Running ZooKeeper coordination services in untrusted clouds

Stefan M. Brenner, Colin Wulf, Rüdiger Kapitza · 2014

Cloud computing is a recent trend in computer science. However, privacy concerns and a lack of trust in cloud providers are an obstacle for many deployments. Matur-ing hardware support for implementing Trusted Execu-tion Environments (TEEs) aims at mitigating these prob-lems. Such technologies allow to run applications in a trusted environment, thereby protecting data from unau-thorized access. To reduce the risk of security vulnerabil-ities, code executed inside a TEE should have a minimal Trusted Codebase. As a consequence, there is a trend for partitioning application’s logic in trusted and untrusted parts. Only the trusted parts are executed inside the TEE handling the privacy-sensitive processing steps. In this paper, we add a transparent encryption layer to ZooKeeper by means of a privacy proxy supposed to run inside a TEE. We show what measures are neces-sary to split an application into a trusted and an untrusted part in order to protect the data stored inside, with Zoo-Keeper as an example. With our solution, ZooKeeper can be deployed at untrusted cloud providers, establish-ing confidential coordination for distributed applications. With our privacy proxy, all ZooKeeper functionality is retained while there is little degradation of throughput. 1

Read the paper · More papers on PaperTik