课题基金 / 基金详情

CT-IS: Shamon: Systems Approaches for Constructing Distributed Trust

CT-IS: Shamon: Systems Approaches for Constructing Distributed Trust
CT-IS:Shamon:构建分布式信任的系统方法
批准号:
0627551
负责人:
Trent Jaeger
金额:
$40.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-09-01 至 2010-08-31

项目摘要

项目成果

Trent Jaeger的其他基金

相关文献

中文摘要
翻译
现有的分布式授权系统侧重于策略的制定,但执行仍然是每个主机的问题。任何组件未能忠实地执行策略都可能导致漏洞,在极端情况下,会导致授权无效。如果对授权实施的完整性没有更大的保证,就无法构建可扩展到互联网范围的应用程序、可靠的分布式授权。共享参考监视器(Shamon)项目利用先进的不完整性测量和虚拟机来组成分布式应用程序的一致性授权系统。Shamon由多台物理机器上的一组参考监视器组成,这些机器经过完整性验证,可以在定义应用程序的虚拟机之间强制执行一致的安全策略。虚拟机的使用提供了粗粒度的隔离,简化了大规模分布式系统的安全策略,并且完整性度量确保Shamon的每个成员都可以验证其他成员正在执行此策略。Shamon项目的重点是构建服务来组合和维护这些共享的参考监视器。首先,定义了基于逻辑的方法,使Shamon引用监视器在执行一致策略时能够组合信任。这种信任组合在包括虚拟机的加入、离开和迁移在内的系统动态存在下是稳健的。其次,Xen管理程序系统增强了这些信任组合服务。通过这种方式,被监视的应用程序将只与规则与其Shamon策略一致的系统通信。
英文摘要
Existing distributed authorization systems focus on the formulation ofpolicy, but enforcement remains a per-host issue. Failure of anycomponent to faithfully enforce policy can lead to vulnerabilities,and in the extreme, renders authorization impotent. Without greaterassurance in the integrity of authorization enforcement, that scalesto Internet-wide applications, reliable, distributed authorizationcannot be built.The Shared Reference Monitor (Shamon) project leverages advances inintegrity measurement and virtual machines to compose a coherentauthorization system for distributed applications. A Shamon consistsof a set of reference monitors on multiple, physical machines that areintegrity-verified to enforce a consistent security policy acrossvirtual machines that define an application. The use of virtualmachines provides coarse-grained isolation that simplifies securitypolicy for large-scale distributed systems, and the integritymeasurement ensures that each member of the Shamon can verify that theothers are enforcing this policy.The Shamon project focuses on building the services tocompose and maintain such shared reference monitors. First, alogic-based approach is defined that enables composition of trust inthe enforcement of a consistent policy by the Shamon referencemonitors. Such trust composition will be robust in the presence ofsystem dynamics including the joining, leaving and migration ofvirtual machines. Second, the Xen hypervisor system is augmented withthese trust composition services. In this way, monitored applicationswill only communicate with systems whose regulation is consistent withits Shamon policy.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Information Flow Control Infrastructure for Single-Use Service Platforms
SaTC: CORE: Medium: Collaborative: Threat-Aware Defense: Evaluating Threats for Continuous Improvement
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
Trusted Infrastructure Workshop 2013