首页 | 本学科首页   官方微博 | 高级检索  
     

抗侧信道攻击的服务功能链部署方法
引用本文:伊鹏, 谢记超, 张震, 谷允捷, 赵丹. 抗侧信道攻击的服务功能链部署方法[J]. 电子与信息学报, 2019, 41(11): 2699-2707. doi: 10.11999/JEIT190127
作者姓名:伊鹏  谢记超  张震  谷允捷  赵丹
作者单位:国家数字交换系统工程技术研究中心 郑州 450002
基金项目:国家自然科学基金;国家自然科学基金;国家自然科学基金;国家重点研发计划;国家重点研发计划
摘    要:侧信道攻击是当前云计算环境下多租户间信息泄露的主要途径,针对现有服务功能链(SFC)部署方法未充分考虑多租户环境下虚拟网络功能(VNF)面临的侧信道攻击问题,该文提出一种抗侧信道攻击的服务功能链部署方法。引入基于时间均值的租户分类策略以及结合历史信息的部署策略,在满足服务功能链资源约束条件下,以最小化租户所能覆盖的服务器数量为目标建立相应的优化模型,并设计了基于贪婪选择的部署算法。实验结果表明,与其他部署方法相比,该方法显著提高了恶意租户实现共存的难度与代价,降低了租户面临的侧信道攻击风险。

关 键 词:侧信道攻击   服务功能链   部署方法   租户分类   历史部署信息
收稿时间:2019-03-01
修稿时间:2019-06-11

A Service Function Chain Deployment Method Against Side Channel Attack
Peng YI, Jichao XIE, Zhen ZHANG, Yunjie GU, Dan ZHAO. A Service Function Chain Deployment Method Against Side Channel Attack[J]. Journal of Electronics & Information Technology, 2019, 41(11): 2699-2707. doi: 10.11999/JEIT190127
Authors:Peng YI  Jichao XIE  Zhen ZHANG  Yunjie GU  Dan ZHAO
Affiliation:National Digital Switching System Engineering & Technological Research Center, Zhengzhou 450002, China
Abstract:Side channel attack is the primary way to leak information between tenants in current cloud computing environment. However, existing Service Function Chain (SFC) deployment methods do not fully consider the side channel attack problem faced by the Virtual Network Function (VNF) in the multi-tenant environment. A SFC deployment method is proposed against side channel attack. A tenant classification strategy based on average time and a deployment strategy considering historical information are introduced. Under the resource constraints of the SFC, the optimization model is established with the goal of minimizing the number of servers that the tenant can cover. And a deployment algorithm is designed based on the greedy choice. The experimental results show that, compared with other deployment methods, this method can significantly improve the difficulty and cost of malicious tenant to realize co-residence, and reduces the risk of side channel attack faced by tenants.
Keywords:Side channel attack  Service Function Chain(SFC)  Deployment method  User classification  Historical deployment information
本文献已被 万方数据 等数据库收录!
点击此处可从《电子与信息学报》浏览原始摘要信息
点击此处可从《电子与信息学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号