Poster: FortNIC: Secure Container Image Registry on SmartNICs

Shaunak Galvankar, Sean Choi · 2025

Modern day cloud data centers are made flexible and scalable by enabling resource sharing via Virtual Machines( VMs) and Containers, where virtual machines enable sharing resources via isolated operating systems that are managed by a hypervisor while containers enable resource sharing using lightweight isolated processes that share the Host OS kernel. In such configuration, each bare-metal server in often houses multiple virtual machines and each virtual machine often runs multiple containers, and these container often share the same set of libraries and code stored in a set of artifacts referred to as container images. Container images are distributed by storing them in online registries that allow developers and enterprises to store custom and verified images with vulnerability metrics. However, it is a known problem that many vulnerabilities can get introduced unknowingly in such images by the usage of conflicting dependencies, misconfigurations or even usage of automated deployment tools, which maybe easily introduced to the containerized workload.To resolve this issue, this work aims to provide a secure registry of verified container images locally by utilizing SmartNICs, which are specialized network hardware that provide hardware acceleration and offload capabilities. Such approach enables restrictions for data centers containers to only use a set of secure images allowed for a given VM. In addition, localized registries within SmartNICs are in a separate security domain compared to the servers in the data center, providing additional layer of security against image corruption. Finally, storing the secure images in the SmartNIC allows for added benefits such as access-control list and caching of images, enabling more efficient and secure image dissemination.

Read the paper · More papers on PaperTik