Abstract:
Since 2020, State Grid Corporation of China has fully advanced the construction of the cloud platform, data middle platform, and IOT platform (collectively referred to as the "Three Platforms"), all of which rely on container technology for application deployment and terminal management. Container technology boasts advantages such as lightweight design and high efficiency; however, due to its shared operating system kernel, it is prone to kernel security risks including privilege escalation and cross-container data leakage, making it difficult to adapt to the information systems with high security requirements. This paper proposes a secure container based on virtualization technology, featuring an independent kernel, compliance with OCI standards, compatibility with existing standard container images, and seamless integration with Kubernetes environments without requiring changes to users’ operating habits. This research enhances the security performance of container technology, ensures the availability of containers in high-security scenarios, and provides support for the containerized deployment of sensitive systems in the construction of the "Three Platforms".