A Roadmap to the Trusted Cloud

by TCG in Action

This week, Trusted Computing Group announced a new effort: the Trusted Multi-Tenant Infrastructure Work Group. While that sounds like a mouthful (and is bound to join the existing TCG alphabet soup), it really means that the group dedicated to enabling Trusted Computing across the enterprise will apply its expertise in hardware-based security to measure and assess the trustworthiness of shared infrastructure in the latest computing paradigm: the cloud. Obviously the users of cloud, or multi-tenant infrastructures, are concerned with how data, access and users are protected. In an article in Network World earlier this year, one provider noted, "...Security concerns will continue to keep some companies out of the cloud."

 

And with attacks proliferating at a dizzying rate, it's unlikely the concern over security will recede into the background. Most believe that multi-tenant infrastructure security requires a holistic, end-to-end approach, but today's approach is patchwork. TCG members believe the industry must address trust and security across solutions derived from combining dedicated and shared infrastructures.

 

What will TCG do to help secure the cloud? The work group's plans include:

 

  • Creating a standards framework for implementing shared infrastructures and multi-provider infrastructures
  • Providing reference models and implementation guidance
  • Identifying and addressing gaps in existing standards

 

Already a number of TCG technologies and standards - the Trusted Platform Modulenetwork security and self-encrypting drives- today secure data, systems and networks, and all of these are relevant to the Trusted Multi-Tenant Infrastructure effort. These technologies will be used to establish trust, exchange information and apply policy. The new TMI Work Group will focus on how we can interface various technical standards to create an end-to-end enterprise solution that is tailored to meet mission and business needs and comply with security policies within public and private business sectors.

 

TCG's efforts will complement work underway on compliance, management, identity and other aspects of cloud computing and security. We are looking for service providers, users and others to help us advance this effort. Interested? Contact TCG!

 

recent white paper talks about general TCG technologies. Stay tuned for new developments.

Categories: Network Security

* Required Fields