Tenants attested Trusted Cloud Service

被引:0
|
作者
Ren, Jiangchun [1 ]
Liu, Ling [2 ]
Zhang, Da [1 ]
Zhang, Qi [2 ]
Ba, Haihe [1 ]
机构
[1] Natl Univ Def Technol, Sch Comp, Changsha, Hunan, Peoples R China
[2] Georgia Inst Technol, Sch Comp Sci, Coll Comp, Atlanta, GA 30332 USA
基金
美国国家科学基金会; 国家高技术研究发展计划(863计划);
关键词
cloud; trust; remote attestation; VM introspection;
D O I
10.1109/CLOUD.2016.83
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing has successfully enabled large scale computing to be offered as pay-as-you-go services to many enterprise and individual tenants. However, the trust on public cloud services has been a sensitive issue for both cloud tenants and cloud service providers (CSPs). Tenants tend to worry about losing the total control over their codes and data hosted on remote servers. Public cloud providers often fear that the applications uploaded by their tenants may carry vicious codes, which may cause serious violations of security and privacy on their cloud platforms. This trust issue has slowed down the wide deployment of public clouds and hindered the promises of cloud computing for both CSPs and Cloud consumers. In this paper, we present Ta-TCS, a novel system framework for two-phase tenants attested trust validation and trust management over their remote VMs and cloud service executions. At the CSP end, we build a Minimal Trusted Environment (MTE) in VMM and an Integrity Verification & Report Service (IVRS) hosted in the control domain Dom0. At the tenant end, we deploy an Integrity Configuration and Attestation Service (ICAS) in new framework. With Ta-TCS, tenants can configure and attest the integrity of their services, and Cloud providers can verify codes running on a guest VM by introspection. Tenants can also check whether the basic platform of Dom0 is trusted or not. This two phase trust establishment increases the level of mutual trust between tenants and its CSP. We implement the first prototype system of Ta-TCS on Xen platform, and most of our implementation mechanisms can be deployed to some open-source virtualization platforms such as KVM. Our evaluation results show that Ta-TCS is effective with negligible performance overhead.
引用
收藏
页码:600 / 607
页数:8
相关论文
共 50 条
  • [21] Cloud Computing: Cloud Security to Trusted Cloud
    Wu Jiyi
    Shen Qianli
    Zhang Jianlin
    Xie Qi
    NEW TRENDS AND APPLICATIONS OF COMPUTER-AIDED MATERIAL AND ENGINEERING, 2011, 186 : 596 - 600
  • [22] A Framework for Preserving Data Security in Hybrid Cloud Environment using Trusted Multiple Cloud Service Providers
    Vijayanand, K. S.
    Mala, T.
    2014 SIXTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING, 2014, : 14 - 18
  • [23] Normal Cloud Model-Based Algorithm for Multi-Attribute Trusted Cloud Service Selection
    Yang, Yuli
    Liu, Rui
    Chen, Yongle
    Li, Tong
    Tang, Yi
    IEEE ACCESS, 2018, 6 : 37644 - 37652
  • [24] Trusted platform-as-a-service: A foundation for trustworthy cloud-hosted applications
    Brown, Andrew
    Chase, Jeffrey S.
    Proceedings of the ACM Conference on Computer and Communications Security, 2011, : 15 - 20
  • [25] Assessment of cloud service trusted state based on fuzzy entropy and Markov chain
    Yang, Ming
    Jiang, Rong
    Wang, Jia
    Gui, Bin
    Long, Leijin
    SCIENTIFIC REPORTS, 2024, 14 (01):
  • [26] Trusted Platform-as-a-Service: A Foundation for Trustworthy Cloud-Hosted Applications
    Brown, Andrew
    Chase, Jeffrey S.
    PROCEEDINGS OF THE 3RD ACM WORKSHOP CLOUD COMPUTING SECURITY WORKSHOP (CCSW'11), 2011, : 15 - 20
  • [27] Trusted Cloud Service Selection Algorithm Based on Lightweight Intuitionistic Fuzzy Numbers
    Yang, Yuli
    Yu, Nanyue
    Chen, Yongle
    IEEE ACCESS, 2020, 8 : 97748 - 97756
  • [28] Trusted Cloud Computing Architectures for infrastructure as a service: Survey and systematic literature review
    Ibrahim, Fady A. M.
    Hemayed, Elsayed E.
    COMPUTERS & SECURITY, 2019, 82 : 196 - 226
  • [29] Cloud-CoCoSo: Cloud Model-Based Combined Compromised Solution Model for Trusted Cloud Service Provider Selection
    Mandal, Sudakshina
    Khan, Danish Ali
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2022, 47 (08) : 10307 - 10332
  • [30] Cloud-CoCoSo: Cloud Model-Based Combined Compromised Solution Model for Trusted Cloud Service Provider Selection
    Sudakshina Mandal
    Danish Ali Khan
    Arabian Journal for Science and Engineering, 2022, 47 : 10307 - 10332