节点文献
开源云平台安全机制的研究与实现
Research And Implementation of Open Source Cloud Platform Security Mechanism
【作者】 姚坤;
【导师】 陆鑫;
【作者基本信息】 电子科技大学 , 软件工程, 2015, 硕士
【摘要】 随着云计算技术的迅速发展,越来越多的机构与企业选择云计算技术作为自己日益复杂繁重业务的解决方案。出于安全,经济,适宜等多方面因素的考虑,以及开源社区的快速发展,有实力的企业往往希望能够采用开源云平台来构建企业内部私有云系统,增强应用运行性能,降低应用维护复杂度。而在传统的机构与企业内部,往往存在着各种各样的应用系统,因为系统的开发时间,适用人群,功能目标,甚至开发团队等因素的不同,导致机构与企业内部系统的安全管理实践是分散的,每个应用都有着自己的安全保障机制。这样,不仅造成了资源的浪费,也存在着极大的安全隐患。当机构或企业准备采用云计算技术,将现有的应用系统移植到云计算平台上时,上述不同系统中分散存在的安全保障机制,会因为云计算的复杂性及不确定性而带来更大的安全问题。同时,相对于商业级软件来说,开源云平台往往会因为缺乏足够的资金、技术等支持,而存在各种各样的安全漏洞。因此,基于开源云平台设计实现一套完整的企业私有云安全保障系统,不管是对于企业,还是对于开源云平台本身的发展来说都至关重要。根据当前开源云平台构建企业私有云安全计算环境所需解决的安全问题的基本需求。本文首先对私有云平台安全整体架构设计进行了研究,并采用开源云平台CloudFoundry v2构建一套私有云计算环境,对云环境中应用的资源隔离与控制机制进行研究。其次,针对当前开源云平台对应用访问安全支持服务的缺乏,设计并实现云应用统一身份认证与访问控制管理框架。同时,针对平台在企业数据存储安全上的缺陷,设计一种分级双重数据加密算法,通过对企业数据进行安全分级,对安全等级高的数据先采用对称算法进行加密,并将对称算法产生的密钥进行非对称加密存储,从而兼顾数据的安全性以及系统运行效率。最后,基于之前的研究,设计并实现一个私有云安全保障系统,提供平台应用的统一身份认证与访问控制管理,应用数据的分级双重加密、核心数据库的备份与恢复以及用户行为审计管理等功能。通过该系统来保障云平台上应用正常运行,加强应用的访问安全及数据安全,从而提高云平台本身以及平台上运行应用的整体安全性。
【Abstract】 With the rapid development of cloud computing technology, an increasing number of organizations and enterprises have chosen cloud computing technology as the solution to their growing complex and heavy business. Considering a variety of factors, such as security, economy, feasibility and the quick development of open source community, competitive enterprises always hope through the open source cloud platform to build a private cloud platform within in the boundaries of the enterprice to enhance the application running performance, decrease the complexity of application operations. There are a wide variety of systems within the traditional organizations and enterprises, because of the differences of the development time of systems, target customers, functional objectives and development teams, the security management of system within organizations and enterprises are dispersed, and every application has its own security guarantee mechanism. Thus, it not only resulted in a waste of resources but also the existence of security risks. Due to the complexity and uncertainty of cloud computing, when organizations or enterprises are going to adopt cloud computing technology to transplant current application system to cloud computing platform, they will face bigger security issues. Meanwhile, compared to commercial software, because of a lack of enough financial and technical support, there are often a variety of security holes in open source cloud platform. Thus, to realize a complete set of enterprise private cloud security system based on open source cloud platform is crucial for the enterprise and the development of open source cloud platform itself.According to the basic needs of the security problems in build enterprise private cloud computing system based on open source cloud platform. Firstly,this thesis studies the design of private cloud platform security architecture, and builds a private cloud computing environment based on open source cloud platform Cloud Foundry v2, and studies the implementation mechanisms for the isolation and control of application resources. Secondly, for the current open source of cloud platform has no enough support to the service of being security access to applications, this thesis designs and implements a framework of the unified identity authentication and access control management system. Meanwhile, for the security flaws in the enterprise data storage, this thesis proposes a new grading encryption algorithm, by grading the data based on the security specification, to encrypt the high requirements data with symmetric encryption, then, to encrypt the encryption key which is used in symmetric encryption, thus to balance the security of the data and system efficiency. Finally, based on the previous studies,this thesis designs and implements a private cloud security system which provides a unified platform for application authentication and provides the function of accessing control management, grading double encryption of application data, the backup and recovery of critical database, and the audit management of user behavior.The system will offer protection for the applications running on the cloud platform, enhance the applications access security and data security, improve the overall security of applications running on the platform and the cloud platform itself.
【Key words】 Open source cloud computing platform; security; data encryption; identify authentication; access control;
- 【网络出版投稿人】 电子科技大学 【网络出版年期】2016年 03期
- 【分类号】TP393.09;TP309
- 【被引频次】1
- 【下载频次】275