Design and Implementation of a Portable ID Management Framework for a Secure Virtual Machine Monitor

Manabu Hirano, Takeshi Okuda, Eiji Kawai, Suguru Yamaguchi · 2007

A commonly used virtual machine monitor (VMM) allows multiple operating systems to share physical hardware resources as virtual resources in a safe manner. It provides a strong isolation mechanism between virtual machines (VMs). In this paper, we state the importance of ID management for a security-purpose VMM system to enforce security policy on an end-user environment. We present a design of a portable ID management framework for a security-purpose VMM. Our proposal employs a smart card (ID card) for user authentication. The proposed ID management framework can provide generic programming interfaces to existing VMM software. Our ID management framework realizes an authentication between a VMM and its users, an authorization for a VM boot operation, storage of cryptographic keys for VMM-layer's disk encryption/decryption, and access control for virtual/physical resources based on a user identity. In this paper, we show the prototype implementation of our ID management framework and its integration into the proven VMM software, QEMU.

Read the paper · More papers on PaperTik