SCONE: Secure Linux Containers with Intel SGX
https://www.usenix.org/system/files/conference/osdi16/osdi16-arnautov.pdf [www.usenix.org]
2017-02-18 16:57
We describe SCONE, a secure container mechanism for Docker that uses the SGX trusted execution support of Intel CPUs to protect container processes from out- side attacks. The design of SCONE leads to (i) a small trusted computing base (TCB) and (ii) a low performance overhead
source: solar