引用本文:李小庆,赵晓东,曾庆凯.基于硬件虚拟化的单向隔离执行模型.软件学报,2012,23(8):2207-2222
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 4232次   下载 6768 本文二维码信息
码上扫一扫!
分享到: 微信 更多
基于硬件虚拟化的单向隔离执行模型
李小庆1,2, 赵晓东1,2, 曾庆凯1,2
1.计算机软件新技术国家重点实验室(南京大学),江苏 南京 210093;2.南京大学 计算机科学与技术系,江苏 南京 210093
摘要:
提出了一种基于硬件虚拟化技术的单向隔离执行模型.在该模型中,安全相关的应用程序可以根据自身需求分离成宿主进程(host process)和安全敏感模块(security sensitive module,简称SSM)两部分.隔离执行器(SSMVisor)作为模型的核心部件,为SSM 提供了一个单向隔离的执行环境.既保证了安全性,又允许SSM 以函数调用的方式与外部进行交互.安全应用程序的可信计算基(trusted computing base,简称TCB)仅由安全敏感模块和隔离执行器构成,不再包括应用程序中的安全无关模块和操作系统,有效地削减了TCB 的规模.原型系统既保持了与原有操作系统环境的兼容性,又保证了实现的轻量级.实验结果表明,系统性能开销轻微,约为6.5%.
关键词:  隔离执行  硬件虚拟化  安全敏感模块  可信计算基
DOI:10.3724/SP.J.1001.2012.04131
分类号:
基金项目:国家自然科学基金(61170070, 60773170, 90818022, 61021062); 国家科技支撑计划(2012BAK26B01); 高等学校博士学科点专项科研基金(200802840002); 江苏省科技支撑计划(BE2010032)
One-Way Isolation Execution Model Based on Hardware Virtualization
LI Xiao-Qing1,2, ZHAO Xiao-Dong1,2, ZENG Qing-Kai1,2
1.State Key Laboratory for Novel Software Technology (Nanjing University), Nanjing 210093, China;2.Department of Computer Science and Technology, Nanjing University, Nanjing 210093, China
Abstract:
A one-way isolation execution model based on hardware virtualization is proposed. In this model, the security application based on self-requirements can be divided into two parts: host process and security sensitive module (SSM). Isolated execution manager named SSMVisor, as the core component of isolation execution model, provides a one-way isolation execution environment for SSMs, not only to ensure security, but also to allow SSMs to call outside functions. As security application’s trusted computing base (TCB) only includes SSMs and SSMVisor, without operating system and the security unrelated module of the applications, the size of security application’s TCB is reduced effectively. A prototype system is not only compatible with the original operating system, but also light-weight. Experimental results show that the performance overhead of prototype system is very low, about 6.5%.
Key words:  isolation execution  hardware virtualization  security sensitive module  TCB (trusted computing base)

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: