Blockchain-based decentralized content trust for docker images

被引:24
作者
Xu, Quanqing [1 ]
Jin, Chao [1 ]
Rasid, Mohamed Faruq Bin Mohamed [1 ]
Veeravalli, Bharadwaj [1 ]
Aung, Khin Mi Mi [1 ]
机构
[1] ASTAR, Data Storage Inst, Singapore, Singapore
关键词
Trust; Docker; Blockchain; Multimedia; Internet of things; FRAMEWORK; STORAGE; CLOUD;
D O I
10.1007/s11042-017-5224-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
It is feasible to deploy Docker containers in IoT (Internet of Things) devices because their runtime overhead is almost zero. Default Docker installation does not verify an image authenticity. Authentication is vital for users to trust that the image is not malicious or tampered with. As Docker is currently a popular choice for developers, tightening its security is a priority for system administrators and DevOps engineers. Docker recently deployed Notary as a solution to verify authenticity of their images. Notary is a viable solution, but it has some potential threats. This paper specifically addresses its vulnerability towards Denial-of-Service (DoS) attacks, and propose a potential solution: blockchain-based Decentralized Docker Trust (DDT). The proposed solution involves decentralizing the trust via a blockchain. The solution greatly reduces the risk of DoS and at the same time provides a signature verification service for Docker images. We demonstrate the proposed blockchain-based solution's scalability and efficiency by conducting performance evaluation. At the same time, we also implemented a system prototype of Decentralized Docker Trust (DDT), and conducted performance evaluation for it on Amazon Web Services (AWS) across multiple data centers.
引用
收藏
页码:18223 / 18248
页数:26
相关论文
共 30 条
[1]   A robust and efficient bilinear pairing based mutual authentication and session key verification over insecure communication [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Vijayakumar, Pandi ;
Khan, Muhammad Khurram ;
Chang, Victor .
MULTIMEDIA TOOLS AND APPLICATIONS, 2018, 77 (09) :11041-11066
[2]  
[Anonymous], INTRO DOCKER CONTENT
[3]  
[Anonymous], 2016, DIRTY COW CRITICAL L
[4]  
[Anonymous], 2016, AB
[5]  
[Anonymous], 2017, NO WAY DIS TRUST ON
[6]  
[Anonymous], 2016, RES HDB DIGITAL TRAN
[7]  
[Anonymous], 2016, P 2016 ACM SIGSAC C
[8]  
[Anonymous], TUF SPEC UPDATE FRAM
[9]  
[Anonymous], 2013, 2013 IEEE 29 S MASS
[10]   VirtCache: Managing Virtual Disk Performance Variation In Distributed File Systems For The Cloud [J].
Arumugam, Rajesh Vellore ;
Xu, Quanqing ;
Shi, Haixiang ;
Cai, Qingchao ;
Wen, Yonggang .
2014 IEEE 6TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2014, :210-217