课题基金 / 基金详情

CSR: Small: Split Virtual Machine Execution for Reliability and Security

CSR: Small: Split Virtual Machine Execution for Reliability and Security
CSR:小型:拆分虚拟机执行以实现可靠性和安全性
批准号:
1419869
负责人:
Jakub Szefer
金额:
$20.08万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-10-01 至 2017-09-30

项目摘要

项目成果

Jakub Szefer的其他基金

相似基金

相关文献

中文摘要
翻译
数据中心是云计算的支柱,云计算因其经济效益而成为重要的计算范式。然而,云计算的可靠性和安全性方面仍然需要更多的调查。在云计算中,虚拟机(也称为虚拟服务器或VM)是主要计算单位之一:客户租用VM,每个VM封装一个操作系统和一个客户的应用程序。在云计算数据中心,许多物理服务器--每台都运行管理程序虚拟化软件--提供运行虚拟服务器所需的计算资源。在硬件故障或物理服务器安全漏洞等紧急情况下,需要立即将VM从其运行的受影响的物理服务器上移走。但是,没有一台未受影响的物理服务器具有在该时刻运行该VM所需的资源。同时,两台或更多台服务器可能共同拥有运行该VM所需的资源。该项目旨在允许拆分一个VM,以便在这种情况下可以在两个或多个服务器上一起运行。这有望提高私人、商业和政府云计算提供商的可靠性、安全性和利用率。该项目将探索拆分虚拟机执行的创新想法,这是一种新技术,允许将一个虚拟机拆分成更小的部分,并作为一个整体继续执行,而这些部分位于不同的物理服务器上。该项目的一个特别重点将是将一个VM拆分成两个部分,并展示这种操作可以透明而高效地完成。本研究还将解决驻留在不同物理服务器上的VM拆分部分之间的内存一致性和中断管理问题。将开发用于同步和控制两部分VM的新协议,以便在不同物理服务器上运行的底层虚拟化软件可以在VM在拆分-VM模式下运行时对其进行管理,从而使拆分-VM的两部分具有相同的内存视图,并在两者之间无缝传递事件(如中断)。此项目的更广泛影响将提供对以透明方式将VM拆分为可在单独的物理服务器上运行的部分的洞察。这些拆分机制将在流行的开源Linux操作系统和开源Xen虚拟化软件上开发和原型,并将新代码分享给社区。将评估拆分操作的性能以及拆分后的VM的执行情况,以深入了解提议的想法的性能,并帮助量化其可靠性和安全效益。这项拟议的工作也将成为指导未来将VM拆分成多个部分而不仅仅是两个部分的研究的垫脚石。因此,此拆分VM项目是通过支持在不同物理服务器之间透明地拆分商用VM来提高云数据中心利用率、可靠性和安全性的第一步。
英文摘要
Data centers are the backbone of cloud computing, which has become an important computing paradigm due to its economic benefits. Reliability and security aspects of cloud computing, however, still need more investigation. In cloud computing, virtual machines (also called virtual servers or VMs) are one of the primary units of computation: customers lease VMs, each encapsulating an operating system and a customer's applications. In cloud computing data centers, many physical servers - each running hypervisor virtualization software - provide compute resources needed to run the virtual servers. In emergency situations like hardware failure or the security breach of a physical server, a VM needs to be immediately moved away from the affected physical server on which it is running. However, no single unaffected physical server may have the exact resources needed to run the VM at that exact instance in time. Meanwhile, two or more servers may collectively have the resources needed to run the VM. This project aims to allow a VM to be split so it can be run on two or more servers together in such a situation. This has promise of increasing the reliability, security and utilization of private, commercial and government cloud computing providers. This project will explore an innovative idea of Split-VM execution, a new technique that will allow for a VM to be broken up into smaller pieces and to continue executing as one, while the pieces are on different physical servers. A particular focus of the project will be on splitting a VM into two pieces and showing that such operation can be done transparently and efficiently. Issues of memory coherency and interrupt management among the split pieces of the VM residing on different physical severs will be addressed in this research as well. New protocols for synchronizing and controlling the two pieces of the VM will be developed so that the underlying virtualization software running on different physical servers can manage the VMs while they are operating in the Split-VM mode enabling both pieces of a Split-VM to have same view of the memory, and events, such as interrupts, to be seamlessly delivered between the two.The broader impacts of this project will offer insight into transparently splitting a VM into parts that can run on separate physical servers. These splitting mechanisms will be developed and prototyped on popular open-source Linux operating system and on open-source Xen virtualization software, with new code shared back to the community. Performance of the splitting operation and also of the execution of the VM after splitting will be evaluated to give insights into the performance of the proposed idea and to help quantify its reliability and security benefits. The proposed work will also be a stepping-stone to guide future research on splitting VMs into many pieces, not just two. This Split-VM project is thus a first step towards improving cloud data center utilization, reliability and security by enabling commodity VMs to be transparently split among different physical servers.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Automatic Detection and Repair of Side Channel Vulnerabilities in Software Code
  • 批准号:
    2245344
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $60.0万
  • 财政年份:
    2023
  • 负责人:
    Jakub Szefer
  • 依托单位:
SaTC: CORE: Medium: Collaborative: Security of Reconfigurable Cloud Computing
  • 批准号:
    1901901
  • 项目类别:
    Standard Grant
  • 资助金额:
    $45.72万
  • 财政年份:
    2019
  • 负责人:
    Jakub Szefer
  • 依托单位:
SaTC: STARSS: Small: Collaborative: Design and Security Verification of Next-Generation Open-Source Processors
  • 批准号:
    1813797
  • 项目类别:
    Standard Grant
  • 资助金额:
    $16.56万
  • 财政年份:
    2018
  • 负责人:
    Jakub Szefer
  • 依托单位:
CAREER: Security Applications of DRAM Cell Decay Effects
  • 批准号:
    1651945
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $55.0万
  • 财政年份:
    2017
  • 负责人:
    Jakub Szefer
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: