azure: every evidence generation pays a fixed 3s sleep and an IMDS round-trip
还没有人认领这个 Issue。
评估
调研方向
从 crates/attestation/src/azure/mod.rs 中的 create_azure_attestation 开始,跟踪 vtpm::get_report_with_report_data 和 vtpm::get_quote。将缓存的 HCL report 和 TD quote proposal 与现有的 verification 及 AK provenance chain 进行比较,同时纳入 concurrency 和 TCB freshness 之间的权衡。完成该任务需要 maintainer 决定是否接受此 binding change,或者是否改为推进 upstream polling improvement。
由索引模型根据 Issue 内容生成。
描述
Main idea: consider a cached HCL report/TD quote with freshness from the TPM quote nonce.
create_azure_attestation (crates/attestation/src/azure/mod.rs) binds
the caller's 64-byte input into the evidence by writing it into the HCL
report's user_data:
let hcl_report_bytes = vtpm::get_report_with_report_data(&input_data)?;
Inside az-tdx-vtpm/az-cvm-vtpm, that call writes the input to a shared NV
index, sleeps a fixed 3 seconds while the paravisor regenerates the HCL
report, and reads it back. Because the report data changes per call, the
TD quote must then also be re-fetched from IMDS on every call. The
consequences:
- every evidence generation costs 3+ seconds of pure sleep plus an IMDS
round-trip; - the write→sleep→read sequence over shared NV indices races against any
concurrent evidence generation on the same VM, so callers must serialize
evidence generation machine-wide (a mismatched report is caught by
user_data verification, but the exchange fails and must retry).
An upstream improvement (poll for user_data match instead of the fixed
sleep — filed as https://github.com/kinvolk/azure-cvm-tooling/issues/93) fixes the
latency overhang and the staleness, but not the fundamental contention:
there is one report-data channel per VM.
The evidence document already carries a second binding channel: the TPM
quote is generated over the caller's input (vtpm::get_quote(&input_data[..32])).
If verification relied on the TPM quote's qualifying data plus the AK
provenance chain (TD quote → HCL runtime claims bind the AK → AK
certificate → TPM quote), the HCL report would no longer need
per-exchange report data at all: the HCL report and the TD quote both
become static for the VM lifetime and can be fetched once and cached.
Evidence generation then reduces to a single TPM quote — no NV write, no
sleep, no IMDS round-trip, and safely concurrent (especially over
/dev/tpmrm0, per the companion TCTI issue).
The trade-offs are real, so filing this as a discussion point rather than
a straightforward fix: the caller input would no longer be embedded in the
TDX quote itself (binding moves entirely to the vTPM AK chain), and a
cached TD quote reflects TCB status as of quote time rather than exchange
time. Interested in whether this direction is acceptable, or whether you
would rather keep the per-exchange TD-quote binding and take only the
upstream polling improvement.
- 主要语言
- Rust
- 星标
- 6
- 派生
- 3
- 平均合并
- 2 天 20 小时
- 30 天内合并 PR
- 3
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
flashbots/attested-tls 的其他 Issue
-
难度 5/5 一周以上 新手友好度 35/100
flashbots/attested-tls#97 ·
-
难度 5/5 一周以上 新手友好度 45/100
flashbots/attested-tls#92 · 4 条评论 ·
-
难度 3/5 1-2 天 新手友好度 68/100
flashbots/attested-tls#87 · 1 条评论 ·
-
难度 4/5 3-5 天 新手友好度 45/100
flashbots/attested-tls#84 · 7 条评论 ·
-
难度 3/5 1-2 天 新手友好度 58/100
flashbots/attested-tls#82 · 1 条评论 ·
查看 flashbots/attested-tls 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 3 天内回复
-
state:triage-needed
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
Automattic/harper#4503 ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 92/100
维护者通常 2 天内回复