A virtual machine migration method, apparatus, device and storage medium
By creating a target virtual machine in the user area of the destination host and sending the key from the user area to the secure area, the problem of insufficient key security and complex handshake in the virtual machine migration process is solved, and a higher key security and simplified handshake process is achieved.
Patent Information
- Application Number
- CN202210258994.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-16
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-03-16
AI Technical Summary
In the prior art, during the virtual machine migration process, the vTPCM key is insufficient, and the handshake process of metric information transmission is complicated.
By creating a target virtual machine in the user area of the destination host, and randomly generating the target key pair according to the preset key generation algorithm, sending it from the user area to the security area, improving the security of the key and simplifying the handshake process of metric information transmission.
It improves the security of keys during virtual machine migration, simplifies the handshake process of metric information transmission, and enhances the security and efficiency of the system.
Smart Images

Figure CN114611163B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing, and particularly to a virtual machine migration method, device, equipment and storage medium. Background Art
[0002] The PKS architecture is a green, open and shared technical architecture and ecological system led by China Electronics. "P" represents (PHYTIUM) Feiteng processor, "K" represents (KYLIN) Kylin operating system, and "S" represents the ability to inject security. Nowadays, cloud computing technology has developed rapidly. As an advantage of cloud services, virtual machine migration technology has received extensive attention and applications. However, in the existing single architecture, the vTPCM (virtual Trusted Platform Control Module) is actually in the user space, and attacks caused by vulnerabilities can steal the keys of the vTPCM and prevent measurement, making the vTPCM itself unable to be effectively protected.
[0003] As described above, methods for improving the security of keys during virtual machine migration and simplifying the measurement information transmission handshake process have become problems to be solved urgently.
[0004] The information disclosed in the above background art section is only used to enhance the understanding of the background of the present disclosure, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide a virtual machine migration method, device, equipment and storage medium, which can improve the security of keys during virtual machine migration and simplify the process of measuring information transmission handshake. The specific solutions are as follows:
[0006] In the first aspect, the present application discloses a virtual machine migration method, which is applied to a cloud management center and includes:
[0007] Sending a virtual machine migration instruction to a host, and creating a virtual machine corresponding to the original virtual machine in the host in the user area of the destination host to obtain a target virtual machine;
[0008] Randomly generating a target key pair according to a preset key generation algorithm, and sending the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host;
[0009] Sending a virtual machine cancellation instruction to the host, so that the host cancels the original virtual machine.
[0010] Optionally, randomly generating a target key pair according to a preset key generation algorithm, and sending the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host, includes:
[0011] Randomly generating a target key pair according to a preset key generation algorithm, and performing a one-to-one binding of the target key pair with the target virtual machine to obtain corresponding binding information;
[0012] Sending the target key pair and the binding information to the user area of the destination host, so that the destination host sends the target key pair and the binding information from the user area of the destination host to the security area of the destination host; wherein, the target virtual machine communicates with the security area of the destination host by using the target key pair.
[0013] Optionally, sending the target key pair and the binding information to the user area of the destination host, so that the destination host sends the target key pair and the binding information from the user area of the destination host to the security area of the destination host, includes:
[0014] Encrypting the target key pair by using a first private key to obtain an encrypted key pair;
[0015] Sending the encrypted key pair and the binding information to the user area of the destination host, so that after receiving the encrypted key pair and the binding information, the destination host sends preset information encrypted by using a second private key from the user area of the destination host to the security area of the destination host, and when the security area of the destination host successfully decrypts the encrypted preset information by using a second public key, sends the encrypted key pair and the binding information from the user area of the destination host to the security area of the destination host; wherein, the second private key and the second public key are keys corresponding to the destination host.
[0016] Optionally, sending the encrypted key pair and the binding information to the user area of the destination host, so that after receiving the encrypted key pair and the binding information, the destination host sends preset information encrypted by using a second private key from the user area of the destination host to the security area of the destination host, and when the security area of the destination host successfully decrypts the encrypted preset information by using a second public key, sends the encrypted key pair and the binding information from the user area of the destination host to the security area of the destination host, includes:
[0017] Send the encrypted key pair and the binding information to the user area of the destination host, so that after the destination host sends the encrypted key pair and the binding information from the user area of the destination host to the security area of the destination host, decrypt the encrypted key pair using the first public key stored in the security area of the destination host to obtain the target key pair;
[0018] Receive the reply information sent by the user area of the destination host; wherein, the reply information is the information triggered when decrypting the encrypted key pair and sent from the security area of the destination host to the user area of the destination host.
[0019] Optionally, the sending the target key pair and the binding information to the user area of the destination host, so that the destination host sends the target key pair and the binding information from the user area of the destination host to the security area of the destination host, further includes:
[0020] Store the first private key in the security area of the cloud management center; wherein, the first private key and the first public key are the keys corresponding to the cloud management center;
[0021] Send the first public key corresponding to the first private key to all physical machines, so that all the physical machines store the first public key in their own security areas.
[0022] Optionally, the receiving the reply information sent by the user area of the destination host includes:
[0023] Receive the reply information sent by the user area of the destination host; wherein, when the destination host sends the reply information to the cloud management center, receive the signature information of the original virtual machine sent by the host through the cloud management center; wherein, the signature information is the information obtained by the host using a preset signature algorithm to sign the information in the original virtual machine.
[0024] Optionally, the sending the virtual machine cancellation instruction to the host, so that the host cancels the original virtual machine, includes:
[0025] Receive the migration completion information sent by the destination host, and then update the target key pair corresponding to the target virtual machine in the security area of the cloud management center based on the binding information; all the target key pairs corresponding to the virtual machines on the destination host are stored in the security area of the cloud management center;
[0026] Send the virtual machine cancellation instruction encrypted with the first private key to the host, so that the host decrypts the virtual machine cancellation instruction using the first public key and then cancels the original virtual machine.
[0027] Second aspect, the present application discloses a virtual machine migration device, which is applied to a cloud management center and includes:
[0028] A first instruction sending module, configured to send a virtual machine migration instruction to a host;
[0029] A virtual machine creation module, configured to create a virtual machine corresponding to the original virtual machine in the host on the user area of the destination host to obtain a target virtual machine;
[0030] A key pair generation module, configured to randomly generate a target key pair according to a preset key generation algorithm, and send the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host;
[0031] A second instruction sending module, configured to send a virtual machine cancellation instruction to the host, so that the host cancels the original virtual machine.
[0032] Third aspect, the present application discloses an electronic device, including:
[0033] A memory, configured to store a computer program;
[0034] A processor, configured to execute the computer program to implement the steps of the virtual machine migration method as disclosed above.
[0035] Fourth aspect, the present application discloses a computer-readable storage medium, configured to store a computer program; wherein, when the computer program is executed by a processor, the virtual machine migration method as disclosed above is implemented.
[0036] It can be seen that the present application provides a virtual machine migration method, including: sending a virtual machine migration instruction to a host, and creating a virtual machine corresponding to the original virtual machine in the host on the user area of the destination host to obtain a target virtual machine; randomly generating a target key pair according to a preset key generation algorithm, and sending the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host; sending a virtual machine cancellation instruction to the host, so that the host cancels the original virtual machine. Thus, in the present application, the cloud management center first creates a target virtual machine in the user area of the destination host, and then sends the generated target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host. The security of the security area in the dual architecture is stronger than that of the user area, which improves the security of the corresponding target key pair during the virtual machine migration process and simplifies the process of the measurement information transmission handshake. Description of the Drawings
[0037] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on the provided drawings.
[0038] Figure 1 Flowchart of a virtual machine migration method disclosed in this application;
[0039] Figure 2 Schematic diagram of a specific virtual machine migration method disclosed in this application;
[0040] Figure 3 Flowchart of a specific virtual machine migration method disclosed in this application;
[0041] Figure 4 Flowchart of a specific virtual machine migration method disclosed in this application;
[0042] Figure 5 Schematic diagram of the structure of a virtual machine migration device provided by this application;
[0043] Figure 6 Structure diagram of an electronic device provided by this application. Detailed implementation manners
[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0045] Currently, the PKS architecture is a green, open, and shared technical architecture and ecological system led by China Electronics. "P" represents (PHYTIUM) Feiteng processor, "K" represents (KYLIN) Kylin operating system, and "S" represents the ability to inject security. Nowadays, cloud computing technology has developed rapidly. As an advantage of cloud services, virtual machine migration technology has received extensive attention and application. However, vTPCM itself cannot be effectively protected, and there are problems with the security of keys during virtual machine migration and the complexity of the measurement information transmission handshake. Therefore, this application provides a virtual machine migration method, which can improve the security of the corresponding target key pair during virtual machine migration and simplify the process of the measurement information transmission handshake.
[0046] The embodiments of the present invention disclose a virtual machine migration method. Refer to Figure 1As shown, applied to the cloud management center, the method includes:
[0047] Step S11: Send a virtual machine migration instruction to the host machine, and create a virtual machine corresponding to the original virtual machine in the host machine on the user area of the destination host to obtain a target virtual machine.
[0048] In this embodiment, first, the cloud management center sends a virtual machine migration instruction to the host machine, and creates a virtual machine corresponding to the original virtual machine in the host machine on the user area of the destination host to obtain a target virtual machine. It should be noted that the cloud management center and all physical machines under the management of the cloud management center adopt a dual-architecture mode, and the cloud environment forms a trusted cloud environment with dual architecture. The dual architecture includes two parts: the user area and the security area. As Figure 2 shown, the cloud management center OS (Operating System) controls two physical hosts: Host OS1 (the system in the physical machine) and Host OS2. For example, there are multiple virtual machines on the user area of Host OS1, denoted as V11 to V1n, and there are corresponding vTCM (virtual trusted cryptography module), TCM (Trusted Cryptography Module), and TPCM (Trusted Platform Control Module) for each virtual machine in the security area of Host OS1. It can be understood that when a virtual machine located in the user area of a physical machine communicates with the security area of the physical machine, it needs to pass through a preset driver. A virtual machine located in the user area of a physical machine can communicate with the physical machine through a hypervisor (an intermediate layer software running between the physical server and the operating system). In addition, the dual architecture solves the efficiency problems of vTPCM semi-virtualization and full virtualization.
[0049] Step S12: Randomly generate a target key pair according to a preset key generation algorithm, and send the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host.
[0050] In this embodiment, after creating a target virtual machine corresponding to the original virtual machine in the host on the user area of the destination host, a target key pair is randomly generated according to a preset key generation algorithm, and then the target key pair is sent to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host. It can be understood that the user area of the destination host interacts with the cloud management center, while the security area of the destination host only interacts with the user area of the destination host, and the above preset key generation algorithm can be any key generation algorithm.
[0051] Step S13: Send a virtual machine cancellation instruction to the host, so that the host cancels the original virtual machine.
[0052] In this embodiment, after sending the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host, a virtual machine cancellation instruction is sent to the host, so that the host cancels the original virtual machine. It can be understood that before sending the virtual machine cancellation instruction to the host, the virtual machine cancellation instruction is encrypted using the first private key of the cloud management center itself to obtain the encrypted virtual machine cancellation instruction, and then the encrypted virtual machine cancellation instruction is sent to the host. Specifically, after receiving the encrypted virtual machine cancellation instruction, the host decrypts the encrypted virtual machine cancellation instruction using the first public key stored in the security area of the host. When the decryption is successful, it indicates that the source of the virtual machine cancellation instruction is correct, so that the host cancels the original virtual machine.
[0053] It can be seen that the present application provides a virtual machine migration method, including: sending a virtual machine migration instruction to a host, and creating a virtual machine corresponding to the original virtual machine in the host on the user area of the destination host to obtain a target virtual machine; randomly generating a target key pair according to a preset key generation algorithm, and sending the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host; sending a virtual machine cancellation instruction to the host, so that the host cancels the original virtual machine. Thus, in the present application, the cloud management center first creates a target virtual machine in the user area of the destination host, and then sends the generated target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host. The security of the security area in the dual architecture is stronger than that of the user area, which improves the security of the corresponding target key pair during the virtual machine migration process and simplifies the process of measuring information transmission handshake.
[0054] SeeFigure 3 As shown in Figure 3 , an embodiment of the present invention discloses a virtual machine migration method. Compared with the previous embodiment, this embodiment further describes and optimizes the technical solution.
[0055] Step S21: Send a virtual machine migration instruction to the host, and create a virtual machine corresponding to the original virtual machine in the host on the user area of the destination host to obtain a target virtual machine.
[0056] Step S22: Randomly generate a target key pair according to a preset key generation algorithm, and bind the target key pair to the target virtual machine one by one to obtain corresponding binding information.
[0057] In this embodiment, after creating the target virtual machine corresponding to the original virtual machine in the host on the user area of the destination host, a target key pair is randomly generated according to a preset key generation algorithm, and then the target key pair is bound to the target virtual machine one by one to obtain corresponding binding information. It can be understood that binding the target key pair to the target virtual machine one by one means that a target virtual machine has one and only one target key pair, and the binding information is the mapping relationship between the virtual machine and the target key pair. Therefore, when there are multiple virtual machines and multiple target key pairs, the target key pair corresponding to each virtual machine can be determined through the binding information. It should be noted that the cloud management center is a trusted centralized management center for VMs (Virtual Machines). When the cloud management center creates the target virtual machine in the user area of the destination host, the target key pair of the target virtual machine is generated in the security area of the cloud management center, and the target virtual machine is bound to the target key pair. In addition, the target virtual machine communicates with the security area of the destination host using the target key pair.
[0058] Step S23: Encrypt the target key pair using the first private key to obtain an encrypted key pair.
[0059] In this embodiment, after binding the target key pair to the target virtual machine one by one and obtaining corresponding binding information, the target key pair is encrypted using the first private key to obtain an encrypted key pair. It can be understood that encrypting the target key pair using the first private key ensures the security of the above target key pair during transmission between the cloud management center and the user area of the destination host.
[0060] Step S24: Send the encrypted key pair and the binding information to the user area of the destination host, so that after receiving the encrypted key pair and the binding information, the destination host sends the preset information encrypted with the second private key from the user area of the destination host to the security area of the destination host. When the security area of the destination host successfully decrypts the encrypted preset information with the second public key, send the encrypted key pair and the binding information from the user area of the destination host to the security area of the destination host; wherein, the second private key and the second public key are the keys corresponding to the destination host.
[0061] In this embodiment, the encrypted key pair and the binding information are sent to the user area of the destination host, so that after receiving the encrypted key pair and the binding information, the destination host sends the preset information encrypted with the second private key from the user area of the destination host to the security area of the destination host. When the security area of the destination host successfully decrypts the encrypted preset information with the second public key, send the encrypted key pair and the binding information from the user area of the destination host to the security area of the destination host. It can be understood that when the security area of the destination host successfully decrypts the encrypted preset information with the second public key, the encrypted key pair and the binding information are sent from the user area of the destination host to the security area of the destination host, and then the encrypted key pair is decrypted with the first public key stored in the security area of the destination host to obtain the target key pair.
[0062] It should be noted that the first private key is the private key stored in the security area of the cloud management center. The cloud management center sends the first public key corresponding to the first private key to all physical machines managed by the cloud management center, so that all the physical machines store the first public key in their own security areas. The first private key and the first public key are the keys corresponding to the cloud management center. The second private key and the second public key are the keys corresponding to the destination host.
[0063] Step S25: Send a virtual machine logout instruction to the host, so that the host logs out the original virtual machine.
[0064] For the specific content of the above steps S21 and S25, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.
[0065] It can be seen that in the embodiment of the present application, while creating the target virtual machine in the user area of the destination host, a target key pair of the target virtual machine is generated in the security area of the cloud management center, and the target virtual machine is bound to the target key pair to obtain binding information. Then, the encrypted key pair obtained by encrypting the target key pair with the first private key and the binding information are sent to the user area of the destination host. When the security area of the destination host successfully decrypts the encrypted preset information sent by the user area of the destination host using the second public key, the encrypted key pair and the binding information are sent from the user area of the destination host to the security area of the destination host, and then the encrypted key pair is decrypted using the first public key stored in the security area of the destination host to obtain the target key pair. This improves the security of the corresponding target key pair during the virtual machine migration process and simplifies the process of measuring information transmission handshake.
[0066] See Figure 4 As shown, the embodiment of the present invention discloses a virtual machine migration method. Compared with the previous embodiment, this embodiment further explains and optimizes the technical solution.
[0067] Step S31: Send a virtual machine migration instruction to the host and create a virtual machine corresponding to the original virtual machine in the host in the user area of the destination host to obtain a target virtual machine.
[0068] Step S32: Randomly generate a target key pair according to a preset key generation algorithm, and perform a one-to-one binding of the target key pair to the target virtual machine to obtain corresponding binding information.
[0069] Step S33: Encrypt the target key pair with the first private key to obtain an encrypted key pair.
[0070] Step S34: Send the encrypted key pair and the binding information to the user area of the destination host. After the destination host receives the encrypted key pair and the binding information, it sends the preset information encrypted with the second private key from the user area of the destination host to the security area of the destination host. When the security area of the destination host successfully decrypts the encrypted preset information using the second public key, the encrypted key pair and the binding information are sent from the user area of the destination host to the security area of the destination host; where the second private key and the second public key are the keys corresponding to the destination host.
[0071] Step S35: Receive the reply information sent by the user area of the destination host; where the reply information is the information triggered when decrypting the encrypted key pair and sent from the security area of the destination host to the user area of the destination host.
[0072] In this embodiment, reply information sent from the user area of the destination host is received. It can be understood that the reply information is information triggered when decrypting the encryption key pair and sent from the secure area of the destination host to the user area of the destination host. For example, when the secure area of the destination host successfully decrypts the encryption key pair, the reply information is that the encryption key pair is successfully decrypted. When the secure area of the destination host fails to decrypt the encryption key pair, the reply information is that the encryption key pair decryption fails.
[0073] It should be noted that when the destination host sends the reply information to the cloud management center, the signature information of the original virtual machine sent by the host is received through the cloud management center. The signature information is information obtained by the host signing the information in the original virtual machine using a preset signature algorithm. The preset signature algorithm can be a hash algorithm.
[0074] Step S36: Receive the migration completion information sent by the destination host, and then update the target key pair corresponding to the target virtual machine in the secure area of the cloud management center based on the binding information; the secure area of the cloud management center stores the target key pairs corresponding to all virtual machines on the destination host.
[0075] In this embodiment, when the secure area of the destination host successfully decrypts the encryption key pair and the destination host receives the signature information of the original virtual machine sent by the host through the cloud management center, it indicates that the virtual machine migration process is completed, and the destination host will return migration completion information to the cloud management center. It can be understood that after the cloud management center receives the migration completion information sent by the destination host, it updates the target key pair corresponding to the target virtual machine in the secure area of the cloud management center based on the binding information. It should be noted that the secure area of the cloud management center stores the vTCM of each VM on the destination host, thereby realizing TPCM passthrough.
[0076] Step S37: Send a virtual machine cancellation instruction encrypted with the first private key to the host, so that the host cancels the original virtual machine after decrypting the virtual machine cancellation instruction using the first public key.
[0077] In this embodiment, after the cloud management center updates the target key pair corresponding to the target virtual machine in the security area of the cloud management center based on the binding information, it sends a virtual machine cancellation instruction encrypted with the first private key to the host, so that the host cancels the original virtual machine after decrypting the virtual machine cancellation instruction with the first public key. It can be understood that the virtual machine cancellation instruction is encrypted with the first private key and then the encrypted virtual machine cancellation instruction is sent to the host. When the host receives the encrypted virtual machine cancellation instruction, it calls the first public key stored in the security area of the host for decryption. When the decryption is successful, it indicates that the source of the encrypted virtual machine cancellation instruction is the cloud management center, and then the original virtual machine is cancelled. If the decryption fails, it indicates that the source of the encrypted virtual machine cancellation instruction is not the cloud management center, and the current operation is ended without cancelling the original virtual machine.
[0078] For the specific content of the above steps S31 to S34, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.
[0079] It can be seen that after the encryption key pair and the binding information are sent to the user area of the destination host in the embodiment of the present application, the reply information sent by the user area of the destination host is received to determine whether the target key pair has been stored in the security area of the destination host. At the same time, the destination host receives the signature information of the original virtual machine sent by the host through the cloud management center. Then, the migration completion information sent by the destination host is received, the target key pair corresponding to the target virtual machine is updated in the security area of the cloud management center based on the binding information, and a virtual machine cancellation instruction encrypted with the first private key is sent to the host, so that the host cancels the original virtual machine after determining that the source of the virtual machine cancellation instruction is the cloud management center by using the first public key. The security of the corresponding target key pair during the virtual machine migration process is improved, and the process of measuring information transmission handshake is simplified.
[0080] See Figure 5 As shown, the embodiment of the present application also correspondingly discloses a virtual machine migration device, which is applied to a cloud management center and includes:
[0081] A first instruction sending module 11, configured to send a virtual machine migration instruction to a host;
[0082] A virtual machine creation module 12, configured to create a virtual machine corresponding to the original virtual machine in the host on the user area of the destination host to obtain a target virtual machine;
[0083] The key pair generation module 13 is used to randomly generate a target key pair according to a preset key generation algorithm, and send the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host;
[0084] The second instruction sending module 14 is used to send a virtual machine cancellation instruction to the host computer, so that the host computer cancels the original virtual machine.
[0085] It can be seen that this application includes: sending a virtual machine migration instruction to the host computer, and creating a virtual machine corresponding to the original virtual machine in the host computer on the user area of the destination host to obtain a target virtual machine; randomly generating a target key pair according to a preset key generation algorithm, and sending the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host; sending a virtual machine cancellation instruction to the host computer, so that the host computer cancels the original virtual machine. Thus, it can be seen that in this application, the cloud management center first creates a target virtual machine in the user area of the destination host, and then sends the generated target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host. The security of the security area in the dual architecture is stronger than that of the user area, which improves the security of the corresponding target key pair during the virtual machine migration process and simplifies the process of measuring information transmission handshake.
[0086] In some specific embodiments, the key pair generation module 13 specifically includes:
[0087] The key pair generation unit is used to randomly generate a target key pair according to a preset key generation algorithm;
[0088] The key pair binding unit is used to perform one-to-one binding of the target key pair and the target virtual machine to obtain corresponding binding information;
[0089] The key pair sending unit is used to send the target key pair and the binding information to the user area of the destination host, so that the destination host sends the target key pair and the binding information from the user area of the destination host to the security area of the destination host.
[0090] In some specific embodiments, the second instruction sending module 14 specifically includes:
[0091] The information receiving unit is used to receive the migration completion information sent by the destination host;
[0092] The key pair update unit is used to update the target key pair corresponding to the target virtual machine in the security area of the cloud management center based on the binding information;
[0093] An instruction encryption unit, configured to encrypt a virtual machine logout instruction by using the first private key to obtain the encrypted virtual machine logout instruction;
[0094] An instruction sending unit, configured to send the encrypted virtual machine logout instruction to the host computer, so that the host computer can cancel the original virtual machine after decrypting the virtual machine logout instruction by using the first public key.
[0095] Furthermore, an embodiment of the present application further provides an electronic device. Figure 6 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure cannot be regarded as any limitation on the scope of use of the present application.
[0096] Figure 6 It is a schematic structural diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the virtual machine migration method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0097] In this embodiment, the power supply 23 is used to provide operating voltages for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application requirements, and no specific limitation is made here.
[0098] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc., and the resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be short-term storage or permanent storage.
[0099] Among them, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device 20, and it may be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the virtual machine migration method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs that can be used to complete other specific tasks.
[0100] Further, the embodiments of the present application also disclose a storage medium, in which a computer program is stored. When the computer program is loaded and executed by a processor, the method steps of virtual machine migration disclosed in any of the foregoing embodiments are implemented.
[0101] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part.
[0102] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0103] The above has introduced in detail a virtual machine migration method, device, equipment and storage medium provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A virtual machine migration method, characterized in that, applied to a cloud management center, including: sending a virtual machine migration instruction to a host, and creating a virtual machine corresponding to the original virtual machine in the host in the user area of the destination host to obtain a target virtual machine; randomly generating a target key pair according to a preset key generation algorithm, and sending the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host; sending a virtual machine cancellation instruction to the host, so that the host cancels the original virtual machine; wherein, the cloud management center and all physical machines under the management of the cloud management center adopt a dual-architecture mode, and the cloud environment forms a dual-architecture trusted cloud environment, and the dual-architecture includes two parts: a user area and a security area; The step of randomly generating a target key pair according to a preset key generation algorithm, and sending the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host includes: randomly generating a target key pair according to a preset key generation algorithm, and binding the target key pair to the target virtual machine one by one to obtain corresponding binding information; sending the target key pair and the binding information to the user area of the destination host, so that the destination host sends the target key pair and the binding information from the user area of the destination host to the security area of the destination host; wherein, the target virtual machine communicates with the security area of the destination host by using the target key pair.
2. The virtual machine migration method according to claim 1, characterized in that, the step of sending the target key pair and the binding information to the user area of the destination host, so that the destination host sends the target key pair and the binding information from the user area of the destination host to the security area of the destination host includes: encrypting the target key pair by using a first private key to obtain an encrypted key pair; sending the encrypted key pair and the binding information to the user area of the destination host, so that after receiving the encrypted key pair and the binding information, the destination host sends the preset information encrypted by using a second private key from the user area of the destination host to the security area of the destination host, and when the security area of the destination host successfully decrypts the encrypted preset information by using a second public key, the encrypted key pair and the binding information are sent from the user area of the destination host to the security area of the destination host; wherein, the second private key and the second public key are the keys corresponding to the destination host.
3. The virtual machine migration method according to claim 2, characterized in that, Sending the encryption key pair and the binding information to the user area of the destination host, so that after the destination host receives the encryption key pair and the binding information, the destination host sends the preset information encrypted by the second private key from the user area of the destination host to the security area of the destination host. When the security area of the destination host successfully decrypts the encrypted preset information by using the second public key, sending the encryption key pair and the binding information from the user area of the destination host to the security area of the destination host, includes: Sending the encryption key pair and the binding information to the user area of the destination host, so that after the destination host sends the encryption key pair and the binding information from the user area of the destination host to the security area of the destination host, decrypting the encryption key pair by using the first public key stored in the security area of the destination host to obtain the target key pair; Receiving the reply information sent by the user area of the destination host; wherein, the reply information is the information triggered when decrypting the encryption key pair, which is sent from the security area of the destination host to the user area of the destination host.
4. The virtual machine migration method according to claim 3, wherein, further includes: Storing the first private key in the security area of the cloud management center; wherein, the first private key and the first public key are the keys corresponding to the cloud management center; Sending the first public key corresponding to the first private key to all physical machines, so that all the physical machines store the first public key in their own security areas.
5. The virtual machine migration method according to claim 3, wherein, The receiving the reply information sent by the user area of the destination host includes: Receiving the reply information sent by the user area of the destination host; wherein, when the destination host sends the reply information to the cloud management center, receiving the signature information of the original virtual machine sent by the host through the cloud management center; wherein, the signature information is the information obtained by the host using a preset signature algorithm to sign the information in the original virtual machine.
6. The virtual machine migration method according to any one of claims 3 to 5, wherein, The sending the virtual machine cancellation instruction to the host, so that the host cancels the original virtual machine, includes: Receiving the migration completion information sent by the destination host, and then updating the target key pair corresponding to the target virtual machine in the security area of the cloud management center based on the binding information; the security area of the cloud management center stores the target key pairs corresponding to all virtual machines on the destination host; Sending the virtual machine cancellation instruction encrypted by the first private key to the host, so that the host cancels the original virtual machine after decrypting the virtual machine cancellation instruction by using the first public key.
7. A virtual machine migration device, wherein, Applied to the cloud management center, includes: A first instruction sending module, configured to send a virtual machine migration instruction to a host; A virtual machine creation module, configured to create a virtual machine corresponding to the original virtual machine in the host machine on the user area of the destination host to obtain a target virtual machine; A key pair generation module, configured to randomly generate a target key pair according to a preset key generation algorithm, and send the target key pair to the user area of the destination host, so that the destination host sends the target key pair from the user area of the destination host to the security area of the destination host; A second instruction sending module, configured to send a virtual machine cancellation instruction to the host machine, so that the host machine cancels the original virtual machine; wherein, the cloud management center and all physical machines under the management of the cloud management center adopt a dual-architecture mode, and the cloud environment forms a trusted cloud environment with a dual-architecture, and the dual-architecture includes two parts: a user area and a security area; The key pair generation module specifically includes: A key pair generation unit, configured to randomly generate a target key pair according to a preset key generation algorithm; A key pair binding unit, configured to perform one-to-one binding of the target key pair and the target virtual machine to obtain corresponding binding information; A key pair sending unit, configured to send the target key pair and the binding information to the user area of the destination host, so that the destination host sends the target key pair and the binding information from the user area of the destination host to the security area of the destination host; wherein, the target virtual machine communicates with the security area of the destination host by using the target key pair.
8. An electronic device, characterized in that, it includes: A memory, configured to store a computer program; A processor, configured to execute the computer program to implement the steps of the virtual machine migration method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, it is used to store a computer program; wherein, when the computer program is executed by a processor, it implements the virtual machine migration method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Secure Key Derivation Functions
CN107111728A
Virtual machine password information safety migration implementation method and system
CN108718316A