首页> 外文会议>IEEE/ACM International Symposium on Microarchitecture >Architectural support for secure virtualization under a vulnerable hypervisor
【24h】

Architectural support for secure virtualization under a vulnerable hypervisor

机译:在易受攻击的虚拟机管理程序下对安全虚拟化的架构支持

获取原文

摘要

Although cloud computing has emerged as a promising future computing model, security concerns due to malicious tenants have been deterring its fast adoption. In cloud computing, multiple tenants may share physical systems by using virtualization techniques. In such a virtualized system, a software hypervisor creates virtual machines (VMs) from the physical system, and provides each user with an isolated VM. However, the hypervisor, with a full control over hardware resources, can access the memory pages of guest VMs without any restriction. By compromising the hypervisor, a malicious user can access the memory contents of the VMs used by other users. In this paper, we propose a hardware-based mechanism to protect the memory of guest VMs from unauthorized accesses, even with an untrusted hypervisor. With this mechanism, memory isolation is provided by the secure hardware, which is much less vulnerable than the software hypervisor. The proposed mechanism extends the current hardware support for memory virtualization with a small extra hardware cost. The hypervisor can still flexibly allocate physical memory pages to virtual machines for efficient resource management. However, the hypervisor can update nested page tables only through the secure hardware mechanism, which verifies each mapping change. Using the hardware-oriented mechanism in each system securing guest VMs under a vulnerable hypervisor, this paper also proposes a cloud system architecture, which supports the authenticated launch and migration of guest VMs.
机译:虽然云计算已成为一个有前途的未来计算模式,但由于恶意租户的安全问题一直阻碍了其快速采用。在云计算中,多个租户可以使用虚拟化技术共享物理系统。在这样的虚拟化系统中,软件管理程序从物理系统创建虚拟机(VM),并为每个用户提供隔离的VM。但是,通过完全控制硬件资源的管理程序可以访问Guest虚拟机的内存页面,而无需任何限制。通过损害虚拟机管理程序,恶意用户可以访问其他用户使用的VM的内存内容。在本文中,我们提出了一种基于硬件的机制来保护访客VM的存储器免受未经授权的访问,即使具有不受信任的虚拟机管理程序。利用这种机制,内存隔离由安全硬件提供,这比软件虚拟机管理程序要小得多。所提出的机制通过额外的硬件成本扩展了对存储器虚拟化的当前硬件支持。管理程序仍然可以灵活地将物理内存页分配给虚拟机,以实现高效的资源管理。但是,管理程序只能通过安全硬件机制更新嵌套页面表,该机制验证每个映射更改。在漏洞的管理程序下,使用每个系统中的面向硬件的机制保护Guest虚拟机管理程序,本文还提出了一种云系统架构,支持Guest虚拟机的经过身份验证的启动和迁移。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号