AI 中文总结
该研究提出一种可验证容器镜像分发架构,通过透明度服务结合策略即代码实现准入时验证,集成GitHub Actions与GitLab Runners的概念验证可缓解常见容器供应链攻击。
AI 中文摘要
容器化工作负载通常通过CI/CD流水线构建、存储在注册表中,并在包括云和边缘环境在内的异构基础设施上执行。单个被攻破的构建步骤或凭证可将常规自动化转变为恶意制品的大规模分发,这促使人们关注完整性、透明度和可强制执行的部署时检查。本文提出一种可验证容器镜像分发的架构,解决密钥管理挑战并支持基于策略的准入时验证。透明度服务生成与经认证身份绑定的一次性签名密钥,在仅追加的透明度注册表中记录签名事件,并返回密码学可验证的包含性证明。这些证明和身份属性被附加到镜像元数据,在准入时由策略即代码(policy-as-code)评估,仅合规的制品会被部署。我们实现了与GitHub Actions和GitLab Runners集成的概念验证,并评估所得流水线在现实威胁模型下缓解常见供应链攻击的效果。
英文摘要
Containerized workloads are commonly built via CI/CD pipelines, stored in registries, and executed across heterogeneous infrastructures, including cloud and edge environments. A single compromised build step or credential can turn routine automation into large-scale distribution of malicious artifacts, motivating integrity, transparency, and enforceable deployment-time checks. In this paper, we present an architecture for verifiable container image distribution that addresses key-management challenges and enables policy-enforced admission-time verification. A transparency service generates one-time signing keys bound to authenticated identities, records signing events in an append-only transparency registry, and returns cryptographically verifiable proofs of inclusion. These proofs and identity attributes are attached to image metadata and evaluated by policy-as-code at admission time, so only compliant artifacts are deployed. We implement a proof-of-concept integrated with GitHub Actions and GitLab Runners and evaluate how the resulting pipeline mitigates common supply-chain attacks under a realistic threat model.
Commentsin IEEE CSR 2026