A Runtime Trust Evaluation Mechanism in the Service Mesh Architecture

Rami Alboqmi, Sharmin Jahan, Rose Gamble · 2023

With the advancement of cloud-native computing, enterprise software is shifting towards a microservice architecture (MSA). In a MSA, the application is built as a composite of microservices (also called services) where each service is dedicated to providing specific functionalities and communicating via APIs. The service mesh is a dedicated infrastructure layer serving as a service-to-service communication platform. It is introduced to alleviate the complexity, manageability, and interoperability challenges involved in a MSA. Even though the service mesh includes APIs to secure service-to-service communication, more functionality is needed to handle the perimeter-less and dynamic cloud environment. The existing APIs enable security measures based on a pre-defined configuration. However, there is no mechanism for dynamic trust evaluation of the participating services, which is necessary to protect the application from potential attacks. Attackers can exploit a vulnerability caused by a rouge service as a backdoor to compromise the application. Thus, there is a need for a trust evaluation mechanism in the service mesh to follow zero-trust architecture (ZTA) principles. This paper introduces a runtime trust evaluator (RTE) incorporated as a component within the service mesh control plane. A RTE can evaluate the trustworthiness of services at runtime before establishing service-to-service communications. The core functionality of a RTE is to assess the new service invocation requests initiated by a service to evaluate the trustworthiness of that service. The RTE collects the services’ invocation history and other telemetric data to determine the services’ criticality level for single-point failure. The RTE assesses service invocation request attributes to determine the existence of an unauthorized request and the impact on the requested service’s criticality level. The result is an evaluation of the initiator service’s trustworthiness. We demonstrate our approach on an open source microservice application from the Google Cloud team called Online Boutique. The environment setup uses Kubernetes as an orchestration solution and Istio as the service mesh platform.

Read the paper · More papers on PaperTik