Unlock instant, AI-driven research and patent intelligence for your innovation.

An Active Remote Attestation Method for Cloud Platform Virtual Machine Metrics

A remote attestation, virtual machine technology, applied in the field of remote attestation for virtual machine trusted state detection, can solve the problems of not taking into account the dynamic measurement of virtual machines, the uncertainty of the number of virtual machines, the limited number of TPMPCRs, etc., to prevent logs The effect of information leakage

Active Publication Date: 2017-02-22
WUHAN UNIV
View PDF4 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0005] Under the cloud computing platform, there are two problems in the remote proof of the state of the virtual machine compared with the traditional remote proof: 1. The number of virtual machines is uncertain
However, generally speaking, a server has only one TPM (Trusted Platform Module) chip, and the number of PCRs of the TPM is limited, usually up to 24
Therefore, the traditional remote attestation method writes the metric value into the PCR of the TPM, and then performs signature and trusted state verification, which cannot meet the dynamic and scalable needs of the virtualization platform.
2. Dynamic metrics of virtual machines require active remote attestation
Therefore, in the distributed environment of the cloud platform, it is difficult for the remote attestation server to synchronize the client to send remote attestation requests for trusted verification
[0006] For remote attestation on cloud platforms, literature [1~3] has enhanced the security of TCG remote attestation protocol, literature [4,5] proposed an attribute-based cloud computing remote attestation method, literature [6~9] The trusted measurement and remote attestation mechanism of the Host and the virtual machine manager (VMM) running on the virtual machine in the cloud platform are studied, but the above research work does not take into account the dynamic measurement of the virtual machine in the protocol design, so the remote attestation is still The passive remote proof method in which the server sends a request to the client and then the client responds

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • An Active Remote Attestation Method for Cloud Platform Virtual Machine Metrics
  • An Active Remote Attestation Method for Cloud Platform Virtual Machine Metrics
  • An Active Remote Attestation Method for Cloud Platform Virtual Machine Metrics

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0024] The technical solution of the present invention will be described in detail below in conjunction with the drawings and embodiments.

[0025]When the virtual machine starts, the virtual machine statically measures the state of its own platform, triggers remote attestation, forms an integrity report and verifies it. The virtual machine remote certification application scenario diagram of the embodiment is as follows figure 1 As shown, the scene description is as follows:

[0026] (1) The user applies to the cloud platform management terminal to use the virtual machine, and the cloud platform management terminal is generally implemented by server technology, that is, a cloud management server is provided. During specific implementation, the cloud management server is generally provided with a virtual machine management part, a key center, a trusted data center and a trusted verification part.

[0027] (2) After receiving the user's request, the cloud platform management ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention provides an active remote attestation method for the measurement of a cloud platform virtual machine. The active remote attestation method comprises the active operation process of a remote attestation client-side and the server trusted authentication process of a cloud management side, wherein static measurement is carried out after the cloud platform virtual machine is started, periodic dynamic measurement is carried out after running, active remote attestation is carried out after measurement is finished, and measurement values and measurement reports are obtained by the cloud management side and then the measurement values are compared with reference values to authenticate whether the state of the virtual machine is changed or not. The traditional passive remote attestation method is changed by the method, the remote attestation client-side is actively triggered by a measurement module, the measurement results are sent to the cloud management server side in real time, and the measurement values do not need to be stored in a PCR of a TPM, so that a remote attestation problem about the dynamic varied measurement and the regular dynamic measurement of the virtual machine in the cloud platform is solved.

Description

technical field [0001] The invention belongs to the technical field of information security, and relates to a remote attestation method aimed at detecting the trustworthy state of a virtual machine. Background technique [0002] The Trusted Computing Platform provides the ability to attest to external entities, known as remote attestation. The trusted computing platform has three roots of trust, which are root of trusted measurement, root of trusted storage, and root of trusted reporting, and supports three core functions of trusted measurement, trusted storage, and trusted reporting. These three core functions The existence of , enables the trusted computing platform to report the identity and status of the platform to external entities, and remote attestation is essentially an extension of the concept of trusted reporting. [0003] Remote attestation is a comprehensive measurement of the platform to prove to the remote communication party that its own operating environmen...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L9/32H04L29/08
Inventor 王鹃周司珺王江严飞赵波张焕国
Owner WUHAN UNIV