摘要
为了最大限度地确保Xen虚拟化系统的可信性和安全性,保护虚拟化系统的软件安全和用户隐私数据的安全,对Xen虚拟机及其安全性进行研究分析,结合可信计算技术着重于确保虚拟机启动阶段的可信性和安全性,实现Xen虚拟化环境整体的可信启动过程,并思考利用国密算法可行性和方法,降低对国外密码算法的依赖,避免国外算法存在的安全隐患。能够抵御文中所述的威胁模型并克服部分TPM的局限性,方法有效且可行,且可信启动效率较高。
In order to implement that the security and safety of the Xen virtual machine and user privacy data can be protected up to the hilt, this article will analyze the fundamental principle and safety of Xen virtual machine. Combined with the technique of trusted computing and native cipher algorithm, we focus our attention on ensuring the trust and security of the startup stage, and realize the trusted booting of Xen virtualization environment. Meanwhile, we will also take considerations of using native cipher algorithm. The use of the native cipher algorithm will greatly reduce the dependence on foreign cipher algorithm and avoid the hidden trouble of the foreign cipher algorithm. The method that is effective and feasible in this article can resist the threat model and overcome the limitations of TPM. The efficiency of the trust startup is high.
出处
《计算机安全》
2014年第11期2-7,14,共7页
Network & Computer Security
基金
国家科技支撑计划项目(项目编号:2013BAH15F03)