A Method and Device for Encrypting and Decrypting Container Images Based on Trusted Computing
By using TKMS and trusted certificate management services during container image encryption and decryption, generating and synchronizing public and private key pairs, creating and merging ciphertext images and data, the problem of incomplete automation of container image encryption and decryption and insufficient key security is solved, and the high security and automation level of the image running environment is achieved.
Patent Information
- Application Number
- CN202211462227.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-22
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-11-22
AI Technical Summary
In the prior art, the container image encryption and decryption process is not fully automated, the key security is insufficient, and the security and trustworthiness of the image operation environment is difficult to ensure, especially in the cloud environment, trustworthy computing technology cannot be effectively utilized.
Generate public and private key pairs through TKMS, apply for ciphertext public key certificates from the trusted certificate management service, and synchronize the private key data to other trusted nodes, create ciphertext mirroring and ciphertext data, perform data merging and encryption and decryption, and ensure the security of the key and the trustworthiness of the mirror operation environment.
It improves the security of the key during the container image encryption and decryption process, ensures the security and trustworthiness of the mirror operation environment, and improves the overall security and efficiency through highly automated mirror construction and operation processes.
Smart Images

Figure CN115733698B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to a method and device for encrypting and decrypting container images based on trusted computing. Background Art
[0002] With the gradual development of cloud computing and the wide application of open-source technologies such as Kubernetes and OpenShift, more and more applications adopt containerized deployment. Containers abstract the operating system, and only contain application programs and necessary dependent resources inside the containers, which can isolate different software and hardware systems and have very good portability. However, this has introduced the problem of container data security. In actual applications, containers may carry sensitive information, and the portable and shared characteristics of containers may leak sensitive data.
[0003] Container encryption technology is one of the widely used technical means to solve container security, but there are still problems such as the incomplete automation of the construction of encrypted images and the decryption and operation, the key security problem in the encryption and decryption process, and the security and trust problem of the mirror running environment.
[0004] Trusted computing, based on a trusted computing platform supported by a hardware security module, can provide the capabilities of static measurement, identity authentication, key management, and key operation. Based on these capabilities, the overall security of the system can be improved, the security problem of the mirror encryption and decryption key can be solved, and the security and trust of the container running environment can be guaranteed. However, currently, trusted computing technology has not been combined with container image encryption and decryption technology, and the security technology advantages of trusted computing have not been exerted in the cloud environment.
[0005] Therefore, how to provide a technology that integrates container encryption and decryption technology with trusted computing technology and highly automates the mirror construction process and the mirror running process has become an urgent technical problem to be solved. Summary of the Invention
[0006] In view of this, in order to overcome the deficiencies of the prior art, the present invention provides a method and device for encrypting and decrypting container images based on trusted computing.
[0007] On the one hand, the present invention provides a method for encrypting and decrypting container images based on trusted computing, including:
[0008] Step S1: Generate a public-private key pair through TKMS, apply for a ciphertext public key certificate from a trusted certificate management service, and synchronously transmit the private key data to other trusted nodes managed by TKMS;
[0009] Step S2: Create a ciphertext image and ciphertext data, merge the created ciphertext image and ciphertext data, obtain a ciphertext image file, and upload it to a ciphertext image repository;
[0010] Step S3: Download the ciphertext image file from the ciphertext image repository to the trusted node, and decrypt the downloaded ciphertext image file.
[0011] Further, in the container image encryption and decryption method based on trusted computing of the present invention, step S1 includes:
[0012] Step S11: Deploy TKMS and TCAS on the physical node with a trusted chip in the cloud environment cluster;
[0013] Step S12: Select the managed trusted nodes through TKMS, create a public-private key pair on the trusted nodes, and export the public key data;
[0014] Step S13: Apply for a ciphertext public key certificate from TCAS using the public key data exported from TKMS;
[0015] Step S14: Synchronize the private key data in the created public-private key pair to other managed trusted nodes through TKMS.
[0016] Further, in the container image encryption and decryption method based on trusted computing of the present invention, the public-private key pair in step S12 is created based on the national cryptography algorithm SM2.
[0017] Further, in the container image encryption and decryption method based on trusted computing of the present invention, step S2 includes:
[0018] Step S21: Import the root certificate of TCAS and the obtained ciphertext public key certificate into the software for automatically building container images to generate a ciphertext symmetric key;
[0019] Step S22: Verify the legitimacy of the ciphertext public key certificate using the root certificate of TCAS;
[0020] Step S23: Encrypt the image content using the ciphertext symmetric key to obtain a ciphertext image;
[0021] Step S24: Encrypt the ciphertext symmetric key using the digital envelope encryption method based on the ciphertext public key certificate that has passed the legitimacy verification to obtain ciphertext data;
[0022] Step S25: Merge the ciphertext image and the ciphertext data to obtain a ciphertext image file, and upload the obtained ciphertext image file to the ciphertext image repository.
[0023] Further, in the container image encryption and decryption method based on trusted computing of the present invention, in step S23, encrypting the image content using the ciphertext symmetric key includes: encrypting the image content using the ciphertext symmetric key according to the encryption algorithm SM4.
[0024] Further, in the container image encryption and decryption method based on trusted computing of the present invention, step S3 includes:
[0025] Step S31: Download the encrypted image file in the encrypted image repository to the trusted node to be run;
[0026] Step S32: Use the root certificate of TCAS to verify the legality of the encrypted public key certificate carried in the encrypted image file;
[0027] Step S33: Decrypt the encrypted symmetric key using the private key data stored in the trusted node to obtain the plaintext symmetric key;
[0028] Step S34: Decrypt the encrypted image file using the plaintext symmetric key to obtain the running container.
[0029] On the other hand, the present invention provides a container image encryption and decryption device based on trusted computing, and the device includes:
[0030] An application module, configured to generate a public-private key pair through TKMS, apply for an encrypted public key certificate from a trusted certificate management service, and synchronously transmit the private key data to other trusted nodes that have been managed by TKMS;
[0031] An image encryption module, configured to create an encrypted image and encrypted data, merge the created encrypted image and encrypted data, obtain an encrypted image file, and upload it to the encrypted image repository;
[0032] An image decryption module, configured to download the encrypted image file from the encrypted image repository to a trusted node and decrypt the downloaded encrypted image file.
[0033] Further, in the container image encryption and decryption device based on trusted computing of the present invention, the application module is specifically configured to: deploy TKMS and TCAS on a physical node with a trusted chip in a cloud environment cluster; select a trusted node that has been managed through TKMS, create a public-private key pair on the trusted node, and export the public key data; apply for an encrypted public key certificate from TCAS using the public key data exported from TKMS; synchronize the private key data in the created public-private key pair to other trusted nodes that have been managed through TKMS.
[0034] Further, in the container image encryption and decryption device based on trusted computing of the present invention, the image encryption module is specifically configured to: import the root certificate of TCAS and the obtained ciphertext public key certificate into the software for automatically building a container image to generate a ciphertext symmetric key; verify the legitimacy of the ciphertext public key certificate by using the root certificate of TCAS; encrypt the image content by using the ciphertext symmetric key to obtain a ciphertext image; encrypt the ciphertext symmetric key by using the digital envelope encryption method based on the ciphertext public key certificate that passes the legitimacy verification to obtain ciphertext data; perform data merging on the ciphertext image and the ciphertext data to obtain a ciphertext image file, and upload the obtained ciphertext image file to the ciphertext image repository.
[0035] Further, the container image encryption and decryption device based on trusted computing of the present invention is characterized in that the image decryption module is specifically configured to: download the ciphertext image file in the ciphertext image repository to the trusted node to be run; verify the legitimacy of the ciphertext public key certificate carried in the ciphertext image file by using the root certificate of TCAS; decrypt the ciphertext symmetric key by using the private key data stored in the trusted node to obtain a plaintext symmetric key; decrypt the ciphertext image file by using the plaintext symmetric key to obtain a running container.
[0036] The container image encryption and decryption method and device based on trusted computing of the present invention improve the security of the key during the encryption and decryption processes of the container image, ensure the security and trustworthiness of the image running environment, and improve the automation degree of image building and image running. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings according to these drawings without creative efforts.
[0038] Figure 1 It is a flowchart of a container image encryption and decryption method based on trusted computing according to an exemplary first embodiment of the present invention.
[0039] Figure 2 It is a flowchart of a container image encryption and decryption method based on trusted computing according to an exemplary second embodiment of the present invention.
[0040] Figure 3 It is a flowchart of a container image encryption and decryption method based on trusted computing according to an exemplary third embodiment of the present invention.
[0041] Figure 4 It is a flowchart of a container image encryption and decryption method based on trusted computing according to an exemplary fourth embodiment of the present invention.
[0042] Figure 5 This is the architecture diagram of a container image encryption and decryption device based on trusted computing for the exemplary fifth embodiment of the present invention. Detailed implementation manners
[0043] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0044] It should be noted that, without conflict, the following embodiments and the features in the embodiments may be combined with each other; and, based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present disclosure.
[0045] It should be noted that the following describes various aspects of embodiments within the scope of the appended claims. It should be apparent that the aspects described herein may be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein may be implemented independently of any other aspect, and two or more of these aspects may be combined in various ways. For example, any number of aspects described herein may be used to implement a device and / or practice a method. Additionally, this device and / or this method may be implemented using other structures and / or functionality in addition to one or more of the aspects described herein.
[0046] The following are the explanations of the terms involved in each of the following embodiments:
[0047] TKMS: The full name is Trust Key Manager Service, a trusted key management system that manages terminal devices with trusted modules mounted in the cloud environment, used to integrate the identity authentication, key management, and key operations of trusted terminal devices, realize the private key synchronization and rotation among the managed devices, provide unified identity authentication, password management, and password operation services externally, and be used for the trusted identity authentication of devices in the cloud environment, the signature and verification of images, the encryption and decryption operations of images, and the key management in the cloud environment.
[0048] TCAS: The full name is Trust Certification Authority Service, a trusted certificate management service. TCAS provides certificate management services that comply with the Public Key Infrastructure standard (PKI) based on trusted computing modules, and provides functions such as certificate issuance, certificate verification, certificate revocation, and automatic rotation of certificates, and is used for the issuance, verification, and automatic rotation of image encryption public key certificates in the cloud environment.
[0049] National cryptographic algorithm SM2: A public key algorithm announced by the State Cryptography Administration, an asymmetric encryption algorithm based on elliptic curves.
[0050] Encryption algorithm SM4: a symmetric encryption algorithm announced by the State Cryptography Administration.
[0051] Figure 1 As shown in the flowchart of a method for encrypting and decrypting container images based on trusted computing according to an exemplary first embodiment of the present invention, Figure 1 As shown, the method of this embodiment includes:
[0052] Step S1: Generate a public-private key pair through TKMS, apply for a ciphertext public key certificate from the trusted certificate management service, and synchronously transmit the private key data to other trusted nodes managed by TKMS.
[0053] Step S2: Create a ciphertext image and ciphertext data, merge the created ciphertext image and ciphertext data, obtain a ciphertext image file, and upload it to the ciphertext image repository.
[0054] Step S3: Download the ciphertext image file from the ciphertext image repository to a trusted node and decrypt the downloaded ciphertext image file.
[0055] Figure 2 As shown in the flowchart of a method for encrypting and decrypting container images based on trusted computing according to an exemplary second embodiment of the present invention, this embodiment is Figure 1 A preferred embodiment of the method shown, as Figure 2 As shown, step S1 of the method of this embodiment includes:
[0056] Step S11: Deploy TKMS and TCAS on physical nodes with trusted chips in the cloud environment cluster.
[0057] Step S12: Select a managed trusted node through TKMS, create a public-private key pair on the trusted node, and export the public key data.
[0058] Step S13: Apply for a ciphertext public key certificate from TCAS using the public key data exported from TKMS.
[0059] Step S14: Synchronize the private key data in the created public-private key pair to other trusted nodes managed by TKMS through TKMS.
[0060] In practical applications, the public-private key pair in step S12 of the method of this embodiment is created based on the national cryptography algorithm SM2.
[0061] Figure 3 As shown in the flowchart of a method for encrypting and decrypting container images based on trusted computing according to an exemplary third embodiment of the present invention, this embodiment is Figure 1 A preferred embodiment of the method shown, as Figure 3 As shown, step S2 of the method of this embodiment includes:
[0062] Step S21: Import the root certificate of TCAS and the obtained ciphertext public key certificate into the software of the automated build container image to generate a ciphertext symmetric key;
[0063] Step S22: Verify the legitimacy of the ciphertext public key certificate using the root certificate of TCAS;
[0064] Step S23: Encrypt the image content using the ciphertext symmetric key to obtain a ciphertext image;
[0065] Step S24: Encrypt the ciphertext symmetric key using the digital envelope encryption method based on the ciphertext public key certificate that has passed the legitimacy verification to obtain ciphertext data;
[0066] Step S25: Merge the ciphertext image and the ciphertext data to obtain a ciphertext image file, and upload the obtained ciphertext image file to the ciphertext image repository.
[0067] In practical applications, in step S23 of the method of this embodiment, the image content is encrypted using the ciphertext symmetric key according to the encryption algorithm SM4.
[0068] Figure 4 As a flowchart of a method for encrypting and decrypting a container image based on trusted computing according to an exemplary fourth embodiment of the present invention, this embodiment is Figure 1 a preferred embodiment of the method shown, as Figure 4 shown, step S3 of the method of this embodiment includes:
[0069] Step S31: Download the ciphertext image file in the ciphertext image repository to the trusted node to be run;
[0070] Step S32: Verify the legitimacy of the ciphertext public key certificate carried in the ciphertext image file using the root certificate of TCAS;
[0071] Step S33: Decrypt the ciphertext symmetric key using the private key data stored in the trusted node to obtain a plaintext symmetric key;
[0072] Step S34: Decrypt the ciphertext image file using the plaintext symmetric key to obtain a running container.
[0073] Figure 5 As an architecture diagram of a device for encrypting and decrypting a container image based on trusted computing according to an exemplary fifth embodiment of the present invention, as Figure 5 shown, the device of this embodiment includes:
[0074] An application module, configured to generate a public-private key pair through TKMS, apply for a ciphertext public key certificate from the trusted certificate management service, and synchronously transmit the private key data to other trusted nodes that have been managed by TKMS;
[0075] The mirror encryption module is used to create ciphertext mirrors and ciphertext data, merge the created ciphertext mirrors and ciphertext data, obtain ciphertext mirror files and upload them to the ciphertext mirror repository;
[0076] The mirror decryption module is used to download the ciphertext mirror file from the ciphertext mirror repository to a trusted node and decrypt the downloaded ciphertext mirror file.
[0077] In practical applications, the application module of the device in this embodiment is specifically used for: deploying TKMS and TCAS on physical nodes with trusted chips in a cloud environment cluster; selecting the managed trusted nodes through TKMS, creating a public-private key pair on the trusted nodes, and exporting the public key data; applying for a ciphertext public key certificate from TCAS using the public key data exported from TKMS; synchronizing the private key data in the created public-private key pair to other managed trusted nodes through TKMS.
[0078] In practical applications, the mirror encryption module of the device in this embodiment is specifically used for: importing the root certificate of TCAS and the obtained ciphertext public key certificate into the software for automatically building container images to generate a ciphertext symmetric key; verifying the legality of the ciphertext public key certificate using the root certificate of TCAS; encrypting the mirror content using the ciphertext symmetric key to obtain a ciphertext mirror; encrypting the ciphertext symmetric key using the digital envelope encryption method based on the ciphertext public key certificate that has passed the legality verification to obtain ciphertext data; merging the ciphertext mirror and the ciphertext data to obtain a ciphertext mirror file, and uploading the obtained ciphertext mirror file to the ciphertext mirror repository.
[0079] In practical applications, the mirror decryption module of the device in this embodiment is specifically used for: downloading the ciphertext mirror file in the ciphertext mirror repository to the trusted node to be run; verifying the legality of the ciphertext public key certificate carried in the ciphertext mirror file using the root certificate of TCAS; decrypting the ciphertext symmetric key using the private key data stored in the trusted node to obtain a plaintext symmetric key; decrypting the ciphertext mirror file using the plaintext symmetric key to obtain a running container.
[0080] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A method for encrypting and decrypting container images based on trusted computing, characterized in that, the method includes: Step S1: Generate a public-private key pair through TKMS, apply for a ciphertext public key certificate from the trusted certificate management service, and synchronously transmit the private key data to other trusted nodes managed by TKMS; Step S2: Create a ciphertext image and ciphertext data, merge the created ciphertext image and ciphertext data, obtain a ciphertext image file and upload it to the ciphertext image repository; Step S3: Download the ciphertext image file from the ciphertext image repository to a trusted node, and decrypt the downloaded ciphertext image file; Step S2 includes: Step S21: Import the root certificate of TCAS and the obtained ciphertext public key certificate into the software for automatically building container images to generate a ciphertext symmetric key; Step S22: Verify the legality of the ciphertext public key certificate using the root certificate of TCAS; Step S23: Encrypt the image content using the ciphertext symmetric key to obtain a ciphertext image; Step S24: Encrypt the ciphertext symmetric key using the digital envelope encryption method based on the ciphertext public key certificate that has passed the legality verification to obtain ciphertext data; Step S25: Merge the ciphertext image and ciphertext data to obtain a ciphertext image file, and upload the obtained ciphertext image file to the ciphertext image repository.
2. The method for encrypting and decrypting container images based on trusted computing according to claim 1, characterized in that, Step S1 includes: Step S11: Deploy TKMS and TCAS on physical nodes with trusted chips in the cloud environment cluster; Step S12: Select a managed trusted node through TKMS, create a public-private key pair on the trusted node, and export the public key data; Step S13: Apply for a ciphertext public key certificate from TCAS using the public key data exported from TKMS; Step S14: Synchronize the private key data in the created public-private key pair to other trusted nodes managed by TKMS through TKMS.
3. The method for encrypting and decrypting container images based on trusted computing according to claim 2, characterized in that, The public-private key pair in Step S12 is created based on the national cryptography algorithm SM2.
4. The method for encrypting and decrypting container images based on trusted computing according to claim 1, characterized in that, In Step S23, encrypting the image content using the ciphertext symmetric key includes: encrypting the image content using the ciphertext symmetric key according to the encryption algorithm SM4.
5. The method for encrypting and decrypting container images based on trusted computing according to claim 1, characterized in that, Step S3 includes: Step S31: Download the ciphertext image file in the ciphertext image repository to the trusted node to be run; Step S32: Verify the legality of the ciphertext public key certificate carried in the ciphertext image file using the root certificate of TCAS; Step S33: Decrypt the ciphertext symmetric key using the private key data stored in the trusted node to obtain the ciphertext symmetric key; Step S34: Decrypt the ciphertext image file using the ciphertext symmetric key to obtain a running container.
6. A device for encrypting and decrypting container images based on trusted computing, characterized in that, the device includes: An application module, which is used to generate a public-private key pair through TKMS, apply for a ciphertext public key certificate from a trusted certificate management service, and synchronously transmit the private key data to other trusted nodes that have been managed by TKMS; A mirror encryption module, which is used to create a ciphertext mirror and ciphertext data, merge the created ciphertext mirror and ciphertext data, obtain a ciphertext mirror file, and upload it to a ciphertext mirror repository; A mirror decryption module, which is used to download a ciphertext mirror file from a ciphertext mirror repository to a trusted node and decrypt the downloaded ciphertext mirror file; The mirror encryption module is specifically used for: importing the root certificate of TCAS and the obtained ciphertext public key certificate into the software for automatically building a container image to generate a ciphertext symmetric key; verifying the legality of the ciphertext public key certificate by using the root certificate of TCAS; encrypting the mirror content by using the ciphertext symmetric key to obtain a ciphertext mirror; encrypting the ciphertext symmetric key by using the digital envelope encryption method based on the ciphertext public key certificate that has passed the legality verification to obtain ciphertext data; merging the ciphertext mirror and ciphertext data to obtain a ciphertext mirror file, and uploading the obtained ciphertext mirror file to a ciphertext mirror repository.
7. The container image encryption and decryption device based on trusted computing according to claim 6, wherein, The application module is specifically used for: deploying TKMS and TCAS on a physical node with a trusted chip in a cloud environment cluster; selecting a managed trusted node through TKMS, creating a public-private key pair on the trusted node, and exporting the public key data; applying for a ciphertext public key certificate from TCAS by using the public key data exported from TKMS; synchronously transmitting the private key data in the created public-private key pair to other trusted nodes that have been managed through TKMS.
8. The container image encryption and decryption device based on trusted computing according to claim 6, wherein, The mirror decryption module is specifically used for: downloading the ciphertext mirror file in the ciphertext mirror repository to a to-be-run trusted node; verifying the legality of the ciphertext public key certificate carried in the ciphertext mirror file by using the root certificate of TCAS; decrypting the ciphertext symmetric key by using the private key data stored in the trusted node to obtain the ciphertext symmetric key; decrypting the ciphertext mirror file by using the ciphertext symmetric key to obtain a running container.
Citation Information
Patent Citations
Network data secure transmission method
CN106506470A
Container instance creation method and device, electronic device and storage medium
CN111562970A