Jessie Frazelle on SCONE: Secure Linux Containers with Intel SGX

In 2016, the SCONE paper was written and presented at the USENIX Symposium on Operating Systems Design and Implementation. It outlined how to use Intel Secure Enclaves to guard containers against attack. Containers are built on the kernel primitives cgroups and namespaces with additional LSM (Linux Security Module) layers on top, such as AppArmor, SELinux, and seccomp.

