An application container key management platform
By designing the application container key management platform, the problem of configuration information leakage during use of the application container is solved, the encryption and security management of container parameters are realized, and the security of the application container is enhanced.
Patent Information
- Application Number
- CN202111313045.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-08
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2041-11-08
AI Technical Summary
The application container is easily stolen during use, resulting in product information leakage.
Design an application container key management platform, including model acquisition module, information acquisition module and configuration acquisition module. The platform ensures the security of configuration information by generating application container models, obtaining and encrypting container parameters, configuring modification conditions, and managing them.
Effectively prevent the leakage of application container configuration information, ensure the security of product information, and enhance the security of application containers.
Smart Images

Figure CN114139115B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information encryption, and particularly to an application container key management platform. Background Art
[0002] Currently, the application container technology is a Docker container engine service platform based on the infrastructure, covering the life cycle management such as development, testing, rehearsal, and online in the software development process, maintaining the rapid construction of the application system and the consistency of each environment. The container technology can handle the differences between different platforms, provide a standardized delivery method, unified configuration, unified environment, ensure efficiency, and effectively implement resource limitations. However, the application container technology is prone to being stolen of configuration information during use, and the security cannot be ensured. Summary of the Invention
[0003] The present invention provides an application container key management platform to solve the problem that the configuration information of the application container is easily stolen during use, thereby inferring product information and causing product leakage.
[0004] To achieve the above object, the present invention proposes an application container key management platform, including:
[0005] A model acquisition module, configured to acquire the prerequisite requirements of the application container and generate an application container model;
[0006] An information acquisition module, configured to acquire application container parameters according to the application container model, configure a key according to the model type of the application container model, and encrypt the application container parameters based on the key to generate data information;
[0007] A configuration acquisition module, configured to decrypt the data information, configure modification conditions for the decrypted information, and manage it.
[0008] Preferably, the model acquisition module includes:
[0009] A function acquisition sub-module, configured to acquire the function construction indexes of the application container based on the prerequisite requirements;
[0010] A model generation sub-module, configured to generate an application container model according to the function construction indexes.
[0011] Preferably, the information acquisition module includes:
[0012] A parameter acquisition sub-module, configured to acquire the application container parameters of the application container model, and at the same time, acquire the model configuration parameters of the application container model according to the model type;
[0013] A secret key generation sub-module, configured to generate a secret key that matches the model configuration parameters;
[0014] An encryption sub-module, configured to encrypt the application container parameters based on the secret key to generate data information.
[0015] Preferably, the configuration acquisition module includes:
[0016] An information reception sub-module, configured to receive the data information and decrypt the data information;
[0017] A configuration management sub-module, configured to determine the information type of the decrypted information, retrieve operation instructions related to the information type from a preset database, and execute corresponding operations.
[0018] Preferably, the secret key generation sub-module includes:
[0019] An information acquisition unit, configured to acquire the model configuration parameters of the application container model, analyze the model configuration parameters of the application container model, and generate analysis information;
[0020] Based on the analysis information, acquire differential configuration information that is different from the current configuration parameters of the application container, generate modification information, classify the modification information, and acquire parameter modification data;
[0021] A secret key generation unit, configured to acquire a secret key generation rule in a cloud database, and generate a corresponding secret key for encryption based on the secret key generation rule and the parameter modification data.
[0022] Preferably, the encryption sub-module includes:
[0023] An encryption unit, configured to set the secret key as a first encryption secret key, perform secondary encryption on the first encryption secret key based on a preset encryption public key to generate a second encryption secret key, and match a corresponding special mark in a cloud Internet database according to the key attribute of the second encryption secret key;
[0024] Based on the cloud Internet database, generate multiple misleading secret keys, and package the multiple misleading secret keys with the second encryption secret key with the special mark to generate a secret key package;
[0025] Encrypt the parameter modification data according to the first encryption secret key to generate encrypted data;
[0026] An information transmission unit, configured to generate data information based on the encrypted data and the secret key package and send it to the configuration acquisition module.
[0027] Preferably, the information reception sub-module includes:
[0028] A receiving unit, configured to receive data information and preprocess the data information according to a preprocessing method related to the model type, so as to obtain first data and a first packet;
[0029] A parsing unit, configured to perform sequence parsing on the first packet to obtain a first sequence;
[0030] A feature analysis unit, configured to extract features from the first sequence, obtain preset feature information in the first sequence, combine the preset feature information to generate a combined result set, assign comparison feature tags to each combined information in the combined result set, and compare with special tags corresponding to a second encryption key;
[0031] If the two tags are exactly the same, determine the tag position distribution of the comparison feature tag in the corresponding combined information, determine the distribution length corresponding to the tag position distribution, and retain it;
[0032] If the two tags are inconsistent, extract each pair of inconsistent tags, filter and retain the tag with a larger weight in each pair of inconsistent tags, determine the tag position distribution corresponding to the retained tag, obtain the corresponding distribution length for retention, and at the same time, obtain the distribution length corresponding to the tag position distribution of the comparison feature tag in the consistent tags in the corresponding combined information;
[0033] Construct a decryption method according to all the retained distribution lengths;
[0034] Perform decryption processing on the first data according to the decryption method;
[0035] Wherein, the first data is decrypted information.
[0036] Preferably, the configuration management sub-module further includes:
[0037] A data receiving unit, configured to receive parameter modification data obtained by the information receiving sub-module;
[0038] An instruction generation unit, configured to obtain the classification of the parameter modification data according to the parameter modification data, obtain, in a cloud Internet database, the operation steps corresponding to the process of modifying the data of the corresponding classification from the current parameter data to the parameter modification data, and generate an operation instruction;
[0039] An execution unit, configured to determine whether the operation instruction meets a preset constraint condition;
[0040] If the operation instruction meets the preset constraint condition, configure a public instruction modification condition related to the operation instruction, and perform corresponding modification on each configuration of the application container;
[0041] Otherwise, configure special instruction modification conditions to make corresponding modifications to the configurations of the application container.
[0042] Preferably, the application container key management platform further includes:
[0043] A channel detection module, used to detect the transmission condition of the data transmission channel when the information acquisition module sends data information to the configuration management module;
[0044] The channel detection module includes:
[0045] A signal acquisition sub-module, set at the end of the data transmission channel, used to receive the transmission data signal in the data transmission channel and generate a first signal to be processed;
[0046] A signal processing sub-module, used to process the first signal to be processed to obtain a noise signal, eliminate the noise signal, generate a denoised original signal, process the denoised original signal based on the maximum likelihood estimation criterion, and obtain a first processed signal;
[0047] Perform wavelet decomposition on the first processed signal based on a wavelet function to generate a preset number of decomposed signals, obtain the energy of each decomposed signal and generate a compensation factor for each decomposed signal, sort the compensation factors, select the median compensation factor to perform compensation processing on the first processed signal, generate a second processed signal, generate a delay value based on the maximum likelihood estimation criterion and the delay of the first processed signal relative to the second processed signal, and perform delay processing on the received second processed signal based on the delay value to obtain a first detection signal;
[0048] Obtain the baseband data of the data transmission channel according to the first detection signal;
[0049] Judge whether it is within the preset baseband data range in the baseband data;
[0050] If it is within, it is determined that the communication channel is qualified;
[0051] If it is not within, it is determined that the communication channel is unqualified, send a working instruction to the alarm module, and control the data repair sub-module to work;
[0052] The data repair sub-module is used to obtain the abnormal signal in the first detection signal, extract the abnormal information, and at the same time, establish a corresponding temporary space according to the information type of the abnormal information and store the abnormal information;
[0053] Based on the application container parameter information, determine a data repair function, and obtain a data repair algorithm that matches the data repair function from an Internet cloud database according to the data repair function, and based on the data repair algorithm, perform repair calculation on the sliced data in the temporary storage space to obtain repaired data;
[0054] Move the repaired data in the temporary storage space to the original position of the abnormal data, and replace the abnormal data.
[0055] Preferably, the model generation sub-module further includes:
[0056] A simulation unit, configured to construct metrics according to the functions of the application container, and simulate the situation of the container model in the working state;
[0057] A data acquisition unit, configured to acquire the operation data information of the container model in the working state, and judge the operation data to determine whether the operation data is normal;
[0058] If the operation data is normal, it is determined that this model can run normally;
[0059] If the operation data is abnormal, it is determined that the model data is abnormal and cannot run normally, and a work instruction is sent to the alarm unit;
[0060] The alarm unit is configured to receive the work instruction sent by the data acquisition unit and perform corresponding alarm operations according to the work instruction
[0061] Other features and advantages of the present invention will be described in the subsequent specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained by the structures specifically pointed out in the written specification, claims, and drawings.
[0062] The technical solution of the present invention will be further described in detail below through the drawings and embodiments. Description of the Drawings
[0063] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the drawings:
[0064] Figure 1 is a flowchart of an application container key management platform in an embodiment of the present invention;
[0065] Figure 2 is a flowchart of an application container key management platform in another embodiment of the present invention;
[0066] Figure 3A flowchart of an application container key management platform in another embodiment of the present invention;
[0067] Figure 4 A flowchart of an application container key management platform in another embodiment of the present invention. Detailed implementation manners
[0068] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only for the purpose of illustrating and explaining the present invention, and are not intended to limit the present invention.
[0069] Next, refer to Figures 1 to 4 to describe an application container key management platform proposed in an embodiment of the present invention.
[0070] Embodiment 1:
[0071] As Figure 1 shown, the present invention provides an application container key management platform, including:
[0072] A model acquisition module, configured to acquire the prerequisite requirements of the application container and generate an application container model;
[0073] An information acquisition module, configured to acquire application container parameters according to the application container model, configure keys according to the model type of the application container model, encrypt the application container parameters based on the keys, and generate data information;
[0074] A configuration acquisition module, configured to decrypt the data information, configure modification conditions for the decrypted information, and perform management.
[0075] In this embodiment, the application container is a Docker container engine service platform provided based on the infrastructure, covering the life cycle management such as development, testing, rehearsal, and online in the software development process; the prerequisite requirement is the functional requirement of the software developed for the application container;
[0076] The application container model is a simulation model generated according to the prerequisite requirements;
[0077] The container parameters are parameter information in the simulated application container model, such as configuration parameters and environment parameters;
[0078] The model type is the classification of the model, such as configuration management type, storage type, running type, etc.;
[0079] The configuration modification condition is the prerequisite condition information for modifying the configuration. For example, when the configuration parameters and environment parameters reach certain conditions, software with corresponding difficulty can be developed;
[0080] Beneficial effects of the above solution: The present invention can generate an application container simulation model according to the premise requirements, obtain application container parameters based on the simulation model, and modify the application container according to the configuration modification conditions obtained from the parameter information. The present invention can encrypt the application container parameters to prevent the leakage of application container parameters.
[0081] Embodiment 2:
[0082] Based on Embodiment 1, the model acquisition module further includes:
[0083] A function acquisition sub-module, configured to obtain function construction indicators of the application container based on the premise requirements;
[0084] A model generation sub-module, configured to generate an application container model according to the function construction indicators.
[0085] In this embodiment, the function construction indicators are key information for model construction obtained according to the premise requirements, such as the minimum efficiency requirements and costs of the developed software;
[0086] Beneficial effects of the above solution: The present invention can construct an application container model according to the premise requirements, facilitating the acquisition of simulation model data and subsequent processing.
[0087] Embodiment 3:
[0088] Based on Embodiment 1, as Figure 2 shown, the information acquisition module further includes:
[0089] A parameter acquisition sub-module, configured to obtain application container parameters of the application container model, and at the same time, obtain model configuration parameters of the application container model according to the model type;
[0090] A secret key generation sub-module, configured to generate a secret key matching the model configuration parameters;
[0091] An encryption sub-module, configured to perform encryption processing on the application container parameters based on the secret key to generate data information.
[0092] In this embodiment, the model configuration parameters are information on various configurations corresponding to the application container model parameters; encryption is the process of changing plaintext information into unreadable ciphertext to make it unreadable; the secret key represents the correspondence between the encrypted content and the original content;
[0093] Beneficial effects of the above solution: The present invention can obtain the configuration information of the model according to the application container parameters and model type of the container model, and generate a corresponding secret key for encryption according to the configuration information, improving the security of the application container configuration information and preventing the configuration information from being cracked.
[0094] Example 4:
[0095] Based on Example 1, the configuration acquisition module includes:
[0096] An information receiving sub-module, configured to receive the data information and perform decryption processing on the data information;
[0097] A configuration management sub-module, configured to determine the information type of the decrypted information, retrieve operation instructions related to the information type from a preset database, and execute corresponding operations.
[0098] In this embodiment, the data information is the information generated by the information acquisition module based on the encrypted data and the key package; the decryption processing is a process of converting an unreadable encrypted file into an original readable file based on the key;
[0099] Advantages of the above solution: The present invention can receive data information, perform decryption processing on the data information, and generate operation instructions according to the decrypted result, which can effectively ensure the accuracy of the instructions and ensure that the actual modification instructions match the original data information.
[0100] Example 5:
[0101] Based on Example 3, the key generation sub-module includes:
[0102] An information acquisition unit, configured to acquire the model configuration parameters of the application container model, analyze the model configuration parameters of the application container model, and generate analysis information;
[0103] Based on the analysis information, obtain difference configuration information that is different from the current configuration parameters of the application container, generate modification information, and classify the modification information to obtain parameter modification data;
[0104] A key generation unit, configured to obtain a key generation rule in the cloud database, and generate a corresponding key for encryption based on the key generation rule and the parameter modification data.
[0105] In this embodiment, the analysis information is the control relationship information representing the model configuration parameters of the application container model and the existing configuration parameters of the container obtained after analyzing the model configuration parameters; the modification information is the configuration type information that needs to be modified because the current configuration parameters of the application container do not match the model configuration parameters; the parameter modification data is the situation of the parameters that need to be modified, specifically the value that the parameter needs to be increased or decreased;
[0106] Beneficial effects of the above solution: The present invention can analyze the model configuration parameters, obtain modification data, and modify the application container configuration according to the modification data. It can visually express the modification situation of the container configuration and ensure that the configuration of the application container meets the preset requirements, avoiding the impact on normal use due to unqualified configuration.
[0107] Embodiment 6:
[0108] Based on Embodiment 3, the encryption sub-module includes:
[0109] An encryption unit, configured to set the secret key as the first encrypted secret key, perform secondary encryption on the first encrypted secret key based on a preset encryption public key to generate a second encrypted secret key, and match a corresponding special mark in the cloud Internet database according to the key attribute of the second encrypted secret key;
[0110] Based on the cloud Internet database, generate multiple misleading secret keys, and package the multiple misleading secret keys with the second encrypted secret key of the special mark to generate a secret key package;
[0111] Encrypt the parameter modification data according to the first encrypted secret key to generate encrypted data;
[0112] An information transmission unit, configured to generate data information based on the encrypted data and the secret key package and send it to the configuration acquisition module.
[0113] In this embodiment, the encryption public key is a pre-set key for encrypting the first encryption key; the special mark is a relatively hidden mark corresponding to the secret key, and different special marks are matched according to the secret key length to ensure that others cannot discover it; the misleading secret key is a secret key set to prevent the first encrypted secret key from being obtained and cannot correctly decrypt the encrypted text;
[0114] Beneficial effects of the above solution: The present invention can encrypt the secret key, prevent the secret key from being cracked, increase security, set special marks on the secret key, and set multiple misleading secret keys, reducing the probability of the real secret key being stolen and further enhancing security.
[0115] Embodiment 7:
[0116] Based on Embodiment 4, the information receiving sub-module includes:
[0117] A receiving unit, configured to receive data information and preprocess the data information according to a preprocessing method related to the model type to obtain first data and a first package;
[0118] An analysis unit, configured to perform sequence analysis on the first package to obtain a first sequence;
[0119] A feature analysis unit, configured to extract features from the first sequence, obtain preset feature information in the first sequence, combine the preset feature information to generate a combined result set, assign comparison feature tags to each combined information in the combined result set, and compare them with special tags corresponding to the second encryption key;
[0120] If the two tags are exactly the same, determine the tag position distribution of the comparison feature tag in the corresponding combined information, determine the distribution length corresponding to the tag position distribution, and retain it;
[0121] If the two tags are inconsistent, extract each pair of inconsistent tags, filter and retain the tag with a larger weight in each pair of inconsistent tags, determine the tag position distribution corresponding to the retained tags, obtain the corresponding distribution length and retain it. At the same time, obtain the distribution length corresponding to the tag position distribution of the comparison feature tag in the consistent tags in the corresponding combined information;
[0122] Construct a decryption method according to all the retained distribution lengths;
[0123] Decrypt the first data according to the decryption method;
[0124] Wherein, the first data is encrypted information.
[0125] In this embodiment, the preprocessing method is a data processing method preset according to the classification of the model; the first sequence is the sequence of all keys in the first packet; the feature information is the information of the special tags in the first sequence; the tag position distribution is the position distribution of the comparison feature tag in the first sequence; the distribution length is the length of the distribution positions corresponding to all the tags corresponding to each combined information, where one or more tags can be assigned to one combined information, which is called the comparison feature tag;
[0126] The beneficial effects of the above solution: The present invention can process data information to obtain the first packet and the first data, parse the first packet to obtain the first sequence, obtain special tag features in the first sequence and obtain a decryption method, and can quickly obtain the correct decryption method in the first packet, and can quickly complete the task on the premise of ensuring security, and has strong practicability.
[0127] Embodiment 8:
[0128] Based on Embodiment 4, the configuration management sub-module further includes:
[0129] A data receiving unit, configured to receive parameter modification data obtained by the information receiving sub-module;
[0130] An instruction generation unit, configured to modify data according to the parameter, obtain the classification of the parameter-modified data, obtain in a cloud Internet database the corresponding operation steps during the process of modifying the data of the corresponding classification from the current parameter data to the parameter-modified data, and generate an operation instruction;
[0131] An execution unit, configured to determine whether the operation instruction meets a preset constraint condition;
[0132] If the operation instruction meets the preset constraint condition, configure a common instruction modification condition related to the operation instruction, and make corresponding modifications to each configuration of the application container;
[0133] Otherwise, configure a special instruction modification condition, and make corresponding modifications to each configuration of the application container.
[0134] In this embodiment, the operation instruction is the operation steps required for modifying the configuration; the preset constraint condition is the configuration range obtained according to the hardware conditions of the application container; the common instruction modification condition is the fixed instruction modification condition obtained when the operation instruction meets the preset constraint condition; the special instruction modification condition is the special instruction modification condition generated by itself when the operation instruction does not meet the preset constraint condition;
[0135] Advantages of the above solution: The present invention generates an operation instruction for parameter-modified data and modifies the configuration of the application container according to the operation instruction. The present invention can obtain in the database the corresponding configuration modification conditions during the process of modifying the current parameter data to the parameter-modified data, and determine whether the operation instruction meets the constraint condition, ensuring the correctness of the modification operation and avoiding unnecessary losses caused by incorrect setting modifications.
[0136] Embodiment 9:
[0137] Based on Embodiment 1, as Figure 3 shown, the application container key management platform further includes:
[0138] A channel detection module, configured to detect the transmission condition of the data transmission channel when the information acquisition module sends data information to the configuration management module;
[0139] The channel detection module includes:
[0140] A signal acquisition sub-module, disposed at the end of the data transmission channel, configured to receive the transmission data signal in the data transmission channel and generate a first signal to be processed;
[0141] A signal processing sub-module, configured to process the first signal to be processed, obtain a noise signal, remove the noise signal, generate a denoised original signal, and process the denoised original signal based on the maximum likelihood estimation criterion to obtain a first processed signal;
[0142] Perform wavelet decomposition on the first processed signal based on a wavelet function to generate a preset number of decomposed signals. Obtain the energy of each decomposed signal and generate a compensation factor for each decomposed signal. Sort the compensation factors, select the median compensation factor, and perform compensation processing on the first processed signal to generate a second processed signal. Generate a delay value based on the maximum likelihood estimation criterion and the delay of the first processed signal relative to the second processed signal. Perform delay processing on the received second processed signal based on the delay value to obtain a first detection signal;
[0143] Obtain the baseband data of the data transmission channel according to the first detection signal;
[0144] Judge whether the baseband data is within a preset baseband data range;
[0145] If it is within the range, determine that the communication channel is qualified;
[0146] If it is not within the range, determine that the communication channel is unqualified, send a working instruction to the alarm module, and control the data repair sub-module to work;
[0147] The data repair sub-module is used to obtain the abnormal signal in the first detection signal and extract the abnormal information. At the same time, according to the information type of the abnormal information, establish a corresponding temporary storage space and store the abnormal information;
[0148] Based on the application container parameter information, determine a data repair function, obtain a data repair algorithm matching the data repair function from the Internet cloud database according to the data repair function, and perform repair calculation on the cut data in the temporary storage space based on the data repair algorithm to obtain repair data;
[0149] Move the repaired data in the temporary storage space to the original position of the abnormal data and replace the abnormal data.
[0150] In the above solution, the data transmission situation in the data transmission channel can also be obtained in real time, and according to the data transmission situation, estimate the number of packet forwarding times of the i-th node in the data transmission channel , and the calculation formula is as follows:
[0151]
[0152] where i is the i-th node in the data transmission channel; H is the total number of packets transmitted in the data transmission channel within a preset time period; is the maximum number of packets transmitted by the i-th node in a single transmission, is the minimum number of packets transmitted by the i-th node in a single transmission; The probability that the number of data packets transmitted for the \(i\)th node is the maximum number The probability that the number of data packets transmitted for the \(i\)th node is the minimum number; Represents the number of data packet forwarding times of the \(i\)th node;
[0153] where \(i\) is the \(i\)th node in the data transmission channel; \(H\) is the total number of data packets transmitted within the preset time period of the data transmission channel; Is the maximum number of data packets transmitted by the \(i\)th node in a single transmission, Is the minimum number of data packets transmitted by the \(i\)th node in a single transmission; The probability that the number of data packets transmitted for the \(i\)th node is the maximum number, The probability that the number of data packets transmitted for the \(i\)th node is the minimum number; Represents the number of data packet forwarding times of the \(i\)th node;
[0154]
[0155] where, Is the energy consumption when the \(i\)th node does not transmit data packets; Is the energy consumption when the \(i\)th node performs a single data packet transmission; Is the energy consumption when the \(i\)th node transmits data for a single fixed distance; \(p\) is the attenuation exponent during data transmission, with a value of 0.89; Is the error coefficient during data transmission; Is the loss coefficient during data transmission; \(e\) is the natural constant; \(n\) is the number of nodes in the node data transmission channel;
[0156] Judge whether the energy consumption \(N\) of each obtained node is within the preset energy consumption threshold range;
[0157] If it is, the data transmission channel operates normally;
[0158] If it is not, the data transmission channel is abnormal and an alarm is issued.
[0159] By calculating the number of data packet forwards of each node, the energy consumption of the nodes in the data transmission channel is calculated, preventing the energy consumption of data transmission from exceeding the standard due to abnormal data channels, reducing energy waste, and improving work efficiency.
[0160] In this embodiment, the data transmission channel is the data sending channel when the information acquisition module sends the acquired information; maximum likelihood estimation, also known as maximum probability estimation, is a theoretical point estimation method; baseband data is basic band data; the compensation factor is a factor that can have a gain effect on the first processed signal; the abnormal information is obtained after the abnormal signal is converted into information; the temporary storage space is a temporarily established temporary storage space for storing abnormal information.
[0161] Advantages of the above solution: The present invention can detect the data transmission situation in the data transmission channel in real time. When abnormal data is detected, the abnormal data can be temporarily stored, repaired, and the original abnormal data can be replaced, avoiding unnecessary losses caused by data anomalies due to data transmission errors and improving work efficiency.
[0162] Embodiment 10:
[0163] Based on Embodiment 2, as Figure 4 shown, the model generation sub-module further includes:
[0164] A simulation unit for constructing indicators according to the functions of the application container and simulating the situation of the container model in the working state;
[0165] A data acquisition unit for collecting the running data information of the container model in the working state and judging the running data to determine whether the running data is normal;
[0166] If the running data is normal, it is determined that this model can run normally;
[0167] If the running data is abnormal, it is determined that the model data is abnormal and cannot run normally, and a work instruction is sent to the alarm unit;
[0168] The alarm unit is used to receive the work instruction sent by the data acquisition unit and perform corresponding alarm operations according to the work instruction.
[0169] In this embodiment, the function construction index is the key information of the model function obtained according to the prerequisite requirements;
[0170] Advantages of the above solution: The present invention can simulate the model operation, obtain the data information of the model in the working state, and judge the data, preventing errors from occurring when modifying the application container data due to the model data not conforming to the actual situation and affecting the normal work.
[0171] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. An application container key management platform, characterized in that, it includes: A model acquisition module, which is used to acquire the prerequisite requirements of the application container and generate an application container model; An information acquisition module, which is used to acquire application container parameters according to the application container model, configure keys according to the model type of the application container model, encrypt the application container parameters based on the keys, and generate data information; A configuration acquisition module, which is used to decrypt the data information, configure modification conditions for the decrypted information, and manage it; The configuration acquisition module includes: An information receiving sub-module, which is used to receive the data information and decrypt the data information; A configuration management sub-module, which is used to determine the information type of the decrypted information, retrieve operation instructions related to the information type from a preset database, and execute corresponding operations; The information receiving sub-module includes: A receiving unit, which is used to receive data information, preprocess the data information according to a preprocessing method related to the model type, and obtain encrypted data and a key package; An analysis unit, which is used to perform sequence analysis on the key package to obtain a first sequence; A feature analysis unit, which is used to extract features from the first sequence, obtain preset feature information in the first sequence, combine the preset feature information to generate a combined result set, and assign comparison feature marks to each combined information in the combined result set, and compare with a special mark corresponding to a second encrypted key; the second encrypted key is a secondary encryption of a first encrypted key based on a preset encryption public key; according to the key attribute of the second encrypted key, match a corresponding special mark in a cloud Internet database; the first encrypted key is a key for encrypting data to be encrypted; If the two marks are exactly the same, determine the mark position distribution of the comparison feature mark in the corresponding combined information, determine the distribution length corresponding to the mark position distribution, and retain it; If the two marks are inconsistent, extract each pair of inconsistent marks, screen and retain the mark with a larger weight in each pair of inconsistent marks, determine the mark position distribution corresponding to the retained mark, obtain the corresponding distribution length and retain it, and at the same time, obtain the distribution length corresponding to the mark position distribution of the comparison feature mark in the consistent marks in the corresponding combined information; Construct a decryption method according to all the retained distribution lengths; Decrypt the encrypted data according to the decryption method.
2. An application container key management platform according to claim 1, characterized in that, the model acquisition module includes: A function acquisition sub-module, which is used to acquire the function construction indicators of the application container based on the prerequisite requirements; A model generation sub-module, which is used to generate an application container model according to the function construction indicators.
3. An application container key management platform according to claim 1, characterized in that, the information acquisition module includes: A parameter acquisition sub-module, which is used to acquire the application container parameters of the application container model, and at the same time, acquire the model configuration parameters of the application container model according to the model type; A secret key generation sub-module, which is used to generate a secret key that matches the model configuration parameters; An encryption sub-module, which is used to encrypt the application container parameters based on the secret key to generate data information.
4. An application container secret key management platform according to claim 3, characterized in that the secret key generation sub-module includes: An information acquisition unit, which is used to acquire the model configuration parameters of the application container model, analyze the model configuration parameters of the application container model, and generate analysis information; Based on the analysis information, obtain the differential configuration information that is different from the current configuration parameters of the application container, generate modification information, classify the modification information, and obtain parameter modification data; A secret key generation unit, which is used to obtain a secret key generation rule in the cloud database, and generate a corresponding secret key for encryption based on the secret key generation rule and the parameter modification data.
5. An application container secret key management platform according to claim 3, characterized in that the encryption sub-module includes: An encryption unit, which is used to set the secret key as the first encryption secret key, perform secondary encryption on the first encryption secret key based on a preset encryption public key, generate a second encryption secret key, and match a corresponding special mark in the cloud Internet database according to the secret key attribute of the second encryption secret key; Based on the cloud Internet database, generate a plurality of misleading secret keys, package the plurality of misleading secret keys and the second encryption secret key with the special mark to generate a secret key package; Encrypt the parameter modification data according to the first encryption secret key to generate encrypted data; An information transmission unit, which is used to generate data information based on the encrypted data and the secret key package and send it to the configuration acquisition module.
6. An application container secret key management platform according to claim 1, characterized in that the configuration management sub-module further includes: A data reception unit, which is used to receive the parameter modification data obtained by the information reception sub-module; An instruction generation unit, which is used to obtain the classification of the parameter modification data according to the parameter modification data, obtain in the cloud Internet database the operation steps corresponding to the process of modifying the corresponding classification data from the current parameter data to the parameter modification data, and generate an operation instruction; An execution unit, which is used to determine whether the operation instruction meets a preset constraint condition; If the operation instruction meets the preset constraint condition, configure the public instruction modification condition related to the operation instruction, and make corresponding modifications to each configuration of the application container; Otherwise, configure a special instruction modification condition and make corresponding modifications to each configuration of the application container.
7. An application container secret key management platform according to claim 1, characterized in that it further includes: A channel detection module, which is used to detect the data transmission situation in the data transmission channel when the information acquisition module sends data information to the configuration management module; The channel detection module includes: A signal acquisition sub-module, which is arranged at the end of the data transmission channel and is used to receive the transmission data signal in the data transmission channel and generate a first signal to be processed; A signal processing sub-module is used to process the first signal to be processed, obtain a noise signal, eliminate the noise signal, generate a denoised original signal, and process the denoised original signal based on the maximum likelihood estimation criterion to obtain a first processed signal; Perform wavelet decomposition on the first processed signal based on a wavelet function to generate a preset number of decomposed signals, obtain the energy of each decomposed signal and generate a compensation factor for each decomposed signal, sort the compensation factors, select the median compensation factor to perform compensation processing on the first processed signal to generate a second processed signal, generate a delay value based on the maximum likelihood estimation criterion and the delay of the first processed signal relative to the second processed signal, and perform delay processing on the received second processed signal based on the delay value to obtain a first detection signal; Obtain the baseband data of the data transmission channel according to the first detection signal; Judge whether it is within a preset baseband data range in the baseband data; If it is within, determine that the communication channel is qualified; If it is not within, determine that the communication channel is unqualified, send a working instruction to the alarm module, and control the data repair sub-module to work; The data repair sub-module is used to obtain the abnormal signal in the first detection signal, extract the abnormal information, and at the same time, establish a corresponding temporary storage space according to the information type of the abnormal information and store the abnormal information; Determine a data repair function based on the application container parameter information, obtain a data repair algorithm matching the data repair function in the Internet cloud database according to the data repair function, and perform repair calculation on the cut data in the temporary storage space based on the data repair algorithm to obtain repair data; Move the repaired data in the temporary storage space to the original position of the abnormal information and replace the abnormal information.
8. As described in claim 2, an application container key management platform, characterized in that, The model generation sub-module further includes: A simulation unit for constructing indexes according to the functions of the application container and simulating the situation of the container model in the working state; A data acquisition unit for acquiring the operation data information of the container model in the working state and judging the operation data to judge whether the operation data is normal; If the operation data is normal, determine that this model can run normally; If the operation data is abnormal, determine that the model data is abnormal and cannot run normally, and send a working instruction to the alarm unit; The alarm unit is used to receive the working instruction sent by the data acquisition unit and perform corresponding alarm operations according to the working instruction.
Citation Information
Patent Citations
Application deployment method and device of PaaS platform, server and storage medium
CN108551487A
Configuration information transmission method, transmission system thereof and storage device
CN110933035A
Data security storage method and system
CN112804195A