A virtual machine group-oriented TPM system for trusted cloud computing
摘要
Though virtual Trusted Platform Module (vTPM) make trusted computing technology compatible with virtualization in individual computers, vTPM does not fit well into the paradigm of cloud computing. Integration of trusted computing technology and cloud computing naturally requires to support the abstraction of Virtual Machine Group (VMG). vTPM is not sufficient for this purpose because each vTPM is bound to a single virtual machine, and the vTPMs bound to a set of virtual machines allocated to the same customer are deemed independent. This not only incurs inconvenience in supporting inter-vTPM cooperations, but also leads to security vulnerabilities. To bridge this gap, we propose TPM for cloud (TPMc), which is bound to a virtual machine group that may be allocated to the same customer or different customers who need the virtual machines to collaborate with each other. We give the detailed implementation of a TPMc prototype system, evaluate the performance of TPMc through extensive testing, and demonstrate that TPMc achieve a significant time-cost reduction, exceeding about 50% in seal and unseal operation, 60% in extend operation.