Secure computing resource deployment using homomorphic encryption

CN116530050BActive Publication Date: 2026-09-08INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180080595.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-12-08
Filing Date
2021-10-19
Publication Date
2026-09-08
Estimated Expiration
2041-10-19

AI Technical Summary

Technical Problem

消费者不管理或控制包括网络、服务器、操作系统或存储在内的底层云基础设施,但是对所部署的应用具有控制

Benefits of technology

[0004] This document also describes and claims protection for computer systems and computer-implemented methods relating to one or more aspects. Additionally, this document also describes and may claim protection for services relating to one or more aspects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116530050B_ABST
    Figure CN116530050B_ABST
Patent Text Reader

Abstract

Secure computing resource deployment within a computing environment is facilitated by receiving a request to deploy a computing resource in the computing environment and obtaining a homomorphically encrypted dataset. The homomorphically encrypted dataset includes configuration-related data for a desired configuration of the computing resource to be deployed in the computing environment. The process further includes using the homomorphically encrypted dataset in configuring the computing resource for deployment, wherein the computing resource is configured for deployment with the desired configuration without decrypting the homomorphically encrypted dataset.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] Cloud computing refers to a set of network elements that provide services (such as data storage and computing power) on demand without requiring direct, active management by consumers or users. Cloud computing relies on resource sharing to achieve consistency and economies of scale.

[0002] Cloud computing can be offered as a service on the Internet, such as in the form of Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and / or Software as a Service (SaaS). Platform as a Service (PaaS) providers allow consumers to deploy consumer resources created using programming languages, libraries, services, and tools supported by the PaaS provider onto PaaS cloud infrastructure. Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but they do have control over the deployed applications. Platform as a Service (PaaS) providers offer a computing platform, typically including an operating system, programming language execution environment, database, and web server, and consumers or users develop and run software on the cloud platform, rather than acquiring and maintaining the underlying hardware and software layers. Summary of the Invention

[0003] By providing a computer program product for facilitating the deployment of secure computing resources in one or more aspects, certain drawbacks of the prior art are overcome and additional advantages are provided. The computer program product includes a computer-readable storage medium having program instructions embodied therein. The program instructions are readable by one or more processors to cause one or more processors to receive a request to deploy computing resources in a computing environment and to obtain a homomorphically encrypted dataset. The homomorphically encrypted dataset includes configuration-related data of the desired configuration of the computing resources to be deployed in the computing environment. The program instructions further cause one or more processors to use the homomorphically encrypted dataset when configuring it for deploying the computing resources, wherein the computing resources are configured to be deployed using the desired configuration without decrypting the homomorphically encrypted dataset.

[0004] This document also describes and claims protection for computer systems and computer-implemented methods relating to one or more aspects. Additionally, this document also describes and may claim protection for services relating to one or more aspects.

[0005] Additional features are implemented using the techniques described herein. Other embodiments and aspects are described in detail herein and are considered part of the claimed aspects. Attached Figure Description

[0006] One or more aspects of the invention are particularly pointed out and explicitly claimed as examples in the claims at the end of the specification. The above-described objects, features, and advantages of one or more aspects of the invention will become apparent from the following detailed description taken in conjunction with the accompanying drawings, in which:

[0007] Figure 1 A block diagram depicts an embodiment of a data processing system capable of implementing one or more aspects of the present invention.

[0008] Figure 2 A computing environment is described that can implement various aspects of embodiments of the invention according to one or more aspects of the invention;

[0009] Figure 3 An embodiment of a process for facilitating the deployment of secure computing resources within a computing environment, according to one or more aspects of the present invention, is described.

[0010] Figure 4 An embodiment of homomorphic encryption processing, according to one or more aspects of the present invention, can be used in one or more embodiments of secure computing resource deployment processing;

[0011] Figure 5 The computational environment and processing flow for implementing one or more aspects of embodiments of the present invention are described;

[0012] Figure 6 An embodiment of a process for deploying secure computing resources according to one or more aspects of the present invention is described;

[0013] Figure 7 A sample configuration dataset, which is homomorphically encrypted and digitally signed according to one or more aspects of the present invention, and is used by a computing environment when configuring settings for computing resource deployment;

[0014] Figure 8 An embodiment of a cloud computing environment is described, which may facilitate the implementation of certain aspects of embodiments of the present invention or be used in association with certain aspects of embodiments of the present invention; and

[0015] Figure 9 An abstract model layer according to an embodiment of the present invention is described. Detailed Implementation

[0016] The accompanying drawings further illustrate the invention and, together with the detailed description of the invention, serve to illustrate various aspects of the invention. Throughout these independent views, the same reference numerals denote the same or functionally similar elements, and these drawings are incorporated in and form a part of this specification. It should be noted that, in this respect, descriptions of well-known systems, devices, processing techniques, etc., have been omitted so as not to unnecessarily obscure the details of the invention. However, it should be understood that the detailed description and this particular example, while indicating various aspects of the invention, are given by way of illustration only and not limitation. Various substitutions, modifications, additions, and / or other arrangements within the spirit or scope of the basic inventive concept will be apparent to those skilled in the art based on this disclosure. It should be further noted that multiple inventive aspects and features are disclosed herein, and unless inconsistent, each disclosed aspect or feature may be combined with any other disclosed aspect or feature required for a particular embodiment of the concept disclosed herein.

[0017] It should also be noted that the specific code, design, architecture, protocol, layout, diagram, or tool used below are described as examples only and not as limiting embodiments. Furthermore, for clarity, specific software, tools, or data processing environments are used in particular instances as examples to describe illustrative embodiments. Illustrative embodiments can be used in conjunction with other comparable or similar structures, systems, applications, or architectures. One or more aspects of the illustrative embodiments can be implemented in hardware, software, or a combination thereof.

[0018] As will be understood by those skilled in the art, the program code mentioned herein may include both software and hardware. For example, in some embodiments of the invention, the program code may include fixed-function hardware, while in other embodiments it may utilize a software-based implementation of the described functionality. Some embodiments combine both types of program code. An example of program code (also referred to as one or more programs) is... Figure 1 The document describes computer-readable program instructions 134, an application program 130, and code 136 for deploying secure computing resources, one or more of which may be stored in memory 106 of the computer system 102. Further examples include... Figure 1 The program 146 and computer-readable program instructions 148 are stored in the data storage device 144.

[0019] Refer to the accompanying drawings, and especially to... Figure 1 The diagram illustrates an example of a data processing environment in which one or more aspects of the illustrative embodiments can be implemented. Figure 1This is merely an example and is not intended to assert or imply any limitation regarding the environments in which different embodiments may be implemented. Specific implementations may be modified in many ways based on the environment depicted in the following description.

[0020] refer to Figure 1 As indicated, the figure depicts a block diagram of a data processing system that can implement one or more aspects of the present invention. Data processing system 100 is an example of a computer (such as a server or other type of device), and for illustrative embodiments, computer-available program code or instructions for implementing one or more processes may reside in the computer.

[0021] like Figure 1 As shown, the data processing system 100 includes, for example, a computer system 102 shown in the form of a general-purpose computing device. The computer system 102 may include, but is not limited to, one or more processors or processing units 104 (e.g., central processing unit (CPU)), memory 106 (referred to as main memory or storage device by way of example), and one or more input / output (I / O) interfaces 108 coupled to each other via one or more buses and / or other connections 110.

[0022] Processor 104 includes multiple functional components for executing instructions. These functional components include, for example, an instruction fetching component for fetching instructions to be executed; an instruction decoding unit for decoding the fetched instructions and obtaining operands of the decoded instructions; an instruction execution component for executing the decoded instructions; a memory access component for accessing memory for instruction execution (if necessary); and a write-back component for providing the results of the executed instructions.

[0023] Bus 110 represents one or more of several types of bus architectures, including memory buses or memory controllers, peripheral buses, accelerated graphics ports, and processor or local buses using any of the various bus architectures. By way of example and not limitation, such architectures include Industry Standard Architecture (ISA), Micro Channel Architecture (MCA), Enhanced ISA (EISA), Video Electronics Standards Association (VESA) Local Bus, and Peripheral Component Interconnect (PCI).

[0024] Memory 106 may include, for example, a cache 120 (such as a shared cache) that may be coupled to a local cache 122 of processor 104. Additionally, memory 106 may include one or more programs or applications 130, an operating system 132, and one or more computer-readable program instructions 134, as well as program code 136 for deploying secure computing resources, such as facilitating the secure deployment of virtual machines (VMs) and / or containers within a secure enclave of a host computing environment, as discussed herein. Additionally or alternatively, the computer-readable program instructions 134 may be configured to perform one or more other functions according to certain embodiments of the invention.

[0025] Computer system 102 can also communicate with one or more external devices 140, one or more network interfaces 142, and / or one or more data storage devices 144 via, for example, I / O interface 108. Example external devices include user terminals, tape drives, pointing devices, displays, etc. Network interface 142 enables computer system 102 to communicate with one or more networks (such as local area networks (LANs), general area networks (WANs), and / or public networks (e.g., the Internet), thereby providing communication with other computing devices or systems.

[0026] Data storage device 144 may store one or more programs 146, one or more computer-readable program instructions 148, and / or data, etc. The computer-readable program instructions may be configured to perform the functions of one or more aspects of the present invention.

[0027] Computer system 102 may include and / or be coupled to removable / non-removable, volatile / non-volatile computer system storage media. For example, it may include and / or be coupled to non-removable, non-volatile magnetic media (commonly referred to as a "hard disk drive"), disk drives for reading from and writing to removable, non-volatile disks (e.g., "floppy disks"), and / or optical disc drives for reading from or writing to removable, non-volatile optical discs (such as CD-ROMs, DVD-ROMs, or other optical media). It should be understood that other hardware and / or software components may be used in conjunction with computer system 102. Examples include, but are not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archiving storage systems.

[0028] Computer system 102 can operate with a number of other general-purpose or special-purpose computing system environments or configurations. Examples of well-known computing systems, environments, and / or configurations suitable for use with computer system 102 include, but are not limited to, personal computer (PC) systems, server computer systems, thin clients, thick clients, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and cloud computing environments that include any of the above systems or devices.

[0029] As pointed out, Figure 1 The examples described are not intended to imply architectural limitations. Furthermore, as noted, Figure 1 The data processing system 100 may be, for example, a server, workstation, tablet computer, laptop computer or other computing device.

[0030] As noted, cloud computing can be offered as a service on the Internet, such as "Platform as a Service" (PaaS). In operation, PaaS providers allow users or consumers to deploy computing resources (such as virtual machines or containers) onto cloud infrastructure to run one or more user applications or workloads. In IT computing environments, an operator framework is typically provided that automates, for example, the configuration of one or more computing resources to run user workloads and the underlying systems. Lifecycle management processing is usually part of the operator framework.

[0031] As a specific example, provided by IBM, Armonk (USA), New York. The System / z computing system can handle many complex workloads in a highly secure manner. For example, using Red from Raleigh, North Carolina (USA)... Provided technology, System / z can provide dynamic deployment of workloads in a cloud-based model. In one or more implementations, The technology includes Container platforms, which use Red Alert Containers behind the scenes Provided operating system. The system is considered immutable and is based on The kernel is an open-source, lightweight operating system designed to provide infrastructure for cluster deployments, while focusing on automation, ease of application development, security, reliability, and scalability (of which, (This is a registered trademark of Linus Torvalds). Managing such complex computing environments is challenging and requires strict control. For example, any changes to a highly secure environment should always be monitored and should be made in a controlled manner. The technology provides an operator framework to... Changes and / or automated configurations are made within the cloud platform. Using an operator-based framework in a highly secure environment requires additional security measures, such as ensuring the cloud operator cannot tamper with configuration settings provided by the user or consumer. For example, in one or more embodiments, one or more trusted entities may be provided to attest to ongoing configuration settings or changes. Furthermore, configuration processing should be tamper-proof, assuring the user that their computing resources (e.g., VMs or containers) are securely deployed for operation as intended.

[0032] Figure 2 An embodiment of a technical environment in which one or more aspects of the present invention can be implemented is illustrated. As shown, technical environment 200 includes one or more user systems 205 operatively coupled to a host computing environment, such as a cloud-based computing environment 210, via one or more networks 201.

[0033] In one or more implementations, user system 205 is operatively coupled to a user or consumer computer system or network of computing environment 210 via one or more networks 201. By way of example only, one or more networks 201 may be or include one or more buses or other links, telecommunications networks, local area networks (LANs), wide area networks (WANs) (such as the Internet), or combinations thereof, and may include wired, wireless, fiber optic connections, etc. Depending on the implementation, the networks may include one or more wired and / or wireless networks capable of receiving and transmitting data (such as the data described herein and other data).

[0034] In one embodiment, the host computing environment 210 includes one or more computing systems or processing environments that can be distributed across a cloud-based environment. Figure 2 In the embodiments shown, as an example, host computing environment 210 includes a digital signature server 211 for performing integrity checks on encrypted datasets, a repository 212 for maintaining the encrypted datasets, and a deployment engine 213 including one or more operators 214 for facilitating the configuration and deployment of user computing resources 215 on host computing environment 210. As noted, in one or more embodiments, computing resources 215 may be one or more virtual machines and / or one or more containers, which are to be securely configured to run user workloads or applications.

[0035] Generally, in one or more embodiments, this document provides a computer system, computer program product, and computer-implemented method for homomorphically encrypting user configuration settings data or files at a user system and securely sending the homomorphically encrypted dataset for operator processing at a host computing environment. Operator processing in cloud-based environments (such as cloud operator processing) is programmed to facilitate the deployment of user resource configurations via an automation framework without knowledge of the contents of the configuration dataset. The automation framework uses one or more operators, which are, for example, program code or containers working on the homomorphically encrypted dataset, to perform necessary data manipulation and analysis in an immutable environment and ensure the integrity of the user's configuration data is maintained. In one embodiment, a deployment engine deploys one or more operators that manage standard templates of configuration settings for, for example, a specific type of computing resource to be deployed, and look up one or more corresponding user-defined settings in the homomorphically encrypted dataset received from the user system. The operator framework also implements proof processing to perform integrity checks on the obtained encrypted dataset to ensure that the dataset actually originates from the user system and that its integrity is maintained.

[0036] Figure 3 An embodiment of a process for facilitating the deployment of secure computing resources within a computing environment, according to one or more aspects of the present invention, is shown. Figure 3 Embodiments of the processing may include computer-implemented methods, computer systems, and computer program products, wherein program code executing on one or more processors receives a request 300 to securely deploy computing resources in a computing environment and obtains a homomorphic encrypted dataset including configuration data 302 of the desired configuration of the computing resources to be deployed in the computing environment. Embodiments of the invention also include program code that uses the homomorphic encrypted dataset to configure or define a method for deploying computing resources using the desired configuration without decrypting the homomorphic encrypted dataset prior to deployment 304.

[0037] In some embodiments, using a homomorphically encrypted dataset includes: homomorphically identifying configuration settings used when configuring computing resources for deployment without decrypting the homomorphically encrypted dataset. In one or more embodiments, program code is provided for deploying computing resources in a secure zone of a computing environment using homomorphically identified configuration settings. In one or more embodiments, the computing resources are virtual machines or containers used to run user workloads or applications.

[0038] In one or more embodiments of the present invention, program code is provided to define a configuration template for computing resources to be deployed, and to obtain a homomorphic encryption key for generating a received homomorphic encrypted dataset, and to homomorphically encrypt the configuration template using the obtained homomorphic encryption key. In one embodiment, homomorphically identifying the configuration settings includes comparing the homomorphically encrypted configuration template with the received homomorphically encrypted dataset to identify the configuration settings without decrypting the homomorphically encrypted dataset. Additionally, in one embodiment, defining the configuration template may include obtaining one or more default configuration settings for the computing resources, and replacing the default configuration settings in one or more default configuration settings with the identified corresponding configuration settings when comparing the homomorphically encrypted configuration template with the received homomorphically encrypted dataset.

[0039] In one or more embodiments of the invention, program code is provided to invoke one or more deployment operators based on a received request to deploy computing resources. The one or more deployment operators obtain a homomorphic encrypted dataset from a repository. In one embodiment, the homomorphic encrypted dataset obtained from the repository is digitally signed to facilitate integrity checks, and program code is provided to perform integrity checks on the obtained homomorphic encrypted dataset. In another embodiment, a blockchain is used to digitally sign the homomorphic encrypted dataset.

[0040] Various embodiments of the present invention are inextricably linked to computing and provide significantly more methods than existing methods for deploying computing resources within a computing environment. For example, embodiments of the present invention provide program code, executable on one or more processors, that leverages the interconnectivity of various systems and various computing-centric data analysis and processing techniques to obtain the desired configuration of computing resources to be deployed in a computing environment without decrypting an encrypted dataset. Both the interconnectivity of the computing systems utilized and the computer-specific data processing techniques employed by the program code enable various aspects of the present invention. Furthermore, embodiments of the present invention provide significantly more methods than existing methods for deploying computing resources within a computing environment by maintaining the configuration dataset for the computing resources encrypted prior to deployment.

[0041] In embodiments of the present invention, the program code provides significantly more functionality, including but not limited to: 1) program code for receiving a request to deploy computing resources in a computing environment; 2) program code for obtaining a homomorphic encrypted dataset, the homomorphic encrypted dataset including configuration-related data of the desired configuration of the computing resources to be deployed in the computing environment; and 3) program code for using the homomorphic encrypted dataset when configuring for deploying computing resources, wherein the computing resources are configured to be deployed using the desired configuration without decrypting the homomorphic encrypted dataset.

[0042] As noted, one or more embodiments described herein partially utilize homomorphic encrypted datasets to facilitate the deployment of secure computing resources. Homomorphic encryption is a type of encryption that allows computation to be performed on encrypted data without first decrypting it. The result of the computation is in encrypted form, and when decrypted, the output is the same as if the operation had been performed on unencrypted data. In particular, homomorphic encryption allows operations to be performed on encrypted data without knowing the private key (i.e., without decryption). Homomorphic encryption encompasses various types of encryption methods that can perform different categories of computations on encrypted data. These include partially homomorphic encryption, somewhat homomorphic encryption, hierarchical fully homomorphic encryption, and fully homomorphic encryption. Fully homomorphic encryption is a cryptographic system that supports arbitrary computation on ciphertext.

[0043] As an example, Figure 4 An example of homomorphic encryption is shown. Figure 4 The diagram illustrates a computing environment in which a trusted domain 400 outsources one or more computations 412 to an untrusted domain 410. As shown, raw plaintext data 401 (such as a set of numbers) is fully homomorphically encrypted 402, such as by using lattice cryptography (which is quantum resistant), to provide the encrypted dataset 411 as ciphertext to the untrusted domain 410. The untrusted domain 410 obtains the associated public key from a key management module or server 404 in the trusted domain 400 to facilitate the execution of one or more fully homomorphic (FHE) computations 412. The computation result 413 of the encrypted operation is then returned to the trusted domain 400 for decryption 405 to obtain an unencrypted output 406. As noted, homomorphic encryption advantageously enables data processing without providing access to the data. In one embodiment, this involves performing computations on the encrypted data itself, rather than requiring decryption of the data. Homomorphic encryption can be provided using any of several open-source fully homomorphic encryption (FHE) libraries. These FHE libraries implement various FHE-generating schemes to provide the desired encryption. For example, the list of available homomorphic encryption implementations is maintained by the industry standards consortium at Homomophicecryption.org.

[0044] Figure 5 and Figure 6 An embodiment of a computing environment and processing flow for secure computing resource deployment according to one or more aspects of the present invention is described.

[0045] First refer to Figure 5The illustration shows one embodiment of a technical environment 500, which includes one or more user systems 510, which may be one or more on-site computer systems of users or consumers, operatively communicating with one or more third-party computing environments, including, for example, a signature or authentication server system 520, a repository 530, and a host computing environment 540 (such as a cloud computing environment) for securely deploying the user's desired computing resources. As noted, in one or more embodiments, the computing resources to be deployed are virtual machines used to covertly run, for example, user workloads or applications. In one or more other embodiments, the computing resources to be deployed include one or more containers. As understood, containers in cloud computing are a method of operating system virtualization. A single container can be used to run anything from small microservices or software processes to larger applications. Inside the container, all necessary executables, binaries, libraries, and configuration files are provided.

[0046] Common Reference Figure 5 and Figure 6 An embodiment of the secure computing resource deployment process according to one or more aspects described herein includes a consumer or user initiating the creation of a computing resource setting 610. Figure 6 ), and especially operator configuration file 511 ( Figure 5 In one embodiment, the user system then uses fully homomorphic encryption (FHE) to invoke the preparation 612 of the encrypted dataset. In one embodiment, the encryption process uses a method via generating a security key and a public key 614 ( Figure 6 The key management module, processes, servers, etc. of 512 Figure 5 One or more secrets or private keys are obtained. The generated security key is used to encrypt data using, for example, fully homomorphic encryption 616, thereby producing a homomorphically encrypted dataset or a homomorphically encrypted configuration file 513. Figure 5 ).like Figure 6 As shown, before forwarding the encrypted dataset to a signing or verification server 520 (which can be a host-based or cloud-based server), information for extracting the key can be added to the payload 618 to sign the payload content using the public key 620. In the illustrated embodiment, the signed homomorphic encrypted dataset can be stored 622 (…). Figure 6 ) to storage repository 530, in one implementation, storage repository 530 is a host-based or cloud-based storage repository.

[0047] like Figure 6As shown, the user system or consumer system decides to create computing resources (e.g., virtual machines or containers) in a host-based computing environment. As part of this, the user sends a request to the computing environment, and specifically to the operator deployment engine 542. Figure 5 The operator deployment engine 542 begins processing user request 630. Figure 6 The deployment engine invokes one or more deployment operators 632. Figure 6 This is to partially extract encrypted datasets or payloads from storage 530. An operator is one or more agents or utilities that assist in the setup of computing resources in a host-based computing environment, and in one or more embodiments may be a collection of containers. In the depicted implementation, integrity check 634 is performed. Figure 6 This ensures that the signed encrypted dataset remains valid and has not been tampered with. As part of the process, applicable signature information is extracted from the signature server 520 to allow for integrity checks. If invalid, the computational resource deployment process terminates at 635. Figure 6 As noted, in one embodiment, a blockchain can be used to implement signed encrypted data.

[0048] like Figure 6 As shown, a configuration template for configuring settings is defined 636 based on desired computing resources (e.g., virtual machines and / or containers). In one or more embodiments, defining the configuration template may include providing a standard template for the resource type and may include providing one or more default configuration settings for the template. Once obtained, the configuration template is homomorphically encrypted 638 using the same homomorphic private key used to encrypt the user's configuration settings file. Figure 6 Homomorphic private keys can be obtained from the user system 512 ( Figure 5 The key is obtained from the associated key management server. In one implementation, the resulting homomorphic encryption configuration template includes all standard configuration settings for the computing resources to be configured and deployed. Essentially, the configuration template comprises a set of default settings, one or more of which can be replaced based on a comparison with the retrieved homomorphic encryption dataset. Specifically, in one implementation, the operator process compares two homomorphic encryption datasets (one from the user system and the other generated by the host system) to identify one or more user-desired configuration settings for the computing resources. This comparison is performed homomorphically, for example, using existing homomorphic comparison methods, and when a user-desired configuration setting is identified, the encrypted configuration template is updated accordingly. Figure 6 ), wherein the process is repeated for one or more configuration settings in the configuration template 644 ( Figure 6Specifically, this process is repeated for each of the configuration settings or definitions provided by the user in the encrypted dataset, and computing resources are deployed once the definition for deployment is obtained.

[0049] like Figure 6 As shown, in Figure 6 During the secure deployment of computing resources, the host cloud administrator of the host computing environment cannot access the decrypted version of the configuration settings. For example, the administrator can manage the deployment of computing resources but is unaware of the configuration settings, which are kept in encrypted form before the resources are deployed. Figure 6 In this embodiment, the homomorphic comparison of the encrypted dataset, the configuration of the deployment definition, and the deployment of computing resource 646 are all performed within a secure zone 601 of the host or cloud computing environment. This processing uses homomorphically encrypted data without requiring the data to be decrypted before deploying the computing resource.

[0050] For example, Figure 7 An embodiment of configuration file entry 700 is shown, in which, for example, the configuration parameter "SELinux" is enabled, and the resulting payload 710 is shown to be homomorphically encrypted using the user's key 712. Another configuration parameter, "Security Context Constraint (SCC)", is also shown to be enabled in this example and has a corresponding encrypted dataset indicated for the payload. As noted, the processing disclosed herein works on a homomorphically encrypted dataset. Specifically, the host deployment operator, published by the deployment engine process, uses the encrypted payload 710 and initially obtains a public key from the signature server for integrity checks on the encrypted dataset. Assuming the integrity check is valid, the processing homomorphically determines the configuration dataset, where the operator operates on the host system (e.g., a cloud computing environment) to determine a specific encrypted dataset value, which is then used to update a configuration template, which itself is also encrypted using the same secret key discussed above 722. The host system then uses the resulting encrypted deployment definition for the configuration settings to deploy computing resources 724, as described herein.

[0051] Those skilled in the art will notice from the foregoing description that what is provided herein is a method for configuring a computer program product, computer system, and computer implementation of a security-sensitive computing environment using a process comprising: encrypting the contents of a configuration file at a user system using, for example, homomorphic encryption; and sending the encrypted configuration file as an operator package dataset (or binary large object (blob)) where a host system administrator, such as a cloud administrator, lacks access to the encrypted content. Proofs are performed to ensure the integrity of the encrypted dataset is maintained, thereby preventing tampering with the contents present in the package. In response to a deployed host system operator configuring computing resources as desired (as described herein), access to the encrypted contents of the configuration file is revoked, for example, based on action tags. In one or more implementations, the process may further include a record proof pattern to strengthen integrity checks along a blockchain network for cross-validation of the process. In one or more embodiments, the process described herein may be used in association with a Kubernetes framework implemented in a host computing environment.

[0052] The following is for reference Figures 8 to 9 Further exemplary embodiments of a computing environment for implementing one or more aspects of the present invention will be described below.

[0053] One or more aspects may involve or utilize cloud computing.

[0054] It is understood in advance that although this disclosure includes a detailed description of cloud computing, the implementation of some of the teachings recorded herein is not limited to cloud computing environments. Rather, embodiments of the invention can be implemented in conjunction with any other type of computing environment now known or developed hereafter.

[0055] Cloud computing is a service delivery model that enables convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with service providers. This cloud model may include at least five features, at least three service models, and at least four deployment models.

[0056] The characteristics are as follows:

[0057] On-demand self-service: Cloud consumers can automatically and unilaterally configure computing power, such as server time and network storage, without the need for manual interaction with service providers.

[0058] Extensive network access: Capabilities are available via the network and through standard mechanisms that facilitate use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs).

[0059] Resource pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, where different physical and virtual resources are dynamically allocated and reallocated based on demand. There is a sense of location independence because consumers typically do not have control or knowledge of the exact location of the resources provided, but may be able to specify the location at a higher level of abstraction (e.g., country, state, or data center).

[0060] Rapid and flexible: Capabilities can be provided quickly and flexibly (in some cases, automatically) to rapidly expand outward and rapidly release inward. For consumers, the available capacity often appears unlimited and can be purchased in any quantity at any time.

[0061] Measurement services: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at a level of abstraction appropriate to the service type (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency for both the service providers and consumers.

[0062] The service model is as follows:

[0063] Software as a Service (SaaS): This provides consumers with the ability to use a provider's applications running on cloud infrastructure. Applications can be accessed from various client devices via thin client interfaces such as web browsers (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating system, storage, or even individual application capabilities, with possible exceptions of limited user-specific application configuration settings.

[0064] Platform as a Service (PaaS): This provides consumers with the ability to deploy applications created or acquired by the consumer onto cloud infrastructure using programming languages ​​and tools supported by the provider. Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but they have control over the deployed applications and the configuration of possible application hosting environments.

[0065] Infrastructure as a Service (IaaS): This provides consumers with the capability to offer processing, storage, networking, and other basic computing resources on which they can deploy and run arbitrary software, including operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but they do have control over the operating system, storage, deployed applications, and potentially limited control over chosen networking components (e.g., host firewalls).

[0066] The deployment model is as follows:

[0067] Private cloud: Cloud infrastructure that operates solely for an organization. It can be managed by the organization or a third party and can exist on-site or off-site.

[0068] Community cloud: Cloud infrastructure shared by several organizations and supporting a specific community with shared concerns (e.g., tasks, security requirements, policies, and compliance considerations). It can be managed by an organization or a third party and can exist on-site or off-site.

[0069] Public cloud: Cloud infrastructure available to the public or large industry groups and owned by organizations that sell cloud services.

[0070] Hybrid cloud: A cloud infrastructure is a combination of two or more clouds (private, community, or public) that remain a single entity but are bound together by standardized or proprietary technologies that enable data and application portability (e.g., cloud bursts for load balancing between clouds).

[0071] Cloud computing environments are service-oriented, focusing on statelessness, loose coupling, modularity, and semantic interoperability. At the heart of cloud computing is the infrastructure of a network of interconnected nodes.

[0072] Cloud computing nodes can include computer systems / servers, such as Figure 1 The computer system / server described in the document. Figure 1 The computer system / server 102 can be implemented in a distributed cloud computing environment where tasks are executed by remote processing devices linked via a communication network. In this environment, program modules can reside on local and remote computer system storage media, including memory storage devices. The computer system / server 102 is capable of implementing and / or performing any of the functions described above.

[0073] Now for reference Figure 8The diagram illustrates an illustrative cloud computing environment 50. As shown, the cloud computing environment 50 may include one or more cloud computing nodes 10, with local computing devices used by cloud consumers that can communicate with these nodes. These local computing devices include, for example, personal digital assistants (PDAs) or cellular phones 54A, desktop computers 54B, laptop computers 54C, and / or automotive computer systems 54N. The nodes 10 can communicate with each other. They may be physically or virtually grouped (not shown) in one or more networks, such as private clouds, community clouds, public clouds, or hybrid clouds, or combinations thereof, as described above. This allows the cloud computing environment 50 to provide infrastructure, platform, and / or software as a service, without requiring cloud consumers to maintain resources on their local computing devices. It should be understood that... Figure 8 The types of computing devices 54A-N shown are intended to be illustrative only, and computing node 10 and cloud computing environment 50 can communicate with any type of computerized device via any type of network and / or network-addressable connection (e.g., using a web browser).

[0074] refer to Figure 9 This demonstrates a cloud computing environment of 50 ( Figure 8 This provides a set of functional abstractions. It should be understood beforehand that... Figure 9 The components, layers, and functions shown are intended to be illustrative only, and embodiments of the invention are not limited thereto. As depicted, the following layers and corresponding functions are provided:

[0075] The hardware and software layer 60 includes hardware and software components. Examples of hardware components include a mainframe 61; a server 62 based on a RISC (Reduced Instruction Set Computer) architecture; a server 63; a blade server 64; a storage device 65; and network and networking components 66. In some embodiments, software components include network application server software 67 and database software 68.

[0076] The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual server 71; virtual storage 72; virtual network 73, including virtual private network; virtual application and operating system 74; and virtual client 75.

[0077] In one example, management layer 80 may provide the following functionalities: Resource Provisioning 81 provides dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Metering and Pricing 82 provides cost tracking when resources are used within the cloud computing environment and bills or invoices for the consumption of these resources. In one example, these resources may include application software licenses. Security provides authentication for cloud consumers and tasks, as well as protection for data and other resources. User Portal 83 provides access to the cloud computing environment for consumers and system administrators. Service Level Management 84 provides cloud resource allocation and management to meet required service levels. Service Level Agreement (SLA) Planning and Fulfillment 85 provides pre-scheduling and procurement of cloud resources to anticipate future needs according to the SLA.

[0078] The workload layer 90 provides examples of functionalities that can be leveraged in a cloud computing environment. Examples of workloads and functionalities that can be provided from this layer include: mapping and navigation 91; software development and lifecycle management 92; virtual classroom education delivery 93; data analytics and processing 94; transaction processing 95; and secure computing resource deployment processing 96.

[0079] Various embodiments of the invention have been described for illustrative purposes, but are not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein has been chosen to best explain the principles of the embodiments, their practical application, or technical improvements to technologies found in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.

[0080] This invention can be a system, method, and / or computer program product with any possible level of technical detail integration. The computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to perform various aspects of the invention.

[0081] Computer-readable storage media can be tangible devices that can hold and store instructions for use by an instruction execution device. Computer-readable storage media can be, for example, but not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital universal disk (DVD), memory sticks, floppy disks, mechanical encoding devices on which instructions are recorded (such as punched cards or raised structures in recesses), and any suitable combination of the foregoing. As used herein, computer-readable storage media should not be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses transmitted through fiber optic cables), or electrical signals transmitted through wires.

[0082] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a suitable computing / processing device or via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network) to an external computer or external storage device. The network may include copper transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the suitable computing / processing device.

[0083] Computer-readable program instructions used to perform the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, integrated circuit configuration data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​(such as Smalltalk, C++, etc.) and procedural programming languages ​​(such as the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)) or may be connected to an external computer (e.g., via the Internet provided by an Internet service provider). In some embodiments, electronic circuits, including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), may execute computer-readable program instructions by personalizing the electronic circuits with state information utilizing the computer-readable program instructions in order to perform various aspects of this invention.

[0084] Various aspects of the invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0085] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that, when executed via the computer or other programmable data processing apparatus, these instructions create means for implementing the functions / actions specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can instruct a computer, programmable data processing apparatus, and / or other devices to operate in a particular manner, such that the computer-readable storage medium storing the instructions includes an article of writing comprising instructions that implement aspects of the functions / actions specified in one or more blocks of a flowchart and / or block diagram.

[0086] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions, which execute on the computer, other programmable apparatus, or other device, implement the function / action specified in one or more boxes of a flowchart and / or block diagram.

[0087] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions comprising one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a non-linear order. For example, depending on the functions involved, two consecutively shown blocks may actually be executed substantially simultaneously, or these blocks may sometimes be executed in reverse order. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified function or action or performs a combination of dedicated hardware and computer instructions.

[0088] In addition to the above, one or more aspects may also be supplied, provided, deployed, managed, serviced, etc., by a service provider that manages the consumer environment. For example, a service provider may create, maintain, support, etc., the computer code and / or computer infrastructure that performs one or more aspects for one or more consumers. In return, as an example, the service provider may receive payments from consumers under subscription and / or fee agreements. Additionally or alternatively, the service provider may receive payments for selling advertising content to one or more third parties.

[0089] In one aspect, an application can be deployed to perform one or more embodiments. As an example, deploying an application includes providing computer infrastructure operable to perform one or more embodiments.

[0090] As a further aspect, computing infrastructure can be deployed, including integrating computer-readable code into the computing system, wherein the code, in conjunction with the computing system, is capable of executing one or more embodiments.

[0091] As a further aspect, a process for integrating computing infrastructure can be provided, including integrating computer-readable code into a computer system. The computer system includes a computer-readable medium, wherein the computer medium includes one or more embodiments. The code, combined with the computer system, is capable of executing one or more embodiments.

[0092] While various embodiments have been described above, these are merely examples. For instance, computing environments with other architectures can be used to combine and utilize one or more embodiments. Furthermore, different instructions, instruction formats, instruction fields, and / or instruction values ​​can be used. Many variations are possible.

[0093] In addition, other types of computing environments can be beneficial and used. As an example, a data processing system suitable for storing and / or executing program code is available, comprising at least two processors directly or indirectly coupled to memory elements via a system bus. Memory elements include, for example, local memory used during the actual execution of the program code, mass storage devices, and cache memory that provides temporary storage for at least some of the program code to reduce the number of times code must be retrieved from mass storage devices during execution.

[0094] Input / output (I / O) devices (including but not limited to keyboards, monitors, pointing devices, DASDs, tape drives, CDs, DVDs, thumb drives, and other storage media) can be coupled to the system directly or via an intermediate I / O controller. Network adapters can also be coupled to the system, enabling the data processing system to be coupled to other data processing systems or remote printers or storage devices via an intermediate private or public network. Modems, cable modems, and Ethernet cards are just some of the available types of network adapters.

[0095] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used herein, unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well. It should be further understood that the terms “comprising” (and any form of inclusion, such as “comprises” and “comprising”), “having” (and any form of having, such as “has” and “having”), “containing” (and any form of containing, such as “includes” and “including”), and “containing” (and any form of containing, such as “contains” and “containing”) are open-ended connecting verbs. Thus, a method or apparatus that “comprising,” “having,” “containing,” or “contains” one or more steps or elements has, but is not limited to having only those steps or elements. Similarly, a method or apparatus that “comprising,” “having,” “containing,” or “contains” one or more features has, but is not limited to having only those features. In addition, devices or structures configured in a certain way are configured at least in this way, but may also be configured in ways not listed.

[0096] All means or steps plus functional elements, their corresponding structures, materials, actions, and equivalents (if any), in the following claims are intended to include any structure, material, or action for performing a function in conjunction with other claimed elements, as specifically claimed. The description of the invention has been presented for purposes of illustration and description, but is not intended to be exhaustive or limited to the forms disclosed. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the invention. Embodiments have been chosen and described in order to best illustrate the principles and practical application of one or more aspects of the invention, and to enable others skilled in the art to understand one or more aspects of the invention for various embodiments with various modifications suited to the intended particular use.

Claims

1. A computer program product for facilitating the deployment of secure computing resources, the computer program product comprising: A computer-readable storage medium having program instructions embodied therein, the program instructions being readable by one or more processors to cause the one or more processors to: Receive requests to deploy computing resources in the computing environment; Obtain a homomorphic encryption dataset, which includes configuration-related data of the desired configuration of the computing resources to be deployed in the computing environment; as well as The homomorphic encrypted dataset is used when configuring the computing resources for deployment, and the computing resources are configured to be deployed using the desired configuration without decrypting the homomorphic encrypted dataset. The use of the homomorphically encrypted dataset includes: homomorphically identifying the configuration settings used when configuring the computing resources for deployment without decrypting the homomorphically encrypted dataset; and The homomorphic identification of configuration settings includes: comparing the homomorphic encryption setting template with the obtained homomorphic encryption dataset without decrypting the homomorphic encryption dataset, in order to identify the configuration settings.

2. The computer program product according to claim 1, wherein, The program instructions further instruct the one or more processors to deploy the computing resources in a secure area of ​​the computing environment using homomorphically recognized configuration settings.

3. The computer program product according to claim 2, wherein, The computing resources are selected from a group consisting of virtual machines and containers.

4. The computer program product according to claim 1, wherein, The program instructions further cause the one or more processors to: Define a configuration template for the computing resources to be deployed; Obtain the homomorphic encryption key used to generate the received homomorphic encrypted dataset; as well as The obtained homomorphic encryption key is used to homomorphically encrypt the given template to generate the homomorphically encrypted given template for comparison with the obtained homomorphically encrypted dataset.

5. The computer program product according to claim 4, wherein, Defining the configuration template includes obtaining one or more default configuration settings for the computing resources, and wherein the program instructions further cause the one or more processors to: identify a corresponding configuration setting by comparing the homomorphically encrypted configuration template with a received homomorphically encrypted dataset, and replace the default configuration setting in the one or more default configuration settings with the identified corresponding configuration setting.

6. The computer program product according to claim 1, wherein, The program instructions further cause the one or more processors to invoke one or more deployment operators based on the received request to deploy the computing resources, the one or more deployment operators obtaining the homomorphic encrypted dataset from the storage.

7. The computer program product according to claim 6, wherein, A homomorphic encrypted dataset obtained from the repository is digitally signed for integrity checks, and wherein the program instructions further cause the one or more processors to perform integrity checks on the obtained homomorphic encrypted dataset.

8. The computer program product according to claim 7, wherein, The homomorphic encrypted dataset is digitally signed using blockchain.

9. A computer system for facilitating the deployment of secure computing resources, the computer system comprising: Memory; One or more processors are operatively coupled to the memory; as well as Program code, executable by the one or more processors via the memory, to perform a method, the method comprising: Receive requests to deploy computing resources in the computing environment; Obtain a homomorphic encryption dataset, the homomorphic encryption dataset including configuration-related data of the desired configuration of the computing resources to be deployed in the computing environment; and The homomorphic encrypted dataset is used when configuring the computing resources for deployment, and the computing resources are configured to be deployed using the desired configuration without decrypting the homomorphic encrypted dataset. The use of the homomorphically encrypted dataset includes: homomorphically identifying the configuration settings used when configuring the computing resources for deployment without decrypting the homomorphically encrypted dataset; and The homomorphic identification of configuration settings includes: comparing the homomorphic encryption setting template with the obtained homomorphic encryption dataset without decrypting the homomorphic encryption dataset, in order to identify the configuration settings.

10. The computer system according to claim 9, further comprising: The computing resources are deployed in the secure zone of the computing environment using homomorphic recognition configuration settings.

11. The computer system according to claim 10, wherein, The computing resources are selected from a group consisting of virtual machines and containers.

12. The computer system according to claim 9, further comprising: Define a configuration template for the computing resources to be deployed; Obtain the homomorphic encryption key used to generate the received homomorphic encrypted dataset; as well as The obtained homomorphic encryption key is used to homomorphically encrypt the given template to generate the homomorphically encrypted given template for comparison with the obtained homomorphically encrypted dataset.

13. The computer system according to claim 9, further comprising: Based on the received request to deploy the computing resources, one or more deployment operators are invoked, and the one or more deployment operators obtain the homomorphic encrypted dataset from the repository.

14. The computer system according to claim 13, wherein, The homomorphic encrypted dataset obtained from the repository is digitally signed for integrity checks, and the program code further causes the one or more processors to perform integrity checks on the obtained homomorphic encrypted dataset.

15. The computer system according to claim 14, wherein, The homomorphic encrypted dataset is digitally signed using blockchain.

16. A computer-implemented method, comprising: Receive requests to deploy computing resources in the computing environment; Obtain a homomorphic encryption dataset, which includes configuration-related data of the desired configuration of the computing resources to be deployed in the computing environment; as well as The homomorphic encrypted dataset is used when configuring the computing resources for deployment, and the computing resources are configured to be deployed using the desired configuration without decrypting the homomorphic encrypted dataset. The use of the homomorphically encrypted dataset includes: homomorphically identifying the configuration settings used when configuring the computing resources for deployment without decrypting the homomorphically encrypted dataset; and The homomorphic identification of configuration settings includes: comparing the homomorphic encryption setting template with the obtained homomorphic encryption dataset without decrypting the homomorphic encryption dataset, in order to identify the configuration settings.

17. The computer-implemented method according to claim 16, further comprising: Define a configuration template for the computing resources to be deployed; Obtain the homomorphic encryption key used to generate the received homomorphic encrypted dataset; as well as The obtained homomorphic encryption key is used to homomorphically encrypt the given template to generate the homomorphically encrypted given template for comparison with the obtained homomorphically encrypted dataset.

Citation Information

Patent Citations

  • Method and device for security assessment of encryption models

    US20200244437A1