Abstract
Data Confidence Fabrics (DCFs) are emerging as a mechanism to obtain measurable trust in decentralized smart computing environments, while remote attestation (RA) is being established as a key mechanism for verifying security in distributed systems. However, both of these approaches remain underutilized in container orchestration platforms, resulting in inadequate trust guarantees, increased attack surface areas, and insufficient mechanisms for verifying the integrity of devices and applications. In this paper, we propose leveraging DCFs to integrate RA with software security practices, and utilizing this integration to securely onboard devices and containerized applications by tracing their provenance and analyzing vulner-abilities. This dual-level protection bridges device attestation measurements with measurements of application security to provide measurable and transparent confidence scores for both. The proposed approach brings trustworthiness into a distributed environment where devices are continuously monitored for malicious tampering, and applications are assessed before being run. We verified this approach on a setup representing real environments. Additionally, a machine learning model was put under test and trained on data weighted with confidence scores produced by our proposed approach. The model saw improved performance and accuracy, showing that this approach can increase the reliability of systems.
| Original language | English |
|---|---|
| Title of host publication | 2025 IEEE International Conference on Smart Computing (SMARTCOMP) |
| Pages | 178-185 |
| Number of pages | 8 |
| ISBN (Electronic) | 979-8-3315-8646-1 |
| DOIs | |
| Publication status | Published - 2025 |
| Event | 11th IEEE International Conference on Smart Computing, SMARTCOMP 2025 - Cork, Ireland Duration: 16 Jun 2025 → 19 Jun 2025 |
Conference
| Conference | 11th IEEE International Conference on Smart Computing, SMARTCOMP 2025 |
|---|---|
| Country/Territory | Ireland |
| City | Cork |
| Period | 16/06/25 → 19/06/25 |
Keywords
- container orchestration platforms
- Data Confidence Fabric
- distributed systems
- remote attestation
- Secure onboarding
- security
- workload on-boarding