摘要
OpenSSH密钥数据保存在文件系统中,在主机遭受攻击后容易暴露,需要对这些重要数据进行保护。为此提出使用虚拟机将密钥数据保存到隔离空间,并提供安全访问方法。这种方式使得即使主机在被攻陷的时候,攻击人员仍然无法获得相应的秘钥信息。使用虚拟机的方式提供了一个完全隔离的安全空间,对OpenSSH秘钥数据起到了保护作用。
OpenSSH stores keys in the file system. The keys are easy to be exposed while the host has been invaded by illegal users. Methods are needed to protect these important data. For such purpose, virtual machine protection was proposed to provide a separate space for storing the important data as well as secure accessing interfaces. By using virtual machine even under the situation that the host is compromised, the important data can still be kept safe. Thus, the safe and separate space provided by virtual machine can protect the keys of OpenSSH securely.
出处
《通信学报》
EI
CSCD
北大核心
2009年第2期1-5,共5页
Journal on Communications
基金
国家重点基础研究发展计划("973"计划)基金资助项目(2007CB310900)
国家高技术研究发展计划("863"计划)基金资助项目(2008AA01Z112)
国家自然科学基金资助项目(90718040
60603071)~~
关键词
虚拟机
密钥
数据隔离
virtual machine
private key
data isolation