提出一种IaaS(infrastructure as a service)完整性度量协议,该协议允许租户主动发起对IaaS资源的度量和验证,使租户能够检测其自身资源的完整性状态,增强IaaS资源状态的可见性.利用SVO逻辑对协议的安全性、完备性进行了分析,并搭建实验平台对协议的抗攻击能力和时间性能进行了验证.分析和实验证明,该协议能够抵御重放攻击、假冒攻击等多种形式的攻击,同时协议的执行耗时不会影响租户的正常使用体验.
This paper presents a protocol of integrity measurement of IaaS resource. It allows users to launch a measurement and verification of their IaaS sources ,which makes IaaS integrity state more visible to users. The protocol is analyzed by SVO logics and verified by an experiment. The protocol is proved to meet the goals and resist many attacks and the experiment results show that the protocol executes in a very short time which cannot have much affect on user experience.