课题基金 / 基金详情

CSR: Small: Split Virtual Machine Execution for Reliability and Security

CSR: Small: Split Virtual Machine Execution for Reliability and Security
CSR:小型:拆分虚拟机执行以实现可靠性和安全性
批准号:
1419869
负责人:
Jakub Szefer
金额:
$20.08万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-10-01 至 2017-09-30

项目摘要

项目成果

Jakub Szefer的其他基金

相似基金

相关文献

中文摘要
翻译
数据中心是云计算的支柱,云计算因其经济效益而成为重要的计算范式。 然而,云计算的可靠性和安全性方面仍需要更多研究。 在云计算中,虚拟机(也称为虚拟服务器或 VM)是主要计算单元之一:客户租用 VM,每个 VM 封装一个操作系统和客户的应用程序。在云计算数据中心,许多物理服务器(每个服务器都运行虚拟机管理程序虚拟化软件)提供运行虚拟服务器所需的计算资源。在硬件故障或物理服务器安全漏洞等紧急情况下,需要立即将虚拟机从其运行的受影响物理服务器上移走。然而,没有一个不受影响的物理服务器可能拥有在该确切实例上及时运行虚拟机所需的确切资源。 同时,两个或多个服务器可能共同拥有运行虚拟机所需的资源。该项目的目标是允许虚拟机被分割,以便在这种情况下它可以在两个或多个服务器上一起运行。这有望提高私人、商业和政府云计算提供商的可靠性、安全性和利用率。 该项目将探索分割虚拟机执行的创新理念,这是一种新技术,允许将虚拟机分成更小的部分并继续作为一个整体执行,而这些部分位于不同的物理服务器上。 该项目的一个特别重点是将虚拟机分成两部分,并表明此类操作可以透明且高效地完成。 本研究还将解决驻留在不同物理服务器上的虚拟机分割部分之间的内存一致性和中断管理问题。 将开发用于同步和控制虚拟机的两个部分的新协议,以便在不同物理服务器上运行的底层虚拟化软件可以在虚拟机以拆分虚拟机模式运行时管理虚拟机,从而使拆分虚拟机的两个部分具有相同的内存视图,并且中断等事件可以在两者之间无缝传递。该项目的更广泛影响将提供对透明地将虚拟机拆分为可以在单独的物理服务器上运行的部分的深入了解。 这些拆分机制将在流行的开源 Linux 操作系统和开源 Xen 虚拟化软件上进行开发和原型设计,并将新代码共享回社区。 将评估拆分操作的性能以及拆分后虚拟机执行的性能,以深入了解所提出想法的性能,并帮助量化其可靠性和安全性优势。 拟议的工作也将成为指导未来将虚拟机分成许多部分(而不仅仅是两个部分)的研究的基石。 因此,这个拆分虚拟机项目是通过使商用虚拟机在不同物理服务器之间透明地拆分来提高云数据中心利用率、可靠性和安全性的第一步。
英文摘要
Data centers are the backbone of cloud computing, which has become an important computing paradigm due to its economic benefits. Reliability and security aspects of cloud computing, however, still need more investigation. In cloud computing, virtual machines (also called virtual servers or VMs) are one of the primary units of computation: customers lease VMs, each encapsulating an operating system and a customer's applications. In cloud computing data centers, many physical servers - each running hypervisor virtualization software - provide compute resources needed to run the virtual servers. In emergency situations like hardware failure or the security breach of a physical server, a VM needs to be immediately moved away from the affected physical server on which it is running. However, no single unaffected physical server may have the exact resources needed to run the VM at that exact instance in time. Meanwhile, two or more servers may collectively have the resources needed to run the VM. This project aims to allow a VM to be split so it can be run on two or more servers together in such a situation. This has promise of increasing the reliability, security and utilization of private, commercial and government cloud computing providers. This project will explore an innovative idea of Split-VM execution, a new technique that will allow for a VM to be broken up into smaller pieces and to continue executing as one, while the pieces are on different physical servers. A particular focus of the project will be on splitting a VM into two pieces and showing that such operation can be done transparently and efficiently. Issues of memory coherency and interrupt management among the split pieces of the VM residing on different physical severs will be addressed in this research as well. New protocols for synchronizing and controlling the two pieces of the VM will be developed so that the underlying virtualization software running on different physical servers can manage the VMs while they are operating in the Split-VM mode enabling both pieces of a Split-VM to have same view of the memory, and events, such as interrupts, to be seamlessly delivered between the two.The broader impacts of this project will offer insight into transparently splitting a VM into parts that can run on separate physical servers. These splitting mechanisms will be developed and prototyped on popular open-source Linux operating system and on open-source Xen virtualization software, with new code shared back to the community. Performance of the splitting operation and also of the execution of the VM after splitting will be evaluated to give insights into the performance of the proposed idea and to help quantify its reliability and security benefits. The proposed work will also be a stepping-stone to guide future research on splitting VMs into many pieces, not just two. This Split-VM project is thus a first step towards improving cloud data center utilization, reliability and security by enabling commodity VMs to be transparently split among different physical servers.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Automatic Detection and Repair of Side Channel Vulnerabilities in Software Code
  • 批准号:
    2245344
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $60.0万
  • 财政年份:
    2023
  • 负责人:
    Jakub Szefer
  • 依托单位:
SaTC: CORE: Medium: Collaborative: Security of Reconfigurable Cloud Computing
  • 批准号:
    1901901
  • 项目类别:
    Standard Grant
  • 资助金额:
    $45.72万
  • 财政年份:
    2019
  • 负责人:
    Jakub Szefer
  • 依托单位:
SaTC: STARSS: Small: Collaborative: Design and Security Verification of Next-Generation Open-Source Processors
  • 批准号:
    1813797
  • 项目类别:
    Standard Grant
  • 资助金额:
    $16.56万
  • 财政年份:
    2018
  • 负责人:
    Jakub Szefer
  • 依托单位:
CAREER: Security Applications of DRAM Cell Decay Effects
  • 批准号:
    1651945
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $55.0万
  • 财政年份:
    2017
  • 负责人:
    Jakub Szefer
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: