首页> 外文期刊>Computer architecture news >NoHype: Virtualized Cloud Infrastructure without the Virtualization
【24h】

NoHype: Virtualized Cloud Infrastructure without the Virtualization

机译:NoHype:没有虚拟化的虚拟化云基础架构

获取原文
获取原文并翻译 | 示例
           

摘要

Cloud computing is a disruptive trend that is changing the way we use computers. The key underlying technology in cloud infrastructures is virtualization - so much so that many consider virtualization to be one of the key features rather than simply an implementation detail. Unfortunately, the use of virtualization is the source of a significant security concern. Because multiple virtual machines run on the same server and since the virtualization layer plays a considerable role in the operation of a virtual machine, a malicious party has the opportunity to attack the virtualization layer. A successful attack would give the malicious party control over the all-powerful virtualization layer, potentially compromising the confidentiality and integrity of the software and data of any virtual machine. In this paper we propose removing the virtualization layer, while retaining the key features enabled by virtualization. Our NoHype architecture, named to indicate the removal of the hypervisor, addresses each of the key roles of the virtualization layer: arbitrating access to CPU, memory, and I/O devices, acting as a network device (e.g., Ethernet switch), and managing the starting and stopping of guest virtual machines. Additionally, we show that our NoHype architecture may indeed be "no hype" since nearly all of the needed features to realize the NoHype architecture are currently available as hardware extensions to processors and I/O devices.
机译:云计算是一种颠覆性趋势,正在改变我们使用计算机的方式。云基础架构中的关键基础技术是虚拟化-如此之多,以至于许多人认为虚拟化是关键功能之一,而不仅仅是实现细节。不幸的是,使用虚拟化是引起重大安全问题的根源。因为多个虚拟机在同一台服务器上运行,并且虚拟化层在虚拟机的运行中起着相当重要的作用,所以恶意方有机会攻击虚拟化层。成功的攻击将使恶意方能够控制功能强大的虚拟化层,从而有可能损害任何虚拟机的软件和数据的机密性和完整性。在本文中,我们建议删除虚拟化层,同时保留虚拟化启用的关键功能。我们的NoHype架构的名称表示要删除虚拟机管理程序,它解决了虚拟化层的每个关键角色:仲裁对CPU,内存和I / O设备的访问,充当网络设备(例如,以太网交换机),以及管理来宾虚拟机的启动和停止。此外,我们证明我们的NoHype架构实际上可能是“没有炒作”,因为当前几乎所有实现NoHype架构所需的功能都可以作为处理器和I / O设备的硬件扩展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号