课题基金 / 基金详情

ITR/SY+SI:The System Architecture of a Computing Utility

ITR/SY+SI:The System Architecture of a Computing Utility
ITR/SY SI:计算工具的系统架构
批准号:
0121481
负责人:
Monica Lam
金额:
$0.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2001
资助国家:
美国
项目状态:
已结题
起止时间:
2001-10-01 至 2009-12-31

项目摘要

项目成果

Monica Lam的其他基金

相似基金

相关文献

中文摘要
翻译
未来的计算服务应该像电力、水或电话服务等任何现代设施一样容易获得和使用。计算实用程序应该可靠且不可见地工作,为用户提供对其数据和个性化计算环境的简单、有效访问。保存在公用事业中的数据可以是私有的、公开的,也可以在指定的各方之间共享。我们提出的计算实用程序体系结构基于计算胶囊的思想,它捕获活动计算环境的整个逻辑状态。胶囊是便携的、持久的、独立于主机的、自包含的,可以挂起在磁盘上,任意绑定到不同的机器,并透明地恢复。实用程序中的计算服务器运行一个小型的可信计算库,它像管理缓存一样管理计算胶囊。用户的胶囊可以在实用程序中的任何计算服务器上运行,并且通常在本地机器上运行,以增强交互性能。胶囊为用户提供可定制性以及与其他用户隔离的保证。作为可以共享、复制和版本控制的持久对象,胶囊可以很容易地管理和管理。与我们目前的环境相比,本实用新型具有显著的优势。首先,不是要求终端用户单独采购、管理和升级他们的设备,而是由专家共享和集中管理公用事业的资源,从而产生一个更有效的系统。其次,全局实用程序允许用户在任何地方有效地访问他们的计算环境。他们不需要处理大量不同的界面,也不需要处理每天往返于家庭和工作之间的不连续性。第三,一个专业管理的计算实用程序,旨在支持全球移动和共享,可以提供比我们目前的环境更高的安全性。相比之下,今天的新手用户负责保持他们的系统安全,缺乏对共享和移动性的足够支持导致了危及安全的做法。第四,公用事业的基础设施可以作为几个新兴计算趋势的优秀平台:由应用服务提供商远程托管的软件,对无处不在的访问设备的支持,以及大规模分布式计算。这个研究项目的目标是调查计算实用程序的可行性,并为这样的基础设施奠定技术基础。所开发的技术也可以应用于管理机构的分布式资源。首先,我们将通过研究胶囊的设计和应用来充分研究胶囊的概念。胶囊可以在机器、操作系统和应用程序级别实现;将研究这些不同方法之间的权衡。我们还将探索胶囊的新用途:胶囊可以用来运行不受信任的软件;它们可以为团队项目提供安全和共享的环境;胶囊也可以作为预先安装的软件包,随时可以在任何机器上运行。我们将开发相关工具,使胶囊易于使用。其次,我们将开发确保计算实用程序安全性的技术。安全性将在三个级别提供:一个小的可信内核,提供胶囊和监视器胶囊之间的隔离,以增加安全性;使用经过认证的胶囊来创建可信的计算环境;数据安全将由加密提供,共享将由灵活的密钥管理方案支持。我们计划对系统的漏洞进行仔细的分析。第三,这项研究将产生有助于创建可扩展、高效和易于维护的计算实用程序的技术。它们包括通过将机器视为胶囊的缓存来管理全球分布式环境中的机器的技术,以及结合胶囊缓存和远程显示技术以支持全球移动性和共享的技术。本研究将开发一个原型计算工具来验证所开发的技术。为了使广泛的实验成为可能,原型将支持遗留软件。这些实验将特别针对大学的信息技术需求而设计。计算机系统经历了两个主要时代,大型机的分时时代和个人计算时代。本研究的成功将开启一个新的计算实用时代,并对我们未来的计算实践产生重大影响。
英文摘要
Computing services in the future should become just as available and easy to use as any of the modernutilities: power, water, or telephone service. A compute utility should work reliably and invisibly,providing users with simple, efficient access to their data and individualized computing environmentsanywhere in the world. Data kept in the utility may be private, publicly available, or shared betweendesignated parties. Our proposed compute utility architecture is based on the idea of a compute capsule, which capturesthe entire logical state of an active computing environment. A capsule is portable, persistent,host-independent, self-contained and can be suspended on disk, arbitrarily bound to different machines,and transparently resumed. Compute servers in a utility run a small trusted computing base, whichmanages the compute capsules like a cache. Users' capsules can be run on any of the compute servers inthe utility and are typically run on local machines for enhanced interactive performance. Capsules provideusers with customizabililty as well as a guarantee of isolation from other users. As persistent objects thatcan be shared, duplicated and version-controlled, capsules can be easily managed and administered. The compute utility model has significant advantages over our current environment. First, instead ofrequiring end users to procure, administer and upgrade their equipment individually, resources of a utilityare shared and managed centrally by experts, thus resulting in a more efficient system. Second, a globalutility allows users efficient access to their computing environment everywhere. They need not juggle alarge number of different interfaces and deal with the discontinuities as they move between home and workevery day. Third, a professionally managed compute utility designed to support global mobility andsharing can provide greater security than our current environment. In contrast, today novice users areresponsible for keeping their systems secure, and the lack of adequate support for sharing and mobilityleads to practices that jeopardize security. Fourth, the infrastructure of a utility serves as an excellentplatform for several emerging computing trends: software hosted remotely by application serviceproviders, support of ubiquitous access devices, and large-scale distributed computing. The goal of this research project is to investigate the viability of a compute utility and to lay thetechnical foundation for such an infrastructure. The techniques developed can also be applied to manage aninstitution's distributed resources. First, we will investigate the concept of capsules fully by studying their design and applications.Capsules can be implemented at the machine, operating system and application level; trade-offs betweenthese different approaches will be studied. We will also explore novel uses of capsules: capsules can beused to run untrusted software; they can provide secure and shared environments for group projects;capsules can also serve as pre-installed software packages ready to run on any machine. We will developthe associated tools to make capsuleseasy to use. Second, we will develop the technologies to ensure security in a compute utility. Security will beprovided at three levels: a small trusted kernel that provides isolation between capsules and monitorscapsules for added security; the use of certified capsules to create trusted computing environments; datasecurity will be provided by encryption, and sharing will be supported by a flexible key managementscheme. We plan to conduct a careful analysis of the vulnerabilities of the system. Third, this research will produce the technologies useful for creating scalable, efficient, and easilymaintainable compute utilities. They include techniques for managing machines in a globally distributedenvironment by treating them as caches of capsules, and techniques that combine capsule caching andremote display technology to support global mobility and sharing. This research will develop a prototype compute utility to validate the technology developed. To makeextensive experimentation possible, the prototype will support legacy software. The experiments will bedesigned especially to address the information technology needs of universities. Computer systems have gone through two major eras, time-sharing on mainframes and personalcomputing. The success of this research may usher in a new era of compute utility and have a significantimpact on our future computing practice.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CNS Core: Large: Autonomy and Privacy with Open Federated Virtual Assistants
  • 批准号:
    1900638
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $300.0万
  • 财政年份:
    2019
  • 负责人:
    Monica Lam
  • 依托单位:
ITR: Software Design Rules
  • 批准号:
    0326227
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $130.0万
  • 财政年份:
    2003
  • 负责人:
    Monica Lam
  • 依托单位:
ITR: Static and Dynamic Tools for Software Design
  • 批准号:
    0086160
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $100.34万
  • 财政年份:
    2000
  • 负责人:
    Monica Lam
  • 依托单位:
Compiler Infrastructure: The SUIF Compiler Infrastructure
  • 批准号:
    9612757
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $50.1万
  • 财政年份:
    1996
  • 负责人:
    Monica Lam
  • 依托单位:
海外基金