This paper presents an extended trusted computing and forensics model in order to efficiently investigate the environment based on trusted computing technique.The workflow of traditional digital forensics model is improved: awareness
authorization and planning task are added.The extended trusted computing and forensic services are used in collecting and analysis activity
including forensic sealing
forensic authentication
key recovery and distributed forensic services.So the trusted computing environment can be investigated by extend forensic services and improved workflow.By the evaluation and comparison
the model has the ability to investigate trusted computing environment.
关键词
数字取证可信计算数据获取加密文件系统
Keywords
digital forensicstrusted computingdata acquisitionencryptionfile system