【24h】

Secure Out-of-Band Remote Management Using Encrypted Virtual Serial Consoles in IaaS Clouds

机译:使用IaaS云中的加密虚拟串行控制台进行安全的带外远程管理

获取原文

摘要

In Infrastructure-as-a-Service (IaaS) clouds, users manage the systems in virtual machines (VMs) through remote management systems such as Secure Shell (SSH). IaaS often provides out-of-band remote management using virtual serial consoles (VSCs). Even on failures inside their VMs, users can directly access their systems through a virtual serial device in the management VM. However, the management VM is not always trustworthy in IaaS. Attackers in the management VM can easily eavesdrop on inputs and outputs in remote management. In this paper, we propose SCCrypt for preventing information leakage in out-of-band remote management. SCCrypt provides encrypted VSCs to the management VM. In an encrypted VSC, the trusted virtual machine monitor (VMM) securely decrypts console inputs encrypted in an SSH client. It also encrypts console outputs, which are decrypted in an SSH client. For this purpose, the VMM correctly identifies the inputs and ouputs by tracking device state without the cooperation of the management VM and user VMs. To support a key change at the reconnection to an encrypted VSC, the VMM re-encrypts pending console outputs. We have implemented SCCrypt in Xen and the OpenSSH client. Then we confirmed that any information did not leak and the overhead was small enough.
机译:在基础架构即服务(IaaS)云中,用户通过诸如Secure Shell(SSH)之类的远程管理系统来管理虚拟机(VM)中的系统。 IaaS通常使用虚拟串行控制台(VSC)提供带外远程管理。即使虚拟机内部发生故障,用户也可以通过管理虚拟机中的虚拟串行设备直接访问其系统。但是,管理VM在IaaS中并不总是值得信赖的。管理VM中的攻击者可以轻松窃听远程管理中的输入和输出。在本文中,我们提出SCCrypt来防止带外远程管理中的信息泄漏。 SCCrypt向管理VM提供加密的VSC。在加密的VSC中,受信任的虚拟机监视器(VMM)安全地解密在SSH客户端中加密的控制台输入。它还会加密控制台输出,并在SSH客户端中将其解密。为此,VMM通过跟踪设备状态来正确识别输入和输出,而无需管理VM和用户VM的配合。为了在重新连接到加密的VSC时支持密钥更改,VMM会对挂起的控制台输出进行重新加密。我们已经在Xen和OpenSSH客户端中实现了SCCrypt。然后我们确认任何信息都不会泄漏,并且开销足够小。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号