TCEC: Integrity Protection for Containers by Trusted Chip on IoT Edge Computing Nodes
Weidong Li, Bo Zhao, Lingzi Zhu, Yixuan Wang, Qian Zhong, Shui Yu · IEEE Sensors Journal · 2024
In edge computing, an Internet of Things (IoT) node may employ container-based virtualization to manage and process data collected by sensors. Compared to cloud computing, containers on edge computing nodes have more components to handle computing tasks. This makes it more challenging to protect the integrity of components within containers. In this article, we propose the trusted container for edge computing (TCEC) solution grounded in trusted computing (TC) designed to address this challenge. TCEC consists of two crucial parts: the trusted agent (TA) and the virtual trusted platform module (vTPM) manager. The TA is distributed within each container, facilitating the effortless collection of component information requiring integrity protection. Subsequently, this information will be forwarded to the vTPM manager. The vTPM manager safeguards the integrity of critical information through integrity measurements and stores the results in the vTPM of the specified container. We have modified the measurement log (ML) format to identify faulty components quickly. TCEC operates on the Linux kernel and is compatible with various container engines without requiring virtualization architecture for IoT device modifications. Experimental results demonstrate the effectiveness and efficiency of TCEC in a Docker-based prototype. It also reveals that existing container protection schemes relying on TC are not directly applicable to an open IoT platform. The codes are available athttps://github.com/chrisli1995/paper/tree/main/TCEC.