首页> 外文会议>IEEE Conference on Communications and Network Security >Enabling Trusted Data-intensive execution in cloud computing
【24h】

Enabling Trusted Data-intensive execution in cloud computing

机译:在云计算中启用可信的数据密集型执行

获取原文

摘要

The security and privacy of user data has become a major concern in the cloud computing era. Cryptographic solutions based on secure computation outsourcing have been extensively studied in order to protect the security and privacy of user data. However, these solutions either suffer from forbiddingly high computation overhead or are only applicable to certain special classes of computations. In this paper, we tackle the challenge of secure computation outsourcing using an entirely different approach - the idea is to have a secure execution environment in the cloud such that user data can be processed in plain text format without compromising its confidentiality. We propose a TrUsted Data-intensive ExeCution (TUDEC) environment optimized for data applications in the cloud. TUDEC is a new system architecture, designed to provide a secure environment for arbitrary data computations in the cloud server. Using a very small trusted computing base including only firmware and hardware, TUDEC is able to provide user VM with isolation against both the legacy host and neighboring VMs. Such isolation is unique in that it provides protection against any software-based attacks. By direct interrupt delivery, interrupt rerouting and IOMMU configuration lock, TUDEC enables close to bare metal computation and I/O performance without sacrificing any security guaranteed. We built a prototype and showed the high efficiency of TUDEC. In particular, when the server is heavily loaded, the TCP bandwidth of the guest VM in TUDEC is significantly better than the current state of art secure execution environment design.
机译:用户数据的安全性和保密性已成为云计算时代的主要关注点。为了保护用户数据的安全性和私密性,已经广泛研究了基于安全计算外包的密码解决方案。但是,这些解决方案要么承受着巨大的计算开销,要么仅适用于某些特殊类别的计算。在本文中,我们使用完全不同的方法来解决安全计算外包的挑战-想法是在云中拥有一个安全的执行环境,以便可以以纯文本格式处理用户数据而不会损害其机密性。我们提出了针对云中的数据应用程序优化的TrUsted数据密集型执行(TUDEC)环境。 TUDEC是一种新的系统架构,旨在为云服务器中的任意数据计算提供安全的环境。 TUDEC使用仅包含固件和硬件的非常小的受信任计算基础,能够为用户VM提供与传统主机和相邻VM隔离的隔离。这种隔离的独特之处在于,它可以防止任何基于软件的攻击。通过直接中断传递,中断重新路由和IOMMU配置锁定,TUDEC可以在不牺牲任何安全性的情况下实现接近裸机的计算和I / O性能。我们构建了一个原型,并展示了TUDEC的高效率。特别是,当服务器负载很重时,TUDEC中来宾VM的TCP带宽明显优于当前最新的安全执行环境设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号