NDSS 2025 – RContainer
嗯,用户让我用中文总结一篇文章的内容,控制在100字以内,而且不需要特定的开头。我先看看文章内容。 这篇文章是关于RContainer的,它是一种安全容器架构,通过扩展ARM CCA硬件来增强容器的安全性。作者们来自中国科学院等机构。RContainer引入了一个小型可信的mini-OS,监控操作系统和容器之间的控制流,并使用shim-style隔离在内核层创建隔离的物理地址空间。他们还在ARMv9和ARMv8硬件上实现了这个架构,并进行了实验,结果显示安全性能提升显著,性能开销小。 用户的需求是总结内容,所以我要抓住关键点:RContainer、ARM CCA、安全容器架构、mini-OS、shim隔离、实验结果。把这些浓缩到100字以内。 可能的结构是:介绍RContainer是什么,它如何工作(扩展ARM CCA),主要功能(mini-OS和shim隔离),以及实验结果(提升安全性和低开销)。 现在组织语言:RContainer通过扩展ARM CCA硬件提供安全容器架构,使用mini-OS监控控制流,并用shim隔离创建独立空间。实验显示安全提升显著且性能影响小。 检查字数:大约90字左右,符合要求。 </think> 文章介绍了一种名为RContainer的安全容器架构,通过扩展ARM Confidential Computing Architecture (CCA)硬件实现强隔离和防护。该架构引入可信mini-OS监控操作系统与容器间的控制流,并利用shim-style隔离机制在内核层创建独立物理地址空间。实验表明其显著提升容器安全性,性能开销较小。 2026-1-25 16:0:0 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

Session 10A: Confidential Computing 2

Authors, Creators & Presenters: Qihang Zhou (Institute of Information Engineering, Chinese Academy of Sciences), Wenzhuo Cao (Institute of Information Engineering, Chinese Academy of Sciences; School of Cyberspace Security, University of Chinese Academy of Sciences), Xiaoqi Jia (Institute of Information Engineering, Chinese Academy of Sciences), Peng Liu (The Pennsylvania State University, USA), Shengzhi Zhang (Department of Computer Science, Metropolitan College, Boston University, USA), Jiayun Chen (Institute of Information Engineering, Chinese Academy of Sciences; School of Cyberspace Security, University of Chinese Academy of Sciences), Shaowen Xu (Institute of Information Engineering, Chinese Academy of Sciences; School of Cyberspace Security, University of Chinese Academy of Sciences), Zhenyu Song (Institute of Information Engineering, Chinese Academy of Science)
PAPER
RContainer: A Secure Container Architecture through Extending ARM CCA Hardware Primitives
Containers have become widely adopted in cloud platforms due to their efficient deployment and high resource utilization. However, their weak isolation has always posed a significant security concern. In this paper, we propose RContainer, a novel secure container architecture that protects containers from untrusted operating systems and enforces strong isolation among containers by extending ARM Confidential Computing Architecture (CCA) hardware primitives. RContainer introduces a small, trusted mini-OS that runs alongside the deprivileged OS, responsible for monitoring the control flow between the operating system and containers. Additionally, RContainer uses shim-style isolation, creating an isolated physical address space called con-shim for each container at the kernel layer through the Granule Protection Check mechanism. We have implemented RContainer on ARMv9-A Fixed Virtual Platform and ARMv8 hardware SoC for security analysis and performance evaluation. Experimental results demonstrate that RContainer can significantly enhance container security with a modest performance overhead and a minimal Trusted Computing Base (TCB).
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.

Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations’ YouTube Channel.

Permalink

*** This is a Security Bloggers Network syndicated blog from Infosecurity.US authored by Marc Handelman. Read the original post at: https://www.youtube-nocookie.com/embed/nYa-RrHYBK8?si=p0180aletgPZqQ7j


文章来源: https://securityboulevard.com/2026/01/ndss-2025-rcontainer/
如有侵权请联系:admin#unsafe.sh