云计算环境下基于系统依赖图的远程证明方案  被引量:2

A Remote Attestation Scheme Based on System Dependence Graph in Cloud Computing Environment

在线阅读下载全文

作  者:陈璐[1] 柯文彬 张立强[2,3] 陈云 CHEN Lu;KE Wenbin;ZHANG Liqiang;CHEN Yun(Department of Information Security,Naval University of Engineering,Wuhan 430033,Hubei,China;School of Cyber Science and Engineering,Wuhan University,Wuhan 430072.Hubei,China;Suzhou Institute of Wuhan University.Suzhou 215000,Jiangsu,China)

机构地区:[1]海军工程大学信息安全系,湖北武汉430033 [2]武汉大学国家网络安全学院,湖北武汉430072 [3]武汉大学苏州研究院,江苏苏州215000

出  处:《武汉大学学报(理学版)》2020年第4期401-408,共8页Journal of Wuhan University:Natural Science Edition

基  金:国家自然科学基金(11202239);航天五院CAST基金(2016020);苏州市前瞻性应用研究项目(SYG201845)。

摘  要:针对云计算环境中服务端执行行为不能被度量以致用户无法判断自身数据安全性的问题,提出云计算环境下基于系统依赖图(system dependence graph,SDG)的远程证明方案。该方案通过构建服务端程序的系统依赖图,刻画程序与文件间的依赖关系,建立行为度量目标集合,实现对用户数据访问程序执行过程的度量分析;针对客户端对云计算服务端存储的用户数据的可验证需求,对远程证明机制进行了扩展,增加了对行为度量的安全性验证。通过构造程序实例发生改变前后的程序依赖图(program dependence graph,PDG)、SDG以及对应节点信息流,验证了本文方案的可靠性和有效性。In the cloud computing environment, the execution behavior of the server side cannot be measured so that users cannot judge their data security. This paper proposes a remote attestation scheme based on system dependence graph(SDG) in cloud computing environment. Through building SDG of the server side program, the study of the dependence relationship between the program and the file can be carried on and the target set of program’s behavior can be established to realize the measurement of program execution process related to user’s data. In order to meet the client’s verification requirement for user’s data stored in cloud computing server, the remote attestation scheme is extended to include the security verification of behavior measurement. The reliability and effectiveness of the scheme are verified by constructing the program dependence graph(PDG) and SDG before and after the change of the program instance and the information flow of the corresponding node.

关 键 词:云安全 可信计算 系统依赖图 远程证明 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象