首页 | 本学科首页   官方微博 | 高级检索  
     

基于虚拟机的内核完整性保护技术
引用本文:张磊,陈兴蜀,刘亮,李辉.基于虚拟机的内核完整性保护技术[J].电子科技大学学报(自然科学版),2015,44(1):117-122.
作者姓名:张磊  陈兴蜀  刘亮  李辉
作者单位:1.四川大学计算机学院 成都 610065;
基金项目:国家自然科学基金(61272447);国家科技支撑计划
摘    要:针对云计算中客户虚拟机内核完整性面临的威胁,该文提出了一种保护虚拟机内核完整性的技术-CTVM。该技术在KVM虚拟机环境中实现了虚拟化可信执行环境的创建,使多个客户虚拟机同时拥有可信计算功能,能对客户虚拟机提供启动完整性度量;在此基础上利用硬件辅助虚拟化技术,通过为客户虚拟机构造隔离的地址空间,使客户虚拟机中不可信模块与内核运行在逻辑隔离的地址空间。从这两个方面实现对客户虚拟机的启动和运行时的完整性保护。最后,以某国产服务器为实验平台实现了CTVM原型系统,系统测试与分析验证了技术的可用性,系统性能损耗在可接受的范围内。

关 键 词:完整性    内核    KVM    可信计算    虚拟机
收稿时间:2014-02-10

A Kernel Integrity Protection Technology Based on Virtual Machine
ZHANG Lei,CHEN Xing-shu,LIU Liang,LI Hui.A Kernel Integrity Protection Technology Based on Virtual Machine[J].Journal of University of Electronic Science and Technology of China,2015,44(1):117-122.
Authors:ZHANG Lei  CHEN Xing-shu  LIU Liang  LI Hui
Affiliation:1.School of Computer Science,Sichuan University Chengdu 610065;2.School of Electronics and Information Engineering,Sichuan University Chengdu 610065
Abstract:For the kernel integrity threats of virtual machine in cloud computing environment, an integrity protecting technology of virtual machine kernel, cloud trusted virtual machine(CTVM), is proposed. In the CTVM, the virtual trusted execution environment in kernel-based virtual machine(KVM) is created, the multiple virtual machines are endowed with a trusted computing function at the same time, and the guest virtual machines are provided with integrity measurement ability. By utilizing hardware virtualization technology, the untrusted kernel modules are isolated from operating system kernel through constructing isolated address space in guest virtual machines, so as to protect the booting integrity and runtime integrity of guest virtual machines. Finally, with a domestic server as the experimental platform, CTVM prototype system is presented. System test and analysis show that the system performance loss is within the acceptable range.
Keywords:integrity  kernel  KVM  trusted computing  virtual machine
本文献已被 万方数据 等数据库收录!
点击此处可从《电子科技大学学报(自然科学版)》浏览原始摘要信息
点击此处可从《电子科技大学学报(自然科学版)》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号