arXiv · 2407.12623
LSKV: A Confidential Distributed Datastore to Protect Critical Data in the Cloud
Abstract
Software services are increasingly migrating to the cloud, requiring trust in actors with direct access to the hardware, software and data comprising the service. A distributed datastore storing critical data sits at the core of many services; a prime example being etcd in Kubernetes. Trusted execution environments can secure this data from cloud providers during execution, but it is complex to build trustworthy data storage systems using such mechanisms. We present the design and evaluation of the Ledger-backed Secure Key-Value datastore (LSKV), a distributed datastore that provides an etcd-like API but can use trusted execution mechanisms to keep cloud providers outside the trust boundary. LSKV provides a path to transition traditional systems towards confidential execution, provides competitive performance compared to etcd, and helps clients to gain trust in intermediary services. LSKV forms a foundational core, lowering the barriers to building more trustworthy systems.
Explore related subjects
Keep this discovery
Andrew Jeffery, Julien Maffre, Heidi Howard, Richard Mortier. 2024-07-17. LSKV: A Confidential Distributed Datastore to Protect Critical Data in the Cloud. https://arxiv.org/abs/2407.12623
Cite the original work for its findings. Save a collection to share your selection of sources.