首页> 外文期刊>IEEE transactions on dependable and secure computing >STYX: A Hierarchical Key Management System for Elastic Content Delivery Networks on Public Clouds
【24h】

STYX: A Hierarchical Key Management System for Elastic Content Delivery Networks on Public Clouds

机译:Styx:公共云上的弹性内容交付网络的分层关键管理系统

获取原文
获取原文并翻译 | 示例

摘要

Hosting content delivery networks (CDNs) on clouds has the potential to improve the performance as resources and caches can be placed closer to subscribers. However, avoiding data leakage over an untrusted public cloud is critical, especially for sensitive data such as the SSL private key. The popular Keyless SSL solution allows content owners to retain on-premise custody of SSL private keys on their own key servers, but this solution likely causes performance bottlenecks and impedes the elasticity of CDNs. This paper describes a novel key management system, named STYX, for transmitting trusted data over untrusted channels and storing them on untrusted platforms. STYX accomplishes secure key provisioning for CDN scale-out and the key is securely protected with full revocation rights for CDN scale-in. STYX is implemented as a three-phase hierarchical key management scheme by leveraging Intel Software Guard Extensions (SGX) and QuickAssist Technology (QAT). Furthermore, STYX supports CDN services by integrating Nginx as the SSL termination proxy and the popular Redis/Memcached/Apache as backend caching engines. The performance evaluation shows that STYX significantly outperforms the native HTTPS servers on the CDN node due to QAT acceleration, providing up to a 5x enhancement in throughput and a 50 percent reduction in latency.
机译:覆盖云上的内容交付网络(CDN)有可能提高性能,因为资源和高速缓存可以更接近订阅者。但是,避免在不受信任的公共云上泄露的数据泄漏至关重要,特别是对于诸如SSL私钥等敏感数据。流行的无钥匙SSL解决方案允许内容所有者在自己的关键服务器上保留SSL私钥的内部内部保管,但此解决方案可能会导致性能瓶颈并阻碍CDN的弹性。本文介绍了名为STYX的新型密钥管理系统,用于将可信数据传输不受信任的信道并将其存储在不受信任的平台上。 Styx完成了CDN缩放的安全键配置,密钥被安全地保护了CDN Scale-In的完全撤销权。 STYX通过利用英特尔软件保护扩展(SGX)和Quickist技术(QAT)来实现为三相分层关键管理方案。此外,Styx通过将Nginx作为SSL终端代理和流行的Redis / Memcached / Apache作为后端缓存引擎进行支持,支持CDN服务。性能评估表明,由于QAT加速,STYX显着优于CDN节点上的天然HTTPS服务器,可提供吞吐量的5倍,降低50%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号