Security capabilities overview

更新时间:
复制 MD 格式

ECS provides layered security protection, including hardware encryption, trusted computing, and confidential computing.

Overview

ECS provides default memory encryption, trusted computing (vTPM), and confidential computing (Confidential VMs and enclaves).

Alibaba Cloud deploys the Ali-PRoT (Platform Root-of-Trust) hardware security chip on ECS hosts. This chip secures underlying hardware and firmware without extra configuration. Core capabilities include:

  • Proactive firmware measurement: Before host startup, Ali-PRoT verifies firmware integrity (such as BIOS and BMC). Unlike traditional passive recording methods, Ali-PRoT proactively detects and blocks potential threats before the firmware executes. Only verified servers can start.

  • Runtime tamper-proofing: Ali-PRoT continuously monitors firmware reads and writes at runtime and blocks unauthorized access and modifications in real time.

  • Hardware identity authentication: Ali-PRoT authenticates physical servers through the chip's unique hardware identity and the cloud platform's security control system, preventing unauthorized devices from accessing the platform.

Security capabilities at a glance

image

Best practices