Research on Extension Method of Container Virtual Trusted Certificate Chain for 5G MEC
Haoqing Xia, Tao Li, Aiqun Hu · 2023
Containers are widely used in 5G MEC scenarios. One of the main obstacles to the deployment of container applications is the security problem it faces. The container image and its internal programs may be maliciously tampered with by an attacker using vulnerabilities at runtime. In view of this problem, we propose to use vTPM technology to solve the integrity protection and safe operation of containers and container images, and design a virtual trusted certificate chain extension scheme. By introducing signature key SK in TPM and identity key cEK in vTPM management domain, we realize the extension of trust chain from TPM to TPM instance. Then we have carried out feasibility analysis and experiment on the proposed certificate chain extension scheme. The experimental results show that this method can build a trusted certificate chain from TPM to vTPM instance, thus meeting the requirements of container reinforcement. Finally, we compare our proposed scheme with some existing virtual trusted certificate chain extension schemes. The results show that our proposed scheme is more suitable for strengthening the container.