TPMSpy:通过低级别追踪TPM使用情况验证 Measured Boot 系统
TPMSpy: Validation of Measured Boot Systems by Low-Level Tracing of TPM Usage
浏览论文内容
中文总结 AI 辅助
TPMSpy 是一种平台无关方法,通过分析虚拟化系统与 TPM 交互的低级别使用情况,验证 Measured Boot 系统,可应用于 Linux、Windows,发现 systemd 245-258 版本的 Measured Boot 存在测量不一致等问题。
中文摘要 AI 辅助
Measured Boot 将已执行软件和系统状态的密码学测量值记录到可信平台模块(TPM)中,从而扩展了对已引导系统的信任,并支持通过远程证明进行后续验证。尽管该机制在当代操作系统中部署日益广泛,但其实际安全性取决于实现是否在预期条件下测量了预期组件,而这一点并未得到系统检查。我们提出了一种平台无关的方法,用于分析虚拟化系统与 TPM 交互层面的低级别 TPM 使用情况,该方法无需依赖 Quote 机制本身即可独立重建和验证 TPM 事件日志。由于该方法不依赖实现细节,因此适用于开源和闭源系统。我们在 Linux 和 Windows 上演示了该方法,并对 systemd 版本 245 至 258(2020 年至 2025 年)的 Linux 系统进行了系统纵向分析,研究了 Measured Boot 使用情况的演变并观察到广泛差异。系统之间未出现单一使用模式,因此需要定制化分析。该分析识别出未记录的行为变化,揭示了用户空间 systemd 服务的测量值不一致,这会阻止此类系统上可靠的远程证明和 LUKS 磁盘解密。
英文摘要
Measured Boot extends trust in a booted system by recording cryptographic measurements of executed software and system state into a Trusted Platform Module (TPM), enabling subsequent verification through remote attestation. Although this mechanism is increasingly deployed in contemporary operating systems, its practical security depends on whether implementations measure the expected components under the expected conditions, yet this is not checked systematically. We propose a platform-agnostic method for analysing low-level TPM usage at the level of virtualized system--TPM interactions. It enables independent reconstruction and validation of the TPM Event Log without relying on the quoting mechanism itself. Because it does not depend on implementation details, it is applicable to both open and closed systems. We demonstrate the method on both Linux and Windows and conduct a systematic longitudinal analysis of Linux systems with systemd versions 245--258 (2020--2025), examining how Measured Boot usage evolved and observing wide divergence. No single usage pattern emerged amongst systems, warranting customized analysis. The analysis identifies undocumented behavioural changes, reveals inconsistent measurements of user-space systemd services, which prevent reliable remote attestation and LUKS disk decryption on such systems.
发表机构
- Masaryk University(马萨里克大学)
机构由 AI 辅助整理,请以论文原文为准。