首页> 外文会议>International Conference on System Safety and Cyber-Security >Porridge: A method of providing resilient and scalable Cloud-Attestation-as-a-Service
【24h】

Porridge: A method of providing resilient and scalable Cloud-Attestation-as-a-Service

机译:粥:一种提供弹性和可扩展云证明 - AS-Service的方法

获取原文

摘要

Effectively establishing trust in Cloud Computing is a critical requirement for achieving wider adoption of hybrid and public cloud. Although a number of Trusted Cloud concepts have been proposed, they suffer from limitations in resilience, scalability and dynamism. We tackle these limitations with the creation of a distributed attestation service, Porridge. Porridge achieves resiliency, as multiple attestation workers are employed and redundant workers assigned for attesting each Virtual Machine (VM); scalability, as the attestation load and responsibility is automatically distributed evenly among workers; adaptivity to cloud dynamism, as each VM's virtual Trusted Platform Module (vTPM) is mapped to a stable set of physical Trusted Platform Modules (TPM) in the host and then the workers TPMs. Overall the attestation scheme enables flexible vTPM-TPM bindings while hiding details of cloud infrastructure, with the root-of-trust for the VM not bound to its underlying host's TPM, but to its managing workers. This concept can be extended to support more advanced cloud security through the introduction of Trusted Service Providers providing Cloud Attestation as a Service (CAaaS).
机译:在云计算中有效地建立信任是实现宽泛采用混合动力车和公共云的关键要求。虽然已经提出了许多值得信赖的云概念,但它们遭受弹性,可扩展性和活力的限制。我们通过创建分布式证明服务粥来解决这些限制。粥达到弹性,因为采用了多种认证工人,并且分配了冗余工人,用于证明每个虚拟机(VM);可扩展性,因为证明负荷和责任自动分布在工人之间;对云动态的适应性,因为每个VM的虚拟可信平台模块(VTPM)映射到主机中的稳定的物理可信平台模块(TPM),然后是工人TPMS。总的来说,证明方案使灵活的VTPM-TPM绑定能够在隐藏云基础架构的细节,并对VM的无限制无限制,而是对其管理工作人员。通过引入可信服务提供商将云证明作为服务(CAAAS),可以扩展此概念以支持更高级的云安全。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号