Pith. sign in

REVIEW

Putting a Padlock on Lambda -- Integrating vTPMs into AWS Firecracker

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2310.03522 v1 pith:QDDE6IQN submitted 2023-10-05 cs.CR cs.ARcs.CY

classification cs.CRcs.ARcs.CY
keywords trustcloudtrustedattackcomputingexplicitfirecrackerintegrating
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

When software services use cloud providers to run their workloads, they place implicit trust in the cloud provider, without an explicit trust relationship. One way to achieve such explicit trust in a computer system is to use a hardware Trusted Platform Module (TPM), a coprocessor for trusted computing. However, in the case of managed platform-as-a-service (PaaS) offerings, there is currently no cloud provider that exposes TPM capabilities. In this paper, we improve trust by integrating a virtual TPM device into the Firecracker hypervisor, originally developed by Amazon Web Services. In addition to this, multiple performance tests along with an attack surface analysis are performed to evaluate the impact of the changes introduced. We discuss the results and conclude that the slight performance decrease and attack surface increase are acceptable trade-offs in order to enable trusted computing in PaaS offerings.

Discussion (0). Continue with ORCID to comment.

Pith tools