We propose a formal model in which to design and analyze \emph{secure} VM placement algorithms, which are online vector bin packing algorithms that simultaneously satisfy certain optimization constraints and notions of security. We introduce and formalize several notions of security, establishing formal connections between them. We also introduce a new notion of efficiency for online bin packing algorithms that better captures their cost in the setting of cloud computing.
Finally, we propose a secure placement algorithm that achieves our strong notions of security when used with a new cryptographic mechanism we refer to as a shared deployment scheme.
Category / Keywords: cloud computing, cross-VM attacks, co-location attacks, isolation, co-location resistance, bin packing, secure multi-worker delegation Original Publication (with major differences): ACM Cloud Computing Security Workshop (CCSW) 2014 Date: received 11 Sep 2014, last revised 12 Sep 2014 Contact author: senyk at microsoft com Available format(s): PDF | BibTeX Citation Version: 20140912:161615 (All versions of this report) Short URL: ia.cr/2014/713 Discussion forum: Show discussion | Start new discussion