信息网络安全 ›› 2016, Vol. 16 ›› Issue (9): 84-89.doi: 10.3969/j.issn.1671-1122.2016.09.017

• • 上一篇    下一篇

一种基于SR-IOV技术的虚拟环境安全隔离模型

刘明达, 马龙宇()   

  1. 江南计算技术研究所,江苏无锡 214083
  • 收稿日期:2016-07-25 出版日期:2016-09-20 发布日期:2020-05-13
  • 作者简介:

    作者简介: 刘明达(1991—),男,山东,硕士研究生,主要研究方向为可信计算和密码学;马龙宇(1987—),男,黑龙江,硕士研究生,主要研究方向为可信计算和嵌入式安全。

  • 基金资助:
    国家自然科学基金[91430214]

A Security Isolation Model of Virtual Environment Based on SR-IOV Technology

Mingda LIU, Longyu MA()   

  1. Jiangnan Institute of Computing Technology, Wuxi Jiangsu 214083, China
  • Received:2016-07-25 Online:2016-09-20 Published:2020-05-13

摘要:

虚拟化技术的发展,带来了计算模式的变革,同时也带来了诸多安全问题。文章研究了虚拟环境安全问题和目前主流的安全防护方式,同时研究了I/O硬件虚拟化技术——SR-IOV,并针对虚拟计算环境安全隔离的问题提出了一种基于SR-IOV技术的虚拟环境安全隔离模型。该模型根据用户需求将虚拟域进行安全分级,安全等级高的虚拟域能够分配专门的物理网卡和加密卡,安全等级较低的虚拟域仍采用传统的软件模拟方法实现I/O设备。在SR-IOV的结构设计中,采用了设备直连技术实现虚拟域和物理设备的通信,设备直连技术本身具备良好的隔离效果,这样就能够根据其安全等级实现网络数据隔离和数据加密隔离。实验结果表明,该模型能够提高虚拟计算环境的安全隔离特性,增强虚拟环境的安全,不仅具有可行性,而且具有良好的性能效率。

关键词: 虚拟环境, SR-IOV, 安全隔离

Abstract:

The development of virtualization technology brings about the change of computing model, but it also brings many security problems. This paper researches virtual environment safety problems, currently the mainstream security protection mode, and I/O hardware virtualization technology (SR-IOV). And then it proposes a virtual environment safety isolation model based on SR-IOV technology for the problems of the virtual computing environment safety isolation. The model devise virtual domain into different safety level according to user needs. High level domain owns dedicated physical network card and encryption card, and lower still uses traditional software simulation method implementing I/O device. SR-IOV uses the direct device technology to realize the communication of virtual domains and the physical equipment. The equipment of direct connected technology has good isolation effect, so it can achieve network data isolation and data encryption isolation according to the level of security. The experimental analysis shows that the model can improve the security isolation characteristics of virtual computing environment, and enhance the security of virtual environment. Not only it has the feasibility, but also has a good performance and efficiency.

Key words: virtual environment, SR-IOV, security isolation

中图分类号: