{"title":"Dynamic Remote Attestation Service for Virtual Machine on the IaaS Cloud Platform","authors":"Huaizhe Zhou, Haihe Ba, Jiangchun Ren, Yong Chen, Yongjun Wang, Zhiying Wang","doi":"10.1109/ICNISC.2017.00017","DOIUrl":null,"url":null,"abstract":"While the Infrastructure-as-a-Service (IaaS) cloud computing model has become a compelling computing solution, the security concerns on the data and application integrity in the virtual machines (VMs) have drastically restricted its widespread adoption. Although numerous researches have been dedicated to deal with the aforementioned issues, it still remains a challenge for now. In this paper, we present DRAS, a novel framework for remote attestation on VMs in IaaS cloud. It combines trusted computing with virtual machine introspection to provide flexible measurement for targeted VMs in a stealthy manner, which is more robust to malicious attackers. Moreover, we minimize the impact on platform performance and reduce trusted computing base by separating integrity measurement and attestation service from privileged domain to a dedicated secure VM. We show a concrete implementation of DRAS and a prototype based on Xen hypervisor.","PeriodicalId":429511,"journal":{"name":"2017 International Conference on Network and Information Systems for Computers (ICNISC)","volume":"5004 2 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-04-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 International Conference on Network and Information Systems for Computers (ICNISC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICNISC.2017.00017","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
While the Infrastructure-as-a-Service (IaaS) cloud computing model has become a compelling computing solution, the security concerns on the data and application integrity in the virtual machines (VMs) have drastically restricted its widespread adoption. Although numerous researches have been dedicated to deal with the aforementioned issues, it still remains a challenge for now. In this paper, we present DRAS, a novel framework for remote attestation on VMs in IaaS cloud. It combines trusted computing with virtual machine introspection to provide flexible measurement for targeted VMs in a stealthy manner, which is more robust to malicious attackers. Moreover, we minimize the impact on platform performance and reduce trusted computing base by separating integrity measurement and attestation service from privileged domain to a dedicated secure VM. We show a concrete implementation of DRAS and a prototype based on Xen hypervisor.