网络与信息安全学报 ›› 2021, Vol. 7 ›› Issue (4): 164-174.doi: 10.11959/j.issn.2096-109x.2021068

• 学术论文 • 上一篇    下一篇

基于TPCM的容器云可信环境研究

刘国杰1,2, 张建标1,2, 杨萍3, 李铮1,2   

  1. 1 北京工业大学信息学部,北京 100124
    2 可信计算北京市重点实验室,北京 100124
    3 北京信息科技大学,北京 100192
  • 修回日期:2021-04-22 出版日期:2021-08-15 发布日期:2021-08-01
  • 作者简介:刘国杰(1982− ),男,北京工业大学博士生,主要研究方向为网络与信息安全、可信计算
    张建标(1969− ),男,北京工业大学教授、博士生导师,主要研究方向为网络与信息安全、可信计算
    杨萍(1987− ),女,北京信息科技大学讲师,主要研究方向为人工智能、智能信息处理、机器学习和信息安全
    李铮(1992− ),女,北京工业大学讲师,主要研究方向为信息安全、密码分析和对称密码算法的设计
  • 基金资助:
    国家自然科学基金(61971014);国防科技实验信息安全实验室对外开放项目(2017XXAQ08)

Research on the trusted environment of container cloud based on the TPCM

Guojie LIU1,2, Jianbiao ZHANG1,2, Ping YANG3, Zheng LI1,2   

  1. 1 Faculty of Information Technology, Beijing University of Technology, Beijing 100124, China
    2 Beijing Key Laboratory of Trusted Computing, Beijing 100124, China
    3 Beijing Information Science and Technology University, Beijing 100192, China
  • Revised:2021-04-22 Online:2021-08-15 Published:2021-08-01
  • Supported by:
    The National Natural Science Foundation of China(61971014);National Defense Science and Technology Laboratory of Information Security(2017XXAQ08)

摘要:

容器技术是一种轻量级的操作系统虚拟化技术,被广泛应用于云计算环境,是云计算领域的研究热点,其安全性备受关注。提出了一种采用主动免疫可信计算进行容器云可信环境构建方法,其安全性符合网络安全等级保护标准要求。首先,通过 TPCM 对容器云服务器进行度量,由 TPCM 到容器的运行环境建立一条可信链。然后,通过在 TSB 增加容器可信的度量代理,实现对容器运行过程的可信度量与可信远程证明。最后,基于Docker与Kubernetes建立实验原型并进行实验。实验结果表明,所提方法能保障云服务器的启动过程与容器运行过程的可信,符合网络安全等级保护标准测评要求。

关键词: 可信计算, 可信启动, 可信度量, 远程证明

Abstract:

Container technology is a lightweight operating system virtualization technology that is widely used in cloud computing environments and is a research hotspot in the field of cloud computing.The security of container technology has attracted much attention.A method for constructing a trusted environment of container cloud using active immune trusted computing was proposed, and its security meet the requirements of network security level protection standards.First, container cloud servers were measured through the TPCM and a trust chain from the TPCM to the container's operating environment was established.Then, by adding the trusted measurement agent of the container to the TSB, the trusted measurement and trusted remote attestation of the running process of the container were realized.Finally, an experimental prototype based on Docker and Kubernetes and conduct experiments were built.The experimental results show that the proposed method can ensure the credibility of the boot process of the cloud server and the running process of the container and meet the requirements of the network security level protection standard evaluation.

Key words: trusted computing, trusted boot, trusted measurement, remote attestation

中图分类号: 

No Suggested Reading articles found!