IP Library Granted Patent US 12,381,739
Granted Patent B2
US 12,381,739 · App. 18/308,414 · Granted Aug 5, 2025

Image management method and apparatus

Inventors: Yu Zhang (Xi'an, CN); Jianfeng Liu (Beijing, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,739
App. No.
18/308,414
Granted
Aug 5, 2025
Kind
B2
Abstract

An image management method includes: receiving information about a signer and information about a target image that are sent by a first terminal device, where the signer is an object designated to sign the target image; obtaining a signature file based on the information about the signer and the information about the target image; and if a first digest that is of the target image and is returned by a container platform matches a second digest obtained based on the signature file, indicating the container platform to allow use of the target image to start a container.

Claims (35)

1. A method comprising:

receiving, from a first terminal device, first information about a signer and second information about a target image, wherein the signer is designated to sign the target image;

obtaining a signature file based on the first information and the second information; and

instructing, when a first digest that is of the target image and is from a container platform matches a second digest that is based on the signature file, the container platform to allow use of the target image to start a container.

2. The method of claim 1 , wherein before receiving the first information and the second information, the method further comprises receiving indication information of the target image and description information of the signer from a second terminal device, wherein the description information indicates the signer.

3. The method of claim 1 , wherein the first information comprises identity information of the signer, and wherein the method further comprises determining, based on the identity information, that identity authentication of the signer succeeds.

4. The method of claim 3 , further comprising:

receiving authentication information of the signer from a second terminal device; and

further determining, based on the authentication information, that the identity authentication of the signer succeeds.

5. The method of claim 4 , further comprising supporting information transmission among the second terminal device, the first terminal device, and the container platform through an application programming interface (API).

6. The method of claim 2 , wherein after receiving the description information, the method further comprises generating a key pair corresponding to the signer and comprising a public key and a private key.

7. The method of claim 6 , wherein the second information comprises a hash value of the target image, wherein the first information corresponds to the private key, and wherein obtaining the signature file comprises generating the signature file based on the private key and the hash value.

8. The method of claim 6 , further comprising receiving, from the container platform, a request message requesting to use the target image to start the container on the container platform.

9. The method of claim 6 , further comprising adding authentication information of the signer to a signer database.

10. An apparatus comprising:

a memory configured to store instructions; and

one or more processors coupled to the memory and configured to execute the instructions to cause the apparatus to:

receive, from a first terminal device, first information about a signer and second information about a target image, wherein the signer is designated to sign the target image;

obtain a signature file based on the first information and the second information; and

instruct, when a first digest that is of the target image and is from a container platform matches a second digest that is based on the signature file, the container platform to allow use of the target image to start a container.

11. The apparatus of claim 10 , wherein before receiving the first information and the second information, the one or more processors are further configured to execute the instructions to cause the apparatus to receive indication information of the target image and description information of the signer from a second terminal device, wherein the description information indicates the signer.

12. The apparatus of claim 10 , wherein the first information comprises identity information of the signer, and wherein the one or more processors are further configured to execute the instructions to cause the apparatus to determine, based on the identity information, that identity authentication of the signer succeeds.

13. The apparatus of claim 12 , wherein the one or more processors are further configured to execute the instructions to cause the apparatus to:

receive authentication information of the signer from a second terminal device; and

further determine, based on the authentication information, that the identity authentication of the signer succeeds.

14. The apparatus of claim 13 , wherein the one or more processors are further configured to execute the instructions to cause the apparatus to support information transmission among the second terminal device, the first terminal device, and the container platform through an application programming interface (API).

15. The apparatus of claim 11 , wherein after receiving the description information, the one or more processors are further configured to execute the instructions to cause the apparatus to generate a key pair corresponding to the signer and comprising a public key and a private key.

16. The apparatus of claim 15 , wherein the second information comprises a hash value of the target image, wherein the first information corresponds to the private key, and wherein the one or more processors are further configured to execute the instructions to cause the apparatus to obtain the signature file by generating the signature file based on the private key and the hash value.

17. The apparatus of claim 15 , wherein the one or more processors are further configured to execute the instructions to cause the apparatus to receive, from the container platform, a request message requesting to use the target image to start the container on the container platform.

18. The apparatus of claim 15 , wherein the one or more processors are further configured to add authentication information of the signer to a signer database.

19. A computer program product comprising instructions that are stored on a non-transitory computer-readable medium and that, when executed by one or more processors, cause an apparatus to:

receive, from a first terminal device, first information about a signer and second information about a target image, wherein the signer is designated to sign the target image;

obtain a signature file based on the first information and the second information; and

instruct, when a first digest that is of the target image and is from a container platform matches a second digest that is based on the signature file, the container platform to allow use of the target image to start a container.

20. The computer program product of claim 19 , wherein before receiving the first information and the second information, the instructions, when executed by the one or more processors, further cause the apparatus to receive indication information of the target image and description information of the signer from a second terminal device, wherein the description information indicates the signer.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2023
From: ZHANG, YU; LIU, JIANFENG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 063929/0151 →
Priority Claims (1)
CN 202011183293.3 · Oct 29, 2020 · national
Continuity (2)
Continuation PCTCN2021101818 · Jun 23, 2021
Related Publication 20230261882A1 · Aug 17, 2023
References Cited (25)
US 8161012B1 · Gerraty · 2012 [cited by examiner]
US 10902114B1 · Trost · 2021 [cited by examiner]
US 11080403B1 · Taylor · 2021 [cited by examiner]
US 11573816B1 · Featonby · 2023 [cited by examiner]
US 11954219B1 · Makmal · 2024 [cited by examiner]
US 20140095886A1 · Futral · 2014 [cited by examiner]
US 20160381075A1 · Goyal · 2016 [cited by examiner]
US 20180129479A1 · McPherson · 2018 [cited by examiner]
US 20180137174A1 · Cahana · 2018 [cited by examiner]
US 20190356492A1 · Picco · 2019 [cited by examiner]
US 20200272440A1 · Burgazzoli · 2020 [cited by examiner]
US 20200272737A1 · Ji · 2020 [cited by examiner]
US 20200296089A1 · Hsiung · 2020 [cited by examiner]
US 20210133313A1 · Sakib · 2021 [cited by examiner]
US 20210312037A1 · Revivo · 2021 [cited by examiner]
US 20220114249A1 · Grancharov · 2022 [cited by examiner]
US 20220318415A1 · Fu · 2022 [cited by examiner]
US 20230370474A1 · Migault · 2023 [cited by examiner]
US 20240424818A1 · Zhang · 2024 [cited by examiner]
CN 111562970A · 2020 [cited by examiner]
“Content trust in Docker|Docker Documentation”, Oct. 24, 2020, 6 pages, XP093133818. [cited by applicant]
“Get started with Notary |Docker Documentation”, Sep. 7, 2020, 4 pages, XP093133820. [cited by applicant]
Weitekamp Aaron: “Container Image Signing”, Jul. 22, 2016, 6 pages, XP093133898. [cited by applicant]
Zou, D., et al., “Constructing trusted virtual execution environment in P2P grids,” Future Generation Computer Systems, vol. 26, No. 5, May 1, 2010, 7 pages, XP055978070. [cited by applicant]
Anonymous Red:“OpenShift—Wikipedia”,Oct. 28, 2020 (Oct. 28, 2020), pp. 1-5, XP093268143. [cited by applicant]