A virtual machine encryption method, device, equipment, and storage medium

By using asymmetric key pairs and symmetric key encryption methods based on the national secret algorithm in virtual machine encryption, the security issues of key transfer and authentication in virtual machine disk encryption are solved, and the security protection of virtual machine data is achieved.

CN115348077BActive Publication Date: 2025-05-16JINAN INSPUR DATA TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210969043.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-12
Publication Date
2025-05-16
Estimated Expiration
2042-08-12

AI Technical Summary

Technical Problem

In the prior art, there is a risk of exposure when the virtual machine disk is encrypted, which can easily lead to key leakage and information data leakage.

Method used

By generating an asymmetric key pair based on the first national secret algorithm, and using the server to generate a symmetric key based on the second national secret algorithm, the symmetric key is encrypted by using the asymmetric public key to ensure the security of the key transmission process.

Benefits of technology

It effectively protects the keys to prevent key leakage, ensures the security of the virtual machine disk encryption process, and provides continuous protection of virtual machine data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115348077B_ABST
    Figure CN115348077B_ABST
Patent Text Reader

Abstract

The present application discloses a virtual machine encryption method, device, equipment, and storage medium, which relates to the field of computer technology, including: when receiving a virtual machine creation request proposed by a user, generating an asymmetric key pair including a first public key and a first private key based on a first national secret algorithm, a user unique identifier, and user parameter information; generating a symmetric key through a server and based on a second national secret algorithm; encrypting the symmetric key with the first public key to obtain a target key; obtaining authorization information of a user authorization request generated by the virtual machine creation request returned by the server; when the authorization information is authenticated, decrypting the target key with the first private key, and creating a virtual disk corresponding to the current virtual machine with the symmetric key to complete virtual machine encryption. By using asymmetric public key encryption for the symmetric key, the security of the key transmission process is guaranteed, and when the user operates the virtual machine, the authorization information is verified again to ensure the security of the virtual machine operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a virtual machine encryption method, device, equipment, and storage medium. Background Art

[0002] At present, my country's information infrastructure construction has been in a passive situation. China's IT industry is heavily dependent on foreign manufacturers in the fields of underlying architecture, standards, products, etc., and there is a risk of key technologies being blocked. Against this background, an alternative industrial chain from underlying chips to upper-level applications has been gradually established, and key links such as domestic CPUs, domestic operating systems, and domestic application software have also achieved significant breakthroughs. The information industry chain is becoming more and more perfect, and enterprises are gradually using domestic virtualization platforms to manage physical resources. The core data assets of virtual machine companies must ensure information security and must prevent information leakage. In order to prevent information leakage, encryption of virtual machine disks is usually adopted. However, this method requires the transmission of keys and verification of identity information between different ends. In this way, the keys required to encrypt virtual machine disks are at risk of being exposed, and keys are easily leaked, resulting in information data leakage.

[0003] In summary, how to encrypt and protect the key and ensure the security of the key transmission process is a technical problem to be solved in this field. Summary of the invention

[0004] In view of this, the purpose of the present invention is to provide a virtual machine encryption method, device, equipment, and storage medium, which can encrypt and protect the key and ensure the security of the key transmission process. The specific scheme is as follows:

[0005] In a first aspect, the present application discloses a virtual machine encryption method, comprising:

[0006] When receiving a virtual machine creation request from a user, an asymmetric key pair including a first public key and a first private key is generated based on a first national secret algorithm, a user unique identifier, and user parameter information; a symmetric key is generated through a server based on a second national secret algorithm;

[0007] Encrypting the symmetric key using the first public key to obtain a target key;

[0008] Obtain authorization information of a user authorization request generated by the virtual machine creation request returned by the server;

[0009] When the authorization information is authenticated, the target key is obtained from the server, and the target key is decrypted using the first private key, so that the virtual disk corresponding to the current virtual machine is created using the symmetric key to complete virtual machine encryption.

[0010] Optionally, the process of generating an asymmetric key pair including a first public key and a first private key based on the first national secret algorithm, the user unique identifier and the user parameter information further includes:

[0011] Generate a transmission key through the client based on a second national secret algorithm, so as to encrypt the first private key with the transmission key to obtain a first encryption key;

[0012] Encrypting the transmission key using the first public key to obtain an encrypted transmission key;

[0013] The first encryption key, the encryption transmission key, and the first public key are sent to a certificate authority so that the certificate authority can perform an encryption certificate signing operation and issue a corresponding encryption certificate through a certificate registration and approval system.

[0014] Optionally, the process of generating a symmetric key through the server based on the second national secret algorithm further includes:

[0015] Use the virtualization platform to create virtual machines and determine computing nodes.

[0016] Optionally, before using the virtualization platform to create a virtual machine and determine the computing node, the process further includes:

[0017] A computing node is added to the virtualization platform in advance, an asymmetric key pair is generated using the unique identifier of the computing node, the asymmetric key pair is stored in a client database, and then the first public key is sent to the virtualization platform database.

[0018] Optionally, obtaining authorization information of a user authorization request generated by the server in response to the virtual machine creation request includes:

[0019] Generate a first random number based on a user authorization request sent by the user including user information and an application key, and obtain a second random number sent by the server;

[0020] Concatenate the first random number and the second random number to obtain a concatenated random number, and send the concatenated random number and an application key corresponding to the virtualization platform application to the client;

[0021] Generate a hash message authentication code based on the concatenated random number and the application key;

[0022] The hash message authentication code and the second random number are sent to the server so that the server can authorize the user authorization request.

[0023] Optionally, the generating a hash message authentication code based on the concatenated random number and the application key includes:

[0024] A hash message authentication code is generated based on the concatenated random number and the application key using the SM3 cryptographic hash function standard algorithm.

[0025] Optionally, using the symmetric key to create a virtual disk corresponding to the current virtual machine to complete virtual machine encryption includes:

[0026] The target data of the current virtual machine operation is encrypted and decrypted using a symmetric key to complete virtual machine encryption.

[0027] In a second aspect, the present application discloses a virtual machine encryption device, comprising:

[0028] A key generation module, configured to generate an asymmetric key pair including a first public key and a first private key based on a first national secret algorithm, a user unique identifier and user parameter information when receiving a virtual machine creation request from a user; and generate a symmetric key based on a second national secret algorithm through a server;

[0029] A key encryption module, used to encrypt the symmetric key using the first public key to obtain a target key;

[0030] An authorization acquisition module, used to acquire authorization information of a user authorization request generated by the virtual machine creation request returned by the server;

[0031] The virtual machine encryption module is used to obtain the target key from the server after the authorization information is authenticated, and use the first private key to decrypt the target key so as to use the symmetric key to create a virtual disk corresponding to the current virtual machine to complete the virtual machine encryption.

[0032] In a third aspect, the present application discloses an electronic device, comprising:

[0033] Memory, used to store computer programs;

[0034] The processor is used to execute the computer program to implement the steps of the virtual machine encryption method disclosed above.

[0035] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the aforementioned disclosed virtual machine encryption method are implemented.

[0036] It can be seen that the present application discloses a virtual machine encryption method, including: when receiving a virtual machine creation request proposed by a user, generating an asymmetric key pair including a first public key and a first private key based on a first national secret algorithm, a user unique identifier and user parameter information; generating a symmetric key through a server and based on a second national secret algorithm; encrypting the symmetric key using the first public key to obtain a target key; obtaining the authorization information of the user authorization request generated by the virtual machine creation request returned by the server; when the authorization information is authenticated, obtaining the target key from the server, decrypting the target key using the first private key, so as to use the symmetric key to create a virtual disk corresponding to the current virtual machine, and complete the virtual machine encryption. It can be seen that the present application encrypts the symmetric key using an asymmetric public key to ensure the security of the key transmission process, and then verifies the authorization information again when the user performs relevant operations on the virtual machine to ensure the security of the operation of the virtual machine, so that the virtual machine can provide continuous protection for data when the workload is moved, cloned or snapshotted in the enterprise infrastructure. Encrypting the virtual machine eliminates the risk of being restricted by hardware, virtual machine managers or cloud providers, and provides ideal fully portable protection for hybrid IT environments and workloads in transit. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0038] Figure 1 A flowchart of a virtual machine encryption method disclosed in this application;

[0039] Figure 2 A flowchart of a specific virtual machine encryption method disclosed in this application;

[0040] Figure 3 A process diagram for creating an encrypted virtual machine disclosed in this application;

[0041] Figure 4 A disk data encryption and decryption flow chart disclosed in this application;

[0042] Figure 5 This is another specific virtual machine encryption method flow chart disclosed in this application;

[0043] Figure 6 A process diagram for creating an SM2 asymmetric key disclosed in this application;

[0044] Figure 7A diagram of a server authentication process disclosed in this application;

[0045] Figure 8 This is a schematic diagram of the structure of a virtual machine encryption device disclosed in this application;

[0046] Fig. 9 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0047] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0048] At present, my country's information infrastructure construction has been in a passive situation. China's IT industry is heavily dependent on foreign manufacturers in the fields of underlying architecture, standards, products, etc., and there is a risk of key technologies being blocked. Against this background, an alternative industrial chain from underlying chips to upper-level applications has been gradually established, and key links such as domestic CPUs, domestic operating systems, and domestic application software have also achieved significant breakthroughs. The information industry chain is becoming more and more perfect, and enterprises are gradually using domestic virtualization platforms to manage physical resources. The core data assets of virtual machine companies must ensure information security and must prevent information leakage. In order to prevent information leakage, encryption of virtual machine disks is usually adopted. However, this method requires the transmission of keys and verification of identity information between different ends. In this way, the keys required to encrypt virtual machine disks are at risk of being exposed, and keys are easily leaked, resulting in information data leakage.

[0049] To this end, the present application provides a virtual machine encryption solution that can encrypt and protect keys to ensure the security of the key transmission process.

[0050] Reference Figure 1 As shown, an embodiment of the present invention discloses a virtual machine encryption method, comprising:

[0051] Step S11: When a virtual machine creation request is received from a user, an asymmetric key pair including a first public key and a first private key is generated based on a first national secret algorithm, a user unique identifier and user parameter information; and a symmetric key is generated through a server based on a second national secret algorithm.

[0052] In this embodiment, a transmission key is generated through the client and based on the second national secret algorithm, so that the first private key is encrypted with the transmission key to obtain the first encryption key; the transmission key is encrypted with the first public key to obtain the encrypted transmission key; the first encryption key, the encrypted transmission key, and the first public key are sent to the certificate management agency so that the certificate management agency can perform the encryption certificate signing operation and issue the corresponding encryption certificate through the certificate registration and approval system. It can be understood that when the security administrator creates a user, the virtualization platform will construct a request based on the user information related parameters and send it to the client; the client uses the user name as a unique identifier to generate an SM2 asymmetric key pair, that is, public key 1 and private key 1. The client also generates a symmetric key based on the SM4 national secret algorithm, that is, transmission key 1, and uses this transmission key 1 to encrypt the private key 1 in the asymmetric key to obtain the encrypted private key 1. The transmission key 1 is encrypted with the SM2 public key to obtain the encrypted transmission key 2. The client sends the encrypted transmission key 2, the encrypted encrypted private key 1, and the SM2 public key to the CA, and the CA sends the encrypted transmission key 2, the encrypted encrypted private key 1, and the SM2 public key to the CA. Issue user signature certificate and encryption certificate, send the issued certificate, encrypted private key 1, and encrypted transmission key 2 to RA, RA returns encryption certificate, signature certificate, encrypted private key 1, and encrypted transmission key 2 to the virtualization platform, the virtualization platform will send the user's unique identifier and encrypted transmission key 2 to the client, the client will use private key 1 to decrypt to obtain transmission key 1, and hand it over to the virtualization platform, the virtualization platform calls the client interface, uses transmission key 1 to decrypt the encrypted private key 2, obtains private key 1, and saves the SM2 private key, encryption certificate, and signature certificate in the user's Ukey. When the user logs in, Ukey will be used for secure login and identity authentication.

[0053] In this embodiment, the client uses the national secret algorithm SM2 to generate a persistent asymmetric key pair in advance, and the server uses the national secret algorithm SM4 to create a symmetric key, where the national secret algorithm SM2 is an elliptic curve public key cryptography algorithm issued by the Cryptography Administration, and the national secret algorithm SM4 is a block cipher algorithm issued by the Cryptography Administration.

[0054] Step S12: Encrypt the symmetric key using the first public key to obtain a target key.

[0055] In this embodiment, after the asymmetric key pair and the symmetric key created by the client and the server are obtained, the symmetric key is encrypted using the first public key in the asymmetric key pair to obtain the target key.

[0056] Step S13: Obtain authorization information of the user authorization request generated by the virtual machine creation request returned by the server.

[0057] In this embodiment, the server authenticates the virtualization platform through the authorization information generated by the virtualization platform. After the virtualization platform obtains the authorization, it can perform key-related operations on the server. It should be noted that if the authorization authentication cannot be passed during the authentication of the authorization information of the virtualization platform, the server refuses to provide the corresponding operation.

[0058] Step S14: When the authorization information is authenticated, the target key is obtained from the server, and the target key is decrypted using the first private key, so as to use the symmetric key to create a virtual disk corresponding to the current virtual machine, thereby completing virtual machine encryption.

[0059] In this embodiment, after the authorization information passes the authentication, the server provides a target key based on the unique identifier of the symmetric key, and uses the first private key to decrypt the target key. When the decryption is successful, the symmetric key is used to create a virtual disk in a preset format corresponding to the current virtual machine to complete the virtual machine encryption. For example, the decrypted SM4S symmetric key is used to create a virtual disk in LUKS (Linux Unified Key Setup Linux, a standard for hard disk encryption) format, so that each virtual machine uses a different SM4 key, so that the virtual disk of the virtual machine can only be used by the current virtual machine, ensuring the security of the data. That is, when the virtual machine is successfully created, the unique identifier of the virtual machine and its corresponding public key encrypted identifier are saved in the user's Ukey. Therefore, when the user performs related operations on the virtual machine, the virtualization platform will perform secondary identity authentication based on the identifier in the Ukey after decryption using the key; when the virtual disk reads and writes data, the corresponding key is used to encrypt and decrypt the data to ensure data security and prevent information leakage.

[0060] It can be seen that the present application discloses a virtual machine encryption method, including: when receiving a virtual machine creation request proposed by a user, generating an asymmetric key pair including a first public key and a first private key based on a first national secret algorithm, a user unique identifier and user parameter information; generating a symmetric key through a server and based on a second national secret algorithm; encrypting the symmetric key using the first public key to obtain a target key; obtaining the authorization information of the user authorization request generated by the virtual machine creation request returned by the server; when the authorization information is authenticated, obtaining the target key from the server, decrypting the target key using the first private key, so as to use the symmetric key to create a virtual disk corresponding to the current virtual machine, and complete the virtual machine encryption. It can be seen that the present application encrypts the symmetric key using an asymmetric public key to ensure the security of the key transmission process, and then verifies the authorization information again when the user performs relevant operations on the virtual machine to ensure the security of the operation of the virtual machine, so that the virtual machine can provide continuous protection for data when the workload is moved, cloned or snapshotted in the enterprise infrastructure. Encrypting the virtual machine eliminates the risk of being restricted by hardware, virtual machine managers or cloud providers, and provides ideal fully portable protection for hybrid IT environments and workloads in transit.

[0061] Reference Figure 2 As shown, the embodiment of the present invention discloses a specific virtual machine encryption method. Compared with the previous embodiment, this embodiment further explains and optimizes the technical solution. Specifically:

[0062] Step S21: When a virtual machine creation request from a user is received, an asymmetric key pair including a first public key and a first private key is generated based on a first national encryption algorithm, a user unique identifier and user parameter information.

[0063] For a more detailed processing procedure in step S21, please refer to the aforementioned disclosed embodiment content, which will not be described again here.

[0064] Step S22: Create a virtual machine using the virtualization platform, determine the computing node, and then generate a symmetric key through the server based on the second national encryption algorithm.

[0065] In this embodiment, the process of creating a virtual machine using a virtualization platform and determining a computing node also includes: pre-adding a computing node to the virtualization platform, generating an asymmetric key pair using the unique identifier of the computing node, storing the asymmetric key pair in the client database, and then sending the first public key to the virtualization platform database. The client generates a public-private key pair, and the public key is stored in the virtualization platform. The server establishes a corresponding application and generates a corresponding user key. It can be understood that when the virtualization platform adds a new computing node, it uses the unique identifier of the computing node to generate a public-private key pair on the client side of the key management system. This public-private key pair needs to be persisted in the client, and the public key is stored in the database of the virtualization platform, where the public key is an SM2 asymmetric key pair. Refer to Figure 3 As shown, when the virtualization platform creates a virtual machine, it selects the corresponding computing node and obtains the corresponding computing node public key. The virtualization platform passes this public key to the server. The server uses this public key and the SM4 key algorithm type to create an SM4 symmetric key. After that, the unique identifier of the symmetric key and the key ciphertext are returned to the virtualization platform. The asymmetric SM2 encrypted data ciphertext needs to meet the "GMT 0018-2012 Cryptographic Device Application Interface Specification". The ciphertext returned by the server and encrypted and protected by the client's SM2 public key should not be persisted to the virtualization platform or the client. The virtualization platform only saves the unique identifier of the symmetric key. Each time the key is used, it needs to be re-obtained from the server. Each virtual machine needs to create a corresponding symmetric key. When the virtualization platform creates a virtual machine, it needs to create a disk in LUKS format. LUKS initialization requires the Master Key for data block encryption, encryption algorithm and encryption mode. The virtualization platform uses the UUID of the virtual machine as the Master Key, and uses the SM4 encryption algorithm and XTS-PLAIN64 encryption mode. The virtualization platform obtains the key ciphertext from the server based on the unique identifier obtained by the symmetric key, decrypts the symmetric key using the private key corresponding to the public key of the computing node, and uses the decrypted SM4 key to create a virtual disk in LUKS format. Each virtual machine uses a different SM4 key, so that the virtual disk of the virtual machine can only be used by the current virtual machine, ensuring data security.

[0066] Step S23: Encrypt the symmetric key using the first public key to obtain a target key.

[0067] Step S24: Obtain authorization information of the user authorization request generated by the virtual machine creation request returned by the server.

[0068] Step S25: When the authorization information is authenticated, the target key is obtained from the server, and the target key is decrypted using the first private key, so as to use the symmetric key to create a virtual disk corresponding to the current virtual machine, thereby completing virtual machine encryption.

[0069] In this embodiment, refer to Figure 4 As shown, when a non-administrator user completes the creation of a virtual machine, the virtualization platform will put the virtual machine's unique identifier UUID and the UUID encrypted with the SM2 public key into the Ukey used by the user to log in. When the user performs related operations on the virtual machine, it first queries whether the UUID of the corresponding virtual machine is saved in the Ukey, and uses the SM2 private key to decrypt it. When the decryption is successful and the UUID corresponds, the user is allowed to operate the virtual machine, otherwise it is considered that the user does not have the authority to operate this virtual machine. When the virtual machine is turned on, the virtualization platform obtains the key ciphertext from the server, uses the private key corresponding to the computing node public key, and passes the decrypted SM4 symmetric key to qemu to encrypt and decrypt the virtual machine's data. When the user creates a virtual machine on the virtualization platform, the virtualization platform creates a symmetric key for each virtual machine on the server, and obtains the asymmetric SM2 encrypted data ciphertext based on the key unique identifier. After the client uses the public and private key pair to decrypt, the virtualization platform creates a LUKS encrypted disk for the virtual machine;

[0070] It can be seen that this embodiment protects the virtual machine data by encrypting the virtual machine with a symmetric key, and saves the unique identification of the virtual machine and the encrypted key in the user's Ukey. When the user performs related operations on the virtual machine, the virtualization platform will authenticate the identity based on the unique identification to ensure the security of the virtual machine operation.

[0071] Reference Figure 5 As shown, the embodiment of the present invention discloses a specific virtual machine encryption method. Compared with the previous embodiment, this embodiment further explains and optimizes the technical solution. Specifically:

[0072] Step S31: When a virtual machine creation request is received from a user, an asymmetric key pair including a first public key and a first private key is generated based on a first national secret algorithm, a user unique identifier and user parameter information; and a symmetric key is generated through a server based on a second national secret algorithm.

[0073] Step S32: Encrypt the symmetric key using the first public key to obtain a target key.

[0074] For more detailed processing procedures in steps S31 and S32, please refer to the aforementioned disclosed embodiments, which will not be described in detail here.

[0075] Step S33: Generate a first random number based on the user authorization request sent by the user including the user information and the application key, and obtain a second random number sent by the server.

[0076] In this embodiment, refer to Figure 6 As shown, first create the SM2 asymmetric key. When adding a new computing node, the virtualization platform uses the unique identifier of the computing node to generate a public-private key pair on the client side of the key management system. This public-private key pair needs to be permanently stored on the client side, and the public key is stored in the database of the virtualization platform. Figure 7 As shown, the server of the key management system generates a random number and hands it over to the virtualization platform, which is the first random number. Then the virtualization platform also generates a random number as the second random number.

[0077] Step S34: concatenate the first random number and the second random number to obtain a concatenated random number, and send the concatenated random number and an application key corresponding to the virtualization platform application to the client.

[0078] In this embodiment, the first random number and the second random number are concatenated, and the client obtains the concatenated random number. At the same time, the server sends the application key corresponding to the virtualization platform to the client.

[0079] Step S35: Generate a hash message authentication code based on the concatenated random number and the application key.

[0080] In this embodiment, the server generates a hash operation message authentication code hmac by using a preset national secret algorithm for the spliced ​​random number sent by the client. The hash message authentication code is generated based on the spliced ​​random number and the application key using the SM3 cryptographic hash function standard algorithm.

[0081] Step S36: Send the hash message authentication code and the second random number to the server so that the server can authorize the user authorization request.

[0082] In this embodiment, the virtualization platform sends the virtualization platform random number to the server, and the client sends the generated hmac to the server, so that the server verifies the virtualization platform with hmac and the virtualization platform random number.

[0083] Step S37: After passing the authorization authentication, the target key is obtained from the server, and the target key is decrypted using the first private key, so that the target data of the current virtual machine operation can be encrypted and decrypted using the symmetric key to complete the virtual machine encryption.

[0084] In this embodiment, when the virtualization platform passes the verification and obtains the authorization, it obtains the target key from the server and decrypts the target key using the first private key so that the target data of the current virtual machine operation can be encrypted and decrypted using the symmetric key to complete the virtual machine encryption.

[0085] It can be seen that this embodiment determines the computing node on the virtualization platform, and then uses the unique identifier of the computing node to generate a public-private key pair on the client to characterize the identity information of the corresponding computing node, so that when performing server authentication, subsequent key operations can be performed through the server authentication.

[0086] Reference Figure 8 As shown, the embodiment of the present invention discloses a specific virtual machine encryption device, including:

[0087] The key generation module 11 is used to generate an asymmetric key pair including a first public key and a first private key based on a first national secret algorithm, a user unique identifier and user parameter information when receiving a virtual machine creation request from a user; and generate a symmetric key based on a second national secret algorithm through a server;

[0088] A key encryption module 12, configured to encrypt the symmetric key using the first public key to obtain a target key;

[0089] The authorization acquisition module 13 is used to obtain the authorization information of the user authorization request generated by the virtual machine creation request returned by the server;

[0090] The virtual machine encryption module 14 is used to obtain the target key from the server after the authorization information is authenticated, and decrypt the target key using the first private key so as to use the symmetric key to create a virtual disk corresponding to the current virtual machine to complete virtual machine encryption.

[0091] It can be seen that the present application discloses a virtual machine encryption method, including: when receiving a virtual machine creation request proposed by a user, generating an asymmetric key pair including a first public key and a first private key based on a first national secret algorithm, a user unique identifier and user parameter information; generating a symmetric key through a server and based on a second national secret algorithm; encrypting the symmetric key using the first public key to obtain a target key; obtaining the authorization information of the user authorization request generated by the virtual machine creation request returned by the server; when the authorization information is authenticated, obtaining the target key from the server, decrypting the target key using the first private key, so as to use the symmetric key to create a virtual disk corresponding to the current virtual machine, and complete the virtual machine encryption. It can be seen that the present application encrypts the symmetric key using an asymmetric public key to ensure the security of the key transmission process, and then verifies the authorization information again when the user performs relevant operations on the virtual machine to ensure the security of the operation of the virtual machine, so that the virtual machine can provide continuous protection for data when the workload is moved, cloned or snapshotted in the enterprise infrastructure. Encrypting the virtual machine eliminates the risk of being restricted by hardware, virtual machine managers or cloud providers, and provides ideal fully portable protection for hybrid IT environments and workloads in transit.

[0092] In some specific implementations, the key generation module 11 specifically includes:

[0093] A certificate issuing unit, configured to generate a transmission key through a client and based on a second national encryption algorithm, so as to encrypt the first private key with the transmission key to obtain a first encryption key;

[0094] Encrypting the transmission key using the first public key to obtain an encrypted transmission key;

[0095] The first encryption key, the encryption transmission key, and the first public key are sent to a certificate authority so that the certificate authority can perform an encryption certificate signing operation and issue a corresponding encryption certificate through a certificate registration and approval system.

[0096] In some specific implementations, the key generation module 11 specifically includes:

[0097] The node determination submodule is used to create a virtual machine using a virtualization platform and determine a computing node.

[0098] In some specific implementations, the node determination submodule specifically includes:

[0099] The key pair generation unit is used to pre-add a computing node to the virtualization platform, generate an asymmetric key pair using the unique identifier of the computing node, store the asymmetric key pair in a client database, and then send the first public key to the virtualization platform database.

[0100] In some specific implementations, the authorization acquisition module 13 specifically includes:

[0101] The authorization submodule is used to generate a first random number based on a user authorization request including user information and an application key sent by the user, and obtain a second random number sent by the server;

[0102] Concatenate the first random number and the second random number to obtain a concatenated random number, and send the concatenated random number and an application key corresponding to the virtualization platform application to the client;

[0103] Generate a hash message authentication code based on the concatenated random number and the application key;

[0104] The hash message authentication code and the second random number are sent to the server so that the server can authorize the user authorization request.

[0105] In some specific implementations, the authorization submodule specifically includes:

[0106] The authentication code generation unit is used to generate a hash message authentication code based on the concatenated random number and the application key using the SM3 cryptographic hash function standard algorithm.

[0107] In some specific implementations, the virtual machine encryption module 14 specifically includes:

[0108] The encryption and decryption unit is used to encrypt and decrypt the target data of the current virtual machine operation using a symmetric key to complete virtual machine encryption.

[0109] Furthermore, the present application also discloses an electronic device. Fig. 9 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.

[0110] Fig. 9A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the virtual machine encryption method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0111] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0112] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 can be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.

[0113] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0114] Among them, the operating system 221 is used to manage and control the hardware devices and computer programs 222 on the electronic device 20, so as to realize the operation and processing of the massive data 223 in the memory 22 by the processor 21, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the virtual machine encryption method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks. In addition to data transmitted from an external device received by the electronic device, the data 223 can also include data collected by its own input and output interface 25, etc.

[0115] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein the computer program, when executed by a processor, implements the aforementioned disclosed virtual machine encryption method. For the specific steps of the method, reference may be made to the corresponding contents disclosed in the aforementioned embodiments, and no further description will be given here.

[0116] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0117] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, computer software or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to the function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application. The steps of the method or algorithm described in conjunction with the embodiments disclosed herein can be directly implemented with a software module executed by a hardware or processor, or a combination of the two. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the technical field.

[0118] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0119] The above is a detailed introduction to a virtual machine encryption method, device, equipment, and storage medium provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for a person skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. A virtual machine encryption method, characterized in that: include: When receiving a virtual machine creation request from a user, generating an asymmetric key pair including a first public key and a first private key based on a first national secret algorithm, a user unique identifier, and user parameter information; Generate a symmetric key through the server based on the second national secret algorithm; Encrypting the symmetric key using the first public key to obtain a target key; Obtain authorization information of a user authorization request generated by the virtual machine creation request returned by the server; When the authorization information is authenticated, the target key is obtained from the server, and the target key is decrypted using the first private key, so as to create a virtual disk corresponding to the current virtual machine using the symmetric key, thereby completing the encryption of the virtual machine; The obtaining of authorization information of a user authorization request generated by the server for the virtual machine creation request includes: Generate a first random number based on a user authorization request sent by the user including user information and an application key, and obtain a second random number sent by the server; Concatenate the first random number and the second random number to obtain a concatenated random number, and send the concatenated random number and an application key corresponding to the virtualization platform application to the client; Generate a hash message authentication code based on the concatenated random number and the application key; The hash message authentication code and the second random number are sent to the server so that the server can authorize the user authorization request.

2. The virtual machine encryption method according to claim 1, characterized in that: The process of generating an asymmetric key pair including a first public key and a first private key based on the first national secret algorithm, a user unique identifier and user parameter information also includes: Generate a transmission key through the client based on a second national secret algorithm, so as to encrypt the first private key with the transmission key to obtain a first encryption key; Encrypting the transmission key using the first public key to obtain an encrypted transmission key; The first encryption key, the encryption transmission key, and the first public key are sent to a certificate authority so that the certificate authority can perform an encryption certificate signing operation and issue a corresponding encryption certificate through a certificate registration and approval system.

3. The virtual machine encryption method according to claim 1, characterized in that: The process of generating a symmetric key through the server based on the second national secret algorithm also includes: Use the virtualization platform to create virtual machines and determine computing nodes.

4. The virtual machine encryption method according to claim 1, characterized in that: The generating a hash message authentication code based on the concatenated random number and the application key includes: A hash message authentication code is generated based on the concatenated random number and the application key using the SM3 cryptographic hash function standard algorithm.

5. The virtual machine encryption method according to any one of claims 1 to 4, characterized in that: The step of using the symmetric key to create a virtual disk corresponding to the current virtual machine to complete virtual machine encryption includes: The target data of the current virtual machine operation is encrypted and decrypted using a symmetric key to complete virtual machine encryption.

6. A virtual machine encryption device, characterized in that: include: A key generation module, configured to generate an asymmetric key pair including a first public key and a first private key based on a first national secret algorithm, a user unique identifier and user parameter information when receiving a virtual machine creation request from a user; Generate a symmetric key through the server based on the second national secret algorithm; A key encryption module, used to encrypt the symmetric key using the first public key to obtain a target key; An authorization acquisition module, used to acquire authorization information of a user authorization request generated by the virtual machine creation request returned by the server; A virtual machine encryption module, used for obtaining the target key from the server after the authorization information is authenticated, and decrypting the target key using the first private key, so as to create a virtual disk corresponding to the current virtual machine using the symmetric key, thereby completing virtual machine encryption; The authorization acquisition module specifically includes: An authorization submodule is used to generate a first random number based on a user authorization request sent by a user containing user information and an application key, and obtain a second random number sent by a server; concatenate the first random number and the second random number to obtain a concatenated random number, and send the concatenated random number and the application key corresponding to the virtualization platform application to the client; generate a hash message authentication code based on the concatenated random number and the application key; and send the hash message authentication code and the second random number to the server so that the server can authorize the user authorization request.

7. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the steps of the virtual machine encryption method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein, when the computer program is executed by a processor, the steps of the virtual machine encryption method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Disk encryption and decryption method and system for virtual machine

    CN110750326A