Journal on Communications ›› 2017, Vol. 38 ›› Issue (9): 65-75.doi: 10.11959/j.issn.1000-436x.2017183

• Papers • Previous Articles     Next Articles

Security-enhanced live migration based on SGX for virtual machine

Yuan SHI1,2,Huan-guo ZHANG1,2,Bo ZHAO1,2,Zhao YU1,2   

  1. 1 School of Computer,Wuhan University,Wuhan 430072,China
    2 Key Laboratory of Aerospace Information Security and Trusted Computing Ministry of Education,Wuhan University,Wuhan 430072,China
  • Revised:2017-02-22 Online:2017-09-01 Published:2017-10-18
  • Supported by:
    The National Natural Science Foundation of China(61332019);The National Basic Research Program of China (973 Program)(2014CB340600);The National High Technology Research and Development Program of China (863 Pro-gram)(2015AA016002)

Abstract:

The virtual machine may face the problem of information leakage in live migration.Therefore,a dynamic memory protection technique SGX was introduced and a security enhancement live migration method based on KVM environment was proposed.Firstly,on both sides of migration,a hardware-isolated secure execution environment centered SGX was built.It guaranteed the security of operations like encryption and integrity measurement and also ensured the security of private data.An encrypted channel to transfer migration data based on the remote attestation between the secure execution environments of both migration sides was constructed.And the mutual authentication of both sides’ platform integrity was realized.Finally,the security enhancement effect and did the experiment was analyzed.The results shows that the introduction of SGX won’t cause much negative effect to the migration performance.

Key words: virtualization, live migration, Intel SGX, remote attestation, integrity measurement

CLC Number: 

No Suggested Reading articles found!