作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (5): 117-119. doi: 10.3969/j.issn.1000-3428.2012.05.035

• 安全技术 • 上一篇    下一篇

IaaS环境可信证明方法研究

辛思远1,2,3,赵 勇2,3,林 莉2,王晓海4   

  1. (1. 解放军信息工程大学电子技术学院,郑州 450004;2. 北京工业大学计算机学院,北京 100124; 3. 中国科学院软件研究所信息安全国家重点实验室,北京 100049;4. 61660部队,北京 100000)
  • 收稿日期:2011-12-26 出版日期:2012-03-05 发布日期:2012-03-05
  • 作者简介:辛思远(1984-),男,博士研究生,主研方向:可信计算;赵 勇、林 莉,讲师;王晓海,高级工程师
  • 基金资助:
    国家“863”计划基金资助项目(2009AA01Z437);“核高基”重大专项(2010ZX01037-001-001);中国科学院软件研究所信息安全国家重点实验室开放课题基金资助项目;北京工业大学博士启动基金资助项目(00700054R1764)

Research on Trusted Attestation Method in IaaS Environment

XIN Si-yuan   1,2,3, ZHAO Yong   2,3, LIN Li   2, WANG Xiao-hai   4   

  1. (1. Institute of Electronic Technology, PLA Information Engineering University, Zhengzhou 450004, China; 2. College of Computer Science and Technology, Beijing University of Technology, Beiing 100124, China; 3. State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences, Beijing 100049, China; 4. 61660 Unit, Beijing 100000, China)
  • Received:2011-12-26 Online:2012-03-05 Published:2012-03-05

摘要: 提出一种基于时间戳的基础设施即服务(IaaS)动态可信证明方法。通过对云节点进行实时的动态度量,并将度量结果与度量时间绑定,验证云节点的当前运行状态可信。基于该方法,结合IaaS的服务业务流程,设计云节点注册证明、虚拟机启动证明及虚拟机关闭证明等远程证明方法,证明用户虚拟机运行于状态可信的云节点上,同时保证虚拟机数据的完整性和机密性。

关键词: 基础设施即服务, 可信证明, 实时证明, 动态度量, 时间戳, 可信云节点

Abstract: A timestamp-based dynamic remote attestation method oriented to Infrastructure as Services(IaaS) is proposed. This method measures the dynamic cloud nodes’ state in real time, binds the time of measurement with the result, and verifies the current trusted running state of cloud nodes. Based on the method, the attestation methods of cloud node register, remote virtual machine boot and shutdown in IaaS computing environment are designed. These IaaS attestation methods can be used to prove that the user’s virtual machine is booted on a cloud node with trusted running state, and protect the integrity and confidentiality of virtual machine data.

Key words: Infrastructure as Service(IaaS), trusted attestation, real-time attestation, dynamic measurement, timestamp, trusted cloud node

中图分类号: