跳到主要导航 跳到搜索 跳到主要内容

TapCoN: Practical third-party attestation for the cloud

  • Yan Zhai
  • , Qiang Cao
  • , Jeffrey Chase
  • , Michael Swift
  • University of Wisconsin-Madison
  • Duke University

科研成果: 会议稿件论文同行评审

摘要

One way to establish trust in a service is to know what code it is running. However, verified code identity is currently not possible for programs launched on a cloud by another party. We propose an approach to integrate support for code attestation—authenticated statements of code identity—into layered cloud platforms and services. To illustrate, this paper describes TapCon, an attesting container manager that provides source-based attestation and network-based authentication for containers on a trusted cloud platform incorporating new features for code attestation. TapCon allows a third party to verify that an attested container is running specific code bound securely to an identified source repository. We also show how to use attested code identity as a basis for access control. This structure enables new use cases such as joint data mining, in which two data owners agree on a safe analytics program that protects the privacy of their inputs, and then ensure that only the designated program can access their data.

源语言英语
出版状态已出版 - 2017
已对外发布
活动9th USENIX Workshop on Hot Topics in Cloud Computing, HotCloud 2017 co-located with USENIX ATC 2017 - Santa Clara, 美国
期限: 10 7月 201711 7月 2017

会议

会议9th USENIX Workshop on Hot Topics in Cloud Computing, HotCloud 2017 co-located with USENIX ATC 2017
国家/地区美国
Santa Clara
时期10/07/1711/07/17

学术指纹

探究 'TapCoN: Practical third-party attestation for the cloud' 的科研主题。它们共同构成独一无二的学术指纹。

引用此