Porridge: a method of providing resilient and scalable cloud-attestation-as-a-service

Porridge: a method of providing resilient and scalable cloud-attestation-as-a-service
复制标题

Porridge:一种提供弹性且可扩展的云认证即服务的方法

DOI:
10.1049/cp.2017.0175
复制
发表时间:
2017
期刊:
--
影响因子:
--
通讯作者:
Wallom D
Wallom D
中科院分区:
--
文献类型:
--
作者:
Wallom D

文献摘要

相似文献

有效地建立对云计算的信任是实现更广泛采用混合云和公共云的关键要求。尽管已经提出了许多可信云概念,但它们在弹性,可扩展性和动态性方面存在局限性。我们通过创建分布式认证服务Porridge来解决这些限制。Porridge实现了弹性,因为采用了多个证明工作者并且为证明每个虚拟机(VM)分配了冗余工作者;可扩展性,因为证明负载和责任在工作者之间自动均匀分布;对云动态的适应性,因为每个VM的虚拟可信平台模块(vTPM)被映射到主机中的一组稳定的物理可信平台模块(TPM),然后是工作者TPM。总的来说,证明方案支持灵活的vTPM-TPM绑定,同时隐藏云基础设施的细节,VM的信任根不绑定到其底层主机的TPM,而是绑定到其管理工作器。通过引入提供云认证即服务(CAaaS)的可信服务提供商,可以扩展此概念以支持更高级的云安全性。
Effectively establishing trust in Cloud Computing is a critical requirement for achieving wider adoption of hybrid and public cloud. Although a number of Trusted Cloud concepts have been proposed, they suffer from limitations in resilience, scalability and dynamism. We tackle these limitations with the creation of a distributed attestation service, Porridge. Porridge achieves resiliency, as multiple attestation workers are employed and redundant workers assigned for attesting each Virtual Machine (VM); scalability, as the attestation load and responsibility is automatically distributed evenly among workers; adaptivity to cloud dynamism, as each VM's virtual Trusted Platform Module (vTPM) is mapped to a stable set of physical Trusted Platform Modules (TPM) in the host and then the workers TPMs. Overall the attestation scheme enables flexible vTPM-TPM bindings while hiding details of cloud infrastructure, with the root-of-trust for the VM not bound to its underlying host's TPM, but to its managing workers. This concept can be extended to support more advanced cloud security through the introduction of Trusted Service Providers providing Cloud Attestation as a Service (CAaaS).