Dstack-TEE / Dstack-TEE/dstack

Alternative to RATLS

Offen
#113 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
security security: roadmap
Vorherrschende Sprache
Rust
Sterne
544
Forks
96
Ø Merge
23 Std. 40 Min.
Gemergte PRs (30 T.)
126

Beschreibung

## Summary
There's [discussion](https://github.com/Dstack-TEE/dstack/pull/91#discussion_r1937196136) about moving away from relying solely on Remote Attestation TLS (RATLS) and considering alternative approaches for secure communication between services.

## Current Approach
Currently using RATLS for several services:
- KMS: onboarding RPC, key providing RPC
- tproxy: registering RPC
- CVM: Inter-App Secure Communication (WIP)

## Concerns
- Performance issues with RATLS (~1s for Azure to establish connection, longer if PCCS fetch needed)
- RATLS hides some implementation details which may be less transparent

## Alternative Approaches
- **Application-level attestation**: Exchange regular TLS certificates along with their attestations
- **Pre-registration approach**: Have each KMS instance register locally generated TLS cert+attestation on boot

## Considerations
- Remote attestation must happen at some level (TLS, HTTP, or Application)
- TLS-level attestation is easier to abstract and reuse across services
- Application-level attestation makes the security more visible but requires additional MITM protections
- Performance is critical for inter-app communication, less so for registration/onboarding

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.