期刊导航

论文摘要

Virt-RSBAC:一种防御云计算内部威胁的框架

Virt-RSBAC:ANovelFrameworktoMitigateInternalThreatofCloudComputing

作者:张磊(四川大学计算机学院网络与可信计算研究所);陈兴蜀(四川大学计算机学院网络与可信计算研究所);刘亮(四川大学电子信息学院);任益(四川大学计算机学院网络与可信计算研究所)

Author:Zhang Lei(NetworkandTrustedComputingInst.,CollegeofComputerSci.,SichuanUniv.);Chen Xingshu(NetworkandTrustedComputingInst.,CollegeofComputerSci.,SichuanUniv.);Liu Liang(CollegeofElectronicsandInfo.Eng.,SichuanUniv.);Ren Yi(NetworkandTrustedComputingInst.,CollegeofComputerSci.,SichuanUniv.)

收稿日期:2014-03-31          年卷(期)页码:2014,46(6):114-121

期刊名称:工程科学与技术

Journal Name:Advanced Engineering Sciences

关键字:云计算;隐私保护;特权控制;RSBAC;VMM

Key words:cloudcomputing;privacyprotection;RSBAC;VMM

基金项目:国家科技支撑计划资助项目(2012BAH18B05)

中文摘要

针对来自云计算平台的内部威胁,为了保护云用户的隐私,缓减平台提供者的安全监控需求与用户隐私之间的策略冲突,提出一种虚拟化环境下的特权控制框架Virt-RSBAC。通过在虚拟机监视器(VMM)中添加特权控制和基于角色的资源隔离规则,实现对特权域管理权限的分离,简化对云用户的管理,借助于创建相互信任的安全虚拟机(SVM)为云平台提供者和云用户提供安全服务。最后,在Xen上实现了该框架的原型。实验与分析表明,该框架能够防止恶意管理员获取用户隐私并提供检测功能,对原有系统的性能损耗在可接受范围内。

英文摘要

For the internal threat of cloud, a privilege control framework named Virt-RSBAC was presented to enhance privacy protection for cloud users, and mitigate the policy conflict between the demand of security monitoring of cloud provider and users’ privacy. By adding privilege control and role-based resource isolation rules in the virtual machine monitor (VMM), it implemented the separation of administrative of privileged domain, simplified the management of cloud users, and created a mutually trusted secure virtual machine (SVM) to provide security services for cloud platform providers and users. Finally, a prototype of the Virt-RSBAC framework based Xen was realized. The experiments showed that the framework can prevent malicious administrator to get user privacy and other security functions work well, and its performance payload is restricted whining an acceptable range compare with the original system.

关闭

Copyright © 2020四川大学期刊社 版权所有.

地址:成都市一环路南一段24号

邮编:610065