Title
H-SVM: Hardware-assisted Secure Virtual Machines under a Vulnerable Hypervisor
Abstract
With increasing demands on cloud computing, protecting guest virtual machines (VMs) from malicious attackers has become critical to provide secure services. The current cloud security model with software-based virtualization relies on the invulnerability of the software hypervisor and its trustworthy administrator with the root permission. However, compromising the hypervisor with remote attacks or root permission grants the attackers with a full access capability to the memory and context of a guest VM. This paper proposes a HW-based approach to protect guest VMs even under an untrusted hypervisor. With the proposed mechanism, memory isolation is provided by the secure hardware, which is much less vulnerable than the software hypervisor. The proposed mechanism extends the current hardware support for memory virtualization based on nested paging with a small extra hardware cost. The hypervisor can still flexibly allocate physical memory pages to virtual machines for efficient resource management. In addition to the system design for secure virtualization, this paper presents a prototype implementation using system management mode. Although the current system management mode is not intended for security functions and thus limits the performance and complete protection, the prototype implementation proves the feasibility of the proposed design.
Year
DOI
Venue
2015
10.1109/TC.2015.2389792
IEEE Transactions on Computers
Keywords
Field
DocType
Cloud computing, security, virtualization
Virtualization,Virtual machine,Computer science,Hypervisor,Real-time computing,Full virtualization,Computer hardware,Hardware virtualization,Storage hypervisor,Parallel computing,Memory virtualization,Operating system,Cloud computing,Embedded system
Journal
Volume
Issue
ISSN
PP
99
0018-9340
Citations 
PageRank 
References 
4
0.41
17
Authors
6
Name
Order
Citations
PageRank
Seongwook Jin120110.24
Jeongseob Ahn216010.32
Jinho Seol3313.70
Sanghoon Cha4583.63
Jaehyuk Huh5100863.91
Seungryoul Maeng673047.58