Tenants attested Trusted Cloud Service

被引:0
|
作者
Ren, Jiangchun [1 ]
Liu, Ling [2 ]
Zhang, Da [1 ]
Zhang, Qi [2 ]
Ba, Haihe [1 ]
机构
[1] Natl Univ Def Technol, Sch Comp, Changsha, Hunan, Peoples R China
[2] Georgia Inst Technol, Sch Comp Sci, Coll Comp, Atlanta, GA 30332 USA
基金
美国国家科学基金会; 国家高技术研究发展计划(863计划);
关键词
cloud; trust; remote attestation; VM introspection;
D O I
10.1109/CLOUD.2016.83
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing has successfully enabled large scale computing to be offered as pay-as-you-go services to many enterprise and individual tenants. However, the trust on public cloud services has been a sensitive issue for both cloud tenants and cloud service providers (CSPs). Tenants tend to worry about losing the total control over their codes and data hosted on remote servers. Public cloud providers often fear that the applications uploaded by their tenants may carry vicious codes, which may cause serious violations of security and privacy on their cloud platforms. This trust issue has slowed down the wide deployment of public clouds and hindered the promises of cloud computing for both CSPs and Cloud consumers. In this paper, we present Ta-TCS, a novel system framework for two-phase tenants attested trust validation and trust management over their remote VMs and cloud service executions. At the CSP end, we build a Minimal Trusted Environment (MTE) in VMM and an Integrity Verification & Report Service (IVRS) hosted in the control domain Dom0. At the tenant end, we deploy an Integrity Configuration and Attestation Service (ICAS) in new framework. With Ta-TCS, tenants can configure and attest the integrity of their services, and Cloud providers can verify codes running on a guest VM by introspection. Tenants can also check whether the basic platform of Dom0 is trusted or not. This two phase trust establishment increases the level of mutual trust between tenants and its CSP. We implement the first prototype system of Ta-TCS on Xen platform, and most of our implementation mechanisms can be deployed to some open-source virtualization platforms such as KVM. Our evaluation results show that Ta-TCS is effective with negligible performance overhead.
引用
收藏
页码:600 / 607
页数:8
相关论文
共 50 条
  • [1] Trusted cloud service
    Ding, Yan
    Wang, Huai-Min
    Shi, Pei-Chang
    Wu, Qing-Bo
    Dai, Hua-Dong
    Fu, Hong-Yi
    Jisuanji Xuebao/Chinese Journal of Computers, 2015, 38 (01): : 133 - 149
  • [2] Security as a Service for Public Cloud Tenants(SaaS)
    Hawedi, Mohamed
    Talhi, Chamseddine
    Boucheneb, Hanifa
    9TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT 2018) / THE 8TH INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY (SEIT-2018) / AFFILIATED WORKSHOPS, 2018, 130 : 1025 - 1030
  • [3] Trusted Cloud Service Certification and Evaluation
    Li, Wei
    Cao, Feng
    TRUSTWORTHY COMPUTING AND SERVICES (ISCTCS 2014), 2015, 520 : 175 - 182
  • [4] Research on the measurement and evaluation of trusted cloud service
    Ma, Zifei
    Jiang, Rong
    Yang, Ming
    Li, Tong
    Zhang, Qiujin
    SOFT COMPUTING, 2018, 22 (04) : 1247 - 1262
  • [5] Facilitating plausible deniability for cloud providers regarding tenants' activities using trusted execution
    O'Keeffe, Dan
    Vranaki, Asma
    Pasquier, Thomas
    Eyers, David
    2020 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E 2020), 2020, : 59 - 65
  • [6] Research on the measurement and evaluation of trusted cloud service
    Zifei Ma
    Rong Jiang
    Ming Yang
    Tong Li
    Qiujin Zhang
    Soft Computing, 2018, 22 : 1247 - 1262
  • [7] Toward security as a service: A trusted cloud service architecture with policy customization
    Huang, Chenlin
    Chen, Wei
    Yuan, Lu
    Ding, Yan
    Jian, Songlei
    Tan, Yusong
    Chen, Hua
    Chen, Dan
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2021, 149 : 76 - 88
  • [8] Service Mining for Trusted Service Composition in Cross-Cloud Environment
    Wu, Taotao
    Dou, Wanchun
    Hu, Chunhua
    Chen, Jinjun
    IEEE SYSTEMS JOURNAL, 2017, 11 (01): : 283 - 294
  • [10] Trusted Block as a Service: Towards Sensitive Applications on the Cloud
    Hao, Jianan
    Cai, Wentong
    TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 73 - 82