引用本文: |
-
石文昌,宋元,周春喜.一种基于多核的完整性度量实施方法[J].广西科学院学报,2020,36(3):317-322. [点击复制]
- SHI Wenchang,SONG Yuan,ZHOU Chunxi.A Multi-Cores-Based Approach to Integrity Measurement Enforcement[J].Journal of Guangxi Academy of Sciences,2020,36(3):317-322. [点击复制]
|
|
摘要: |
为了解决在使用内核完整性度量机制对操作系统进行实时度量时,由于操作系统内核在设计之初没有考虑内核完整性度量机制的出现,导致不能对系统进行及时度量的问题,本研究提出一种基于多核的完整性度量实施方法,该方法通过在操作系统内核相关部分加入对内核完整性度量机制的支持来解决这一问题。本文首先介绍该方法的设计和实现,然后通过实验对该方法的有效性及性能开销进行分析。该方法可以为内核完整性度量机制分配核运行,实现对操作系统内核的及时度量,且性能开销极小。 |
关键词: 操作系统 内核 完整性度量 度量实施方法 多核处理器 调度 |
DOI:10.13657/j.cnki.gxkxyxb.20201027.008 |
|
基金项目:国家自然科学基金项目(61472429,61070192和61170240),北京市自然科学基金项目(4122041)和国家社科重大项目(20ZDA062)资助。 |
|
A Multi-Cores-Based Approach to Integrity Measurement Enforcement |
SHI Wenchang, SONG Yuan, ZHOU Chunxi
|
(School of Information, Renmin University of China, Beijing, 100872, China) |
Abstract: |
In order to solve the problem that when using the kernel integrity measurement mechanisms to measure the integrity of the operating system in real-time,because the kernel integrity measurement mechanisms had not been taken into consideration when designing the kernels,it usually causes the issue that integrity measurement mechanisms are not able to run on time.This paper proposes a multi-cores-based integrity measurement enforcement to solve this problem by adding mechanism supporting the measurement mechanisms to the kernel.This paper explains the design and implements of this method,and then analysis the effectiveness and performance of this method.By locating cores for the measurement mechanisms to run,the enforcement can let measurement mechanisms measure the kernel on time with little performance cost. |
Key words: operating system kernel integrity measurement measurement enforcement method multi-cores processor scheduling |