首页> 外文期刊>Computers & Security >Hardware-based solutions for trusted cloud computing
【24h】

Hardware-based solutions for trusted cloud computing

机译:基于硬件的可信云计算解决方案

获取原文
获取原文并翻译 | 示例

摘要

The increasing number of threats targeting cloud computing and the exploitation of specifically privileged software vulnerabilities have pushed the security managers of cloud service providers to deploy hardware-based solutions. These solutions can offer better hardware-assisted security features for a broad range of computing platforms including both CISC and RISC architecture families in datacenters. Their goal is to reduce the attack surface by rooting the trust into the hardware instead of some high-privileged pieces of system software such as the operating system or the hypervisor which have been demonstrated that they include severe security vulnerabilities, thus limiting the adoption of the cloud computing model for some security-skeptical users. In this paper, we give cloud users and customers, application developers and security managers a comprehensive overview of four major industrial-scale commercial hardware-based solutions brought by major vendors in the cloud market. We present, analyze and compare Intel TXT, ARM TrustZone, AMD SEV, and Intel SGX technologies with respect to more than twenty criteria fitting within three categories: security, functional and deployment. We discuss each of these technologies and show the cases where they particularly excel. Our comparison can help IT managers to take the right decision about which better industrial technology to adopt for their particular security requirements and future cloud migrations.
机译:越来越多的威胁云计算和专门特权软件漏洞的开发已经推动了云服务提供商的安全管理人员来部署基于硬件的解决方案。这些解决方案可以为广泛的计算平台提供更好的硬件辅助安全功能,包括数据中心中的CISC和RISC架构系列。他们的目标是通过将信任源于硬件而不是一些高特权的系统软件(如操作系统或虚拟机管理程序)来减少攻击面,这些软件已经证明它们包括严重的安全漏洞,因此限制了采用一些安全持怀疑态度的云计算模型。在本文中,我们提供云用户和客户,应用程序开发人员和安全管理人员全面概述了云市场主要供应商带来的四个主要的工业规模商业硬件解决方案。我们在三个类别中介绍,分析和比较Intel TXT,ARM Trustzone,AMD SEV和Intel SGX技术:安全,功能和部署。我们讨论这些技术中的每一个,并展示他们特别优质的情况。我们的比较可以帮助IT管理人员采取正确的决定,更好的工业技术为其特定的安全要求和未来的云迁移采用。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号