• DocumentCode
    2676006
  • Title

    Research on Storage Security Based on Trusted Computing Platform

  • Author

    He, Jian ; Xu, Mingdi

  • Author_Institution
    No. 2 Dept., Commanding Commun. Acad., Wuhan
  • fYear
    2008
  • fDate
    3-5 Aug. 2008
  • Firstpage
    448
  • Lastpage
    452
  • Abstract
    As an information carrier for multifarious platforms, the security issues about disk storage directly effected system security, dependability and data confidentiality. How to ensure data not to be accessed by unauthorized users effectively, and to guarantee information to be in safe and secure state? Aiming at these problems, we introduce concept of trusted storage (TS), and advance implements about TS through analyzing several access scenarios in practice. Then we put forward a novel scheme for protecting data on personal computer platform. By combing trusted computing platform, we propose a secure and reliable model for user authentication and data encryption. The model uses storage protocol to establish a subsystem to encrypt data, and uses TPM to authenticate different users. We also implement this model by adding it into trusted computing platform. The enhanced platform can not only encrypt data per sector drastically, but also exclude those who canpsilat be authenticated. Some external software attacks and physical theft also cut no ice. Deep analysis and comparison show that using TS can help to extend trust chain of platform to peripherals to analyze the security risk of different operation environment. Moreover, TS can enhance communication protocol of storage device to improve security of data flow.
  • Keywords
    cryptography; disc storage; communication protocol; data confidentiality; data encryption; data flow security; disk storage; external software attacks; information carrier; multifarious platforms; personal computer platform; security issues; storage security; system security; trusted computing platform; trusted storage; Access protocols; Authentication; Cryptography; Data security; Ice; Information security; Microcomputers; Protection; Risk analysis; Secure storage;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Electronic Commerce and Security, 2008 International Symposium on
  • Conference_Location
    Guangzhou City
  • Print_ISBN
    978-0-7695-3258-5
  • Type

    conf

  • DOI
    10.1109/ISECS.2008.144
  • Filename
    4606105