首页> 外文会议>IEEE Symposium on Reliable Distributed Systems >Satem: Trusted Service Code Execution across Transactions
【24h】

Satem: Trusted Service Code Execution across Transactions

机译:SATEM:跨交易的可信服务代码执行

获取原文

摘要

Web services and service oriented architectures are becoming the de facto standard for Internet computing. A main problem faced by users of such services is how to ensure that the service code is trusted. While methods that guarantee trusted service code execution before starting a client-service transaction exist, there is no solution for extending this assurance to the entire lifetime of the transaction. This paper presents Satem, a Service-aware trusted execution monitor that guarantees the trustworthiness of the service code across a whole transaction. The Satem architecture consists of an execution monitor residing in the operating system kernel on the service provider platform, a trust evaluator on the client platform, and a service commitment protocol. During this protocol, executed before every transaction, the client requests and verifies against its local policy a commitment from the service platform that promises trusted code execution. Subsequently, the monitor enforces this commitment for the duration of the transaction. To initialize the trust on the monitor, we use the Trusted Platform Module specified by the Trusted Computing Group. We implemented Satem under the Linux 2.6.12 kernel and tested it for a web service and DNS. The experimental results demonstrate that Satem does not incur significant overhead to the protected services and does not impact the unprotected services.
机译:Web服务和面向服务的架构正在成为互联网计算的事实标准。这些服务的用户面临的主要问题是如何确保服务代码是值得信任的。虽然保证在启动客户服务事务之前保证受信任服务代码执行的方法,但是没有解决事务的整个生命周期的解决方案。本文介绍SATEM,一个服务感知值得信赖的执行监视器,可确保整个事务的服务代码的可信度。 SATEM架构包括驻留在服务提供商平台上的操作系统内核中的执行监视器,客户端平台上的信任评估程序以及服务承诺协议。在此协议期间,在每次交易之前执行,客户端请求并验证其本地策略来自从事值得信赖的代码执行的服务平台的承诺。随后,监视器在交易期间强制执行此承诺。要初始化监视器上的信任,我们使用可信计算组指定的可信平台模块。我们在Linux 2.6.12内核下实现了SATEM,并为Web服务和DNS测试了它。实验结果表明,SATEM并不导致受保护服务的显着开销,并且不会影响未受保护的服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号