4 ms·
If one can give strong proof that everything done in a VM is encrypted, then would it be possible to create a "decentralized cloud provider", in which data cent
by carlosf 6y ago
If one can give strong proof that everything done in a VM is encrypted, then would it be possible to create a "decentralized cloud provider", in which data center owners agree to a common spec for services?
- zatel 6y agoI think this sounds like the right idea to move towards. With so many similarities in their offerings it seems like the logical next step. Maybe a company can be created to offer a middleware that abstracts all the common offerings into your spec because I don't expect the major cloud providers to do that on their own soon. Cheers to your upcoming IPO when this works out
- luizfelberti 6y agoNot really, physical access to the machine violates pretty much any chain of trust you can conceivably have for most (all?) security models. Federated distributed computing relates to what you're thinking of, but it is an extremely difficult topic, and veers into the realm of blockchains and things like that. There is also the whole area of Zero-Knowledge Proofs/Compute that deals with these matters: https://eprint.iacr.org/2013/229.pdf https://eprint.iacr.org/2013/229.pdf If your threat model falls under the uber-paranoid category, you have to on-prem everything, preferrably inside your very own bunker. There is no getting around this afaik, and if there is there will probably be major tradeoffs (like the blockchain thingy) instead of a "drop-in" replacement for traditional compute.
- joshuamorton 6y agoFully Homomorphic Encryption does also work. But there's other issues that make it infeasible outside of very specific niches (an explosion in the compute cost).
- wang_li 6y agoYou’re looking for haven[0] but I doubt any cloud provider is going to facilitate you splitting your workload to their competitor. https://www.microsoft.com/en-us/research/publication/shielding-applications-from-an-untrusted-cloud-with-haven/ https://www.microsoft.com/en-us/research/publication/shieldi...