Zero Trust security model permits to secure cloud native applications while encrypting all network communication, authenticating, and authorizing every request. The service mesh can enable Zero Trust using a side-car proxy without changes to the application code. To the best of our knowledge, no previous work has provided a performance analysis of Zero Trust in a multi-cloud environment. This paper proposes a multi-cloud framework and a testing workflow to analyze performance of the data plane under load and the impact on the control plane, when Zero Trust is enabled. The results of preliminary tests show that Istio has reduced latency variability in responding to sequential HTTP requests. Results also reveal that the overall CPU and memory usage can increase based on service mesh configuration and the cloud environment.
翻译:零信任安全模型允许在加密所有网络通信、认证和授权每项请求的同时,确保云源本地应用程序的安全。 服务网格可以使零信任使用随身车代用器而无需修改应用程序代码。 据我们所知,以往没有工作在多层环境中对零信任进行业绩分析。 本文提出了一个多层框架和测试工作流程, 以分析载荷数据平面的性能和在启用零信任时对控制平面的影响。 初步测试结果显示, Istio 降低了对连续 HTTP 请求作出反应时的耐久性变异性。 研究结果还显示, CPU 和记忆的总体使用可以根据服务网格配置和云环境增加 。