You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 5 Next »

Bug Reference

Branch

master, 4.2.0

Introduction

Trusted compute pools with Intel Trusted Execution Technology enable isolation and tamper detection in boot process and complement run time protections. Meanwhile, hardware-based trust provides verification useful in compliance and trust status, which security and policy applications use to control workload.

Using Intel's TXT technology, a number of painpoints of a secure computing environments can be addressed. For example, Isolation is a key concern in a shared infrastructure where a lack of traditional guarantees of physical separation are lacking and multiple workloads may interfere with each other. Enforcement i.e. controls needed to enforce protection of Infrastructure can prevent pre-runtime environments are target of new attacks and low-level attacks are hard to detect and can be difficult to recover from.Encryption is another problem that can get worse in a cloud where data protection can be harder due to lack of boundaries and multi-tenancy.

Source: Intel TXT Overview

Purpose

This document describes the specifications and design of the feature.

References

http://www.intel.com/content/www/us/en/architecture-and-technology/trusted-execution-technology/malware-reduction-general-technology.html

Document History

Author

Description

Date

Hari Kannan

Inital Requirement

01/10/2013

Devdeep Singh

Draft of the FS

03/7/2013

Requirement:

  • CloudStack will work with an attestation server to secure the deployed Hosts - the attestation server has the capability to compare launch values against "known good"
  • When setting up a cloudstack environment, automatically understand which hosts are "trustworthy" and present it to the admin.
  • Administrators are able to create a service offering that will allow users to select if they need the VMs to be deployed on trusted hosts.
  • Ensure that instances requested in such a manner are always placed on trusted hosts. Instances that do not require a trusted host will not be blocked from getting deployed on a trusted host.
  • Whenever a trusted host or the attestation server itself is rebooted, verify the trustworthiness.
  • Migration of VM from a trusted to untrusted host should be allowed but it should raise an alert.

Non requirements

  • The attestation server will not be managed by cloudstack. It'll have to be setup and configured and then registered with cloudstack for checking the trust attributes of a host.

Glossary

Feature Specification

Test Guidelines

Hypervisor support

The functionality will be made available for VmWare, KVM and XenServer.

Supportability characteristics

Logging

All successful operations are logged to INFO, all exceptions/failures to ERROR, and all synchronization checks to DEBUG.

Events/Alerts

If an instance created from a service offering requires a trusted host and it is placed on an untrusted or unattested host, an alert will be raised to bring it to administrators attention.

Uses Cases

Architecture and Design description

Dependency on the attestation server client library
A java client library is available for easy integration with the attestation server. Cloudstack will be using it to register with the attestation server and to check for the trust relationship of a host. The library and this feature will be made available under non-oss.

Registering an attestation server with cloudstack

  • Only one attestation server can be registered with a cloudstack management server.
  • The attestation service can be enabled or disabled through a global configuration parameter 'enable.attestation.service' (Boolean: true/false). It'll be disabled by default.
  • A root administrator can register the details of an attestation server by making a registerAttestationServer api call. This is an async call. Cloudstack management server will open a connection to the attestation server and it'll use the KeystoreUtil.createUserInDirectory client library api call to register/create a user. On successful registration the attestation server details will be persisted in the db.
  • The above request for a new user needs to be approved by an attestation server administrator. This is a manual process and will be included in the documentation.
  • If an attestation service is already registered with the management server, any subsequent requests to register another attestation server will override the older registration.

Database modifications

Web Services APIs

UI Flow


Open Issues

  • No labels