A New Method to Enhance Container with vTPM

Zhang Xiao Jian, Zhou Peng, Qi Wang, Peng Gao, Wang Yi Liang · 2022

This paper proposes a new container security enhancement system and method for containers running on 5G edge computing nodes. The system consists of vTPM module, physical TPM, container manager, vTPM manager, MEC controller and physical host. vTPM module is responsible for not only container image integrity measurement and starting up the container with trust, but also the trustworthiness measurement of container runtime file system and process. Physical TPM undertakes data encryption and password protection. Container manager performs trustworthiness measurement and verification of container. The MEC controller stores the measurement reference value for the physical TPM and issues keys and certificates for the physical TPM. The container enhancing method based on this system establishes a complete trust chain from the host to the container manager, and finally to containers. This ensures the trusted startup of the container, preventing the container itself and its runtime environment from being maliciously tampered with. It also dynamically measures the file system of the container in runtime to ensure the trustworthiness of the container. The experimental results indicate that this method is able to meet the requirements of container security enhancement for power 5G edge computing nodes.

Read the paper · More papers on PaperTik