Container encryption method, device, electronic device and storage medium

By using the built-in key in the container to decrypt the container file directory and mount it to a non-encrypted path, combined with periodic access to the masquerade path, the problem of key asset protection in the container is solved and the security of container assets is improved.

CN114329531BActive Publication Date: 2025-05-13NSFOCUS INFORMATION TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202111568309.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-21
Publication Date
2025-05-13
Estimated Expiration
2041-12-21

AI Technical Summary

Technical Problem

In container technology, how to effectively protect critical assets within a container from access and attacks by malicious users, especially when container data is usually stored in non-encrypted paths.

Method used

By decrypting the preset encrypted container file directory with the built-in first key while the container is running, the decrypted container file directory is obtained and mounted to the preset non-encrypted path. At the same time, use the masquerade path to overwrite the non-encrypted path and periodically access the masquerade path to increase security.

Benefits of technology

This method provides an additional layer of protection for files in the container, preventing malicious users from accessing the decrypted non-encrypted path, thereby improving the security of container assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114329531B_ABST
    Figure CN114329531B_ABST
Patent Text Reader

Abstract

The present application relates to the field of container security technology, and in particular to a container encryption method, device, electronic device and storage medium. When determining that a container is running, a preset encrypted container file directory is decrypted using a built-in first key to obtain a decrypted container file directory; the container file directory is mounted to a preset non-encrypted path, wherein the non-encrypted path is used to present an unencrypted container file directory; a disguised path is used to cover the non-encrypted path, and the disguised path is periodically accessed, so that the security of the container file can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of container security technology, and in particular to a container encryption method, device, electronic device and storage medium. Background Art

[0002] With the development of the network, container technology can be applied to many different fields, such as cloud-native scenarios. Through container technology, an isolated operating environment can be provided for applications.

[0003] In the actual application of container products, the open environment based on containers brings corresponding asset protection requirements. How to ensure the security of data in the container and how to implement encryption protection of files in the container have become urgent issues to be solved.

[0004] In related technologies, container data is generally stored in an unencrypted path. When a malicious user enters the decrypted unencrypted path, he or she can obtain key assets in the container. Therefore, how to protect key assets in the container has become an urgent problem to be solved. Summary of the invention

[0005] Embodiments of the present application provide a container encryption method, device, electronic device, and storage medium to improve the security of container assets.

[0006] The specific technical solutions provided by the embodiments of this application are as follows:

[0007] A container encryption method, comprising:

[0008] When determining that the container is running, use the built-in first key to decrypt the preset encrypted container file directory to obtain the decrypted container file directory;

[0009] Mounting the container file directory to a preset non-encrypted path, wherein the non-encrypted path is used to present an unencrypted container file directory;

[0010] The non-encrypted path is covered with a camouflaged path, and the camouflaged path is periodically accessed.

[0011] Optionally, also include:

[0012] In response to a file encryption request, mounting a pre-generated encrypted path to the non-encrypted path, wherein the encrypted path is used to present an encrypted container file directory;

[0013] The obtained container file directory is stored in the non-encrypted path, and the container file directory is encrypted to obtain an encrypted container file directory;

[0014] The encrypted container file directory is stored in the encrypted path, and the mount between the encrypted path and the non-encrypted path is canceled to obtain the encrypted container file directory stored in the encrypted path.

[0015] Optionally, mounting the pre-generated encrypted path to the non-encrypted path specifically includes:

[0016] Using the first key to decrypt the encrypted second key in the container image to obtain the second key, wherein the first key is used to decrypt the encrypted second key, and the second key is used to decrypt the encrypted path to obtain the unencrypted path;

[0017] Mounting the encrypted path to trigger a decryption instruction;

[0018] In response to the decryption instruction, the encrypted path is decrypted using the second key to obtain a non-encrypted path.

[0019] Optionally, using the first key to decrypt the encrypted second key in the container image to obtain the second key specifically includes:

[0020] Based on the parsing algorithm, the preset obfuscated first key is restored to obtain the first key, wherein the encrypted first key is obtained by obfuscating the pre-generated first key based on the obfuscation algorithm;

[0021] Get the encrypted second key built into the container image;

[0022] A second key is obtained based on the first key and the encrypted second key.

[0023] Optionally, periodically accessing the camouflaged path specifically includes:

[0024] Creating an empty directory file in the non-encrypted path;

[0025] The empty directory file is accessed according to a preset period.

[0026] Optionally, after obtaining the encrypted container file directory stored in the encrypted path, the method further includes:

[0027] Receiving a file operation request triggered by a target object, wherein the file operation request includes at least an object identifier, a process identifier, an operation type, and an identifier of a file to be processed;

[0028] Based on the object identifier and the process identifier, performing a validity check on the target object;

[0029] When it is determined that the target object passes the legality check, a corresponding file processing operation is determined based on the operation type;

[0030] Based on the file processing operation, the to-be-processed file corresponding to the to-be-processed file identifier is processed.

[0031] Optionally, based on the object identifier and the process identifier, performing a validity check on the target object specifically includes:

[0032] Obtaining a preset illegal identification set, wherein the illegal identification set includes at least a plurality of illegal object identifications and a plurality of illegal process identifications;

[0033] If it is determined that the object identifier and / or the process identifier is included in the illegal identifier set, it is determined that the target object has failed the legality check;

[0034] If it is determined that neither the object identifier nor the process identifier is included in the illegal identifier set, it is determined that the target object passes the legality check.

[0035] A container encryption device, comprising:

[0036] A decryption module, used to determine when the container is running, use the built-in first key to decrypt a preset encrypted container file directory to obtain a decrypted container file directory;

[0037] A mounting module, used to mount the container file directory to a preset non-encrypted path, wherein the non-encrypted path is used to present the unencrypted container file directory;

[0038] The first processing module is used to cover the non-encrypted path with a camouflaged path and periodically access the camouflaged path.

[0039] Optionally, a second processing module is further included, and the second processing module is specifically used for:

[0040] In response to a file encryption request, mounting a pre-generated encrypted path to the non-encrypted path, wherein the encrypted path is used to present an encrypted container file directory;

[0041] The obtained container file directory is stored in the non-encrypted path, and the container file directory is encrypted to obtain an encrypted container file directory;

[0042] The encrypted container file directory is stored in the encrypted path, and the mount between the encrypted path and the non-encrypted path is canceled to obtain the encrypted container file directory stored in the encrypted path.

[0043] Optionally, when the pre-generated encrypted path is mounted to the non-encrypted path, the second processing module is specifically configured to:

[0044] Using the first key to decrypt the encrypted second key in the container image to obtain the second key, wherein the first key is used to decrypt the encrypted second key, and the second key is used to decrypt the encrypted path to obtain the unencrypted path;

[0045] Mounting the encrypted path to trigger a decryption instruction;

[0046] In response to the decryption instruction, the encrypted path is decrypted using the second key to obtain a non-encrypted path.

[0047] Optionally, when the first key is used to decrypt the encrypted second key in the container image to obtain the second key, the second processing module is specifically used to:

[0048] Based on the parsing algorithm, the preset obfuscated first key is restored to obtain the first key, wherein the encrypted first key is obtained by obfuscating the pre-generated first key based on the obfuscation algorithm;

[0049] Get the encrypted second key built into the container image;

[0050] A second key is obtained based on the first key and the encrypted second key.

[0051] Optionally, the camouflaged path is periodically accessed, and the first processing module is specifically configured to:

[0052] Creating an empty directory file in the non-encrypted path;

[0053] The empty directory file is accessed according to a preset period.

[0054] Optionally, after obtaining the encrypted container file directory stored in the encrypted path, a verification module is further included, and the verification module is specifically used to:

[0055] Receiving a file operation request triggered by a target object, wherein the file operation request includes at least an object identifier, a process identifier, an operation type, and an identifier of a file to be processed;

[0056] Based on the object identifier and the process identifier, performing a validity check on the target object;

[0057] When it is determined that the target object passes the legality check, a corresponding file processing operation is determined based on the operation type;

[0058] Based on the file processing operation, the to-be-processed file corresponding to the to-be-processed file identifier is processed.

[0059] Optionally, when performing a validity check on the target object based on the object identifier and the process identifier, the verification module is specifically used to:

[0060] Obtaining a preset illegal identification set, wherein the illegal identification set includes at least a plurality of illegal object identifications and a plurality of illegal process identifications;

[0061] If it is determined that the object identifier and / or the process identifier is included in the illegal identifier set, it is determined that the target object has failed the legality check;

[0062] If it is determined that neither the object identifier nor the process identifier is included in the illegal identifier set, it is determined that the target object passes the legality check.

[0063] An electronic device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the container encryption method when executing the program.

[0064] A computer-readable storage medium stores a computer program, which implements the steps of the container encryption method when executed by a processor.

[0065] In the embodiment of the present application, when the container is determined to be running, the preset encrypted container file directory is decrypted using the built-in first key to obtain the decrypted container file directory; the container file directory is mounted to a preset non-encrypted path, wherein the non-encrypted path is used to present the unencrypted container file directory; the non-encrypted path is covered with a disguised path, and the disguised path is periodically accessed. In this way, a disguised protective shell is added to the non-encrypted path that is actually running, preventing malicious users from entering the decrypted non-encrypted path and obtaining key assets in the container, thereby improving the security of container assets. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 This is an application framework diagram in the embodiment of this application;

[0067] Figure 2 This is a flow chart of a container encryption method in an embodiment of the present application;

[0068] Figure 3 This is a flowchart of the startup process in an embodiment of the present application;

[0069] Figure 4 This is a flowchart of the startup process in an embodiment of the present application;

[0070] Figure 5A diagram showing the interaction between the user-mode file system and the kernel in an embodiment of the present application;

[0071] Figure 6 This is a schematic diagram of the process of encrypting a static file system in an embodiment of the present application;

[0072] Figure 7 A schematic diagram of the key management method in an embodiment of the present application;

[0073] Figure 8 This is a schematic diagram of the structure of a container encryption device in an embodiment of the present application;

[0074] Fig. 9 Schematic diagram of the structure of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION

[0075] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0076] Some of the terms used in the embodiments of the present application are explained below to facilitate understanding by those skilled in the art.

[0077] Linux: Linux is a UNIX-like operating system that is free to use and freely distributed.

[0078] Container: An open source application container engine.

[0079] Container privileges: permissions that can be configured for containers. Configuring different container privileges allows access to different resources on the host.

[0080] Process: The basic unit for resource allocation and scheduling.

[0081] Process ID: A numerical identifier assigned to each process that uniquely identifies the process.

[0082] Ps command: A user command in the Linux system, used to view information about processes in the system.

[0083] Proc directory: a container file directory in the Linux system that contains information related to process running.

[0084] Filesystem in Userspace (FUSE): implements the interface of user-mode encrypted file system. FUSE includes kernel module and libfuse dynamic library.

[0085] Among them, the Libfuse dynamic library provides communication implementation with the kernel module.

[0086] Namespace: A method used by Linux to isolate resources. Resources in different namespaces are isolated from each other and cannot be directly accessed by each other.

[0087] Control groups: It is a resource isolation mechanism provided by Linux. Through the resource isolation mechanism, resource limitation, isolation and statistical functions can be implemented for Linux processes or process groups.

[0088] Union File System (unionFS): The contents of multiple container file directories can be mounted jointly into the same container file directory, while the physical locations of the container file directories are separate.

[0089] File system: A software system that manages and organizes stored file information.

[0090] User-mode encrypted file system: A user-mode file system implemented based on fuse technology that has encryption and decryption functions and user protection functions.

[0091] Operation Code (OPCode): used to identify the type of current operation.

[0092] Key: used to encrypt the container file directory. When decrypting, the same key is required to decrypt the encrypted container file directory.

[0093] Encrypted path: A path created using the user-mode encrypted file system.

[0094] Non-encrypted path: The path to which the encrypted path of the user-mode encrypted file system is mounted after decryption.

[0095] Startup process: The initialization process used to start the business in the container.

[0096] Mount: It refers to the process of establishing a connection between a device file and a system path (or two system paths) in Linux. Accessing a system path is equivalent to accessing a device file. Linux supports multiple mounts of the same path, and the latter mount will overwrite the previous mount.

[0097] For example: 1.mount src1 dst: means src1 establishes a connection with dst. Modifying dst means modifying src1.

[0098] 2.mount src2 dst: means that src2 establishes a connection with dst. At this time, the content in src1 cannot be seen under dst, and only the content in src2 can be seen. Modifying dst means modifying src2.

[0099] 3.umount dst: means canceling the mount on dst.

[0100] It should be noted that after canceling the mount, only the mount of src2 on dst is canceled, and the content of src1 can still be read.

[0101] 4. Execute umount dst again: to cancel the mount on dst.

[0102] It should be noted that at this time, the mount of src1 on dst is canceled, and the content of src1 or src2 cannot be seen under dst.

[0103] In recent years, with the continuous development of cloud computing, cloud-native applications and service platforms have been gradually applied to different scenarios. Container technology is widely used in the construction of cloud-native applications and service platforms, and container technology can also be applied to a variety of different fields.

[0104] Container technology uses Linux namespaces, cgroups, unionFS and other basic technologies to provide an isolated operating environment for applications. From the perspective of the system running the container, each container is essentially a Linux application. Due to the openness of the container, the program and data in the container can be easily accessed on the host system of the container without effective protection measures, which greatly reduces the security of the container. In the actual transmission and application process of the container, the core programs and files in the container need to be encrypted to ensure the security of the files in the container. Therefore, how to encrypt the files in the container has become an urgent problem to be solved.

[0105] In the related art, when encrypting files in a container, it can be implemented in the following two ways:

[0106] The first encryption method: when encrypting files in a container, when encoding the container, the programs and files in the container are obfuscated, or the container files are encrypted, so as to increase the security protection capability of the container. However, the first encryption method in the related art requires that all programs and container files be encrypted, that is, each program is encrypted in turn, and each container file is encrypted in turn. Therefore, the efficiency of encrypting container files is not high.

[0107] The second encryption method: When encrypting container files in a container, it relies on hardware security functions, such as Intel SGX, TPM, etc. However, the second container encryption method in the related art relies on hardware security functions, so the adaptability of container operation is very poor, and the implementation of container migration function is very difficult and cannot be supported.

[0108] Moreover, in the related technology, container data is generally stored in an unencrypted path. When a malicious user enters the decrypted unencrypted path, the key assets in the container can be obtained. Therefore, how to protect the key assets in the container has become an urgent problem to be solved.

[0109] In order to solve the above problems, an embodiment of the present application provides a container encryption method, which determines that when the container is running, a preset encrypted container file directory is decrypted using a built-in first key to obtain a decrypted container file directory; the container file directory is mounted to a preset non-encrypted path, wherein the non-encrypted path is used to present an unencrypted container file directory; a disguised path is used to cover the non-encrypted path, and the disguised path is periodically accessed. In this way, the security of files in the container can be improved by using a disguised path, and malicious users can be prevented from obtaining container assets in the non-encrypted path.

[0110] Based on the above embodiments, see Figure 1 As shown, it is an application framework diagram in the embodiment of the present application, which specifically includes:

[0111] 1. Startup process: the startup program of the business software.

[0112] In the embodiment of the present application, the startup process performs the following functions:

[0113] (1) Start the user-mode encrypted file system software and dynamically mount the encrypted file system.

[0114] (2) Mount the camouflaged path to the non-encrypted path, so that the camouflaged path covers the non-encrypted path.

[0115] (3) Maintain access to non-encrypted paths.

[0116] 2. User-mode encrypted file system software: user-mode file system software with encryption, decryption, and user identification functions.

[0117] In the embodiment of the present application, the user-mode encrypted file system software performs the following functions:

[0118] (1) Based on the Libfuse open source library, it interacts with the kernel to implement a user-mode file system.

[0119] (2) Encrypt the container file directory.

[0120] 3. Disguised path: The startup process uses the disguised path to overwrite the non-encrypted path and continues to occupy the disguised path.

[0121] 4. Encryption path: used to encrypt the container file directory using the user-mode encrypted file system to obtain the encrypted container file directory. The encryption path is also used to store the encrypted container file directory.

[0122] 5. Non-encrypted path: The path used to decrypt the encrypted container file directory using the user-mode encrypted file system, obtain the decrypted container file directory, and mount the container file directory.

[0123] 6. Built-in key: also known as the first key, used to encrypt the second key and decrypt the encrypted second key.

[0124] 7. Key file: that is, the second key is encrypted using the first key to obtain the encrypted second key, which is the key for encrypting and decrypting the user-mode file system.

[0125] It should be noted that the key file is stored in the container image.

[0126] 8. Linux root file system: a file system that supports the boot process and user-mode encrypted file system software.

[0127] Based on the above embodiments, see Figure 2 FIG. 1 is a flow chart of a container encryption method in an embodiment of the present application, which specifically includes:

[0128] S20: When determining that the container is running, use the built-in first key to decrypt the preset encrypted container file directory to obtain the decrypted container file directory.

[0129] In the embodiment of the present application, when the container is running, the preset encrypted container file directory is decrypted using the built-in first key to obtain the container file directory.

[0130] It should be noted that, since the encrypted container file directory is obtained by encrypting the container file directory using the first key, during the decryption process, the encrypted container file directory also needs to be decrypted using the first key.

[0131] S21: Mount the container file directory to a preset non-encrypted path.

[0132] The non-encrypted path is used to present the unencrypted container file directory.

[0133] In the embodiment of the present application, after obtaining the container file directory, the container file directory is copied to a preset non-encrypted path, so that the container file directory is stored on the non-encrypted path.

[0134] S22: Use the camouflaged path to cover the non-encrypted path, and periodically access the camouflaged path.

[0135] In an embodiment of the present application, a disguised path is generated in advance, the pre-generated disguised path is mounted in the non-encrypted path, and the disguised path is periodically accessed. In this way, the disguised path is mounted in the non-encrypted path, and the content presentation of the disguised path covers the content presentation of the encrypted path on the non-encrypted path. Therefore, when a malicious user requests to access the non-encrypted path, he can only access the disguised path, and cannot read the container file decrypted from the encrypted path to the non-encrypted path, nor can he access the non-encrypted path. Therefore, the disguised path is mounted in the non-encrypted path, thereby adding a disguised protective shell to the real running non-encrypted path, preventing malicious users from entering the decrypted non-encrypted path, and then obtaining the key container files in the container, further ensuring the security of the container.

[0136] Optionally, in an embodiment of the present application, a possible implementation method is provided for periodically accessing a spoofed path, specifically including:

[0137] S221: Create an empty directory file in a non-encrypted path.

[0138] In the embodiment of the present application, an empty directory file is created in the non-encrypted path, that is, the non-encrypted path accesses the empty directory file at this time.

[0139] S222: Access empty directory files according to a preset period.

[0140] In the embodiment of the present application, the empty directory file is accessed according to a preset period, so that malicious users cannot view the container assets in the non-encrypted path.

[0141] The following is an introduction to the process of encrypting the container file directory in the embodiment of the present application, which specifically includes:

[0142] S23: In response to the file encryption request, the pre-generated encrypted path is mounted to the non-encrypted path.

[0143] The encrypted path is used to present the encrypted file.

[0144] In an embodiment of the present application, a file encryption request triggered by a target object is obtained, and in response to the file encryption request triggered by the target object, a user-state encryption file program is called to create an encryption path, and the pre-generated encryption path is mounted to a non-encrypted path created by calling the user-state encryption file program.

[0145] Among them, the encrypted path is the path in which the core content such as the file directory to be processed is encrypted and stored using the user-state encrypted file system software, and the non-encrypted path is the path in which the encrypted content is decrypted and stored using the user-state encrypted file system software.

[0146] It should be noted that, in the embodiment of the present application, a possible implementation method is provided for executing S23. The following is a detailed description of the method of mounting the pre-generated encrypted path to the non-encrypted path in the embodiment of the present application, specifically including:

[0147] S231: Use the first key to decrypt the encrypted second key in the container image to obtain the second key.

[0148] The first key is used to decrypt the encrypted second key, and the second key is used to decrypt the encrypted path to obtain the unencrypted path.

[0149] In an embodiment of the present application, in order to protect the second key used to decrypt the encrypted path, the second key is encrypted and stored in the container image, and then in the process of creating an unencrypted path, the encrypted second key in the container image is obtained, and the user-mode encrypted file program randomly generates a first key for decrypting the encrypted second key through a random algorithm, and decrypts the encrypted second key through the first key to obtain the second key.

[0150] In this way, in order to protect the second key, the second key is encrypted and stored in the container image. In the process of creating a non-encrypted path, the first key is used to decrypt it to obtain the second key. This can increase the difficulty of obtaining the second key and prevent the second key from being obtained by malicious users to crack the encrypted core business programs or encrypted files in the container image, thereby further ensuring the security of the container.

[0151] It should be noted that the encrypted second key in the embodiment of the present application is obtained by randomly generating a first key through a user-mode encryption file program and then encrypting the pre-configured second key with the first key.

[0152] In addition, it should be noted that the randomly generated first key used in the process of encrypting the second key in the embodiment of the present application and the randomly generated first key used in the process of decrypting the encrypted second key are the same key.

[0153] Specifically, in the embodiment of the present application, a possible implementation method is provided for obtaining the second key. S231 in the embodiment of the present application is described in detail below, specifically including:

[0154] S2311: Based on the parsing algorithm, restore the preset obfuscated first key to obtain the first key.

[0155] The encrypted first key is obtained by performing obfuscation processing on the pre-generated first key based on an obfuscation algorithm.

[0156] In an embodiment of the present application, a parsing algorithm for restoring the obfuscated first key is obtained, and at the same time, the obfuscated first key is obtained. Then, when the user-mode encrypted file program is running, the obtained parsing algorithm is used to restore the obfuscated first key, thereby obtaining the first key.

[0157] It should be noted that, in the embodiment of the present application, the obfuscated first key is obtained by using a specific obfuscation algorithm to obfuscate the pre-generated first key and then compiling it into the binary of the user-state encryption file program. That is, the system randomly generates a first key, and then, based on the obfuscation algorithm, obfuscates the randomly generated first key to obtain the obfuscated first key, and compiles the obfuscated first key into the binary of the user-state encryption file program.

[0158] In addition, it should be noted that, in the embodiment of the present application, the obfuscation algorithm used when obfuscating the randomly generated first key and the restoration algorithm used when restoring the obfuscated first key are the same calculation algorithm.

[0159] S2312: Obtain the encrypted second key built into the container image.

[0160] In the embodiment of the present application, since the container image has a built-in encrypted second key saved in the form of a file, the encrypted second key is read from the container image.

[0161] S2313: Obtain a second key based on the first key and the encrypted second key.

[0162] In the embodiment of the present application, after obtaining the first key and the encrypted second key, the encrypted second key is decrypted using the first key to obtain the second key.

[0163] S232: Mount the encrypted path to trigger a decryption instruction.

[0164] In the embodiment of the present application, the encrypted path is mounted and a decryption instruction is triggered to obtain the encrypted encrypted path.

[0165] It should be noted that the operation of mounting the encrypted path can automatically trigger the decryption instruction.

[0166] S233: In response to the decryption instruction, the encrypted path is decrypted using the second key to obtain a non-encrypted path.

[0167] In the embodiment of the present application, in response to a decryption instruction, the encrypted path is decrypted using the second key to obtain a non-encrypted path, thereby mounting the encrypted path into the non-encrypted path.

[0168] It should be noted that, in the embodiment of the present application, the second key is used to decrypt the encrypted path to obtain the unencrypted path.

[0169] S24: The obtained container file directory is stored in a non-encrypted path, and the container file directory is encrypted to obtain an encrypted container file directory.

[0170] In an embodiment of the present application, after the encrypted path is mounted to the non-encrypted path, the obtained container file directory is copied and stored in the non-encrypted path, triggering the generation of encryption instructions, and in response to the triggered encryption instructions, the container file directory is encrypted to obtain an encrypted container file directory.

[0171] It should be noted that in the embodiment of the present application, since the non-encrypted path contains unencrypted files or file directories, when encrypting the container file directory, encryption processing needs to be performed in the non-encrypted path.

[0172] S25: The encrypted container file directory is stored in the encrypted path, and the mount between the encrypted path and the non-encrypted path is canceled to obtain the encrypted container file directory stored in the encrypted path.

[0173] In an embodiment of the present application, after obtaining the encrypted container file directory, since the encrypted container file directory is encrypted data and the encrypted path and the non-encrypted path are in a mounted state at this time, the obtained encrypted container file directory can be stored under the encrypted path, and the mount between the encrypted path and the non-encrypted path can be canceled, thereby obtaining the encrypted container file directory stored in the encrypted path.

[0174] Optionally, in the embodiment of the present application, after obtaining the non-encrypted path, the file can be decrypted. The following is a detailed description of the process of processing the file in the embodiment of the present application, which specifically includes:

[0175] S26: Receive a file operation request triggered by the target object.

[0176] The file operation request at least includes an object identifier, a process identifier, an operation type, and an identifier of a file to be processed.

[0177] In the embodiment of the present application, when the target object needs to operate on the container file, the target object may trigger a file operation request, and then receive the file operation request triggered by the target object.

[0178] It should be noted that, in the embodiment of the present application, since the file operation request is triggered and generated by the target object, the file operation request includes the object identifier corresponding to the target object, and since the file operation request is generated based on the file operation process, the file operation request also includes the process identifier corresponding to the file operation process. In addition, since the file operation request is for processing the container file in the container, the file operation request also includes the to-be-processed container file identifier corresponding to the to-be-processed container file to be processed, and the operation type for the processing operation on the to-be-processed container file.

[0179] The operation type represents type information corresponding to the operation that the target object is going to perform on the container file to be processed. For example, when the target object needs to modify the container file to be processed, the operation type in the file operation request is modification. For another example, when the target object needs to clear the container file to be processed, the operation type in the file operation request is clear. This is not limited in the embodiments of the present application.

[0180] S27: Based on the object ID and process ID, the target object is verified for legitimacy.

[0181] In an embodiment of the present application, since the target object that triggers the file operation request may be a malicious object, or the process that performs the file operation is a malicious process, it is necessary to perform a legitimacy check on the target object. Specifically, the legitimacy of the target object is checked based on the object identifier and the process identifier.

[0182] Among them, in the embodiment of the present application, a possible implementation method is provided for executing S27. The process of performing the legality verification on the target object in the embodiment of the present application is described in detail below, specifically including:

[0183] S271: Obtain a preset illegal identification set.

[0184] The illegal identification set includes at least a plurality of illegal object identifications and a plurality of illegal process identifications.

[0185] In an embodiment of the present application, relevant staff may pre-configure an illegal identification set, thereby obtaining a preset illegal identification set.

[0186] It should be noted that, in the embodiment of the present application, the illegal identification set includes at least a plurality of illegal object identifications and a plurality of illegal process identifications. The illegal object identification represents the identification corresponding to the malicious object, and the illegal process identification represents the identification corresponding to the illegal process.

[0187] S272: If it is determined that the object identifier and / or the process identifier is included in the illegal identifier set, it is determined that the target object has failed the legality check.

[0188] In the embodiment of the present application, whether the object identifier and / or process identifier is included in the illegal identifier set can be determined in the following four cases:

[0189] Case 1: Both the object ID and the process ID are included in the illegal ID set.

[0190] In the embodiment of the present application, if it is determined that the object identifier is included in the illegal identifier set, and the process identifier is included in the illegal identifier set, it is determined that the target object has failed the legality check.

[0191] Specifically, when it is determined that the object identifier is included in the illegal identifier set, the target object corresponding to the object identifier is determined to be a malicious object, and when it is determined that the process identifier is included in the illegal identifier set, the process operated by the target object is determined to be an illegal process. Therefore, it is determined that the target object has not passed the legitimacy check at this time.

[0192] The second case: the object ID is included in the illegal ID set, but the process ID is not included in the illegal ID set.

[0193] In the embodiment of the present application, if it is determined that the object identifier is included in the illegal identifier set, but the process identifier is not included in the illegal identifier set, it is determined that the target object has failed the legality check.

[0194] Specifically, when it is determined that the object identifier is included in the illegal identifier set, the target object corresponding to the object identifier is determined to be a malicious object. Although in the above case, the process identifier is not included in the illegal identifier set, since the target object is a malicious object, it is determined that the target object has not passed the legitimacy check.

[0195] The third case: The object ID is not included in the illegal ID set, but the process ID is included in the illegal ID set.

[0196] In the embodiment of the present application, if it is determined that the object identifier is not included in the illegal identifier set, but the process identifier is included in the illegal identifier set, it is determined that the target object has failed the legality check.

[0197] Specifically, when it is determined that the object identifier is not included in the illegal identifier set, it is determined that the target object corresponding to the object identifier is not a malicious object, and in the above case, the process identifier is included in the illegal identifier set, and it is determined that the target object has not passed the legality check. Although in the above case, the object identifier is not included in the illegal identifier set, since the process is a malicious process, even if the target object is a non-malicious object, the target object still cannot pass the legality check.

[0198] The fourth case: Neither the object ID nor the process ID is included in the illegal ID set.

[0199] In the embodiment of the present application, if it is determined that the object identifier is not included in the illegal identifier set, and the process identifier is not included in the illegal identifier set, then it is determined that the target object passes the legality check.

[0200] Specifically, when it is determined that the object identifier is not included in the illegal identifier set, it is determined that the target object corresponding to the object identifier is not a malicious object, and, in the above case, the process identifier is also not included in the illegal identifier set. Therefore, it is determined that the process corresponding to the process identifier is not a malicious process, thereby determining that the target object can pass the legitimacy check.

[0201] Therefore, in the embodiment of the present application, if it is determined that the object identifier and / or the process identifier is not included in the illegal identifier set, it is determined that the target object has failed the legality check.

[0202] S273: If it is determined that neither the object identifier nor the process identifier is included in the illegal identifier set, it is determined that the target object passes the legality check.

[0203] In an embodiment of the present application, if it is determined that the object identifier is not included in the illegal identifier set, the target object is determined to be a legitimate user. In the above case, it is determined that the process identifier is not included in the illegal identifier set, and the process is determined to be a legitimate process. Therefore, it is determined that the target object passes the legitimacy check.

[0204] S28: When it is determined that the target object passes the legality check, a corresponding file processing operation is determined based on the operation type.

[0205] In an embodiment of the present application, a validity check is performed on the target object. When it is determined that the target object passes the validity check, a corresponding file processing operation is determined based on the operation type in the file operation request.

[0206] Among them, the operation type can be, for example, file creation, deletion, editing, reading, and file path creation, deletion, and other operations supported by the file system, which are not limited in the embodiments of the present application.

[0207] It should be noted that before mounting the pre-generated encrypted path to the non-encrypted path, the operation type of the file operation needs to be constructed.

[0208] S29: Based on the file processing operation, the to-be-processed file corresponding to the to-be-processed file identifier is processed.

[0209] In the embodiment of the present application, based on the file processing operation, a corresponding file processing operation is performed on the file to be processed corresponding to the file to be processed identifier.

[0210] For example, when the operation type is file deletion, the to-be-processed file corresponding to the to-be-processed file identifier is deleted.

[0211] In an embodiment of the present application, the key asset directory in the container is encrypted to prevent the key asset directory in the container from being statically cracked, and a user-mode encrypted file system is run in the container, and the product system is dynamically mounted to an encrypted path. After the product function is started, the runtime file system is overwritten and an encrypted path is presented, thereby preventing anyone from outside the container from spying on the container. Furthermore, by protecting the non-encrypted path through a disguised path, malicious users can be prevented from illegally viewing the non-encrypted path, thereby protecting the container assets.

[0212] Based on the above embodiments, see Figure 3 As shown, it is a flowchart of the startup process in an embodiment of the present application, which specifically includes:

[0213] S300: Start.

[0214] S310: Running the user-mode encrypted file system software.

[0215] In an embodiment of the present application, the user-state encrypted file system software is run by the startup process, so that the user-state encrypted file system software mounts the encrypted path to the non-encrypted path, performs a decryption operation on the encrypted container file directory in the encrypted path, and obtains the corresponding container file directory after decryption.

[0216] S320: Determine whether the user-mode encrypted file system has completed decryption. If so, execute S330; if not, execute S320 again.

[0217] In the embodiment of the present application, it is determined whether the user-mode encrypted file system has completed decryption, that is, it is determined whether the corresponding container file directory is obtained. If it is determined that the corresponding container file directory is obtained, the business function associated with the container file directory is run. If it is determined that the corresponding container file directory is not obtained, the decryption operation is re-performed on the encrypted container file directory.

[0218] S330: running business functions.

[0219] In the embodiment of the present application, after the encrypted container file directory is decrypted, it switches to a non-encrypted path and runs related business functions.

[0220] S340: Mount the camouflage path to the non-encrypted path.

[0221] In the embodiment of the present application, since the content presentation of the disguised path covers the content presentation of the encrypted path on the non-encrypted path, the user can only see the content of the disguised path but cannot read the content decrypted from the encrypted path to the non-encrypted path.

[0222] S350: Maintain access to the non-encrypted path.

[0223] It should be noted that access to the non-encrypted path is maintained during the startup process by creating a temporary file in the non-encrypted path and continuously occupying the file. If the container startup process is killed, the user-mode encrypted file system will be automatically unmounted.

[0224] In an embodiment of the present application, by creating a file in a non-encrypted path and continuously accessing the file, possession of the non-encrypted path is maintained, which can prevent malicious users from canceling the mounting of an empty directory and entering the decrypted non-encrypted path.

[0225] Based on the above embodiments, see Figure 4 As shown, it is a flowchart of the startup process in an embodiment of the present application, which specifically includes:

[0226] S400: Start the user-mode encrypted file system.

[0227] S410: Use the first key in the user-mode encrypted file system to decrypt the encrypted second key built into the container to obtain the second key.

[0228] S420: Use the second key to mount the encrypted path to the non-encrypted path.

[0229] S430: Receive a kernel file operation message.

[0230] In the embodiment of the present application, it runs continuously, receives file operation messages transmitted by the kernel, and processes file operations.

[0231] S440: Parse the file operation to obtain the object identifier of the target object.

[0232] S450: Determine whether the target object passes the legality check, if so, execute S460, if not, execute S490.

[0233] In an embodiment of the present application, it is determined whether the object identifier of the target object is included in the illegal identifier set. If it is determined that the object identifier of the target object is not included in the illegal set, it is determined that the target object passes the legality check and the file system operation is performed. If it is determined that the object identifier of the target object is included in the illegal set, it is determined that the target object does not pass the legality check and failure is directly returned.

[0234] S460: Execute file system operations.

[0235] S470: Determine whether the file system operation is successful, if so, execute S480, if not, execute S490.

[0236] S480: The encapsulation success message is returned.

[0237] S490: Encapsulation failure message is returned.

[0238] In the embodiment of the present application, by performing a legitimacy check on the target object, it is possible to prevent malicious objects from identifying the running directory of key assets in the container through paths such as proc during the operation of the container.

[0239] Based on the above embodiments, see Figure 5 As shown, it is a diagram of the interaction relationship between the user-mode file system and the kernel in the embodiment of the present application, which specifically includes:

[0240] 1. The user-mode encrypted file system mounts encrypted path A to non-encrypted path B. Operations on non-encrypted path B enter the kernel virtual file system VFS.

[0241] 2. The virtual file system calls the FUSE module according to the file system type.

[0242] 3. The FUSE kernel module passes the call to the user-mode libfuse library.

[0243] 4. The Libfuse library passes the file operation message to the user-mode encrypted file system.

[0244] 5. The user-mode encrypted file system encrypts the container file directory, obtains the encrypted container file directory, and returns the encrypted container file directory to the libfuse library.

[0245] 6. The Libfuse library returns the result of the success or failure of the user-mode file system call to the FUSE kernel module.

[0246] 7. The FUSE kernel module returns a success or failure message to the virtual file system.

[0247] Based on the above embodiments, see Figure 6FIG. 1 is a flow chart of a static file system encryption method according to an embodiment of the present application, which specifically includes:

[0248] S600: Create an encryption path using the user-mode encryption file system.

[0249] In the embodiment of the present application, an encrypted path is created using a user-mode encrypted file system, and the encrypted path presents encrypted data, such as an encrypted container file directory.

[0250] S610: Mount the encrypted path to the non-encrypted path.

[0251] In the embodiment of the present application, the non-encrypted path will present the decrypted files and the container file directory.

[0252] S620: Copy the core business process and container file directory to the encrypted path.

[0253] In an embodiment of the present application, the core business process and the container file directory are copied to an encrypted path, the user-mode encrypted file system is triggered, the core business process is encrypted, and the container file directory is encrypted to obtain the encrypted core business process and the encrypted container file directory, and store them in the encrypted path.

[0254] S630: Cancel mounting the non-encrypted path.

[0255] In the embodiment of the present application, the mounting of the non-encrypted path is canceled, and the user can only see the encrypted path.

[0256] In the embodiment of the present application, the core business process or file is encrypted, and after the encryption is completed, the mounting of the encrypted file system is canceled to complete the production of the container image.

[0257] Based on the above embodiments, see Figure 7 FIG. 1 is a flow chart of a key management method in an embodiment of the present application, which specifically includes:

[0258] S700: Start the process.

[0259] S710: Customize an obfuscation algorithm, obfuscate the first key, and store the obfuscated first key in the code.

[0260] S720: Use a parsing algorithm corresponding to the obfuscation algorithm to restore the obfuscated first key, and use the restored first key for subsequent decryption.

[0261] In the embodiment of the present application, the core algorithm logic in the system will also be managed, and the core algorithm logic includes a built-in key obfuscation algorithm, an actual key decryption algorithm, and a file system decryption logic.

[0262] In the embodiment of the present application, obfuscation strategies and process forgery are used for protection, which increases the difficulty of obtaining key keys and prevents the keys from being obtained by malicious users, thereby cracking the encrypted core business programs or container file directories in the container.

[0263] Based on the same inventive concept, the embodiment of the present application also provides a container encryption device, which can be a hardware structure, a software module, or a hardware structure plus a software module. Figure 8 The schematic diagram of the structure of the container encryption device in the embodiment of the present application is shown, which specifically includes:

[0264] The decryption module 800 is used to determine that when the container is running, use the built-in first key to decrypt the preset encrypted container file directory to obtain the decrypted container file directory;

[0265] A mounting module 810, configured to mount the container file directory to a preset non-encrypted path, wherein the non-encrypted path is used to present an unencrypted container file directory;

[0266] The first processing module 820 is configured to use a camouflaged path to cover the non-encrypted path, and periodically access the camouflaged path.

[0267] Optionally, a second processing module 830 is further included, and the second processing module 830 is specifically used for:

[0268] In response to a file encryption request, mounting a pre-generated encrypted path to the non-encrypted path, wherein the encrypted path is used to present an encrypted container file directory;

[0269] The obtained container file directory is stored in the non-encrypted path, and the container file directory is encrypted to obtain an encrypted container file directory;

[0270] The encrypted container file directory is stored in the encrypted path, and the mount between the encrypted path and the non-encrypted path is canceled to obtain the encrypted container file directory stored in the encrypted path.

[0271] Optionally, when the pre-generated encrypted path is mounted to the non-encrypted path, the second processing module 830 is specifically configured to:

[0272] Using the first key to decrypt the encrypted second key in the container image to obtain the second key, wherein the first key is used to decrypt the encrypted second key, and the second key is used to decrypt the encrypted path to obtain the unencrypted path;

[0273] Mounting the encrypted path to trigger a decryption instruction;

[0274] In response to the decryption instruction, the encrypted path is decrypted using the second key to obtain a non-encrypted path.

[0275] Optionally, when the first key is used to decrypt the encrypted second key in the container image and the second key is obtained, the second processing module 830 is specifically used to:

[0276] Based on the parsing algorithm, the preset obfuscated first key is restored to obtain the first key, wherein the encrypted first key is obtained by obfuscating the pre-generated first key based on the obfuscation algorithm;

[0277] Get the encrypted second key built into the container image;

[0278] A second key is obtained based on the first key and the encrypted second key.

[0279] Optionally, the camouflaged path is periodically accessed, and the first processing module 820 is specifically configured to:

[0280] Creating an empty directory file in the non-encrypted path;

[0281] The empty directory file is accessed according to a preset period.

[0282] Optionally, after obtaining the encrypted container file directory stored in the encrypted path, a verification module 840 is further included, and the verification module 840 is specifically used to:

[0283] Receiving a file operation request triggered by a target object, wherein the file operation request includes at least an object identifier, a process identifier, an operation type, and an identifier of a file to be processed;

[0284] Based on the object identifier and the process identifier, performing a validity check on the target object;

[0285] When it is determined that the target object passes the legality check, a corresponding file processing operation is determined based on the operation type;

[0286] Based on the file processing operation, the to-be-processed file corresponding to the to-be-processed file identifier is processed.

[0287] Optionally, when performing a validity check on the target object based on the object identifier and the process identifier, the checking module 840 is specifically configured to:

[0288] Obtaining a preset illegal identification set, wherein the illegal identification set includes at least a plurality of illegal object identifications and a plurality of illegal process identifications;

[0289] If it is determined that the object identifier and / or the process identifier is included in the illegal identifier set, it is determined that the target object has failed the legality check;

[0290] If it is determined that neither the object identifier nor the process identifier is included in the illegal identifier set, it is determined that the target object passes the legality check.

[0291] Based on the above embodiments, see Fig. 9 Shown is a schematic diagram of the structure of an electronic device in an embodiment of the present application.

[0292] An embodiment of the present application provides an electronic device, which may include a processor 910 (Center Processing Unit, CPU), a memory 920, an input device 930 and an output device 940, etc. The input device 930 may include a keyboard, a mouse, a touch screen, etc., and the output device 940 may include a display device, such as a liquid crystal display (Liquid Crystal Display, LCD), a cathode ray tube (Cathode Ray Tube, CRT), etc.

[0293] The memory 920 may include a read-only memory (ROM) and a random access memory (RAM), and provides the processor 910 with program instructions and data stored in the memory 920. In an embodiment of the present application, the memory 920 may be used to store a program of any container encryption method in an embodiment of the present application.

[0294] The processor 910 calls the program instructions stored in the memory 920, and the processor 910 is used to execute any container encryption method in the embodiments of the present application according to the obtained program instructions.

[0295] Based on the above embodiments, in an embodiment of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the container encryption method in any of the above method embodiments is implemented.

[0296] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0297] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0298] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0299] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0300] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. A container encryption method, characterized in that: include: When determining that the container is running, using the built-in first key to decrypt the preset encrypted container file directory to obtain the decrypted container file directory; Mounting the container file directory to a preset non-encrypted path, wherein the non-encrypted path is used to present an unencrypted container file directory; Using a camouflaged path to cover the non-encrypted path, and periodically accessing the camouflaged path; In response to a file encryption request, mounting a pre-generated encrypted path to the non-encrypted path, wherein the encrypted path is used to present an encrypted container file directory; The obtained container file directory is stored in the non-encrypted path, and the container file directory is encrypted to obtain an encrypted container file directory; The encrypted container file directory is stored in the encrypted path, and the mount between the encrypted path and the non-encrypted path is canceled to obtain the encrypted container file directory stored in the encrypted path.

2. The method according to claim 1, characterized in that Mounting the pre-generated encrypted path to the non-encrypted path specifically includes: Using the first key to decrypt the encrypted second key in the container image to obtain the second key, wherein the first key is used to decrypt the encrypted second key, and the second key is used to decrypt the encrypted path to obtain the unencrypted path; Mounting the encrypted path to trigger a decryption instruction; In response to the decryption instruction, the encrypted path is decrypted using the second key to obtain a non-encrypted path.

3. The method according to claim 2, characterized in that Using the first key to decrypt the encrypted second key in the container image to obtain the second key specifically includes: Based on the parsing algorithm, the preset obfuscated first key is restored to obtain the first key, wherein the encrypted first key is obtained by obfuscating the pre-generated first key based on the obfuscation algorithm; Get the encrypted second key built into the container image; A second key is obtained based on the first key and the encrypted second key.

4. The method according to claim 2 or 3, characterized in that Periodically accessing the camouflaged path specifically includes: Creating an empty directory file in the non-encrypted path; The empty directory file is accessed according to a preset period.

5. The method according to claim 1, characterized in that After obtaining the encrypted container file directory stored in the encrypted path, the method further includes: Receiving a file operation request triggered by a target object, wherein the file operation request includes at least an object identifier, a process identifier, an operation type, and an identifier of a file to be processed; Based on the object identifier and the process identifier, performing a validity check on the target object; When it is determined that the target object passes the legality check, a corresponding file processing operation is determined based on the operation type; Based on the file processing operation, the to-be-processed file corresponding to the to-be-processed file identifier is processed.

6. The method according to claim 5, characterized in that Based on the object identifier and the process identifier, the target object is subjected to a validity check, specifically including: Obtaining a preset illegal identification set, wherein the illegal identification set includes at least a plurality of illegal object identifications and a plurality of illegal process identifications; If it is determined that the object identifier and / or the process identifier is included in the illegal identifier set, it is determined that the target object has failed the legality check; If it is determined that neither the object identifier nor the process identifier is included in the illegal identifier set, it is determined that the target object passes the legality check.

7. A container encryption device, characterized in that: include: A decryption module, used to determine when the container is running, use the built-in first key to decrypt a preset encrypted container file directory to obtain a decrypted container file directory; A mounting module, used to mount the container file directory to a preset non-encrypted path, wherein the non-encrypted path is used to present the unencrypted container file directory; A first processing module, configured to cover the non-encrypted path with a camouflaged path and periodically access the camouflaged path; A second processing module, configured to mount a pre-generated encrypted path to the non-encrypted path in response to a file encryption request, wherein the encrypted path is used to present an encrypted container file directory; The obtained container file directory is stored in the non-encrypted path, and the container file directory is encrypted to obtain an encrypted container file directory; The encrypted container file directory is stored in the encrypted path, and the mount between the encrypted path and the non-encrypted path is canceled to obtain the encrypted container file directory stored in the encrypted path.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.