信息网络安全 ›› 2025, Vol. 25 ›› Issue (11): 1745-1761.doi: 10.3969/j.issn.1671-1122.2025.11.008

• 专题论文:机密计算 • 上一篇    下一篇

一种面向容器生命周期的多维安全度量架构

赵波1,2(), 吕佳敏1,2, 王一琁1,2   

  1. 1.武汉大学国家网络安全学院武汉 430072
    2.空天信息安全与可信计算教育部重点实验室武汉 430072
  • 收稿日期:2025-06-11 出版日期:2025-11-10 发布日期:2025-12-02
  • 通讯作者: 赵波 zhaobo@whu.edu.cn
  • 作者简介:赵波(1972—),男,山东,教授,博士,CCF高级会员,主要研究方向为系统安全、可信计算|吕佳敏(2001—),女,山西,硕士研究生,主要研究方向为系统安全、可信计算|王一琁(1994—),男,江苏,博士研究生,主要研究方向为网络安全、知识图谱
  • 基金资助:
    国家自然科学基金(U1936122)

A Multidimensional Security Measurement Architecture for the Container Lifecycle

ZHAO Bo1,2(), LYU Jiamin1,2, WANG Yixuan1,2   

  1. 1. School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China
    2. Key Laboratory of Aerospace Information Security and Trusted Computing of Ministry of Education, Wuhan 430072, China
  • Received:2025-06-11 Online:2025-11-10 Published:2025-12-02

摘要:

容器面临的安全威胁日益复杂,基于可信执行环境(TEE)的安全方案已成为提升容器可信性的有效手段。然而,现有方案多聚焦于启动阶段的静态度量,或仅监控运行时的局部行为,难以全面覆盖容器生命周期,尤其难以应对控制流劫持等复杂攻击。同时,TEE通信多采用同步交互,频繁传输易引发网络阻塞与性能瓶颈。因此,文章提出一种面向容器生命周期的多维安全度量架构,覆盖容器构建与运行阶段,实时监控内存变化与间接跳转、间接函数调用和函数返回等关键控制流行为,实现持续完整性保护。此外,文章设计了基于TrustZone的跨域通信机制,结合共享内存、环形缓冲区与信号量,实现了度量信息的高效安全传输。实验结果表明,文章所提架构在提升容器完整性度量能力的同时可以保持较低的性能开销,能够满足云原生环境和多租户平台的需求。

关键词: 容器安全, 可信执行环境, 动态完整性度量, 控制流完整性

Abstract:

Container security threats have become increasingly complex. Trusted Execution Environment (TEE)-based solutions emerged as an effective way to enhance container trustworthiness. However, existing approaches mainly focus on static measurements at the container launch stage or monitor only partial runtime behaviors, making it difficult to comprehensively cover the entire container lifecycle and defend against complex attacks such as control-flow hijacking. In addition, TEE communication often relies on synchronous interactions, where frequent data transmissions may lead to blocking and performance bottlenecks. To address these issues, this paper proposed a multidimensional security measurement Architecture for the container lifecycle. The Architecture covered both image construction and runtime stages, and monitored memory changes and key control-flow events, including indirect jumps, indirect function calls, and returns. Furthermore, a TrustZone-based cross-domain communication mechanism was designed, which integrated shared memory, a ring buffer, and semaphores to enable efficient and secure transmission of measurement data. Experimental results show that the proposed system enhances container integrity protection with low performance overhead. It meets the requirements of cloud-native environments and multi-tenant platforms.

Key words: container security, trusted execution environment, dynamic integrity measurement, control flow integrity

中图分类号: