网络与信息安全学报 (Dec 2018)

VMI-based virtual machine remote attestation scheme

  • Wei WANG,Xin JIN,
  • Xingshu CHEN,
  • Xiao LAN

DOI
https://doi.org/10.11959/j.issn.2096-109x.2018098
Journal volume & issue
Vol. 4, no. 12
pp. 32 – 43

Abstract

Read online

The virtual machine attestation scheme proposed by trusted computing group (TCG) can provide attestation service of virtual machine for cloud computing.However,the service using the scheme proposed by the TCG directly would be threatened by the cuckoo attack and its performance would be lower.Therefore,a new virtual machine remote attestation scheme based on virtual machine introspection (VMI) was proposed.Firstly,it eliminated the path to perform cuckoo attacks in virtual machines via obtaining virtual machines′ remote attestation evidence in virtual machine monitor (VMM).Secondly,it used physical trusted platform module (TPM) to ensure the integrity of virtual machines’ remote attestation evidence and reduced the number of attestation identity key (AIK) certificates required during remote attestation to balance the load of private CA.Experiments show that the proposed scheme can verify the status of virtual machines correctly and increase the performance of bulk virtual machines’ remote attestation significantly.

Keywords