Supporting Security Sensitive Tenants in a Bare-Metal Cloud

Amin Mosayyebzadeh,Apoorve Mohan,Sahil Tikale,Mania Abdi,Nabil Schear,Charles Munson,Trammell Hudson,Larry Rudolph,Gene Cooperman,Peter Desnoyers,Orran Krieger
DOI: https://doi.org/10.48550/arXiv.1907.06110
2019-07-14
Abstract:Bolted is a new architecture for bare-metal clouds that enables tenants to control tradeoffs between security, price, and performance. Security-sensitive tenants can minimize their trust in the public cloud provider and achieve similar levels of security and control that they can obtain in their own private data centers. At the same time, Bolted neither imposes overhead on tenants that are security insensitive nor compromises the flexibility or operational efficiency of the provider. Our prototype exploits a novel provisioning system and specialized firmware to enable elasticity similar to virtualized clouds. Experimentally we quantify the cost of different levels of security for a variety of workloads and demonstrate the value of giving control to the tenant.
Distributed, Parallel, and Cluster Computing,Cryptography and Security
What problem does this paper attempt to address?