80 likes | 185 Views
Trusted Server Environments IEEE CQR – Ft. Myers, FL May 2007 Frank Tycksen – VP of Engineering at SignaCert, Inc. Trusted Platform Focus Today. Trust focused inside the enterprise. Laptops & Desktops. Simplified static trust environment Includes portions of the OS/Kernel in the TCB
E N D
Trusted Server Environments IEEE CQR – Ft. Myers, FL May 2007 Frank Tycksen – VP of Engineering at SignaCert, Inc.
Trusted Platform Focus Today Trust focused inside the enterprise Laptops & Desktops Simplified static trust environment Includes portions of the OS/Kernel in the TCB Relies on post-execution verification Provides verifier with re-constructible evidence of boot chain TNC Measure Extend Verify Execute Verifiable Boot
Trusting Partners and eCommerce • Key Questions • Proof of Trust • Verification • Expression • Normalized Trust Me! • SSL • SLA / Contractual • Audit Controls • Regulatory Compliance Reliance on Third Parties As transactional value increases, so do demands for visibility and trustworthiness.
What Are We Asking? WIDGECO.COM Mainframe & Legacy Servers Load Balancer Routers Switches Firewall Firewall Web Servers Dbase Clusters Routers Switches SOA & SAAS Storage Networks • Taking A Systems Perspective • Highly heterogeneous • Loads of legacy • Variety of vendors • External dependencies Financial Servers Partners How do we get a common reference?
Measure & Verify Relative to Self Measure & Verify Relative to World A Starting Point WIDGECO.COM Statement of Health Integrity Partners Authenticity
Virtual Appliance Virtualization Impact • Key drivers: • Low Utilization • Power Costs • Rack space & Cooling Business Agility Authenticity Integrity Measure and Verify VM Lifecycle Suspend Create Start Migrate Destroy Stop
Summary for the Trusted Enterprise • Complete trusted enterprise mechanisms are nascent • Few vendors providing complete capabilities, today • Hard to find in commercial non-PC platforms (routers, switches, etc.) • External measurement & verification mechanisms required for asserting trust • Measurement is the common starting point • Normalized to a standard • Common usage • With vendor support can make integrity and source authenticity guarantees • Standardized measurement leads to … • Visibility and understanding of systems • Greater reliability, security and compliance • Improved business agility • Virtualization… more of a reality • Creates new system management challenges • Defining new platforms and service delivery models