首页> 外文期刊>Services Computing, IEEE Transactions on >A Trusted IaaS Environment with Hardware Security Module
【24h】

A Trusted IaaS Environment with Hardware Security Module

机译:具有硬件安全模块的可信IaaS环境

获取原文
获取原文并翻译 | 示例
           

摘要

With the proliferation of cloud computing, security concerns about confidentiality violations of user data by the privileged domain and system administrators have been growing. This paper proposes secure cloud architecture with a hardware security module, which isolates cloud user data from potentially malicious privileged domains or cloud administrators. Within a securely isolated execution environment, the hardware security module provides essential security functionality with only restricted interfaces exposed to vulnerable management systems or cloud administrators. Such restriction prevents cloud administrators from affecting the security of guest VMs. The proposed architecture not only defends against wide attack vectors but also achieves a small TCB. This paper discusses our hardware and software implementation of the proposed cloud architecture, analyzes its security, and presents its performance results.
机译:随着云计算的普及,特权域和系统管理员对用户数据的机密性违反的安全性关注日益增长。本文提出了带有硬件安全模块的安全云体系结构,该模块将云用户数据与潜在的恶意特权域或云管理员隔离开来。在安全隔离的执行环境中,硬件安全模块提供了基本的安全功能,只有受限制的接口才暴露给易受攻击的管理系统或云管理员。这样的限制可以防止云管理员影响来宾VM的安全性。所提出的体系结构不仅防御广泛的攻击媒介,而且实现了较小的TCB。本文讨论了我们对所提出的云体系结构的硬件和软件实现,分析了其安全性,并提出了其性能结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号