Javascript must be enabled to continue!
Radium: Secure Policy Engine in Hypervisor
View through CrossRef
The basis of today’s security systems is the trust and confidence that the system will behave as expected and are in a known good trusted state. The trust is built from hardware and software elements that generates a chain of trust that originates from a trusted known entity. Leveraging hardware, software and a mandatory access control policy technology is needed to create a trusted measurement environment. Employing a control layer (hypervisor or microkernel) with the ability to enforce a fine grained access control policy with hyper call granularity across multiple guest virtual domains can ensure that any malicious environment to be contained. In my research, I propose the use of radium's Asynchronous Root of Trust Measurement (ARTM) capability incorporated with a secure mandatory access control policy engine that would mitigate the limitations of the current hardware TPM solutions. By employing ARTM we can leverage asynchronous use of boot, launch, and use with the hypervisor proving its state and the integrity of the secure policy. My solution is using Radium (Race free on demand integrity architecture) architecture that will allow a more detailed measurement of applications at run time with greater semantic knowledge of the measured environments. Radium incorporation of a secure access control policy engine will give it the ability to limit or empower a virtual domain system. It can also enable the creation of a service oriented model of guest virtual domains that have the ability to perform certain operations such as introspecting other virtual domain systems to determine the integrity or system state and report it to a remote entity.
Title: Radium: Secure Policy Engine in Hypervisor
Description:
The basis of today’s security systems is the trust and confidence that the system will behave as expected and are in a known good trusted state.
The trust is built from hardware and software elements that generates a chain of trust that originates from a trusted known entity.
Leveraging hardware, software and a mandatory access control policy technology is needed to create a trusted measurement environment.
Employing a control layer (hypervisor or microkernel) with the ability to enforce a fine grained access control policy with hyper call granularity across multiple guest virtual domains can ensure that any malicious environment to be contained.
In my research, I propose the use of radium's Asynchronous Root of Trust Measurement (ARTM) capability incorporated with a secure mandatory access control policy engine that would mitigate the limitations of the current hardware TPM solutions.
By employing ARTM we can leverage asynchronous use of boot, launch, and use with the hypervisor proving its state and the integrity of the secure policy.
My solution is using Radium (Race free on demand integrity architecture) architecture that will allow a more detailed measurement of applications at run time with greater semantic knowledge of the measured environments.
Radium incorporation of a secure access control policy engine will give it the ability to limit or empower a virtual domain system.
It can also enable the creation of a service oriented model of guest virtual domains that have the ability to perform certain operations such as introspecting other virtual domain systems to determine the integrity or system state and report it to a remote entity.
Related Results
Re-treatment of metastatic castration-resistant prostate cancer patients with radium-223 therapy in daily practice.
Re-treatment of metastatic castration-resistant prostate cancer patients with radium-223 therapy in daily practice.
183
Background:
Radium-223 is a therapeutic option for metastatic castration-resistant prostate cancer (mCRPC) patients with symptomat...
Development of the Tour Split-Cycle Internal Combustion Engine
Development of the Tour Split-Cycle Internal Combustion Engine
<div class="section abstract"><div class="htmlview paragraph">The Tour engine is a novel split-cycle internal combustion engine (ICE) that divides the four-stroke Otto ...
Integrity Verification of Applications on RADIUM Architecture
Integrity Verification of Applications on RADIUM Architecture
Trusted Computing capability has become ubiquitous these days, and it is being widely deployed into consumer devices as well as enterprise platforms. As the number of threats is in...
A SURVEY OF THE HOST HYPERVISOR SECURITY ISSUES PRESENTED IN PUBLIC IAAS ENVIRONMENTS AND THEIR SOLUTIONS
A SURVEY OF THE HOST HYPERVISOR SECURITY ISSUES PRESENTED IN PUBLIC IAAS ENVIRONMENTS AND THEIR SOLUTIONS
The use of virtualization can be attributed
to the success of cloud computing. However, usage of a
hypervisor in a shared environment among mistrusting
users presents significant c...
Quantitative Feedback Control of Air Path in Diesel-Dual-Fuel Engine
Quantitative Feedback Control of Air Path in Diesel-Dual-Fuel Engine
<div class="section abstract"><div class="htmlview paragraph">In this paper, we investigate a multivariable control of air path of a diesel-dual-fuel (DDF) engine. The ...
The F-16 Common Engine Bay
The F-16 Common Engine Bay
In 1979 the United States Air Force elected under the Engine Model Derivative Program (EMDP) to explore derivative engine concepts by the General Electric Company and the Pratt and...
Monitoring and treatment of combined radium in Iowa private wells
Monitoring and treatment of combined radium in Iowa private wells
Unregulated private drinking water supplies, especially private wells, are likely to be disproportionately impacted by naturally-occurring radioactive material (NORM), which contam...
The Period of Decay of Radium B and Radium C
The Period of Decay of Radium B and Radium C
Measurements of the saturation currents produced between two parallel plates by a source of radium C of carefully tested purity have been performed by an accurate galvanometer meth...


