Privacy-preserving Remote Attestation of pods in Kubernetes
Stefano Caradonna
Privacy-preserving Remote Attestation of pods in Kubernetes.
Rel. Antonio Lioy, Lorenzo Ferro. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2025
|
Preview |
PDF (Tesi_di_laurea)
- Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (4MB) | Preview |
|
|
Archive (ZIP) (Documenti_allegati)
- Altro
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (10MB) |
Abstract
The advent of cloud computing has led to a paradigm shift in application and data management, offering greater flexibility, availability and cost-efficiency. Unlike traditional on-premises environments, wherein data and computations are executed locally, cloud-based systems abstract both storage and processing, thereby enabling dynamic resource allocation. The contemporary tendency towards the adoption of fully virtualised environments, wherein multiple tenants' workloads are shared across a common infrastructure, is indicative of this transition. While this model enhances efficiency and reduces operational costs, it also introduces new security challenges, particularly in ensuring the integrity of cloud-based workloads and protecting sensitive data from unauthorised access. In this context, Remote Attestation emerges as a security mechanism designed to verify the integrity of running applications by analysing system measurements, thus ensuring trust in cloud-based workloads despite the inherent risks of shared infrastructure.
These measurements, recorded in Measurement Logs (ML) by the Integrity Measurement Architecture (IMA) in Linux, provide a snapshot of the system's state, ensuring that applications and their dependencies remain unaltered
Tipo di pubblicazione
URI
![]() |
Modifica (riservato agli operatori) |
