【24h】

TSD: A Flexible Root of Trust for the Cloud

机译:TSD:灵活的云信任根

获取原文
获取原文并翻译 | 示例

摘要

Due to the tight one-to-one binding relationship between the TPM and the single platform lacks of flexibility and scalability, the Trusted Platform Module (TPM) can not be directly applied to the cloud virtualization platform, on which concurrently running several user domains (VMs). For establishing the trust in the cloud, we propose the Trusted Service Domain (TSD), as a novel root of trust for the cloud. Being an independent functional domain, the TSD is able to provide the trusted service for the multiple user domains on the cloud virtualization platform. We firstly extend the existing trusted chain to secure the TSD, and generate the independent key hierarchies for the user domains in the TSD to support the cryptography service and secure storage. Then we design the secure communication mechanism to protect the inter-domain data, and present the migration scheme for the TSD in the cloud. Finally, we detailed our implementation of the prototype system and analyze the security of the TSD. Preliminary experiment results showed that the TSD has higher efficiency than the existing schemes on the trusted commands handling and the migration, which satisfied flexible deployment and rapidly migration requirements of the cloud virtualization platform.
机译:由于TPM与单一平台之间的紧密一对一绑定关系缺乏灵活性和可伸缩性,因此受信任的平台模块(TPM)无法直接应用于同时运行多个用户域的云虚拟化平台(虚拟机)。为了建立对云的信任,我们提出了可信服务域(TSD),作为对云的新型信任根。作为一个独立的功能域,TSD能够为云虚拟化平台上的多个用户域提供可信服务。我们首先扩展现有的受信任链来保护TSD,并为TSD中的用户域生成独立的密钥层次结构,以支持加密服务和安全存储。然后,我们设计了一种安全的通信机制来保护域间数据,并提出了云中TSD的迁移方案。最后,我们详细介绍了原型系统的实现并分析了TSD的安全性。初步实验结果表明,TSD在可信命令处理和迁移方面具有比现有方案更高的效率,满足了云虚拟化平台的灵活部署和快速迁移的需求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号