Abstract
Infrastructure-as-a-Service (IaaS) is a widespread cloud computing provisioning model where ICT infrastructure, including servers, storage and networking, is supplied on-demand, in a pay-as-you-go fashion. IaaS cloud providers give their clients virtual machines (VMs) that are controlled by cloud administrators who can run, stop, restore and migrate the VMs. A typical threat to IaaS is unauthorized access of untrustworthy administrators to cloud users' sensitive information residing in VMs' memory. In this paper we focus on the threat of users' cryptographic keys being stolen from the RAM of the VM they provision. We propose a decrypt-scatter/gather-decrypt technique that allows users to carry our encryption/decryption while protecting keys from unauthorized peeks on the part of cloud administrators. Our technique does not require modification to the current cloud architecture, but only the availability of a Trusted Platform Module (TPM) capable of creating and holding a TPM-protected public/private key pair. It lends itself to security-as-a-service scenarios where third parties perform encryption/decryption on behalf of data owners.
| Original language | British English |
|---|---|
| Title of host publication | Proceedings - 2015 IEEE/ACM 8th International Conference on Utility and Cloud Computing, UCC 2015 |
| Editors | Omer Rana, Rajkumar Buyya, Ioan Raicu |
| Publisher | Institute of Electrical and Electronics Engineers Inc. |
| Pages | 397-401 |
| Number of pages | 5 |
| ISBN (Electronic) | 9780769556970 |
| DOIs | |
| State | Published - 2015 |
| Event | 8th IEEE/ACM International Conference on Utility and Cloud Computing, UCC 2015 - Limassol, Cyprus Duration: 7 Dec 2015 → 10 Dec 2015 |
Publication series
| Name | Proceedings - 2015 IEEE/ACM 8th International Conference on Utility and Cloud Computing, UCC 2015 |
|---|
Conference
| Conference | 8th IEEE/ACM International Conference on Utility and Cloud Computing, UCC 2015 |
|---|---|
| Country/Territory | Cyprus |
| City | Limassol |
| Period | 7/12/15 → 10/12/15 |
UN SDGs
This output contributes to the following UN Sustainable Development Goals (SDGs)
-
SDG 9 Industry, Innovation, and Infrastructure
Keywords
- Cloud Computing
- code obfuscation
- encryption key
- memory protection
- VM RAM security
Fingerprint
Dive into the research topics of 'Securing Cryptographic Keys in the IaaS Cloud Model'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver