CRISP: Confidentiality, Rollback, and Integrity Storage Protection for Confidential Cloud-Native Computing

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Hartono, Ardhi Putra Pratama, Brito, Andrey, Fetzer, Christof
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866913468513255424
author Hartono, Ardhi Putra Pratama
Brito, Andrey
Fetzer, Christof
author_facet Hartono, Ardhi Putra Pratama
Brito, Andrey
Fetzer, Christof
contents Trusted execution environments (TEEs) protect the integrity and confidentiality of running code and its associated data. Nevertheless, TEEs' integrity protection does not extend to the state saved on disk. Furthermore, modern cloud-native applications heavily rely on orchestration (e.g., through systems such as Kubernetes) and, thus, have their services frequently restarted. During restarts, attackers can revert the state of confidential services to a previous version that may aid their malicious intent. This paper presents CRISP, a rollback protection mechanism that uses an existing runtime for Intel SGX and transparently prevents rollback. Our approach can constrain the attack window to a fixed and short period or give developers the tools to avoid the vulnerability window altogether. Finally, experiments show that applying CRISP in a critical stateful cloud-native application may incur a resource increase but only a minor performance penalty.
format Preprint
id arxiv_https___arxiv_org_abs_2408_06822
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle CRISP: Confidentiality, Rollback, and Integrity Storage Protection for Confidential Cloud-Native Computing
Hartono, Ardhi Putra Pratama
Brito, Andrey
Fetzer, Christof
Cryptography and Security
Operating Systems
Trusted execution environments (TEEs) protect the integrity and confidentiality of running code and its associated data. Nevertheless, TEEs' integrity protection does not extend to the state saved on disk. Furthermore, modern cloud-native applications heavily rely on orchestration (e.g., through systems such as Kubernetes) and, thus, have their services frequently restarted. During restarts, attackers can revert the state of confidential services to a previous version that may aid their malicious intent. This paper presents CRISP, a rollback protection mechanism that uses an existing runtime for Intel SGX and transparently prevents rollback. Our approach can constrain the attack window to a fixed and short period or give developers the tools to avoid the vulnerability window altogether. Finally, experiments show that applying CRISP in a critical stateful cloud-native application may incur a resource increase but only a minor performance penalty.
title CRISP: Confidentiality, Rollback, and Integrity Storage Protection for Confidential Cloud-Native Computing
topic Cryptography and Security
Operating Systems
url https://arxiv.org/abs/2408.06822