摘要
提出一种IaaS(infrastructure as a service)完整性度量协议,该协议允许租户主动发起对IaaS资源的度量和验证,使租户能够检测其自身资源的完整性状态,增强IaaS资源状态的可见性.利用SVO逻辑对协议的安全性、完备性进行了分析,并搭建实验平台对协议的抗攻击能力和时间性能进行了验证.分析和实验证明,该协议能够抵御重放攻击、假冒攻击等多种形式的攻击,同时协议的执行耗时不会影响租户的正常使用体验.
This paper presents a protocol of integrity measurement of IaaS resource. It allows users to launch a measurement and verification of their IaaS sources ,which makes IaaS integrity state more visible to users. The protocol is analyzed by SVO logics and verified by an experiment. The protocol is proved to meet the goals and resist many attacks and the experiment results show that the protocol executes in a very short time which cannot have much affect on user experience.
出处
《武汉大学学报(理学版)》
CAS
CSCD
北大核心
2014年第5期386-392,共7页
Journal of Wuhan University:Natural Science Edition
基金
国家重点基础研究发展计划(973)项目(2014CB340600)
国家自然科学基金重点项目(61332019)
国家自然科学基金(61173138
61272452
61103220)
湖北省重点新产品新工艺研究开发项目(2012BAA03004)
华为研究基金(YB2012120174
YB2013110084)资助项目
关键词
IAAS
资源完整性
度量
协议
IaaS(infrastructure as a service)
integrity measure
protocol