{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:38:19Z","timestamp":1750307899304,"version":"3.41.0"},"reference-count":17,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGOPS Oper. Syst. Rev."],"published-print":{"date-parts":[[2009,1]]},"abstract":"<jats:p>Virtualization brings exibility to the data center and enables separations allowing for better security properties. For these security properties to be fully utilized, virtual machines need to be able to connect to secure services such as networking and storage. This paper addresses the problems associated with managing the cryptographic keys upon which such services rely by ensuring that keys remain within the trusted computing base. Here we describe a general architecture for managing keys tied to the underlying virtualized systems, with a specific example given for secure storage.<\/jats:p>","DOI":"10.1145\/1496909.1496919","type":"journal-article","created":{"date-parts":[[2009,1,29]],"date-time":"2009-01-29T13:48:36Z","timestamp":1233236916000},"page":"44-51","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Providing secure services for a virtual infrastructure"],"prefix":"10.1145","volume":"43","author":[{"given":"Adrian","family":"Baldwin","sequence":"first","affiliation":[{"name":"HP Labs, Bristol, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chris","family":"Dalton","sequence":"additional","affiliation":[{"name":"HP Labs, Bristol, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Simon","family":"Shiu","sequence":"additional","affiliation":[{"name":"HP Labs, Bristol, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Krzysztof","family":"Kostienko","sequence":"additional","affiliation":[{"name":"Birmingham University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qasim","family":"Rajpoot","sequence":"additional","affiliation":[{"name":"Birmingham University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2009,1]]},"reference":[{"key":"e_1_2_1_2_1","volume-title":"SISW '02: Proceedings of the First International IEEE Security in Storage Workshop. IEEE Computer Society","author":"Baldwin A.","year":"2002","unstructured":"A. Baldwin and S. Shiu . Encryption and key management in a san . In SISW '02: Proceedings of the First International IEEE Security in Storage Workshop. IEEE Computer Society , 2002 . A. Baldwin and S. Shiu. Encryption and key management in a san. In SISW '02: Proceedings of the First International IEEE Security in Storage Workshop. IEEE Computer Society, 2002."},{"key":"e_1_2_1_3_1","series-title":"LNCS","volume-title":"ESORICS","author":"Baldwin A.","year":"2003","unstructured":"A. Baldwin and S. Shiu . Hardware encapsulation of security services . In ESORICS , volume 2808 of LNCS . Springer , 2003 . A. Baldwin and S. Shiu. Hardware encapsulation of security services. In ESORICS, volume 2808 of LNCS. Springer, 2003."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-004-0061-9"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945462"},{"key":"e_1_2_1_6_1","volume-title":"UCSD tech report","author":"Bellare M.","year":"1997","unstructured":"M. Bellare and B. Yee . Forward integrity for audit logs. Technical report , UCSD tech report , 1997 . M. Bellare and B. Yee. Forward integrity for audit logs. Technical report, UCSD tech report, 1997."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315275"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1165389.945464"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/APTC.2008.17"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2004.221"},{"key":"e_1_2_1_13_1","volume-title":"Securing access of virtual resources to a shared storage facility based on tcg. Master's thesis","author":"Kostienko K.","year":"2007","unstructured":"K. Kostienko . Securing access of virtual resources to a shared storage facility based on tcg. Master's thesis , University of Birmingham , October 2007 . K. Kostienko. Securing access of virtual resources to a shared storage facility based on tcg. Master's thesis, University of Birmingham, October 2007."},{"key":"e_1_2_1_15_1","volume-title":"IEEE Symposium on Security and Privacy","author":"Merkle R.","year":"1980","unstructured":"R. Merkle . Protocols for public key cryptography . In IEEE Symposium on Security and Privacy , 1980 . R. Merkle. Protocols for public key cryptography. In IEEE Symposium on Security and Privacy, 1980."},{"key":"e_1_2_1_16_1","doi-asserted-by":"crossref","DOI":"10.1049\/PBPC006E","volume-title":"Trusted Computing (Professional Applications of Computing","author":"Mitchell C.","year":"2005","unstructured":"C. Mitchell . Trusted Computing (Professional Applications of Computing . IEE Press , 2005 . C. Mitchell. Trusted Computing (Professional Applications of Computing. IEE Press, 2005."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1346256.1346278"},{"key":"e_1_2_1_18_1","volume-title":"Key management for secure storage in a virtualised data center. Master's thesis","author":"Rajpoot Q.","year":"2007","unstructured":"Q. Rajpoot . Key management for secure storage in a virtualised data center. Master's thesis , University of Birmingham , October 2007 . Q. Rajpoot. Key management for secure storage in a virtualised data center. Master's thesis, University of Birmingham, October 2007."},{"key":"e_1_2_1_19_1","doi-asserted-by":"crossref","unstructured":"RSA Labs. Pkcs#11 v2.11 cryptographic token interface standard 2001. RSA Labs. Pkcs#11 v2.11 cryptographic token interface standard 2001.","DOI":"10.1049\/cp:20010740"},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the Second Workshop on Advances in Trusted Computing","author":"Stumpf F.","year":"2006","unstructured":"F. Stumpf , P. R. O. Tafreschi and, and C. Eckert . A robust integrity reporting protocol for remote attestation . In Proceedings of the Second Workshop on Advances in Trusted Computing , 2006 . F. Stumpf, P. R. O. Tafreschi and, and C. Eckert. A robust integrity reporting protocol for remote attestation. In Proceedings of the Second Workshop on Advances in Trusted Computing, 2006."},{"key":"e_1_2_1_22_1","volume-title":"TCG pc specific implementation specification","author":"Trusted Computing Group","year":"2003","unstructured":"Trusted Computing Group . TCG pc specific implementation specification , 2003 . Trusted Computing Group. TCG pc specific implementation specification, 2003."}],"container-title":["ACM SIGOPS Operating Systems Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1496909.1496919","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1496909.1496919","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T14:47:31Z","timestamp":1750258051000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1496909.1496919"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,1]]},"references-count":17,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2009,1]]}},"alternative-id":["10.1145\/1496909.1496919"],"URL":"https:\/\/doi.org\/10.1145\/1496909.1496919","relation":{},"ISSN":["0163-5980"],"issn-type":[{"type":"print","value":"0163-5980"}],"subject":[],"published":{"date-parts":[[2009,1]]},"assertion":[{"value":"2009-01-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}