{"id":101990,"date":"2019-08-19T14:33:59","date_gmt":"2019-08-19T18:33:59","guid":{"rendered":"https:\/\/www.ucf.edu\/news\/?p=101990"},"modified":"2022-03-07T13:50:18","modified_gmt":"2022-03-07T18:50:18","slug":"ucf-collaborates-with-ohio-state-in-study-to-improve-cloud-computing","status":"publish","type":"post","link":"https:\/\/www.ucf.edu\/news\/ucf-collaborates-with-ohio-state-in-study-to-improve-cloud-computing\/","title":{"rendered":"UCF Collaborates with Ohio State in Study to Improve Cloud Computing"},"content":{"rendered":"
New technology intended to improve the security of cloud computing may still be vulnerable to attacks, according to a new study co-authored by a 海角直播 researcher.<\/p>\n
Some of the vulnerabilities were detailed in a research presentation at the USENIX Security Symposium on Aug. 15, in Santa Clara, California.<\/p>\n
The study examined processor manufacturer AMD\u2019s Secure Encrypted Virtualization technology, a new advancement, which aims to provide privacy of computation and data in public clouds without needing to trust the cloud service providers and their software so users can experience confidential cloud computing.<\/p>\n
\u201cThe goal is to essentially say, \u2018Hey you don\u2019t have to trust the cloud computing companies, you can just trust the processor,\u2019\u201d said Yan Solihin, a professor in UCF\u2019s Department of Computer Science who helped co-author the study. \u201cThat\u2019s the promise. What we show in the paper is it\u2019s not easy to get to that promise.\u201d<\/p>\n
The lead author of the research paper was Mengyuan Li, a doctoral student in The Ohio State 海角直播\u2019s Department of Computer Science and Engineering. Co-authors also included Zhiqiang Lin and Yinqian Zhang, associate professors in the university\u2019s Department of Computer Science and Engineering.<\/p>\n
The team worked together to discover the vulnerability and demonstrate the proof-of-concept attacks successfully in a lab setting.<\/p>\n
\u201cMy student, Mengyuan, put quite a lot of effort in this work,\u201d Zhang said.<\/p>\n
Other computer processor companies, such as Intel, also offer similar environments that are walled off from the cloud computing service. AMD\u2019s processor is unique, however, because it encrypts the entire memory, unlike other processors, where only portions of the memory are encrypted at a time.<\/p>\n
This is an added security feature, but also means that the processor is reliant on input and output messages with the cloud computer software, rather than dedicating a portion of encrypted memory for that. It\u2019s in these incoming and outgoing communications where the vulnerabilities lay, the researchers said.<\/p>\n
Other researchers have reported the memory-integrity problems in the processor in the past, but this study was the first to report the vulnerabilities in the input and output operations, along with resulting other problems.<\/p>\n