A Virtual Machine Encryption Method, Device, Equipment and Medium in a Cloud Platform

By building the KMS system pool and encryption policy binding, the problem of inconsistent encryption of virtual machines on cloud platforms under multiple KMS systems is solved, and reliable encryption and decryption and compatibility improvement are achieved.

CN114003336BActive Publication Date: 2025-07-11JINAN INSPUR DATA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111162483.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-30
Publication Date
2025-07-11
Estimated Expiration
2041-09-30

AI Technical Summary

Technical Problem

In the multi-KMS system scenario, cloud platform virtual machines are easily encrypted and key inconsistency leads to decryption failure or data loss.

Method used

Build a KMS system pool, configure multiple verification KMS systems, and bind it to the virtual machine to be encrypted through encryption policies to obtain symmetric encryption keys for virtual disk encryption and decryption, supporting the compatibility and availability of multi-KMS systems.

Benefits of technology

Reliable encryption and decryption of virtual machines in multi-KMS system scenarios is realized, the compatibility and availability of cloud platforms are improved, and data decryption failure caused by non-associated KMS systems to obtain keys is prevented.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114003336B_ABST
    Figure CN114003336B_ABST
Patent Text Reader

Abstract

The present invention provides a virtual machine encryption method in a cloud platform, including: constructing a KMS system pool, where multiple verified KMS systems are configured in the KMS system pool; creating a number of encryption policies, and each encryption policy is bound to one verified KMS system in the KMS system pool; a virtual machine to be encrypted in the cloud platform selects an encryption policy from all the encryption policies and binds the selected encryption policy to the virtual machine to be encrypted; obtaining a symmetric encryption key from the KMS system corresponding to the selected encryption policy and encrypting all virtual disks of the virtual machine to be encrypted. The present invention also provides a virtual machine encryption device, equipment and medium in a cloud platform, which prevents the virtual machine to be encrypted under the cloud platform from obtaining a key from a KMS system that is not bound and associated, and avoids the scenario where data cannot be decrypted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of virtual machine encryption, and in particular to a method, device, equipment and medium for virtual machine encryption in a cloud platform. Background Art

[0002] With the development of cloud computing, more and more enterprise applications are migrated to the cloud platform. After an enterprise migrates to the cloud, how to ensure the information security of the enterprise's core data assets and prevent information leakage has become the primary problem to be solved.

[0003] To prevent information leakage, virtual machine disk encryption is usually adopted. In this method, the plaintext of the virtual disk is encrypted into the ciphertext of the virtual disk by using a symmetric key, and then the data is stored. To ensure the security of the key, the encryption key is saved by a separate key management system KMS (Key Management System). When the cloud platform connects to the KMS, it needs to be authenticated by the KMS before obtaining the relevant key. The mainstream KMS system usually performs authentication in the Server (server side) + Client (client side) manner, that is, the KMS serves as the Server side, and the cloud platform serves as the Client side for network connection. The cloud platform must present the Client certificate downloaded from the KMS system to pass the authentication.

[0004] However, this authentication method for unidirectionally authenticating the identity of the Client side can well support the 1+1 (that is, only 1 KMS system is configured under 1 cloud platform) application scenario. However, there are many problems in the 1+N (that is, 1 cloud platform is configured with N KMS systems, N>1) application scenario. When the cloud platform obtains the key corresponding to a certain virtual machine from the first KMS system, the virtual machine in the cloud platform uses the corresponding key to encrypt and store the virtual disk. For example, if the administrator configures the Client certificate of the second KMS system, when the cloud platform decrypts the above virtual machine, it will obtain the key corresponding to the virtual machine from the second KMS system. The second KMS system will consider this request as a new key request, so the second KMS system will create another brand-new key and return it to the cloud platform (the key management system will query the key ID. When the key ID does not exist, it will create the key and then return it to the cloud platform). However, this brand-new key is definitely different from the key created by the original first KMS, so the decryption of the virtual machine will not succeed. If forced decryption is performed, it may also cause the loss of the original encrypted data. Summary of the Invention

[0005] In order to solve the problems existing in the prior art, the present invention innovatively proposes a virtual machine encryption method, device, equipment and medium in a cloud platform, effectively solving the problem that after the virtual machine in the cloud platform is encrypted, the key is obtained from a non-associated KMS system in the prior art, resulting in incorrect encryption and decryption of data, and effectively improving the availability of virtual machine encryption in the cloud platform.

[0006] In the first aspect of the present invention, a virtual machine encryption method in a cloud platform is provided, including:

[0007] Construct a KMS system pool, and configure multiple verified KMS systems in the KMS system pool;

[0008] Create a number of encryption policies, and each encryption policy is bound to one verified KMS system in the KMS system pool;

[0009] The virtual machine to be encrypted in the cloud platform selects an encryption policy from all encryption policies and binds the selected encryption policy to the virtual machine to be encrypted;

[0010] Obtain a symmetric encryption key from the KMS system bound by the selected encryption policy, and encrypt all virtual disks of the virtual machine to be encrypted.

[0011] Optionally, constructing a KMS system pool, and configuring multiple verified KMS systems in the KMS system pool specifically includes:

[0012] Obtain the input KMS system information, and the KMS system information at least includes the Client certificate;

[0013] Create a symmetric key on the currently input KMS system, encrypt the preset eigenvalue with the created symmetric key to obtain the ciphertext, and decrypt the ciphertext with the symmetric key to obtain the plaintext. Check whether the plaintext is the same as the preset eigenvalue. If it is the same, the verification passes; if it is different, an error is prompted;

[0014] After the verification passes, calculate the hash value of the Client certificate in the currently input KMS system. Taking the calculated hash value as a characteristic condition, query whether there is a corresponding storage record in the KMS system database in the KMS system pool. If not, add the currently input KMS system information record to the database; if there is a corresponding storage record, give an error prompt.

[0015] Further, the KMS system information further includes the IP information and port information of the KMS system. The IP information is used to determine the KMS system, and the port information is used for KMS system communication.

[0016] Optionally, create a number of encryption policies, and bind each encryption policy to a verified KMS system in the KMS system pool, which specifically includes:

[0017] Create a number of encryption policies, and according to the input information of the system administrator, bind a KMS system to each encryption policy in the KMS system pool;

[0018] According to the input information of the system administrator, bind a storage domain to each encryption policy from the storage pool, and all disks of a number of virtual machines to be encrypted are included in the storage domain;

[0019] Name the encryption policies, and form a list of encryption policies created for virtual machines to be encrypted under the cloud platform to select.

[0020] Furthermore, a virtual machine to be encrypted in the cloud platform selects an encryption policy from all encryption policies, and binding the selected encryption policy to the virtual machine to be encrypted specifically includes:

[0021] When encrypting the virtual machine to be encrypted in the cloud platform, determine an encryption policy according to the input information of the system administrator;

[0022] Check whether all disks of the virtual machine to be encrypted are located in the storage domain corresponding to the determined encryption policy;

[0023] If all are located, check whether the host where the virtual machine to be encrypted is located can communicate with the KMS system bound by the determined encryption policy. If communication can be established, bind the selected encryption policy to the virtual machine to be encrypted.

[0024] Optionally, it further includes:

[0025] When decrypting the encrypted virtual machine, the host where the encrypted virtual machine is located obtains the symmetric key from the KMS system bound by the encryption policy during encryption, and decrypts all virtual disks of the encrypted virtual machine.

[0026] Optionally, the encryption policy supports update operations, and the update operations include but are not limited to addition, modification, and deletion.

[0027] The second aspect of the present invention provides a virtual machine encryption device in a cloud platform, including:

[0028] A construction module that constructs a KMS system pool, and multiple verified KMS systems are configured in the KMS system pool;

[0029] A first binding module that creates a number of encryption policies, and binds each encryption policy to a verified KMS system in the KMS system pool;

[0030] The second binding module, where the virtual machine to be encrypted in the cloud platform selects an encryption policy from all encryption policies and binds the selected encryption policy to the virtual machine to be encrypted;

[0031] The encryption module obtains a symmetric encryption key from the KMS system bound corresponding to the selected encryption policy and encrypts all virtual disks of the virtual machine to be encrypted.

[0032] The third aspect of the present invention provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of a virtual machine encryption method in a cloud platform as described in the first aspect of the present invention when executing the computer program.

[0033] The fourth aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of a virtual machine encryption method in a cloud platform as described in the first aspect of the present invention are implemented.

[0034] The technical solutions adopted by the present invention include the following technical effects:

[0035] 1. In the present invention, the encryption policy is bound to the KMS system and the virtual machine to be encrypted respectively, enabling multiple KMS systems to be used simultaneously in the cloud platform, preventing the virtual machine to be encrypted in the cloud platform from obtaining keys from non-bound associated KMS systems, avoiding the scenario where data cannot be decrypted, and also enabling multiple manufacturers' KMS systems to be configured simultaneously in the cloud platform, improving the compatibility and availability of the cloud platform.

[0036] 2. In the technical solution of the present invention, multiple verified KMS systems are configured in the KMS system pool. After verification, the hash value of the Client certificate in the currently input KMS system is calculated. Taking the calculated hash value as a characteristic condition, it is queried whether there is a corresponding storage record in the KMS system database in the KMS system pool. If not, the information record of the currently input KMS system is newly added to the database, ensuring that all KMS systems in the KMS system pool are directly usable KMS systems and facilitating the query and acquisition of KMS systems.

[0037] 3. In the technical solution of the present invention, according to the input information of the system administrator, a storage domain is bound to each encryption policy from the storage pool, and the encryption policy is named. The created several encryption policies are formed into an encryption policy list for the virtual machine to be encrypted in the cloud platform to select, facilitating the determination of the encryption policy of the virtual machine to be encrypted according to the input information of the system administrator.

[0038] 4. The encryption policy in the technical solution of the present invention supports update operations, including but not limited to addition, modification, and deletion, ensuring the availability and reliability of the encryption policy.

[0039] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0041] Figure 1 It is a flowchart of the method of Embodiment 1 in the solution of the present invention;

[0042] Figure 2 It is a flowchart of step S1 in the method of Embodiment 1 in the solution of the present invention;

[0043] Figure 3 It is a flowchart of step S2 in the method of Embodiment 1 in the solution of the present invention;

[0044] Figure 4 It is a flowchart of step S3 in the method of Embodiment 1 in the solution of the present invention;

[0045] Figure 5 It is another flowchart of the method of Embodiment 1 in the solution of the present invention;

[0046] Figure 6 It is a structural diagram of the device of Embodiment 2 in the solution of the present invention;

[0047] Figure 7 It is another structural diagram of the device of Embodiment 2 in the solution of the present invention;

[0048] Figure 8 It is a structural diagram of the device of Embodiment 3 in the solution of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] In order to clearly illustrate the technical features of this solution, the present invention will be described in detail below through specific embodiments and in combination with its drawings. The following disclosure provides many different embodiments or examples for implementing different structures of the present invention. To simplify the disclosure of the present invention, the components and settings of specific examples are described below. In addition, the present invention may repeat reference numerals and / or letters in different examples. This repetition is for the purpose of simplification and clarity, and does not itself indicate the relationship between the various embodiments and / or settings discussed. It should be noted that the components illustrated in the drawings are not necessarily drawn to scale. The present invention omits the description of well-known components and processing techniques and processes to avoid unnecessarily limiting the present invention.

[0050] Embodiment 1

[0051] As Figure 1 shown, the present invention provides a virtual machine encryption method in a cloud platform, including:

[0052] S1. Construct a KMS system pool, and configure multiple verified KMS systems in the KMS system pool;

[0053] S2. Create several encryption policies, and bind each encryption policy to one verified KMS system in the KMS system pool;

[0054] S3. The virtual machine to be encrypted in the cloud platform selects an encryption policy from all the encryption policies, and binds the selected encryption policy to the virtual machine to be encrypted;

[0055] S4. Obtain a symmetric encryption key from the KMS system corresponding to the selected encryption policy, and encrypt all the virtual disks of the virtual machine to be encrypted.

[0056] Among them, as Figure 2 shown, step S1 specifically includes:

[0057] S11. Obtain the input KMS system information, and the KMS system information at least includes a Client certificate;

[0058] S12. Create a symmetric key on the currently input KMS system, encrypt a preset eigenvalue with the created symmetric key to obtain a ciphertext, and decrypt the ciphertext with the symmetric key to obtain a plaintext;

[0059] S13. Check whether the plaintext is the same as the preset eigenvalue. If the check result is yes, execute step S14. If the check result is no, execute step S15;

[0060] S14. Then the check passes;

[0061] S15. Prompt an error;

[0062] S16. After the check passes, calculate the hash value of the Client certificate in the currently input KMS system, and query whether there is a corresponding storage record in the KMS system database in the KMS system pool based on the calculated hash value as a characteristic condition. If the query result is yes, execute step S17. If the query result is no, execute step S18;

[0063] S17. Give an error prompt.

[0064] S18. Then add a record of the currently input KMS system information to the database.

[0065] Among them, in step S11, the KMS system information includes, in addition to the Client certificate, the IP information and port information of the KMS system. The IP information is used to determine the KMS system, and the port information is used for communication with the KMS system.

[0066] In step S12, the preset eigenvalue can be a fixed string, such as "1qaz@WSX", or other forms such as numbers, symbols, or a combination of multiple forms. The present invention does not limit this here.

[0067] In step S16, the hash value of the Client certificate can be the SHA56 (a hash function) hash value, or other forms of hash values. The present invention does not limit this here.

[0068] In steps S15 and S17, after an error is prompted, the current interface is exited, and the user or system administrator re-enters the KMS system information.

[0069] Through steps S11 - S18, it can be realized that multiple available verified KMS systems are configured in the KMS system pool.

[0070] As Figure 3 shown, step S2 specifically includes:

[0071] S21, create several encryption policies, and bind a KMS system to each encryption policy in the KMS system pool according to the input information of the system administrator;

[0072] S22, according to the input information of the system administrator, bind a storage domain to each encryption policy from the storage pool. The storage domain includes all the disks of several virtual machines to be encrypted.

[0073] S23, name the encryption policies, and form a list of encryption policies created for the virtual machines to be encrypted under the cloud platform to select.

[0074] Among them, in step S21, an association mapping relationship is established between the encryption policy and a KMS system in the KMS system pool, that is, the encryption policy is bound to a KMS system in the KMS system pool.

[0075] In step S23, the encryption policies in the encryption policy list can support update operations, that is, including but not limited to addition, modification, deletion, etc.

[0076] As Figure 4 shown, step S3 specifically includes:

[0077] S31, when encrypting the virtual machines to be encrypted in the cloud platform, determine an encryption policy according to the input information of the system administrator;

[0078] S32. Check whether all disks of the virtual machine to be encrypted are located in the storage domain corresponding to the determined encryption policy. If the check result is yes, execute step S33; if the check result is no, execute step S34;

[0079] S33. Check whether the host machine where the virtual machine to be encrypted is located can communicate with the KMS system bound to the determined encryption policy. If the check result is yes, execute step S35; if the check result is no, execute step S36;

[0080] S34. Prompt that not all disks of the virtual machine to be encrypted are located in the storage domain corresponding to the determined encryption policy, and exit;

[0081] S35. Bind the selected encryption policy to the virtual machine to be encrypted;

[0082] S36. Prompt that the host machine where the virtual machine to be encrypted is located cannot communicate with the KMS system bound to the determined encryption policy, and exit.

[0083] Further, as Figure 5 shown, a virtual machine encryption method provided by the technical solution of the present invention further includes:

[0084] S5. When decrypting the encrypted virtual machine, the host machine where the encrypted virtual machine is located obtains the symmetric key from the KMS system bound to the encryption policy during encryption, and decrypts all virtual disks of the encrypted virtual machine.

[0085] It should be noted that steps S1 - S5 in the technical solution of the present invention can all be implemented by hardware or software language programming, and the implementation idea corresponds to the steps. It can also be implemented by other means, and the present invention does not make any restrictions here.

[0086] The present invention binds the encryption policy to the KMS system and the virtual machine to be encrypted respectively, enabling multiple KMS systems to be used simultaneously in the cloud platform, preventing the virtual machine to be encrypted in the cloud platform from obtaining the key from a non - bound associated KMS system, avoiding the scenario where data cannot be decrypted, and also enabling multiple manufacturers' KMS systems to be configured simultaneously in the cloud platform, improving the compatibility and availability of the cloud platform.

[0087] In the technical solution of the present invention, multiple verified KMS systems are configured in the KMS system pool. After verification, calculate the hash value of the Client certificate in the currently input KMS system. Using the calculated hash value as a characteristic condition, query whether there is a corresponding storage record in the KMS system database in the KMS system pool. If not, add the information record of the currently input KMS system to the database, ensuring that all KMS systems in the KMS system pool are directly usable KMS systems and facilitating the query and acquisition of KMS systems.

[0088] In the technical solution of the present invention, according to the input information of the system administrator, a storage domain is bound to each encryption policy from the storage pool, and the encryption policy is named. A number of created encryption policies are formed into an encryption policy list for the virtual machines to be encrypted under the cloud platform to select, which is convenient to determine the encryption policy of the virtual machines to be encrypted according to the input information of the system administrator.

[0089] In the technical solution of the present invention, the encryption policy supports update operations, including but not limited to adding, modifying, and deleting, which ensures the availability and reliability of the encryption policy.

[0090] Embodiment 2

[0091] As Figure 6 shown, the technical solution of the present invention also provides a virtual machine encryption device in a cloud platform, including:

[0092] A construction module 101 constructs a KMS system pool, and a plurality of verified KMS systems are configured in the KMS system pool;

[0093] A first binding module 102 creates a number of encryption policies, and each encryption policy is bound to one verified KMS system in the KMS system pool;

[0094] A second binding module 103 allows the virtual machines to be encrypted in the cloud platform to select an encryption policy from all the encryption policies and binds the selected encryption policy to the virtual machines to be encrypted;

[0095] An encryption module 104 obtains a symmetric encryption key from the KMS system corresponding to the selected encryption policy and encrypts all the virtual disks of the virtual machines to be encrypted.

[0096] Further, as Figure 7 shown, a virtual machine encryption method in a cloud platform provided by the technical solution of the present invention further includes:

[0097] A decryption module 105, when decrypting the encrypted virtual machine, the host machine where the encrypted virtual machine is located obtains the symmetric key from the KMS system bound by the encryption policy during encryption and decrypts all the virtual disks of the encrypted virtual machine.

[0098] The present invention binds the encryption policy to the KMS system and the virtual machines to be encrypted respectively, so that multiple KMS systems can be used simultaneously under the cloud platform, preventing the virtual machines to be encrypted under the cloud platform from obtaining keys from non-bound and associated KMS systems, avoiding the scenario where data cannot be decrypted, and at the same time enabling multiple manufacturers' KMS systems to be configured simultaneously under the cloud platform, improving the compatibility and availability of the cloud platform.

[0099] In the technical solution of the present invention, multiple verified KMS systems are configured in the KMS system pool. After passing the verification, the hash value of the Client certificate in the currently input KMS system is calculated. Using the calculated hash value as a characteristic condition, it is queried whether there is a corresponding storage record in the KMS system database in the KMS system pool. If not, the information record of the currently input KMS system is newly added to the database, ensuring that multiple KMS systems in the KMS system pool are all directly usable KMS systems and facilitating the query and acquisition of KMS systems.

[0100] In the technical solution of the present invention, according to the input information of the system administrator, a storage domain is bound to each encryption policy from the storage pool, and the encryption policy is named. The created several encryption policies are formed into an encryption policy list for the virtual machines to be encrypted under the cloud platform to select, facilitating the determination of the encryption policy of the virtual machines to be encrypted according to the input information of the system administrator.

[0101] The encryption policy in the technical solution of the present invention supports update operations, including but not limited to addition, modification, and deletion, ensuring the availability and reliability of the encryption policy.

[0102] Embodiment III

[0103] As Figure 8 shown, the technical solution of the present invention also provides an electronic device, including: a memory 201 for storing a computer program; a processor 202 for implementing the steps of a virtual machine encryption method in a cloud platform as in Embodiment I when executing the computer program.

[0104] The memory 201 in the embodiments of the present application is used to store various types of data to support the operation of the electronic device. Examples of such data include: any computer program for operating on the electronic device. It can be understood that the memory 201 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache.By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), sync link dynamic random access memory (SLDRAM), direct rambus random access memory (DRRAM). The memory 201 described in the embodiments of the present application is intended to include but not limited to these and any other suitable types of memory. The methods disclosed in the embodiments of the present application above can be applied to or implemented by the processor 202. The processor 202 may be an integrated circuit chip with signal processing capabilities. In the implementation process, the steps of the above methods can be completed by the integrated logic circuit of the hardware in the processor 202 or instructions in the form of software. The above processor 202 may be a general-purpose processor, a DSP (Digital Signal Processing, that is, a chip capable of implementing digital signal processing technology), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 202 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. Combining the steps of the methods disclosed in the embodiments of the present application, it can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module may be located in the storage medium, and this storage medium is located in the memory 201. The processor 202 reads the program in the memory 201 and combines its hardware to complete the steps of the foregoing methods. When the processor 202 executes the program, the corresponding processes in the various methods of the embodiments of the present application are implemented. For the sake of brevity, they are not described herein again.

[0105] The present invention binds an encryption policy to a KMS system and a virtual machine to be encrypted respectively, enabling multiple KMS systems to be used simultaneously in a cloud platform, preventing the virtual machine to be encrypted in the cloud platform from obtaining keys from a KMS system that is not bound and associated, avoiding the scenario where data cannot be decrypted, and also enabling multiple manufacturers' KMS systems to be configured simultaneously in the cloud platform, improving the compatibility and availability of the cloud platform.

[0106] In the technical solution of the present invention, multiple verified KMS systems are configured in a KMS system pool. After passing the verification, the hash value of the Client certificate in the currently input KMS system is calculated. Using the calculated hash value as a characteristic condition, it is queried whether there is a corresponding storage record in the KMS system database in the KMS system pool. If not, the information record of the currently input KMS system is newly added to the database, ensuring that multiple KMS systems in the KMS system pool are all directly usable KMS systems and facilitating the query and acquisition of KMS systems.

[0107] In the technical solution of the present invention, according to the input information of the system administrator, a storage domain is bound to each encryption policy from a storage pool, and the encryption policy is named. The created encryption policies are formed into an encryption policy list for the virtual machine to be encrypted in the cloud platform to select, facilitating the determination of the encryption policy for the virtual machine to be encrypted according to the input information of the system administrator.

[0108] The encryption policy in the technical solution of the present invention supports update operations, including but not limited to addition, modification, and deletion, ensuring the availability and reliability of the encryption policy.

[0109] Embodiment 4

[0110] The technical solution of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of a virtual machine encryption method in a cloud platform as in Embodiment 1 are implemented.

[0111] For example, it includes a memory 201 storing a computer program, and the above computer program can be executed by a processor 202 to complete the steps of the foregoing method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.

[0112] Those of ordinary skill in the art can understand that all or part of the steps to implement the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes: various media such as removable storage devices, ROM, RAM, magnetic disks, or optical discs that can store program codes. Alternatively, if the above integrated units of the present application are implemented in the form of software function modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable an electronic device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in various embodiments of the present application. And the foregoing storage medium includes: various media such as removable storage devices, ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0113] The present invention binds the encryption policy to the KMS system and the virtual machine to be encrypted respectively, enabling multiple KMS systems to be used simultaneously under the cloud platform, preventing the virtual machine to be encrypted under the cloud platform from obtaining keys from a non-bound associated KMS system, avoiding the scenario where data cannot be decrypted, and at the same time enabling multiple manufacturers' KMS systems to be configured simultaneously under the cloud platform, improving the compatibility and availability of the cloud platform.

[0114] In the technical solution of the present invention, multiple verified KMS systems are configured in the KMS system pool. After passing the verification, calculate the hash value of the Client certificate in the currently input KMS system. Using the calculated hash value as a characteristic condition, query whether there is a corresponding storage record in the KMS system database in the KMS system pool. If not, add the information record of the currently input KMS system to the database, ensuring that multiple KMS systems in the KMS system pool are all directly usable KMS systems and facilitating the query and acquisition of KMS systems.

[0115] In the technical solution of the present invention, according to the input information of the system administrator, a storage domain is bound to each encryption policy from the storage pool, and the encryption policy is named. The created several encryption policies are formed into an encryption policy list for the virtual machine to be encrypted under the cloud platform to select, facilitating the determination of the encryption policy of the virtual machine to be encrypted according to the input information of the system administrator.

[0116] The encryption policy in the technical solution of the present invention supports update operations, including but not limited to addition, modification, and deletion, ensuring the availability and reliability of the encryption policy.

[0117] Although the specific embodiments of the present invention have been described above in conjunction with the accompanying drawings, it is not a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications or deformations that can be made without creative efforts based on the technical solutions of the present invention are still within the protection scope of the present invention.

Claims

1. A virtual machine encryption method in a cloud platform, characterized in that Including: Construct a KMS system pool, in which multiple verified KMS systems are configured; Create a number of encryption policies, and each encryption policy is bound to one verified KMS system in the KMS system pool; among them, creating a number of encryption policies, and each encryption policy is bound to one verified KMS system in the KMS system pool specifically includes: Create a number of encryption policies, and according to the input information of the system administrator, bind a KMS system in the KMS system pool for each encryption policy; According to the input information of the system administrator, bind a storage domain for each encryption policy from the storage pool, and all disks of a number of virtual machines to be encrypted are included in the storage domain; Name the encryption policies, and form a list of encryption policies composed of the created number of encryption policies for the virtual machines to be encrypted under the cloud platform to select; The virtual machines to be encrypted in the cloud platform select an encryption policy from all the encryption policies, and bind the selected encryption policy to the virtual machines to be encrypted; among them, the virtual machines to be encrypted in the cloud platform select an encryption policy from all the encryption policies, and bind the selected encryption policy to the virtual machines to be encrypted specifically includes: When encrypting the virtual machines to be encrypted in the cloud platform, determine an encryption policy according to the input information of the system administrator; Check whether all the disks of the virtual machines to be encrypted are located in the storage domain corresponding to the determined encryption policy; If all are located, check whether the host where the virtual machines to be encrypted are located can communicate with the KMS system bound by the determined encryption policy. If communication is possible, bind the selected encryption policy to the virtual machines to be encrypted; Obtain the symmetric encryption key on the KMS system corresponding to the selected encryption policy, and encrypt all the virtual disks of the virtual machines to be encrypted.

2. The virtual machine encryption method in a cloud platform according to claim 1, characterized in that, Construct a KMS system pool, and the specific inclusion of configuring multiple verified KMS systems in the KMS system pool includes: Obtain the input KMS system information, and the KMS system information at least includes the Client certificate; Create a symmetric key on the currently input KMS system, encrypt the preset eigenvalue with the created symmetric key to obtain the ciphertext, and decrypt the ciphertext with the symmetric key to obtain the plaintext. Check whether the plaintext is the same as the preset eigenvalue. If the same, the verification passes; if different, an error is prompted; After the verification passes, calculate the hash value of the Client certificate in the currently input KMS system, and use the calculated hash value as the characteristic condition to query whether there is a corresponding storage record in the KMS system database in the KMS system pool. If not, add the current input KMS system information record to the database; if there is a corresponding storage record, an error prompt is given.

3. The virtual machine encryption method in a cloud platform according to claim 2, characterized in that, The KMS system information further includes the IP information and port information of the KMS system. The IP information is used to determine the KMS system, and the port information is used for KMS system communication.

4. A virtual machine encryption method in a cloud platform according to any one of claims 1-3, characterized in that, further Including: When decrypting the encrypted virtual machines, the host where the encrypted virtual machines are located obtains the symmetric key from the KMS system bound by the encryption policy during encryption, and decrypts all the virtual disks of the encrypted virtual machines.

5. A virtual machine encryption method in a cloud platform according to any one of claims 1-3, characterized in that The encryption policy supports update operations, and the update operations include addition, modification, and deletion.

6. A virtual machine encryption device in a cloud platform, characterized in that It includes: A construction module that constructs a KMS system pool, and multiple verified KMS systems are configured in the KMS system pool; A first binding module that creates several encryption policies, and each encryption policy is bound to one verified KMS system in the KMS system pool; among them, creating several encryption policies, and each encryption policy is bound to one verified KMS system in the KMS system pool specifically includes: Create several encryption policies, and according to the input information of the system administrator, bind a KMS system in the KMS system pool to each encryption policy; According to the input information of the system administrator, bind a storage domain to each encryption policy from the storage pool, and all disks of several virtual machines to be encrypted are included in the storage domain; Name the encryption policies, and form a list of encryption policies composed of the created several encryption policies for the virtual machines to be encrypted under the cloud platform to select; A second binding module, a virtual machine to be encrypted in the cloud platform selects an encryption policy from all encryption policies and binds the selected encryption policy to the virtual machine to be encrypted; among them, a virtual machine to be encrypted in the cloud platform selects an encryption policy from all encryption policies and binds the selected encryption policy to the virtual machine to be encrypted specifically includes: When the virtual machine to be encrypted in the cloud platform is encrypted, determine an encryption policy according to the input information of the system administrator; Check whether all disks of the virtual machine to be encrypted are located in the storage domain corresponding to the determined encryption policy; If all are located, check whether the host where the virtual machine to be encrypted is located can communicate with the KMS system bound to the determined encryption policy. If it can communicate, bind the selected encryption policy to the virtual machine to be encrypted; An encryption module that obtains a symmetric encryption key from the KMS system corresponding to the selected encryption policy and encrypts all virtual disks of the virtual machine to be encrypted.

7. An electronic device, characterized in that, It includes: A memory for storing computer programs; A processor, when executing the computer program, implements the steps of a virtual machine encryption method in a cloud platform as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by the processor, it implements the steps of a virtual machine encryption method in a cloud platform as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Password resource pool system, encryption method, electronic device and storage medium

    CN111245813A

  • Data processing method and device based on cloud platform and computer program

    CN111818032A