高级检索

    弹性机密虚拟机:基于内部特权隔离的云集群容灾备份架构

    ResiCVM: A Cloud Cluster Disaster Recovery and Backup Architecture Based on Intra-Guest Privilege Isolation

    • 摘要: 机密计算环境的内存加密机制使得宿主机对机密虚拟机的内部状态不可见,这在保证了机密虚拟机内部数据安全的同时对传统基于虚拟机监视器的容灾备份方案带来了严重的技术挑战。而使用TEE安全处理器的解决方案存在着严重的性能问题。这严重制约了云机密计算集群的部署,削弱了云机密计算节点的安全弹性。本文提出了ResiCVM(resilient confidential virtual machine),一个基于虚拟机内部特权级隔离的弹性容灾备份框架。通过虚拟机内部特权级隔离机制,ResiCVM 将客户虚拟机的状态提取与密码学保护逻辑,从原有TEE安全处理器上转移至虚拟机内部的高特权域中执行,同时将客户操作系统排除在可信计算基(TCB)之外。此外,为了保证虚拟机和安全管理中心之间通讯的安全性,我们设计了一套端到端的密码学认证通信协议,确保了虚拟机状态备份流程的安全。我们在AMD EPYC 9745平台上实现了ResiCVM的原型系统,实验评估表明,ResiCVM对虚拟机状态数据的备份封装存储吞吐量达到了基于TEE安全处理器方案的62.7倍。并且在多虚拟机并发的维护任务中,ResiCVM的执行效率并未出现显著下降;而基于TEE安全处理器的方案的性能则随着并发数的增加呈等比下降。ResiCVM无需对宿主机端系统做任何修改,本方案提高了机密计算集群的灾备性能,为机密计算集群的安全运维提供了安全弹性技术支撑。

       

      Abstract: The memory encryption mechanism in confidential computing environments renders the internal state of confidential virtual machines (CVMs) invisible to the host. While ensuring internal data security, this poses severe technical challenges for traditional hypervisor-based disaster recovery and backup solutions. Meanwhile, existing solutions relying on TEE secure processors suffer from severe performance bottlenecks, which heavily restricts the deployment of cloud confidential computing clusters and degrades their security resilience. This paper presents ResiCVM (Resilient Confidential Virtual Machine), a resilient disaster recovery and backup framework based on intra-VM privilege isolation. ResiCVM shifts the state extraction and cryptographic protection logic from the legacy TEE secure processor to a high-privilege domain within the VM, strictly excluding the guest operating system from the Trusted Computing Base (TCB). Additionally, we design an end-to-end cryptographic authentication protocol to ensure secure communication between the VM and the security management center during the state backup process. We implemented a prototype of ResiCVM on the AMD EPYC 9745 platform. Experimental evaluations show that ResiCVM achieves a backup encapsulation and storage throughput 62.7 times higher than that of TEE secure processor-based schemes. Crucially, during concurrent multi-VM maintenance tasks, ResiCVM maintains stable execution efficiency, whereas TEE-based solutions suffer proportional performance degradation. Requiring zero host-side modifications, ResiCVM significantly improves disaster recovery performance and provides robust technical support for the secure operations and security resilience of confidential computing clusters.

       

    /

    返回文章
    返回