Secure Partitioning of Cloud Applications, with Cost Look-Ahead

被引:0
|
作者
Bocci, Alessandro [1 ]
Forti, Stefano [1 ]
Guanciale, Roberto [2 ]
Ferrari, Gian-Luigi [1 ]
Brogi, Antonio [1 ]
机构
[1] Univ Pisa, Dept Comp Sci, I-56127 Pisa, Italy
[2] KTH Royal Inst Technol, Div Theoret Comp Sci, S-11428 Stockholm, Sweden
关键词
data confidentiality; trusted execution environments; separation kernels; information-flow security; deployment costs; declarative programming; ISSUES;
D O I
10.3390/fi15070224
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The security of Cloud applications is a major concern for application developers and operators. Protecting users' data confidentiality requires methods to avoid leakage from vulnerable software and unreliable Cloud providers. Recently, trusted execution environments (TEEs) emerged in Cloud settings to isolate applications from the privileged access of Cloud providers. Such hardware-based technologies exploit separation kernels, which aim at safely isolating the software components of applications. In this article, we propose a methodology to determine safe partitionings of Cloud applications to be deployed on TEEs. Through a probabilistic cost model, we enable application operators to select the best trade-off partitioning in terms of future re-partitioning costs and the number of domains. To the best of our knowledge, no previous proposal exists addressing such a problem. We exploit information-flow security techniques to protect the data confidentiality of applications by relying on declarative methods to model applications and their data flow. The proposed solution is assessed by executing a proof-of-concept implementation that shows the relationship among the future partitioning costs, number of domains and execution times.
引用
收藏
页数:38
相关论文
共 50 条
  • [1] A Look-Ahead Approach to Secure Multiparty Protocols
    Nergiz, Mehmet Ercan
    Cicek, Abdullah Ercument
    Pedersen, Thomas B.
    Saygin, Yucel
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2012, 24 (07) : 1170 - 1185
  • [2] Look-Ahead
    Mannan, Joya
    Cutting Tool Engineering, 2023, 75 (01):
  • [3] LOOK-AHEAD ON PUSHDOWNS
    ENGELFRIET, J
    VOGLER, H
    INFORMATION AND COMPUTATION, 1987, 73 (03) : 245 - 279
  • [4] Adaptive inter CU partitioning based on a look-ahead stage for HEVC
    Cebrian-Marquez, Gabriel
    Luis Martinez, Jose
    Cuenca, Pedro
    SIGNAL PROCESSING-IMAGE COMMUNICATION, 2019, 76 : 97 - 108
  • [5] Global Routing Congestion Reduction with Cost Allocation Look-ahead
    Nunes, Leandro
    Reis, Ricardo
    2013 26TH SYMPOSIUM ON INTEGRATED CIRCUITS AND SYSTEMS DESIGN (SBCCI 2013), 2013,
  • [6] Secure Partitioning of Composite Cloud Applications
    Bocci, Alessandro
    Guanciale, Roberto
    Forti, Stefano
    Ferrari, Gian-Luigi
    Brogi, Antonio
    SERVICE-ORIENTED AND CLOUD COMPUTING, 2022, 13226 : 47 - 64
  • [7] Cloud Aided Implementation of Energy Optimal Look-ahead Speed Control
    Soumelidis, Alexandros
    Gaspar, Peter
    Kisari, Adam
    Bakos, Adam
    Nemeth, Balazs
    Mihaly, Andras
    Hankovszki, Zoltan
    IFAC PAPERSONLINE, 2018, 51 (09): : 361 - 366
  • [8] CONSTRAINED LOOK-AHEAD MANUFACTURING
    ROSENWEIN, MB
    STONE, RE
    WAHLS, ET
    INTERNATIONAL JOURNAL OF PRODUCTION RESEARCH, 1991, 29 (09) : 1845 - 1851
  • [9] Look-ahead memory consistency model
    Wu, CC
    Pean, DL
    Chen, C
    1998 INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, PROCEEDINGS, 1998, : 504 - 510
  • [10] A 50-YEAR LOOK-AHEAD
    COATES, JF
    TECHNOLOGICAL FORECASTING AND SOCIAL CHANGE, 1995, 48 (01) : 103 - 105