Re: Release: KNOPPIX5.1.1 for Trusted Compuintg Geeks (v1.0)

 >>> >> We released KNOPPIX5.1.1 for Trusted Computing Geeks (v1.0).
 >>> >>    http://unit.aist.go.jp/itri/knoppix/index-en.html
 >>> >> It includes trusted computing software based on TPM(Trusted Platform
 >>> >> Module). Debian packages on KNOPPIX is validated by Remote Attestation.
 >>> sounds an awful lot like Remote Exploit to me.
 >>That's indeed remotely similar.

Our remote attestation is a kind of CHECKER of two type of database
for trustworthy. The database of DSA (Debian Security Advisory)
validates the packages of knoppix.  The database of platform integrity
was created by our samples, which is listed at
The database validates the boot procedure, which is based on "Trusted

 >>See e.g.: http://lwn.net/Articles/144681/

Thank you. Good reference site.

 >>That said, I don't fully understand what they attempt to provide.
 >>>From the little I understand, I figure that their system tries to
 >>guarantee that all software is valid Debian debs (plus some bits from
 >>their repositories). I have no idea how they implemented this. I have no
 >>idea what are the actual guarantees of kernel-level "trusted computing" 
 >>to a system as complex as Debian. 

Please refer the following papers.

 "Design and Implementation of a TCG-based Integrity Measurement
 Architecture", USENIX Security Symposium 2004.
 "Trusted Computing and Linux", Ottawa Linux Symposium 2005.


