首页> 外文会议>2011 IEEE Ninth International Conference on Dependable, Autonomic and Secure Computing >An Authenticated Key Exchange Scheme for Efficient Security-Aware Scheduling of Scientific Applications in Cloud Computing
【24h】

An Authenticated Key Exchange Scheme for Efficient Security-Aware Scheduling of Scientific Applications in Cloud Computing

机译:云计算中科学应用的高效安全性调度的经过身份验证的密钥交换方案

获取原文

摘要

Instead of purchasing and maintaining their own computing infrastructure, scientists can now run data-intensive scientific applications in cloud computing environment by facilitating its vast storage and computation capabilities. During the scheduling of such scientific applications for execution, various computation data flows will happen between the controller and computing server instances. Amongst various quality-of-service (QoS) metrics, data security is one of the greatest concerns to scientists because their data may be intercepted or stolen by malicious parties during those data flows. An existing typical method for addressing this issue is to apply Internet Key Exchange (IKE) scheme to generate and exchange session keys, and then to apply these keys for performing symmetric-key encryption which will encrypt those data flows. However, the IKE scheme suffers from low efficiency due to its low performance of asymmetric-key crypto logical operations over a large amount of data and high-density operations which are exactly the characteristics of scientific applications. In this paper, we propose Cloud Computing Background Key Exchange (CCBKE), a novel authenticated key exchange scheme that aims at efficient security-aware scheduling of scientific applications. Our scheme is designed based on randomness-reuse strategy and Internet Key Exchange (IKE) scheme. Theoretical analyses and simulation results demonstrate that, compared with the IKE scheme, our CCBKE scheme can significantly improve the efficiency by dramatically reducing time consumption and computation load without sacrificing the level of security.
机译:现在,科学家无需购买和维护自己的计算基础架构,就可以通过促进其庞大的存储和计算功能,在云计算环境中运行数据密集型科学应用程序。在调度此类科学应用程序以供执行期间,控制器和计算服务器实例之间将发生各种计算数据流。在各种服务质量(QoS)指标中,数据安全性是科学家最关心的问题之一,因为在这些数据流期间,其数据可能被恶意方截获或窃取。解决此问题的现有典型方法是应用Internet密钥交换(IKE)方案来生成和交换会话密钥,然后将这些密钥应用于执行对称密钥加密,该对称密钥加密将对那些数据流进行加密。然而,由于其在大量数据上的非对称密钥密码运算的低性能以及高密度运算,这使得IKE方案效率低下,而这正是科学应用的特征。在本文中,我们提出了云计算背景密钥交换(CCBKE),这是一种新颖的经过身份验证的密钥交换方案,旨在对科学应用程序进行有效的安全感知调度。我们的方案是基于随机重用策略和Internet密钥交换(IKE)方案设计的。理论分析和仿真结果表明,与IKE方案相比,我们的CCBKE方案可以通过显着减少时间消耗和计算负荷而显着提高效率,而不会牺牲安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号