A Hypervisor-Based Secure Storage Scheme
Dan Wang, Dengguo Feng · 2010
We demonstrate an approach for data security in a virtual platform that seals data to the properties of system components with the trusted platform module (TPM). Based on the hypervisor, there are some trusted services provided to support sealing and unsealing so that the TPM can serve all virtual machines (VMs). We implement the prototype system on the Xen hypervisor which has no evident decrease in efficiency compared with the current property-based sealing solutions. We show that, through our architecture, a piece of confidential data can be used securely in all VMs co-hosted on one platform.