(jié)構(gòu)下的消息流 Message flow between ponents 34 擁有 TPM的 TNC體系結(jié)構(gòu) The TNC architecture with the TPM 35 思科的自防御網(wǎng)絡(luò)體系 Cisco’s selfdefending work 36 思科的自防御網(wǎng)絡(luò)體系 Cisco’s selfdefending work 37 松散安全結(jié)構(gòu)的代表 ——框架和方案 Loose security structure — Framework ? 松散結(jié)構(gòu)中的各個(gè)部件關(guān)聯(lián)關(guān)系,常??咳说募蓙?lái)實(shí)現(xiàn) The connection among the ponents of loose structure is always integrated by human. ? 松散結(jié)構(gòu)常常表現(xiàn)為框架 Framework – 技術(shù)框架 Technology framework – 管理體系 Management system ? ISO27001, ISO20220, etc. 38 39 技術(shù)功能是 PDR的衍生 PDR can express technology framework 40 檢測(cè)能力是松散技術(shù)結(jié)構(gòu)的關(guān)聯(lián)要素 Detection make the loose structure tight ? 攻擊者不得不面對(duì)越來(lái)越多的 Attackers have to face more – 入侵檢測(cè) IDS – 漏洞掃描 scanner – 應(yīng)用審計(jì)系統(tǒng) Application auditing system – 日志系統(tǒng) log system – 蜜罐 honey pot – 取證系統(tǒng) forensic system – 監(jiān)控平臺(tái) monitoring platform – 等等 etc. 41 一個(gè)信息安全管理體系的結(jié)構(gòu) Structure