首页> 外文期刊>Operating systems review >Terra: A Virtual Machine-Based Platform for Trusted Computing
【24h】

Terra: A Virtual Machine-Based Platform for Trusted Computing

机译:Terra:基于虚拟机的可信计算平台

获取原文
获取原文并翻译 | 示例
           

摘要

We present a flexible architecture for trusted computing, called Terra, that allows applications With a wide range of security requirements to run simultaneously on commodity hardware. Applications on Terra enjoy the semantics of running on a separate, dedicated, tamper-resistant hardware platform, while retaining the ability to run side-by-side with normal applications on a general-purpose computing platform. Terra achieves this synthesis by use of a trusted virtual machine monitor (TVMM) that partitions a tamper-resistant hardware platform into multiple, isolated virtual machines (VM), providing the appearance of multiple boxes on a single, general-purpose platform. To each VM, the TVMM provides the semantics of either an "open box," i.e. a general-purpose hardware platform like today's PCs and workstations, or a "closed box," an opaque special-purpose platform that protects the privacy and integrity of its contents like today's game consoles and cellular phones. The software stack in each VM can be tailored from the hardware interface up to meet the security requirements of its application(s). The hardware and TVMM can act as a trusted party to allow closed-box VMs to cryptographically identify the software they run, i.e. what is in the box, to remote parties. We explore the strengths and limitations of this architecture by describing our prototype implementation and several applications that we developed for it.
机译:我们提供了一种称为Terra的灵活的可信计算体系结构,该体系结构允许具有广泛安全要求的应用程序同时在商品硬件上运行。 Terra上的应用程序享有在单独的专用防篡改硬件平台上运行的语义,同时保留了与通用计算平台上的常规应用程序并排运行的能力。 Terra通过使用受信任的虚拟机监视器(TVMM)来实现此综合,该监视器将防篡改的硬件平台划分为多个隔离的虚拟机(VM),从而在单个通用平台上提供多个框的外观。对于每个VM,TVMM提供的语义既可以是“开放式”(即像今天的PC和工作站之类的通用硬件平台),也可以是“封闭式”(一种不透明的专用平台),它可以保护虚拟机的隐私和完整性。其内容类似于当今的游戏机和手机。每个VM中的软件堆栈都可以从硬件接口进行定制,以满足其应用程序的安全性要求。硬件和TVMM可以充当受信方,以允许封闭式VM加密地标识它们运行的​​软件(即,包装盒中的内容)给远程方。通过描述我们的原型实现以及为此开发的几个应用程序,我们探索了该体系结构的优势和局限性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号