首页> 外文期刊>Concurrency and computation: practice and experience >Secure cryptographic functions via virtualization-based outsourced computing
【24h】

Secure cryptographic functions via virtualization-based outsourced computing

机译:通过基于虚拟化的外包计算来保护加密功能

获取原文
获取原文并翻译 | 示例
           

摘要

Cryptographic functions, such as encryption/decryption libraries, are common and important tools for applications to enhance confidentiality of the data. However, these functions could be compromised by subtle attacks launched by untrusted operating system or other applications, and sensitive keys or cryptographic procedures could then be compromised. In this paper, based on virtualization technology, we propose a novel approach that outsources the cryptographic functions in one virtual machine (VM) into another dedicated VM, so that sensitive keys and the cryptographic procedures are only contained by this VM with specific purpose. We also propose a prototype, called cryptographic function assurance (CFA), to enhance the security of cryptographic functions. Taking OpenSSL as an example, CFA allows those applications that use OpenSSL library to transparently utilize CFA to protect the cryptographic functions. We present the detailed implementation, as well as the security analysis of CFA. We also give the performance evaluation for OpenSSL's interfaces and Apache httpd, to show the overhead caused by the integration of CFA. Copyright © 2015 John Wiley & Sons, Ltd.
机译:加密功能(例如加密/解密库)是应用程序用来增强数据机密性的常用工具。但是,不受信任的操作系统或其他应用程序发起的细微攻击可能会破坏这些功能,然后可能会破坏敏感密钥或加密过程。在本文中,基于虚拟化技术,我们提出了一种新颖的方法,该方法将一个虚拟机(VM)中的加密功能外包到另一个专用VM中,以便该特定目的的VM仅包含敏感密钥和加密过程。我们还提出了一个原型,称为密码功能保证(CFA),以增强密码功能的安全性。以OpenSSL为例,CFA允许那些使用OpenSSL库的应用程序透明地利用CFA保护密码功能。我们介绍了CFA的详细实现以及安全性分析。我们还对OpenSSL的接口和Apache httpd进行了性能评估,以显示CFA集成引起的开销。版权所有©2015 John Wiley&Sons,Ltd.

著录项

  • 来源
  • 作者单位

    Huazhong University of Science and Technology Services Computing Technology and System Lab and Cluster and Grid Computing Lab School of Computer Science and Technology Wuhan China;

    Huazhong University of Science and Technology Services Computing Technology and System Lab and Cluster and Grid Computing Lab School of Computer Science and Technology Wuhan China;

    Huazhong University of Science and Technology Services Computing Technology and System Lab and Cluster and Grid Computing Lab School of Computer Science and Technology Wuhan China;

    Huazhong University of Science and Technology Services Computing Technology and System Lab and Cluster and Grid Computing Lab School of Computer Science and Technology Wuhan China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    cryptographic functions; virtualization; untrusted OS; outsourced computing;

    机译:加密功能;虚拟化;不受信任的操作系统;外包计算;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号