Enabling Secure VM-vTPM Migration in Private Clouds

被引:54
|
作者
Danev, Boris [1 ]
Masti, Ramya Jayaram [1 ]
Karame, Ghassan O. [1 ]
Capkun, Srdjan [1 ]
机构
[1] Swiss Fed Inst Technol, Dept Comp Sci, Zurich, Switzerland
基金
瑞士国家科学基金会;
关键词
D O I
10.1145/2076732.2076759
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The integration of Trusted Computing technologies into virtualized computing environments enables the hardware-based protection of private information and the detection of malicious software. Their use in virtual platforms, however, requires appropriate virtualization of their main component, the Trusted Platform Module (TPM) by means of virtual TPMs (vTPM). The, challenge here is that the use of TPM virtualization should not impede classical platform processes such as virtual machine (VM) migration. In this work, we consider the problem of enabling secure migration of vTPM-based virtual machines in private clouds. We detail the requirements that a secure VM-VrPM migration solution should satisfy in private virtualized environments and propose a vTPM key structure suitable for VM-vTPM. migration. We then leverage on this structure to construct a secure VM-vTPM migration protocol. We, show that our protocol provides stronger security guarantees when compared to existing solutions for VM-vTPM migration. We evaluate the feasibility of our scheme via an implementation OR the Xen hypervisor and we show that it can be directly integrated within existing hypervisors. Our Xen-based implementation can he downloaded as open-source software. Finally, we discuss how our scheme can be extended to support live-migration of vTPM-based VMs.
引用
收藏
页码:187 / 196
页数:10
相关论文
共 42 条
  • [21] Memory-virtualizing and -devirtualizing VM Migration with Private Virtual Memory
    Muraoka, Yuji
    Kourai, Kenichi
    [J]. 2023 IEEE 47TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE, COMPSAC, 2023, : 91 - 96
  • [22] Towards cost-aware VM migration to maximize the profit in federated clouds
    Najm, Moustafa
    Tamarapalli, Venkatesh
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 134 : 53 - 65
  • [23] Considering VM migration between IaaS Clouds and mobile Clients: Challenges and Potentials
    Katzmarski, Bernhard
    Herrholz, Andreas
    Paolino, Michele
    Rigo, Alvise
    Nebel, Wolfgang
    [J]. 2014 IEEE 3RD INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (CLOUDNET), 2014, : 327 - 332
  • [24] Hiding Media Data via Shaders: Enabling Private Sharing in the Clouds
    Liu, Kaikai
    Li, Min
    Li, Xiaolin
    [J]. 2015 IEEE 8TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, 2015, : 122 - 129
  • [25] VM Migration for Secure Out-of-band Remote Management with Nested Virtualization
    Unoki, Tomoya
    Kourai, Kenichi
    [J]. 2020 IEEE 13TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD 2020), 2020, : 517 - 521
  • [26] Emerging VM Threat Prediction and Dynamic Workload Estimation for Secure Resource Management in Industrial Clouds
    Saxena, Deepika
    Gupta, Rishabh
    Singh, Ashutosh Kumar
    Vasilakos, Athanasios V.
    [J]. IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2023, : 1 - 15
  • [27] Secure Offloading of Legacy IDSes Using Remote VM Introspection in Semi-trusted Clouds
    Kourai, Kenichi
    Juda, Kazuki
    [J]. PROCEEDINGS OF 2016 IEEE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2016, : 43 - 50
  • [28] Adaptive Live VM Migration in Share-Nothing IaaS-Clouds with LiveFS
    Katsipoulakis, Nick R.
    Tsakalozos, Konstantinos
    Delis, Alex
    [J]. 2013 IEEE FIFTH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), VOL 2, 2013, : 293 - 298
  • [29] Secure VM Migration in Cloud: Multi-Criteria Perspective with Improved Optimization Model
    Verma, Garima
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2022, 124 (01) : 75 - 102
  • [30] Secure VM Migration in Cloud: Multi-Criteria Perspective with Improved Optimization Model
    Garima Verma
    [J]. Wireless Personal Communications, 2022, 124 : 75 - 102