SvTPM: SGX-Based Virtual Trusted Platform Modules for Cloud Computing

云计算 计算机科学 可信计算 计算机安全 回降 操作系统 管理程序 虚拟机 架空(工程) 密码学 实施 虚拟化 数据库 软件工程 数据库事务
作者
Juan Wang,Jie Wang,Chengyang Fan,Fei Yan,Yueqiang Cheng,Yinqian Zhang,Wenhui Zhang,Mengda Yang,Hongxin Hu
出处
期刊:IEEE Transactions on Cloud Computing [Institute of Electrical and Electronics Engineers]
卷期号:11 (3): 2936-2953 被引量:9
标识
DOI:10.1109/tcc.2023.3243891
摘要

Virtual Trusted Platform Modules (vTPMs) are widely used in commercial cloud platforms (e.g., VMware Cloud, Google Cloud, and Microsoft Azure) to provide virtual root-of-trust and security services for virtual machines. Unfortunately, current state-of-the-art vTPM implementations for cloud computing cannot provide strong protection for vTPMs at run-time and suffer from poor performance under binding vTPMs to a physical TPM. In this paper, we propose SvTPM, an SGX-based virtual trusted platform module, which provides complete life cycle protection of vTPMs in the cloud and does not rely on the physical TPM. SvTPM provides strong isolation protection so malicious cloud tenants or even cloud administrators cannot access vTPM's private keys or any other sensitive data. In this paper, we implement a prototype of SvTPM, which identifies and solves a couple of critical security challenges for vTPM protection with SGX, such as NVRAM rollback attacks, NVRAM binding attacks, and vTPM rollback attacks. SvTPM also shows how to establish trust between vTPM and SGX Platform. Our performance evaluation shows that the NVRAM launch time of SvTPM is $1700\times$ faster than vTPM built upon hardware TPM. In TPM standard command evaluation, we find that SvTPM incurs negligible performance overhead while providing strong isolation and protection. To our knowledge, SvTPM is the first practical work to solve the critical security challenges of securing vTPM using SGX.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
小轩完成签到,获得积分10
1秒前
1秒前
李健的小迷弟应助123采纳,获得10
1秒前
1秒前
贪玩的戒指完成签到,获得积分10
1秒前
2秒前
2秒前
正版小魏完成签到,获得积分20
3秒前
sss发布了新的文献求助10
3秒前
某某某发布了新的文献求助10
4秒前
结实的老虎完成签到,获得积分10
5秒前
彭于晏应助天水张家辉采纳,获得10
5秒前
马飞完成签到,获得积分10
5秒前
5秒前
你哈完成签到 ,获得积分10
6秒前
azw完成签到,获得积分10
6秒前
吴彦祖发布了新的文献求助10
6秒前
槿忆萱影应助高高的戎采纳,获得10
6秒前
7秒前
7秒前
8秒前
我不爱池鱼应助lwypku采纳,获得10
8秒前
DHW完成签到,获得积分10
8秒前
VCC完成签到,获得积分20
8秒前
8秒前
123456完成签到,获得积分10
8秒前
starry完成签到,获得积分10
8秒前
WFF发布了新的文献求助10
9秒前
滋达不溜完成签到,获得积分10
9秒前
Rogerlee完成签到,获得积分10
11秒前
11秒前
酷炫斓发布了新的文献求助10
12秒前
VCC发布了新的文献求助10
12秒前
郑明明完成签到,获得积分10
12秒前
lixiaohe908发布了新的文献求助30
12秒前
Aries发布了新的文献求助30
13秒前
虚心以丹完成签到,获得积分10
13秒前
13秒前
13秒前
半分青完成签到,获得积分10
14秒前
高分求助中
Licensing Deals in Pharmaceuticals 2019-2024 3000
Effect of reactor temperature on FCC yield 2000
Very-high-order BVD Schemes Using β-variable THINC Method 1020
PraxisRatgeber: Mantiden: Faszinierende Lauerjäger 800
Near Infrared Spectra of Origin-defined and Real-world Textiles (NIR-SORT): A spectroscopic and materials characterization dataset for known provenance and post-consumer fabrics 610
Mission to Mao: Us Intelligence and the Chinese Communists in World War II 600
Promoting women's entrepreneurship in developing countries: the case of the world's largest women-owned community-based enterprise 500
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 催化作用 物理化学 免疫学 量子力学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 3305153
求助须知:如何正确求助?哪些是违规求助? 2939026
关于积分的说明 8491012
捐赠科研通 2613498
什么是DOI,文献DOI怎么找? 1427461
科研通“疑难数据库(出版商)”最低求助积分说明 663007
邀请新用户注册赠送积分活动 647648