-
A Secure Cloud with Minimal Provider Trust
Authors:
Amin Mosayyebzadeh,
Gerardo Ravago,
Apoorve Mohan,
Ali Raza,
Sahil Tikale,
Nabil Schear,
Trammell Hudson,
Jason Hennessey,
Naved Ansari,
Kyle Hogan,
Charles Munson,
Larry Rudolph,
Gene Cooperman,
Peter Desnoyers,
Orran Krieger
Abstract:
Bolted is a new architecture for a bare metal cloud with the goal of providing security-sensitive customers of a cloud the same level of security and control that they can obtain in their own private data centers. It allows tenants to elastically allocate secure resources within a cloud while being protected from other previous, current, and future tenants of the cloud. The provisioning of a new s…
▽ More
Bolted is a new architecture for a bare metal cloud with the goal of providing security-sensitive customers of a cloud the same level of security and control that they can obtain in their own private data centers. It allows tenants to elastically allocate secure resources within a cloud while being protected from other previous, current, and future tenants of the cloud. The provisioning of a new server to a tenant isolates a bare metal server, only allowing it to communicate with other tenant's servers once its critical firmware and software have been attested to the tenant. Tenants, rather than the provider, control the tradeoffs between security, price, and performance. A prototype demonstrates scalable end-to-end security with small overhead compared to a less secure alternative.
△ Less
Submitted 13 July, 2019;
originally announced July 2019.
-
Supporting Security Sensitive Tenants in a Bare-Metal Cloud
Authors:
Amin Mosayyebzadeh,
Apoorve Mohan,
Sahil Tikale,
Mania Abdi,
Nabil Schear,
Charles Munson,
Trammell Hudson,
Larry Rudolph,
Gene Cooperman,
Peter Desnoyers,
Orran Krieger
Abstract:
Bolted is a new architecture for bare-metal clouds that enables tenants to control tradeoffs between security, price, and performance. Security-sensitive tenants can minimize their trust in the public cloud provider and achieve similar levels of security and control that they can obtain in their own private data centers. At the same time, Bolted neither imposes overhead on tenants that are securit…
▽ More
Bolted is a new architecture for bare-metal clouds that enables tenants to control tradeoffs between security, price, and performance. Security-sensitive tenants can minimize their trust in the public cloud provider and achieve similar levels of security and control that they can obtain in their own private data centers. At the same time, Bolted neither imposes overhead on tenants that are security insensitive nor compromises the flexibility or operational efficiency of the provider. Our prototype exploits a novel provisioning system and specialized firmware to enable elasticity similar to virtualized clouds. Experimentally we quantify the cost of different levels of security for a variety of workloads and demonstrate the value of giving control to the tenant.
△ Less
Submitted 13 July, 2019;
originally announced July 2019.
-
M2: Malleable Metal as a Service
Authors:
Apoorve Mohan,
Ata Turk,
Ravi S. Gudimetla,
Sahil Tikale,
Jason Hennessey,
Ugur Kaynar,
Gene Cooperman,
Peter Desnoyers,
Orran Krieger
Abstract:
Existing bare-metal cloud services that provide users with physical nodes have a number of serious disadvantage over their virtual alternatives, including slow provisioning times, difficulty for users to release nodes and then reuse them to handle changes in demand, and poor tolerance to failures. We introduce M2, a bare-metal cloud service that uses network-mounted boot drives to overcome these d…
▽ More
Existing bare-metal cloud services that provide users with physical nodes have a number of serious disadvantage over their virtual alternatives, including slow provisioning times, difficulty for users to release nodes and then reuse them to handle changes in demand, and poor tolerance to failures. We introduce M2, a bare-metal cloud service that uses network-mounted boot drives to overcome these disadvantages. We describe the architecture and implementation of M2 and compare its agility, scalability, and performance to existing systems. We show that M2 can reduce provisioning time by over 50% while offering richer functionality, and comparable run-time performance with respect to tools that provision images into local disks. M2 is open source and available at https://github.com/CCI-MOC/ims.
△ Less
Submitted 1 January, 2018;
originally announced January 2018.