摘要
云计算环境下,服务资源分布广泛、迁移频繁,资源之间的信任关系不易建立与维护。传统的可信计算远程验证方法存在性能瓶颈和计算复杂等问题。在研究云服务资源信任验证方法的基础上,提出一种属性协商的远程验证方法。采用环签名算法和基于属性的敏感信息保护机制,提高了信任验证计算效率,减小了敏感信息泄露的风险。设计的安全模型证明了方法的安全性。通过Hadoop平台下的实验,验证了方法的有效性和可行性。
In cloud computing, the resources of service are widely distributed and migrated frequently. The trust rela- tionship between them is hard to establish and maintain. There are some problems for traditional remote attestation based on trust computing, such as performance bottleneck and computational-complexity. This article proposed a novel remote attestation mechanism based on property negotiation in cloud computing. According to the ring signature algo- rism and sensitive property-based protection, this mechanism promotes the computational efficiency and reduces the leakage risk of sensitive property. Security of the mechanism is verified by security model. Validity and feasibility are tested by the experiment on Hadoop platform.
出处
《计算机科学》
CSCD
北大核心
2013年第7期107-112,共6页
Computer Science
基金
国家"十一五"科技支撑计划项目(2006BAF01A00)资助
关键词
云计算
可信计算
远程证明
环签名
自动信任协商
Cloud computing, Trust computing, Remote attestation, Ring signature, Automated trust negotiation