A Security-Improved Scheme for Virtual TPM Based on KVM  被引量:6

A Security-Improved Scheme for Virtual TPM Based on KVM

在线阅读下载全文

作  者:SHI Yuan ZHAO Bo YU Zhao ZHANG Huanguo 

机构地区:[1]School of Computer,Key Laboratory of Aerospace Information Security and Trusted Computing Ministry of Education,Wuhan University

出  处:《Wuhan University Journal of Natural Sciences》2015年第6期505-511,共7页武汉大学学报(自然科学英文版)

基  金:Supported by the National Basic Research Program of China(973 Program)(2014CB340600);the National High Technology Research and Development Program of China(863 Program)(2015AA016002);the National Natural Science Foundation of China(61173138,61272452,61332018)

摘  要:Virtual trusted platform module (vTPM) is an impor- tant part in building trusted cloud environment. Aiming at the remediation of lack of effective security assurances of vTPM in- stances in the existing virtual TPM architecture, this paper pre- sents a security-improved scheme for virtual TPM based on ker- nel-based virtual machine (KVM). By realizing the TPM2.0 speci- fication in hardware and software, we add protection for vTPM's secrets using the asymmetric encryption algorithm of TPM. This scheme supports the safety migration of a TPM key during VM-vTPM migration and the security association for different virtual machines (VMs) with vTPM instances. We implement a virtual trusted platform with higher security based on KVM virtual infrastructure. The experiments show that the proposed scheme can enhance the security of virtual trusted platform and has fewer additional performance loss for the VM migration with vTPM.Virtual trusted platform module (vTPM) is an impor- tant part in building trusted cloud environment. Aiming at the remediation of lack of effective security assurances of vTPM in- stances in the existing virtual TPM architecture, this paper pre- sents a security-improved scheme for virtual TPM based on ker- nel-based virtual machine (KVM). By realizing the TPM2.0 speci- fication in hardware and software, we add protection for vTPM's secrets using the asymmetric encryption algorithm of TPM. This scheme supports the safety migration of a TPM key during VM-vTPM migration and the security association for different virtual machines (VMs) with vTPM instances. We implement a virtual trusted platform with higher security based on KVM virtual infrastructure. The experiments show that the proposed scheme can enhance the security of virtual trusted platform and has fewer additional performance loss for the VM migration with vTPM.

关 键 词:trusted computing virtual trusted platform mod- ule(vTPM) TPM2.0 kernel-based virtual machine (KVM) 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象