首页> 外文会议>European Symposium on Research in Computer Security >Detangling Resource Management Functions from the TCB in Privacy-Preserving Virtualization
【24h】

Detangling Resource Management Functions from the TCB in Privacy-Preserving Virtualization

机译:在隐私保留虚拟化中的TCB中解铃资源管理功能

获取原文

摘要

Recent research has developed virtualization architectures to protect the privacy of guest virtual machines. The key technology is to include an access control matrix in the hypervisor. However, existing approaches have either limited functionalities in the hypervisor or a Trusted Computing Base (TCB) which is too large to secure. In this paper, we propose a new architecture, MyCloud SEP, to separate resource allocation and management from the hypervisor in order to reduce the TCB size while supporting privacy protection. In our design, the hypervisor checks all resource accesses against an access control matrix in the hypervisor. While providing flexibility of plugging-in resource management modules, the size of TCB is significantly reduced compared with commercial hypervisors. Using virtual disk manager as an example, we implement a prototype on x86 architecture. The performance evaluation results also show acceptable overheads.
机译:最近的研究开发了虚拟化架构,以保护客人虚拟机的隐私。关键技术是在虚拟机管理程序中包含一个访问控制矩阵。然而,现有方法具有虚拟机管理程序或可信计算库(TCB)的有限功能,这太大而无法安全。在本文中,我们提出了一种新的体系结构,MyCloud SEP,以将资源分配和管理从管理程序分开,以便在支持隐私保护时降低TCB大小。在我们的设计中,管理程序在管理程序中检查所有资源访问的所有资源访问。虽然提供插入式资源管理模块的灵活性,但与商业虚拟机管理程序相比,TCB的尺寸显着减少。使用虚拟磁盘管理器作为示例,我们在X86架构上实现了原型。性能评估结果也显示出可接受的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号