| |
This RFD describes Oxide's key-hierarchy strategy for securing data within server racks using a Trust Quorum system based on Shamir secret sharing. A rack-level secret is split into N shares distributed across bootstrap agents on different sleds, requiring K shares to reconstruct the secret, which prevents attackers from recovering sensitive information without stealing multiple physical devices. The document outlines plans to establish a comprehensive key-protection framework that defines what data is protected, the lifecycle and physical locality of that data, and the key derivation hierarchy used throughout the system.
Read Full Article →
← More Tech news