摘要
针对Iaa S(infrastructure as a service)环境下虚拟机通信数据在共享网络基础设施中的安全性问题,提出了一种虚拟机无代理通信加密机制。该机制通过加载于虚拟化节点内的加密模块与平台统一加密控制器间的协作,实现了Iaa S环境下虚拟机通信无代理按需加密;同时,引入通信加密策略有效性保障机制,保障了虚拟机全生命周期内的通信加密策略有效性。实验结果表明,该机制在引入较小性能开销的前提下,可以有效实现虚拟机通信加密,并保障虚拟机全生命周期内加密策略的有效性。
To ensure the security of communication data of virtual machine in Iaa S environment adopting shared network infrastructure,this paper proposed an agentless communication encryption framework for virtual machine in Iaa S environment.Through the cooperation between an encryption module which was loaded in virtualization node and a platform unified encryption controller,it implemented the agentless communication encryption for virtual machine in Iaa S. Moreover,this paper developed a mechanism for effectiveness of communication encryption policy to ensure the effectiveness of communication encryption policy in the whole life cycle of virtual machine. The results show that the framework can encrypt communication data of virtual machine on-demand and ensure the effectiveness of encryption policy in the whole life cycle of virtual machine,while introducing a few overhead.
出处
《计算机应用研究》
CSCD
北大核心
2016年第3期855-859,共5页
Application Research of Computers
基金
国家科技支撑计划资助项目(2012BAH18B05)