Virtual TPM Dynamic Trust Extension Suitable for Frequent Migrations
Title | Virtual TPM Dynamic Trust Extension Suitable for Frequent Migrations |
Publication Type | Conference Paper |
Year of Publication | 2016 |
Authors | Yu, F., Chen, L., Zhang, H. |
Conference Name | 2016 IEEE Trustcom/BigDataSE/ISPA |
Keywords | attestation data, authentication, authentication server, authorisation, composability, Computers, Elliptic curve cryptography, frequent migrations, Heuristic algorithms, identity key certificate, IK certificate, performance measurements, physical TPM, pTPM, pubcrawl, public key cryptography, Real-time Systems, Resiliency, Servers, time token, Trust Extension, Trusted Computing, Trusted Platform Module (TPM), trusted platform modules, virtual machines, virtual TPM dynamic trust extension, virtual trusted platform module, virtual Trusted Platform Module (vTPM), vTPM DTE |
Abstract | This paper has presented an approach of vTPM (virtual Trusted Platform Module) Dynamic Trust Extension (DTE) to satisfy the requirements of frequent migrations. With DTE, vTPM is a delegation of the capability of signing attestation data from the underlying pTPM (physical TPM), with one valid time token issued by an Authentication Server (AS). DTE maintains a strong association between vTPM and its underlying pTPM, and has clear distinguishability between vTPM and pTPM because of the different security strength of the two types of TPM. In DTE, there is no need for vTPM to re-acquire Identity Key (IK) certificate(s) after migration, and pTPM can have a trust revocation in real time. Furthermore, DTE can provide forward security. Seen from the performance measurements of its prototype, DTE is feasible. |
URL | http://ieeexplore.ieee.org/document/7846929/ |
DOI | 10.1109/TrustCom.2016.0046 |
Citation Key | yu_virtual_2016 |
- pubcrawl
- vTPM DTE
- virtual Trusted Platform Module (vTPM)
- virtual trusted platform module
- virtual TPM dynamic trust extension
- virtual machines
- trusted platform modules
- Trusted Platform Module (TPM)
- Trusted Computing
- Trust Extension
- time token
- Servers
- Resiliency
- real-time systems
- public key cryptography
- attestation data
- pTPM
- physical TPM
- performance measurements
- IK certificate
- identity key certificate
- Heuristic algorithms
- frequent migrations
- Elliptic curve cryptography
- Computers
- composability
- authorisation
- authentication server
- authentication