DocumentCode
1726557
Title
Trusted Virtual Infrastructure Bootstrapping for On Demand Services
Author
Membrey, Peter ; Chan, Keith C C ; Ngo, Canh ; Demchenko, Yuri ; De Laat, Cees
Author_Institution
Hong Kong Polytech. Univ., Hong Kong, China
fYear
2012
Firstpage
350
Lastpage
357
Abstract
As cloud computing continues to gain traction, a great deal of effort is being expended in researching the most effective ways to build and manage secure and trustworthy clouds. Providing consistent security services in on-demand provisioned Cloud infrastructure services is of primary importance due to the multi-tenant and potentially multi-provider nature of Cloud Infrastructure. Cloud security infrastructure should address two aspects of the IaaS operation and dynamic security services provisioning: (1) provide security infrastructure for secure Cloud IaaS operation; (2) provisioning dynamic security services. Although the first task is a traditional task in security engineering, dynamic provisioning of managed security services in virtualized environment remains a problem and requires additional research. Entire frameworks have been proposed and demonstrated but although successful, there is a tendency to see such solutions as integrated ´all in one´ infrastructures. This paper describes a light-weight mechanism and protocol for building trust between two machines that takes advantage of the Trusted Platform Module (TPM) to handle a key exchange and remote trusted deployment of a bootstrapping tool (referred to as the Bootstrapping Initiator (BI)). Once deployed, the BI can execute any arbitrary software required which could be (but is not limited to) solutions for advanced architecture management such as the Dynamic Access Control Infrastructure (DACI). The proposed solution provides a light-weight layer of trust backed by a TPM that additional systems can build upon as required by the individual use case without the requirement for a specific management or security infrastructure to be deployed along with it.
Keywords
authorisation; cloud computing; computer bootstrapping; trusted computing; BI; DACI; TPM; bootstrapping initiator; bootstrapping tool remote trusted deployment; cloud IaaS operation security; cloud computing; cloud security infrastructure; dynamic access control infrastructure; dynamic security services provisioning; key exchange; on-demand provisioned cloud infrastructure services; trusted platform module; trusted virtual infrastructure bootstrapping; trustworthy clouds; Authentication; Bismuth; Computer architecture; Payloads; Protocols; Public key; Bootstrapping; Cloud Security; Deployment; Trusted Computing;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2012 Seventh International Conference on
Conference_Location
Prague
Print_ISBN
978-1-4673-2244-7
Type
conf
DOI
10.1109/ARES.2012.82
Filename
6329204
Link To Document