Journal of Information Security Reserach ›› 2022, Vol. 8 ›› Issue (10): 1028-.

Previous Articles     Next Articles

Research on SGX-based Cloud Outsourcing Computing Trust Problem Solution

  

  • Online:2022-10-25 Published:2022-10-24

基于SGX的云外包计算信任问题解决方案研究

王冠, 尹煜   

  1. (北京工业大学信息学部北京100124)
    (可信计算北京重点实验室北京100124)
  • 通讯作者: 王冠 副教授,硕士生导师.主要研究方向为信息安全、可信计算、数据挖掘与智能信息系统. wanguan@bjut.edu.cn
  • 作者简介:王冠 副教授,硕士生导师.主要研究方向为信息安全、可信计算、数据挖掘与智能信息系统. wanguan@bjut.edu.cn 尹煜 硕士研究生.主要研究方向为信息安全、可信计算. 4338680@qq.com

Abstract: General users and small and mediumsized enterprises mostly use the distributed big data computing environment provided by cloud service providers. The consequence is that users lose some control over code and data and are vulnerable to internal cloud attacks. Therefore, a cloud outsourcing computing security solution based on Intel SGX (software guard extensions) is proposed with the participation of a trusted third party. The trusted third party formulates a unified computing environment security standard and creates a trusted execution environment in the cloud through SGX technology. It performs authentication and maintenance to ensure that user code data is calculated in a secure computing environment configured by a trusted third party to solve data security and user trust issues in cloud outsourcing computing. The application and simulation experiment of the security scheme is carried out under the Hadoop architecture. The experimental results show that the security scheme can ensure data security in the cloud computing process, and at the same time, the user’s trust in the cloud computing environment can be solved through the authentication and management of the trusted environment by a trusted third party, and compared with the standard MapReduce computing Performance loss is small.

Key words: cloud outsourcing, big data, distributed computing, Intel SGX, cloud security

摘要: 一般用户与中小企业多使用云服务商提供的分布式大数据计算环境,带来的后果是用户对代码及数据失去了部分控制权并极易遭受云端内部攻击.因此提出了可信第三方参与的基于Intel SGX(software guard extensions)的云外包计算安全方案,由可信第三方进行统一的计算环境安全标准制定,在云端通过SGX技术创建可信执行环境并对其进行认证与维护,保证用户代码数据在可信第三方配置的安全计算环境中执行计算,解决云外包计算中数据安全与用户信任问题.在Hadoop架构下进行安全方案的应用与模拟实验.实验结果表明,安全方案可以有效实现上述安全目标,相比标准的MapReduce计算性能损耗较小.

关键词: 云外包, 大数据, 分布式计算, Intel SGX, 云安全