Container mirror image security management method and system

Through layered encryption and dynamic access control, combined with device fingerprints and geographic fencing, the problems of insufficient differentiation of hierarchical security requirements in container image security management and the easy cracking of traditional encryption are solved, thereby improving the security and anti-attack capabilities of container image transmission.

CN120597288AInactive Publication Date: 2025-09-05NANJING TORTOISE & HARE RACE SOFTWARE RES INST CO LTD

Patent Information

Application Number
CN202511094398.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-09-05
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing technologies fail to effectively distinguish different levels of security requirements in container image security management, resulting in high-risk vulnerabilities and supply chain attack risks. Traditional encryption is easily cracked, permission control is disconnected from the environment, and key storage is vulnerable at a single point.

Method used

A layered encryption strategy is adopted, and differentiated encryption keys are generated through the policy center. Independent encryption is implemented for the kernel dependency layer, runtime environment layer, application code layer, and sensitive configuration layer. Combined with device fingerprints, geographic fences, and environmental risk scores, operation trajectories are analyzed in real time, access control is dynamically adjusted, and attacks are resisted through a double-layer encryption channel.

Benefits of technology

It improves the anti-attack capability of container image transmission, reduces the threat of man-in-the-middle attacks and data tampering, enhances the security and environmental adaptability of keys, and prevents long-term leakage risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597288A_ABST
    Figure CN120597288A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data access security, and discloses a container mirror image security management method and system, and the method comprises the steps: constructing a container mirror image, generating a differential encryption key through a strategy center, carrying out the encryption strategy of a kernel dependence layer, a runtime environment layer, an application code layer and a sensitive configuration layer, and forming a hierarchical protection basis. If an access request is triggered, firstly collecting equipment fingerprints and geofence information and evaluating an environmental risk score, verifying access authority and an access scene matching degree through attribute-based encryption, analyzing operation track characteristics in real time, identifying an abnormal mode, and if the three-layer verification is passed, generating a temporary access token; according to the method, access request authority is verified, a temporary access token is matched, key fragments are synthesized, a master key is only temporarily generated in a memory and encrypted and stored, and through combination of a double-layer encryption channel and inner-layer and outer-layer defense, the anti-attack ability of container mirror image transmission is improved, and man-in-the-middle attack and data tampering are effectively coped with.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data access security and discloses a container image security management method and system. Background Art

[0002] Existing technologies for container image security management only encrypt the image as a whole, without differentiating between security requirements at different layers, such as the kernel, runtime, and code. For example, most container images contain high-risk vulnerabilities, but traditional encryption cannot prevent attackers from exploiting them through the unencrypted kernel layer. Unverified integration of third-party dependency packages also poses the risk of supply chain attacks. Many authorized permissions are currently unused, but dependency package vulnerabilities could still be exploited. Summary of the Invention

[0003] To solve the above technical problems, the main purpose of the present invention is to provide a container image security management method and system, wherein the container image security management method includes:

[0004] Container image construction generates differentiated encryption keys through the policy center, and implements encryption policies for the kernel dependency layer, runtime environment layer, application code layer, and sensitive configuration layer to form a layered protection foundation;

[0005] If an access request is triggered, the device fingerprint and geo-fence information are first collected and the environmental risk score is assessed. The access rights and access scenario matching are verified through attribute-based encryption. The operation trajectory characteristics are analyzed in real time to identify abnormal patterns. If the three-layer verification passes, a temporary access token is generated.

[0006] Verify access request permissions and match temporary access tokens, synthesize key shards, and temporarily generate and encrypt the master key in memory.

[0007] A double-layer encryption channel is established, wherein the outer layer of the double-layer encryption channel writes an access encryption protocol, and the inner layer of the double-layer encryption channel outputs a sufficient encryption strategy for mirror fragments in real time.

[0008] As a preferred solution of the container image security management method of the present invention, wherein:

[0009] The container image construction includes multiple layers of dynamic encryption, which are independent layers of encryption, and the encryption key is dynamically derived by the policy center;

[0010] The multi-layer independent encryption includes implementing independent encryption strategies for the kernel dependency layer, runtime environment layer, application code layer and sensitive configuration layer.

[0011] As a preferred solution of the container image security management method of the present invention, wherein:

[0012] The kernel dependency layer detects whether there are unverified third-party dependency packages through dependency analysis, and identifies in real time whether the kernel version belongs to a version with known vulnerabilities;

[0013] The runtime environment layer detects whether the runtime environment contains debugging tools through sensitive identification. If unconventional ports are found to be exposed, they are marked as risk items. If risks are identified, runtime monitoring probes are embedded when the runtime environment layer is encrypted, and abnormal memory operations are continuously detected after the container is started.

[0014] The application code layer identifies hard-coded API key patterns in the code and detects whether it contains encryption and decryption function calls. When sensitive code patterns are found, dynamic code obfuscation is triggered, pseudocode branches are inserted before encryption, and a coupling dependency is formed with the key generation logic.

[0015] As a preferred solution of the container image security management method of the present invention, wherein:

[0016] The dependency analysis detection parses the publisher certificate chain in the dependency package metadata, cross-validates the publisher certificate chain with the pre-stored trusted CA root certificate, and identifies the third-party dependency package. If it is not on the whitelist, the dependency package performs a sandbox simulation installation and monitors whether there are any abnormal system calls or covert channel creation behaviors;

[0017] The identification of whether the kernel version is a known vulnerability version includes: extracting the compilation timestamp and version identifier of the kernel image, verifying the integrity and consistency of the version identifier with the official release package through a hash chain, correlating the kernel version number with the CVE database for query, and establishing a vulnerability impact scoring model. When an unpatched high-risk vulnerability is detected, it is marked as a risk level. For the vulnerable kernel version, a version isolation tag is embedded in the encryption process, restricting the image to be decrypted and run only in a host environment equipped with a virtualization vulnerability mitigation mechanism;

[0018] When dependency analysis detects high-risk dependencies or vulnerable kernels, the encryption system performs hardware environment binding operations and injects verification logic based on the trusted execution environment into the image layer, allowing the decryption process to negotiate keys through the hardware security module of the secure physical device and implement dynamic address randomization protection in the memory.

[0019] As a preferred solution of the container image security management method of the present invention, wherein:

[0020] The sensitive identification detection includes a sensitive information feature library, identifying hard-coded keys through regular expressions, and verifying the validity of the hard-coded keys in combination with contextual semantics. If it is detected that the key string is not referenced by an environment variable or encrypted, it is determined to be a risk item;

[0021] The runtime monitoring probe is injected when the container is started to hijack key system call instruction functions. If a memory read operation on the encrypted code segment is detected, the digital signature of the access process is verified, the attach request of the unauthorized debugger is intercepted, the memory page of the code segment is write-protected, and the code injection behavior is monitored in real time.

[0022] Establish a baseline for function call frequency during normal operation. When abnormal behavior is detected, dynamically modify the encryption function pointer, making it impossible for attackers to locate the real decryption logic and reconstruct the pseudo-key distribution path in memory, inducing reverse engineering into an infinite loop.

[0023] As a preferred solution of the container image security management method of the present invention, wherein:

[0024] The dynamic code obfuscation includes: when the semantic analysis engine detects a sensitive code pattern, starting the code mutation controller to parse the target function control flow graph and inserting pseudocode branches at key nodes;

[0025] The coupling dependency formed with the key generation logic includes dynamic key sharding and reorganization and verification chain;

[0026] The dynamic key fragmentation and reorganization splits the original key into static fragments and dynamic fragments, wherein the static fragments are stored in a fixed position in the code annotation or resource file, and the dynamic fragments are dispersed in the operation results of the pseudo code branch;

[0027] Establish a key coupling reinforcement mechanism and inject environment binding parameters in the code obfuscation stage to make the key synthesis process dependent on the actual preset operating environment.

[0028] As a preferred solution of the container image security management method of the present invention, wherein:

[0029] The environmental risk score calculates the environmental risk coefficient in real time by establishing a risk model and assessing the risk level and deviation index of historical access behavior;

[0030] The input data of the risk model includes the network proxy type, the validity period and revocation status of the device integer chain. The network proxy type, the validity period and revocation status of the device integer chain are tested through point rewards, and the final score is obtained. If the final score is less than the minimum threshold, the security verification is triggered to re-verify the identity information.

[0031] As a preferred solution of the container image security management method of the present invention, wherein:

[0032] Establishing a dynamic attribute certificate system based on the environmental risk score, generating a multi-dimensional attribute tag for each access request including a real-time risk score, device trust level, and operation type;

[0033] When security verification is triggered, the system compares the attribute tags of the current access request with historical risk data, requiring that the newly submitted attribute set must completely cover and exceed the historical minimum security threshold;

[0034] By analyzing the timing characteristics and parameter patterns of API call sequences, a behavioral baseline for operation types is established. If an operation type does not match the device trust level, an operation jump that does not conform to business logic occurs in the time sequence, a mechanized call pattern with fixed time intervals, or a high-frequency access that exceeds a preset frequency threshold is detected, it is marked as an anomaly.

[0035] A graph neural network is used to perform topological analysis on data access paths and extract path feature maps of normal operations. When the similarity between the real-time access path and the training map falls below the preset similarity threshold, a risk warning mechanism is triggered.

[0036] Build an anomaly prediction model, continuously iterate based on the historical anomaly sample library, and adapt to the latest attack patterns through transfer learning technology.

[0037] As a preferred solution of the container image security management method of the present invention, wherein:

[0038] The operation type and normal behavior are learned through a temporal convolutional network, the normal path is output, and the dependency coefficient of the operation coherence is captured. If the dependency coefficient is higher than a preset coefficient threshold, the operation type is non-abnormal;

[0039] The real-time operation type is sliced ​​by time window to generate a feature vector. The deviation degree between the real-time operation type vector and the operation type training set distribution is compared, and a risk score of 0-100 is output. The alarm threshold is automatically adjusted according to the system load.

[0040] As a preferred solution of the container image security management method of the present invention, wherein:

[0041] The double-layer encryption channel includes an outer layer of the double-layer encryption channel and an inner layer of the double-layer encryption channel. The outer layer of the double-layer encryption channel establishes a standard encryption channel and verifies the server certificate through a hardware security module. The inner layer of the double-layer encryption channel establishes a dynamic sharding encryption tunnel, shards the container image according to a fixed block size, encrypts each shard, and assigns an independent transmission path index to each shard.

[0042] As a preferred solution of the container image security management method of the present invention, wherein:

[0043] The outer layer of the double-layer encrypted channel carries shard metadata and dynamic reassembly instructions, and the inner layer of the double-layer encrypted channel selects multiple optimal transmission paths according to the real-time network status and constructs a path confusion matrix;

[0044] Detect abnormal access behavior based on the hidden Markov model. If it is suspicious behavior, switch to the AES-NI instruction set. If it is moderately abnormal, reroute the shard path. If it is severely abnormal, update the key maze key.

[0045] The outer session key of the key maze management unit is generated by the hardware security module, and the inner shard key is distributed through the blockchain smart contract. The legitimacy of the key shard is verified based on zero-knowledge proof;

[0046] Integrate three-dimensional access geofencing, device fingerprinting, and environmental risk scoring to dynamically adjust shard encryption strength.

[0047] The present invention discloses a container image security management system, wherein:

[0048] The policy center generates encryption keys and implements encryption policies on the kernel dependency layer, runtime environment layer, application code layer, and sensitive configuration layer to form a basic protection unit;

[0049] Three-dimensional access control parameters, including collecting device fingerprints, geo-fencing information, and evaluating environmental risk scores. By establishing a risk model, the environmental risk coefficient is calculated in real time, and the risk level and deviation index of historical access behavior are evaluated.

[0050] Establish an operation type anomaly prediction model, learn operation types and normal behaviors through a time series convolutional network, and automatically detect and obtain the normal path based on the actual operation type of the system;

[0051] A double-layer encryption channel is established, wherein the outer layer of the double-layer encryption channel writes an access encryption protocol, and the inner layer of the double-layer encryption channel outputs a sufficient encryption strategy for mirror fragments in real time.

[0052] Beneficial effects of the present invention:

[0053] This application solves the problems of static encryption that is easily cracked, permission control that is disconnected from the environment, and single-point vulnerability of key storage in traditional container image security through layered sensitive-aware encryption, dynamically adaptive access control, and quantum-resistant sharding key architecture.

[0054] This application establishes a double-layer encryption channel. The outer layer ensures the security of basic communications, and the inner layer resists advanced attacks through dynamic fragmentation and reorganization. It improves the anti-attack capability of container image transmission, effectively responds to the threats of man-in-the-middle attacks and data tampering, and reduces the risk of long-term key leakage through dynamic path obfuscation and key update mechanisms. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings without inventive effort. Among them:

[0056] Figure 1 This is a flow chart of the container image security management method of the present invention;

[0057] Figure 2 This is a flow chart of the access request phase and the image building phase in the container image security management method of the present invention;

[0058] Figure 3 This is a structural diagram of a double-layer encryption channel in the container image security management method of the present invention;

[0059] Figure 4 This is a flow chart of the outer layer data transmission of the double-layer encryption channel in the container image security management method of the present invention;

[0060] Figure 5 This is a flow chart of data transmission in the inner layer of a double-layer encrypted channel in the container image security management method of the present invention.

[0061] Figure numerals: 1. Secure standard encrypted channel; 2. Secure dynamic fragmented encrypted tunnel; 3. Abnormal response dynamic fragmented encrypted tunnel; 4. Abnormal response secure standard channel. DETAILED DESCRIPTION

[0062] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0063] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0064] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive of other embodiments.

[0065] Example 1

[0066] like Figure 1 、 Figure 2 As shown in the figure, the container image security management method includes:

[0067] Container images are built, and differentiated encryption keys are generated through the policy center. Encryption policies are implemented on the kernel dependency layer, runtime environment layer, application code layer, and sensitive configuration layer to form a layered protection foundation.

[0068] Specifically, the container image construction includes multiple layers of dynamic encryption, which are multiple layers of independent encryption, and the encryption key is dynamically derived by the policy center;

[0069] The multi-layer independent encryption includes implementing independent encryption strategies for the kernel dependency layer, runtime environment layer, application code layer and sensitive configuration layer.

[0070] Furthermore, the kernel dependency layer detects whether there are unverified third-party dependency packages through dependency analysis, and identifies in real time whether the kernel version belongs to a version with known vulnerabilities;

[0071] The runtime environment layer detects whether the runtime environment contains debugging tools through sensitive identification. If unconventional ports are found to be exposed, they are marked as risk items. If risks are identified, runtime monitoring probes are embedded during encryption at this layer to continuously detect abnormal memory operations after the container is started.

[0072] The application code layer identifies hard-coded API key patterns in the code and detects whether it contains encryption and decryption function calls. When sensitive code patterns are found, dynamic code obfuscation is triggered, pseudocode branches are inserted before encryption, and a coupling dependency is formed with the key generation logic.

[0073] A specific implementation method for encrypting the kernel dependency layer includes:

[0074] During the container image building phase, static parsing tools are used to automatically extract all third-party software packages in the kernel dependency layer, such as system libraries, kernel modules, dynamic link libraries, etc., to generate a dependency graph. The package manager's metadata installation traceability is used to identify dependencies with non-standard installation paths and ensure that implicit dependencies are covered.

[0075] The dependency graph is uploaded to the policy center and compared with the preset trusted source list. If an unsigned, unknown source, or unregistered version dependency package is detected, it is marked as an unverified dependency, an alarm is triggered, and metadata is recorded.

[0076] The policy center synchronizes with the external vulnerability database in real time and establishes a kernel version vulnerability mapping table. Vulnerability characteristics include: affected version range, vulnerability type, etc.

[0077] During the build process, the kernel version number of the current image is extracted and compared with the vulnerability library for semantic versioning. If the version number falls within the known vulnerability range and there is no corresponding hot patch mark, it is determined to be a risky version and a vulnerability details report is generated. The vulnerability details report includes the vulnerability ID, severity level, and attack vector.

[0078] The policy center dynamically derives encryption keys based on dependency verification results and vulnerability determination status:

[0079] The input factors are matched with the master key of the policy center to generate a unique session key. If the kernel state changes, the key is automatically invalidated and re-derived.

[0080] Kernel dependency layer encryption uses transparent file system encryption technology. It encrypts files at the file level when building the image. The encrypted metadata is embedded in the image metadata layer, and the decryption trigger conditions are agreed upon with the runtime decryption engine.

[0081] When the container starts, the decryption agent initiates a key request to the policy center, submitting the current kernel version, dependency package hash, and container identity credentials. The policy center verifies the environmental compliance and returns a temporary decryption key if it passes.

[0082] If the kernel dependency layer is marked as a risky version, the policy center will issue memory monitoring rules simultaneously with the key return. After the decryption agent loads the decrypted content into memory, it will enable lightweight runtime detection to intercept abnormal memory operations.

[0083] Dynamic code obfuscation includes: when the semantic analysis engine detects a sensitive code pattern, it starts the code mutation controller to parse the target function control flow graph and insert pseudocode branches at key nodes.

[0084] A method for triggering and executing dynamic code obfuscation includes:

[0085] Set up a dynamic code feature library, define sensitive codes, and match semantic analysis results against the sensitive codes defined in the dynamic code feature library.

[0086] Furthermore, during the compilation or bytecode loading phase, the code execution flow is monitored in real time. If the probe captures the calling code to allocate the key buffer, a deep analysis is triggered.

[0087] The controller converts source code or binary into a platform-independent intermediate representation, eliminating interference from platform characteristics and facilitating unified analysis.

[0088] By statically analyzing the basic blocks and jump relationships in the IR, a weighted control flow graph is constructed. The weights are based on the node execution frequency and are calculated through historical monitoring data or static prediction models.

[0089] Among them, IR is the intermediate representation, which is an abstract code form used by the compiler to convert source code into target code. It is used to simplify cross-platform compilation, code optimization, static analysis and other operations.

[0090] A method for defining a key node includes:

[0091] Key nodes define code areas involved in key generation, encryption and decryption operations, and sensitive configuration loading, and are the branch decision points that dominate the core logic of the program.

[0092] Methods for inserting pseudocode at key nodes and establishing key coupling reinforcement mechanisms include:

[0093] Insert true or false conditional judgments before key nodes, embed equivalent redundant operations on both sides of branches, insert loop structures with no practical effect outside key nodes, and make loop termination conditions depend on random numbers or environmental parameters to waste reverse analysis time. Embed key fragment A into code comments and retain it as debug symbols, image metadata, or XOR mask after compilation. Use the "dead code retention" feature of the compilation tool chain to avoid optimization stripping, record the execution order and time interval of pseudocode branches, and generate a timing chain hash.

[0094] Furthermore, a verification probe is inserted to calculate the hash value of the key code segment and compare it with the pre-stored value. If it is tampered with, the key fragment is triggered to self-destruct. When the container is started, the CPU fingerprint and ASLR offset are re-collected and compared with the key synthesis parameters. If the environment changes, the key is automatically invalidated.

[0095] Furthermore, if tampered with, the key fragments are cut off according to application requirements, terminating access to the critical code.

[0096] Dynamic key fragmentation and reorganization splits the original key into static fragments and dynamic fragments. The static fragments are stored in a fixed location in the code annotation or resource file, and the dynamic fragments are scattered in the operation results of the pseudo code branch;

[0097] The key coupling reinforcement mechanism is established, and environment binding parameters are injected into the code obfuscation stage, so that the key synthesis process depends on the actual preset operating environment.

[0098] Environment-dependent implementations of key synthesis include:

[0099] The key synthesis method includes real-time collection of environmental binding parameters. The master key is split into multiple fragments, each fragment corresponds to a type of environmental parameter, the device fingerprint is generated and stored in the hardware security module, and the current timestamp is generated. The validity period of each fragment is only a single session.

[0100] When the environmental parameters corresponding to all fragments meet the conditions at the same time, the complete key is synthesized through the key reorganization algorithm.

[0101] The specific methods for establishing the environmental parameter collection, hash verification, fragment decryption, and combined verification process include:

[0102] Collect the current device fingerprint and calculate the hash value; use the hardware private key in the HSM to decrypt the stored hardware fragments; compare the decrypted fragment hash with the hash value calculated in real time; if they are consistent, continue to synthesize other fragments; after all fragments are verified, generate the final key through the key derivation function.

[0103] If an abnormal environment parameter is detected, the following defense measures are immediately triggered: destroy the key fragments in the memory; terminate the current session and record the abnormality log; send an environmental risk alert to the policy center and dynamically adjust the encryption strength of subsequent access.

[0104] Specifically, a specific implementation method of dynamic code obfuscation includes:

[0105] The dependency analysis detection includes: parsing the publisher certificate chain in the dependency package metadata, cross-verifying the publisher certificate chain with the pre-stored trusted CA root certificate, identifying the third-party dependency package, and if it is not on the whitelist, performing a sandbox simulation installation of the dependency package and monitoring whether there are any abnormal system calls or covert channel creation behaviors;

[0106] The identification of whether the kernel version is a known vulnerability version includes: extracting the compilation timestamp and version identifier of the kernel image, verifying the integrity and consistency of the version identifier with the official release package through a hash chain, correlating the kernel version number with the CVE database for query, and establishing a vulnerability impact scoring model. When an unpatched high-risk vulnerability is detected, it is marked as a risk level. For the vulnerable kernel version, a version isolation tag is embedded in the encryption process, restricting the image to be decrypted and run only in a host environment equipped with a virtualization vulnerability mitigation mechanism;

[0107] When dependency analysis detects high-risk dependencies or vulnerable kernels, the encryption system performs hardware environment binding operations and injects verification logic based on the trusted execution environment into the image layer, allowing the decryption process to negotiate keys through the hardware security module of the secure physical device and implement dynamic address randomization protection in the memory.

[0108] Furthermore, high-risk dependencies refer to third-party components introduced during the software construction process that have known security flaws or potential risks. Third-party components with known security flaws or potential risks include open source libraries that have not passed digital signature verification and those that have remote code execution vulnerabilities.

[0109] Furthermore, a vulnerable kernel specifically refers to a security risk in which there are exploitable flaws in the kernel layer of the operating system.

[0110] A specific implementation method of dependency analysis detection includes:

[0111] Before installing the dependent package, use a static scanning tool to extract the publisher's digital signature embedded in the package, parse the certificate chain structure, trace back to the root certificate authority, and extract metadata such as the publisher name, certificate validity period, and key usage.

[0112] The policy center pre-installs a trusted root certificate library, including official repository CAs, enterprise-built CAs, and compliant third-party supplier CAs. It compares the dependent package certificate chain with the trusted library step by step: verifying that the certificate has not expired or been revoked, ensuring the purpose of the certificate, and preventing the abuse of ordinary encryption certificates. If the final root certificate of the certificate chain is not in the trusted library, it is marked as an uncertified issuer.

[0113] For dependency packages developed by the enterprise or provided by partners, it supports dynamic uploading of their certificates to the temporary whitelist of the policy center and attaching signature timeliness policy.

[0114] For dependent packages that fail certificate verification, a lightweight sandbox is started to simulate the real installation environment to restrict CPU, memory, disk and network access permissions, open only the basic system call whitelist, virtualize the kernel version and hardware information, prevent the dependent package from detecting sandbox features, execute the dependent package installation script in the sandbox, record all operations through the system call interception layer, and monitor unconventional inter-process communications.

[0115] Files generated or modified during the installation process are marked as unverified dependency products. If such files are subsequently loaded during container runtime, a real-time hash check is triggered and compared with the file snapshot recorded in the sandbox.

[0116] Extract the compilation timestamp and version identifier from the kernel image header file, such as 5.4.0-100-generic, and verify whether it is consistent with the public version by combining it with the official build log database.

[0117] 5.4.0-100-generic is the Linux kernel version identifier, which is used to uniquely identify a specific kernel version and its configuration.

[0118] Furthermore, during the hash chain verification process, the kernel source code package and binary package of the corresponding version are downloaded and their hash values ​​are calculated. If the kernel is custom compiled, a build audit log is required to verify the reproducibility of the build process through the log hash chain.

[0119] Furthermore, CVE vulnerability association and scoring are matched with vulnerability data in real time through the policy center to establish a kernel version-vulnerability mapping table, with additional dimensions such as vulnerability exploitation complexity, repair status, and attack scenarios.

[0120] The dynamic scoring model identifies the vulnerability type based on the CVSS score and determines whether the vulnerability has been exposed to the public network based on the expected operating environment of the container.

[0121] Specifically, during the process of binding encryption isolation to the hardware environment, if the kernel version is marked as a high-risk vulnerability and has not been fixed, an isolation policy tag is embedded during encryption, declaring that the image is only allowed to run on a host machine that meets the following conditions: the host machine enables hardware-level protection such as kernel page table isolation and management mode access protection, the host machine kernel version is not lower than the specified patch level, and high-risk modules have been disabled. During the encryption key derivation process, a trusted execution environment is introduced to generate a hardware-unique key to ensure that the key cannot be directly accessed by the host machine OS. During memory decryption, the TEE drives the memory management unit to implement dynamic base address offsets for the decrypted code segment, randomizes the memory layout each time it is loaded, and prevents ROP attacks. The decryption request needs to be authenticated twice through an HSM, such as YubiKey or TPM security chip. After the HSM verifies that the host machine hardware fingerprint matches the policy, it releases the decryption key to the secure memory area. The key lifecycle is bound to the container instance.

[0122] ROP is an advanced code injection attack technique in which attackers exploit existing code snippets in a program to perform malicious operations without injecting new code.

[0123] Specifically, behavior traceability and policy dynamic updates can also be set based on container key security.

[0124] The sensitive identification detection includes a sensitive information feature library, identifying hard-coded keys through regular expressions, and verifying the validity of the hard-coded keys in combination with contextual semantics. If it is detected that the key string is not referenced by an environment variable or encrypted, it is determined to be a risk item;

[0125] Furthermore, the runtime monitoring probe is injected when the container is started to hijack key system call instruction functions. If a memory read operation on the encrypted code segment is detected, the digital signature of the access process is verified, the attach request of the unauthorized debugger is intercepted, the memory page of the code segment is write-protected, and the code injection behavior is monitored in real time.

[0126] Establish a baseline for function call frequency during normal operation. When abnormal behavior is detected, dynamically modify the encryption function pointer, making it impossible for attackers to locate the real decryption logic and reconstruct the pseudo-key distribution path in memory, inducing reverse engineering into an infinite loop.

[0127] A specific implementation method of a monitoring probe includes:

[0128] The probe modifies the kernel system call table and implants interception logic before instruction execution. Through the scalability of the operating system kernel, it verifies the legitimacy of the process before calling system resources.

[0129] Furthermore, the encryption module function pointer is dynamically managed, and a shadow pointer table is maintained as a mapping carrier between the real function and the trap function. Under normal circumstances, the pointer points to the real logic. When an abnormality is detected, the probe dynamically switches the pointer to the preset trap function through the memory address remapping mechanism; through the indirect addressing characteristics of pointers in computer systems, attackers cannot locate the real decryption logic through static analysis.

[0130] Furthermore, the page table permission mechanism of the memory management unit is the basis for defending against code injection. The probe marks the encrypted code segment as read-only and uses the hardware's memory protection features to make any write operation trigger a page fault exception. When an exception occurs, the probe verifies the source of the operation through the kernel exception handling mechanism, blocks unauthorized memory modifications, and sets a write protection barrier in the memory area. At the same time, it combines the operating system's exception handling process to achieve active defense. The memory base address of the encrypted code segment is randomized at startup, and the data structure offset is adjusted in real time. The address space layout randomization technology is used to increase the difficulty for attackers to use return-oriented programming attacks.

[0131] Specifically, randomized memory addresses make it difficult to predict the location of the instruction fragments required for the attack, destroying the fixed memory layout that ROP attacks rely on, thereby increasing the difficulty for attackers to exploit return-oriented programming attacks.

[0132] The encryption key is split into multiple fragments and stored in the memory, hardware registers and policy center protected by the probe. The fragments are combined through a logical XOR chain and are only allowed to take effect when the probe integrity check passes. If the probe detects anomalies such as tampering or attack, it immediately triggers the displacement of the key fragment, combines the timestamp and the hardware entropy source to generate a new key, and synchronously updates it to the policy center. Through state dependency, the key changes dynamically with the defense environment. Even if the attacker obtains part of the key fragment, he will not be able to restore the complete key due to the change of the probe state or the failure of the time factor, thereby eliminating the possibility of offline analysis and cracking.

[0133] The probe blocks system call hijacking and debugger attachment in real time, achieving real-time monitoring and closed-loop response of the execution environment. Dynamic pointer redirection, memory write protection, key state binding, and ASLR technologies form a multi-layered defense barrier.

[0134] Furthermore, pointer redirection prevents logical targeting, write protection blocks physical tampering, dynamic key updates resist state analysis, and ASLR increases attack complexity. By minimizing trust assumptions, the defense system becomes adaptive.

[0135] Furthermore, by combining the trusted execution environment with the hardware-level root of trust provided by the hardware security module, the probe can flexibly adjust the defense strength based on the policy, blocking the attacker's control path to the code execution environment.

[0136] Example 2

[0137] A container image security management system, the specific implementation method includes:

[0138] If an access request is triggered, the device fingerprint and geo-fence information are first collected and the environmental risk score is evaluated. The access rights and access scenario matching are verified through attribute-based encryption, the operation trajectory characteristics are analyzed in real time, and abnormal patterns are identified. If the three-layer verification is passed, a temporary access token is generated.

[0139] The three-layer verification includes the kernel dependency layer, the runtime environment layer, the application code layer and the sensitive configuration layer.

[0140] The environmental risk score calculates the environmental risk coefficient in real time by establishing a risk model and assessing the risk level and deviation index of historical access behavior;

[0141] The input data of the risk model includes the network proxy type, the validity period and revocation status of the device integer chain. The network proxy type, the validity period and revocation status of the device integer chain are tested through point rewards, and the final score is obtained. If the final score is less than the minimum threshold, security verification is triggered and the identity information is re-verified.

[0142] The methods for establishing risk models include:

[0143] Classify network proxies, mark data sources, set device certificate chain status and historical behavior records.

[0144] Furthermore, the device certificate chain status includes validity period verification, revocation status check, and certificate chain integrity verification.

[0145] Validity verification is used to check the start and end times of the client certificate, and points will be deducted if it is close to expiration.

[0146] Revocation status check is used to query the certificate revocation list in real time. If the certificate is revoked, it is considered high risk.

[0147] Certificate chain integrity verification is used to verify whether the certificate chain is complete and whether it contains untrusted CAs.

[0148] Establishing a dynamic attribute certificate system based on the environmental risk score, generating a multi-dimensional attribute tag for each access request including a real-time risk score, device trust level, and operation type;

[0149] When security verification is triggered, the system compares the attribute tags of the current access request with historical risk data, requiring that the newly submitted attribute set must completely cover and exceed the historical minimum security threshold.

[0150] Specifically, the network proxy type corresponds to the real-time risk score, the device certificate chain corresponds to the device trust level, and the revocation status test corresponds to whether the current operation meets the preset requirements. According to the corresponding relationship, if the security verification is triggered, it means that the current real-time risk score, device trust level and current operation type trigger an early warning, then the deviation index of the data access risk level and historical access behavior is high, and immediate feedback is given to re-verify the identity information.

[0151] By analyzing the timing characteristics and parameter patterns of API call sequences, a behavioral baseline for operation types is established. If an operation type does not match the device trust level, an operation jump that does not conform to business logic occurs in the time sequence, a mechanized call pattern with fixed time intervals, or a high-frequency access that exceeds a preset frequency threshold is detected, it is marked as an anomaly.

[0152] A graph neural network is used to perform topological analysis on data access paths and extract path feature maps of normal operations. When the similarity between the real-time access path and the training map falls below the preset similarity threshold, a risk warning mechanism is triggered.

[0153] Build an anomaly prediction model, continuously iterate based on the historical anomaly sample library, and adapt to the latest attack patterns through transfer learning technology.

[0154] The specific implementation methods of using graph neural networks to perform topological analysis on data access paths include:

[0155] Data collection and feature definition, including: the system records the metadata of all API requests, including operation type, timestamp, caller identity, parameter structure, response status code, etc., stores them as time series logs in a unified format, and extracts key features from the logs, such as operation type combination, time interval distribution, parameter diversity, and access path depth.

[0156] Establish an anomaly detection mechanism, including: counting the time difference between consecutive requests. If the interval exceeding the threshold ratio falls within a fixed interval, it is marked as a mechanized rhythm. If the number of similar operations in the sliding window exceeds the historical baseline, it is marked as burst traffic. Verify whether the operation sequence conforms to the business scenario and whether the detection parameter value exceeds the normal range.

[0157] Establishing a normal path topology includes: converting historical normal API call sequences into a directed graph, with nodes as operation types and edge weights as transfer frequencies, identifying high-frequency core operations, calculating indicators such as path length, number of branches, and loop structure, encoding path graph features into fixed-dimensional numerical vectors as input to the neural network, and using autoencoders to learn the distribution pattern of normal operation sequences. The model captures the implicit rules in the path topology through a compression-reconstruction process.

[0158] Perform anomaly prediction and dynamic response, including: inputting real-time API sequences into a trained autoencoder, calculating the difference between the output and input, comparing the degree of match between the current sequence and the normal topology, enhancing logging, limiting the rate of non-critical operations, blocking high-risk requests in real time, triggering multi-factor authentication, and notifying the security team to intervene and analyze.

[0159] Conduct closed-loop feedback and model optimization, including: recording manual review intercepts, marking misjudgment cases, correcting training data labels, regularly inputting newly collected normal operation data into the model, fine-tuning network weights to adapt to business changes, and dynamically optimizing anomaly scoring thresholds based on recent attack frequency and business load.

[0160] Example 3

[0161] like Figure 4 and Figure 5 As shown, the container image security management method also includes:

[0162] Establish a double-layer encryption channel, the outer layer of the double-layer encryption channel writes access encryption protocol, and the inner layer of the double-layer encryption channel outputs real-time image fragmentation encryption sufficient strategy.

[0163] The double-layer encryption channel includes an outer layer and an inner layer of the double-layer encryption channel. The outer layer of the double-layer encryption channel establishes a standard encryption channel and verifies the server certificate through a hardware security module. The inner layer of the double-layer encryption channel establishes a dynamic sharding encryption tunnel, shards the container image according to a fixed block size, encrypts each shard, and assigns an independent transmission path index to each shard.

[0164] The outer layer of the double-layer encrypted channel carries shard metadata and dynamic reassembly instructions, while the inner layer of the double-layer encrypted channel selects multiple optimal transmission paths based on real-time network status and constructs a path confusion matrix;

[0165] Detect abnormal access behavior. If it is suspicious, switch the AES-NI instruction set. If it is moderately abnormal, reroute the shard path. If it is severely abnormal, update the key maze key.

[0166] Suspicious behavior refers to abnormal signs that deviate from normal access patterns but do not yet pose a clear threat, including access identity and authentication anomalies, data transmission and fragmentation anomalies, etc.

[0167] Moderately abnormal behavioral characteristics include operations that deviate from the normal baseline but do not affect core security; operation frequency exceeds the norm but does not reach the high-frequency threshold; and there are non-critical logic jump anomalies in the API call sequence.

[0168] The scoring standard for a moderately abnormal environment is that the risk score is lower than the safety threshold but does not reach the minimum line.

[0169] The system response to moderate anomalies is to trigger the rerouting of shard paths to obfuscate transmission tracks; enhance log monitoring without blocking normal access.

[0170] Severely abnormal behavioral characteristics include clear signs of attack; high-frequency mechanized operations; and highly sensitive operations initiated by low-trust devices.

[0171] The scoring standard for a severely abnormal environment is that the risk score is far below the safety baseline.

[0172] The system response to severe anomalies is to trigger the highest level of defense: updating the key maze key and blocking access requests; linking the hardware security module to verify the device fingerprint and limit the image decryption environment.

[0173] The outer session key of the key maze management unit is generated by the hardware security module, and the inner shard key is distributed through the blockchain smart contract. The legitimacy of the key shard is verified based on zero-knowledge proof;

[0174] Integrate three-dimensional access geofencing, device fingerprinting, and environmental risk scoring to dynamically adjust shard encryption strength.

[0175] Furthermore, dynamic encryption and path management include:

[0176] Block-level encryption is achieved through shard encryption, which supports parallel processing to improve efficiency. Each shard uses an independent 256-bit encryption key, which is dynamically generated by the key maze management module.

[0177] Path obfuscation calculates multiple optimal paths in real time. Path selection factors include bandwidth utilization, node credibility, etc. Fragmented data is transmitted through different paths, and the receiving end reassembles the image based on the path index.

[0178] Through intelligent anomaly detection and response analysis of operation trajectory characteristics, the anomaly probability is calculated in real time, and the state transition matrix is ​​trained based on historical operation behavior to distinguish normal operations from attack behaviors.

[0179] The response strategy is adaptively selected based on normal operations and attack behaviors. The response strategies include suspicious behaviors, moderate anomalies, and severe anomalies.

[0180] Specifically, when suspicious behavior occurs, switch to the AES-NI instruction set.

[0181] In case of moderate anomalies, the shard path is rerouted.

[0182] In case of severe anomalies, the key maze is triggered to update the key.

[0183] The outer session key of the key maze management unit is generated by the HSM, and the inner shard key is distributed through the blockchain smart contract. Furthermore, the key shards are stored in the HSM, blockchain and runtime environment. Decryption requires device certificate verification, dynamic password matching and zero-knowledge proof synthesis.

[0184] The key maze management unit also includes memory security protection, combined with memory page randomization to prevent side-channel attacks. The master key is only temporarily assembled in memory and erased immediately after use.

[0185] The key maze management unit also includes three-dimensional access control integration, which includes environmental dimension, role dimension and behavioral dimension. Furthermore, the environmental dimension includes geo-fences to limit transmission path endpoints, device fingerprint binding encryption parameters, role dimension includes attribute-based encryption technology to verify user permissions and scenario matching, and the behavioral dimension analyzes operation consistency based on the time series convolutional network and predicts abnormal behavior.

[0186] like Figure 3 As shown, it is a double-layer encryption channel, including the outer layer of the double-layer encryption channel composed of the security standard encryption channel 1 and the abnormal response security standard channel 4, and the inner layer of the double-layer encryption channel composed of the security dynamic fragmented encryption tunnel 2 and the abnormal response dynamic fragmented encryption tunnel 3. The triangular area is the security core area, as shown in Figure 3 As shown in the figure, when accessing the security core area, if an exception occurs, the outer layer of the encrypted channel changes from a solid line to a dotted line, which triggers security feedback, the server returns the access, and re-performs client security authentication.

[0187] The specific implementation methods include: the outer layer of the double-layer encrypted channel establishes a secure transport layer based on the TLS 1.3 protocol, adopts the ECDHE-ECDSA-AES256-GCM-SHA384 algorithm suite to negotiate session keys, verifies the server certificate chain through the hardware security module (HSM), ensures the trustworthiness of the communication endpoint, and carries sharding metadata and dynamic reassembly instructions.

[0188] The inner layer of the double-layer encryption channel shards the container image into 4KB fixed block sizes, encrypts each shard using AES-XTS mode, and allocates three independent transmission paths for each shard. The path confusion matrix is ​​updated every 30 seconds based on the real-time network status. The legitimacy of the shard data is verified through zero-knowledge proof to prevent tampering by middlemen.

[0189] Furthermore, the main process from the client to the server is represented by a solid line, and the abnormal response branch is represented by a dotted line.

[0190] The double-layer channel structure can resist man-in-the-middle attacks and data tampering, and uses distributed storage and dynamic update mechanisms to reduce the risk of key leakage. Parallel encryption and path obfuscation shorten the image transmission time. The three-dimensional access parameters are dynamically bound to the encryption strength, reducing the risk of permission violations.

[0191] Specifically, in this application, a preferred implementation method of a double-layer encryption channel includes:

[0192] The double-layer encryption channel is divided into an outer standard encryption channel and an inner dynamic sharding encryption tunnel, forming an outer authentication and inner encryption defense. Furthermore, the outer layer verifies the server certificate based on the protocol and hardware security module to ensure the trustworthiness of the identities of both communicating parties, carries sharding metadata and reorganization instructions, and builds the first security barrier; the inner layer shards the container image according to a fixed block size, and can use AES-XTS mode to encrypt each shard and assign it an independent transmission path index. The layered principle is used to separate data integrity verification from confidentiality protection: the outer layer is responsible for establishing trusted connections and basic transmission control, and the inner layer focuses on data encryption and path obfuscation. Even if the outer channel is attacked, the inner encrypted data cannot be cracked, thereby achieving effective isolation of the attack surface.

[0193] Furthermore, the inner channel dynamically calculates multiple optimal transmission paths based on the real-time network status and constructs a path confusion matrix to resist attacks through the dynamic nature of the network environment and path diversity. Each fragment is assigned an independent transmission path index, and the data is transmitted through different nodes. The receiving end then reassembles the image based on the index, breaking the complete data into fragments and transporting them through multiple covert paths. Even if an attacker intercepts part of the data, it is difficult to restore the full picture of the data. At the same time, the path confusion matrix is ​​updated every t seconds, and the path selection is dynamically adjusted, further increasing the difficulty of the attack and making traditional traffic analysis and data reconstruction attacks ineffective.

[0194] By analyzing operation trajectories and state transition matrices, suspicious, moderate, and severe abnormal behaviors can be identified in real time. Models are trained using historical operation data to learn normal behavior patterns. When operations that deviate from these patterns are detected, different responses are triggered based on the risk level: suspicious behavior switches to the AES-NI instruction set;

[0195] Furthermore, defense is enhanced through encryption algorithm upgrades; moderate anomalies reroute shard paths, confuse transmission tracks, and reduce the success rate of attacks; severe anomalies update the key maze key, block access, and link HSM to verify device fingerprints, cutting off the attack chain. This not only avoids performance loss caused by excessive defense, but also ensures precise defense in different threat scenarios.

[0196] The Key Maze Management Unit achieves decentralized storage and dynamic control of keys through an architecture where the outer session key is generated by the HSM and the inner shard keys are distributed by blockchain smart contracts. Key shards are distributed across the HSM, blockchain, and runtime environment. Decryption requires multiple verifications, including device certificates, dynamic passwords, and zero-knowledge proofs, to ensure unique key usage and immutability.

[0197] When a severe anomaly is detected, the key maze updates the key, combining the time factor and environmental parameters to generate a new key, so that even if an attacker obtains the old key, he cannot decrypt the new data. Memory security protection prevents side-channel attacks through page randomization. The master key is only temporarily assembled and erased immediately after use, further improving key security.

[0198] The three-dimensional access control of environment, role, and behavior dimensions is dynamically associated with encryption strength to build an adaptive security strategy. In the environment dimension, the transmission range and device credibility are restricted by geographic fencing and device fingerprints; in the role dimension, attribute-based encryption technology is used to verify user permissions; in the behavior dimension, abnormal operations are predicted based on a temporal convolutional network. By dynamically associating the three-dimensional access control with encryption strength, the encryption strength is dynamically adjusted according to the credibility of the access subject and the risk of the operation behavior. Specifically, the encryption level is automatically increased for high-risk operations, and resource consumption is reduced in low-risk scenarios, achieving a balance between security and efficiency.

[0199] This application deeply integrates encryption technology, network dynamics, intelligent analysis and key management through a double-layer encryption channel, forming a full life cycle protection for container image transmission and storage, effectively resisting threats such as man-in-the-middle attacks and data tampering.

[0200] It is important to note that the configuration and arrangement of the present application, as illustrated in various exemplary embodiments, are illustrative only. Although only two embodiments are described in detail in this disclosure, those reading this disclosure will readily appreciate that numerous modifications are possible without materially departing from the novel teachings and advantages of the subject matter described herein. For example, variations in the size, dimensions, structure, shape, and proportions of various components, as well as parameter values ​​(e.g., temperature, pressure, etc.), mounting arrangements, use of materials, color, orientation, and the like, are possible. For example, components shown as integrally formed may be comprised of multiple parts or components, the positions of components may be inverted or otherwise altered, and the nature, number, or position of discrete components may be modified or changed. Therefore, all such modifications are intended to be encompassed within the scope of this invention. The order or sequence of any process or method steps may be altered or reordered according to alternative embodiments. Any "means-plus-function" clause is intended to cover structures that perform the functions described herein, and not only structural equivalence but also structural equivalents. Other substitutions, modifications, changes, and omissions may be made in the design, operating conditions, and arrangement of the exemplary embodiments without departing from the scope of this invention. Therefore, the invention is not limited to the specific embodiments, but extends to various modifications that still fall within the scope of the appended claims.

[0201] Additionally, in order to provide a concise description of exemplary embodiments, all features of an actual embodiment may not be described (ie, those features that are not relevant to the best mode presently contemplated for carrying out the invention or those that are not relevant to implementing the invention).

[0202] It should be understood that in the development of any actual embodiment, as in any engineering or design project, numerous implementation-specific decisions may be made. Such a development effort may be complex and time-consuming, but for those of ordinary skill having the benefit of this disclosure, the development effort will be a routine task of design, fabrication, and production without undue experimentation.

[0203] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A container image security management method, characterized in that: include: Container image construction generates differentiated encryption keys through the policy center, and implements encryption policies for the kernel dependency layer, runtime environment layer, application code layer, and sensitive configuration layer, forming a layered protection foundation. If an access request is triggered, the device fingerprint and geo-fence information are first collected and the environmental risk score is assessed. The access rights and access scenario matching are verified through attribute-based encryption. The operation trajectory characteristics are analyzed in real time to identify abnormal patterns. If the three-layer verification passes, a temporary access token is generated. Verify access request permissions and match temporary access tokens, synthesize key shards, and temporarily generate and encrypt the master key in memory. A double-layer encryption channel is established, wherein the outer layer of the double-layer encryption channel writes an access encryption protocol, and the inner layer of the double-layer encryption channel outputs a sufficient encryption strategy for mirror fragments in real time.

2. The container image security management method according to claim 1, characterized in that: The container image construction includes multiple layers of dynamic encryption, which are independent layers of encryption, and the encryption key is dynamically derived by the policy center; The multi-layer independent encryption includes implementing independent encryption strategies for the kernel dependency layer, runtime environment layer, application code layer and sensitive configuration layer.

3. The container image security management method according to claim 2, characterized in that: The kernel dependency layer detects whether there are unverified third-party dependency packages through dependency analysis, and identifies in real time whether the kernel version belongs to a version with known vulnerabilities; The runtime environment layer detects whether the runtime environment contains debugging tools through sensitive identification. If an unconventional port is found to be exposed, it is marked as a risk item. If a risk is identified, a runtime monitoring probe is embedded when the runtime environment layer is encrypted. When the container is started, abnormal memory operations are continuously detected; The application code layer identifies hard-coded API key patterns in the code and detects whether it contains encryption and decryption function calls. When sensitive code patterns are found, dynamic code obfuscation is triggered, pseudocode branches are inserted before encryption, and a coupling dependency is formed with the key generation logic.

4. The container image security management method according to claim 3, characterized in that: The dependency analysis detection parses the publisher certificate chain in the dependency package metadata, cross-validates the publisher certificate chain with the pre-stored trusted CA root certificate, and identifies the third-party dependency package. If it is not on the whitelist, the dependency package performs a sandbox simulation installation and monitors whether there are any abnormal system calls or covert channel creation behaviors; The identification of whether the kernel version is a known vulnerability version includes: extracting the compilation timestamp and version identifier of the kernel image, verifying the integrity and consistency of the version identifier with the official release package through a hash chain, correlating the kernel version number with the CVE database for query, and establishing a vulnerability impact scoring model. When an unpatched high-risk vulnerability is detected, it is marked as a risk level. For the vulnerable kernel version, a version isolation tag is embedded in the encryption process, restricting the image to be decrypted and run only in a host environment equipped with a virtualization vulnerability mitigation mechanism; When dependency analysis detects high-risk dependencies or vulnerable kernels, the encryption system performs hardware environment binding operations and injects verification logic based on the trusted execution environment into the image layer, allowing the decryption process to negotiate keys through the hardware security module of the secure physical device and implement dynamic address randomization protection in the memory.

5. The container image security management method according to claim 3, characterized in that: The sensitive identification detection includes a sensitive information feature library, identifying hard-coded keys through regular expressions, and verifying the validity of the hard-coded keys in combination with contextual semantics. If it is detected that the key string is not referenced by an environment variable or encrypted, it is determined to be a risk item; The runtime monitoring probe is injected when the container is started to hijack key system call instruction functions. If a memory read operation on the encrypted code segment is detected, the digital signature of the access process is verified, the attach request of the unauthorized debugger is intercepted, the memory page of the code segment is write-protected, and the code injection behavior is monitored in real time. Establish a baseline for function call frequency during normal operation. When abnormal behavior is detected, dynamically modify the encryption function pointer, making it impossible for attackers to locate the real decryption logic and reconstruct the pseudo-key distribution path in memory, inducing reverse engineering into an infinite loop.

6. The container image security management method according to claim 3, characterized in that: The dynamic code obfuscation includes: when the semantic analysis engine detects a sensitive code pattern, starting the code mutation controller to parse the target function control flow graph and inserting pseudocode branches at key nodes; The coupling dependency formed with the key generation logic includes dynamic key sharding and reorganization and verification chain; The dynamic key fragmentation and reorganization splits the original key into static fragments and dynamic fragments, wherein the static fragments are stored in a fixed position in the code annotation or resource file, and the dynamic fragments are dispersed in the operation results of the pseudo code branch; Establish a key coupling reinforcement mechanism and inject environment binding parameters in the code obfuscation stage to make the key synthesis process dependent on the actual preset operating environment.

7. The container image security management method according to claim 1, characterized in that: The environmental risk score calculates the environmental risk coefficient in real time by establishing a risk model and assessing the risk level and deviation index of historical access behavior; The input data of the risk model includes the network proxy type, the validity period and revocation status of the device integer chain. The network proxy type, the validity period and revocation status of the device integer chain are tested through point rewards, and the final score is obtained. If the final score is less than the minimum threshold, the security verification is triggered to re-verify the identity information.

8. The container image security management method according to claim 7, characterized in that: Establishing a dynamic attribute certificate system based on the environmental risk score, generating a multi-dimensional attribute tag for each access request including a real-time risk score, device trust level, and operation type; When security verification is triggered, the system compares the attribute tags of the current access request with historical risk data, requiring the newly submitted attribute set to completely cover and exceed the historical minimum security threshold; By analyzing the timing characteristics and parameter patterns of API call sequences, a behavioral baseline for operation types is established. If an operation type does not match the device trust level, an operation jump that does not conform to business logic occurs in the time sequence, a mechanized call pattern with fixed time intervals, or a high-frequency access that exceeds a preset frequency threshold is detected, it is marked as an anomaly. Use graph neural networks to perform topological analysis on data access paths and extract path feature maps of normal operations; When the similarity between the real-time access path and the training graph is lower than the preset similarity threshold, the risk warning mechanism is triggered; Build an anomaly prediction model, continuously iterate based on the historical anomaly sample library, and adapt to the latest attack patterns through transfer learning technology.

9. The container image security management method according to claim 8, characterized in that: The operation type and normal behavior are learned through a temporal convolutional network, the normal path is output, and the dependency coefficient of the operation coherence is captured. If the dependency coefficient is higher than a preset coefficient threshold, the operation type is non-abnormal; The real-time operation type is sliced ​​by time window to generate a feature vector. The deviation degree between the real-time operation type vector and the operation type training set distribution is compared, and a risk score of 0-100 is output. The alarm threshold is automatically adjusted according to the system load.

10. The container image security management method according to claim 9, characterized in that: The double-layer encryption channel includes an outer layer of the double-layer encryption channel and an inner layer of the double-layer encryption channel. The outer layer of the double-layer encryption channel establishes a standard encryption channel and verifies the server certificate through a hardware security module. The inner layer of the double-layer encryption channel establishes a dynamic sharding encryption tunnel, shards the container image according to a fixed block size, encrypts each shard, and assigns an independent transmission path index to each shard.

11. The container image security management method according to claim 1, characterized in that: The outer layer of the double-layer encrypted channel carries shard metadata and dynamic reassembly instructions, and the inner layer of the double-layer encrypted channel selects multiple optimal transmission paths according to the real-time network status and constructs a path confusion matrix; Detect abnormal access behavior based on the hidden Markov model. If it is suspicious, switch the AES-NI instruction set. If it is moderately abnormal, reroute the shard path. If it is severely abnormal, update the key maze key. The outer session key of the key maze management unit is generated by the hardware security module, and the inner shard key is distributed through the blockchain smart contract. The legitimacy of the key shard is verified based on zero-knowledge proof; Integrate three-dimensional access geo-fencing, device fingerprinting, and environmental risk scoring to dynamically adjust shard encryption strength.

12. A container image security management system, configured to implement the container image security management method according to any one of claims 1 to 11, characterized in that: include: The policy center generates encryption keys and implements encryption policies on the kernel dependency layer, runtime environment layer, application code layer, and sensitive configuration layer to form a basic protection unit; Three-dimensional access control parameters, including collecting device fingerprints, geo-fencing information, and evaluating environmental risk scores. By establishing a risk model, the environmental risk coefficient is calculated in real time, and the risk level and deviation index of historical access behavior are evaluated. Establish an operation type anomaly prediction model, learn operation types and normal behaviors through a time series convolutional network, and automatically detect and obtain the normal path based on the actual operation type of the system; A double-layer encryption channel is established, wherein the outer layer of the double-layer encryption channel writes an access encryption protocol, and the inner layer of the double-layer encryption channel outputs a mirror fragment encryption strategy in real time.

Citation Information

Patent Citations

  • Container mirror image construction method and device

    CN114995949A

  • File encryption system oriented to confidential container scene

    CN119004512A

  • Encrypted enterprise network data security access method and system

    CN120017424A

  • Attribute-based encryption for selective document content protection

    EP4557144A1

  • Attribute-based encryption for selective document content protection

    US20250165649A1

Cited By

  • Forensic analysis method and system based on intelligent terminal

    CN120763982A

  • AI large model access data security control method

    CN121145235A

  • AI large model access data security control method

    CN121145235B

  • Intelligent ERP financial system data security management and authentication method

    CN121167793A

  • Mobile solid state disk data encryption storage method based on trusted computing module

    CN121234421A