Authenticating Distributed Systems Using SPIRE over Kubernetes Cluster

Akarsh Goel, B. Thangaraju
{"title":"Authenticating Distributed Systems Using SPIRE over Kubernetes Cluster","authors":"Akarsh Goel, B. Thangaraju","doi":"10.1109/CONECCT55679.2022.9865835","DOIUrl":null,"url":null,"abstract":"Distributed systems like microservices, containerized applications and cloud computing are considered crown jewels for developing business driven applications. These systems provide scalability, resiliency, ease of accessibility and act like self-contained independent applications. As microservices grow, it becomes difficult to establish secure communication with them. Absence of secure communication could lead to security breaches like identity spoofing, identity repudiation, data in-confidentiality, broken data integrity and data un-availability. If a rogue microservice exists in the organization's environment, it could easily access critical microservices residing in the environment.SPIRE Project, an implementation of the Secure Production Identity Framework for Everyone (SPIFFE), is an open- source standard which could be leveraged to solve above- mentioned security challenges. This paper talks about various capabilities of the SPIFFE framework for secure bootstrapping and issuing unique cryptographic identities to distributed systems. We would showcase how distributed systems could mutually authenticate to prove their individual identities, before these systems could try and access critical data.","PeriodicalId":380005,"journal":{"name":"2022 IEEE International Conference on Electronics, Computing and Communication Technologies (CONECCT)","volume":"146 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-07-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE International Conference on Electronics, Computing and Communication Technologies (CONECCT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CONECCT55679.2022.9865835","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Distributed systems like microservices, containerized applications and cloud computing are considered crown jewels for developing business driven applications. These systems provide scalability, resiliency, ease of accessibility and act like self-contained independent applications. As microservices grow, it becomes difficult to establish secure communication with them. Absence of secure communication could lead to security breaches like identity spoofing, identity repudiation, data in-confidentiality, broken data integrity and data un-availability. If a rogue microservice exists in the organization's environment, it could easily access critical microservices residing in the environment.SPIRE Project, an implementation of the Secure Production Identity Framework for Everyone (SPIFFE), is an open- source standard which could be leveraged to solve above- mentioned security challenges. This paper talks about various capabilities of the SPIFFE framework for secure bootstrapping and issuing unique cryptographic identities to distributed systems. We would showcase how distributed systems could mutually authenticate to prove their individual identities, before these systems could try and access critical data.
在Kubernetes集群上使用SPIRE对分布式系统进行认证
像微服务、容器化应用程序和云计算这样的分布式系统被认为是开发业务驱动应用程序的皇冠上的宝石。这些系统提供可伸缩性、弹性、易访问性,并像自包含的独立应用程序一样运行。随着微服务的增长,与它们建立安全通信变得越来越困难。缺乏安全通信可能导致安全漏洞,如身份欺骗、身份否认、数据保密、数据完整性破坏和数据不可用。如果组织的环境中存在流氓微服务,那么它可以很容易地访问驻留在该环境中的关键微服务。SPIRE项目是人人安全生产身份框架(SPIFFE)的一个实现,是一个开源标准,可以用来解决上述安全挑战。本文讨论了SPIFFE框架用于安全引导和向分布式系统发布唯一加密身份的各种功能。在这些系统尝试访问关键数据之前,我们将展示分布式系统如何相互验证以证明其个人身份。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信