首页> 外文会议>Mediterranean conference on information communication technologies >Protecting Co-resident VMs from Side-Channel Attack in Cloud Environment: SAFEPERIMETER System
【24h】

Protecting Co-resident VMs from Side-Channel Attack in Cloud Environment: SAFEPERIMETER System

机译:在云环境中保护共同驻留的虚拟机免受侧通道攻击:SAFEPERIMETER系统

获取原文

摘要

Today, the use of Cloud Computing is constrained by its vulnerabilities, because sharing the same resources with potential attackers may breaks the isolation between VMs. Also, some studies demonstrated that cache-based side channel attacks can break full encryption keys of RSA, DES and AES. In this paper we investigate side channel attacks via shared memory caches that can break the isolation between Vms, and present our new system, which has been called SAFEPERIMETER, and which aims to mitigate such discussed attacks, in a special thread, like AES encryption. It consists on securing access to L3 cache by locking it line by line, for a special confidential thread, without assigning any locked cache line to any VM. We also present the idea of implementing this service on a particular Image Management System.
机译:如今,云计算的使用受到其漏洞的限制,因为与潜在的攻击者共享相同的资源可能会破坏虚拟机之间的隔离。此外,一些研究表明,基于缓存的边信道攻击可以破坏RSA,DES和AES的完整加密密钥。在本文中,我们通过共享内存缓存研究了可以破坏Vms之间隔离的侧面通道攻击,并提出了我们的新系统SAFEPERIMETER,其目的是在诸如AES加密之类的特殊线程中减轻这种讨论的攻击。它包括通过为特殊的机密线程逐行锁定L3缓存来确保对L3缓存的访问,而无需将任何锁定的缓存行分配给任何VM。我们还提出了在特定的图像管理系统上实施此服务的想法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号