Dstack-TEE / Dstack-TEE/dstack

Static HKDF salt "RATLS" with no key versioning

Aberta
#552 2 comentários 0 reações 0 responsáveis Ver no GitHub
security security: report security: roadmap
Linguagem predominante
Rust
Estrelas
544
Forks
96
Merge médio
23h 40min
PRs com merge (30d)
126

Descrição

The disk encryption key derivation in `dstack/kms/src/main_service.rs` uses a hardcoded, empty HKDF salt rather than a per-instance random salt, reducing HKDF's security margin and making all derived keys deterministic given the same input keying material.

## Root Cause

The RA-TLS key derivation uses a hardcoded salt `b"RATLS"` for all HKDF operations. There is no key versioning mechanism and no support for key rotation. If the HKDF input keying material (IKM) is compromised at any point, all historically derived keys are also compromised because the salt is static and publicly known.

```rust
// kdf.rs:28
const SALT: &[u8] = b"RATLS";
```

## Attack Path

1. Attacker compromises the HKDF input keying material (e.g., via a KMS vulnerability)
2. Because the salt is static and hardcoded, the attacker can re-derive all keys ever produced by this KDF
3. No key versioning means there is no way to distinguish keys from different epochs
4. Key rotation requires changing the IKM, but old keys remain derivable from old IKM + static salt

## Impact

No forward secrecy in the key derivation hierarchy. Compromise of the IKM at any point reveals all past and future derived keys. The static salt provides no additional entropy or domain separation beyond what the IKM already provides.

## Suggested Fix

1. Include a version number in the salt or info parameter: `format!("RATLS-v{}", version)`
2. Support key rotation by allowing the salt to be updated periodically
3. Consider using a random salt persisted alongside the derived keys

---
> **Note:** This issue was created automatically. The vulnerability report was generated by Claude and has not been verified by a human.

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Comece lendo dstack/kms/src/main_service.rs e o código KDF em kdf.rs:28 para verificar como o salt estático é usado e se o impacto relatado se aplica. A issue propõe versionamento, rotação ou salts aleatórios persistidos, mas não seleciona um design; a conclusão exige uma abordagem acordada de derivação e rotação de chaves com a validação correspondente.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
rust
Domínio
cryptography, security
Tipo de issue
Bug
Dificuldade
5/5
Tempo estimado
Mais de uma semana
Status de atividade
Pouca atividade
Clareza
Razoavelmente clara
Facilidade para iniciantes
35/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.