首页> 外文会议>IEEE Conference on Communications and Network Security >Enabling Trusted Data-intensive execution in cloud computing
【24h】

Enabling Trusted Data-intensive execution in cloud computing

机译:在云计算中启用可信数据密集型执行

获取原文

摘要

The security and privacy of user data has become a major concern in the cloud computing era. Cryptographic solutions based on secure computation outsourcing have been extensively studied in order to protect the security and privacy of user data. However, these solutions either suffer from forbiddingly high computation overhead or are only applicable to certain special classes of computations. In this paper, we tackle the challenge of secure computation outsourcing using an entirely different approach - the idea is to have a secure execution environment in the cloud such that user data can be processed in plain text format without compromising its confidentiality. We propose a TrUsted Data-intensive ExeCution (TUDEC) environment optimized for data applications in the cloud. TUDEC is a new system architecture, designed to provide a secure environment for arbitrary data computations in the cloud server. Using a very small trusted computing base including only firmware and hardware, TUDEC is able to provide user VM with isolation against both the legacy host and neighboring VMs. Such isolation is unique in that it provides protection against any software-based attacks. By direct interrupt delivery, interrupt rerouting and IOMMU configuration lock, TUDEC enables close to bare metal computation and I/O performance without sacrificing any security guaranteed. We built a prototype and showed the high efficiency of TUDEC. In particular, when the server is heavily loaded, the TCP bandwidth of the guest VM in TUDEC is significantly better than the current state of art secure execution environment design.
机译:用户数据的安全性和隐私已成为云计算时代的主要问题。已经广泛研究了基于安全计算外包的加密解决方案,以保护用户数据的安全性和隐私。然而,这些解决方案既遭受禁止的高计算开销,要么仅适用于某些特殊的计算类别。在本文中,我们使用完全不同的方法解决安全计算外包的挑战 - 该想法是在云中具有安全执行环境,使得可以以纯文本格式处理用户数据,而不会影响其机密性。我们提出了一个可信数据密集的执行(TUDEC)环境,针对云中的数据应用程序进行了优化。 TUDEC是一种新的系统架构,旨在为云服务器中的任意数据计算提供安全的环境。使用仅具有固件和硬件的非常小的可信计算库,Tudec能够为用户VM提供隔离,用于传统主机和相邻VM。这种隔离是独一无二的,因为它提供了针对任何基于软件的攻击的保护。通过直接中断传递,中断重传和Iommu配置锁定,TUDEC可以靠近裸机计算和I / O性能,而不会牺牲任何保证任何安全性。我们建立了一个原型并显示了Tudec的高效率。特别是,当服务器加载时,TUDEC中Guest VM的TCP带宽显着优于当前艺术安全执行环境设计的最新状态。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号