Method and device for guaranteeing safety of mirror image file supply chain and electronic equipment
The hashing algorithm and public key encryption technology generate tamper-proof check value, which solves the security problems during the transfer of mirror files and ensures the integrity and security of files.
Patent Information
- Application Number
- CN202510652004.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-07-11
AI Technical Summary
Mirror files lack tamper-proof mechanisms during transmission, resulting in files being eavesdropped or tampered with, and cannot guarantee security.
The hash algorithm is used to calculate the summary value of the mirror file, and a key digital envelope is generated through public key encryption, and a tamper-proof verification value is generated based on the certificate sequence number. It is encapsulated as a security information associated with the mirror file and transmitted through a secure protocol.
Ensure the integrity of mirror files during transmission and storage, reduce the risk of being tampered with, forged or used, and improve the security of the supply chain.
Smart Images

Figure CN120301607A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security. Specifically, it relates to a method for ensuring the security of the mirror file supply chain, a device for ensuring the security of the mirror file supply chain, and an electronic device. Background Art
[0002] During the transmission of mirror files, due to the lack of a transmission anti-tampering mechanism, the mirror file data may be eavesdropped or tampered with, resulting in the receiving party possibly obtaining a tampered mirror file, and the security of the mirror file during transmission cannot be guaranteed. Summary of the Invention
[0003] The main purpose of this application is to provide a method for ensuring the security of the mirror file supply chain, a device for ensuring the security of the mirror file supply chain, and an electronic device, so as to at least solve the problem of low security of the mirror file supply chain in the prior art.
[0004] To achieve the above objective, according to one aspect of this application, a method for ensuring the security of the mirror file supply chain is provided, including: calculating the mirror file using a hash algorithm to obtain a digest value of the mirror file, and parsing the mirror file to obtain a public key of the mirror file and a certificate serial number, where the certificate serial number is a unique identifier of the digital certificate of the mirror file; encrypting the generated symmetric key using the public key to obtain a key digital envelope, and encrypting the digest value of the mirror file using the symmetric key to obtain an anti-tampering check value; encapsulating a string composed of the anti-tampering check value, the key digital envelope, and the certificate serial number as security information associated with the mirror file, and sending the mirror file carrying the security information to the container cloud management platform in the production environment.
[0005] Optionally, before calculating the mirror file using a hash algorithm to obtain the digest value of the mirror file, the method further includes: sending a request file to the container cloud management platform in the production environment, where the request file is an application file for applying for a target application publisher certificate, and the target application publisher certificate is a digital certificate representing the identity of the publisher; receiving the target application publisher certificate sent by the container cloud management platform in the production environment; encapsulating at least the application program code and configuration file corresponding to the target application publisher certificate to obtain the mirror file.
[0006] Optionally, after at least encapsulating the application code and configuration file corresponding to the target application publisher certificate to obtain the image file, the method further includes: splitting the image file into at least two shards according to a preset file size, where each shard has a unique identifier; generating the security information for each shard; sending the shards carrying the security information to the container cloud management platform in the production environment, so that the container cloud management platform in the production environment assembles and calculates each shard according to the unique identifier of the shard to obtain the hash value of the recombined image file; when the hash value of the recombined image file is the same as the anti-tampering verification value corresponding to the image file, storing the recombined image file in the image repository under the container cloud management platform in the production environment; when the hash value of the recombined image file is different from the anti-tampering verification value corresponding to the image file, deleting the recombined image file under the container cloud management platform in the production environment.
[0007] Optionally, sending the image file carrying the security information to the container cloud management platform in the production environment includes: writing the security information as metadata of the image file into the image file, and signing the image file with the written metadata to obtain an image description file, where the signature is the signature of the creator of the image file; sending the image description file to the container cloud management platform in the production environment through the SSH protocol.
[0008] Optionally, encrypting the digest value of the image file using the symmetric key to obtain an anti-tampering verification value includes: splitting the digest value into at least two data blocks according to a predetermined data length, assigning a serial number identifier to each of the split data blocks, where the serial number identifier is used to determine the order of encryption operations for each data block; according to the serial number identifier, performing the encryption operation on the data blocks in sequence using the CBC mode of SM4, where the output after the encryption operation of each data block and the symmetric key are the input for the encryption operation of the next data block, and determining the output after the encryption operation of the last data block as the anti-tampering verification value.
[0009] Optionally, after sending the image description file to the container cloud management platform in the production environment via the SSH protocol, the method further includes: receiving the hash value of the image description file calculated by the container cloud management platform in the production environment; in the case where the hash value of the image description file is different from the anti-tampering verification value, deleting the image description file under the container cloud management platform in the production environment, and generating a prompt message indicating a failed transmission; in the case where the hash value of the image description file is the same as the anti-tampering verification value, storing the image description file in the image repository under the container cloud management platform in the production environment.
[0010] Optionally, before encrypting the generated symmetric key using the public key, the method further includes: establishing a communication channel with the container cloud management platform in the production environment through a security protocol, where the security protocol includes the TLS protocol; calculating a first temporary public key based on the algorithm of the DH protocol according to the generated temporary private key; sending the first temporary public key to the container cloud management platform in the production environment through the communication channel, and receiving a second temporary public key sent by the container cloud management platform in the production environment according to the first temporary public key; calculating the symmetric key according to the second temporary public key and the temporary private key using the algorithm of the DH protocol.
[0011] Optionally, before calculating the digest value of the image file using the hash algorithm, the method further includes: passing the image file into an API package so that the API package calculates the image file and generates security information.
[0012] According to another aspect of the present application, there is provided a device for ensuring the security of the image file supply chain, including: a calculation unit for calculating the digest value of the image file using a hash algorithm, and parsing the image file to obtain the public key of the image file and the certificate serial number, where the certificate serial number is the unique identifier of the digital certificate of the image file; an encryption unit for encrypting the generated symmetric key using the public key to obtain a key digital envelope, and encrypting the digest value of the image file using the symmetric key to obtain an anti-tampering verification value; a packaging unit for packaging the string composed of the anti-tampering verification value, the key digital envelope, and the certificate serial number into security information associated with the image file, and sending the image file carrying the security information to the container cloud management platform in the production environment.
[0013] According to another aspect of the present application, an electronic device is provided, including: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include those for executing any one of the methods.
[0014] Applying the technical solution of the present application, first, a hash algorithm is used to calculate the mirror file to obtain the digest value of the mirror file, and the mirror file is parsed to obtain the public key of the mirror file and the certificate serial number, where the certificate serial number is the unique identifier of the digital certificate of the mirror file; then, the generated symmetric key is encrypted using the public key to obtain a key digital envelope, and the digest value of the mirror file is encrypted using the symmetric key to obtain an anti-tampering check value; finally, the string composed of the anti-tampering check value, the key digital envelope, and the certificate serial number is encapsulated as security information associated with the mirror file, and the mirror file carrying the security information is sent to the container cloud management platform in the production environment. In the present application, by using a hash algorithm to calculate the mirror file to generate a unique digest value, any tampering with the mirror file will cause a change in the digest value, ensuring the integrity of the mirror file during transmission and storage; then, a randomly generated symmetric key is used to encrypt the digest value of the mirror file to generate an anti-tampering check value, and the symmetric key is encrypted using the public key parsed from the mirror file to form a key digital envelope, ensuring that even if the key is intercepted during transmission, the attacker cannot decrypt it to obtain the original symmetric key, reducing the risk of the mirror file being tampered with, forged, or misused in the supply chain, and improving the security of the supply chain. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The specification drawings forming a part of the present application are used to provide a further understanding of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0016] Figure 1 It shows a schematic flowchart of a method for ensuring the security of the mirror file supply chain according to an embodiment of the present application;
[0017] Figure 2 It shows a schematic flowchart of another method for ensuring the security of the mirror file supply chain according to an embodiment of the present application;
[0018] Figure 3 It shows a schematic flowchart of yet another method for ensuring the security of the mirror file supply chain according to an embodiment of the present application;
[0019] Figure 4 The structural block diagram of a device for ensuring the security of the mirror file supply chain provided according to an embodiment of the present application is shown. Detailed implementation manners
[0020] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.
[0021] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0022] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data may be interchanged under appropriate circumstances so as to describe the embodiments of the present application here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0023] As introduced in the background art, the security of the mirror file supply chain in the prior art is low. To solve the above technical problems, embodiments of the present application provide a method for ensuring the security of the mirror file supply chain, a device for ensuring the security of the mirror file supply chain, and an electronic device.
[0024] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention.
[0025] In this embodiment, a method for ensuring the security of the mirror file supply chain is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0026] Figure 1 is the flowchart of the method for ensuring the security of the mirror file supply chain according to the embodiment of the present application. As Figure 1As shown, the method includes the following steps:
[0027] Step S101: Calculate the mirror file using the hash algorithm to obtain the digest value of the mirror file, and parse the mirror file to obtain the public key and certificate serial number of the mirror file. The certificate serial number is the unique identifier of the digital certificate of the mirror file.
[0028] Step S102: Encrypt the generated symmetric key using the public key to obtain a key digital envelope, and perform an encryption operation on the digest value of the mirror file using the symmetric key to obtain an anti-tampering check value.
[0029] Step S103: Package the string composed of the anti-tampering check value, the key digital envelope, and the certificate serial number into security information associated with the mirror file, and send the mirror file carrying the security information to the container cloud management platform in the production environment.
[0030] Through the above embodiments, first, calculate the mirror file using the hash algorithm to obtain the digest value of the mirror file, and parse the mirror file to obtain the public key and certificate serial number of the mirror file. The certificate serial number is the unique identifier of the digital certificate of the mirror file. Then, encrypt the generated symmetric key using the public key to obtain a key digital envelope, and perform an encryption operation on the digest value of the mirror file using the symmetric key to obtain an anti-tampering check value. Finally, package the string composed of the anti-tampering check value, the key digital envelope, and the certificate serial number into security information associated with the mirror file, and send the mirror file carrying the security information to the container cloud management platform in the production environment. In this application, by calculating the mirror file using the hash algorithm to generate a unique digest value, any tampering with the mirror file will cause a change in the digest value, ensuring the integrity of the mirror file during transmission and storage. Then, a randomly generated symmetric key is used to encrypt the digest value of the mirror file to generate an anti-tampering check value, and the symmetric key is encrypted using the public key parsed from the mirror file to form a key digital envelope, ensuring that even if the key is intercepted during transmission, the attacker cannot decrypt it to obtain the original symmetric key, reducing the risk of the mirror file being tampered with, forged, or misused in the supply chain, and improving the security of the supply chain.
[0031] Specifically, select the SHA-256 hash algorithm to calculate the digest value of the mirror file. The mirror file supply chain includes the container cloud management platform in the test environment and the container cloud management platform in the production environment.
[0032] In an alternative solution, before calculating the digest value of the mirror file using the hash algorithm to obtain the digest value of the above mirror file, the above method further includes: sending a request file to the container cloud management platform in the above production environment, where the request file is an application file for applying for a target application publisher certificate, and the target application publisher certificate is a digital certificate representing the identity of the publisher; receiving the target application publisher certificate sent by the container cloud management platform in the above production environment; encapsulating at least the application code and configuration file corresponding to the target application publisher certificate to obtain the above mirror file.
[0033] In the above embodiment, the publisher needs to apply for a digital certificate, and relevant information such as identity proof and authorization documents needs to be provided during the application process to prove its legality and authorization. After passing the review, the digital certificate is issued. The certificate contains key information such as the public key of the publisher, the certificate serial number, the issuer information, the validity period, and the revocation status. By verifying the validity of the certificate, the legality and effectiveness of the certificate are ensured. During the mirror file construction process, by embedding the publisher's digital certificate into the mirror file, it is ensured that each mirror can be associated with a specific certificate number and issuance record. In the event of a supply chain security incident, such as the mirror file being tampered with or malicious components being implanted, the specific construction responsible person can be traced back through the certificate, improving the accuracy and efficiency of responsibility tracing and further enhancing the security of the mirror file supply chain.
[0034] Specifically, a request file for applying for a digital certificate is generated through a mirror construction tool, and the request file contains: identification information of the application publisher (such as organization name, email, purpose, etc.) and the corresponding public key.
[0035] In another alternative solution, after at least encapsulating the application code and configuration file corresponding to the target application publisher certificate to obtain the above mirror file, the above method further includes: splitting the above mirror file according to a preset file size to obtain at least two shards, each of the above shards having a unique identifier; generating the above security information for each of the above shards; sending the shards carrying the above security information to the container cloud management platform in the above production environment, so that the container cloud management platform in the above production environment assembles and calculates each of the above shards according to the unique identifier of the shard to obtain the hash value of the recombined mirror file; when the hash value of the above recombined mirror file is the same as the anti-tampering verification value corresponding to the above mirror file, storing the above recombined mirror file in the mirror repository under the container cloud management platform in the above production environment; when the hash value of the above recombined mirror file is different from the anti-tampering verification value corresponding to the above mirror file, deleting the above recombined mirror file under the container cloud management platform in the above production environment.
[0036] In the above embodiments, the complete mirror file is segmented according to a preset file size to obtain multiple shards, which can meet the transmission requirements in different network environments. Especially when the network bandwidth is limited or the transmission is unstable, the small shards are easier to be transmitted successfully. And when the transmission fails, only the failed shards need to be retransmitted instead of the entire mirror file. By configuring a unique identifier for each shard, the accuracy and traceability of the shards during the transmission and assembly processes are ensured. By sending the shards carrying security information to the container cloud management platform in the production environment through a secure transmission protocol, it is ensured that the shards are not tampered with or stolen during the transmission process. The container cloud management platform in the production environment assembles the shards according to the unique identifiers of the shards to restore the original mirror file structure, that is, to reconstruct the mirror file. Then, the same hash algorithm as that used when building the mirror file is used to calculate the hash value of the reconstructed mirror file to further verify whether the reconstructed mirror file is consistent with the original mirror file. If the hash value of the reconstructed mirror file is the same as the anti-tampering check value corresponding to the mirror file, it indicates that the reconstructed mirror file has not been tampered with during the transmission process and maintains the integrity of the original mirror file. At this time, the reconstructed mirror file is stored in the mirror repository under the container cloud management platform in the production environment for subsequent deployment and use. If the hash value of the reconstructed mirror file is different from the anti-tampering check value corresponding to the mirror file, it indicates that the reconstructed mirror file may have been tampered with or damaged during the transmission process. At this time, the container cloud management platform in the production environment will delete the reconstructed mirror file to prevent it from being wrongly stored in the mirror repository and used for subsequent deployment, further ensuring the security of the supply chain.
[0037] Specifically, to ensure that the shards can be transmitted to the container cloud management platform in the production environment safely and efficiently, a secure copy protocol or a secure file transfer protocol can be used for the transmission of the shards.
[0038] In some other exemplary embodiments, sending the above mirror file carrying the above security information to the container cloud management platform in the production environment includes: writing the above security information as metadata of the above mirror file into the above mirror file, and signing the above mirror file with the written metadata to obtain a mirror description file, where the signature is the signature of the creator of the above mirror file; sending the above mirror description file to the above container cloud management platform in the above production environment through the SSH protocol.
[0039] In the above embodiments, by writing security information as metadata into the image file, it is ensured that the image file itself contains key information such as its source and creation time. Throughout the entire life cycle of the image file (including transmission, storage, and use), this security information is always associated with the image file, and no additional files or databases are required to store and query this information. By signing the image file with the written metadata and using the private key of the image file creator for signing, an immutable digital fingerprint is provided for the image file, ensuring the integrity and source credibility of the image file, because any modification to the image file will result in a failed signature verification. By sending the image description file to the container cloud management platform in the production environment through the SSH protocol, the content of the image description file cannot be stolen or tampered with, and only authorized users can access and receive this file. The use of the SSH protocol provides a secure and reliable channel for the transmission of the image file, further enhancing the security of the supply chain.
[0040] Specifically, it is necessary to select an appropriate metadata format according to the format of the image file and the requirements of the container cloud management platform. Metadata formats include JSON, YAML, etc., which can store information in a structured manner, facilitating subsequent parsing and processing.
[0041] In another alternative solution, the above symmetric key is used to perform an encryption operation on the above digest value of the above image file to obtain a tamper-proof verification value, including: splitting the above digest value according to a predetermined data length to obtain at least two data blocks, assigning a serial number identifier to each of the split data blocks, and the above serial number identifier is used to determine the order of the above encryption operations for each of the above data blocks; according to the above serial number identifier, the above data blocks are sequentially subjected to the above encryption operation in the CBC mode of SM4, where the output after the above encryption operation for each of the above data blocks and the above symmetric key are the input for the next above data block to perform the above encryption operation, and the output after the above encryption operation for the last above data block is determined as the above tamper-proof verification value.
[0042] In the above embodiments, by splitting the digest value into multiple data blocks and using the symmetric key and the CBC mode of SM4 for encryption operations, a tamper-proof verification value is generated. Any tampering with the digest value will cause a change in the encryption operation result, thus making it impossible to generate a matching tamper-proof verification value. Therefore, this method effectively protects the integrity of the data and ensures that the digest value has not been tampered with during transmission or storage. Using the CBC mode of SM4 for encryption operations further enhances the security of the encryption. In the CBC mode (Cipher Block Chaining, a mode of operation for block encryption algorithms), the encryption result of each data block will be XORed with the plaintext of the next data block before encryption. This "chain" reaction makes the encryption result more dependent on the content of all data blocks, thus increasing the difficulty of cracking and further improving the security of the supply chain.
[0043] Specifically, the digest value is split according to a preset data length (for example, each 16 bytes is a block) to obtain multiple data blocks; if the length of the digest value is not divisible, the last data block is padded to make its length reach 16 bytes.
[0044] In some exemplary solutions of this application, after sending the above mirror description file to the above container cloud management platform in the above production environment through the SSH protocol, the above method further includes: receiving the hash value of the above mirror description file calculated by the above container cloud management platform in the above production environment; in the case where the above hash value of the above mirror description file is different from the above tamper-proof verification value, deleting the above mirror description file under the above container cloud management platform in the above production environment and generating a prompt message indicating a sending failure; in the case where the above hash value of the above mirror description file is the same as the above tamper-proof verification value, storing the above mirror description file in the mirror repository under the above container cloud management platform in the above production environment.
[0045] In the above embodiments, by receiving the hash value of the mirror description file calculated by the container cloud management platform in the production environment and comparing it with the previously generated tamper-proof verification value, it can be ensured that the mirror description file has not been tampered with during transmission. If the hash values do not match, it indicates that the file may have been modified or damaged, thus detecting problems in a timely manner. In the case where the hash values do not match, the mirror description file under the container cloud management platform in the production environment is automatically deleted, avoiding the incorrect storage of invalid or tampered files in the mirror repository, thereby maintaining the accuracy and reliability of the files in the mirror repository. By generating a prompt message indicating a sending failure, it helps the administrator to timely understand the problems that occur during the file transmission process and take corresponding measures for troubleshooting and repair, improving the efficiency of the supply.
[0046] In some other exemplary solutions of the present application, before encrypting the generated symmetric key with the above public key, the above method further includes: establishing a communication channel with the container cloud management platform of the above production environment through a security protocol, where the security protocol includes the TLS protocol (Transport Layer Security Protocol, a security protocol widely used in Internet communication); calculating a first temporary public key based on the generated temporary private key according to the algorithm of the DH protocol (Diffie-Hellman Protocol, an asymmetric key exchange protocol); sending the above first temporary public key to the container cloud management platform of the above production environment through the above communication channel, and receiving a second temporary public key sent by the container cloud management platform of the above production environment according to the above first temporary public key; calculating the above symmetric key according to the above second temporary public key and the above temporary private key using the algorithm of the above DH protocol.
[0047] In the above embodiment, by using the TLS protocol to establish a communication channel with the container cloud management platform of the production environment, it is ensured that the communication between the two parties is encrypted and only the two communication parties can decrypt it, effectively preventing man-in-the-middle attacks and eavesdropping. Through the key negotiation protocol, a temporary private key is first generated, and a corresponding first temporary public key is calculated based on the temporary private key and the algorithm of the DH protocol. The sender sends the first temporary public key to the container cloud management platform of the production environment through a secure communication channel and receives the second temporary public key from the container cloud management platform of the production environment. Without directly exchanging private keys, the two parties securely negotiate a shared key. The symmetric key is calculated using the algorithm of the DH protocol based on the received second temporary public key and the previously generated temporary private key. The key length used for symmetric key encryption is shorter, with higher efficiency.
[0048] In an alternative solution, before calculating the digest value of the above mirror file using a hash algorithm, the above method further includes: passing the above mirror file into an API software package (Application Programming Interface, an application program interface software package that encapsulates a group of related API functions, classes, and methods and provides them to developers or other software systems in a modular form) so that the above API software package calculates and generates security information for the above mirror file.
[0049] In the above embodiments, by uploading the mirror file to the API software package, only by calling the API interface and uploading the mirror file, a series of steps such as automatically calculating the hash value, generating the symmetric key, and encapsulating the digital envelope can be completed, reducing the need for manual intervention, improving the processing efficiency, and reducing the security risks caused by human errors. The API software package encapsulates the key logic uniformly, ensuring that the generated security information structures are consistent and the formats are unified when called in different test environments and by different developers, providing a reliable comparison basis for verification in the subsequent production environment and reducing the error risks brought by environmental differences.
[0050] In order to enable those skilled in the art to understand the technical solution of the present application more clearly, the implementation process of the method for ensuring the security of the mirror file supply chain of the present application will be described in detail below with reference to specific embodiments.
[0051] This embodiment relates to a specific method for ensuring the security of the mirror file supply chain. As Figure 2 shown, exemplarily, 1-Initiate construction: The container cloud management platform in the test environment initiates the construction operation of the container mirror file to generate a container mirror file construction pipeline; 2-Obtain security information: The test environment container cloud management platform uploads the mirror file to the secret management API software package, and the secret management API software package generates security information after calculation; 3-Generate the mirror file and attach security information: Use the defined mirror construction pipeline to generate the mirror file and attach security information; 4-Push the mirror: Push the generated container mirror file to the mirror repository in the test environment; 5-Pull the mirror: The test environment of the container cloud platform pulls the container mirror file from the test environment mirror repository and starts the container pod of the application program to run. The above container pod is a basic scheduling unit in the container orchestration system and is used to manage and run containerized application programs; 6-Export the mirror file and attach security information: Import the container mirror file that has passed the test in the test environment into the online management system with the security information attached; 7-Upload the mirror file and attach security information: The online management system uploads the mirror file with the security information attached to the container cloud management platform system in the production environment; 8-Security information verification: The container cloud management platform in the production environment uploads the mirror file and the security information to the key management system in the production environment for security information verification; 9-Push the mirror to the production mirror repository: The container cloud management platform in the production environment pushes the mirror file that has passed the security information verification to the mirror repository in the production environment; 10-Pull the mirror: The production operation environment of the container cloud platform pulls the container mirror file from the production environment mirror repository and starts the container pod of the application program to run.
[0052] Another embodiment for realizing the security of the container mirror file supply chain through cryptographic techniques, as Figure 3As shown, exemplarily: 1 - Offline certificate application: The container cloud management platform in the test environment applies for a container image file publisher certificate from the key management system in the production environment through an offline manual method; 2 - Offline certificate return: The key management system in the production environment receives the certificate request file sent through the offline manual method, and completes the signing of the container image file publisher certificate through the digital certificate subsystem of the key management system in the production environment; 3 - Generate image: The container cloud management platform in the test environment performs the construction operation of the container image file in the test environment; 4 - Send image file: The container cloud management platform in the test environment transfers the container image file in the test environment into the API software package of the key management system; 5 - Generate security information: After receiving the container image file, the key management API software package generates security information. The specific calculation process of the security information is as follows: a. Using a hash algorithm, perform a digest calculation on the container image file to obtain the digest value of the container image file; b. Perform a certificate parsing operation on the image file issuer certificate in step 2 to obtain the public key information and certificate serial number information in the certificate; c. Generate a symmetric key for the SM4 algorithm, and encrypt the symmetric key using the public key information to obtain a key digital envelope; d. Use the SM4 symmetric key to perform the generation calculation of the tamper-proof check value MAC in CBC mode for the digest value of the image file; e. Assemble the tamper-proof check value MAC, digital envelope, and certificate serial number into security information; 6 - Return security information: The key management API software package returns the generated security information to the container cloud management platform in the test environment; 7 - Import the image file and attached security information: The container cloud management platform in the test environment uploads and imports the container image file with attached security information into the container cloud management platform in the production environment through the upgrade management system; The container cloud management platform in the production environment receives the container image file and security information; 8 - Accept the image file and security information: 9 - Send the image file and security information: The container cloud management platform in the production environment sends the container image file with attached security information to the key management system production environment; 10 - Verify security information: After receiving the container image file, the key management system production environment verifies the security information. The specific calculation process of the security information verification is as follows: a. The key management system performs a certificate validity check (issuer, validity period, revocation list) on the user certificate to verify the identity of the container image file publisher; b. The key management system uses the private key information corresponding to the user certificate to perform a decryption operation on the digital envelope to obtain the SM4 symmetric key; c. Using a hash algorithm, perform a digest calculation on the container image file to obtain the digest value of the container image file; d. Use the SM4 symmetric key to perform the verification calculation of the tamper-proof check value MAC in CBC mode for the digest value of the image file; 11 - Return the verification result: The key management system production environment returns the verification result of the container image file security information to the container cloud management platform in the production environment.
[0053] A specific usage scenario of encryption operation using the CBC mode of the SM4 algorithm is provided. In the test environment, whenever a new application image file is built, the application image file is passed into the API software package. The API software package first calculates the digest value of the image file using a hashing algorithm, and then divides the digest value into multiple data blocks, with each data block assigned a serial number identifier. Using the assigned serial number identifier, the API software package encrypts each data block in sequence using the CBC mode of the SM4 algorithm. The first data block is encrypted using the initial vector and the symmetric key, and the encryption of each subsequent data block uses the encrypted output of the previous data block as part of the input. The encrypted output of the last data block is regarded as the final tamper-proof check value. This tamper-proof check value, together with the key digital envelope and the certificate serial number, is encapsulated as security information. The additional security information is attached to the image file and sent to the container cloud management platform in the production environment through the SSH protocol. On the container cloud management platform in the production environment, an integrity check is performed on the image description file, and only when the tamper-proof check value is verified to match correctly will the image file be officially stored in the image repository in the production environment. The use of the CBC mode increases the probability that it is difficult to detect after the image file has been tampered with because tampering with one data block will affect the tamper-proof check values of all subsequent data blocks, which makes any unauthorized modification detectable and improves the security level of the entire supply chain. The method of dividing data blocks allows the image file to be processed more flexibly, and the processing capacity of large-scale image files can be improved by adjusting the size of the data blocks to adapt to different computing resource limitations. While ensuring security, this method improves the speed of encryption and verification by processing different data blocks in parallel, especially when processing large image files, it can significantly reduce the waiting time and improve the deployment efficiency.
[0054] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0055] The embodiment of the present application also provides a device for ensuring the security of the image file supply chain. It should be noted that the device for ensuring the security of the image file supply chain in the embodiment of the present application can be used to execute the method for ensuring the security of the image file supply chain provided by the embodiment of the present application. The device for implementing the above embodiment and the preferred implementation manner has been described and will not be repeated here. As used hereinafter, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0056] The following introduces the device for ensuring the security of the mirror file supply chain provided by the embodiments of the present application.
[0057] Figure 4 It is a schematic diagram of the device for ensuring the security of the mirror file supply chain according to the embodiments of the present application. As Figure 4 shown, the device includes:
[0058] A computing unit 10, configured to calculate the mirror file by using a hash algorithm to obtain the digest value of the mirror file, and parse the mirror file to obtain the public key of the mirror file and the certificate serial number, where the certificate serial number is the unique identifier of the digital certificate of the mirror file;
[0059] An encryption unit 20, configured to encrypt the generated symmetric key by using the public key to obtain a key digital envelope, and perform an encryption operation on the digest value of the mirror file by using the symmetric key to obtain an anti-tampering check value;
[0060] A first encapsulation unit 30, configured to encapsulate the string composed of the anti-tampering check value, the key digital envelope, and the certificate serial number into security information associated with the mirror file, and send the mirror file carrying the security information to the container cloud management platform in the production environment.
[0061] Through the above embodiments, first, the computing unit calculates the mirror file by using a hash algorithm to obtain the digest value of the mirror file, and parses the mirror file to obtain the public key of the mirror file and the certificate serial number, where the certificate serial number is the unique identifier of the digital certificate of the mirror file; then, the encryption unit encrypts the generated symmetric key by using the public key to obtain a key digital envelope, and performs an encryption operation on the digest value of the mirror file by using the symmetric key to obtain an anti-tampering check value; finally, the first encapsulation unit encapsulates the string composed of the anti-tampering check value, the key digital envelope, and the certificate serial number into security information associated with the mirror file, and sends the mirror file carrying the security information to the container cloud management platform in the production environment. In the present application, by calculating the mirror file by using a hash algorithm to generate a unique digest value, any tampering with the mirror file will cause a change in the digest value, ensuring the integrity of the mirror file during transmission and storage; then, a randomly generated symmetric key is used to encrypt the digest value of the mirror file to generate an anti-tampering check value, and the symmetric key is encrypted by the public key parsed from the mirror file to form a key digital envelope, ensuring that even if the key is intercepted during transmission, the attacker cannot decrypt it to obtain the original symmetric key, reducing the risk of the mirror file being tampered with, forged, or misused in the supply chain, and improving the security of the supply chain.
[0062] Specifically, the SHA-256 hash algorithm is selected to calculate the digest value of the image file. The image file supply chain includes the container cloud management platform in the test environment and the container cloud management platform in the production environment.
[0063] In an alternative solution, the above device further includes: a first sending unit, configured to send a request file to the container cloud management platform in the production environment, where the request file is an application file for applying for a target application publisher certificate, and the target application publisher certificate is a digital certificate representing the identity of the publisher; a receiving unit, configured to receive the target application publisher certificate sent by the container cloud management platform in the production environment; a second encapsulation unit, configured to encapsulate at least the application code and configuration file corresponding to the target application publisher certificate to obtain the image file.
[0064] In the above embodiment, the publisher needs to apply for a digital certificate. During the application process, relevant information such as identity proof and authorization files needs to be provided to prove its legality and authorization. After passing the review, the digital certificate is issued. The certificate contains key information such as the public key of the publisher, the certificate serial number, the issuer information, the validity period, and the revocation status. By verifying the validity of the certificate, the legality and effectiveness of the certificate are ensured. During the image file construction process, by embedding the publisher's digital certificate into the image file, it is ensured that each image can be associated with a specific certificate number and issuance record. Once a supply chain security incident occurs, such as the image file being tampered with or malicious components being implanted, the specific construction responsible person can be traced back through the certificate, improving the accuracy and efficiency of responsibility tracing and further enhancing the security of the image file supply chain.
[0065] Specifically, a request file for applying for a digital certificate is generated through an image construction tool, and the request file contains: identification information of the application publisher (such as organization name, email, purpose, etc.) and the corresponding public key.
[0066] As an alternative, the above device further includes: a splitting unit, configured to split the above mirror file according to a preset file size to obtain at least two shards, each of the above shards having a unique identifier; a generating unit, configured to generate the above security information for each of the above shards; a second sending unit, configured to send the above shards carrying the above security information to the container cloud management platform of the above production environment, so that the container cloud management platform of the above production environment assembles and calculates each of the above shards according to the above unique identifier of the shard to obtain a hash value of the recombined mirror file; a storing unit, configured to store the recombined mirror file in the mirror repository under the container cloud management platform of the above production environment when the hash value of the recombined mirror file is the same as the anti-tampering verification value corresponding to the above mirror file; a deleting unit, configured to delete the above recombined mirror file under the container cloud management platform of the above production environment when the hash value of the recombined mirror file is different from the anti-tampering verification value corresponding to the above mirror file.
[0067] In the above embodiment, the complete mirror file is split according to a preset file size to obtain multiple shards, which can meet the transmission requirements in different network environments. Especially when the network bandwidth is limited or the transmission is unstable, small shards are more likely to be transmitted successfully. And when the transmission fails, only the failed shard needs to be retransmitted instead of the entire mirror file. By configuring a unique identifier for each shard, the accuracy and traceability of the shards during transmission and assembly are ensured. By sending the shards carrying security information to the container cloud management platform of the production environment through a secure transmission protocol, it is ensured that the shards are not tampered with or stolen during transmission. The container cloud management platform of the production environment assembles each shard according to the unique identifier of the shard to restore the original mirror file structure, that is, the recombined mirror file. Then, the same hash algorithm as when constructing the mirror file is used to calculate the recombined mirror file to obtain its hash value, further verifying whether the recombined mirror file is consistent with the original mirror file. If the hash value of the recombined mirror file is the same as the anti-tampering verification value corresponding to the mirror file, it indicates that the recombined mirror file has not been tampered with during transmission and maintains the integrity of the original mirror file. At this time, the recombined mirror file is stored in the mirror repository under the container cloud management platform of the production environment for subsequent deployment and use. If the hash value of the recombined mirror file is different from the anti-tampering verification value corresponding to the mirror file, it indicates that the recombined mirror file may have been tampered with or damaged during transmission. At this time, the container cloud management platform of the production environment will delete the recombined mirror file to prevent it from being wrongly stored in the mirror repository and used for subsequent deployment, further ensuring the security of the supply chain.
[0068] Specifically, to ensure that the shards can be transmitted to the container cloud management platform in the production environment safely and efficiently, a secure copy protocol or a secure file transfer protocol can be used for the transmission of the shards.
[0069] An optional solution is that the above first encapsulation unit includes: a writing module, configured to write the above security information as metadata of the above mirror file into the above mirror file, and sign the above mirror file with the written metadata to obtain a mirror description file, where the signature is the signature of the creator of the above mirror file; a first sending module, configured to send the above mirror description file to the above container cloud management platform in the above production environment through the SSH protocol.
[0070] In the above embodiment, by writing the security information as metadata into the mirror file, it is ensured that the mirror file itself contains key information such as its source and creation time. Throughout the entire life cycle of the mirror file (including transmission, storage, and use), this security information is always associated with the mirror file, and no additional files or databases are required to store and query this information. By signing the mirror file with the written metadata and using the private key of the mirror file creator for signing, an immutable digital fingerprint is provided for the mirror file, ensuring the integrity and source credibility of the mirror file, because any modification to the mirror file will result in a signature verification failure. By sending the mirror description file to the container cloud management platform in the production environment through the SSH protocol, the content of the mirror description file cannot be stolen or tampered with, and only authorized users can access and receive this file. The use of the SSH protocol provides a secure and reliable channel for the transmission of the mirror file, further enhancing the security of the supply chain.
[0071] Specifically, it is necessary to select an appropriate metadata format according to the format of the mirror file and the requirements of the container cloud management platform. Metadata formats include JSON, YAML, etc., which can store information in a structured manner, facilitating subsequent parsing and processing.
[0072] In another optional solution, the above encryption unit includes: a splitting module, configured to split the above digest value according to a predetermined data length to obtain at least two data blocks, and assign a sequence identifier to each of the split data blocks, where the sequence identifier is used to determine the order of encryption operations for each of the above data blocks; an operation module, configured to sequentially perform the above encryption operations on the above data blocks according to the above sequence identifier using the CBC mode of SM4, where the output after the above encryption operation for each of the above data blocks and the above symmetric key are the input for the next above data block to perform the above encryption operation, and determine the output after the above encryption operation for the last above data block as the above anti-tampering check value.
[0073] In the above embodiments, by splitting the digest value into multiple data blocks and using the symmetric key and the CBC mode of SM4 for encryption operations, a tamper-proof verification value is generated. Any tampering with the digest value will cause a change in the encryption operation result, thus preventing the generation of a matching tamper-proof verification value. Therefore, this method effectively protects the integrity of the data and ensures that the digest value has not been tampered with during transmission or storage. Using the CBC mode of SM4 for encryption operations further enhances the security of encryption. In the CBC mode, the encryption result of each data block is XORed with the plaintext of the next data block before encryption. This "chain" reaction makes the encryption result more dependent on the content of all data blocks, thus increasing the difficulty of cracking and further improving the security of the supply chain.
[0074] Specifically, the digest value is split according to a preset data length (for example, each 16 bytes is a block) to obtain multiple data blocks; if the length of the digest value is not divisible, the last data block is padded to make its length reach 16 bytes.
[0075] In some exemplary solutions of the present application, the above first encapsulation unit further includes: a receiving module, configured to receive the hash value of the above mirror description file calculated by the above container cloud management platform in the above production environment; a deletion module, configured to delete the above mirror description file under the above container cloud management platform in the above production environment and generate a prompt message indicating a sending failure when the hash value of the above mirror description file is different from the above tamper-proof verification value; a storage module, configured to store the above mirror description file in the mirror repository under the above container cloud management platform in the above production environment when the hash value of the above mirror description file is the same as the above tamper-proof verification value.
[0076] In the above embodiments, by receiving the hash value of the mirror description file calculated by the container cloud management platform in the production environment and comparing it with the previously generated tamper-proof verification value, it can be ensured that the mirror description file has not been tampered with during transmission. If the hash values do not match, it indicates that the file may have been modified or damaged, thus timely detecting problems. In the case where the hash values do not match, the mirror description file under the container cloud management platform in the production environment is automatically deleted, avoiding the incorrect storage of invalid or tampered files in the mirror repository, thus maintaining the accuracy and reliability of the files in the mirror repository. By generating a prompt message indicating a sending failure, it helps the administrator to timely understand the problems occurring during the file transmission process and take corresponding measures for troubleshooting and repair, improving the efficiency of the supply.
[0077] In some other exemplary embodiments, the above encryption unit includes: a establishing module, configured to establish a communication channel with the container cloud management platform of the above production environment through a security protocol, where the security protocol includes the TLS protocol; a first computing module, configured to calculate a first temporary public key based on the algorithm of the DH protocol according to the generated temporary private key; a second sending module, configured to send the above first temporary public key to the container cloud management platform of the above production environment through the above communication channel, and receive a second temporary public key sent by the container cloud management platform of the above production environment according to the above first temporary public key; a second computing module, configured to calculate the above symmetric key according to the above second temporary public key and the above temporary private key by using the algorithm of the above DH protocol.
[0078] In the above embodiments, by using the TLS protocol to establish a communication channel with the container cloud management platform of the production environment, it is ensured that the communication between the two parties is encrypted and only the two communication parties can decrypt it, effectively preventing man-in-the-middle attacks and eavesdropping. Through the key negotiation protocol, a temporary private key is first generated, and a corresponding first temporary public key is calculated based on the temporary private key and the algorithm of the DH protocol. The sender sends the first temporary public key to the container cloud management platform of the production environment through the secure communication channel and receives the second temporary public key from the container cloud management platform of the production environment. Without directly exchanging private keys, the two parties securely negotiate a shared key. By using the received second temporary public key and the previously generated temporary private key, the symmetric key is calculated by using the algorithm of the DH protocol. The key length used for symmetric key encryption is shorter, which has higher efficiency.
[0079] According to some further optional solutions of the present application, the above device further includes: an incoming unit, configured to send the above mirror file into the API software package, so that the API software package calculates the above mirror file and generates security information.
[0080] In the above embodiments, by sending the mirror file into the API software package, only by calling the API interface and sending in the mirror file, a series of steps such as hash value calculation, symmetric key generation, and digital envelope encapsulation can be automatically completed, reducing the need for manual intervention, improving the processing efficiency, and reducing the security risks caused by human errors. The API software package uniformly encapsulates the key logic, ensuring that the security information structures generated when different test environments and different developers call are consistent in structure and unified in format, providing a reliable comparison basis for subsequent verification in the production environment and reducing the error risks brought by environmental differences.
[0081] The above device for ensuring the security of the mirror file supply chain includes a processor and a memory. The above computing unit, the above encryption unit, and the above first encapsulation unit, etc. are all stored in the memory as program units, and the processor executes the above program units stored in the memory to implement corresponding functions. The above modules are all located in the same processor; or, the above modules are respectively located in different processors in any combination form.
[0082] The processor contains a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set, and by adjusting the kernel parameters, at least the problem of low security of the mirror file supply chain in the prior art can be solved.
[0083] The memory may include non-permanent memory in a computer-readable medium, forms such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.
[0084] An embodiment of the present invention provides an electronic device. The device includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, it implements at least the following steps: Step S101, calculate the mirror file using a hash algorithm to obtain the digest value of the above mirror file, and parse the above mirror file to obtain the public key of the above mirror file and the certificate serial number, where the above certificate serial number is the unique identifier of the digital certificate of the above mirror file;
[0085] Step S102, encrypt the generated symmetric key using the above public key to obtain a key digital envelope, and perform an encryption operation on the above digest value of the above mirror file using the above symmetric key to obtain an anti-tampering verification value;
[0086] Step S103, encapsulate the string composed of the above anti-tampering verification value, the above key digital envelope, and the above certificate serial number into security information associated with the above mirror file, and send the above mirror file carrying the above security information to the container cloud management platform in the production environment.
[0087] Specifically, the SHA-256 hash algorithm is selected to calculate the digest value of the mirror file. The mirror file supply chain includes the container cloud management platform in the test environment and the container cloud management platform in the production environment.
[0088] In an embodiment of the present application, before calculating the digest value of the mirror file using the hash algorithm to obtain the above-mentioned digest value of the mirror file, the above method further includes: sending a request file to the container cloud management platform in the above production environment, where the request file is an application file for applying for a target application publisher certificate, and the target application publisher certificate is a digital certificate representing the identity of the publisher; receiving the target application publisher certificate sent by the container cloud management platform in the above production environment; encapsulating at least the application code and configuration files corresponding to the target application publisher certificate to obtain the above mirror file.
[0089] In an embodiment of the present application, after at least encapsulating the application code and configuration files corresponding to the target application publisher certificate to obtain the above mirror file, the above method further includes: splitting the above mirror file into at least two shards according to a preset file size, and each of the above shards has a unique identifier; generating the above security information for each of the above shards; sending the shards carrying the above security information to the container cloud management platform in the above production environment, so that the container cloud management platform in the above production environment assembles and calculates each of the above shards according to the unique identifier of the shards to obtain the hash value of the recombined mirror file; in the case where the hash value of the above recombined mirror file is the same as the anti-tampering verification value corresponding to the above mirror file, storing the above recombined mirror file in the mirror repository under the container cloud management platform in the above production environment; in the case where the hash value of the above recombined mirror file is different from the anti-tampering verification value corresponding to the above mirror file, deleting the above recombined mirror file under the container cloud management platform in the above production environment.
[0090] In an embodiment of the present application, sending the mirror file carrying the above security information to the container cloud management platform in the production environment includes: writing the above security information as metadata of the above mirror file into the above mirror file, and signing the above mirror file with the written metadata to obtain a mirror description file, where the signature is the signature of the creator of the above mirror file; sending the above mirror description file to the container cloud management platform in the above production environment through the SSH protocol.
[0091] In one embodiment of the present application, the above-mentioned symmetric key is used to perform an encryption operation on the above-mentioned digest value of the above-mentioned mirror file to obtain an anti-tampering verification value, including: splitting the above-mentioned digest value according to a predetermined data length to obtain at least two data blocks, and assigning a serial number identifier to each of the split data blocks, where the serial number identifier is used to determine the order of encryption operations for each of the above-mentioned data blocks; according to the above-mentioned serial number identifier, using the CBC mode of SM4 to sequentially perform the above-mentioned encryption operation on the above-mentioned data blocks, where the output after the above-mentioned encryption operation for each of the above-mentioned data blocks and the above-mentioned symmetric key are the input for the next above-mentioned data block to perform the above-mentioned encryption operation, and determining the output after the above-mentioned encryption operation for the last above-mentioned data block as the above-mentioned anti-tampering verification value.
[0092] In one embodiment of the present application, after sending the above-mentioned mirror description file to the above-mentioned container cloud management platform in the above-mentioned production environment through the SSH protocol, the above-mentioned method further includes: receiving the hash value of the above-mentioned mirror description file calculated by the above-mentioned container cloud management platform in the above-mentioned production environment; in the case where the above-mentioned hash value of the above-mentioned mirror description file is different from the above-mentioned anti-tampering verification value, deleting the above-mentioned mirror description file under the above-mentioned container cloud management platform in the above-mentioned production environment and generating a prompt message indicating a failed transmission; in the case where the above-mentioned hash value of the above-mentioned mirror description file is the same as the above-mentioned anti-tampering verification value, storing the above-mentioned mirror description file in the mirror repository under the above-mentioned container cloud management platform in the above-mentioned production environment.
[0093] In one embodiment of the present application, before encrypting the generated symmetric key using the above-mentioned public key, the above-mentioned method further includes: establishing a communication channel with the above-mentioned container cloud management platform in the above-mentioned production environment through a security protocol, where the security protocol includes the TLS protocol; calculating a first temporary public key based on the algorithm of the DH protocol according to the generated temporary private key; sending the above-mentioned first temporary public key to the above-mentioned container cloud management platform in the above-mentioned production environment through the above-mentioned communication channel and receiving a second temporary public key sent by the above-mentioned container cloud management platform in the above-mentioned production environment according to the above-mentioned first temporary public key; calculating the above-mentioned symmetric key according to the above-mentioned second temporary public key and the above-mentioned temporary private key using the algorithm of the above-mentioned DH protocol.
[0094] In one embodiment of the present application, before calculating the digest value of the above-mentioned mirror file using a hash algorithm, the above-mentioned method further includes: passing the above-mentioned mirror file into an API software package so that the API software package calculates and generates security information for the above-mentioned mirror file.
[0095] The devices in this article can be servers, PCs, PADs, mobile phones, etc.
[0096] Obviously, those skilled in the art should understand that the various modules or steps of the present invention described above can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program code executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order than here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. In this way, the present invention is not limited to any specific combination of hardware and software.
[0097] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0098] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one or more of the flows or multiple flows and / or blocks Figure 1 one or more of the blocks or multiple blocks.
[0099] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one or more of the flows or multiple flows and / or blocks Figure 1 one or more of the blocks or multiple blocks.
[0100] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the functions in the flowFigure 1 one or more processes and / or blocks Figure 1 steps of functions specified in one or more blocks
[0101] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0102] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.
[0103] Computer-readable media includes permanent and non-permanent, removable and non-removable media and can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0104] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.
[0105] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:
[0106] 1) The method for ensuring the security of the mirror file supply chain in this application first calculates the mirror file using a hash algorithm to obtain the digest value of the above mirror file, and parses the above mirror file to obtain the public key and certificate serial number of the above mirror file, where the above certificate serial number is the unique identifier of the digital certificate of the above mirror file; then, encrypts the generated symmetric key using the above public key to obtain a key digital envelope, and performs an encryption operation on the above digest value of the above mirror file using the above symmetric key to obtain an anti-tampering check value; finally, encapsulates the string composed of the above anti-tampering check value, the above key digital envelope, and the above certificate serial number as security information associated with the above mirror file, and sends the above mirror file carrying the above security information to the container cloud management platform in the production environment. In this application, by calculating the mirror file using a hash algorithm to generate a unique digest value, any tampering with the mirror file will cause a change in the digest value, ensuring the integrity of the mirror file during transmission and storage; then, the randomly generated symmetric key is used to encrypt the digest value of the mirror file to generate an anti-tampering check value, and the above symmetric key is encrypted by the public key parsed from the mirror file to form a key digital envelope, ensuring that even if the key is intercepted during transmission, the attacker cannot decrypt it to obtain the original symmetric key, reducing the risk of the above mirror file being tampered with, forged, or misused in the supply chain, and improving the security of the supply chain.
[0107] 2) The device for ensuring the security of the mirror file supply chain in this application first uses a computing unit to calculate the mirror file using a hash algorithm to obtain the digest value of the above mirror file, and parses the above mirror file to obtain the public key and certificate serial number of the above mirror file, where the above certificate serial number is the unique identifier of the digital certificate of the above mirror file; then, through the encryption unit, the generated symmetric key is encrypted using the above public key to obtain a key digital envelope, and the above symmetric key is used to perform an encryption operation on the above digest value of the above mirror file to obtain an anti-tampering verification value; finally, through the first encapsulation unit, the string composed of the above anti-tampering verification value, the above key digital envelope, and the above certificate serial number is encapsulated into security information associated with the above mirror file, and the above mirror file carrying the above security information is sent to the container cloud management platform in the production environment. In this application, by calculating the mirror file using a hash algorithm to generate a unique digest value, any tampering with the mirror file will cause a change in the digest value, ensuring the integrity of the mirror file during transmission and storage; then, a randomly generated symmetric key is used to encrypt the digest value of the mirror file to generate an anti-tampering verification value, and the above symmetric key is encrypted using the public key parsed from the mirror file to form a key digital envelope, ensuring that even if the key is intercepted during transmission, the attacker cannot decrypt it to obtain the original symmetric key, reducing the risk of the above mirror file being tampered with, forged, or misused in the supply chain, and improving the security of the supply chain.
[0108] The above are only the preferred embodiments of this application and are not used to limit this application. For those skilled in the art, various changes and modifications can be made to this application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this application shall be included within the protection scope of this application.
Claims
1. A method for ensuring the security of the mirror file supply chain, characterized in that, Including: Calculating the mirror file by using a hash algorithm to obtain the digest value of the mirror file, and parsing the mirror file to obtain the public key of the mirror file and the certificate serial number, where the certificate serial number is the unique identifier of the digital certificate of the mirror file; Encrypting the generated symmetric key by using the public key to obtain a key digital envelope, and encrypting the digest value of the mirror file by using the symmetric key to obtain an anti-tampering check value; Encapsulating the string composed of the anti-tampering check value, the key digital envelope and the certificate serial number into security information associated with the mirror file, and sending the mirror file carrying the security information to the container cloud management platform in the production environment.
2. The method according to claim 1, wherein Before calculating the mirror file by using a hash algorithm to obtain the digest value of the mirror file, the method further includes: Sending a request file to the container cloud management platform in the production environment, where the request file is an application file for the target application publisher certificate, and the target application publisher certificate is a digital certificate representing the identity of the publisher; Receiving the target application publisher certificate sent by the container cloud management platform in the production environment; At least encapsulating the application code and configuration file corresponding to the target application publisher certificate to obtain the mirror file.
3. The method according to claim 2, wherein After at least encapsulating the application code and configuration file corresponding to the target application publisher certificate to obtain the mirror file, the method further includes: Dividing the mirror file into at least two shards according to a preset file size, and each shard has a unique identifier; Generating the security information for each shard; Sending the shard carrying the security information to the container cloud management platform in the production environment, so that the container cloud management platform in the production environment assembles and calculates each shard according to the unique identifier of the shard to obtain the hash value of the recombined mirror file; When the hash value of the recombined mirror file is the same as the anti-tampering check value corresponding to the mirror file, storing the recombined mirror file in the mirror repository under the container cloud management platform in the production environment; When the hash value of the recombined mirror file is different from the anti-tampering check value corresponding to the mirror file, deleting the recombined mirror file under the container cloud management platform in the production environment.
4. The method according to claim 1, wherein And sending the mirror file carrying the security information to the container cloud management platform in the production environment, including: Writing the security information as metadata of the mirror file into the mirror file, and signing the mirror file with the written metadata to obtain a mirror description file, where the signature is the signature of the creator of the mirror file; Sending the mirror description file to the container cloud management platform in the production environment through the SSH protocol.
5. The method according to claim 1, wherein Encrypting the digest value of the mirror file by using the symmetric key to obtain an anti-tampering check value, including: Divide the summary value according to a predetermined data length to obtain at least two data blocks, and assign a serial number identifier to each of the divided data blocks, where the serial number identifier is used to determine the order of encryption operations for each of the data blocks; According to the serial number identifier, perform the encryption operation on the data blocks in sequence using the CBC mode of SM4, where the output after the encryption operation of each data block and the symmetric key are the input for the encryption operation of the next data block, and determine that the output after the encryption operation of the last data block is the anti-tampering verification value.
6. The method according to claim 4, characterized in that, After sending the image description file to the container cloud management platform in the production environment through the SSH protocol, the method further includes: Receiving the hash value of the image description file calculated by the container cloud management platform in the production environment; In the case where the hash value of the image description file is different from the anti-tampering verification value, delete the image description file under the container cloud management platform in the production environment and generate a prompt message indicating a failed transmission; In the case where the hash value of the image description file is the same as the anti-tampering verification value, store the image description file in the image repository under the container cloud management platform in the production environment.
7. The method according to claim 1, wherein Before encrypting the generated symmetric key using the public key, the method further includes: Establishing a communication channel with the container cloud management platform in the production environment through a security protocol, where the security protocol includes the TLS protocol; Calculating a first temporary public key based on the algorithm of the DH protocol according to the generated temporary private key; Sending the first temporary public key to the container cloud management platform in the production environment through the communication channel, and receiving a second temporary public key sent by the container cloud management platform in the production environment according to the first temporary public key; Calculating the symmetric key according to the second temporary public key and the temporary private key using the algorithm of the DH protocol.
8. The method according to any one of claims 1 to 7, characterized in that, Before calculating the summary value of the image file using the hash algorithm, the method further includes: Passing the image file into an API software package so that the API software package calculates the image file and generates security information.
9. An apparatus for ensuring the security of the mirror file supply chain, characterized in that, Including: A calculation unit, configured to calculate the summary value of the image file using a hash algorithm, and parse the image file to obtain the public key of the image file and the certificate serial number, where the certificate serial number is the unique identifier of the digital certificate of the image file; An encryption unit, configured to encrypt the generated symmetric key using the public key to obtain a key digital envelope, and perform an encryption operation on the summary value of the image file using the symmetric key to obtain an anti-tampering verification value; An encapsulation unit, configured to encapsulate a string composed of the anti-tampering verification value, the key digital envelope, and the certificate serial number into security information associated with the image file, and send the image file carrying the security information to the container cloud management platform in the production environment.
10. An electronic device, characterized in that, Including: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include those for performing the method according to any one of claims 1 to 7.