• DocumentCode
    2898400
  • Title

    A DRTM-Based Method for Trusted Network Connection

  • Author

    Feng, Wei ; Qin, Yu ; Yu, Ai-min ; Feng, Dengguo

  • Author_Institution
    State Key Lab. of Inf. Security, Inst. of Software, Beijing, China
  • fYear
    2011
  • fDate
    16-18 Nov. 2011
  • Firstpage
    425
  • Lastpage
    435
  • Abstract
    Trusted Network Connection (TNC for short) can prevent insecure terminal from accessing protected network and thus strengthen the security of network. Existing TNC solutions face a serious problem called lying endpoint problem (LEP for short). If an attacker modifies the terminal agent software which is responsible for collecting the integrity state of an endpoint platform, Trusted Network Connection will lose its meanings. Trusted Computing Group (TCG) adds the functionality of trusted computing to prevent lying endpoint problem, but TCG´s TNC relies on the traditional Static Root of Trust for Measurement (SRTM) which has too big TCB (Trusted Computing Base) and has been proved unsafe. In this paper, we design and implement an improved TNC scheme with high reliability and scalability based on trusted integrity status of terminal. While focusing on LEP problem under the context of Network Access Control (NAC), we leverage Dynamic Root of Trust for Measurement (DRTM) technology to realize desired security requirements such as smaller TCB. We also use the Logic of Secure Systems (LS2) to prove the security properties of our improved TNC system. Our experimental evaluation demonstrates that our method is feasible.
  • Keywords
    software agents; trusted computing; DRTM based method; LEP; LS2; NAC; SRTM; TCB; TCG; TNC; logic of secure systems; lying endpoint problem; network access control; network protection; software agent; static root of trust for measurement; trusted computing base; trusted computing group; trusted network connection; Access control; Authentication; Computers; Hardware; Malware; Software; Dynamic Root of Trust Measurement (DRTM); Logic of Secure System; TPM; Trusted Computing; Trusted Network Connection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2011 IEEE 10th International Conference on
  • Conference_Location
    Changsha
  • Print_ISBN
    978-1-4577-2135-9
  • Type

    conf

  • DOI
    10.1109/TrustCom.2011.55
  • Filename
    6120848