首页> 外文期刊>Frontiers of computer science in China >A secure and rapid response architecture for virtual machine migration from an untrusted hypervisor to a trusted one
【24h】

A secure and rapid response architecture for virtual machine migration from an untrusted hypervisor to a trusted one

机译:一种安全,快速的响应架构,用于虚拟机从不受信任的虚拟机管理程序迁移到受信任的虚拟机管理程序

获取原文
获取原文并翻译 | 示例
           

摘要

Two key issues exist during virtual machine (VM) migration in cloud computing. One is when to start migration, and the other is how to determine a reliable target, both of which totally depend on whether the source hypervisor is trusted or not in previous studies. However, once the source hypervisor is not trusted any more, migration will be facing unprecedented challenges. To address the problems, we propose a secure architecture SMIG (secure migration), which defines a new concept of Region Critical TCB and leverages an innovative adjacent integrity measurement (AIM) mechanism. AIM dynamically monitors the integrity of its adjacent hypervisor, and passes the results to the Region Critical TCB, which then determines whether to start migration and where to migrate according to a table named integrity validation table. We have implemented a prototype of SMIG based on the Xen hypervisor. Experimental evaluation result shows that SMIG could detect a malicious hypervisor and start migration to a trusted one rapidly, only incurring a moderate overhead for computing intensive and I/O intensive tasks, and small for others.
机译:在云计算中的虚拟机(VM)迁移期间存在两个关键问题。一个是何时开始迁移,另一个是如何确定可靠的目标,这两者都完全取决于源虚拟机管理程序在以前的研究中是否受信任。但是,一旦不再信任源管理程序,迁移将面临前所未有的挑战。为了解决这些问题,我们提出了一种安全体系结构SMIG(安全迁移),该体系结构定义了区域关键TCB的新概念,并利用了创新的相邻完整性度量(AIM)机制。 AIM动态监视其相邻虚拟机管理程序的完整性,并将结果传递给Region Critical TCB,然后该区域TCB根据名为完整性验证表的表确定是否开始迁移以及在何处迁移。我们已经基于Xen管理程序实现了SMIG的原型。实验评估结果表明,SMIG可以检测到恶意的虚拟机管理程序,并迅速开始迁移到受信任的虚拟机管理程序,仅对计算密集型和I / O密集型任务产生适度的开销,而对其他任务则较小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号