SvTPM: SGX-Based Virtual Trusted Platform Modules for Cloud Computing

云计算 计算机科学 可信计算 计算机安全 回降 操作系统 管理程序 虚拟机 架空(工程) 密码学 实施 虚拟化 数据库 软件工程 数据库事务
作者
Juan Wang,Jie Wang,Chengyang Fan,Fei Yan,Yueqiang Cheng,Yinqian Zhang,Wenhui Zhang,Mengda Yang,Hongxin Hu
出处
期刊:IEEE Transactions on Cloud Computing [Institute of Electrical and Electronics Engineers]
卷期号:11 (3): 2936-2953 被引量:9
标识
DOI:10.1109/tcc.2023.3243891
摘要

Virtual Trusted Platform Modules (vTPMs) are widely used in commercial cloud platforms (e.g., VMware Cloud, Google Cloud, and Microsoft Azure) to provide virtual root-of-trust and security services for virtual machines. Unfortunately, current state-of-the-art vTPM implementations for cloud computing cannot provide strong protection for vTPMs at run-time and suffer from poor performance under binding vTPMs to a physical TPM. In this paper, we propose SvTPM, an SGX-based virtual trusted platform module, which provides complete life cycle protection of vTPMs in the cloud and does not rely on the physical TPM. SvTPM provides strong isolation protection so malicious cloud tenants or even cloud administrators cannot access vTPM's private keys or any other sensitive data. In this paper, we implement a prototype of SvTPM, which identifies and solves a couple of critical security challenges for vTPM protection with SGX, such as NVRAM rollback attacks, NVRAM binding attacks, and vTPM rollback attacks. SvTPM also shows how to establish trust between vTPM and SGX Platform. Our performance evaluation shows that the NVRAM launch time of SvTPM is $1700\times$ faster than vTPM built upon hardware TPM. In TPM standard command evaluation, we find that SvTPM incurs negligible performance overhead while providing strong isolation and protection. To our knowledge, SvTPM is the first practical work to solve the critical security challenges of securing vTPM using SGX.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
PDF的下载单位、IP信息已删除 (2025-6-4)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
皇家搓澡师完成签到,获得积分10
1秒前
过时的冰淇淋完成签到,获得积分10
3秒前
4秒前
4秒前
orixero应助liuzong采纳,获得10
5秒前
香蕉觅云应助顾宇采纳,获得10
5秒前
6秒前
8秒前
威威发布了新的文献求助10
8秒前
8秒前
仲乔妹发布了新的文献求助10
9秒前
Panini发布了新的文献求助10
9秒前
维维发布了新的文献求助10
9秒前
姜彦乔发布了新的文献求助10
10秒前
我是老大应助如风随水采纳,获得10
10秒前
actor2006完成签到,获得积分10
11秒前
13秒前
SIHUONIANHUA发布了新的文献求助10
13秒前
笨笨中心应助万松辉采纳,获得10
13秒前
14秒前
15秒前
Panini完成签到,获得积分10
15秒前
17秒前
17秒前
18秒前
量子星尘发布了新的文献求助10
18秒前
19秒前
SIHUONIANHUA完成签到,获得积分20
20秒前
seven完成签到,获得积分10
20秒前
22秒前
昌雪琴发布了新的文献求助30
22秒前
22秒前
zf发布了新的文献求助10
22秒前
yu完成签到,获得积分10
22秒前
如风随水发布了新的文献求助10
23秒前
orixero应助鱼鱼子999采纳,获得10
23秒前
23秒前
23秒前
seven发布了新的文献求助10
24秒前
兰胖子发布了新的文献求助10
24秒前
高分求助中
The Mother of All Tableaux Order, Equivalence, and Geometry in the Large-scale Structure of Optimality Theory 2400
Ophthalmic Equipment Market by Devices(surgical: vitreorentinal,IOLs,OVDs,contact lens,RGP lens,backflush,diagnostic&monitoring:OCT,actorefractor,keratometer,tonometer,ophthalmoscpe,OVD), End User,Buying Criteria-Global Forecast to2029 2000
Optimal Transport: A Comprehensive Introduction to Modeling, Analysis, Simulation, Applications 800
Official Methods of Analysis of AOAC INTERNATIONAL 600
ACSM’s Guidelines for Exercise Testing and Prescription, 12th edition 588
T/CIET 1202-2025 可吸收再生氧化纤维素止血材料 500
Comparison of adverse drug reactions of heparin and its derivates in the European Economic Area based on data from EudraVigilance between 2017 and 2021 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 冶金 细胞生物学 免疫学
热门帖子
关注 科研通微信公众号,转发送积分 3952646
求助须知:如何正确求助?哪些是违规求助? 3498064
关于积分的说明 11090366
捐赠科研通 3228670
什么是DOI,文献DOI怎么找? 1785032
邀请新用户注册赠送积分活动 869081
科研通“疑难数据库(出版商)”最低求助积分说明 801349