Deployment of virtual machines in Lock-Keeper

被引:0
|
作者
Cheng, Feng [1 ]
Meinel, Christoph [1 ]
机构
[1] Univ Potsdam, Hasso Plattner Inst, Postfach 900460, D-14440 Potsdam, Germany
来源
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As a remarkable realization of the simple idea "Physical Separation", the Lock-Keeper technology has been proven to be a practical approach to provide high-level security for a sensitive internal network by completely separating it with the less secure external network. The data exchange between the two separated networks is accomplished by the Lock-Keeper Secure Data Exchange software which is occupied by three PC-based Lock-Keeper components: INNER, OUTER and GATE. The SDE's application modules on INNER and OUTER provide specific network services to the external world through normal network connections and organize the network traffic into Lock-Keeper-mode units which can be transferred through the Lock-Keeper by its SDE's basic data exchange modules on INNER, OUTER and GATE. There is an extra data scanning module located on GATE to check the passing data contents. In this paper, a new implementation of the SDE software will be proposed based on the Virtual Machine technology. Application modules on INNER and OUTER are respectively replaced by some Virtual Machines. According to different requirements of corresponding applications, different configurations and resource assignments can be employed by these Virtual Machines. Such special-purpose Virtual Machines and their underlying host can be isolated from one another by the natural property of the Virtual Machine technology so that both the host and each single application can be easily restored in the case of destruction. In addition, a content scanning VM will be built on GATE to support offline scanning, configuration, updating and other useful extension.
引用
收藏
页码:147 / +
页数:3
相关论文
共 50 条
  • [1] THE 'LOCK-KEEPER OF JOSSELIN'
    HAMPDEN, H
    [J]. STAND MAGAZINE, 1993, 35 (01): : 35 - 35
  • [2] Strong authentication over Lock-Keeper
    Cheng, Feng
    Meinel, Christoph
    [J]. SOFSEM 2008: THEORY AND PRACTICE OF COMPUTER SCIENCE, 2008, 4910 : 572 - 584
  • [3] Implementing IDS Management on Lock-Keeper
    Cheng, Feng
    Roschke, Sebastian
    Meinel, Christoph
    [J]. INFORMATION SECURITY PRACTICE AND EXPERIENCE, PROCEEDINGS: 5TH INTERNATIONAL CONFERENCE, ISPEC 2009, 2009, 5451 : 360 - 371
  • [4] Design of Lock-Keeper Federated Authentication Gateway
    Cheng, Feng
    Meinel, Christoph
    [J]. 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III, PROCEEDINGS,, 2009, : 1041 - 1046
  • [5] A Specialized Tool for Simulating Lock-Keeper Data Transfer
    Cheng, Feng
    Thanh-Dien Tran
    Roschke, Sebastian
    Meinel, Christoph
    [J]. 2010 24TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2010, : 182 - 189
  • [6] A secure web services providing framework based on lock-keeper
    Cheng, Feng
    Menzel, Michael
    Meinel, Christoph
    [J]. MANAGING NEXT GENERATION NETWORKS AND SERVICES, PROCEEDINGS, 2007, 4773 : 375 - +
  • [7] A Theoretical Model of Lock-Keeper Data Exchange and its Practical Verification
    Roschke, Sebastian
    Cheng, Feng
    Tran, Thanh-Dien
    Meinel, Christoph
    [J]. 2009 6TH IFIP INTERNATIONAL CONFERENCE ON NETWORK AND PARALLEL COMPUTING, 2009, : 190 - 196
  • [8] A complete solution for highly secure data exchange: Lock-keeper and its advancements
    Cheng, F
    Meinel, C
    Engel, T
    Mullenheim, G
    Bern, J
    Thewes, D
    [J]. PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, PDCAT'2003, PROCEEDINGS, 2003, : 201 - 205
  • [9] Scaling the Deployment of Virtual Machines in UnaCloud
    Chavarriaga, Jaime
    Forero-Gonzalez, Cesar
    Padilla-Agudelo, Jesse
    Munoz, Andres
    Caliz-Ospino, Rodolfo
    Castro, Harold
    [J]. HIGH PERFORMANCE COMPUTING, 2018, 796 : 399 - 413
  • [10] Elastic Provisioning of Virtual Machines for Container Deployment
    Nardelli, Matteo
    Hochreiner, Christoph
    Schulte, Stefan
    [J]. ICPE'17: COMPANION OF THE 2017 ACM/SPEC INTERNATIONAL CONFERENCE ON PERFORMANCE ENGINEERING, 2017, : 5 - 10