Hardware-based solutions for trusted cloud computing

被引:11
作者
Demigha, Oualid [1 ]
Larguet, Ramzi [1 ]
机构
[1] Ecole Mil Polytech, POB 17, Algiers 16111, Algeria
关键词
Trusted cloud computing; Hardware-assisted security; Trusted execution environment; Intel TXT; AMD SEV; ARM TrustZone; Intel SGX; ARM; TRUSTZONE; SECURITY;
D O I
10.1016/j.cose.2020.102117
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increasing number of threats targeting cloud computing and the exploitation of specifically privileged software vulnerabilities have pushed the security managers of cloud service providers to deploy hardware-based solutions. These solutions can offer better hardwareassisted security features for a broad range of computing platforms including both CISC and RISC architecture families in datacenters. Their goal is to reduce the attack surface by rooting the trust into the hardware instead of some high-privileged pieces of system software such as the operating system or the hypervisor which have been demonstrated that they include severe security vulnerabilities, thus limiting the adoption of the cloud computing model for some security-skeptical users. In this paper, we give cloud users and customers, application developers and security managers a comprehensive overview of four major industrial-scale commercial hardware-based solutions brought by major vendors in the cloud market. We present, analyze and compare Intel TXT, ARM TrustZone, AMD SEV, and Intel SGX technologies with respect to more than twenty criteria fitting within three categories: security, functional and deployment. We discuss each of these technologies and show the cases where they particularly excel. Our comparison can help IT managers to take the right decision about which better industrial technology to adopt for their particular security requirements and future cloud migrations. (c) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:18
相关论文
共 73 条
  • [1] Aaron Grabein L. G., 2020, ADV SECURITY FEATURE
  • [2] Advanced Micro Devices, 2018, TECHNICAL PREVIEW
  • [3] Advanced Micro Devices AMD Inc
  • [4] , 2018, WHIT PAP ENH YOUR CL
  • [5] On the Performance of ARM TrustZone (Practical Experience Report)
    Amacher, Julien
    Schiavoni, Valerio
    [J]. DISTRIBUTED APPLICATIONS AND INTEROPERABLE SYSTEMS, DAIS 2019, 2019, 11534 : 133 - 151
  • [6] [Anonymous], 2019, IEEE S SEC PRIV S P
  • [7] [Anonymous], 2017, P 10 EUROPEAN WORKSH
  • [8] [Anonymous], 2018, MOB COMPUT COMMUN RE
  • [9] [Anonymous], 2016, P HARDW ARCH SUPP SE
  • [10] [Anonymous], 2018, 27 USENIX SEC S USEN