DocumentCode :
3063575
Title :
Obtaining the Integrity of Your Virtual Machine in the Cloud
Author :
Yu, Aimin ; Qin, Yu ; Wang, Dan
Author_Institution :
State Key Lab. of Inf. Security, Inst. of Software, Beijing, China
fYear :
2011
fDate :
Nov. 29 2011-Dec. 1 2011
Firstpage :
213
Lastpage :
222
Abstract :
Infrastructure-as-a-service(IaaS) cloud provides the user the ability to use the computing resource of the cloud provider through renting a virtual machine(VM). At the same time it becomes an essential requirement for the user to verify the integrity of his VM. In this paper we designed and implemented TCG(trusted computing group)-based remote attestation for the Xen VM under the assumption that the trusted platform module(TPM) and hyper visor are secure and the privileged domain0 may be malicious. Firstly we realized load-time integrity measurement of the guest OS(operating system) kernel in the hyper visor directly and built the trust chain that is independent of the domain0. Secondly we realized the virtualized AIK(attestation identity key) and PCR(platform configuration register) that simulated the security functions of TPM AIK and PCR and supported VM migration, save and restore operations. Finally through the prototype implementation it is shown that the code complexity and the performance overhead are acceptable for the real system.
Keywords :
cloud computing; operating system kernels; security of data; trusted computing; virtual machines; PCR; TCG based remote attestation; Xen VM; attestation identity key; code complexity; guest OS kernel; infrastructure-as-a-service cloud; load-time integrity measurement; platform configuration register; trusted computing group; trusted platform module; virtual machine; virtualized AIK; Current measurement; Hardware; Kernel; Monitoring; Security; Virtual machine monitors; Virtual machining; IaaS cloud; VM integrity; virtualized TPM;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud Computing Technology and Science (CloudCom), 2011 IEEE Third International Conference on
Conference_Location :
Athens
Print_ISBN :
978-1-4673-0090-2
Type :
conf
DOI :
10.1109/CloudCom.2011.37
Filename :
6133146
Link To Document :
بازگشت