Partially Trusting the Service Mesh Control Plane

10/23/2022
by   Constantin Adam, et al.
0

Zero Trust is a novel cybersecurity model that focuses on continually evaluating trust to prevent the initiation and horizontal spreading of attacks. A cloud-native Service Mesh is an example of Zero Trust Architecture that can filter out external threats. However, the Service Mesh does not shield the Application Owner from internal threats, such as a rogue administrator of the cluster where their application is deployed. In this work, we are enhancing the Service Mesh to allow the definition and reinforcement of a Verifiable Configuration that is defined and signed off by the Application Owner. Backed by automated digital signing solutions and confidential computing technologies, the Verifiable Configuration allows changing the trust model of the Service Mesh, from the data plane fully trusting the control plane to partially trusting it. This lets the application benefit from all the functions provided by the Service Mesh (resource discovery, traffic management, mutual authentication, access control, observability), while ensuring that the Cluster Administrator cannot change the state of the application in a way that was not intended by the Application Owner.

READ FULL TEXT

page 3

page 5

page 10

research
05/05/2021

Performance Analysis of Zero-Trust multi-cloud

Zero Trust security model permits to secure cloud native applications wh...
research
07/26/2021

When SRv6 meets 5G Core: Implementation and Deployment of a Network Service Chaining Function in SmartNICs

Currently, we have witnessed a myriad of solutions that benefit from pro...
research
05/24/2022

Helm – What It Can Do and Where Is It Going?

Deploying an application into a Kubernetes cluster requires sending a ma...
research
05/16/2023

A simple protocol to automate the executing, scaling, and reconfiguration of Cloud-Native Apps

We propose a simple protocol for Service Mesh management. The protocol s...
research
10/27/2018

Resource Control in P2P Cryptocurrency Networks

For decentralised P2P networks, it is very important to have a mechanism...
research
05/12/2022

A Qualitative Evaluation of Service Mesh-based Traffic Management for Mobile Edge Cloud

Service mesh is getting widely adopted as the cloud-native mechanism for...
research
07/02/2022

Dissecting Service Mesh Overheads

Service meshes play a central role in the modern application ecosystem b...

Please sign up or login with your details

Forgot password? Click here to reset