首页> 外文学位 >Practical system integrity verification in cloud computing environments.
【24h】

Practical system integrity verification in cloud computing environments.

机译:云计算环境中的实用系统完整性验证。

获取原文
获取原文并翻译 | 示例

摘要

Online applications have become the de facto medium through which modern computing services are offered. This model not only reduces administrative costs, but enables companies to shift their physical infrastructure to virtualized environments like cloud computing platforms. However, with this move to remotely administered services come serious risks. Since users no longer control the systems they rely upon, they must assume they were correctly configured to protect their sensitive data. As history has demonstrated, even the most well funded companies are prone to compromises, which may lead to the loss of countless confidential customer records. If the world is to continue adopting this computing model, then a greater emphasis must be placed on building verifiable systems that customers can inspect.;In this dissertation, we explore the design challenges in building verification frameworks that overcome the limitations of current verification techniques for detecting unsafe and compromised systems. Existing approaches leverage trusted computing hardware like the Trusted Platform Module (TPM) to securely record and attest to integrity-relevant events occurring on the proving system. However, these approaches are insufficient for verifying today's high performance and highly connected environments. First, we developed the Root of Trust for Installation, a method for bootstrapping trust in virtual machine (VM) hosts that form the basis of many cloud offerings. Second, we designed a remote integrity verifier to address many of the difficulties that attestation-only verification causes. Using this Integrity Verification Proxy, we are able to verify heterogeneous integrity requirements at the proving system without the delay and complexity of traditional integrity measurement. Finally, we incorporated our research into the Cloud Verifier, a framework for verifying the integrity of instances hosted on clouds. This permits cloud administrators, customers, and external clients to verify integrity criteria without having to directly inspect the configuration of the entire platform. Our proof-of-concept implementation and evaluation demonstrates the feasibility of building a verifiable, yet functional cloud platform. While this work represents only a starting point, we believe it will lead to a greater understand of how today's online services can be designed in a more transparent way.
机译:在线应用程序已经成为提供现代计算服务的事实上的媒介。这种模型不仅降低了管理成本,而且使公司能够将其物理基础架构转移到云计算平台等虚拟化环境。但是,随着向远程管理服务的转移,带来了严重的风险。由于用户不再控制他们依赖的系统,因此他们必须假定已正确配置它们以保护其敏感数据。历史证明,即使资金最雄厚的公司也容易遭受妥协,这可能会导致丢失无数的机密客户记录。如果世界要继续采用这种计算模型,那么就必须更加着重于构建客户可以检查的可验证系统。在本论文中,我们探索了构建验证框架的设计挑战,这些框架克服了当前验证技术的局限性。检测不安全和受到威胁的系统。现有方法利用诸如可信平台模块(TPM)之类的可信计算硬件来安全地记录和证明在证明系统上发生的与完整性相关的事件。但是,这些方法不足以验证当今的高性能和高度连接的环境。首先,我们开发了“安装的信任根”,这是一种引导虚拟机(VM)主机中信任的方法,而虚拟机是许多云产品的基础。其次,我们设计了一个远程完整性验证程序,以解决仅证明验证所引起的许多困难。使用此完整性验证代理,我们能够在证明系统上验证异构完整性要求,而不会出现传统完整性测量的延迟和复杂性。最后,我们将研究成果纳入了Cloud Verifier,这是一个用于验证托管在云上的实例的完整性的框架。这允许云管理员,客户和外部客户端验证完整性标准,而不必直接检查整个平台的配置。我们的概念验证实施和评估证明了构建可验证且功能强大的云平台的可行性。尽管这项工作只是一个起点,但我们相信它将使人们更加了解如何以更加透明的方式设计当今的在线服务。

著录项

  • 作者单位

    The Pennsylvania State University.;

  • 授予单位 The Pennsylvania State University.;
  • 学科 Engineering Computer.;Computer Science.
  • 学位 Ph.D.
  • 年度 2012
  • 页码 129 p.
  • 总页数 129
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号