• DocumentCode
    3264634
  • Title

    TSD: A Flexible Root of Trust for the Cloud

  • Author

    Chang, Dexian ; Chu, Xiaobo ; Qin, Yu ; Feng, Dengguo

  • fYear
    2012
  • fDate
    25-27 June 2012
  • Firstpage
    119
  • Lastpage
    126
  • Abstract
    Due to the tight one-to-one binding relationship between the TPM and the single platform lacks of flexibility and scalability, the Trusted Platform Module (TPM) can not be directly applied to the cloud virtualization platform, on which concurrently running several user domains (VMs). For establishing the trust in the cloud, we propose the Trusted Service Domain (TSD), as a novel root of trust for the cloud. Being an independent functional domain, the TSD is able to provide the trusted service for the multiple user domains on the cloud virtualization platform. We firstly extend the existing trusted chain to secure the TSD, and generate the independent key hierarchies for the user domains in the TSD to support the cryptography service and secure storage. Then we design the secure communication mechanism to protect the inter-domain data, and present the migration scheme for the TSD in the cloud. Finally, we detailed our implementation of the prototype system and analyze the security of the TSD. Preliminary experiment results showed that the TSD has higher efficiency than the existing schemes on the trusted commands handling and the migration, which satisfied flexible deployment and rapidly migration requirements of the cloud virtualization platform.
  • Keywords
    cloud computing; cryptography; virtual machines; virtualisation; TSD; VM; cloud virtualization platform; cryptography service; interdomain data protection; migration scheme; secure communication mechanism; secure storage; trust root; trusted commands handling; trusted service domain; virtual machines; Booting; Cloud computing; Computer architecture; Cryptography; Hardware; Cloud Virtualization platform; Migration; Root of Trust; TPM; Trusted Computing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
  • Conference_Location
    Liverpool
  • Print_ISBN
    978-1-4673-2172-3
  • Type

    conf

  • DOI
    10.1109/TrustCom.2012.287
  • Filename
    6295966