A Trusted Bootstrap Scheme on EFI and TC

12
A Trusted Bootstrap Scheme on EFI and TC Rui Zhang,Jiqiang Liu, Shuanghe Peng IEEE Computer Society

description

A Trusted Bootstrap Scheme on EFI and TC. Rui Zhang,Jiqiang Liu, Shuanghe Peng IEEE Computer Society. Introduction EFI Boot Process The architecture of EFI Trust chain in EFI Trusted boot process of EFI TPM TPM Software Stack Attestation Problem. Introduction (1/2). EFI? - PowerPoint PPT Presentation

Transcript of A Trusted Bootstrap Scheme on EFI and TC

Page 1: A Trusted Bootstrap Scheme on EFI  and TC

A Trusted Bootstrap Scheme on EFI

and TCRui Zhang,Jiqiang Liu, Shuanghe Peng

IEEE Computer Society

Page 2: A Trusted Bootstrap Scheme on EFI  and TC

Introduction EFI Boot Process The architecture of EFI Trust chain in EFI Trusted boot process of EFI TPM TPM Software Stack Attestation Problem

Page 3: A Trusted Bootstrap Scheme on EFI  and TC

EFI?◦ Extensible Firmware Interface

Introduction (1/2)

Page 4: A Trusted Bootstrap Scheme on EFI  and TC

BIOS Vs EFI◦ 바이오스가 하는일을 포함한 EFI -> 완전한 대체◦ 부팅속도◦ VGA 의존성 X 네트워크나 직렬라인으로부팅 가능◦ PreOS -> 드라이버인식 , 제어 ,cd, 파일복사 , 인터넷 ,마우스 , 쉘 ,GUI, 다국어 ( 한국어 )◦ 한계용량 극복 (Globally Unuque Identifier->GPT)◦ 운영체제 손상시 유용◦ C 언어로작성 -> 확장성◦ 다양한 플랫폼지원

Introduction (2/2)

Page 5: A Trusted Bootstrap Scheme on EFI  and TC

EFI Boot Process

Page 6: A Trusted Bootstrap Scheme on EFI  and TC
Page 7: A Trusted Bootstrap Scheme on EFI  and TC

Trust chain in EFI

Page 8: A Trusted Bootstrap Scheme on EFI  and TC

Trusted boot process of EFI

Page 9: A Trusted Bootstrap Scheme on EFI  and TC

TPM

Page 10: A Trusted Bootstrap Scheme on EFI  and TC

TPM Software Stack

Page 11: A Trusted Bootstrap Scheme on EFI  and TC

Attestation

Page 12: A Trusted Bootstrap Scheme on EFI  and TC

EFI

TPM

Problem