摘要
资源隔离是计算机安全的一个重要手段,良好的安全隔离使得虚拟机技术成为近年来学术界和工业界的热点。在深入分析Linux环境下Xen完全虚拟化技术理论的基础上,设计了一个基于IntelVT技术的虚拟机安全隔离设计方案。该方案通过安全内存管理(SMM)和安全I/O管理(SIOM)两种手段进行保护,完善了Xen宿主机系统与虚拟机系统之间的安全隔离,为Xen虚拟机在实际的安全隔离环境中的应用提供了较高的安全保障。
Resource isolation mechanisms are very important for computer security,and virtual machine technology becomes very popular in research communities and industries owing to its fair isolation solution in computer system.Through theoretical analysis of Xen virtualization in Linux,this paper proposed a solution for security isolation of virtual machines based on Intel VT,which could achieve security isolation of Xen host machine and virtual machines through secure memory management(SMM) and secure I/O management(SIOM),thus offering an even higher security guarantee for the application of Xen in security isolation environment.
出处
《信息安全与通信保密》
2011年第5期101-103,共3页
Information Security and Communications Privacy