Abstract:
A measurement method, an electronic device, and a measurement system where the electronic device reads, from a hardware storage device, running code and running data that are in a running process of a virtual machine manager (VMM), and generates first verification information according to the running code and the running data, and the electronic device stores the first verification information, and transmits, to a trusted data center, log information generated in a process that is from reading, by the electronic device, the running code and the running data to storing, by the electronic device, the first verification information such that the trusted data center measures the electronic device using the first verification information acquired from the electronic device and second verification information generated according to the log information.
Abstract:
An image management method and apparatus are provided. The method includes: receiving information about a signer and information about a target image that are sent by a first terminal device, where the signer is an object designated to sign the target image; obtaining a signature file based on the information about the signer and the information about the target image; and if a first digest that is of the target image and is returned by a container platform matches a second digest obtained based on the signature file, indicating the container platform to allow use of the target image to start a container. According to this method, a fine-grained and easy-to-use image control function is implemented by using a signature technology, to ensure security of image content and security of a container platform in a full life cycle of a container image.
Abstract:
A measurement method, an electronic device, and a measurement system where the electronic device reads, from a hardware storage device, running code and running data that are in a running process of a virtual machine manager (VMM), and generates first verification information according to the running code and the running data, and the electronic device stores the first verification information, and transmits, to a trusted data center, log information generated in a process that is from reading, by the electronic device, the running code and the running data to storing, by the electronic device, the first verification information such that the trusted data center measures the electronic device using the first verification information acquired from the electronic device and second verification information generated according to the log information.