Flowrider: Fast On-Demand Key Provisioning for Cloud Networks

SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2021, PT II(2021)

引用 0|浏览24
暂无评分
摘要
Increasingly fine-grained cloud billing creates incentives to review the software execution footprint in virtual environments. For example, virtual execution environments move towards lower overhead: from virtual machines to containers, unikernels, and serverless cloud computing. However, the execution footprint of security components in virtualized environments has either remained the same or even increased. We present Flowrider, a novel key provisioning mechanism for cloud networks that unlocks scalable use of symmetric keys and significantly reduces the related computational load on network endpoints. We describe the application of Flowrider to common transport security protocols, the results of its formal verification, and its prototype implementation. Our evaluation shows that Florwider uses up to an order of magnitude less CPU to establish a TLS session while preventing by construction some known attacks.
更多
查看译文
关键词
Network security, Software defined networking, Secure communication, Key management, Cloud security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要