云计算
计算机科学
可信计算
计算机安全
回降
操作系统
管理程序
虚拟机
架空(工程)
密码学
实施
虚拟化
数据库
软件工程
数据库事务
作者
Juan Wang,Jie Wang,Chengyang Fan,Fei Yan,Yueqiang Cheng,Yinqian Zhang,Wenhui Zhang,Mengda Yang,Hongxin Hu
出处
期刊:IEEE Transactions on Cloud Computing
[Institute of Electrical and Electronics Engineers]
日期:2023-02-10
卷期号:11 (3): 2936-2953
被引量:9
标识
DOI:10.1109/tcc.2023.3243891
摘要
Virtual Trusted Platform Modules (vTPMs) are widely used in commercial cloud platforms (e.g., VMware Cloud, Google Cloud, and Microsoft Azure) to provide virtual root-of-trust and security services for virtual machines. Unfortunately, current state-of-the-art vTPM implementations for cloud computing cannot provide strong protection for vTPMs at run-time and suffer from poor performance under binding vTPMs to a physical TPM. In this paper, we propose SvTPM, an SGX-based virtual trusted platform module, which provides complete life cycle protection of vTPMs in the cloud and does not rely on the physical TPM. SvTPM provides strong isolation protection so malicious cloud tenants or even cloud administrators cannot access vTPM's private keys or any other sensitive data. In this paper, we implement a prototype of SvTPM, which identifies and solves a couple of critical security challenges for vTPM protection with SGX, such as NVRAM rollback attacks, NVRAM binding attacks, and vTPM rollback attacks. SvTPM also shows how to establish trust between vTPM and SGX Platform. Our performance evaluation shows that the NVRAM launch time of SvTPM is $1700\times$ faster than vTPM built upon hardware TPM. In TPM standard command evaluation, we find that SvTPM incurs negligible performance overhead while providing strong isolation and protection. To our knowledge, SvTPM is the first practical work to solve the critical security challenges of securing vTPM using SGX.
科研通智能强力驱动
Strongly Powered by AbleSci AI