Enhancing security of cloud service systems by leveraging hardware-based isolation technology클라우드 서비스 시스템의 보안성 강화를 위한 하드웨어 기반 격리 기술 활용에 대한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 134
  • Download : 0
Hardware-based isolation technologies have been utilized within a cloud environment to satisfy the demands for secure and scalable security services. However, a naïve adoption of hardware-based isolation fails to protect on-cloud services against emerging security threats arising from the untrusted nature of a cloud environment. Also, it is challenging to apply hardware-based isolation to legacy on-cloud services while considering security, flexibility, scalability, and performance, as this requires expertise in multiple domains. In this dissertation, we argue that providing high-level abstractions of hardware-based isolation encapsulating security-sensitive components helps in implementing secure and scalable on-cloud services. To substantiate our claim, we present the design and implementation of two security service systems. First, we show EVE, a secure middlebox framework that enables visibility on encrypted traffic over multiple encryption protocols. EVE securely processes encrypted traffic leveraging a combination of trusted execution environment (TEE) and software security technology, and provides high-level abstractions for the secure middlebox processing. EVE abstractions relieve engineering efforts while supporting diverse use cases with multiple encryption protocols. Next, we propose ScaleTrust, a scalable and secure key management system that virtualizes cloud-backed hardware security modules (HSMs) using a TEE. The virtual HSM partition abstracts away the details of secure key management such as secure channel establishment and the verification of isolated key usages. By supporting the isolation of each virtual HSM partition, ScaleTrust provides multi-tenancy scalability and security against insider threats in an untrusted cloud environment.
Advisors
Han, Dongsuresearcher한동수researcher
Description
한국과학기술원 :전기및전자공학부,
Publisher
한국과학기술원
Issue Date
2022
Identifier
325007
Language
eng
Description

학위논문(박사) - 한국과학기술원 : 전기및전자공학부, 2022.8,[iv, 63 p. :]

Keywords

Cloud System and Security▼aTrusted Execution Environment▼aNetwork Middlebox▼aHardware Security Module▼aKey Management System; 클라우드 시스템 및 보안▼a신뢰 실행 환경▼a네트워크 미들박스▼a하드웨어 보안 모듈▼a키 관리 시스템

URI
http://hdl.handle.net/10203/309213
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=1007940&flag=dissertation
Appears in Collection
EE-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0