信息网络安全 ›› 2018, Vol. 18 ›› Issue (4): 9-14.doi: 10.3969/j.issn.1671-1122.2018.04.002

• • 上一篇    下一篇

面向云计算环境的vTPCM可信管理方案

张建标1,2, 杨石松1,2(), 涂山山1,2, 王晓1,2   

  1. 1.北京工业大学信息学部可信计算北京市重点实验室, 北京 100124
    2.信息安全等级保护关键技术国家工程实验室,北京 100142
  • 收稿日期:2018-01-30 出版日期:2018-04-15 发布日期:2020-05-11
  • 作者简介:

    作者简介:张建标(1969—),男,江苏,教授,博士,主要研究方向为信息安全与可信计算;杨石松(1989—),男,陕西,硕士研究生,主要研究方向为云安全与可信计算;涂山山(1983—),男,湖北,讲师,博士,主要研究方向为云安全、云隐私保护;王晓(1983—),女,河北,讲师,博士,主要研究方向为可信计算、云安全。

  • 基金资助:
    国家自然科学基金[61671030];国家高技术研究发展计划(863计划)[2015AA016002]

Research on vTPCM Trust Management Technology for Cloud Computing Environment

Jianbiao ZHANG1,2, Shisong YANG1,2(), Shanshan TU1,2, Xiao WANG1,2   

  1. 1.Beijing Key Laboratory of Trusted Computing, Faculty of Information Technology, Beijing University of Technology, Beijing 100124
    2. National Engineering Laboratory for Critical Technologies of Information Security Classified Protection, Beijing 100142, China
  • Received:2018-01-30 Online:2018-04-15 Published:2020-05-11

摘要:

随着云计算技术规模的不断扩大,其安全问题备受人们担忧,面对亟待解决的云计算安全问题,基于TPCM双系统体系结构的可信计算,实现了为云计算平台上的每个虚拟机提供主动免疫可信安全机制,从而防止了云环境下虚拟机化技术相关的安全问题。然而目前针对如何管理vTPCM与虚拟机的生命周期并没有相应的具体方案,因此文章首先提出了管理vTPCM实例的整体架构,旨在解决vTPCM实例与虚拟机生命周期同步;然后,提出了一种基于可信计算的vTPCM管理方案,解决了虚拟机迁移过程中的生命周期同步问题,以及虚拟机访问vTPCM实例与物理机访问TPCM的映射问题,从而有效地提高vTPCM与虚拟机的关联性。

关键词: 云计算, 可信计算, vTPCM管理, 虚拟机迁移, 强关联性

Abstract:

With the continuous expansion of cloud computing technology, its security issues have been worried about. In the face of the urgent need to solve the cloud computing security issues, the Trusted Computing TPCM-based dual-system architecture enables the provision of proactive immune trusted security mechanisms for each virtual machine on the cloud computing platform, thus preventing the cloud environment virtual machine technology-related security issues. However, this paper first puts forward the overall architecture of managing vTPCM instances, which aims at solving the management of the lifecycle of vTPCM instance and virtual machine. Then, the paper analyzes the vTPCM instance and the virtual machine lifecycle, This paper proposes a management scheme based on Trusted Computing to solve the problem of lifecycle synchronization in virtual machine migration process and the mapping between virtual machine accesses vTPCM instance and physical machine access TPCM, so as to effectively improve the association between vTPCM and virtual machine.

Key words: cloud computing, trusted computing, vTPCM management, VM migration, strong association

中图分类号: