首页 | 本学科首页   官方微博 | 高级检索  
     

基于TPCM的容器云可信环境研究
作者姓名:刘国杰  张建标  杨萍  李铮
作者单位:1. 北京工业大学信息学部,北京 100124;2. 可信计算北京市重点实验室,北京 100124;3. 北京信息科技大学,北京 100192
基金项目:国家自然科学基金(61971014);国防科技实验信息安全实验室对外开放项目(2017XXAQ08)
摘    要:容器技术是一种轻量级的操作系统虚拟化技术,被广泛应用于云计算环境,是云计算领域的研究热点,其安全性备受关注.提出了一种采用主动免疫可信计算进行容器云可信环境构建方法,其安全性符合网络安全等级保护标准要求.首先,通过TPCM对容器云服务器进行度量,由TPCM到容器的运行环境建立一条可信链.然后,通过在TSB增加容器可信的...

关 键 词:可信计算  可信启动  可信度量  远程证明

Research on the trusted environment of container cloud based on the TPCM
Authors:Guojie LIU  Jianbiao ZHANG  Ping YANG  Zheng LI
Affiliation:1. Faculty of Information Technology, Beijing University of Technology, Beijing 100124, China;2. Beijing Key Laboratory of Trusted Computing, Beijing 100124, China;3. Beijing Information Science and Technology University, Beijing 100192, China
Abstract:Container technology is a lightweight operating system virtualization technology that is widely used in cloud computing environments and is a research hotspot in the field of cloud computing.The security of container technology has attracted much attention.A method for constructing a trusted environment of container cloud using active immune trusted computing was proposed, and its security meet the requirements of network security level protection standards.First, container cloud servers were measured through the TPCM and a trust chain from the TPCM to the container's operating environment was established.Then, by adding the trusted measurement agent of the container to the TSB, the trusted measurement and trusted remote attestation of the running process of the container were realized.Finally, an experimental prototype based on Docker and Kubernetes and conduct experiments were built.The experimental results show that the proposed method can ensure the credibility of the boot process of the cloud server and the running process of the container and meet the requirements of the network security level protection standard evaluation.
Keywords:trusted computing  trusted boot  trusted measurement  remote attestation  
点击此处可从《》浏览原始摘要信息
点击此处可从《》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号