Docker container hardening method based on trusted computing

Yuang Shen,Xuejun Yu
DOI: https://doi.org/10.1088/1742-6596/1619/1/012014
2020-08-01
Journal of Physics: Conference Series
Abstract:Abstract In view of the incomplete isolation of docker, the image file is easy to be tampered with, and the problem of insecure container operation. Based on the analysis of the existing isolation mechanism and security enhancement technology of docker container, this article uses trusted computing technologies such as cryptographic algorithms, integrity measurement, realtime monitoring, etc., a hardening method for docker containers is proposed. The feasibility of the reinforcement method was verified by experiments. The results show that this method can realize that docker is in a trusted and secure environment during the entire process of downloading the image from the container to the container, and ensuring that the container and the image file are not tampered with. When the container is enabled, the system resources are in a monitorable state, which greatly improves the credibility and security of the docker container.
What problem does this paper attempt to address?