IJISA Vol.3, No.1, Feb. 2011

Sensitive Data Protection Based on Intrusion Tolerance in Cloud Computing

Jingyu Wang, xuefeng Zheng, Dengliang Luo

Index Terms

Cloud Computing;Virtualization;Intrusion Tolerance;Cloud Security;Virtual Adversary Structure


Service integration and supply on-demand coming from cloud computing can significantly improve the utilization of computing resources and reduce power consumption of per service, and effectively avoid the error of computing resources. However, cloud computing is still facing the problem of intrusion tolerance of the cloud computing platform and sensitive data of new enterprise data center. In order to address the problem of intrusion tolerance of cloud computing platform and sensitive data in new enterprise data center, this paper constructs a virtualization intrusion tolerance system based on cloud computing by researching on the existing virtualization technology, and then presents a method of intrusion tolerance to protect sensitive data in cloud data center based on virtual adversary structure by utilizing secret sharing. This system adopts the method of hybrid fault model, active and passive replicas, state update and transfer, proactive recovery and diversity, and initially implements to tolerate F faulty replicas in N=2F+1 replicas and ensure that only F+1 active replicas to execute during the intrusion-free stage. The remaining replicas are all put into passive mode, which significantly reduces the resource consuming in cloud platform. At last we prove the reconstruction and confidentiality property of sensitive data by utilizing secret sharing.

Jingyu Wang, xuefeng Zheng, Dengliang Luo,"Sensitive Data Protection Based on Intrusion Tolerance in Cloud Computing“, International Journal of Intelligent Systems and Applications(IJISA), vol.3, no.1, pp.58-66, 2011. DOI: 10.5815/ijisa.2011.01.08


