Difference between revisions of "Hardware-Enabled Security"
From MgmtWiki
(→Context) |
|||
| Line 2: | Line 2: | ||
[[Hardware-Enabled Security]] originated as a government category that includes a variety of implementations like TPM, Secure Enclave, [[Trusted Execution Environment]] and many others. | [[Hardware-Enabled Security]] originated as a government category that includes a variety of implementations like TPM, Secure Enclave, [[Trusted Execution Environment]] and many others. | ||
==Context== | ==Context== | ||
| − | [https://csrc.nist.gov/publications/detail/nistir/8320d/draft | + | [https://csrc.nist.gov/publications/detail/nistir/8320d/draft NIST Interagency Report 8320D on Hardware-Enabled Security]<blockquote>Organizations employ a growing volume of machine identities, often numbering in the thousands or millions per organization. Machine identities, such as secret cryptographic keys, can be used to identify which policies need to be enforced for each machine. Centralized management of machine identities helps streamline policy implementation across devices, workloads, and environments. However, the lack of protection for sensitive data in use (e.g., machine identities in memory) puts it at risk. This report presents an effective approach for overcoming security challenges associated with creating, managing, and protecting machine identities throughout their lifecycle. It describes a proof-of-concept implementation, a prototype, that addresses those challenges by using hardware-based confidential computing. The report is intended to be a blueprint or template that the general security community can use to validate and utilize the described implementation.</blockquote> |
==References== | ==References== | ||
Revision as of 17:50, 25 February 2023
Full Title or Meme
Hardware-Enabled Security originated as a government category that includes a variety of implementations like TPM, Secure Enclave, Trusted Execution Environment and many others.
Context
NIST Interagency Report 8320D on Hardware-Enabled SecurityOrganizations employ a growing volume of machine identities, often numbering in the thousands or millions per organization. Machine identities, such as secret cryptographic keys, can be used to identify which policies need to be enforced for each machine. Centralized management of machine identities helps streamline policy implementation across devices, workloads, and environments. However, the lack of protection for sensitive data in use (e.g., machine identities in memory) puts it at risk. This report presents an effective approach for overcoming security challenges associated with creating, managing, and protecting machine identities throughout their lifecycle. It describes a proof-of-concept implementation, a prototype, that addresses those challenges by using hardware-based confidential computing. The report is intended to be a blueprint or template that the general security community can use to validate and utilize the described implementation.