When deploying mission-critical systems in the cloud, where deviations may have severe consequences, the assurance of critical decisions becomes essential. Typical cloud systems are operated by third parties and are built on complex software stacks consisting of e.g., Kubernetes, Istio, or Kafka, which due to their size are difficult to be verified. Nevertheless, one needs to make sure that mission-critical choices are made correctly. We propose a flexible runtime monitoring approach that is independent of the implementation of the observed system that allows to monitor safety and data-related properties. Our approach is based on combining distributed Datalog-based programs with tamper-proof storage based on Trillian to verify the premises of safety-critical actions. The approach can be seen as a generalization of the Certificate Transparency project. We apply our approach to an industrial use case that uses a cloud infrastructure for orchestrating unmanned air vehicles.
翻译:在云端部署关键任务系统时,偏差可能导致严重后果,因此对关键决策的保障变得至关重要。典型的云系统由第三方运营,并基于复杂软件栈构建,例如Kubernetes、Istio或Kafka,这些系统因其规模庞大而难以验证。尽管如此,仍需确保关键决策的正确性。本文提出一种灵活的运行时监控方法,该方法独立于被观测系统的实现,可监控安全性和数据相关属性。该方法将基于分布式Datalog的程序与基于Trillian的防篡改存储相结合,以验证安全关键操作的前提条件。该方案可视为证书透明度项目(Certificate Transparency)的泛化。我们将该方法应用于一个使用云基础设施编排无人驾驶飞行器的工业案例。