A method, device, electronic device, and storage medium for mirror security inspection

By using the key pair signature mechanism in the image building pipeline and Kubernetes cluster, the problem of mirroring is easily tampered with is solved, and the security and integrity of the mirroring are guaranteed.

CN114254399BActive Publication Date: 2025-06-27INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111592925.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-23
Publication Date
2025-06-27
Estimated Expiration
2041-12-23

AI Technical Summary

Technical Problem

The existing mirror delivery method only matches the image name and TAG tag when deploying the mirror container, resulting in the image being easily tampered with, and there are integrity and security issues.

Method used

By creating a key pair, the private key is stored in the image construction pipeline, the public key is saved in the Kubernetes cluster, and each built image is signed. When the preset conditions are met, the public key is used to sign and check the image to be checked.

Benefits of technology

Through the signature mechanism, we ensure that the source of the mirror is trustworthy and secure, avoid attacks caused by the mirror being tampered with, and ensure the security and integrity of the mirror.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114254399B_ABST
    Figure CN114254399B_ABST
Patent Text Reader

Abstract

The present disclosure provides a mirror security check method, apparatus, electronic device, storage medium, and program product, which can be used in the financial field and other fields. Among them, the mirror security check method includes: creating a key pair, storing the private key in the key pair in the mirror building pipeline, saving the public key in the key pair in the Kubernetes cluster, for each built mirror, signing the mirror with the private key, when a preset condition is met, determining the mirror to be checked according to the preset condition, and performing a signature check on the mirror to be checked with the public key saved in the Kubernetes cluster. By creating a key pair, the private key is used to encrypt and sign the mirror, and the public key is used to check and verify the mirror signature, avoiding attacks caused by mirror tampering, ensuring that the source of the mirror is trustworthy and secure, and guaranteeing the security and integrity of the mirror.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of cloud computing data security, and in particular, to a method, apparatus, electronic device, storage medium, and program product for mirror security inspection. Background Art

[0002] With the development of cloud computing, more and more application programs gradually migrate the nodes deployed on traditional servers to the cloud platform, deliver the application programs in the form of images, and start the image application programs in the form of containers. For the existing image delivery method, when deploying the image container, usually only the image name and TAG label are matched, and there are problems with the integrity and security of the image container that the image is easily tampered with and may cause attacks.

[0003] Disclosure Content

[0004] In view of the above problems, the present disclosure provides a method, apparatus, electronic device, storage medium, and program product for mirror security inspection.

[0005] According to a first aspect of the present disclosure, there is provided a method for mirror security inspection, the method comprising:

[0006] Create a key pair, store the private key in the key pair in the image building pipeline, and save the public key in the key pair in the Kubernetes cluster;

[0007] For each built image, sign the image with the private key;

[0008] When a preset condition is satisfied, determine the image to be inspected according to the preset condition, and perform a signature check on the image to be inspected with the public key saved in the Kubernetes cluster.

[0009] In an embodiment of the present disclosure, after signing the image with the private key, the method further comprises:

[0010] Create a first inspection policy, and save the first inspection policy in the Kubernetes cluster in the form of a Kubernetes Configmap;

[0011] The first inspection policy includes: sorting the images to be inspected according to a preset dimension, and performing a signature check on the images to be inspected in order; or

[0012] Randomly perform a signature check on the images to be inspected one by one.

[0013] In an embodiment of the present disclosure, if the preset condition is that at least one image is started, the image to be inspected is the at least one image;

[0014] Then, the signature check of the above image using the above public key stored in the Kubernetes cluster includes:

[0015] When at least one of the above images is started, the Validating Webhook mechanism of the above Kubernetes cluster is triggered, so that the above Kubernetes cluster calls the above first check policy and uses the above public key to perform a signature check on the image to be checked according to the above first check policy;

[0016] If the signature check of any image in the above image to be checked fails, the startup of the above image fails, and an alarm message is sent to the application related to the above image;

[0017] If the signature check of any image in the above image to be checked passes, the above image is started.

[0018] In an embodiment of the present disclosure, if the above preset condition is to reach a preset time period, then the signature check of the above image using the above public key includes:

[0019] The above Kubernetes cluster calls the above first check policy and uses the above public key to perform a signature check on the image to be checked according to the above first check policy;

[0020] When the signature check of any image in the above image to be checked fails, an alarm message is sent to the application related to the above image.

[0021] In an embodiment of the present disclosure, if the above preset condition is to reach a preset time period, then the method for determining the above image to be checked includes:

[0022] Randomly extracting a preset number of images from the above Kubernetes cluster; or

[0023] Randomly extracting a preset number of images that meet the first preset condition from the above Kubernetes cluster; or

[0024] Sorting all the images in the above Kubernetes cluster in any dimension and sequentially extracting a preset number of images.

[0025] In an embodiment of the present disclosure, if the above preset condition is to reach a preset time period, then when the preset time period is reached, it is judged whether the number of times of reaching the preset time period in history is zero;

[0026] If the number of times the history reaches the preset time period is zero, then sort and number all the images in the above-mentioned Kubernetes cluster according to any dimension, continuously extract a preset number of images starting from the first image after sorting, call the above-mentioned first inspection policy, and use the above-mentioned public key to perform signature inspection on the extracted images according to the above-mentioned first inspection policy;

[0027] If the number of times the history reaches the preset time period is greater than zero, then obtain the dimension for sorting all the images in the above-mentioned Kubernetes cluster, the number of images to be inspected, and the number of the last inspected image when the preset time period was reached last time, and determine the images to be inspected according to the above-mentioned dimension, the above-mentioned number, and the above-mentioned number.

[0028] In an embodiment of the present disclosure, the determining the images to be inspected according to the above-mentioned dimension, the above-mentioned number, and the above-mentioned number specifically includes:

[0029] Sort and number all the images in the above-mentioned Kubernetes cluster according to the above-mentioned dimension, continuously extract the above-mentioned number of images starting from the image next to the above-mentioned number, call the above-mentioned first inspection policy, and use the above-mentioned public key to perform signature inspection on the extracted images according to the above-mentioned first inspection policy;

[0030] If the number of extracted images still does not reach the above-mentioned number after the last image in the above-mentioned Kubernetes cluster is extracted, then determine whether to change the dimension for sorting all the images in the above-mentioned Kubernetes cluster;

[0031] If the dimension for sorting all the images in the above-mentioned Kubernetes cluster is changed, then sort and number all the images in the above-mentioned Kubernetes cluster according to the changed dimension, and continue to execute the step of continuously extracting a preset number of images starting from the first image after sorting, calling the above-mentioned first inspection policy, and using the above-mentioned public key to perform signature inspection on the extracted images according to the above-mentioned first inspection policy;

[0032] If the dimension for sorting all the images in the above-mentioned Kubernetes cluster is not changed, then continue to continuously extract starting from the first image after sorting until the number of extracted images reaches the above-mentioned number, and then stop extracting, call the above-mentioned first inspection policy, and use the above-mentioned public key to perform signature inspection on the extracted images according to the above-mentioned first inspection policy.

[0033] A second aspect of the present disclosure provides an image security inspection device, and the device includes:

[0034] A creation module, configured to create a key pair, store the private key in the key pair in the image building pipeline, and save the public key in the key pair in the Kubernetes cluster;

[0035] A signature module, configured to sign each built image with the private key;

[0036] An inspection module, configured to, when a preset condition is met, determine an image to be inspected according to the preset condition, and perform a signature inspection on the image to be inspected with the public key saved in the Kubernetes cluster.

[0037] A third aspect of the present disclosure provides an electronic device, including:

[0038] One or more processors;

[0039] A memory, configured to store one or more programs,

[0040] wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the image security inspection method.

[0041] A fourth aspect of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the image security inspection method.

[0042] A fifth aspect of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the image security inspection method is implemented.

[0043] The image security inspection method provided by the present disclosure includes: creating a key pair, storing the private key in the key pair in the image building pipeline, saving the public key in the key pair in the Kubernetes cluster, signing each built image with the private key, when a preset condition is met, determining an image to be inspected according to the preset condition, and performing a signature inspection on the image to be inspected with the public key saved in the Kubernetes cluster. By creating a key pair, the private key is used to encrypt and sign the image, and the public key is used to check and verify the image signature, avoiding attacks caused by image tampering, ensuring that the source of the deployed and running image is trustworthy and secure, and guaranteeing the security and integrity of the image. Description of the Drawings

[0044] To more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure. For those skilled in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0045] Figure 1 FIG. schematically shows an application scenario diagram of a mirror security inspection method according to an embodiment of the present disclosure;

[0046] Figure 2 FIG. schematically shows a flowchart of a mirror security inspection method provided by an embodiment of the present disclosure;

[0047] Figure 3 FIG. schematically shows a flowchart of another mirror security inspection method provided by an embodiment of the present disclosure;

[0048] Figure 4 FIG. schematically shows a flowchart of another mirror security inspection method provided by an embodiment of the present disclosure;

[0049] Figure 5 FIG. schematically shows a flowchart of yet another mirror security inspection method provided by an embodiment of the present disclosure;

[0050] Figure 6 FIG. schematically shows a structural block diagram of a mirror security inspection device provided by an embodiment of the present disclosure;

[0051] Figure 7 FIG. schematically shows a structural block diagram of another mirror security inspection device provided by an embodiment of the present disclosure;

[0052] Figure 8 FIG. schematically shows a structural block diagram of yet another mirror security inspection device provided by an embodiment of the present disclosure; and

[0053] Figure 9 FIG. schematically shows a block diagram of an electronic device suitable for implementing a mirror security inspection method according to an embodiment of the present disclosure. Detailed implementation manners

[0054] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.

[0055] The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the present disclosure. The terms "including", "comprising", etc. as used herein indicate the presence of the described features, steps, operations, and / or components, but do not preclude the presence or addition of one or more other features, steps, operations, or components.

[0056] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those of ordinary skill in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0057] In cases where expressions such as "at least one of A, B, and C, etc." are used, generally it should be interpreted according to the meaning commonly understood by those of ordinary skill in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.). In cases where expressions such as "at least one of A, B, or C, etc." are used, generally it should be interpreted according to the meaning commonly understood by those of ordinary skill in the art (for example, "a system having at least one of A, B, or C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.). Those of ordinary skill in the art should also understand that substantially any disjunctive conjunction and / or phrase that represents two or more alternative items, whether in the specification, claims, or drawings, should be understood as presenting the possibility of including one of such items, either of such items, or both items. For example, the phrase "A or B" should be understood as including the possibility of "A" or "B", or "A and B".

[0058] Some block diagrams and / or flowcharts are shown in the accompanying drawings. It should be understood that some blocks or combinations of blocks in the block diagrams and / or flowcharts can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when executed by the processor, these instructions can create a device for implementing the functions / operations illustrated in these block diagrams and / or flowcharts. The technology of the present disclosure can be implemented in the form of hardware and / or software (including firmware, microcode, etc.). In addition, the technology of the present disclosure can take the form of a computer program product on a computer-readable medium storing instructions, and the computer program product can be used by or in combination with an instruction execution system. In the context of the present disclosure, a computer-readable medium can be any medium that can contain, store, transmit, propagate, or transport instructions. For example, a computer-readable medium can include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, components, or propagation media. Specific examples of computer-readable media include: magnetic storage devices, such as magnetic tapes or hard disk drives (HDDs); optical storage devices, such as compact discs (CD-ROMs); memories, such as random access memories (RAMs) or flash memories; and / or wired / wireless communication links.

[0059] The present disclosure provides a mirror security check method, including: creating a key pair, storing the private key in the key pair in the mirror building pipeline, storing the public key in the key pair in the Kubernetes cluster, for each built mirror, signing the mirror with the private key, when a preset condition is met, determining the mirror to be checked according to the preset condition, and performing a signature check on the mirror to be checked with the public key stored in the Kubernetes cluster. The mirror security check method provided by the present disclosure creates a pair of public and private keys, where the private key is used to encrypt and sign the mirror, and the public key is used to check and verify the mirror signature, which can ensure that the source of the deployed and running mirror is trusted and secure, guarantee the security of the mirror, avoid attacks caused by mirror tampering, and ensure the security and integrity of the mirror.

[0060] The present disclosure provides a mirror security check method, device, electronic device, storage medium, and program product. The following is an exemplary description with reference to the accompanying drawings. It should be noted that the serial numbers of the various operations in the following methods are only used as representations of the operations for description, and should not be regarded as indicating the execution order of the various operations. Unless explicitly stated, the method does not need to be executed exactly in the order shown.

[0061] It should be noted that a mirror security check method, device, electronic device, storage medium, and program product provided by the present disclosure can be used in the financial field and can also be used in any field other than the financial field. The present disclosure does not limit the application fields of the provided mirror security check method, device, electronic device, storage medium, and program product.

[0062] Figure 1 Schematically shows an application scenario diagram of a mirror security check method according to an embodiment of the present disclosure. As Figure 1 shown, the application scenario diagram 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, and a server / server cluster 105. The network 104 is used as a medium to provide a communication link between the terminal devices 101, 102, 103 and the server / server cluster 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0063] Users can use the terminal devices 101, 102, 103 to interact with the server / server cluster 105 through the network 104 to receive or send messages, etc. Various client applications may be installed on the terminal devices 101, 102, 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0064] The terminal devices 101, 102, 103 can interact with the server / server cluster 105 through various client applications to send various requests to the server / server cluster 105 or receive the results returned by the server / server cluster 105.

[0065] The terminal devices 101, 102, 103 can be various electronic devices, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.

[0066] The server / server cluster 105 can be a server that provides various services, such as a background management server that supports the websites browsed by users using the terminal devices 101, 102, 103 (only as an example). The background management server can analyze and process data such as received user requests, etc., and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests, etc.) to the terminal devices.

[0067] It should be noted that a mirror security check method provided by an embodiment of the present disclosure can generally be executed by a server / server cluster 105. Correspondingly, a distributed database resource management and control device provided by an embodiment of the present disclosure can generally be set in the server / server cluster 105. A mirror security check method provided by an embodiment of the present disclosure can also be executed by a server or a server cluster different from the server / server cluster 105 and capable of communicating with the terminal devices 101, 102, 103 and / or the server / server cluster 105. Correspondingly, a mirror security check device provided by an embodiment of the present disclosure can also be set in a server or a server cluster different from the server / server cluster 105 and capable of communicating with the terminal devices 101, 102, 103 and / or the server / server cluster 105.

[0068] It should be understood that Figure 1 the numbers of the terminal devices, networks, and the server / server cluster in

[0069] are merely illustrative. According to actual needs, there can be any number of terminal devices, networks, and server / server clusters. Figure 1 The following will be based on Figures 2 to 5 the scenarios described below, and a mirror security check method of the disclosed embodiments will be described in detail through

[0070] Figure 2 FIG. schematically shows a flowchart of a mirror security check method provided by an embodiment of the present disclosure.

[0071] As Figure 2 shown, in an embodiment of the present disclosure, the method includes operation S210 to operation S230.

[0072] In operation S210, a key pair is created, the private key in the above key pair is stored in the mirror building pipeline, and the public key in the above key pair is saved in the Kubernetes cluster.

[0073] In operation S220, for each built mirror, the above mirror is signed using the above private key.

[0074] In operation S230, when a preset condition is met, a mirror to be checked is determined according to the above preset condition, and the above mirror to be checked is subjected to a signature check using the public key saved in the Kubernetes cluster.

[0075] To avoid problems such as integrity and security issues of the image caused by image tampering, it is necessary to check the image. Existing checking methods usually only match the name and TAG label of the image and cannot solve the above technical problems. In this embodiment, by creating a key pair, storing the private key in the key pair in the image building pipeline server, after the image building is completed, the private key can be used to sign the image, and at the same time, the public key is saved in the Kubernetes cluster. When the preset conditions are met, the public key saved in the Kubernetes cluster is used to check the signature of the image. There are many kinds of preset conditions. Different preset conditions may result in different images to be checked. For example, when the preset condition is that at least one image is started, the images to be checked are all the started images. When the preset condition is to reach a preset time period, the images to be checked can be all or part of the images in the Kubernetes cluster. Different preset conditions have corresponding images to be checked, which can meet various image checking requirements. Whether it is to check the signature of the started images or regularly check the signatures of a certain number of images in the Kubernetes cluster, it can effectively ensure the security and integrity of the images.

[0076] It should be understood that the description of the preset conditions in this embodiment is only exemplary to help those skilled in the art understand the technical solution of the present disclosure and is not intended to limit the protection scope of the present disclosure. The preset conditions can be set according to actual needs.

[0077] Figure 3 Schematically shows a flowchart of another image security checking method provided by an embodiment of the present disclosure.

[0078] As Figure 3 shown, in an embodiment of the present disclosure, the method includes operations S310 to S340. Among them, operations S310, S320, and S340 are implemented in the same way as operations S210, S220, and S230 respectively, and the repeated parts will not be elaborated in detail.

[0079] In operation S310, create a key pair, store the private key in the key pair in the image building pipeline, and save the public key in the key pair in the Kubernetes cluster.

[0080] In operation S320, for each built image, use the above private key to sign the above image.

[0081] In operation S330, a first inspection policy is created and saved in the Kubernetes cluster in the form of a Kubernetes Configmap. The first inspection policy includes: sorting the images to be inspected according to a preset dimension and performing signature checks on the images to be inspected in sequence; or randomly performing signature checks on the images to be inspected one by one.

[0082] In operation S340, when preset conditions are met, the images to be inspected are determined according to the preset conditions, and the public key saved in the Kubernetes cluster is used to perform signature checks on the images to be inspected.

[0083] In this embodiment, in order to further improve the inspection efficiency of the images in the Kubernetes cluster and enable the Kubernetes cluster to automatically perform signature checks on the images, a first inspection policy is created and saved in the Kubernetes cluster before performing signature checks on the images. Among them, the first inspection policy is saved in the Kubernetes cluster in the form of a Kubernetes Configmap, which is convenient for triggering the ValidatingWebhook mechanism of the Kubernetes cluster when preset conditions are met, so that the Kubernetes cluster can automatically call the first inspection policy to perform signature checks on the images to be inspected. The images to be inspected may be one or more, and there may be differences in dimensions such as importance, size, and generation time among multiple images to be inspected. Therefore, when inspecting multiple images to be inspected, the multiple images to be inspected can be preprocessed first. For example, the multiple images to be inspected are sorted according to a certain dimension, and then signature checks are performed on the multiple images to be inspected in sequence. Alternatively, no preprocessing may be done, and the multiple images to be inspected are randomly checked.

[0084] It should be understood that the examples of the first inspection policy in the above embodiments are exemplary to help those skilled in the art understand the technical solutions of the present disclosure, and are not intended to limit the protection scope of the present disclosure. The first inspection policy can be set according to actual needs.

[0085] In one embodiment of the present disclosure, a Kubernetes cluster includes at least one namespace, and each image must be stored in a certain namespace. Therefore, the first inspection policy can also be to perform signature inspection on images in a preset number of namespaces in the Kubernetes cluster, or a list of namespaces to be inspected can be set in advance, and only the images in the namespaces in the list of namespaces to be inspected need to be inspected during inspection. Specifically, which namespaces to select for inspection can be set according to requirements. For example, namespaces storing more images or the number of stored images reaching a certain threshold can be selected for inspection. Obviously, there are also cases where signature inspection needs to be performed on multiple images when performing signature inspection on images in a preset number of namespaces in the Kubernetes cluster. For multiple images to be inspected, the processing method is the same as or similar to another embodiment of the first inspection policy described above, and will not be elaborated here. Similarly, the processing method for multiple namespaces to be inspected is also the same as or similar to another embodiment of the first inspection policy described above (sorting by importance, etc. and then inspecting in order), and will not be elaborated here.

[0086] It should be understood that the examples of the first inspection policy in the above embodiments are exemplary to help those skilled in the art understand the technical solution of the present disclosure, and are not intended to limit the protection scope of the present disclosure. The first inspection policy can be set according to actual needs.

[0087] For different preset conditions, the images to be inspected may be different, and the specific inspection methods may also be different. The following will use specific embodiments to illustrate how to determine the images to be inspected for different preset conditions, and how to perform signature inspection on the images to be detected.

[0088] Figure 4 The flowchart of another image security inspection method provided by an embodiment of the present disclosure is schematically shown.

[0089] As Figure 4 shown, in this embodiment, the preset condition is that at least one image is started, and the method includes operation S410 to operation S460. Among them, operation S410 - operation S430 are implemented in the same way as operation S210, operation S220, and operation S330 respectively, and the repeated parts will not be elaborated in detail.

[0090] In operation S410, a key pair is created, the private key in the key pair is stored in the image building pipeline, and the public key in the key pair is saved in the Kubernetes cluster.

[0091] In operation S420, for each built image, the above private key is used to sign the above image.

[0092] In operation S430, a first inspection policy is created and saved in the Kubernetes cluster in the form of a Kubernetes ConfigMap. The first inspection policy includes: sorting the images to be inspected according to a preset dimension and performing signature checks on the images to be inspected in sequence; or randomly performing signature checks on the images to be inspected one by one.

[0093] In operation S440, when at least one image is started, the images to be inspected are the at least one image, triggering the Validating Webhook mechanism of the Kubernetes cluster, causing the Kubernetes cluster to call the first inspection policy and perform signature checks on the images to be inspected according to the first inspection policy using the public key.

[0094] In operation S450, if the signature check of any one of the images to be inspected fails, the startup of the image fails, and an alarm message is sent to the application related to the image.

[0095] In operation S460, if the signature check of any one of the images to be inspected passes, the image is started.

[0096] In this embodiment, the preset condition is that at least one image is started, and the images to be inspected are all the started images. At this time, the Validating Webhook mechanism of the Kubernetes cluster is triggered, causing the Kubernetes cluster to perform signature checks on the started images according to the preset first inspection policy using the public key saved in the Kubernetes cluster. The first inspection policy here can be to sort the images to be inspected and then perform signature checks on the images to be inspected in sequence, or randomly perform signature checks on the images to be inspected one by one. For example, sort the images to be inspected according to the size or importance of the images to be inspected, and then perform signature checks on the images to be inspected in sequence. For example, sort multiple images to be inspected according to their importance. Specifically, the multiple images can be sorted in descending order of importance, and then signature checks are performed on the multiple images to be inspected in sequence. If the signature check of a certain image among the images to be inspected fails, it indicates that the security and integrity of the image are in doubt. The image may have been tampered with, or the source of the image is suspicious. Therefore, the image cannot be started. At the same time, for security reasons, it is also necessary to compose an alarm message including the message that the startup of the image fails and the message that the image may have been tampered with and send it to the application related to the image so that relevant personnel can handle the situation in a timely manner. If the signature check of a certain image among the images to be inspected passes, the image is started. During the inspection process, the user can view the detailed situation of the current inspection at any time and specify the sorting dimension or the images to be inspected.

[0097] It should be understood that the examples of the first inspection policy in the above embodiments are exemplary, to help those skilled in the art understand the technical solutions of the present disclosure, and are not intended to limit the protection scope of the present disclosure. The first inspection policy can be set according to actual needs.

[0098] Figure 5 The flowchart of another mirror security inspection method provided by an embodiment of the present disclosure is schematically shown.

[0099] As Figure 5 shown, in this embodiment, the preset condition is to reach a preset time period, and this method includes operations S510 to S550. Among them, operations S510 - S530 are implemented in the same way as operations S210, operation S220, and operation S330 respectively, and the repeated parts will not be elaborated in detail.

[0100] In operation S510, a key pair is created, the private key in the above key pair is stored in the image building pipeline, and the public key in the above key pair is saved in the Kubernetes cluster.

[0101] In operation S520, for each built image, the above image is signed using the above private key.

[0102] In operation S530, a first inspection policy is created and saved in the above Kubernetes cluster in the form of Kubernetes Configmap. The above first inspection policy includes: sorting the images to be inspected according to a preset dimension, and performing signature inspection on the images to be inspected in sequence; or randomly performing signature inspection on the images to be inspected one by one.

[0103] In operation S540, when the preset time period is reached, the images to be inspected are determined, and the above Kubernetes cluster calls the above first inspection policy and uses the above public key to perform signature inspection on the images to be inspected according to the above first inspection policy.

[0104] In operation S550, when any one of the images to be inspected fails the signature inspection, an alarm message is sent to the application related to the above image.

[0105] In this embodiment, to ensure the security and integrity of each image, not only the launched image needs to be checked for signatures, but also the images in the Kubernetes cluster need to be regularly checked for signatures, so as to timely detect abnormal situations of those images with low startup frequencies. For example, when the preset condition is to reach a preset time period, after determining the image to be checked, the Kubernetes cluster calls the first check policy and uses the public key to check the signature of the image to be checked according to the called first check policy. The image to be checked can be determined in various ways. For example, a preset number of images that meet the first preset condition can be randomly selected from the above-mentioned Kubernetes cluster. For example, 10 images that have been launched less than 1 time within 7 days are randomly selected from the Kubernetes cluster. Or, a preset number of images are randomly selected from the above-mentioned Kubernetes cluster. For example, 10 images are randomly selected from the Kubernetes cluster. Or, all the images in the above-mentioned Kubernetes cluster are sorted according to any dimension, and a preset number of images are sequentially selected. For example, all the images in the Kubernetes cluster are sorted according to the generation time, and 5 images are sequentially selected. For example, if there are 20 images in the Kubernetes cluster, the 5th to 10th images can be selected. Of course, the image to be checked here can also be all the images in the Kubernetes cluster. When periodically checking the signatures of the images in the Kubernetes cluster, if an image passes the check, the remaining images to be checked are continuously checked until all the images to be checked are checked. If an image fails the check, it proves that the image is at risk, such as being tampered with, and further checks need to be carried out on the image to determine the specific situation. Therefore, it is necessary to send alarm information such as the check result to the application related to the image so that relevant personnel can process it, and then continue to check the remaining images to be checked.

[0106] In an embodiment of the present disclosure, if the above preset condition is to reach a preset time period, then when the preset time period is reached, it is judged whether the number of times the preset time period has been reached historically is zero; if the number of times the preset time period has been reached historically is zero, then all the images in the above-mentioned Kubernetes cluster are sorted and numbered according to any dimension, and a preset number of images are continuously selected starting from the first image after sorting, and the above-mentioned first check policy is called and the signature of the selected image is checked according to the above-mentioned first check policy using the above-mentioned public key; if the number of times the preset time period has been reached historically is greater than zero, then the dimension for sorting all the images in the above-mentioned Kubernetes cluster, the number of images to be checked, and the number of the last image to be checked when the preset time period was reached last time are obtained, and the images to be checked are determined according to the above dimension, the above number, and the above number.

[0107] In one embodiment of the present disclosure, determining the mirror images to be inspected according to dimensions, quantities, and numbers specifically includes: sorting and numbering all the mirror images in the above-mentioned Kubernetes cluster according to the above-mentioned dimensions, continuously extracting the above-mentioned quantity of mirror images starting from the next mirror image of the above-mentioned number, calling the above-mentioned first inspection policy, and using the above-mentioned public key to perform signature inspection on the extracted mirror images according to the above-mentioned first inspection policy; if after the last mirror image in the above-mentioned Kubernetes cluster is extracted, the number of the extracted mirror images still does not reach the above-mentioned quantity, then determine whether to change the dimension for sorting all the mirror images in the above-mentioned Kubernetes cluster; if changing the dimension for sorting all the mirror images in the above-mentioned Kubernetes cluster, then sort and number all the mirror images in the above-mentioned Kubernetes cluster according to the changed dimension, and continue to execute the step of continuously extracting the preset quantity of mirror images starting from the first mirror image after sorting, calling the above-mentioned first inspection policy, and using the above-mentioned public key to perform signature inspection on the extracted mirror images according to the above-mentioned first inspection policy; if not changing the dimension for sorting all the mirror images in the above-mentioned Kubernetes cluster, then continue to continuously extract starting from the first mirror image sorted according to the above-mentioned dimension until the number of the extracted mirror images reaches the above-mentioned quantity and then stop extracting, and call the above-mentioned first inspection policy and use the above-mentioned public key to perform signature inspection on the above-mentioned extracted mirror images according to the above-mentioned first inspection policy.

[0108] Combining the above two embodiments, when the preset condition is to reach a preset time period, it can also be set to cyclic inspection. Before the inspection, it is necessary to determine whether this inspection is the first inspection. If so, all the images in the Kubernetes cluster are sorted and numbered according to a certain dimension, the number of images to be inspected this time is determined, and then the above-mentioned number of images are extracted in order from the first image for signature inspection. After all the images have been inspected, one can choose to change the sorting dimension or not. If the sorting dimension is changed, after sorting according to the changed dimension, continue to execute the above step of extracting a certain number of images from the first one for signature inspection. If the sorting dimension is not changed, one can continue to extract images from the beginning for signature inspection until the number of extracted images meets the requirements. If it is not the first inspection, signature inspection is performed according to the dimension, quantity, and the number of the last inspected image in the previous inspection. If all the images in the Kubernetes cluster were just inspected in the previous inspection, one can also choose a new dimension for signature inspection this time. For example, assume there are 31 images in the Kubernetes cluster. Sort these 31 images according to the generation time (either from far to near or from near to far, which can be selected according to actual needs). If it is determined to inspect 5 images in this Kubernetes cluster this time, then in the first inspection, inspect from the 1st image to the 5th image. In the second inspection, inspect from the (5 + 1)th image to the (5 + 5)th image, and so on. When the 7th inspection is performed, start inspecting from the 31st image. After the 31st image has been inspected, all the images in this Kubernetes cluster have been inspected. At this time, one can choose whether to sort these 31 images according to other dimensions. If the dimension is changed to another one, after sorting according to the changed dimension, continue to execute the above step of extracting a certain number of images from the first one for signature inspection. If the sorting dimension is not changed, after the 31st image has been inspected, loop back to the 1st image and continue the inspection until a total of 5 images have been inspected in this inspection and then end the inspection. Specifically, regarding what dimension to sort all the images in the Kubernetes cluster, the user can preset a dimension list in advance. During the inspection, just call this dimension list and arbitrarily select a sorting dimension from it, or select the dimensions in the dimension list in order to sort all the images in the Kubernetes cluster. One can also use instructions to let the Kubernetes cluster automatically select the sorting dimension and automatically select whether to change the dimension. If new images are added to the Kubernetes cluster before reaching the preset time period, one can re-sort the used images and then perform signature inspection, or append the newly added images to the end of the sorted images for signature inspection. The specific method can be set according to actual needs. During the inspection process, the user can view the detailed situation of the current inspection at any time and specify the sorting dimension or the images to be inspected.

[0109] It should be understood that the examples of the method for determining the mirror to be inspected in this embodiment are exemplary, to help those skilled in the art understand the technical solution of the present disclosure, and are not intended to limit the protection scope of the present disclosure. The method for determining the mirror to be inspected can be set according to actual needs.

[0110] Based on the above mirror security inspection method, the present disclosure also provides a mirror security inspection device. The following will be combined with Figures 6 - 8 to describe this device in detail.

[0111] Figure 6 The structural block diagram of a mirror security inspection device provided by an embodiment of the present disclosure is schematically shown.

[0112] As Figure 6 shown, in an embodiment of the present disclosure, the device 600 includes: a first creation module 610, a first signature module 620, and a first inspection module 630.

[0113] The first creation module 610 is used to create a key pair, store the private key in the key pair in the mirror building pipeline, and save the public key in the key pair in the Kubernetes cluster. In one embodiment, the first creation module 610 can be used to perform the operation S210 described above, which will not be elaborated here.

[0114] The first signature module 620 is used to sign each built mirror with the above private key. In one embodiment, the first signature module 620 can be used to perform the operation S220 described above, which will not be elaborated here.

[0115] The first inspection module 630 is used to determine the mirror to be inspected according to the above preset conditions when the preset conditions are met, and perform a signature inspection on the mirror to be inspected with the public key saved in the Kubernetes cluster. In one embodiment, the first inspection module 630 can be used to perform the operation S230 described above, which will not be elaborated here.

[0116] Figure 7 The structural block diagram of another mirror security inspection device provided by an embodiment of the present disclosure is schematically shown.

[0117] As Figure 7 shown, in this embodiment, the preset condition is that at least one mirror is started. The device 700 includes: a second creation module 710, a second signature module 720, a third creation module 730, a second inspection module 740, a first warning module 750, and a start module 760.

[0118] Among them, the second creation module 710 and the second signature module 720 respectively have functions corresponding to, similar to, or the same as those of the first creation module 610 and the first signature module 620. The repeated parts will not be elaborated here.

[0119] A third creation module 730, configured to create a first inspection policy and save the first inspection policy in the Kubernetes cluster in the form of a Kubernetes Configmap. The first inspection policy includes: sorting the images to be inspected according to a preset dimension and performing signature inspection on the images to be inspected in sequence; or randomly and one by one performing signature inspection on the images to be inspected. In one embodiment, the third creation module 730 may be used to perform the operation S430 described above, which will not be elaborated here.

[0120] A second inspection module 740, configured to trigger the Validating Webhook mechanism of the Kubernetes cluster when at least one image is started and the image to be inspected is the at least one image, so that the Kubernetes cluster calls the first inspection policy and uses the public key to perform signature inspection on at least one of the images according to the first inspection policy. In one embodiment, the second inspection module 740 may be used to perform the operation S440 described above, which will not be elaborated here.

[0121] A first warning module 750, configured to, if the signature inspection of any one of the images to be inspected fails, then the startup of the image fails, and send a warning message to the application related to the image. In one embodiment, the first warning module 750 may be used to perform the operation S450 described above, which will not be elaborated here.

[0122] A startup module 760, configured to start the image if the signature inspection of any one of the images to be inspected passes. In one embodiment, the startup module 760 may be used to perform the operation S460 described above, which will not be elaborated here.

[0123] Figure 8 Schematically shows a structural block diagram of another image security inspection device provided by an embodiment of the present disclosure.

[0124] As Figure 8 shown, in this embodiment, the preset condition is to reach a preset time period. The device 800 includes: a fourth creation module 810, a third signature module 820, a fifth creation module 830, a third inspection module 840, and a second warning module 850.

[0125] Among them, the fourth creation module 810, the third signature module 820, and the fifth creation module 830 respectively have functions corresponding to, similar to, or the same as those of the first creation module 610, the first signature module 620, and the third creation module 730, and the repeated parts will not be elaborated here.

[0126] The third inspection module 840 is configured to determine a mirror to be inspected when a preset time period is reached, and the Kubernetes cluster invokes the first inspection policy and uses the public key to perform a signature inspection on the mirror to be inspected according to the first inspection policy. In one embodiment, the third inspection module 840 can be used to perform the operation S540 described above, which will not be elaborated here.

[0127] The second alarm module 850 is configured to send an alarm message to an application related to the mirror when the signature inspection of any mirror in the mirror to be inspected fails. In one embodiment, the second alarm module 850 can be used to perform the operation S550 described above, which will not be elaborated here.

[0128] It should be noted that the implementation manners, the technical problems solved, the functions achieved, and the technical effects achieved by each module / unit / sub-unit, etc. in some embodiments of the apparatus are respectively the same as or similar to those of the corresponding steps in some embodiments of the method, which will not be elaborated here.

[0129] Any combination of multiple, or at least part of the functions of any of the modules, sub-modules, units, and sub-units according to the embodiments of the present disclosure can be implemented in one module. Any one or more of the modules, sub-modules, units, and sub-units according to the embodiments of the present disclosure can be split into multiple modules for implementation. Any one or more of the modules, sub-modules, units, and sub-units according to the embodiments of the present disclosure can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or can be implemented by any other reasonable way of integrating or packaging the circuit in hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, one or more of the modules, sub-modules, units, and sub-units according to the embodiments of the present disclosure can be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding function can be executed.

[0130] For example, any combination of the first creation module 610, the first signature module 620, and the first verification module 630 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the first creation module 610, the first signature module 620, and the first verification module 630 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging circuits, etc., implemented by hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, at least one of the first creation module 610, the first signature module 620, and the first verification module 630 may be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.

[0131] Figure 9 A block diagram of an electronic device suitable for implementing a mirror security check method according to an embodiment of the present disclosure is schematically shown.

[0132] As Figure 9 shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage section 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 901 may also include on-board memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0133] In the RAM 903, various programs and data required for the operation of the electronic device 900 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the programs may also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 may also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0134] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, and the input / output (I / O) interface 905 is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the I / O interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed so that a computer program read therefrom is installed into the storage portion 908 as needed.

[0135] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon, the program including a mirror security check method as described above. The computer-readable storage medium may be included in the device / apparatus described in the above embodiments; or it may exist separately and not be assembled into the device / apparatus. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.

[0136] According to an embodiment of the present disclosure, a computer-readable medium may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the above two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the above-described ROM 902 and / or RAM 903 and / or one or more memories other than ROM 902 and RAM 903.

[0137] Embodiments of the present disclosure also include a computer program product that includes a computer program containing program code for performing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to cause the computer system to implement the mirror security check method provided by the embodiments of the present disclosure.

[0138] When the computer program is executed by the processor 901, the above functions defined in the system / apparatus of the embodiments of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. may be implemented by computer program modules.

[0139] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium and downloaded and installed through the communication part 909, and / or installed from the removable medium 911. The program code included in the computer program may be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0140] In such an embodiment, the computer program may be downloaded and installed from the network through the communication part 909, and / or installed from the removable medium 911. When the computer program is executed by the processor 901, the above functions defined in the system of the embodiments of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. may be implemented by computer program modules.

[0141] According to embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. The programming languages include, but are not limited to, programming languages such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, by connecting through the Internet using an Internet service provider).

[0142] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0143] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.

[0144] The embodiments of the present disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the present disclosure has been shown and described with reference to specific exemplary embodiments thereof, those skilled in the art should understand that various changes in form and detail may be made therein without departing from the spirit and scope of the present disclosure as defined by the appended claims and their equivalents. Therefore, the scope of the present disclosure should not be limited to the above embodiments, but should be determined not only by the appended claims but also by the equivalents of the appended claims.

Claims

1. A mirror security check method, characterized in that, Including: Create a key pair, store the private key in the key pair in the image building pipeline, and save the public key in the key pair in the Kubernetes cluster; For each built image, sign the image using the private key; When a preset condition is met, determine the image to be inspected according to the preset condition, and perform a signature check on the image to be inspected using the public key saved in the Kubernetes cluster. The preset condition includes that at least one image is started and a preset time period is reached; Wherein, after signing the image using the private key, the method further includes: Create a first inspection policy and save the first inspection policy in the Kubernetes cluster in the form of a Kubernetes Configmap; The first inspection policy includes: sorting the images to be inspected according to a preset dimension, and performing a signature check on the images to be inspected in order. The preset dimension includes the size or importance of the images to be inspected; or Randomly perform a signature check on the images to be inspected one by one.

2. The image security inspection method according to claim 1, characterized in that If the preset condition is that at least one image is started, the image to be inspected is the at least one image; Then the performing a signature check on the image using the public key saved in the Kubernetes cluster includes: When the at least one image is started, trigger the Validating Webhook mechanism of the Kubernetes cluster, so that the Kubernetes cluster calls the first inspection policy and uses the public key to perform a signature check on the image to be inspected according to the first inspection policy; If the signature check of any image in the images to be inspected fails, the startup of the image fails, and an alarm message is sent to the application related to the image; If the signature check of any image in the images to be inspected passes, start the image.

3. The image security inspection method according to claim 1, characterized in that If the preset condition is that a preset time period is reached, the performing a signature check on the image using the public key saved in the Kubernetes cluster includes: The Kubernetes cluster calls the first inspection policy and uses the public key to perform a signature check on the image to be inspected according to the first inspection policy; When the signature check of any image in the images to be inspected fails, an alarm message is sent to the application related to the image.

4. The mirror security check method according to claim 3, characterized in that If the preset condition is that a preset time period is reached, the method for determining the image to be inspected includes: Randomly select a preset number of images from the Kubernetes cluster; or Randomly select a preset number of images that meet the first preset condition from the Kubernetes cluster; or Sort all the images in the Kubernetes cluster according to any dimension, and sequentially select a preset number of images.

5. The mirror security check method according to claim 1, wherein: If the preset condition is to reach a preset time period, then when the preset time period is reached, it is judged whether the number of times of reaching the preset time period in history is zero; If the number of times of reaching the preset time period in history is zero, then all the images in the Kubernetes cluster are sorted and numbered according to any dimension, a preset number of images are continuously extracted starting from the first image after sorting, and the first check policy is called and the public key is used to perform signature check on the extracted images according to the first check policy; If the number of times of reaching the preset time period in history is greater than zero, then when the preset time period was reached last time, the dimension for sorting all the images in the Kubernetes cluster, the number of images to be checked, and the number of the last image to be checked are obtained, and the images to be checked are determined according to the dimension, the number, and the number.

6. The mirror security check method according to claim 5, wherein The determining the images to be checked according to the dimension, the number, and the number specifically includes: All the images in the Kubernetes cluster are sorted and numbered according to the dimension, a number of images equal to the number are continuously extracted starting from the image next to the number, and the first check policy is called and the public key is used to perform signature check on the extracted images according to the first check policy; If after the last image in the Kubernetes cluster is extracted, the number of extracted images still does not reach the number, it is judged whether to change the dimension for sorting all the images in the Kubernetes cluster; If the dimension for sorting all the images in the Kubernetes cluster is changed, then all the images in the Kubernetes cluster are sorted and numbered according to the changed dimension, and the step of continuously extracting a preset number of images starting from the first image after sorting, calling the first check policy and using the public key to perform signature check on the extracted images according to the first check policy is continued; If the dimension for sorting all the images in the Kubernetes cluster is not changed, then continuous extraction is continued starting from the first image after sorting according to the dimension until the number of extracted images reaches the number, and then the first check policy is called and the public key is used to perform signature check on the extracted images according to the first check policy.

7. A mirror image security inspection device, characterized in that, Including: A creation module, configured to create a key pair, store the private key in the key pair in the image building pipeline, and save the public key in the key pair in the Kubernetes cluster; A signature module, configured to sign each built image by using the private key; An inspection module, configured to, when a preset condition is satisfied, determine the images to be inspected according to the preset condition, and perform signature inspection on the images to be inspected by using the public key saved in the Kubernetes cluster, where the preset condition includes that at least one image is started and a preset time period is reached; A third creation module, configured to create a first inspection policy and save the first inspection policy in the Kubernetes cluster in the form of a Kubernetes Configmap; The first inspection policy includes: sorting the images to be inspected according to a preset dimension, and performing signature inspection on the images to be inspected in sequence, where the preset dimension includes the size or importance level of the images to be inspected; or randomly performing signature inspection on the images to be inspected one by one.

8. An electronic device, characterized in that, The electronic device includes: one or more processors; a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the image security inspection method according to any one of claims 1 to 6.

9. A computer-readable storage medium, having stored thereon executable instructions which, when executed by a processor, cause the processor to execute the image security inspection method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program which, when executed by a processor, implements the image security inspection method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Trusted software authorization verification system and method for container platform

    CN110069921A

  • Container instance creation method and device, electronic device and storage medium

    CN111562970A