Security Enhancement of Ansible Based on Intel SGX
CSTR:
Author:
Affiliation:

Clc Number:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    As one of the most popular tools for automatic operation and maintenance in cloud platforms, Ansible usually stores a lot of administrator accounts information in a configuration file for batching executions. The configuration file is usually stored in the disk in plain text. However, it is not safe in the cloud because the confidentiality and integrity of configuration of Ansible depend on the security of the underlying software. Therefore, it is crucial to reinforce the security of configuration management mechanism of Ansible. In this paper, we implement a configuration management component for Ansible based on SGX (Software Guard eXtensions) proposed by Intel in recent years, which can manage the configuration information of Ansible in a trusted execution environment (TEE) independently. With this component, the configuration information cannot be read or written from outside and its security doesn't depend on the underlying software. The experiments show that our solution is more reliable, and the extra overhead is also acceptable. It is possible to extend our application to a general component for configuration protection in cloud platforms such as OpenStack.

    Reference
    Related
    Cited by
Get Citation

杨骁,于佳耕,武延军.基于Intel SGX的Ansible安全增强.计算机系统应用,2017,26(10):67-72

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:January 04,2017
  • Revised:
  • Adopted:
  • Online: October 31,2017
  • Published:
Article QR Code
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063