论文部分内容阅读
针对当前KVM平台上的带虚拟可信平台模块的vTPM虚拟机无法实现动态迁移的问题,提出并实现了一种基于KVM的vTPM虚拟机动态迁移方案。在分析KVM架构与vTPM虚拟化特征的基础上,将vTPM虚拟机的动态迁移与KVM上原生态普通虚拟机的动态迁移过程相融合,保证了迁移前后系统安全状态的一致性和迁移过程中vTPM实例数据的安全性。实验结果表明,与普通虚拟机的动态迁移相比,利用该方案实现了用户无感知的vTPM虚拟机动态迁移过程,在保证虚拟机迁移后vTPM设备可用性的基础上,迁移中平均停机时间不超过50 ms,性能损失仅为15%。
In view of the problem that the vTPM virtual machine with the virtual trusted platform module on the KVM platform can not be dynamically migrated, a dynamic KVM-based vTPM virtual machine migration solution is proposed and implemented. Based on the analysis of the features of KVM architecture and vTPM virtualization, the dynamic migration of vTPM virtual machines and the dynamic migration process of primitive virtual machines in KVM are integrated to ensure the consistency of system security status before and after migration and the vTPM instances Data security. The experimental results show that compared with the dynamic migration of common virtual machines, this solution realizes the user-insensitive vTPM virtual machine migration process. On the basis of ensuring the availability of vTPM devices after migration of virtual machines, the average downtime during migration does not exceed 50 ms, the performance loss is only 15%.