The invention discloses a trustworthy computing base anti-leakage
cutting method used for a
virtual machine system; the
virtual machine system comprises a hardware layer, a
virtual machine monitor layer, a virtual
trusted platform module manager,
a domain creating module, a kernel and a sensitive
data access policy; the virtual
trusted platform module manager, the domain creating module, the kernel and the sensitive
data access policy are positioned at a privilege domain; the method is characterized in that: a special user domain which is isolated with the privilege domain is built, the virtual
trusted platform module manager, the domain creating module and the sensitive
data access policy are moved to the special user domain, and the kernel is kept in the privilege domain; communication is built between the privilege domain and the special user domain, and the trustworthy computing base is formed by the hardware layer, the virtual
machine monitor layer, the virtual trusted platform module manager, the domain creating module and the sensitive data access policy; the invention provides a trustworthy computing base
cutting proposal, the advantages of the traditional trustworthy computing base proposal is not only kept, but also the safety and starting speed of the virtual
machine system are enhanced.