首页> 外文期刊>IEEE transactions on dependable and secure computing >CAFE: A Virtualization-Based Approach to Protecting Sensitive Cloud Application Logic Confidentiality
【24h】

CAFE: A Virtualization-Based Approach to Protecting Sensitive Cloud Application Logic Confidentiality

机译:Cafe:一种基于虚拟化的保护敏感云应用程序逻辑机密方法的方法

获取原文
获取原文并翻译 | 示例

摘要

Cloud application marketplaces of modern cloud infrastructures offer a new software deployment model, integrated with the cloud environment in its configuration and policies. However, similar to traditional software distribution which has been suffering from software piracy and reverse engineering, cloud marketplaces face the same challenges that can deter the success of the evolving ecosystem of cloud software. We present a novel system named CAFE for cloud infrastructures where sensitive software logic can be executed with high secrecy protected from any piracy or reverse engineering attempts in a virtual machine even when its operating system kernel is compromised. The key mechanism is the end-to-end framework for the execution of applications, which consists of the secure encryption and distribution of confidential application binary files, and the runtime techniques to load, decrypt, and protect the program logic by isolating them from tenant virtual machines based on hypervisor-level techniques. We evaluate applications in several software categories which are commonly offered in cloud marketplaces showing that strong confidential execution can be provided with only marginal changes (around 100-220 lines of code) and minimal performance overhead. The results demonstrate the effectiveness and practicality of CAFE in cloud marketplaces.
机译:现代云基础架构的云应用市场提供了一种新的软件部署模型,在其配置和策略中集成了云环境。然而,类似于传统的软件分发,这已经遭受软件盗版和逆向工程,云市场面临着相同的挑战,可以阻止云软件不断发展的生态系统的成功。我们为云基础架构提供了一个名为Cafe的新颖系统,其中敏感的软件逻辑可以通过保护从任何盗版或逆向工程尝试的高保密,即使当其操作系统内核受到泄露时,也可以在虚拟机中的逆向工程尝试。关键机制是执行应用程序的端到端框架,它由机密应用程序二进制文件的安全加密和分发,以及通过将它们与租户隔离来加载,解密和保护程序逻辑的运行时技术组成基于管理程序级技术的虚拟机。我们评估在云市场中通常提供的多个软件类别中的应用程序,显示唯一的机密执行,只能提供边际更改(大约100-220行代码)和最小性能开销。结果展示了Cafe在云市场中的有效性和实用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号