首页> 外文期刊>Cloud Computing, IEEE Transactions on >Providing User Security Guarantees in Public Infrastructure Clouds
【24h】

Providing User Security Guarantees in Public Infrastructure Clouds

机译:在公共基础架构云中提供用户安全保证

获取原文
获取原文并翻译 | 示例

摘要

The infrastructure cloud (IaaS) service model offers improved resource flexibility and availability, where tenants – insulated from the minutiae of hardware maintenance – rent computing resources to deploy and operate complex systems. Large-scale services running on IaaS platforms demonstrate the viability of this model; nevertheless, many organizations operating on sensitive data avoid migrating operations to IaaS platforms due to security concerns. In this paper, we describe a framework for data and operation security in IaaS, consisting of protocols for a trusted launch of virtual machines and domain-based storage protection. We continue with an extensive theoretical analysis with proofs about protocol resistance against attacks in the defined threat model. The protocols allow trust to be established by remotely attesting host platform configuration prior to launching guest virtual machines and ensure confidentiality of data in remote storage, with encryption keys maintained outside of the IaaS domain. Presented experimental results demonstrate the validity and efficiency of the proposed protocols. The framework prototype was implemented on a test bed operating a public electronic health record system, showing that the proposed protocols can be integrated into existing cloud environments.
机译:基础架构云(IaaS)服务模型提供了改进的资源灵活性和可用性,其中租户–与硬件维护的细节隔离–租用计算资源来部署和操作复杂的系统。在IaaS平台上运行的大规模服务证明了该模型的可行性。但是,出于安全考虑,许多处理敏感数据的组织都避免将操作迁移到IaaS平台。在本文中,我们描述了IaaS中的数据和操作安全性框架,该框架由用于可靠启动虚拟机和基于域的存储保护的协议组成。我们将继续进行广泛的理论分析,并提供有关已定义威胁模型中的协议抵抗攻击的证据。该协议允许在启动来宾虚拟机之前通过远程验证主机平台配置来建立信任,并通过在IaaS域外部维护的加密密钥来确保远程存储中数据的机密性。提出的实验结果证明了所提出协议的有效性和效率。该框架原型是在运行公共电子健康记录系统的测试床上实现的,表明所建议的协议可以集成到现有的云环境中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号