Enabling Secure VM-vTPM Migration in Private Clouds

被引:54
|
作者
Danev, Boris [1 ]
Masti, Ramya Jayaram [1 ]
Karame, Ghassan O. [1 ]
Capkun, Srdjan [1 ]
机构
[1] Swiss Fed Inst Technol, Dept Comp Sci, Zurich, Switzerland
基金
瑞士国家科学基金会;
关键词
D O I
10.1145/2076732.2076759
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The integration of Trusted Computing technologies into virtualized computing environments enables the hardware-based protection of private information and the detection of malicious software. Their use in virtual platforms, however, requires appropriate virtualization of their main component, the Trusted Platform Module (TPM) by means of virtual TPMs (vTPM). The, challenge here is that the use of TPM virtualization should not impede classical platform processes such as virtual machine (VM) migration. In this work, we consider the problem of enabling secure migration of vTPM-based virtual machines in private clouds. We detail the requirements that a secure VM-VrPM migration solution should satisfy in private virtualized environments and propose a vTPM key structure suitable for VM-vTPM. migration. We then leverage on this structure to construct a secure VM-vTPM migration protocol. We, show that our protocol provides stronger security guarantees when compared to existing solutions for VM-vTPM migration. We evaluate the feasibility of our scheme via an implementation OR the Xen hypervisor and we show that it can be directly integrated within existing hypervisors. Our Xen-based implementation can he downloaded as open-source software. Finally, we discuss how our scheme can be extended to support live-migration of vTPM-based VMs.
引用
收藏
页码:187 / 196
页数:10
相关论文
共 42 条
  • [1] Secure and Reliable VM-vTPM Migration in Private Cloud
    Liang, Xinlong
    Jiang, Rui
    Kong, Huafeng
    [J]. 2013 2ND INTERNATIONAL SYMPOSIUM ON INSTRUMENTATION AND MEASUREMENT, SENSOR NETWORK AND AUTOMATION (IMSNA), 2013, : 510 - 514
  • [2] A Trusted VM-vTPM Live Migration Protocol in Clouds
    Zhou, Hong
    Wang, Juan
    Zhang, HuanGuo
    [J]. PROCEEDINGS OF THE 1ST INTERNATIONAL WORKSHOP ON CLOUD COMPUTING AND INFORMATION SECURITY (CCIS 2013), 2013, 52 : 299 - 302
  • [3] Enhanced Secure Mechanism for VM Migration in Clouds
    Janjua, Kanwal
    Ali, Waris
    [J]. 2018 INTERNATIONAL CONFERENCE ON FRONTIERS OF INFORMATION TECHNOLOGY (FIT 2018), 2018, : 135 - 140
  • [4] 一种安全VM-vTPM迁移协议的设计与实现
    于颖超
    刘了
    陈左宁
    [J]. 电子技术应用, 2012, 38 (04) : 130 - 133
  • [5] An Improved vTPM-VM Live Migration Protocol
    FAN Peiru
    ZHAO Bo
    SHI Yuan
    CHEN Zhihong
    NI Mingtao
    [J]. Wuhan University Journal of Natural Sciences, 2015, 20 (06) : 512 - 520
  • [6] Secure VM Migration in Tactical Cloudlets
    Lewis, Grace A.
    Echeverria, Sebastian
    Klinedinst, Dan
    Williams, Keegan
    [J]. MILCOM 2017 - 2017 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2017, : 388 - 393
  • [7] Secure VM Backup and Vulnerability Removal in Infrastructure Clouds
    Kaur, Prabhjeet
    Somani, Gaurav
    [J]. 2014 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2014, : 1217 - 1226
  • [8] Private Clouds: Secure Managed Services
    Orakwue, Enuma
    [J]. INFORMATION SECURITY JOURNAL, 2010, 19 (06): : 295 - 298
  • [9] Enabling Secure and Effective Deduplication in Multi Clouds
    Sreeja, B. P.
    Rajeshkumar, G.
    Kiruthika, Alagu B.
    Prabha, Sasi N.
    Varshini, R.
    Afzal, J.
    [J]. 2024 7TH INTERNATIONAL CONFERENCE ON DEVICES, CIRCUITS AND SYSTEMS, ICDCS 2024, 2024, : 55 - 59
  • [10] Enabling Scalable Cloud Infrastructure using Autonomous VM Migration
    Choi, Hyung Won
    Sohn, Andrew
    Kwak, Hukeun
    Chung, Kyusik
    [J]. 2012 IEEE 14TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS & 2012 IEEE 9TH INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (HPCC-ICESS), 2012, : 1066 - 1073