当前位置:首页 > 报告详情

Security++ Hide your secrets via a distributed Hardware Security Module.pdf

上传人: 2*** 编号:140604 2023-08-31 20页 2.09MB

1、Iris DingCloud Software Engineer,Malini BhandaruSenior Principal Engineer,Thanks to my colleagues:QimingLiu,HuailongZhang,XintongChen,XinHuang,RuijingGuo,RuoyuYing,ChangranWang,ForrestZhao,SoodKapil,PoussaSakari,PuustinenIsmo,ValluriAmarnath,Venkatasubramanian SankaranarayananSecurity+:Hide your sec

2、rets via a distributed Hardware Security Module(HSM)Agenda Cloud HSM and Challenges Distributed HSM Use CasesHardware Security Module(HSM)A physical computing device that safeguards and manages secrets(most importantly digital keys),performs encryption and decryption functions for digital signatures

3、,strong authentication and other cryptographic functions.Traditionally a plug-in card or an external device that attaches directly to a computer or network server.A hardware security module contains one or more secure cryptoprocessor chips.https:/en.wikipedia.org/wiki/Hardware_security_moduleHSM Mar

4、ketExpected to reach USD 2.0 Billion by 2028,growing at a CAGR of 13.1%Driven by:Growing data breaches and cyberattacksIncreasing demand for data security in cloud environments*Data source:https:/ HSMPros Lower cost from sharing Flexibility and simplicityCons:Higher latency crypto operations Lower t

5、ransaction rate(TPS)Migration difficulty No substitutes on edgeDistributed HSMWhere you need it,sized to your needsHighly Secure,even at the EdgeLower Latency and Greater ThroughputLower CostHow?UsingTrusted Execution Environments!APPTrusted Execution Environments(TEEs)Hardware and firmware supporte

6、d confidentiality and integrity of code and dataProtect even from privileged processes(OS,Hypervisor.)Demonstrate trust-quotes and attestationData at RestData in MotionData in UseSECURECPU-TrustedOperating System/Virtual Machine Monitor-UntrustedTEEIntel SGX:a Process-based TEEMe

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要介绍了Iris Ding和Malini Bhandaru等人在硬件安全模块(HSM)领域的相关工作,以及他们提出的Distributed HSM解决方案。硬件安全模块是一种物理计算设备,用于保护和管理数字密钥,并执行加密和解密等密码学功能。随着数据泄露和网络攻击的增加,数据安全需求不断上升,硬件安全模块市场预计到2028年将达到200亿美元,年复合增长率为13.1%。 Distributed HSM解决方案具有高度的安全性,即使在边缘位置也能保证安全,同时具有较低的延迟和更高的吞吐量,且成本较低。为实现这一目标,文章提出了使用可信执行环境(TEE)的方案,如Intel SGX,它提供了硬件和固件支持,确保代码和数据的机密性和完整性。文章还介绍了两个使用案例,分别是基于Istio服务网格的加密操作和证书颁发机构(CA)的信任证书服务。 总之,本文主要探讨了硬件安全模块在数据安全领域的重要性,以及提出的Distributed HSM解决方案,通过使用可信执行环境等技术,实现了高度安全、低延迟、高吞吐量和低成本的目标。
"硬件安全模块(HSM)是什么?" "分布式HSM如何解决云HSM的挑战?" "如何使用Trusted Execution Environments (TEEs)来提高数据安全性?"
客服
商务合作
小程序
服务号
折叠