首页 | 官方网站   微博 | 高级检索  
     

基于分片的云虚拟机安全保护技术
引用本文:樊文生,华铭轩.基于分片的云虚拟机安全保护技术[J].通信技术,2015,48(6):734-739.
作者姓名:樊文生  华铭轩
作者单位:1.海司信息化部 北京100041;2. 中国电子科技集团公司第三十研究所,四川 成都 610041
摘    要:在典型的IaaS云中,用户使用云服务需要通过虚拟机实现。最近有研究表明,在大多数常用的加密协议(如SSL/TLS等)中,至关重要的加密密钥,可能被攻击者通过跨虚拟机的旁路攻击截获。针对这种攻击方式,提出了一种云虚拟机密钥保护系统,通过将加密密钥随机分割为多个分片,并将每个分片存储于不同的虚拟机中,能有效保护云中的加密密钥,抵御各类跨虚拟机的旁路攻击。此外,云虚拟机密钥保护系统会周期性地对加密密钥进行重新分割,即便攻击者能够截获局部的加密密钥,也无法进行还原。将云虚拟机密钥保护系统作为一种对应用软件透明的扩展库,运行在亚马逊EC2云的web服务器,取得了较好的成果。

关 键 词:虚拟机  密钥分割    
收稿时间:2015-01-09

Security Protection Technology based on Piecewise Cloud Virtual Machine
FAN Wen-sheng,HUA Ming-xuan.Security Protection Technology based on Piecewise Cloud Virtual Machine[J].Communications Technology,2015,48(6):734-739.
Authors:FAN Wen-sheng  HUA Ming-xuan
Affiliation:1. Information Department of Navy Command, Beijing 100041, China;2. No.30 Institute of CETC, Chengdu Sichuan 610041, China
Abstract:In a typical IaaS (Infrastructure-as-a-Service) cloud, the user would acquire cloud services via executing VM (Virtual Machines). However, recent studies indicate that the crypto keys, as the most crucial component in the usually-used cryptographic protocols (e.g., SSL/TLS), may be extracted by using cross-VM side-channel attacks. To defeat such a threat, this paper proposes a new system for protecting the crypto key of cloud VM. By simply partitioning the crypto key into multiple random shares and storing each share in different VMs, the crypto key in the cloud could be effectively protected, and the cross-VM side-channel attack be resisted. In addition, this crypto-key protection system of cloud VM may periodically re-partition the crypto key, thus the attacker could not re-construct the key, even acquires partial key. This key protection system of cloud VM is taken as a library extension transparent to the application software and applied to the web server of Amazon EC2 cloud. Experiment indicates an excellent result.
Keywords:VM  key partitioning  cloud  
点击此处可从《通信技术》浏览原始摘要信息
点击此处可从《通信技术》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号