首页 | 本学科首页   官方微博 | 高级检索  
     

基于硬件虚拟化的单向隔离执行模型
引用本文:李小庆,赵晓东,曾庆凯.基于硬件虚拟化的单向隔离执行模型[J].软件学报,2012,23(8):2207-2222.
作者姓名:李小庆  赵晓东  曾庆凯
作者单位:计算机软件新技术国家重点实验室(南京大学),江苏南京210093;南京大学计算机科学与技术系,江苏南京210093
基金项目:国家自然科学基金,国家科技支撑计划,高等学校博士学科点专项科研基金,江苏省科技支撑计划
摘    要:提出了一种基于硬件虚拟化技术的单向隔离执行模型.在该模型中,安全相关的应用程序可以根据自身需求分离成宿主进程(host process)和安全敏感模块(security sensitive module,简称SSM)两部分.隔离执行器(SSMVisor)作为模型的核心部件,为SSM提供了一个单向隔离的执行环境.既保证了安全性,又允许SSM以函数调用的方式与外部进行交互.安全应用程序的可信计算基(trusted computing base,简称TCB)仅由安全敏感模块和隔离执行器构成,不再包括应用程序中的安全无关模块和操作系统,有效地削减了TCB的规模.原型系统既保持了与原有操作系统环境的兼容性,又保证了实现的轻量级.实验结果表明,系统性能开销轻微,约为6.5%.

关 键 词:隔离执行  硬件虚拟化  安全敏感模块  可信计算基
收稿时间:2011/5/16 0:00:00
修稿时间:2011/7/21 0:00:00

One-Way Isolation Execution Model Based on Hardware Virtualization
LI Xiao-Qing,ZHAO Xiao-Dong and ZENG Qing-Kai.One-Way Isolation Execution Model Based on Hardware Virtualization[J].Journal of Software,2012,23(8):2207-2222.
Authors:LI Xiao-Qing  ZHAO Xiao-Dong and ZENG Qing-Kai
Affiliation:1,2+) 1(State Key Laboratory for Novel Software Technology(Nanjing University),Nanjing 210093,China) 2(Department of Computer Science and Technology,Nanjing University,Nanjing 210093,China)
Abstract:A one-way isolation execution model based on hardware virtualization is proposed.In this model,the security application based on self-requirements can be divided into two parts:host process and security sensitive module(SSM).Isolated execution manager named SSMVisor,as the core component of isolation execution model, provides a one-way isolation execution environment for SSMs,not only to ensure security,but also to allow SSMs to call outside functions.As security application’s trusted computing base(TCB) only includes SSMs and SSMVisor, without operating system and the security unrelated module of the applications,the size of security application’s TCB is reduced effectively.A prototype system is not only compatible with the original operating system,but also light-weight.Experimental results show that the performance overhead of prototype system is very low,about 6.5%.
Keywords:isolation execution  hardware virtualization  security sensitive module  TCB(trusted computing base)
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号