The invention relates to the technical field of
data access security, and discloses a container
mirror image security management method and
system, and the method comprises the steps: constructing a container
mirror image, generating a differential
encryption key through a strategy center, carrying out the
encryption strategy of a kernel dependence layer, a runtime environment layer, an application code layer and a sensitive configuration layer, and forming a hierarchical protection basis. If an access request is triggered, firstly collecting equipment fingerprints and geofence information and evaluating an
environmental risk score, verifying access authority and an access
scene matching degree through attribute-based
encryption, analyzing operation track characteristics in real time, identifying an abnormal mode, and if the three-layer
verification is passed, generating a temporary
access token; according to the method, access request authority is verified, a temporary
access token is matched, key fragments are synthesized, a
master key is only temporarily generated in a memory and encrypted and stored, and through combination of a double-layer encryption channel and inner-layer and outer-layer defense, the anti-
attack ability of container
mirror image transmission is improved, and man-in-the-middle
attack and data tampering are effectively coped with.