安全容器在智能电网数字化转型中的探索与应用

Exploration and application of secure containers in the digital transformation of smart grid

  • 摘要: 自2020年开始,国家电网有限公司全面推进云平台、数据中台和物联平台(三台)建设,三者均依赖容器 技术实现应用部署与终端管理。容器技术具有轻量化、高效率等优点,但因与操作系统共享内核,易引发特权逃逸、 跨容器泄露等内核安全风险,难以适配高安全需求的信息化系统。提出一种基于虚拟化技术的安全容器,该容器拥 有独立内核,遵照OCI标准,可兼容现有标准容器镜像,支持无缝接入Kubernetes环境,无需改变用户操作习惯。 本研究提升了容器技术的安全性能,确保容器在高安全要求场景的可用性,为“三台”建设中敏感系统的容器化部 署提供支撑。

     

    Abstract: Since 2020, State Grid Corporation of China has fully advanced the construction of the cloud platform, data middle platform, and IOT platform (collectively referred to as the "Three Platforms"), all of which rely on container technology for application deployment and terminal management. Container technology boasts advantages such as lightweight design and high efficiency; however, due to its shared operating system kernel, it is prone to kernel security risks including privilege escalation and cross-container data leakage, making it difficult to adapt to the information systems with high security requirements. This paper proposes a secure container based on virtualization technology, featuring an independent kernel, compliance with OCI standards, compatibility with existing standard container images, and seamless integration with Kubernetes environments without requiring changes to users’ operating habits. This research enhances the security performance of container technology, ensures the availability of containers in high-security scenarios, and provides support for the containerized deployment of sensitive systems in the construction of the "Three Platforms".

     

/

返回文章
返回