SYS-CON MEDIA Authors: Elizabeth White, Pat Romanski, Carmen Gonzalez, Gary Arora, Zakia Bouachraoui

Blog Feed Post

Announcing Enomaly ECP High Assurance Edition for Trusted Cloud Computing

Uses A Variety of Hardware Assisted Security Mechanisms

Today I am in Beijing, China at the Intel Developer Forum (IDF) and am happy to announce the latest Enomaly product offering, The ECP High Assurance Edition (HAE). ECP HAE has been something we've been busy developing in partnership with Intel over the last 18 months and continues on the previous research of world renowned security expert Dr. David Lie from the University of Toronto. The platform uses a variety of hardware assisted security mechanisms to provide what we believe is the most secure public cloud computing platform for service providers available today. In this post, I thought I'd take a moment to dive into some of the technical capabilities of HAE and our rationale.

Like it or not, security concerns have been a key factor limiting the adoption of cloud computing services. We believe that customers with higher security requirements, such as banks, health and government agencies, have been right to be cautious about the security capabilities of exiting public clouds. Our new technology will enable these customers to begin to reap the benefits of cloud computing, by giving them reliable proof the underlying environment hasn't been compromised. In the most simple terms, ECP HAE provides a trusted and verified cloud computing infrastructure.

To give a little more background, the Enomaly ECP HAE platform allows a remote cloud user to establish trust in a cloud provider's platform. The end customer uses Enomaly's ECP HAE client, which uses our patented technology to verify the integrity of the cloud provider's software stack. When the client is connected to an "approved" HAE-verified platform, Enomaly's HAE client displays a prominent positive verification screen indicating that the platform is safe to use. Validation can also be provided programmatically and integrated into existing application monitoring solutions and business processes engines which enables a extra level of verifiable trust when using remote cloud resources. If a remote providers environment changes for any reason you will know proactively before it's too late. HAE changes cloud security from a reactive process to a proactive one and enables a variety of new potential applications never possible before because of the lack of insight into cloud service providers' infrastructures. 

What might happen if the cloud provider's hypervisor were to be tampered with?  This could happen for a variety of reasons.  For example, a disgruntled employee at the cloud provider might want to steal secrets from the cloud provider's customers, or there could be a malicious insider paid by a competitor to spy on the VMs of the cloud users.  Similarly, the hypervisor itself may have a security vulnerability that is exploited, allowing a remote attacker outside of the cloud provider to tamper with the cloud provider's hypervisor. Since the hypervisor is the most trusted component in a cloud computing infrastructure, any loss of its integrity means an immediate and catastrophic breach of security which could easily never be detected because of the very nature of the hypervisor - it makes you or your applications see what whatever it whats you to believe. So even a exploited hypervisor will appear to be normal from the point of a virtual machine making VM based security a risky endeavor to say the least. HAE goes a long way toward solving this problem. 

Enomaly HAE enables our hosting & cloud service provider customers to securely establish the integrity of the remote platform. To do this, Enomaly's HAE system uses Intel's TXT processor extensions along with a Trusted Computing Group (TCG) Trusted Platform Module (TPM) in conjunction to the Xen hypervisor. We use a mechanism called remote attestation, which until now has only been explored [mostly] in experimental research settings. Thanks in part to the work of our lead security architect, Dr David Lie, we've taken the bold step of making attestation practical by integrating it into the ECP system targeting IaaS hosting providers. HAE takes care of all the complexity of making the attestation requests, ensuring that the requests cannot be tampered with and distilling the result of the attestation requests into a simple and easy to understand safe / not safe message. More importantly, this trust can be directly integrated into existing monitoring and business processes to ensure only truly secure remote cloud environments are being utilized in a completely automated way.

ECP High Assurance Edition is available immediately to service providers interested in offering a high-security cloud computing platform to their customers.  In addition to its unique security features, ECP HAE includes the industry-leading capabilities of Enomaly's ECP platform, enabling a service provider's customers to access and manage any number of virtual servers, running Microsoft Windows, Linux, Solaris, or any other operating system with the software applications of their choice.  Customers can access and manage their virtual servers through a web-based dashboard, and can also automatically scale up and down their use of cloud servers through a robust API.

We are delighted to be able to deliver this uniquely differentiated offering to our service provider customers We believe the fast-growing market for cloud computing services will benefit from the improved security that service providers can offer their customers by using Enomaly ECP HAE.

(Posted via email from China - please ignore any strange formatting).

 

More Stories By Reuven Cohen

An instigator, part time provocateur, bootstrapper, amateur cloud lexicographer, and purveyor of random thoughts, 140 characters at a time.

Reuven is an early innovator in the cloud computing space as the founder of Enomaly in 2004 (Acquired by Virtustream in February 2012). Enomaly was among the first to develop a self service infrastructure as a service (IaaS) platform (ECP) circa 2005. As well as SpotCloud (2011) the first commodity style cloud computing Spot Market.

Reuven is also the co-creator of CloudCamp (100+ Cities around the Globe) CloudCamp is an unconference where early adopters of Cloud Computing technologies exchange ideas and is the largest of the ‘barcamp’ style of events.

Latest Stories
Data center, on-premise, public-cloud, private-cloud, multi-cloud, hybrid-cloud, IoT, AI, edge, SaaS, PaaS... it's an availability, security, performance and integration nightmare even for the best of the best IT experts. Organizations realize the tremendous benefits of everything the digital transformation has to offer. Cloud adoption rates are increasing significantly, and IT budgets are morphing to follow suit. But distributing applications and infrastructure around increases risk, introdu...
DevOps has long focused on reinventing the SDLC (e.g. with CI/CD, ARA, pipeline automation etc.), while reinvention of IT Ops has lagged. However, new approaches like Site Reliability Engineering, Observability, Containerization, Operations Analytics, and ML/AI are driving a resurgence of IT Ops. In this session our expert panel will focus on how these new ideas are [putting the Ops back in DevOps orbringing modern IT Ops to DevOps].
Atmosera delivers modern cloud services that maximize the advantages of cloud-based infrastructures. Offering private, hybrid, and public cloud solutions, Atmosera works closely with customers to engineer, deploy, and operate cloud architectures with advanced services that deliver strategic business outcomes. Atmosera's expertise simplifies the process of cloud transformation and our 20+ years of experience managing complex IT environments provides our customers with the confidence and trust tha...
Moving to Azure is the path to digital transformation, but not every journey is effective. Organizations that start with a cohesive, well-planned migration strategy can avoid common mistakes and stay a step ahead of the competition. Learn from Atmosera CEO, Jon Thomsen about the opportunities and challenges found in three pivotal phases of the journey to the cloud: Evaluation and Architecting, Migration and Management, and Optimization & Innovation. In each phase, there are distinct insights tha...
Every organization is facing their own Digital Transformation as they attempt to stay ahead of the competition, or worse, just keep up. Each new opportunity, whether embracing machine learning, IoT, or a cloud migration, seems to bring new development, deployment, and management models. The results are more diverse and federated computing models than any time in our history.
Intel is an American multinational corporation and technology company headquartered in Santa Clara, California, in the Silicon Valley. It is the world's second largest and second highest valued semiconductor chip maker based on revenue after being overtaken by Samsung, and is the inventor of the x86 series of microprocessors, the processors found in most personal computers (PCs). Intel supplies processors for computer system manufacturers such as Apple, Lenovo, HP, and Dell. Intel also manufactu...
CloudEXPO has been the M&A capital for Cloud companies for more than a decade with memorable acquisition news stories which came out of CloudEXPO expo floor. DevOpsSUMMIT New York faculty member Greg Bledsoe shared his views on IBM's Red Hat acquisition live from NASDAQ floor. Acquisition news was announced during CloudEXPO New York which took place November 12-13, 2019 in New York City. Our Silicon Valley 2019 schedule will showcase 200 keynotes, sessions, general sessions, power panels, and...
SUSE is a German-based, multinational, open-source software company that develops and sells Linux products to business customers. Founded in 1992, it was the first company to market Linux for the enterprise. Founded in 1992, SUSE is the world's first provider of an Enterprise Linux distribution.
Artifex Software began 25-years ago with Ghostscript, a page description language (PDL) interpreter software prevalent in printing and related applications requiring rendering and/or conversion from one software language to another. Founded by renowned computer scientist Dr. L. Peter Deutsch, our company has thrived on the basis of our sharp focus on this area of expertise, a zealous commitment to quality and a strong customer service orientation. Over 100 OEM partners representing some of th...
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
The graph represents a network of 1,329 Twitter users whose recent tweets contained "#DevOps", or who were replied to or mentioned in those tweets, taken from a data set limited to a maximum of 18,000 tweets. The network was obtained from Twitter on Thursday, 10 January 2019 at 23:50 UTC. The tweets in the network were tweeted over the 7-hour, 6-minute period from Thursday, 10 January 2019 at 16:29 UTC to Thursday, 10 January 2019 at 23:36 UTC. Additional tweets that were mentioned in this...
FinTech is a disruptive innovation that denotes the adoption of technologies that have changed how traditional financial services work. While FinTech is now embedded deeply into the financial services ecosystem, the rise of digital age has paved way to FinTech 2.0 - which is rolling out innovative solutions through emerging technologies at a disruptive pace while maintaining the tenets of security and compliances. Blockchain as a technology has started seeing pilot adoption in FinTech around ...
Now is the time for a truly global DX event, to bring together the leading minds from the technology world in a conversation about Digital Transformation. DX encompasses the continuing technology revolution, and is addressing society's most important issues throughout the entire $78 trillion 21st-century global economy. DXWorldEXPO® has organized these issues along 10 tracks, 22 keynotes and general sessions, and a faculty of 222 of the world's top speakers.
Alan Hase is Vice President of Engineering and Chief Development Officer at Big Switch. Alan has more than 20 years of experience in the networking industry and leading global engineering teams which have delivered industry leading innovation in high end routing, security, fabric and wireless technologies. Alan joined Big Switch from Extreme Networks where he was responsible for product strategy for its secure campus switching, intelligent mobility and campus orchestration products. Prior to Ext...
Japan DX Pavilion at @CloudEXPO Silicon Valley