A Secure Cloud with Minimal Provider Trust

07/13/2019
by   Amin Mosayyebzadeh, et al.
0

Bolted is a new architecture for a bare metal cloud with the goal of providing security-sensitive customers of a cloud the same level of security and control that they can obtain in their own private data centers. It allows tenants to elastically allocate secure resources within a cloud while being protected from other previous, current, and future tenants of the cloud. The provisioning of a new server to a tenant isolates a bare metal server, only allowing it to communicate with other tenant's servers once its critical firmware and software have been attested to the tenant. Tenants, rather than the provider, control the tradeoffs between security, price, and performance. A prototype demonstrates scalable end-to-end security with small overhead compared to a less secure alternative.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/13/2019

Supporting Security Sensitive Tenants in a Bare-Metal Cloud

Bolted is a new architecture for bare-metal clouds that enables tenants ...
research
01/31/2022

Architectures for Protecting Cloud Data Planes

This paper explores three approaches for protecting cloud application da...
research
05/21/2019

SvTPM: A Secure and Efficient vTPM in the Cloud

Virtual Trusted Platform Modules (vTPMs) have been widely used in commer...
research
09/03/2020

Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud

The cloud model allows many enterprises able to outsource computing reso...
research
05/15/2019

Towards a Security Baseline for IaaS-Cloud Back-Ends in Industry 4.0

The popularity of cloud based Infrastructure-as-a- Service (IaaS) soluti...
research
11/19/2020

To Terminate or Not to Terminate Secure Sockets Layer (SSL) Traffic at the Load Balancer

The concepts of terminating or not terminating Secure Sockets Layer (SSL...
research
08/23/2019

Design choices for productive, secure, data-intensive research at scale in the cloud

We present a policy and process framework for secure environments for pr...

Please sign up or login with your details

Forgot password? Click here to reset