Virtual machine encryption and decryption method, device and computer equipment
Through communication and interaction between the virtualization management platform and KMS, the encryption and decryption operations of virtual machines are completed automatically, solving the problem of cumbersome operation of inserting and removing password cards on iNode in the existing technology, realizing efficient virtual machine encryption and decryption, and saving manpower and time costs.
Patent Information
- Application Number
- CN202210097889.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-29
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2042-01-29
AI Technical Summary
Existing virtual machine encryption and decryption technologies require inserting and removing password cards on each iNode, which is cumbersome and time-consuming, especially when the number of iNodes is large.
Through communication and interaction between the virtualization management platform, iNode, and password management system KMS, the encryption and decryption operations of the virtual machine are completed automatically, eliminating the need to insert and remove password cards on iNode, and the encryption and decryption process is implemented in software.
It greatly saves manpower and time costs, especially when the number of iNodes is huge, and improves the performance of the virtualization management platform.
Smart Images

Figure CN114448606B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a virtual machine encryption / decryption method, apparatus, and computer device. Background Technology
[0002] In the development of virtualization technology, the application of virtual machines is particularly important. However, in the face of the rapid development of high technology in the 21st century, it is very important to prevent user resources from being illegally attacked and to ensure data security.
[0003] In some existing traditional virtualization products, encryption and decryption of virtual machines are controlled via cryptographic cards, with each iNode equipped with one. To encrypt the virtual machine, a cryptographic card needs to be installed on each iNode, and when encryption is no longer required, the card must be manually removed. This process is cumbersome and labor-intensive, especially when the number of iNodes is very large, resulting in significant labor and time costs. Summary of the Invention
[0004] This application provides a virtual machine encryption / decryption method, apparatus, and computer device to solve the aforementioned technical problems in the prior art.
[0005] Firstly, this application provides a virtual machine encryption / decryption method, which is executed by an iNode and includes:
[0006] Receive control messages from the virtualization management platform to start virtual machines. The control messages include the identification information of the virtual machine to be started, as well as the control instructions corresponding to the operations to be performed on the virtual machine.
[0007] Start the virtual machine corresponding to the control message;
[0008] Send the virtual machine's identification information to the Key Management Service (KMS).
[0009] Obtain the key sent by KMS corresponding to the identification information;
[0010] Based on the key and control instructions, perform encryption or decryption operations on the virtual machine.
[0011] Secondly, this application provides a virtual machine encryption / decryption method, which is executed by a virtualization management platform and includes:
[0012] Obtain license verification information;
[0013] When the level of the license verification information is determined to be the preset level, initiate virtual machine encryption or decryption trigger operation.
[0014] Based on the triggered operation, obtain KMS configuration information;
[0015] Once the KMS configuration information is determined to be valid, the KMS configuration information is distributed to each iNode that has established a communication connection with the virtualization management platform.
[0016] Thirdly, this application provides a virtual machine encryption / decryption device, which includes:
[0017] The receiving module is used to receive control messages for starting virtual machines sent by the virtualization management platform. The control messages include identification information of the virtual machine to be started, as well as control instructions corresponding to the operations to be performed on the virtual machine.
[0018] The startup module is used to start the virtual machine corresponding to the control message.
[0019] The sending module is used to send the virtual machine's identification information to the password management system (KMS).
[0020] The acquisition module is used to acquire the key sent by KMS that corresponds to the identification information;
[0021] The encryption / decryption module is used to perform encryption or decryption operations on the virtual machine based on the key and control instructions.
[0022] Fourthly, this application provides a virtual machine encryption / decryption device, which includes:
[0023] The acquisition module is used to obtain license verification information;
[0024] The startup module is used to initiate virtual machine encryption or decryption trigger operations when the level of the license verification information is determined to be a preset level.
[0025] The acquisition module is also used to obtain KMS configuration information based on the triggered operation;
[0026] The sending module is used to distribute the KMS configuration information to each iNode that has established a communication connection with the virtualization management platform when it is determined that the KMS configuration information is valid.
[0027] Fifthly, a computer device is provided, which includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus.
[0028] Memory, used to store computer programs;
[0029] When a processor executes a program stored in memory, it implements the steps of the virtual machine encryption / decryption method of any embodiment of the first aspect;
[0030] Alternatively, the steps of the virtual machine encryption / decryption method of any embodiment of the second aspect may be implemented.
[0031] Fourthly, a computer-readable storage medium is provided, on which a computer program is stored, wherein when the computer program is executed by a computer device, it implements the steps of the virtual machine encryption / decryption method as described in any embodiment of the first aspect.
[0032] Alternatively, the steps of the virtual machine encryption / decryption method as described in any embodiment of the second aspect may be implemented.
[0033] The technical solutions provided in this application have the following advantages compared with the prior art:
[0034] The method provided in this application embodiment receives a control message from a virtualization management platform to start a virtual machine. Based on the control message, the virtual machine corresponding to the control message is started. Then, the identification information of the virtual machine is sent to the KMS, and a key corresponding to the identification information is obtained from the KMS. The virtual machine is then encrypted or decrypted using the key. Throughout this process, the operation of inserting and removing password cards on the iNode is eliminated. The encryption of the virtual machine is entirely implemented in software. Furthermore, the operation is completed through communication and interaction between the virtualization management platform, the iNode, and the KMS. This eliminates the need for manual intervention, significantly saving manpower and time costs. This effect is particularly pronounced when there is a large number of iNodes. Attached Figure Description
[0035] Figure 1 This is a schematic diagram of a virtual machine encryption / decryption method provided in an embodiment of the present invention;
[0036] Figure 2 A schematic diagram of the method flow executed on one side of the virtualization management platform provided by the present invention;
[0037] Figure 3 A schematic diagram of the method for generating a license provided by the present invention;
[0038] Figure 4 This is a schematic diagram of the method for verifying KMS configuration information provided by the present invention.
[0039] Figure 5 This is a partial flowchart illustrating the method for encrypting and decrypting virtual machines by enabling information exchange between the virtualization management platform, iNode, and KMS provided by this invention.
[0040] Figure 6 This is a schematic diagram of another virtual machine encryption / decryption method provided in an embodiment of the present invention;
[0041] Figure 7This is a schematic diagram of a virtual machine encryption / decryption device provided in an embodiment of the present invention;
[0042] Figure 8 This is a schematic diagram of another virtual machine encryption / decryption device provided in an embodiment of the present invention;
[0043] Figure 9 This invention provides a schematic diagram of a computer device structure. Detailed Implementation
[0044] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0045] To facilitate understanding of the embodiments of the present invention, further explanations and descriptions will be provided below with reference to the accompanying drawings and specific embodiments. These embodiments do not constitute a limitation on the embodiments of the present invention.
[0046] Figure 1 This is a schematic diagram of a virtual machine encryption / decryption method provided in an embodiment of the present invention. The method is executed by iNode. Before describing the virtual machine encryption / decryption method provided in this embodiment, the virtual machine encryption / decryption system to which iNode belongs is first explained. This system includes: a virtualization management platform, iNode, and KMS.
[0047] First, staff need to deploy a virtualization platform system on the server. This includes providing all the virtual hardware resources required for virtual machines to run, such as the necessary functions for computer virtualization, storage virtualization, and network virtualization.
[0048] The virtualization platform system can automatically generate license keys.
[0049] Specific processes may include, for example, generating a license based on the machine code and serial number.
[0050] The machine code is automatically generated after the system is installed, and the generated machine code is a unique identifier.
[0051] The logic for generating the machine code is as follows: obtain the Media Access Control (MAC) address information of the physical machine and write it into the encrypted file to be protected. The machine code is the minimum MAC address information obtained from the encrypted file, and the machine code is generated by the algorithm.
[0052] The machine code generation algorithm is as follows: obtain the MAC address from the encrypted file, take the smallest block of the Peripheral Component Interconnect (PCI) address, encrypt it using SHA-256, and each digit after encryption corresponds to an index variable value i. Convert each variable value i to a binary number m. Take a fixed value of 10, convert 10 to a binary number, and the binary value is 1010. Finally, perform a logical AND operation between the value m and 1010, and convert it to a hexadecimal string again, which is the machine code.
[0053] A serial number is a series of encrypted characters that serve as a special identifier for a user, provided by a serial number management system.
[0054] The code generated above, which is used to activate the system through the serial number management system, is the license key.
[0055] The license includes a standard version license and a secure version license. The standard version license controls all software functions except for configuring KMS and virtual machine disk encryption / decryption; the secure version license controls all software functions including configuring KMS and virtual machine disk encryption / decryption. In this embodiment, the secure version license is primarily used.
[0056] The standard license only has the default administrator "admin" and includes basic functionality.
[0057] Based on the secure version license, various roles can be configured in the virtualization platform system to meet more advanced security requirements. For example, system administrators, security and confidentiality administrators, and security audit administrators can be configured.
[0058] Among them, the system administrator is responsible for managing resources such as the computing pool, virtual machines, storage pool, and network pool;
[0059] Security and confidentiality administrator: Controls users, roles, access management, resource allocation, security policy management, etc.;
[0060] Security Audit Administrator: Controls functions related to task log auditing.
[0061] Security administrators can configure KMS information, and system administrators can configure which files to encrypt and decrypt. Security audit administrators can view related operation logs.
[0062] Once the license is imported into the system, the virtualization management platform can determine the subsequent operations based on the license type. For example, if the license type is determined to be a security version license, functions such as configuring KMS and virtual machine disk encryption / decryption can be initiated.
[0063] The type of license certificate can be determined based on the type of the license system. When importing a license certificate, the type of the system that generated the license certificate will be identified.
[0064] Verification of license certificates can include checking their authenticity and integrity. The specific verification process is existing technology and will not be elaborated upon here. For example, the authenticity and integrity of the license certificate can be determined by calculating its MD5 hash. Additionally, the accuracy of the password for the license certificate can also be verified.
[0065] Once the license certificate is confirmed to be valid and complete, operations such as creating a disk-encrypted virtual machine (creating a virtual machine suitable for the security version) and / or converting a non-disk-encrypted virtual machine to an encrypted virtual machine (considering that the original virtual machine may be using the standard version, now switching to the security version) can be initiated. Simultaneously, the virtualization management platform will also distribute the license certificate and the password bound to it to each iNode node, enabling the iNode nodes to perform actions such as... Figure 1 The relevant operations of the corresponding embodiments.
[0066] Optionally, after verifying the license certificate, the security administrator can also distinguish the encrypted virtual machine by encryption identifier.
[0067] For example, virtual machines can be divided into different levels such as None, Secret, Confidential, and Top Secret according to their own needs.
[0068] For details, please refer to the above operation process. Figure 2 and Figure 3 The corresponding method flowchart. Figure 2 The diagram illustrates the process executed by the virtualization management platform, including creating a license, verifying the license type, performing operations based on the license type, verifying the KMS certificate and completing the verification, and subsequently creating encrypted virtual machines and configuring encryption levels, etc. The detailed process has already been described above and will not be elaborated upon further here. Figure 3 This illustrates the process of generating a license. Similarly, the specific operation process has been described in detail above and will not be repeated here.
[0069] The following will introduce a virtual machine encryption / decryption method provided by an embodiment of the present invention. See details below. Figure 1 As shown, it may include the following steps:
[0070] Step 110: Receive the control message for starting the virtual machine sent by the virtualization management platform.
[0071] Step 120: Start the virtual machine corresponding to the control message according to the control message.
[0072] Specifically, the control message includes the identification information of the virtual machine to be started, as well as the control instructions corresponding to the operations to be performed on the virtual machine. For example, performing encryption or decryption operations on the virtual machine corresponding to the identification information. This allows iNode to determine the virtual machine to be started based on the identification information.
[0073] Optionally, before performing this operation, the method may also include the following steps, see details below. Figure 4 As shown, Figure 4 The method flow for verifying KMS configuration information is shown.
[0074] Step 410: Obtain the KMS configuration information sent by the virtualization management platform.
[0075] Step 420: Transfer the configuration information to the virtualization management platform.
[0076] Specifically, staff can configure KMS information in advance in the virtualization management system, or more specifically, in the virtualization management platform. This information may include, but is not limited to, the following: KMS port information, IP address information, KMS certificate, and the password bound to the certificate.
[0077] The KMS configuration information is then distributed to each iNode. Upon receiving the KMS configuration information, the iNode sends a response to the virtualization management platform. The platform verifies that the KMS configuration information received by the iNode matches the KMS information it distributed. If they match, the KMS configuration information verification is successful.
[0078] Then, a control message can be generated and sent to the iNode. The iNode can then identify the virtual machine to be encrypted or decrypted based on the control message.
[0079] Step 130: Send the virtual machine's identification information to the password management system KMS.
[0080] Step 140: Obtain the key sent by KMS that corresponds to the identification information.
[0081] Optionally, after performing step 110, the method may further include: creating a secure communication channel with KMS.
[0082] Establishing a secure communication channel with KMS facilitates subsequent information exchange with KMS. For example, in step 130, the virtual machine's identification information is sent to the password management system KMS, and in step 140, the key corresponding to the identification information sent by KMS is obtained.
[0083] The key is generated by KMS based on the identification information. Specifically, the virtual machine's identification information is a unique identifier. KMS can generate an SM4 key based on the unique identifier and send the SM4 key back to the iNode.
[0084] An SM4 key is a key generated using the domestically developed SM4 cryptographic algorithm certified by the State Cryptography Administration. In cryptography, SM4 stands for Block Cipher, also known as block encryption or block cipher, and is a symmetric-key algorithm. It divides plaintext into multiple equal-length blocks and encrypts and decrypts each block separately using a defined algorithm and a symmetric key.
[0085] Step 150: Perform encryption or decryption operations on the virtual machine based on the key and control instructions.
[0086] Specifically, this mainly involves encrypting or decrypting the various I / O ports of the virtual machine.
[0087] Figure 5 This diagram illustrates a partial flowchart of the process by which the virtualization management platform, iNode, and KMS interact to encrypt and decrypt virtual machines. The specific operational procedures have been described in detail above, so they will not be repeated here.
[0088] See Figure 5 It can also be seen that the main interaction during the key acquisition process is between iNode and KMS. Compared with existing technologies, this can reduce the interaction between the virtualization management platform and iNode, reduce the workload of the virtualization management platform, and greatly improve the performance of the virtualization management platform.
[0089] The virtual machine encryption / decryption method provided in this invention receives a control message from a virtualization management platform to start a virtual machine. Based on the control message, the virtual machine corresponding to the control message is started. Then, the virtual machine's identification information is sent to the Virtualization Management System (KMS), and a key corresponding to the identification information is obtained from the KMS. The virtual machine is then encrypted or decrypted using the key. Throughout this process, the need to insert and remove a cryptographic card on the iNode is eliminated. The encryption of the virtual machine is entirely implemented in software. Furthermore, the operation is completed through communication and interaction between the virtualization management platform, the iNode, and the KMS. This eliminates the need for manual intervention, significantly saving manpower and time costs. This effect is particularly pronounced when there are a large number of iNodes.
[0090] Figure 6 This is a schematic diagram of another virtual machine encryption / decryption method provided in an embodiment of the present invention. The method is executed by a virtualization management platform, and the steps of the method include:
[0091] Step 610: Obtain license verification information.
[0092] In a specific example, license verification information can refer to the license certificate mentioned above. The specific steps for obtaining license verification information are also described above and will not be repeated here.
[0093] Step 620: When the level of the license verification information is determined to be the preset level, initiate the virtual machine encryption or decryption trigger operation.
[0094] In one optional example, the license verification information level includes a standard level and a security level, with the default level being the security level. When the license verification information is a license certificate, then the license verification information level corresponds to the standard version and the security version mentioned above. That is, only the security version of the license certificate has the software functions including configuring KMS and virtual machine disk encryption and decryption. Therefore, when the license verification information level is determined to be the default level, the virtual machine encryption or decryption trigger operation is initiated.
[0095] Specifically, virtual machine encryption and decryption configuration operations may include, but are not limited to, KMS configuration operations, as well as starting and creating disk-encrypted virtual machines or editing non-disk-encrypted virtual machines to convert them into encrypted virtual machines.
[0096] Step 630: Obtain KMS configuration information based on the triggered operation.
[0097] Specifically, KMS configuration information includes, but is not limited to, the following: KMS IP address information, port information, KMS certificate, and the password bound to the certificate.
[0098] Step 640: When the KMS configuration information is determined to be valid, the KMS configuration information is distributed to each iNode that has established a communication connection with the virtualization management platform.
[0099] In addition, it also includes sending control messages to the iNode, which contain the identification information of the virtual machine to be started and the control instructions corresponding to the operations to be performed on the virtual machine.
[0100] The specific verification of the legality of KMS configuration information has been detailed above. Distributing KMS configuration information to each iNode that has established a communication connection with the virtualization management platform is also to facilitate each iNode to better interact with KMS in order to obtain keys and perform encryption and decryption on virtual machines.
[0101] The detailed contents of the above operation process have been explained in detail at the beginning of the specific embodiments of the present invention, so only a brief introduction is given here, and no further details are provided.
[0102] In a specific example, there are three physical machines A, B, and C. Physical machine A has a management node installed, which is the virtualization management platform. The management node's IP address is set to D, and this IP address D is the login address of the virtualization management platform. Physical machines B and C have compute nodes iNode installed.
[0103] The process involves generating a license based on the machine code and serial number of the virtualization management platform system, including: logging into the virtualization management platform at address D, obtaining the machine code, and generating license E based on the machine code and the obtained serial number. License E is a security version license.
[0104] Classify the license type, perform logical judgment (type judgment), and initiate the required KMS information configuration operation;
[0105] The verification is performed based on the type of license E. Since the security version license controls software functions including configuring KMS and virtual machine disk encryption and decryption, it meets the verification rules. Therefore, in the virtualization management platform system D, the security administrator is started to configure KMS information, upload the certificate file and certificate binding password, and distribute them to each iNode node.
[0106] Verify the integrity of the uploaded certificate file, and then start creating a disk-encrypted virtual machine or converting a non-disk-encrypted virtual machine into an encrypted virtual machine.
[0107] This step takes starting the creation of a disk-encrypted virtual machine as an example: After the KMS information-related operations have been deployed, upload the certificate and certificate binding password file, perform integrity verification based on the SHA-256 value of the file, and if there is no alarm notification, start the virtual machine creation operation.
[0108] Furthermore, it can also include enabling encryption identification to differentiate encrypted virtual machines. Assuming a virtual machine is created as F, after creation, the security level of the virtual machine can be edited, such as marking it as confidential.
[0109] This invention provides a virtual machine encryption / decryption method. First, it obtains license verification information. Then, if the license verification information is deemed secure, it initiates a virtual machine encryption or decryption trigger operation. Based on the trigger operation, it obtains KMS configuration information. Then, if the KMS configuration information is deemed valid, it is distributed to each iNode that establishes a communication connection with the virtualization management platform. This allows the iNode to subsequently establish a communication connection with the KMS based on the configuration information, complete the interaction process, and obtain the key for encryption / decryption operations on the virtual machine. The encryption / decryption operation on the virtual machine is then completed using the key. This process eliminates the need to insert and remove password cards on the iNodes. The encryption of the virtual machine is entirely implemented in software. Furthermore, the operation is completed through communication and interaction between the virtualization management platform, iNodes, and KMS. This eliminates the need for human intervention, significantly saving manpower and time costs. This effect is particularly pronounced when there are a large number of iNodes.
[0110] Figure 7 A virtual machine encryption / decryption device provided in this embodiment of the invention includes: a receiving module 701, a starting module 702, a sending module 703, and an acquisition module 704.
[0111] The receiving module 701 is used to receive a control message for starting a virtual machine sent by the virtualization management platform. The control message includes the identification information of the virtual machine to be started and the control instructions corresponding to the operation to be performed on the virtual machine.
[0112] The startup module 702 is used to start the virtual machine corresponding to the control message according to the control message;
[0113] The sending module 703 is used to send the identification information of the virtual machine to the password management system KMS;
[0114] The acquisition module 704 is used to acquire the key sent by KMS corresponding to the identification information;
[0115] The encryption / decryption module is used to perform encryption or decryption operations on the virtual machine based on the key and control instructions.
[0116] Optionally, module 704 is also used to obtain KMS configuration information sent by the virtualization management platform;
[0117] The sending module 703 is also used to transmit configuration information to the virtualization management platform, so that the virtualization management platform can generate and send control messages to the iNode after verifying that the configuration information fed back by the iNode is accurate.
[0118] Optionally, the device may also include a creation module 705.
[0119] Module 705 is created to establish a secure communication channel with KMS, enabling information exchange between KMS and KMS through this secure communication channel.
[0120] Optional configuration information for KMS includes KMS IP address, port information, KMS certificate, and the password bound to the certificate.
[0121] This invention provides a virtual machine encryption / decryption device that receives a control message from a virtualization management platform to start a virtual machine. Based on the control message, the device starts the virtual machine corresponding to that control message. Then, the device sends the virtual machine's identification information to a Virtualization Management System (KMS) and obtains a key corresponding to the identification information from the KMS. The device then encrypts or decrypts the virtual machine using the key. Throughout this process, the need to insert and remove a password card on the iNode is eliminated. The encryption of the virtual machine is entirely implemented in software. Furthermore, the operation is completed through communication and interaction between the virtualization management platform, the iNode, and the KMS. This eliminates the need for manual intervention, significantly saving manpower and time costs. This effect is particularly pronounced when dealing with a large number of iNodes.
[0122] Figure 8 This is a schematic diagram of another virtual machine encryption / decryption device provided in an embodiment of the present invention. The device includes: an acquisition module 801, a startup module 802, and a sending module 803.
[0123] Module 801 is used to obtain license verification information;
[0124] The startup module 802 is used to initiate virtual machine encryption or decryption triggering operations when the level of the license verification information is determined to be a preset level.
[0125] The acquisition module 801 is also used to acquire KMS configuration information based on the triggered operation;
[0126] The sending module 803 is used to distribute the KMS configuration information to each iNode that has established a communication connection with the virtualization management platform when it is determined that the KMS configuration information is valid.
[0127] Optionally, the license verification information level includes a standard level and a security level, with the default level being the security level.
[0128] This invention provides a virtual machine encryption / decryption device. First, it acquires license verification information. Then, if the license verification information is deemed secure, it initiates a virtual machine encryption or decryption trigger operation. Based on the trigger operation, it acquires KMS configuration information. Then, if the KMS configuration information is deemed valid, it distributes the KMS configuration information to each iNode that has established a communication connection with the virtualization management platform. This allows the iNode to subsequently establish a communication connection with the KMS based on the configuration information, complete the interaction process, and obtain the key for encryption / decryption operations on the virtual machine. The encryption / decryption operation on the virtual machine is then completed using the key. This process eliminates the need to insert and remove password cards on the iNodes. The encryption of the virtual machine is entirely implemented in software. Furthermore, the operation is completed through communication and interaction between the virtualization management platform, the iNodes, and the KMS. This eliminates the need for human intervention, significantly saving manpower and time costs. This effect is particularly pronounced when there are a large number of iNodes.
[0129] like Figure 9 As shown, this application embodiment provides a computer device that can act as an iNode, executing all operations of the iNode; or it can act as a virtualization management platform, executing all operations of the virtualization management platform. Of course, in this embodiment, a single computer device performs only one function at a time. Therefore, the entire virtualization platform system includes multiple computer devices.
[0130] Each computer device includes a processor 111, a communication interface 112, a memory 113, and a communication bus 114, wherein the processor 111, the communication interface 112, and the memory 113 communicate with each other through the communication bus 114.
[0131] Memory 113 is used to store computer programs;
[0132] In one embodiment of this application, the processor 111, when executing a program stored in the memory 113, implements... Figure 1 The virtual machine encryption / decryption method provided in the corresponding method embodiment includes:
[0133] Receive control messages from the virtualization management platform to start virtual machines. The control messages include the identification information of the virtual machine to be started, as well as the control instructions corresponding to the operations to be performed on the virtual machine.
[0134] Start the virtual machine corresponding to the control message;
[0135] Send the virtual machine's identification information to the password management system (KMS);
[0136] Obtain the key sent by KMS corresponding to the identification information;
[0137] Based on the key and control instructions, perform encryption or decryption operations on the virtual machine.
[0138] Optionally, the system receives a control message from the virtualization management platform to start a virtual machine. This control message includes the identification information of the virtual machine to be started, and before the control instructions corresponding to the operations to be performed on the virtual machine, it also includes:
[0139] Obtain KMS configuration information sent by the virtualization management platform;
[0140] The configuration information is transmitted to the virtualization management platform so that the virtualization management platform can verify the accuracy of the configuration information fed back by the iNode, and then generate and send control messages to the iNode.
[0141] Optionally, after obtaining the KMS configuration information sent by the virtualization management platform, the method further includes: creating a secure communication channel with the KMS so as to complete information interaction with the KMS through the secure communication channel.
[0142] Optional configuration information for KMS includes KMS IP address, port information, KMS certificate, and the password bound to the certificate.
[0143] In another embodiment of this application, the processor 111, when executing the program stored in the memory 113, implements the aforementioned... Figure 6 The virtual machine encryption / decryption method provided in the corresponding method embodiment includes:
[0144] Obtain license verification information;
[0145] When the level of the license verification information is determined to be the preset level, initiate virtual machine encryption or decryption trigger operation.
[0146] Based on the triggered operation, obtain KMS configuration information;
[0147] Once the KMS configuration information is determined to be valid, the KMS configuration information is distributed to each iNode that has established a communication connection with the virtualization management platform.
[0148] Optionally, the license verification information level includes a standard level and a security level, with the default level being the security level.
[0149] This application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a computer device, implements... Figure 1 The steps of the virtual machine encryption / decryption method provided in the corresponding method embodiment; or, implementing as follows Figure 6 The steps of the virtual machine encryption / decryption method provided in the corresponding method embodiment.
[0150] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.
[0151] The above are merely specific embodiments of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A virtual machine encryption / decryption method, characterized in that, The method is executed by iNode, and the method includes: The system receives a control message from the virtualization management platform to start a virtual machine. The control message includes the identification information of the virtual machine to be started, as well as the control instructions corresponding to the operation to be performed on the virtual machine. Start the virtual machine corresponding to the control message according to the control message; The identification information of the virtual machine is sent to the password management system KMS; Obtain the key sent by KMS that corresponds to the identification information; Based on the key and the control instructions, the virtual machine is encrypted or decrypted. Before receiving the control message for starting the virtual machine sent by the virtualization management platform, the method further includes: The configuration information of the KMS sent by the virtualization management platform is obtained. This configuration information includes the KMS's IP address, port information, certificate, and the password bound to the certificate. The password is generated based on machine code and serial number. The machine code generation logic includes: obtaining the physical machine's media access control address information and writing it into an encrypted file to be protected; obtaining the media access control address information from the encrypted file; encrypting the smallest block of the external device interconnection standard address to generate an index variable value; converting the index variable value into a binary number, performing a logical AND operation with a binary number generated by a preset fixed value, and then converting it into a hexadecimal string. The serial number is an encrypted character generated by a serial number management system. The configuration information is transmitted to the virtualization management platform so that the virtualization management platform can verify the accuracy of the configuration information fed back by the iNode, and then generate and send control messages to the iNode.
2. The method according to claim 1, characterized in that, After obtaining the KMS configuration information sent by the virtualization management platform, the method further includes: A secure communication channel is created between the KMS and the KMS to facilitate information exchange.
3. A virtual machine encryption / decryption device, characterized in that, The device includes: The receiving module is used to receive a control message for starting a virtual machine sent by the virtualization management platform. The control message includes the identification information of the virtual machine to be started and the control instructions corresponding to the operation to be performed on the virtual machine. A startup module is used to start the virtual machine corresponding to the control message according to the control message; The sending module is used to send the identification information of the virtual machine to the password management system KMS; The acquisition module is used to acquire the key sent by the KMS that corresponds to the identification information; An encryption / decryption module is used to perform encryption or decryption operations on the virtual machine based on the key and the control instructions; The acquisition module is further configured to acquire the KMS configuration information sent by the virtualization management platform. The KMS configuration information includes the KMS's IP address information, port information, KMS certificate, and the password bound to the certificate. The password is generated based on machine code and serial number. The machine code generation logic includes: acquiring the physical machine's media access control address information and writing it into an encrypted file to be protected; acquiring the media access control address information from the encrypted file; encrypting the smallest block of the external device interconnection standard address to generate an index variable value; converting the index variable value into a binary number, performing a logical AND operation with a binary number generated from a preset fixed value, and then converting it into a hexadecimal string. The serial number is an encrypted character generated by the serial number management system. The sending module is further configured to transmit the configuration information to the virtualization management platform, so that the virtualization management platform can generate and send control messages to the iNode after verifying the accuracy of the configuration information fed back by the iNode.
4. A computer device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, when executing a program stored in memory, implements the steps of the virtual machine encryption / decryption method as described in claim 1 or 2.
5. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the computer device as described in claim 4, it implements the steps of the virtual machine encryption / decryption method as described in claim 1 or 2.
Citation Information
Patent Citations
Method, apparatus and system for encryption / decryption in virtualization system
CN106063218A
Security control method and system for software-defined storage in InCloud Rail system
CN112000423A
Virtual machine disk data encryption and decryption method and device, equipment and storage medium
CN113285804A
Distributed management and installation of digital certificates on a cluster for authentication with an external key management service
US20210218723A1