6 ms·
Asylo: an open-source framework for confidential computing
- hungerstrike 8y agoThe name doesn’t inspire confidence to me. Too close to Asylum, but I guess they’re going for “a silo”. It's just my opinion. I know the meaning of the word Asylum, but as I explained below...it's the association that I get from it. It's like using the word Niggardly - even though the definition is not related to race, people don't use it because it just sounds wrong.
- maltalex 8y ago> Today we’re excited to announce Asylo (Greek for “safe place”)
- gschier 8y agoI think asylum is exactly what they mean. Asylo is the dative singular of asȳlum according to Wiktionary: https://en.wiktionary.org/wiki/asylo https://en.wiktionary.org/wiki/asylo Asylum simply means a shelter or protection from danger.
- geospeck 8y agoMost likely they mean άσυλο[1][2] It has many meanings one of them is "safe place" too. [1] https://en.wiktionary.org/wiki/άσυλο https://en.wiktionary.org/wiki/άσυλο [2] https://el.wiktionary.org/wiki/άσυλο https://el.wiktionary.org/wiki/άσυλο In Greek
- hungerstrike 8y agoYep. I know the meaning, but association of the word with "insane asylums" seems like a bad choice to me. It's like if I said the word niggardly. The meaning is completely unrelated to race, but you're not going to say it.
- blueline 8y agothe other use of the word 'asylum' is a synonym of 'safe place' "seeking political asylum" is a common use
- legostormtroopr 8y agoYou are taking a very niggardly approach to expanding your vocabulary. Asylum can also mean a safe place - for example someone seeking asylum.
- hungerstrike 8y agoWhatever HN. People agree with me - https://arstechnica.com/information-technology/2018/05/google-releases-open-source-framework-for-building-enclaved-apps-for-cloud/?comments=1&post=35269645 https://arstechnica.com/information-technology/2018/05/googl...
- colonelxc 8y agoThe main TEE wikipedia article wasn't very informative for me (about as high level as this blog post). Looking through links off of that brought me to Intel's "Software Guard Extensions" wikipedia[1] article, which actually defines enclaves: "Intel SGX is a set of central processing unit (CPU) instruction codes from Intel that allows user-level code to allocate private regions of memory, called enclaves, that are protected from processes running at higher privilege levels." I still don't fully understand the security model of enclaves (for instance, the same wikipedia page also talks about modifying spectre to work against enclaves[2]). [1]https://en.wikipedia.org/wiki/Software_Guard_Extensions https://en.wikipedia.org/wiki/Software_Guard_Extensions [2]https://github.com/lsds/spectre-attack-sgx https://github.com/lsds/spectre-attack-sgx (disclaimer: I work at Google, but obviously not on this)
- savagaon 8y agoDisclaimer: I am from the Asylo team. You can find an overview of what enclaves are at https://asylo.dev/about/overview.html https://asylo.dev/about/overview.html. The security model of enclaves is as follows: Enclaves rely on the OS for their resource management/scheduling, however, the OS cannot compromise the enclave.
- option_greek 8y agoIs it possible to write applications in languages other than C/Cpp ? Even with Cpp, it appears from the examples that this seems more about handling specific secure data and seem to rely on special data structures. How do we convert existing applications to take advantage of Asylo ? Does it involve moving the sensitive parts to a enclave app and communicating with it from normal one ?
- savagaon 8y agoThe release today is just a start. We are looking at supporting additional languages and toolchains. Future releases/community contributions should also bring richer POSIX support. As to refactoring--it is really up to the developer. With sufficient POSIX support, an entire POSIX-compliant app can live inside an enclave. On the other hand, for security reasons, the developer may decide to refactor their application.
- option_greek 8y agoThis is very exciting. May be this can hold the fort till fully homomorphic computing becomes a reality.
- stenioaraujo 8y agoThis is really promising. The use of enclave is strongly chained to its Hardware. Having a Framework with a plugin-like architecture definitely helps. I may be wrong, but I have the impression that the development of TEE within Virtual Machines and Containers is still in its early stages. I am looking forward to see how Asylo will help on this.
- Confiks 8y ago"Confidential computing" might seem to refer to homomorphic encryption, but has nothing to do with it in its usage here. After searching around a bit, I suspect that Microsoft Azure first used it in 2017 to refer to code running within a trusted enclave. It looks to me that while Asylo is agnostic about the specific TEE used, it is primarily targeted at Intel SGX [1]. Instead of having to trust Google to run your code correctly and not read your data, you'd have to trust Intel to manufacture a secure enclave and essentially bake in a private key that cannot be read. You could use the public key to encrypt your code and workload, and it would run in a part of the processor that Google presumably cannot access (or measure [2]). A good further introduction might be this paper [3] (especially the diagram on page 2), or this answer [4]. I'll repeat my main concern with this system: you will reinforce Intel's position as 'feudal lord' in this model [5]. [1] https://github.com/google/asylo/tree/master/asylo/identity/sgx https://github.com/google/asylo/tree/master/asylo/identity/s... [2] https://arxiv.org/abs/1702.08719 https://arxiv.org/abs/1702.08719 [3] https://eprint.iacr.org/2016/086.pdf https://eprint.iacr.org/2016/086.pdf [4] https://security.stackexchange.com/questions/175749/what-are-the-functional-similarity-and-difference-between-tpm-and-sgx-in-trust-c https://security.stackexchange.com/questions/175749/what-are... [5] https://news.ycombinator.com/item?id=15936121 https://news.ycombinator.com/item?id=15936121
- walterbell 8y agoHas anyone gone through the process of requesting and receiving Intel whitelist permission to run production code within an SGX enclave?
- kitd 8y agoIBM Z Series mainframes also support encryption for all data end-to-end. https://venturebeat.com/2017/07/16/ibm-z-mainframe-brings-end-to-end-encryption-to-all-your-data/ https://venturebeat.com/2017/07/16/ibm-z-mainframe-brings-en...
- stev0lution 8y agoAn extensive open source framework for efficient homomorphic encryption would have been so much more exciting and I really hope there will be some kind of breakthrough that reduces the current overhead significantly so it will be more commonly used in the future.. Oh well, at least there is a theoretical foundation (for completely trustless computation) on which we can build on.
- robododo 8y agoDoes this all hinge on EPID? So will cloud workloads have to phone home to Intel for assertions to be satisfied? My question is built on the presumption that SGX is the only real TEE available right now. Also, how is Google dealing with PRM/EPC memory limitations of SGX?
- bluegate010 8y agoAsylo is not tied to EPID; the framework aims to abstract away any unique behavior specific to TEE implementations, and provide a common backend interface that developers can code against. The goal is to allow developers to easily migrate their apps between backends with little to no source-code changes. Specifically for attestation purposes, Asylo defines the EnclaveAssertionGenerator[1] and EnclaveAssertionVerifier[2] interfaces; these will need technology-specific implementations. In this initial release we only support a simulated backend, for experimental development. We'll continue looking into specific TEE technologies going forward. [1] https://github.com/google/asylo/blob/master/asylo/identity/enclave_assertion_generator.h https://github.com/google/asylo/blob/master/asylo/identity/e... [2] https://github.com/google/asylo/blob/master/asylo/identity/enclave_assertion_verifier.h https://github.com/google/asylo/blob/master/asylo/identity/e...
- userbinator 8y agoMake no mistake: this is nothing more than the old "treacherous computing" that RMS warned about a long time ago, but coming back in new clothes, and is going to be used the most by DRM and other user-hostile applications. They're just trying to sneak it past everyone under the guise of "security" and other ostensibly-somewhat-friendly uses, but don't be fooled. https://www.gnu.org/philosophy/can-you-trust.en.html https://www.gnu.org/philosophy/can-you-trust.en.html https://en.wikipedia.org/wiki/Next-Generation_Secure_Computing_Base https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi...
- bluegate010 8y agoMany of us on the Asylo team share your reservations about DRM. However, the capability to run software in a not-entirely-trustworthy environment leads to many positive possibilities. For instance, you could imagine a world in which customers didn’t have to trust their cloud vendor or worry about their data falling into unauthorized hands. Or you could implement chat applications which can prove to you that your communications really are being encrypted end-to-end. In our view, trusted computing has applications well beyond DRM.
- alexnewman 8y agoI don’t get why people trust Secure Enclave it calls home over tls and dns for ra. Certainly tls can be broken by state actors.