首页> 外文期刊>Cloud Computing, IEEE Transactions on >Secure Outsourcing of Virtual Appliance
【24h】

Secure Outsourcing of Virtual Appliance

机译:虚拟设备的安全外包

获取原文
获取原文并翻译 | 示例
           

摘要

Computation outsourcing using virtual appliance is getting prevalent in cloud computing. However, with both hardware and software being controlled by potentially curious or even malicious cloud operators, it is no surprise to see frequent reports of security accidents, like data leakages or abuses. This paper proposes Kite, a hardware-software framework that guards the security of tenant’s virtual machine (VM), in which the outsourced computation is encapsulated. Kite only trusts the processor and makes no security assumption on external memory, devices, or hypervisor. Unlike prior hardware-based approaches, Kite retains transparency with existing VM and requires few changes to the (untrusted) hypervisor by introducing VM-Shim mechanism. Each VM-Shim instance runs in between its VM and the hypervisor, which only transfers necessary information designated by the VM to the hypervisor and external environments. Kite also considers the high-level semantic of interaction between VM and hypervisor to defend against attacks through legitimate operations or interfaces. We have implemented a prototype of Kite’s secure processor in a QEMU-based full-system emulator and its software components on real machine. Evaluation shows that the performance overhead of Kite ranges from 0.5-14.0 percent on simulated platform and 0.4-7.3 percent on real hardware.
机译:使用虚拟设备的计算外包在云计算中越来越普遍。但是,由于软硬件都由潜在的好奇甚至是恶意的云运营商控制,因此频繁出现安全事故报告(如数据泄漏或滥用)也就不足为奇了。本文提出了一种Kite,一种硬件软件框架,可保护租户虚拟机(VM)的安全性,其中封装了外包的计算。 Kite仅信任处理器,不对外部存储器,设备或虚拟机监控程序进行安全假设。与以前的基于硬件的方法不同,Kite保留了现有VM的透明性,并且通过引入VM-Shim机制几乎不需要更改(不受信任的)虚拟机管理程序。每个VM-Shim实例都在其VM和管理程序之间运行,后者仅将VM指定的必要信息传输到管理程序和外部环境。 Kite还考虑了VM和虚拟机管理程序之间交互的高级语义,以防御通过合法操作或接口进行的攻击。我们已经在基于QEMU的完整系统仿真器中实现了Kite安全处理器的原型,并在实际机器上实现了其软件组件。评估显示,在仿真平台上,Kite的性能开销范围为0.5-14.0%,在实际硬件上为0.4-7.3%。

著录项

  • 来源
    《Cloud Computing, IEEE Transactions on》 |2017年第3期|390-404|共15页
  • 作者单位

    Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University, Shanghai, China;

    Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University, Shanghai, China;

    Department of Computer Science, Shanghai Jiao Tong University, Shanghai, China;

    Institute of Computing Technology, Chinese Academy of Sciences, China;

    Institute of Computing Technology, Chinese Academy of Sciences, China;

    Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University, Shanghai, China;

    Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University, Shanghai, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Virtual machine monitors; Software; Security; Hardware; Virtualization; Context; Outsourcing;

    机译:虚拟机监视器;软件;安全性;硬件;虚拟化;上下文;外包;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号