Netinfo Security ›› 2025, Vol. 25 ›› Issue (11): 1745-1761.doi: 10.3969/j.issn.1671-1122.2025.11.008

Previous Articles     Next Articles

A Multidimensional Security Measurement Architecture for the Container Lifecycle

ZHAO Bo1,2(), LYU Jiamin1,2, WANG Yixuan1,2   

  1. 1. School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China
    2. Key Laboratory of Aerospace Information Security and Trusted Computing of Ministry of Education, Wuhan 430072, China
  • Received:2025-06-11 Online:2025-11-10 Published:2025-12-02

Abstract:

Container security threats have become increasingly complex. Trusted Execution Environment (TEE)-based solutions emerged as an effective way to enhance container trustworthiness. However, existing approaches mainly focus on static measurements at the container launch stage or monitor only partial runtime behaviors, making it difficult to comprehensively cover the entire container lifecycle and defend against complex attacks such as control-flow hijacking. In addition, TEE communication often relies on synchronous interactions, where frequent data transmissions may lead to blocking and performance bottlenecks. To address these issues, this paper proposed a multidimensional security measurement Architecture for the container lifecycle. The Architecture covered both image construction and runtime stages, and monitored memory changes and key control-flow events, including indirect jumps, indirect function calls, and returns. Furthermore, a TrustZone-based cross-domain communication mechanism was designed, which integrated shared memory, a ring buffer, and semaphores to enable efficient and secure transmission of measurement data. Experimental results show that the proposed system enhances container integrity protection with low performance overhead. It meets the requirements of cloud-native environments and multi-tenant platforms.

Key words: container security, trusted execution environment, dynamic integrity measurement, control flow integrity

CLC Number: