Disclosed are a method and apparatus for
mirror image verification based on a dual-chain-of-trust mechanism, a device, and a medium. The method for
mirror image verification based on a dual-chain-of-trust mechanism comprises: determining a read-only
file system on the basis of an original
mirror image file system and target
operating system verification information; constructing a signed mirror image by means of the read-only
file system, a root hash value file generated on the basis of the read-only file
system, a customized public key, and a signature result of a customized private key on the root hash value file, the root hash value file being obtained on the basis of a
device mapper verification method of a hardware manufacturer chain-of-trust mechanism, and the customized public key being stored in a one-time programmable region; performing a target operation on the customized public key to obtain a first encrypted value, writing the first encrypted value into a verified mirror image, and burning the signed mirror image into a device
flash memory; after the device is powered on, mounting the signed mirror image on the basis of a startup script of the started verified mirror image, and performing a target operation on the customized public key in the signed mirror image to obtain a second encrypted value; and if the first encrypted value is the same as the second encrypted value, verifying the root hash value file on the basis of the customized public key and the signature result, and if the verification passes, implementing verified boot of the target
operating system by means of the root hash value file, so as to ensure the reliability of the chain-of-trust mechanism of the target
operating system.