This paper proposes a novel secure live virtual machine migration framework by using a virtual trusted platform module instance to improve the integrity of the migration process from one virtual machine to another on the same platform. The proposed framework, called Koror\=a, is designed and developed on a public infrastructure-as-a-service cloud-computing environment and runs concurrently on the same hardware components (Input/Output, Central Processing Unit, Memory) and the same hypervisor (Xen); however, a combination of parameters needs to be evaluated before implementing Koror\=a. The implementation of Koror\=a is not practically feasible in traditional distributed computing environments. It requires fixed resources with high-performance capabilities, connected through a high-speed, reliable network. The following research objectives were determined to identify the integrity features of live virtual machine migration in the cloud system: To understand the security issues associated with cloud computing, virtual trusted platform modules, virtualization, live virtual machine migration, and hypervisors; To identify the requirements for the proposed framework, including those related to live VM migration among different hypervisors; To design and validate the model, processes, and architectural features of the proposed framework; To propose and implement an end-to-end security architectural blueprint for cloud environments, providing an integrated view of protection mechanisms, and then to validate the proposed framework to improve the integrity of live VM migration. This is followed by a comprehensive review of the evaluation system architecture and the proposed framework state machine. The overarching aim of this paper, therefore, is to present a detailed analysis of the cloud computing security problem, from the perspective of cloud architectures and the cloud... [Abridged]
翻译:本文提出一个新的安全现场虚拟机器迁移框架,方法是使用虚拟信任平台模块,提高从一台虚拟机器到同一平台上另一个虚拟机器迁移过程的完整性。拟议框架称为Koor ⁇ a,是在一个公共基础设施-服务性云计算环境中设计和开发的,同时运行于同一个硬件部件(投入/产出、中央处理股、记忆)和高官(Xen);然而,在实施Koor ⁇ a之前,需要评估各种参数的组合。在传统的分布式云层计算环境中,实施Koor ⁇ a并不实际可行。它需要具备高性能的固定资源,通过高速、可靠的网络连接。以下研究目标是确定云系统现场虚拟机器迁移的完整性特征:理解与云计算、虚拟信任平台模块、虚拟化、虚拟机器迁移实时迁移和超高官(Xen);然而,在拟议框架实施之前,为不同高压电流计算系统进行现场迁移,设计和验证模型、流程和建筑结构特征,为当前安全结构的完整框架提供一个蓝图,然后为最终的建筑框架提供一个蓝图,为当前的安全性框架提供一个蓝图, 向最终评估,为当前的结构框架提供和结构结构框架的改进。