首页> 外国专利> BLOCK DEVICE SIGNATURE-BASED INTEGRITY PROTECTION FOR CONTAINERIZED APPLICATIONS

BLOCK DEVICE SIGNATURE-BASED INTEGRITY PROTECTION FOR CONTAINERIZED APPLICATIONS

机译:集装箱应用程序的块基于设备签名的完整性保护

摘要

Integrity verification of a containerized application using a block device signature is described. For example, a container deployed to a host system is signed with a single block device signature. The operating system of the host system implements an integrity policy to verify the integrity of the container when the container is loaded into memory and when its program code executes. During such events, the operating system verifies whether the block device signature is valid. If the block device signature is determined to be valid, the operating system enables the program code to successfully execute. Otherwise, the program code is prevented from being executed. By doing so, certain program code or processes that are not properly signed are prevented from executing, thereby protecting the host system from such processes. Moreover, by using a single block device signature for a container, the enforcement of the integrity policy is greatly simplified.
机译:描述了使用块设备签名的集装箱化应用程序的完整性验证。例如,部署到主机系统的容器用单个块设备签名签名。主机系统的操作系统实现了完整性策略,以验证当容器加载到内存中以及其程序代码执行时容器的完整性。在此类事件期间,操作系统验证块设备签名是否有效。如果确定块设备签名是有效的,则操作系统使程序代码能够成功执行。否则,防止程序代码被执行。通过这样做,防止了未正确签名的某些程序代码或处理,从而保护主机系统免受这样的过程。此外,通过使用对容器的单个块设备签名,大大简化了完整性策略的实施。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号