用硬件可信执行环境保护云端数据使用中的安全,防住恶意软件和系统漏洞。
Confidential Computing for Cloud Security: Exploring Hardware based Encryption Using Trusted Execution Environments
- 利用Intel SGX和ARM TrustZone等硬件级可信执行环境隔离敏感计算。
- 实验验证其可有效防止数据在处理时被泄露,即使操作系统被攻破。
- 适合关注云安全、数据隐私及高风险应用的开发者与架构师。
云计算的发展极大提升了数据处理与存储的可扩展性和灵活性,但同时也带来了严峻的安全挑战,尤其在保护数据使用过程中的安全性方面。传统加密手段(如静态和传输中加密)无法保障数据在使用时的安全,使其面临多种潜在泄露风险。为此,机密计算应运而生,通过硬件级可信执行环境(TEEs)实现对数据处理过程的保护。TEEs(如Intel SGX和ARM TrustZone)在处理器内部提供受保护的执行上下文,确保数据在使用过程中保持机密性、完整性和安全性,即便面对恶意软件或被攻破的操作系统亦然。本研究系统分析了Intel SGX与ARM TrustZone的架构与安全特性,评估其在提升云数据安全方面的有效性。通过全面文献调研,我们探讨了部署策略、性能指标与实际应用场景,并讨论了部署难题、潜在弱点、可扩展性及集成问题。结果表明,TEEs在强化和推进云安全基础设施中具有核心作用,具备构建机密计算安全基础的能力。
原文摘要 · Abstract (English)
The growth of cloud computing has revolutionized data processing and storage capacities to another levels of scalability and flexibility. But in the process, it has created a huge challenge of security, especially in terms of safeguarding sensitive data. Classical security practices, including encryption at rest and during transit, fail to protect data in use and expose it to various possible breaches. In response to this problem , Confidential Computing has been a tool ,seeking to secure data in processing by usage of hardware-based Trusted Execution Environments (TEEs). TEEs, including Intel's Software Guard Extensions (SGX) and ARM's TrustZone, offers protected contexts within the processor, where data is kept confidential ,intact and secure , even with malicious software or compromised operating systems. In this research, we have explored the architecture and security features of TEEs like Intel SGX and ARM TrustZone, and their effectiveness in improving cloud data security. From a thorough literature survey ,we have analyzed the deployment strategies, performance indicators, and practical uses of these TEEs for the same purpose. In addition, we have discussed the issues regarding deployment, possible weaknesses, scalability issues, and integration issues. Our results focuses on the central position of TEEs in strengthening and advancing cloud security infrastructures, pointing towards their ability to create a secure foundation for Confidential Computing.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。