We use machine learning technology to do auto-translation. Click "English" on top navigation bar to check Chinese version.
Introducing the Security Design of the Amazon Web Services Nitro System whitepaper
Amazon Web Services recently released a whitepaper on the
This whitepaper is a detailed design document on the inner workings of the Amazon Web Services Nitro System, and how we use it to help secure your most critical workloads. This is the first time that Amazon Web Services has provided such a detailed design document on the Nitro System and how it offers a no-operator access design and strong tenant isolation. The whitepaper describes the security design of the Nitro System in detail to help you evaluate Amazon EC2 for your sensitive workloads.
Three key components of the Nitro System are used to implement this design:
- Purpose-built Nitro Cards – Hardware devices designed by Amazon Web Services that provide overall system control and I/O virtualization that is independent of the main system board with its CPUs and memory.
- Nitro Security Chip – Enables a secure boot process for the overall system based on a hardware root of trust, the ability to offer bare metal instances, and defense-in-depth that offers protection to the server from unauthorized modification of system firmware.
- Nitro Hypervisor – A deliberately minimized and firmware-like hypervisor designed to provide strong resource isolation, and performance that is nearly indistinguishable from a bare metal server.
The whitepaper describes the fundamental architectural change introduced by the Nitro System compared to previous approaches to virtualization. It discusses the three key components of the Nitro System, and provides a demonstration of how these components work together by walking through what happens when a new
The
If you have feedback about this post, submit comments in the Comments section below. If you have questions about this post,
Want more Amazon Web Services Security news? Follow us on
The mentioned AWS GenAI Services service names relating to generative AI are only available or previewed in the Global Regions. Amazon Web Services China promotes AWS GenAI Services relating to generative AI solely for China-to-global business purposes and/or advanced technology introduction.