Hardware Chain of Trust for Container Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional container management solutions in cloud data centers are vulnerable to attacks, leading to security bottlenecks due to encryption/decryption-related performance penalties, compromising the trustworthiness of container security.

Innovation Solution

A hardware-based chain of trust is established and extended to container managers and applications, using authenticated code modules, trusted platform modules, and root of trust measurement agents to verify the integrity and authenticity of containerized applications, ensuring secure launch and operation through cryptographic measurements and policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional container management solutions are used, then container deployment is simple and fast, but security is compromised due to vulnerability to attacks

Engineering Contradiction:
Improvecontainer securityVSAvoidsecurity architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements pre-boot measurements and verification of container images before deployment. The system performs integrity checks, cryptographic verification, and security policy validation during the boot process and container initialization phase, ensuring that only authenticated and unmodified containers are deployed. This preliminary security verification prevents attacks before they can compromise the container runtime environment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security apparatus as an intermediary layer between the container management system and the underlying hardware/platform. This security apparatus includes components such as a root of trust measurement agent, trusted platform module, and security policy enforcement mechanism that mediate the container deployment process, providing cryptographic verification and security controls without requiring fundamental changes to the container runtime architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption/decryption is applied to enhance security, then container security is improved, but performance penalties occur

Engineering Contradiction:
Improvecontainer securityVSAvoidlaunch performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs cryptographic verification and security checks during the pre-boot and container image validation phase, before the container is actually launched. By completing these security-intensive operations beforehand, the actual container launch process can proceed more quickly without repeated encryption/decryption overhead during runtime operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts and isolates the heavy cryptographic verification operations into a separate security apparatus that operates independently from the main container runtime. The security apparatus handles authentication, integrity verification, and policy enforcement, allowing the container engine to focus on deployment and execution without bearing the full performance burden of continuous cryptographic operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11042643B2Trusted deployment of application containers in cloud data centers
Publication Date: 2021.06.22 INTEL CORP
  • US11042643B2 patent drawing
  • US11042643B2 patent drawing
  • US11042643B2 patent drawing

AI summary

Systems, apparatuses and methods may provide for establishing a hardware-based chain of trust in a computing system and extending the hardware-based chain of trust to a container manager and a containerized application on the computing system. Additionally, the containerized application may be checked for its trust and security while it is launched, via the container manager, on the computing system. In one example, extending the hardware-based chain of trust includes conducting a pre-boot measurement of the container manager, a root of trust measurement agent, and one or more packages associated with the containerized application, and verifying the pre-boot measurement of the platform/host and the application itself prior to the containerized application being launched.