TrustMig: A Container Migration Architecture Model Based on TEE

Qingyu Gao, Xiaoling Li, Xiaochuan Wang, Liantao Song, Yan Ding, Yongpeng Liu, Yuran Sun · 2024

In the context of cloud-native environments, establishing and maintaining trust for dynamically migrating contain-ers is a crucial concern. The existing container live migration schemes often lack sufficient support for security, isolation, and consistency. The Trusted Execution Environment (TEE) can provide an isolated execution environment for key operations, but face challenges such as untrusted operating systems and third-party attacks during transmission. We introduce TrustMig, a container security migration framework based on TEE. The model constructs a hardware-isolated security execution environment with TEE at its core on both ends of the migration, ensuring secure operations such as encryption, decryption, and integrity measurement for sensitive information. A mutual authentication protocol for the host is devised, and a bi-directional encrypted channel is established for transmitting migration data, with TEE verifying the integrity of sensitive information during migration. The proposed architecture model is implemented on ARMv8 development boards, and its performance is assessed by migrating actual containers. Experimental results indicate that TrustMig typically introduces an overhead of approximately 12% on standard containers compared to conventional container migration.

Read the paper · More papers on PaperTik