Enabling Secure VM-vTPM Migration in Private Clouds

被引:54
|
作者
Danev, Boris [1 ]
Masti, Ramya Jayaram [1 ]
Karame, Ghassan O. [1 ]
Capkun, Srdjan [1 ]
机构
[1] Swiss Fed Inst Technol, Dept Comp Sci, Zurich, Switzerland
基金
瑞士国家科学基金会;
关键词
D O I
10.1145/2076732.2076759
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The integration of Trusted Computing technologies into virtualized computing environments enables the hardware-based protection of private information and the detection of malicious software. Their use in virtual platforms, however, requires appropriate virtualization of their main component, the Trusted Platform Module (TPM) by means of virtual TPMs (vTPM). The, challenge here is that the use of TPM virtualization should not impede classical platform processes such as virtual machine (VM) migration. In this work, we consider the problem of enabling secure migration of vTPM-based virtual machines in private clouds. We detail the requirements that a secure VM-VrPM migration solution should satisfy in private virtualized environments and propose a vTPM key structure suitable for VM-vTPM. migration. We then leverage on this structure to construct a secure VM-vTPM migration protocol. We, show that our protocol provides stronger security guarantees when compared to existing solutions for VM-vTPM migration. We evaluate the feasibility of our scheme via an implementation OR the Xen hypervisor and we show that it can be directly integrated within existing hypervisors. Our Xen-based implementation can he downloaded as open-source software. Finally, we discuss how our scheme can be extended to support live-migration of vTPM-based VMs.
引用
收藏
页码:187 / 196
页数:10
相关论文
共 42 条
  • [31] PASTO: Enabling Secure and Efficient Task Offloading in TrustZone-Enabled Edge Clouds
    Li, Yuepeng
    Zeng, Deze
    Gu, Lin
    Zhu, Andong
    Chen, Quan
    Yu, Shui
    [J]. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2023, 72 (06) : 8234 - 8238
  • [32] Time-Constrained Live VM Migration in Share-Nothing IaaS-Clouds
    Tsakalozos, Konstantinos
    Verroios, Vasilis
    Roussopoulos, Mema
    Delis, Alex
    [J]. 2014 IEEE 7TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2014, : 56 - 63
  • [33] Toward a Secure VM Migration Control Mechanism Using Blockchain Technique for Cloud Computing Environment
    Uchibayashi, Toshihiro
    Apduhan, Bernady
    Suganuma, Takuo
    Hiji, Masahiro
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2018, PT III, 2018, 10962 : 177 - 186
  • [34] A secure VM live migration technique in a cloud computing environment using blowfish and blockchain technology
    Gupta, Ambika
    Namasudra, Suyel
    Kumar, Prabhat
    [J]. JOURNAL OF SUPERCOMPUTING, 2024,
  • [35] Live VM Migration Under Time-Constraints in Share-Nothing IaaS-Clouds
    Tsakalozos, Konstantinos
    Verroios, Vasilis
    Roussopoulos, Mema
    Delis, Alex
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2017, 28 (08) : 2285 - 2298
  • [36] Energy-efficient adaptive virtual machine migration mechanism for private Clouds
    Sohrabi, Sahar
    Yang, Yun
    Moser, Irene
    Aleti, Aldeida
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2017, 29 (18):
  • [37] Enabling Secure XMPP Communications in Federated IoT Clouds Through XEP 0027 and SAML/SASL SSO
    Celesti, Antonio
    Fazio, Maria
    Villari, Massimo
    [J]. SENSORS, 2017, 17 (02)
  • [38] Power and Time aware VM Migration for Multi-tier Applications over Geo-distributed Clouds
    Addya, Sourav Kanti
    Satpathy, Anurag
    Ghosh, Bishakh Chandra
    Chakraborty, Sandip
    Ghosh, Soumya K.
    [J]. 2019 IEEE 12TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (IEEE CLOUD 2019), 2019, : 339 - 343
  • [39] Models for availability and power consumption evaluation of a private cloud with VMM rejuvenation enabled by VM Live Migration
    Matheus Torquato
    I M Umesh
    Paulo Maciel
    [J]. The Journal of Supercomputing, 2018, 74 : 4817 - 4841
  • [40] Models for availability and power consumption evaluation of a private cloud with VMM rejuvenation enabled by VM Live Migration
    Torquato, Matheus
    Umesh, I. M.
    Maciel, Paulo
    [J]. JOURNAL OF SUPERCOMPUTING, 2018, 74 (09): : 4817 - 4841