通信学报 ›› 2017, Vol. 38 ›› Issue (9): 31-38.doi: 10.11959/j.issn.1000-436x.2017180

• 学术论文 • 上一篇    下一篇

基于双层非平衡散列树的云平台远程验证方案

荣星1,2,沈昌祥2,江荣3,赵勇2   

  1. 1 解放军信息工程大学三院,河南 郑州450004
    2 北京工业大学计算机学院,北京 100124
    3 国防科技大学六院,湖南 长沙 410073
  • 修回日期:2017-06-09 出版日期:2017-09-01 发布日期:2017-10-18
  • 作者简介:荣星(1986-),男,安徽合肥人,解放军信息工程大学博士生,主要研究方向为网络安全、云计算。|沈昌祥(1940-),男,浙江奉化人,中国工程院院士,北京工业大学教授、博士生导师,主要研究方向为计算机信息系统、密码学、信息安全架构、系统软件安全及网络安全。|江荣(1984-),男,福建连城人,博士,国防科技大学助理研究员,主要研究方向为大数据隐私保护和网络空间安全。|赵勇(1980-),男,山西左权人,博士,北京工业大学讲师,主要研究方向为可信计算、安全操作系统。
  • 基金资助:
    国家高技术研究发展计划(“863”计划)基金资助项目(2015AA016002);国家重点研发计划基金资助项目(2016YFB0800804);国家重点研发计划基金资助项目(2016YFB0800303)

Remote attestation scheme for cloud platform based on double-layer unbalanced hash tree

Xing RONG1,2,Chang-xiang SHEN2,Rong JIANG3,Yong ZHAO2   

  1. 1 The 3rd Academy,PLA Information Engineering University,Zhengzhou 450004,China
    2 College of Computer Science,Beijing University of Technology,Beijing 100124,China
    3 The 6th Academy,National University of Defense Technology,Changsha 410073,China
  • Revised:2017-06-09 Online:2017-09-01 Published:2017-10-18
  • Supported by:
    The National High Technology Research and Development Program (863 Program) of China(2015AA016002);The National Key Research and Development Program(2016YFB0800804);The National Key Research and Development Program(2016YFB0800303)

摘要:

为验证云服务的可信性,提出一种改进的基于非平衡散列树的云平台远程验证方案。通过引入层级构建双层非平衡散列树,将原先的单一树扩展为主树和子树,二者分别对应云服务平台中的虚拟机和虚拟机中的运行组件,证明时仅需要提供待度量组件和认证路径。分析表明,该方案进一步提高了云平台的证明效率,并且具有较好的隐私保护能力和可伸缩性,能够很好地用于云服务的可信性证明。

关键词: 远程证明, 云计算, 非平衡散列树, 虚拟机

Abstract:

In order to validate the service of cloud,an improved remote attestation scheme based on unbalanced hash tree of cloud platform was proposed.Double-layer unbalanced hash tree was built by introducing layer,original single tree was expanded to main tree and sub tree,which corresponded to virtual machine in cloud platform and the running components in virtual machine.Attestation needs no more than measurement component and authentication path.The analysis shows that this scheme can increase the attestation efficiency of cloud platform,and is good at protecting privacy and expandability,which is suitable for validating cloud platform service.

Key words: remote attestation, cloud computing, unbalanced hash tree, virtual machine

中图分类号: 

No Suggested Reading articles found!