首页 | 官方网站   微博 | 高级检索  
     

基于VMI的虚拟机远程证明方案
作者姓名:王伟  陈兴蜀  兰晓  金鑫
作者单位:1. 四川大学计算机学院,四川 成都 610065;2. 四川大学网络空间安全研究院,四川 成都 610065;3. 四川大学网络空间安全学院,四川 成都 610065
基金项目:国家自然科学基金资助项目(61802270);国家“双创”示范基地之变革性技术国际研发转化平台基金资助项目(C700011)
摘    要:可信计算组织(TCG,trusted computing group)提出的虚拟机远程证明方案可以为云计算平台提供虚拟机完整性验证服务,而直接使用 TCG 提出的方案性能较低,并且会受到布谷鸟攻击的威胁。利用虚拟机自省技术(VMI,virtual machine introspection)设计了新的虚拟机远程证明方案。通过在虚拟机监视器(VMM,virtual machine monitor)中获取虚拟机远程验证证据的方法消除在虚拟机内执行布谷鸟攻击的路径,利用物理可信平台模块(TPM,trusted platform module)保证虚拟机远程验证证据的完整性,减少了身份证明密钥(AIK,attestation identity key)证书的产生数量,降低了私有证书颁发机构的负载。实验表明,方案可以有效验证虚拟机的完整性状态,在虚拟机数量较多的情况下,性能优于TCG提出的虚拟机远程证明方案。

关 键 词:虚拟机远程证明  布谷鸟攻击  虚拟机自省技术  可信平台模块  身份证明密钥  

VMI-based virtual machine remote attestation scheme
Authors:Wei WANG  Xingshu CHEN  Xiao LAN  Xin JIN
Affiliation:1. College of Computer Science,Sichuan University,Chengdu 610065,China;2. Cybersecurity Research Institute,Sichuan University,Chengdu 610065,China;3. College of Cybersecurity,Sichuan University,Chengdu 610065,China
Abstract:The virtual machine attestation scheme proposed by trusted computing group (TCG) can provide attestation service of virtual machine for cloud computing.However,the service using the scheme proposed by the TCG directly would be threatened by the cuckoo attack and its performance would be lower.Therefore,a new virtual machine remote attestation scheme based on virtual machine introspection (VMI) was proposed.Firstly,it eliminated the path to perform cuckoo attacks in virtual machines via obtaining virtual machines′ remote attestation evidence in virtual machine monitor (VMM).Secondly,it used physical trusted platform module (TPM) to ensure the integrity of virtual machines’ remote attestation evidence and reduced the number of attestation identity key (AIK) certificates required during remote attestation to balance the load of private CA.Experiments show that the proposed scheme can verify the status of virtual machines correctly and increase the performance of bulk virtual machines’ remote attestation significantly.
Keywords:virtual machine remote attestation  the cuckoo attack  virtual machine introspection  TPM  attestation identity key  
点击此处可从《》浏览原始摘要信息
点击此处可从《》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号