Tang server disk encryption
The following components and technologies implement Network-Bound Disk Encryption (NBDE).
Tang is a server for binding data to network presence. It makes a node containing the data available when the node is bound to a certain secure network. Tang is stateless and does not require Transport Layer Security (TLS) or authentication. Unlike escrow-based solutions, where the key server stores all encryption keys and has knowledge of every encryption key, Tang never interacts with any node keys, so it never gains any identifying information from the node.
Clevis is a pluggable framework for automated decryption that provides automated unlocking of Linux Unified Key Setup-on-disk-format (LUKS) volumes. The Clevis package runs on the node and provides the client side of the feature.
A Clevis pin is a plugin into the Clevis framework. There are three pin types:
- TPM2
-
Binds the disk encryption to the TPM2.
- Tang
-
Binds the disk encryption to a Tang server to enable NBDE.
- Shamir’s secret sharing (sss)
-
Allows more complex combinations of other pins. It allows more nuanced policies such as the following:
-
Must be able to reach one of these three Tang servers
-
Must be able to reach three of these five Tang servers
-
Must be able to reach the TPM2 AND at least one of these three Tang servers
-