arrow
Return

CAFE: A Virtualization-Based Approach to Protecting Sensitive Cloud Application Logic Confidentiality

delete2020-07-01
delete3
delete
OA
AI
S
Sungjin Park *
C
Chung Hwan Kim
J
Junghwan Rhee
J
Jong-Jin Won
T
Taisook Han
DOI:10.1109/TDSC.2018.2817545delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Cloud application marketplaces of modern cloud infrastructures offer a new software deployment model, integrated with the cloud environment in its configuration and policies. However, similar to traditional software distribution which has been suffering from software piracy and reverse engineering, cloud marketplaces face the same challenges that can deter the success of the evolving ecosystem of cloud software. We present a novel system named CAFE for cloud infrastructures where sensitive software logic can be executed with high secrecy protected from any piracy or reverse engineering attempts in a virtual machine even when its operating system kernel is compromised. The key mechanism is the end-to-end framework for the execution of applications, which consists of the secure encryption and distribution of confidential application binary files, and the runtime techniques to load, decrypt, and protect the program logic by isolating them from tenant virtual machines based on hypervisor-level techniques. We evaluate applications in several software categories which are commonly offered in cloud marketplaces showing that strong confidential execution can be provided with only marginal changes (around 100-220 lines of code) and minimal performance overhead. The results demonstrate the effectiveness and practicality of CAFE in cloud marketplaces.
Keywords:
Cloud computing
Binary codes
Reverse engineering
Runtime
Kernel
Cryptography
Cloud computing marketplace
secure execution environment
code confidentiality protection
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

Purdue University System cover
Purdue University System
Scholars:
3.9W
Papers: 3.6W
Citations: 66
P
Purdue University
Scholars:
2.7W
Papers: 2.1W
Citations: 147
N
nec corporation
Scholars:
1.0K
Papers: 955
Citations: 0
researcher View more organizations