DocumentCode :
2673769
Title :
Building dynamic integrity protection for multiple independent authorities in virtualization-based infrastructure
Author :
Cheng, Ge ; Jin, Hai ; Zou, Deqing ; Zhang, Xinwen ; Li, Min ; Yu, Chen ; Xiang, Guofu
Author_Institution :
Services Comput. Technol. & Syst. Lab., Huazhong Univ. of Sci. & Technol., Wuhan, China
fYear :
2009
fDate :
13-15 Oct. 2009
Firstpage :
113
Lastpage :
119
Abstract :
In grid and cloud computing infrastructures, the integrity of a computing platform is a critical security requirement in order to provide secure and honest computing environments to service providers and resource consumers. However, due to the fact that software components running on a single platform are usually provided and maintained by different authorities which are potentially untrusted to each other, the problem to monitor and protect runtime system integrity become very challenging and has not been well addressed yet. In this paper, we present a virtualization based dynamic integrity protection method which ensures that only appropriate authorities can control over their components without interfering with other component providers or authorities. In our solution, integrity requirements defined by the authorities of upper components (e.g., service middleware and applications) are respected by preventing the underlying components (e.g., operating system) from exposing their sensitive data, which can be caused by update of the underlying components or other malicious actions. We implement our solution on Xen-based platform, and our evaluation results show that the solution is effective for integrity protection with acceptable performance overhead.
Keywords :
data integrity; grid computing; object-oriented programming; security of data; Xen-based platform; cloud computing; computing environments; critical security requirement; dynamic integrity protection; grid computing; multiple independent authority; resource consumers; runtime system integrity; service providers; software components; virtualization-based infrastructure; Application software; Cloud computing; Computer science; Grid computing; Hardware; Middleware; Operating systems; Physics computing; Portable computers; Protection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Grid Computing, 2009 10th IEEE/ACM International Conference on
Conference_Location :
Banff, AB
Print_ISBN :
978-1-4244-5148-7
Electronic_ISBN :
978-1-4244-5149-4
Type :
conf
DOI :
10.1109/GRID.2009.5353079
Filename :
5353079
Link To Document :
بازگشت