Digital Edition

SYS-CON.TV
Trusting Cloud Computing
Trust is an important word in the world of security

Cloud Security Journal on Ulitzer

The company I work for, HyTrust, recently worked with Intel and VMware on a very cool project.

Essentially, it was about demonstrating the ability to establish trust in the cloud, and then enforce policy based on trust.

Trust.

Trust is an important word in the world of security, and in cloud computing it's an even bigger deal.

Cloud computing offers up the promise that an organizations will be able to run any application from anywhere at any time. But in a multi-tenant environment, a cloud application running in a virtual machine might be located on any number of hosts in a virtualized datacenter, and running next to others' virtual machines on those hosts.


4th International Cloud Computing Conference & Expo attracted more than 50 sponsors, among leading Cloud technology providers and visited by 2,250 conference delegates, November 2-4, 2009, at the Santa Clara Convention Center, CA

So, if we're talking about critical applications - for example, a credit card transaction system - how can anyone guarantee the environment is secure? It's a difficult problem and one that must be solved. It's absolutely essential for trust to be established before customers can feel confident about turning over their applications to cloud infrastructure.

And that's where we began.

The prototype we developed with Intel and VMware is a strong one. It uses hardware-level security capabilities to protect against software-based attacks and to establish a "trust status" for the system. And the beauty part is that policy can then be enforced based on that trust status (for example, allowing virtual machines to be powered on or live migrated only to trust hosts). Intel's TXT technology essentially allows trust to be measured at boot-time and for applications to run within their own execution environment. VMware's vSphere technology then provides APIs which HyTrust leverages to determine this trust status which then gets included in the policy decisions that HyTrust makes for the virtual infrastructure.

TXT will be embedded in Intel's next generation chip technology for 2010 and going forward. By providing hardware-level security through to the hypervisor with HyTrust, the virtualized host can be secured and trusted. This will not only provide differentiation for Intel, VMware and HyTrust but also drive value for end consumers similar to how digital signatures are used to validate the authenticity of electronic documents.

How does all this affect consumers of cloud computing in the long run?

Well, as industry insiders know, cloud environments today have no uniform standard for security and compliance. Similar to banking before FDIC insurance became standard, consumers of cloud services have no way to compare the security of cloud providers on an apples-to-apples basis. This issue will become more and more important as cloud computing evolves and companies host a greater number of critical systems and applications in their cloud environments. The "trust measurement" of cloud environments is still up in the air and many options are being proposed. It very well may end up becoming similar to the type of VeriSign certificates that are used to validate the authenticity of e-commerce websites. And one day we might also be looking to see a certified "stamp" of approval.

In fact, perhaps someday trust will be as easy to identify as the Intel Inside logo.

About Eric Chiu
Eric Chiu is CEO and founder of HyTrust, an early stage startup focused on secure virtualization management and compliance. He has in-depth knowledge about what’s needed to achieve the same level of operational readiness in virtual, as in physical I.T. infrastructures. Previously Eric served in executive roles at Cemaphore, MailFrontier, mySimon, and was a venture capitalist at Brentwood/Redpoint, Pinnacle, and M&A at Robertson, Stephens and Company.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1



ADS BY GOOGLE
Subscribe to the World's Most Powerful Newsletters

ADS BY GOOGLE

The best way to leverage your CloudEXPO | DXWorldEXPO presence as a sponsor and exhibitor is to plan...
JETRO showcased Japan Digital Transformation Pavilion at SYS-CON's 21st International Cloud Expo® at...
HyperConvergence came to market with the objective of being simple, flexible and to help drive down ...
@DevOpsSummit at Cloud Expo, taking place November 12-13 in New York City, NY, is co-located with 22...
With 10 simultaneous tracks, keynotes, general sessions and targeted breakout classes, @CloudEXPO an...
DXWorldEXPO LLC announced today that the upcoming DXWorldEXPO | CloudEXPO New York event will featur...
22nd International Cloud Expo, taking place June 5-7, 2018, at the Javits Center in New York City, N...
"We're focused on how to get some of the attributes that you would expect from an Amazon, Azure, Goo...
In his keynote at 19th Cloud Expo, Sheng Liang, co-founder and CEO of Rancher Labs, discussed the te...
We all know that end users experience the Internet primarily with mobile devices. From an app develo...
We all know that end users experience the internet primarily with mobile devices. From an app develo...
We all know that end users experience the internet primarily with mobile devices. From an app develo...
DXWorldEXPO LLC announced today that All in Mobile, a mobile app development company from Poland, wi...
All organizations that did not originate this moment have a pre-existing culture as well as legacy t...
We are seeing a major migration of enterprises applications to the cloud. As cloud and business use ...
Founded in 2000, Chetu Inc. is a global provider of customized software development solutions and IT...
DXWorldEXPO LLC announced today that Dez Blanchfield joined the faculty of CloudEXPO's "10-Year Anni...
In his session at 21st Cloud Expo, James Henry, Co-CEO/CTO of Calgary Scientific Inc., introduced yo...
One of the biggest challenges with adopting a DevOps mentality is: new applications are easily adapt...
I think DevOps is now a rambunctious teenager - it's starting to get a mind of its own, wanting to g...