A management method, system and terminal device of a hardware encryption machine
By connecting a Ukey to the terminal device and establishing a communication link with the virtual machine in the VPC environment, the hardware encryption machine management software on the virtual machine can be remotely controlled, solving the compatibility problem between the hardware encryption machine and the offline terminal device, and achieving the effects of simplifying operation and reducing costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ALIBABA GROUP HOLDING LTD
- Filing Date
- 2019-07-11
- Publication Date
- 2026-05-12
AI Technical Summary
Within the VPC environment of the cloud platform, hardware encryption machines are incompatible with offline terminal devices, making it impossible for terminal devices to remotely manage hardware encryption machines within the VPC environment. Furthermore, existing VPN setups are complex and costly.
By connecting a Ukey to the terminal device, a communication link is established with the virtual machines in the VPC environment, allowing remote control of the hardware encryption machine management software on the virtual machines. The password verification function of the Ukey is used to manage the hardware encryption machine, avoiding the need to build a VPN in the VPC environment.
This enables terminal devices to remotely control hardware encryption machines within a VPC environment without needing to set up a VPN, simplifying the operation process and reducing costs.
Smart Images

Figure CN112214761B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a management method, system, terminal device, and readable storage medium for a hardware encryption machine. Background Technology
[0002] To provide users with a more secure and isolated network environment on the cloud platform, the cloud platform offers Virtual Private Cloud (VPC) technology, which allows users (enterprises or individuals renting cloud platforms) to build their own VPC environment on the cloud platform, thereby isolating the offline network environment.
[0003] In layman's terms, a VPC is like a network container. Virtual machines (VMs) can be created within a VPC environment to implement cloud product instances. A VM is a complete computer system simulated by software, possessing full hardware system functionality, and running in a completely isolated environment. For example, you can create a VM within a VPC to simulate a server, or you can create another VM within the VPC to simulate a hardware encryption machine. Here, the hardware encryption machine provides key services for data transmission between the server and terminal devices.
[0004] After a period of use, the hardware encryption machine needs to undergo software program or encryption command management operations to update its management. Currently, managing the hardware encryption machine relies on a storage device (Ukey) with password verification functionality connected to the terminal device. For example... Figure 1 As shown, users can build a Virtual Private Network (VPN) within the VPC environment of the cloud platform. Terminal devices can dial into the VPC environment through the VPN so that they can use the access Ukey to manage the hardware encryption machine.
[0005] However, if the VPN is set up by the user, its security and stability cannot be guaranteed, and it requires a considerable amount of time and expertise from professional technicians to set up, making the process quite complex. If the VPN is purchased from a cloud platform, it incurs higher costs. Furthermore, while a hardware encryption machine can be set up within a VPC environment on a cloud platform, the terminal devices used to manage and control the hardware encryption machine are located in an offline network environment. The incompatibility between the offline network environment and the VPC environment prevents the terminal devices from effectively managing the hardware encryption machine within the VPC. Summary of the Invention
[0006] In view of this, this application provides a method, system, terminal device and readable storage medium for managing hardware encryption machines, which can easily and conveniently achieve the purpose of managing hardware encryption machines in a VPC environment.
[0007] To achieve the above objectives, embodiments of this application provide a method for managing a hardware encryption machine, comprising:
[0008] After the terminal device detects the access of the storage device with password verification function, it establishes a communication link with the virtual machine, and receives and displays the running interface of the virtual machine through the communication link; wherein, the virtual machine is a virtual machine that has been built in a virtual private cloud environment;
[0009] The terminal device starts the hardware encryption machine management software on the virtual machine's running interface and loads the driver for the storage device with password verification function, thereby enabling the storage device with password verification function to manage the hardware encryption machine.
[0010] Optionally, the virtual machine is a virtual machine with a public IP address.
[0011] Optionally, the step of the terminal device starting the hardware encryption machine management software and loading the driver for the storage device with password verification function on the virtual machine's runtime interface includes:
[0012] The terminal device detects whether hardware encryption machine management software is installed in the virtual machine and obtains the detection result.
[0013] Based on the detection results, the terminal device starts and installs the hardware encryption machine management software on the virtual machine's running interface and loads the driver for the storage device with password verification function.
[0014] Optionally, the terminal device, based on the detection result, initiates the installation of the hardware encryption machine management software and loads the driver for the storage device with password verification function on the virtual machine's runtime interface, including:
[0015] The detection result indicates that hardware encryption machine management software is installed in the virtual machine, and the terminal device starts and installs the hardware encryption machine management software on the virtual machine's running interface and loads the driver for the storage device with password verification function.
[0016] Optionally, the terminal device, based on the detection result, initiates the installation of the hardware encryption machine management software and loads the driver for the storage device with password verification function on the virtual machine's runtime interface, including:
[0017] The detection result indicates that no hardware encryption device management software is installed in the virtual machine. The terminal device mounts the hardware encryption device management software on the virtual machine through the virtual machine's running interface, starts the hardware encryption device management software, and loads the driver for the storage device with password verification function.
[0018] Optionally, the method further includes:
[0019] The terminal device constructs a virtual machine with a public IP address within the virtual private cloud environment.
[0020] Optionally, the step of establishing a communication link between the terminal device and the virtual machine includes:
[0021] The terminal device receives a remote desktop connection command and obtains a public IP address based on the remote desktop connection command.
[0022] The terminal device sends a remote desktop connection request containing the public IP address to the cloud platform;
[0023] The terminal device establishes a communication link with the virtual machine based on the remote desktop connection request.
[0024] Optionally, the step of the terminal device receiving and displaying the running interface of the virtual machine through the communication link includes:
[0025] The terminal device obtains the username and password;
[0026] The terminal device generates connection credentials based on the username and password, and sends the connection credentials to the virtual machine through the communication link;
[0027] After the virtual machine successfully verifies the username and password based on the connection credentials, the terminal device receives and displays the running interface of the virtual machine.
[0028] Optionally, after controlling the hardware encryption machine using the Ukey on the virtual machine's runtime interface, the system further includes:
[0029] Release the virtual machine within the VPC environment.
[0030] To achieve the above objectives, embodiments of this application provide a management system for a hardware encryption machine, comprising:
[0031] Cloud platforms and terminal devices; among them,
[0032] The cloud platform is used to build a virtual private cloud environment; a hardware encryption machine and a virtual machine connected to the hardware encryption machine are set up in the virtual private cloud environment;
[0033] The terminal device is used to establish a communication link with the virtual machine after detecting the access of the storage device with password verification function, and to receive and display the running interface of the virtual machine through the communication link; and to start the hardware encryption machine management software on the running interface of the virtual machine and load the driver of the storage device with password verification function, so as to realize the management of the hardware encryption machine of the storage device with password verification function.
[0034] Optionally, the virtual machine is a virtual machine with a public IP address.
[0035] To achieve the above objectives, this application provides a terminal device, including:
[0036] The port is used to connect to a storage device with password authentication functionality;
[0037] A communication module is used for data interaction between the terminal device and the virtual machine;
[0038] The display module is used to display the running interface of the virtual machine;
[0039] The processor is configured to, upon detecting the access of a storage device with password verification functionality, initiate the communication module, establish a communication link between the processor and the virtual machine, receive the virtual machine's running interface through the communication link, and initiate the display module; on the virtual machine's running interface, initiate the hardware encryption machine management software and load the driver for the storage device with password verification functionality, thereby enabling the management of the storage device with password verification functionality through the hardware encryption machine.
[0040] Optionally, the processor is further configured to release the virtual machine within the VPC environment after the remotely controlled virtual machine manages the hardware encryption machine on the hardware encryption machine management software.
[0041] To achieve the above objectives, this application provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the hardware encryption machine management method described above.
[0042] To achieve the above objectives, embodiments of this application provide a readable storage medium storing a computer program thereon, which, when executed, implements the steps of the hardware encryption machine management method described above.
[0043] The following beneficial effects can be achieved through the above technical means:
[0044] This technical solution establishes a virtual machine within a VPC environment, and a communication link is established between the terminal device and the virtual machine. This allows the terminal device to remotely control the virtual machine and manage the hardware encryption machine within the VPC environment using a Ukey connected to the terminal device. This solution eliminates the need for a VPN within the VPC environment, thus avoiding the drawbacks of such a setup. Attached Figure Description
[0045] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0046] Figure 1 This is a schematic diagram of a traditional hardware encryption machine management system;
[0047] Figure 2 This is a schematic diagram of a management system for a hardware encryption machine disclosed in an embodiment of this application;
[0048] Figure 3 This is a schematic diagram of a hardware encryption machine management method disclosed in an embodiment of this application;
[0049] Figure 4 This is a flowchart illustrating the method for establishing a connection between a terminal device and a virtual machine as disclosed in an embodiment of this application.
[0050] Figure 5 A flowchart illustrating how a terminal device receives and displays the virtual machine's runtime interface via the communication link;
[0051] Figure 6 For based on Figure 2 The diagram shows the management method of the hardware encryption machine implemented by the management system.
[0052] Figure 7 This is a schematic diagram of the structure of the terminal device disclosed in the embodiments of this application;
[0053] Figure 8 This is a schematic diagram of an electronic device disclosed in an embodiment of this application. Detailed Implementation
[0054] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0055] Terminology Explanation:
[0056] Hardware Security Module (HSM): A hardware security module is used to implement various cryptographic algorithms and securely store keys, such as the root key of a Certificate Authority (CA).
[0057] Ukey: A small, reliable, and high-speed storage device that connects directly to a computer via USB (Universal Serial Bus interface) and features password authentication.
[0058] Virtual Private Cloud (VPC): A VPC is a dynamically configured pool of public cloud computing resources that requires the use of encryption protocols, tunneling protocols, and other security procedures to transmit data between private enterprises and cloud service providers. Essentially, a VPC transforms a cloud service provider's multi-tenant architecture into a single-tenant architecture. It builds an isolated private network based on the cloud computing environment, creating an isolated, user-configurable, and manageable virtual network environment for elastic cloud servers, improving the security of user cloud resources and simplifying network deployment.
[0059] Virtual Private Network (VPN) enables businesses to establish a secure wide area network (WAN) service on a low-cost, shared infrastructure, using the same policies offered by a private network.
[0060] Virtual Machine (VM): A software-simulated complete computer system with full hardware system functionality, running in a completely isolated environment.
[0061] Remote Desktop Protocol (RDP) is a multi-channel protocol that allows terminal devices to connect to a computer that provides terminal services, also known as a server or "remote computer."
[0062] Mounting is the process by which the operating system makes computer files and directories on a storage device (such as a hard drive) accessible to users through the computer's file system. Generally, when the computer is shut down, each mounted storage device undergoes an unmounting process to ensure that all queued data is written and to maintain the integrity of the file system structure on the medium.
[0063] To facilitate those skilled in the art to understand the application scenarios of this application, this application provides a management system for a hardware encryption machine.
[0064] See Figure 2 Within a VPC environment, the management system for the hardware encryption machine includes: terminal devices and a cloud platform connected to the terminal devices. It is understood that the number of terminal devices can be determined based on the actual situation. Figure 2 The illustration will be based on a single terminal device.
[0065] Cloud platforms can provide VPC technology, allowing users who rent cloud platforms to build their own dedicated VPC environments. See also... Figure 2 Users can build virtual machines and hardware encryption machines connected to the virtual machines within the VPC environment.
[0066] Typically, a VPC environment has its own dedicated network environment, isolated from the offline network environment. In order to communicate with terminal devices in the offline network environment and to control the hardware encryption machine in the VPC environment using the terminal devices in the offline network environment, a virtual machine with a public IP address is set up in the VPC environment. Once the virtual machine has a public IP address, it means that the terminal devices in the offline network environment can access the virtual machine through the public IP address, thus enabling communication between the terminal devices and the virtual machine in the VPC environment.
[0067] Based on the above analysis, in this technical solution, after the Ukey is connected to the terminal device, the terminal device establishes a communication link with the virtual machine, and the terminal device receives and displays the running interface of the virtual machine; wherein, the virtual machine is a virtual machine that has been built in the VPC environment; on the running interface of the virtual machine, the hardware encryption machine management software is started and the Ukey driver is loaded; on the running interface of the virtual machine, the hardware encryption machine is managed using the Ukey.
[0068] In this technical solution, when the terminal device remotely controls the virtual machine, it uses the Ukey connected to the terminal device to manage the hardware encryption machine in the VPC environment. There is no need to build a VPN in the VPC environment, so the disadvantages of building a VPN in the VPC environment can be avoided.
[0069] Based on the above description, this application provides a method for managing a hardware encryption machine, see [link to relevant documentation]. Figure 3 This includes the following steps:
[0070] Step 301: After the terminal device detects the access of the storage device with password verification function, it establishes a communication link with the virtual machine, and receives and displays the running interface of the virtual machine through the communication link; wherein, the virtual machine is a virtual machine that has been built in a virtual private cloud environment.
[0071] Users send instructions to the cloud platform via their terminal devices to set up virtual machines, and can configure the virtual machines to have public IP addresses. Upon receiving the instructions, the cloud platform sets up a virtual machine and assigns it the user-defined public IP address.
[0072] Since a virtual machine will be used to manage the hardware encryption machine, the terminal device can send the hardware encryption machine management software to the virtual machine so that it can be installed within the virtual machine. Alternatively, it's also possible to manage the hardware encryption machine using the hardware encryption machine management software on the terminal device, without installing it within the virtual machine.
[0073] Since virtual machines within a VPC environment are software-virtualized computer environments, they cannot be connected to a Ukey. Therefore, this technical solution still requires connecting a Ukey on the terminal device.
[0074] Before establishing a remote desktop connection, both the terminal device and the virtual machine need to have remote desktop connection enabled. Users can insert the Ukey into the USB port of the terminal device. Once the terminal device detects that the Ukey is correctly connected, it establishes a remote desktop connection between the terminal device and the virtual machine with a public IP address within the VPC environment of the cloud platform, thus establishing a communication link between the terminal device and the virtual machine.
[0075] According to one embodiment of this application, see Figure 4 The process of establishing a remote desktop connection between a terminal device and a virtual machine may include the following steps:
[0076] S401: The terminal device receives a remote desktop connection command and obtains a public IP address based on the remote desktop connection command.
[0077] The terminal device receives the remote desktop connection command input by the user, and then responds to the remote desktop connection command by popping up a remote desktop dialog box so that the user can enter the public IP address of the virtual machine.
[0078] S402: The terminal device sends a remote desktop connection request containing the public IP address to the cloud platform;
[0079] After the user enters a public IP address in the dialog box, the terminal device receives the virtual machine's public IP address and constructs a remote desktop connection request containing the public IP address. Then, it sends this request to the virtual machine corresponding to the public IP address.
[0080] S403: The terminal device establishes a communication link with the virtual machine based on the remote desktop connection request.
[0081] After receiving a remote desktop connection request, the virtual machine confirms that it has enabled the remote desktop connection function and then confirms that a remote desktop connection can be established.
[0082] To ensure the virtual machine's interface is accessible to the correct device, the terminal device needs to provide connection credentials. The terminal device will display a dialog box for the user to enter connection credentials, which can be the virtual machine's username and password. Figure 5 The diagram shows a flowchart of how a terminal device receives and displays the running interface of the virtual machine through the communication link.
[0083] S501: The terminal device obtains the username and password;
[0084] S502: Generate connection credentials based on the username and password, and send the connection credentials to the virtual machine through the communication link.
[0085] After the user enters their username and password in the dialog box, the terminal device generates connection credentials containing the username and password and sends the connection credentials to the virtual machine.
[0086] S503: After the virtual machine successfully verifies the username and password based on the connection credentials, the terminal device receives and displays the running interface of the virtual machine.
[0087] After receiving the username and password, the virtual machine verifies whether the username and password sent by the terminal device match its own. If they match, the virtual machine determines that the terminal device can remotely control the virtual machine. The virtual machine then sends its interface to the terminal device, which receives and displays the virtual machine's interface.
[0088] Step 302: The terminal device starts the hardware encryption machine management software on the virtual machine's running interface and loads the driver for the storage device with password verification function, thereby enabling the management of the hardware encryption machine for the storage device with password verification function.
[0089] In this technical solution, the steps of the terminal device starting the hardware encryption machine management software and loading the driver for the storage device with password verification function on the virtual machine's runtime interface include:
[0090] The terminal device detects whether hardware encryption machine management software is installed in the virtual machine and obtains the detection result.
[0091] Based on the detection results, the terminal device starts and installs the hardware encryption machine management software on the virtual machine's running interface and loads the driver for the storage device with password verification function.
[0092] Specifically, the inspection results fall into two categories: First, if the hardware encryption device management software is installed within the virtual machine, the software is launched, and the Ukey driver is loaded via the Windows RDP protocol. Second, if the hardware encryption device management software is not installed within the virtual machine, the hardware encryption device management software installed on the terminal device is mounted on the virtual machine, launched, and the Ukey driver is loaded via the Windows RDP protocol.
[0093] From the above, it can be seen that this application has the following beneficial effects:
[0094] This technical solution establishes a virtual machine within a VPC environment, and a communication link is established between the terminal device and the virtual machine. This allows the terminal device to remotely control the virtual machine and manage the hardware encryption machine within the VPC environment using a Ukey connected to the terminal device. This solution eliminates the need for a VPN within the VPC environment, thus avoiding the drawbacks of such a setup.
[0095] like Figure 6 As shown, it is based on Figure 2 The diagram illustrates the management method for the hardware encryption machine implemented by the management system. It includes:
[0096] S601: The terminal device sends an instruction to the VPC environment of the cloud platform to build a virtual machine with a public IP address.
[0097] S602: The cloud platform receives instructions and builds a virtual machine with a public IP address within the VPC environment.
[0098] S603: After the terminal device detects the access of the storage device with password verification function, it establishes a communication link with the virtual machine and receives and displays the running interface of the virtual machine through the communication link.
[0099] S604: Start the hardware encryption machine management software on the virtual machine's running interface and load the Ukey driver.
[0100] S605: The hardware encryption machine is controlled using the Ukey on the virtual machine's running interface.
[0101] S606: The terminal device sends a command to release the virtual machine to the VPC environment via remote desktop.
[0102] Because the hardware encryption machine is managed infrequently, after the terminal device finishes remotely controlling the virtual machine to manage the hardware encryption machine, it can send a command to the VPC environment to release the virtual machine, thereby reducing operating costs. The next time the hardware encryption machine is managed, steps S601-S606 can be repeated.
[0103] Of course, without considering operating costs, after the terminal device finishes remotely controlling the virtual machine to manage the hardware encryption machine, the virtual machine can be left unreleased, i.e., S606 can be skipped. This way, the next time the hardware encryption machine is managed, the existing virtual machine can be used directly, and S604-S605 can be executed, saving the process of setting up the hardware encryption machine and establishing a remote desktop connection.
[0104] See Figure 7 This application also provides a terminal device, including:
[0105] The port is used to connect to a storage device with password authentication functionality;
[0106] A communication module is used for data interaction between the terminal device and the virtual machine;
[0107] The display module is used to display the running interface of the virtual machine;
[0108] The processor is configured to, upon detecting the access of a storage device with password verification functionality, initiate the communication module, establish a communication link between the processor and the virtual machine, receive the virtual machine's running interface through the communication link, and initiate the display module; on the virtual machine's running interface, initiate the hardware encryption machine management software and load the driver for the storage device with password verification functionality, thereby enabling the management of the storage device with password verification functionality through the hardware encryption machine.
[0109] The processing procedure for terminal devices can be found in [reference]. Figure 3 The specific description process in the embodiments will not be repeated here.
[0110] like Figure 8 The diagram shown is a schematic representation of an electronic device according to an embodiment of this application. It includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the aforementioned hardware encryption machine management method.
[0111] The hardware encryption machine management method provided in the embodiments of this specification, the specific functions implemented by its memory and processor can be explained in comparison with the foregoing embodiments in this specification, and can achieve the technical effects of the foregoing embodiments, so they will not be repeated here.
[0112] In this embodiment, the memory may include a physical device for storing information, typically digitizing the information and then storing it using a medium employing electrical, magnetic, or optical methods. The memory described in this embodiment may further include: devices that store information using electrical energy, such as RAM and ROM; devices that store information using magnetic energy, such as hard disks, floppy disks, magnetic tapes, magnetic core memory, bubble memory, and USB flash drives; and devices that store information using optical methods, such as CDs or DVDs. Of course, there are other types of memory, such as quantum memories and graphene memories.
[0113] In this embodiment, the processor can be implemented in any suitable manner. For example, the processor can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers, etc.
[0114] In this embodiment, the present application also provides a readable storage medium storing a computer program thereon, which, when executed, implements the steps of the hardware encryption machine management method described above.
[0115] As can be seen from the above, this technical solution provides a method, system, and terminal device for managing hardware encryption machines within a VPC environment. The method includes: after the Ukey is correctly connected to the terminal device, a remote desktop connection is established to a virtual machine with a public IP address within the VPC environment; the virtual machine's running interface is received and displayed; the virtual machine is remotely controlled to start the hardware encryption machine management software and load the Ukey; and the virtual machine is remotely controlled to manage the hardware encryption machine using the Ukey. This application constructs a virtual machine with a public IP address within a VPC environment, and the terminal device's remote desktop connects to the virtual machine, enabling the terminal device to remotely control the virtual machine to manage the hardware encryption machine in the VPC environment using the Ukey connected to the terminal device. This application does not build a VPN within the VPC environment, thus avoiding the disadvantages of building a VPN within a VPC environment.
[0116] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog are the most commonly used. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0117] Those skilled in the art will also know that, besides implementing the client and server in purely computer-readable program code, the client and server can achieve the same functionality by logically programming the method steps, using logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers (PLCs), and embedded microcontrollers. Therefore, such a client and server can be considered a hardware component, and the devices included within it for implementing various functions can also be considered structures within that hardware component. Alternatively, the devices for implementing various functions can be considered both software modules implementing the method and structures within a hardware component.
[0118] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0119] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on its differences from other embodiments. In particular, the embodiments for the client and server can be explained by referring to the descriptions of the foregoing method embodiments.
[0120] This application can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0121] Although this application has been described through embodiments, those skilled in the art will know that this application has many modifications and variations without departing from the spirit of this application, and it is intended that the appended claims cover such modifications and variations without departing from the spirit of this application.
Claims
1. A management method for a hardware encryption machine, characterized in that, include: After the terminal device detects the access of a storage device with password verification function, it establishes a communication link with the virtual machine, and receives and displays the running interface of the virtual machine through the communication link; wherein, the virtual machine is a virtual machine that has been built in a virtual private cloud environment; The terminal device starts the hardware encryption machine management software on the virtual machine's running interface and loads the driver for the storage device with password verification function, thereby enabling the storage device with password verification function to manage the hardware encryption machine. The hardware encryption machine is located in the virtual private cloud environment and is connected to the virtual machine, which is a virtual machine with a public IP address.
2. The method as described in claim 1, characterized in that, The steps of the terminal device starting the hardware encryption machine management software and loading the driver for the storage device with password verification function on the virtual machine's runtime interface include: The terminal device detects whether hardware encryption machine management software is installed in the virtual machine and obtains the detection result. Based on the detection results, the terminal device starts and installs the hardware encryption machine management software on the virtual machine's running interface and loads the driver for the storage device with password verification function.
3. The method as described in claim 2, characterized in that, The terminal device, based on the detection results, initiates the installation of the hardware encryption machine management software and loads the driver for the storage device with password verification function on the virtual machine's runtime interface, including: The detection result indicates that no hardware encryption device management software is installed in the virtual machine. The terminal device mounts the hardware encryption device management software on the virtual machine through the virtual machine's running interface, starts the hardware encryption device management software, and loads the driver for the storage device with password verification function.
4. The method as described in claim 2, characterized in that, The terminal device, based on the detection results, initiates the installation of the hardware encryption machine management software and loads the driver for the storage device with password verification functionality on the virtual machine's runtime interface, including: The detection result indicates that hardware encryption machine management software is installed in the virtual machine, and the terminal device starts and installs the hardware encryption machine management software on the virtual machine's running interface and loads the driver for the storage device with password verification function.
5. The method as described in claim 1, characterized in that, The method further includes: The terminal device constructs a virtual machine with a public IP address within the virtual private cloud environment.
6. The method as described in claim 1, characterized in that, The steps for establishing a communication link between the terminal device and the virtual machine include: The terminal device receives a remote desktop connection command and obtains a public IP address based on the remote desktop connection command. The terminal device sends a remote desktop connection request containing the public IP address to the cloud platform; The terminal device establishes a communication link with the virtual machine based on the remote desktop connection request.
7. The method as described in claim 1, characterized in that, The steps of the terminal device receiving and displaying the running interface of the virtual machine through the communication link include: The terminal device obtains the username and password; The terminal device generates connection credentials based on the username and password, and sends the connection credentials to the virtual machine through the communication link; After the virtual machine successfully verifies the username and password based on the connection credentials, the terminal device receives and displays the running interface of the virtual machine.
8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: The terminal device releases the virtual machine within the VPC environment.
9. A management system for a hardware encryption machine, characterized in that, include: Cloud platforms and terminal devices; among them, The cloud platform is used to build a virtual private cloud environment; a hardware encryption machine and a virtual machine connected to the hardware encryption machine are set up in the virtual private cloud environment; The terminal device is used to establish a communication link with the virtual machine after detecting the access of the storage device with password verification function, and to receive and display the running interface of the virtual machine through the communication link; to start the hardware encryption machine management software on the running interface of the virtual machine and load the driver of the storage device with password verification function, so as to realize the management of the hardware encryption machine by the storage device with password verification function, wherein the hardware encryption machine is located in the virtual private cloud environment and is connected to the virtual machine.
10. The management system as described in claim 9, characterized in that, The virtual machine is a virtual machine with a public IP address.
11. A terminal device, characterized in that, include: The port is used to connect to a storage device with password authentication functionality; The communication module is used for data interaction between the terminal device and the virtual machine; The display module is used to display the running interface of the virtual machine; The processor, upon detecting the access of a storage device with password verification functionality, initiates the communication module to establish a communication link between the processor and the virtual machine, receives the virtual machine's running interface through the communication link, and initiates the display module; on the virtual machine's running interface, it initiates hardware encryption machine management software and loads the driver for the storage device with password verification functionality, thereby enabling the storage device with password verification functionality to manage the hardware encryption machine, wherein the hardware encryption machine is located within the virtual private cloud environment and is connected to the virtual machine.
12. The terminal device as described in claim 11, characterized in that, The processor is also used to release the virtual machine within the VPC environment after remotely controlling the virtual machine to manage the hardware encryption machine on the hardware encryption machine management software.
13. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the management method of the hardware encryption machine according to any one of claims 1 to 8.
14. A readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed, it implements the steps of the management method for the hardware encryption machine as described in any one of claims 1 to 8.