• DocumentCode
    2673769
  • Title

    Building dynamic integrity protection for multiple independent authorities in virtualization-based infrastructure

  • Author

    Cheng, Ge ; Jin, Hai ; Zou, Deqing ; Zhang, Xinwen ; Li, Min ; Yu, Chen ; Xiang, Guofu

  • Author_Institution
    Services Comput. Technol. & Syst. Lab., Huazhong Univ. of Sci. & Technol., Wuhan, China
  • fYear
    2009
  • fDate
    13-15 Oct. 2009
  • Firstpage
    113
  • Lastpage
    119
  • Abstract
    In grid and cloud computing infrastructures, the integrity of a computing platform is a critical security requirement in order to provide secure and honest computing environments to service providers and resource consumers. However, due to the fact that software components running on a single platform are usually provided and maintained by different authorities which are potentially untrusted to each other, the problem to monitor and protect runtime system integrity become very challenging and has not been well addressed yet. In this paper, we present a virtualization based dynamic integrity protection method which ensures that only appropriate authorities can control over their components without interfering with other component providers or authorities. In our solution, integrity requirements defined by the authorities of upper components (e.g., service middleware and applications) are respected by preventing the underlying components (e.g., operating system) from exposing their sensitive data, which can be caused by update of the underlying components or other malicious actions. We implement our solution on Xen-based platform, and our evaluation results show that the solution is effective for integrity protection with acceptable performance overhead.
  • Keywords
    data integrity; grid computing; object-oriented programming; security of data; Xen-based platform; cloud computing; computing environments; critical security requirement; dynamic integrity protection; grid computing; multiple independent authority; resource consumers; runtime system integrity; service providers; software components; virtualization-based infrastructure; Application software; Cloud computing; Computer science; Grid computing; Hardware; Middleware; Operating systems; Physics computing; Portable computers; Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Grid Computing, 2009 10th IEEE/ACM International Conference on
  • Conference_Location
    Banff, AB
  • Print_ISBN
    978-1-4244-5148-7
  • Electronic_ISBN
    978-1-4244-5149-4
  • Type

    conf

  • DOI
    10.1109/GRID.2009.5353079
  • Filename
    5353079