电信科学 ›› 2013, Vol. 29 ›› Issue (6): 72-81.doi: 10.3969/j.issn.1000-0801.2013.06.012

• 研究与开发 • 上一篇    下一篇

一种面向云平台的虚拟机内存SLA审计机制

李攀攀,张宏莉,邓会敏,周志刚   

  1. 哈尔滨工业大学计算机科学与技术学院 哈尔滨150001
  • 出版日期:2013-06-20 发布日期:2017-07-18
  • 基金资助:
    国家自然科学基金资助项目;国家自然科学基金资助项目;国家重点基础研究发展计划(“973”计划)基金资助项目;国家高技术研究发展计划(“863”计划)基金资助项目

SLA Audit Mechanism of Virtual Machine Memory on Cloud

Panpan Li,Hongli Zhang,Huimin Deng,Zhigang Zhou   

  1. School of Computer Science and Engineering, Harbin Institute of Technology, Harbin 150001, China
  • Online:2013-06-20 Published:2017-07-18

摘要:

针对云计算的服务模式屏蔽了云租户的物理硬件视图,不可信的云服务提供商(cloud service provider, CSP)可能利用廉价的硬盘资源通过虚拟化技术,违背服务等级协议约定(service level agreement,SLA)按物理内存定价标准为云租户提供服务这一问题,为了审计CSP提供内存服务的SLA合约性,提出了由Xen层到物理硬件层的内存轻量级测量的SLA合约性审计方案。同时引入可信启动机制和HyperSentry用于保证审计系统的可信启动和完整性运行,提出了带云租户签名机制的Diffie-Hellman密钥交换协议支持策略安全和可信告警。实验结果表明,在虚拟机运行环境下该方法能高效地进行内存SLA合约性审计,同时具有较高的云租户自定义策略扩展性和较低的性能开销。

关键词: 云计算, 内存SLA, 审计, 虚拟化, Xen

Abstract:

Cloud service style has shield physical hardware view to cloud tenant, thus untrusted CSP(cloud service provider)may replace expensive physical memory by cheaper hard disk resource, which violates the SLA. Therefore, in order to audit memory SLA of cloud, a novel scheme for auditing physical memory of VM was proposed. This scheme is based on light-weight memory measurement SLA auditing by Xen layer to physical layer. Meanwhile, trust boot mechanism and HyperSentry module to ensure trust boot and integrity guarantee at running time were introduced. Then, digital signatures-based Diffie-Hellman key exchange protocol was also proposed to support strategy security exchange and trust alarm. The experimental results indicate that the proposed module can effectively audit VM memory SLA,and also support strong expansibility of cloud tenant customize strategy with low overhead.

Key words: cloud computing, memory SLA, audit, virtualization, Xen

No Suggested Reading articles found!