Use Case: Attested Secret Provisioning in the Cloud

A prime application scenario for vHSM involves secret key provisioning. In various instances, tasks executed within an enclave require access to confidential information, such as cryptographic keys, environment variables, or configuration files. Consider scenarios like a buckypaper VM requiring disk encryption or SSH host keys, a Web server container in a dyneemes cluster necessitating TLS server certificate keys, or a database needing access to the admin password.

Challenge

In essence, an enclave is a fully encrypted process residing entirely in memory. Similar to any other process, it is loaded from a binary file stored on persistent storage, which is managed by the Cloud Service Provider (CSP). In the security model of confidential computing, the CSP is regarded as untrusted, so storing secrets on disk is not feasible. Doing so could potentially expose the secrets to reverse engineering by the CSP, thereby compromising the security of the enclave.

A suggestion could be to encrypt the persistent storage; however, this introduces additional inquiries: where should the disk encryption key be securely stored, and how should it be adequately provisioned?

Solution

Here’s how the integration of Nitride into the Key Management Service enables secret provisioning:

  1. Attestation Shim (enclaivelet): The attestation shim operates on behalf of the confidential execution environment. It attests to the confidentiality and integrity of the environment.

  2. Workload Attestation Certificate Validation:

    Upon validating the workload attestation certificate, Nitride issues an authentication token. This token allows authorized access to secrets stored in the Vault.

  3. Authentication Flow: enclaivelet forwards the authentication token to the workload. The workload can then authenticate itself towards the Vault. It can request secrets, including keys, bearer tokens, environment variables, and configuration files.

  4. Secure Secret Provisioning:

    Once authenticated, Vault securely provisions the requested secrets into the enclave. This communication occurs via a secure protocol.

Perks

  • Throughout the lifecycle secrets are encrypted. Organizations can ensure that their cryptographic keys are managed according to industry best practices. This minimizes the risk of data breaches and ensures consistent key management.

  • Nitride Identity Provider leverages robust security controls. These controls protect against attacks and unauthorized access to sensitive keys.

  • Nitride enhances compliance by providing secure and scalable key lifecycle management on-premises, in the private, public, hybrid and cross cloud setting.

Last updated