Security-enhanced cloud VPN with SGX and enclave migrationSGX를 이용한 클라우드 가상사설망의 보안 강화 및 Enclave 마이그레이션 기법 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 344
  • Download : 0
This dissertation presents a security-enhanced cloud Virtual Private Network (VPN) with Software Guard Extensions (SGX) and enclave migration. Cloud VPN is an essential cloud-based network infrastructure that connects on-premise networks with Virtual Private Cloud (VPC) networks securely. However, in the semi-trusted cloud environment cloud VPN suffers from privacy concerns due to the information disclosure caused by hypervisor vulnerabilities, malicious cloud management operations, etc. The existing literature has limitations in providing each tenant with the privacy-protected cloud VPN because the weak isolation of executing the VPN service in the shared environment does not defense attacks under the semi-trusted cloud environment. We present SGX-VPN, a security-enhanced cloud VPN with SGX. With the hardware-assisted isolated execution environment and the isolated memory region that SGX supports, SGX-VPN provides each tenant with the privacy-protected key exchange and packet processing. SGX-VPN also provides each tenant with an on-demand functionality to verify the integrity of the running security policies in cloud VPN. We implement a prototype on an actual machine to measure the performance penalties of SGX-VPN. We also evaluate SGX-VPN using a formal analysis tool to prove the security of SGX-VPN. However, there is still a challenging problem with imposing SGX into cloud VPN because existing SGX-enabled Virtual Machine Managers (VMMs) do not provide live migration of SGX-enabled VMs. This management operation is impossible because the VMM cannot directly access the Enclave Page Cache (EPC) pages where the VM’s enclaves reside. We propose an SGX extension for migrating enclaves called eMotion that adds additional instructions and migration support to the SGX architecture for enabling the secure managed migration of running enclaves. eMotion allows that the participating hosts establish a key used in enclave migration and the VMMs in the hosts migrate running enclaves using the established key. We implement a prototype on top of OpenSGX, an open source SGX emulator, to demonstrate the operations of eMotion and to estimate the impact on enclave migration.
Advisors
Kim, Kwangjoresearcher김광조researcher
Description
한국과학기술원 :정보보호대학원,
Publisher
한국과학기술원
Issue Date
2019
Identifier
325007
Language
eng
Description

학위논문(박사) - 한국과학기술원 : 정보보호대학원, 2019.8,[vi, 68 p. :]

Keywords

Cloud computing▼aVPN▼aSGX▼amigration▼aIKE▼aIPsec; 클라우드 컴퓨팅▼a가상사설망▼a마이그레이션▼a키교환▼a패킷처리

URI
http://hdl.handle.net/10203/283330
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=871505&flag=dissertation
Appears in Collection
IS-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0