AMD SEV-SNP로 Amazon EC2 인스턴스 증명하기
AMD SEV-SNP로 Amazon EC2 인스턴스 증명하기 (Attest an Amazon EC2 instance with AMD SEV-SNP)
증명(attestation)은 인스턴스가 자신의 상태와 정체성을 증명할 수 있게 해주는 프로세스예요. 인스턴스에 AMD SEV-SNP를 활성화하면 기본 프로세서에서 AMD SEV-SNP 증명 보고서(attestation report)를 요청할 수 있어요. AMD SEV-SNP 증명 보고서에는 초기 게스트 메모리 내용과 초기 vCPU 상태의 암호화 해시인 시작 측정값(launch measurement)이 들어 있어요. 증명 보고서는 AMD 루트 오브 트러스트(root of trust)로 연결되는 VCEK 서명(전용 호스트) 또는 VLEK 서명(공유 테넌시)으로 서명돼요. 증명 보고서에 포함된 시작 측정값을 사용해 인스턴스가 진짜 AMD 환경에서 실행 중인지 검증하고, 인스턴스를 시작하는 데 사용된 초기 부팅 코드를 검증할 수 있어요.
출처: 문서
본문
사전 요구 사항 (Prerequisite)
AMD SEV-SNP가 활성화된 인스턴스를 시작해요. 자세한 내용은 EC2 인스턴스에 AMD SEV-SNP 활성화하기를 참고하세요.
전용 호스트의 인스턴스 증명 (Attestation for instances on Dedicated Hosts)
전용 호스트는 VCEK(Versioned Chip Endorsement Key)라는 칩별 고유 서명 키로 증명 보고서를 서명해요. VCEK 인증서에서 AMD의 루트 오브 트러스트까지 거슬러 올라가는 신뢰 체인을 검증해야 해요.
참고 현재 지원되는 프로세서 모델은
milan이에요.
사전 요구 사항 (Prerequisites)
AMD SEV-SNP가 활성화된 전용 호스트에서 실행되고 Git, Cargo, Perl이 설치된 인스턴스.
1단계: snpguest 유틸리티 빌드 (Step 1: Build the snpguest utility)
이 단계에서는 증명 보고서를 생성하고 필요한 인증서를 가져오며 증명 보고서를 검증하는 데 사용할 snpguest 유틸리티를 설치하고 빌드해요.
- 인스턴스에 연결해요.
- 사전 요구 사항이 설치되어 있는지 확인해요.
$ perl --version; cargo --version; git --version
- 다음 명령을 실행해 snpguest 저장소에서 snpguest 유틸리티를 빌드해요.
$ git clone https://github.com/virtee/snpguest.git
$ cd snpguest
$ cargo build -r
$ cd target/release
2단계: 증명 보고서 생성 (Step 2: Generate the attestation report)
증명 보고서에 대한 요청을 생성해요. snpguest 유틸리티는 호스트를 통해 AMD Secure Processor에 증명 보고서를 요청하고, 이를 바이너리 파일로 써요. 다음 예시는 임의의 요청 nonce를 만들어 report.bin에 보고서를 저장해요.
$ ./snpguest report report.bin request-file.txt --random
3단계: VCEK 인증서 체인 가져오고 검증하기 (Step 3: Fetch and validate the VCEK certificate chain)
증명 보고서는 전용 호스트의 AMD 칩에 고유한 VCEK로 서명돼요. VCEK에서 AMD의 루트 오브 트러스트까지 거슬러 올라가는 신뢰 체인을 검증해야 해요.
- AMD Key Distribution Service(KDS)에서 VCEK 인증서를 가져와요. 인증서는 증명 보고서의 칩 ID와 TCB 버전으로 식별돼요.
$ ./snpguest fetch vcek pem ./ ./report.bin --processor-model milan
- 신뢰 체인을 구성하는 AMD 루트 인증서(AMD Root Key(ARK)와 AMD SEV Key(ASK))를 가져와요.
$ ./snpguest fetch ca PEM ./ milan --endorser vcek
- 인증서 체인을 검증해요.
$ ./snpguest verify certs ./
다음은 예시 출력이에요.
The AMD ARK was self-signed!
The AMD ASK was signed by the AMD ARK!
The VCEK was signed by the AMD ASK!
선택 사항: 추가 투명성을 위해 인증서를 AMD에서 직접 다운로드하고 openssl을 사용해 체인을 독립적으로 검증할 수 있어요.
$ curl --proto '=https' --tlsv1.2 -sSf https://kdsintf.amd.com/vcek/v1/Milan/cert_chain -o ./cert_chain.pem
$ openssl verify --CAfile ./cert_chain.pem vcek.pem
다음은 예시 출력이에요.
vcek.pem: OK
4단계: 증명 보고서 서명 검증 (Step 4: Validate the attestation report signature)
증명 보고서가 VCEK 인증서로 서명되었는지 확인해요. 이는 보고서가 진짜 AMD 하드웨어에서 생성되었고 변조되지 않았음을 확인해줘요.
$ ./snpguest verify attestation ./ report.bin
다음은 예시 출력이에요.
Reported TCB Boot Loader from certificate matches the attestation report.
Reported TCB TEE from certificate matches the attestation report.
Reported TCB SNP from certificate matches the attestation report.
Reported TCB Microcode from certificate matches the attestation report.
VEK signed the Attestation Report!
TCB(Trusted Computing Base) 버전 필드는 인증서의 펌웨어 버전이 증명 보고서에 보고된 버전과 일치함을 확인해줘요. 마지막 줄은 VCEK가 보고서에 서명했음을 확인해줘요.
공유 테넌시의 인스턴스 증명 (Attestation for instances on shared tenancy)
공유 테넌시 인스턴스는 AMD가 AWS를 위해 발급한 VLEK(Versioned Loaded Endorsement Key)를 사용해요. VLEK 인증서에서 AMD의 루트 오브 트러스트까지 거슬러 올라가는 신뢰 체인을 검증해야 해요.
1단계: snpguest 유틸리티 빌드 (Step 1: Build the snpguest utility)
이 단계에서는 증명 보고서를 생성하고 필요한 인증서를 가져오며 증명 보고서를 검증하는 데 사용할 snpguest 유틸리티를 설치하고 빌드해요.
- 인스턴스에 연결해요.
- 다음 명령을 실행해 snpguest 저장소에서 snpguest 유틸리티를 빌드해요.
$ git clone https://github.com/virtee/snpguest.git
$ cd snpguest
$ cargo build -r
$ cd target/release
2단계: 증명 보고서 생성 (Step 2: Generate the attestation report)
증명 보고서에 대한 요청을 생성해요. snpguest 유틸리티는 호스트에 증명 보고서를 요청하고 바이너리 파일로 써요. 다음 예시는 임의의 요청 nonce를 만들어 report.bin에 보고서를 저장해요.
$ ./snpguest report report.bin request-file.txt --random
호스트 메모리에서 인증서를 요청하고 PEM 파일로 저장해요.
$ ./snpguest certificates PEM ./
3단계: VLEK 인증서 체인 가져오고 검증하기 (Step 3: Fetch and validate the VLEK certificate chain)
증명 보고서는 AMD가 AWS를 위해 발급한 VLEK로 서명돼요. VLEK에서 AMD의 루트 오브 트러스트까지 거슬러 올라가는 신뢰 체인을 검증해야 해요.
- 공식 AMD Key Distribution Service에서 VLEK 루트 오브 트러스트 인증서를 현재 디렉터리에 다운로드해요.
$ sudo curl --proto '=https' --tlsv1.2 -sSf https://kdsintf.amd.com/vlek/v1/Milan/cert_chain -o ./cert_chain.pem
- openssl을 사용해 VLEK 인증서가 AMD 루트 오브 트러스트 인증서로 서명되었는지 검증해요.
$ sudo openssl verify --CAfile ./cert_chain.pem vlek.pem
다음은 예시 출력이에요.
vlek.pem: OK
4단계: 증명 보고서 서명 검증 (Step 4: Validate the attestation report signature)
증명 보고서가 VLEK 인증서로 서명되었는지 확인해요. 이는 보고서가 진짜 AMD 하드웨어에서 생성되었고 변조되지 않았음을 확인해줘요.
$ ./snpguest verify attestation ./ report.bin
다음은 예시 출력이에요.
Reported TCB Boot Loader from certificate matches the attestation report.
Reported TCB TEE from certificate matches the attestation report.
Reported TCB SNP from certificate matches the attestation report.
Reported TCB Microcode from certificate matches the attestation report.
VEK signed the Attestation Report!