Method, system and device for encrypting and measuring key files of cloud hard disk based on DPU
By generating RSA public and private keys on the DPU, hashing and encrypting and decrypting the business operating system of the cloud hard disk, the security problem of cloud hard disk in a bare metal virtualization environment is solved, and the full encryption and measurement of key files is realized, ensuring the security and flexibility of cloud hard disk startup.
Patent Information
- Application Number
- CN202311394096.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-25
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2043-10-25
AI Technical Summary
In the prior art, the business operating system of cloud hard disk has insufficient security in virtualization scenarios, especially in bare metal virtualization environments, which lacks effective encryption and measurement mechanisms, resulting in cloud hard disk and business-related key files being easily damaged and attacked, and the DPU lacks detection and alarm mechanisms for OS images.
By generating RSA public and private keys on the DPU, using PXE Rom Driver and management devices to hash and encrypt and decrypt key files of the business operating system, and using the management devices on the DPU side to measure and encrypt, ensuring the security of key files, and decryption and measurement values are compared when the BIOS is started, realizing full encryption transmission.
It improves the security of the business operating system and key files started by cloud hard disk, ensures safe operation in a bare metal server environment, prevents file tampering and corruption, provides flexible encryption and measurement mechanisms, and enhances DPU security.
Smart Images

Figure CN117499028B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of virtualization technology, and in particular to a method, system and device for encrypting and measuring key files of a cloud hard disk based on a DPU. Background Art
[0002] The emergence of virtualization technology has greatly promoted the development of cloud computing and the Internet of Things. However, with the widespread application of cloud computing and the Internet of Things, virtualization technology has encountered bottlenecks. Traditional virtualization technology requires the call of the operating system to access hardware resources. For applications and scenarios with high performance and latency requirements, this method is no longer suitable.
[0003] The introduction of bare metal virtualization technology can solve the bottleneck problem of traditional virtualization technology and provide better performance and low latency experience for modern applications. At the same time, bare metal virtualization technology can make applications run faster, not only improving the utilization of hardware resources, but also better meeting the specific performance and service requirements of applications.
[0004] Elastic Bare Metal has the characteristics of minute-level delivery, and the operating system cloud hard disk is mounted immediately after use, which is convenient for user needs. However, as the main place for user business data storage, security issues are receiving more and more attention. In a full-disk encryption and decryption method and system based on network card ROM with publication number CN111177773A, it accesses the network card Rom based on grub2 in the installation file in the OS, obtains the key, and symmetrically encrypts the hard disk. It can be seen that the use scenario of CN111177773A is a general physical machine startup scenario. The physical hard disk is encrypted, which has limited flexibility and scenarios; symmetric encryption with keys has a high risk; this scenario uses the bootloader program to start the OS, which is not the commonly used uefi, and the scenario is limited; at the same time, CN111177773A only involves the use of OS itself grub2 in the OS startup stage to measure the installed hard disk partition, and the legitimacy of grub2 itself is not guaranteed; and CN111177773A does not involve virtualization scenarios, and the network card Rom must be bound to the OS file containing grub2, which has poor flexibility.
[0005] It can be seen that the prior art has the following technical defects:
[0006] 1. Business-related OS images are scheduled and backed up through cloud management platforms (such as OpenStack), which are prone to packet loss or defects, causing damage to cloud hard disks and business-related key files.
[0007] 2. Network cloud hard drives run on the Internet and are easily attacked by hackers and infected with viruses.
[0008] 3. The DPU, which is a key component for implementing virtualized bare metal, lacks a detection and alarm mechanism for cloud service OS images.
[0009] 4. The current SecureBoot (Secure Boot is a security feature designed to protect a computer's boot process from malware and unauthorized operating systems. It is a technology introduced by Microsoft and is now widely used in many computers and mobile devices) technology prevents users from installing custom operating systems on a computer or modifying certain components during the boot process. Additionally, if the private key of the digital signature is leaked or attacked, Secure Boot may also be affected. Therefore, when using Secure Boot, users need to protect the private key of the digital signature and ensure that the computer is not affected by any security vulnerabilities. The disadvantage is that the user's business is not flexible enough, and there is a lack of encryption and measurement mechanisms for critical files. Summary of the Invention
[0010] In view of this, the present invention provides a method, system, and device for encrypting and measuring critical files of a cloud hard disk based on a DPU, which can greatly improve the security of the business operating system for cloud hard disk startup and the security of critical files that users are interested in.
[0011] In a first aspect, a method for encrypting and measuring critical files of a cloud hard disk based on a DPU, the method includes:
[0012] A DPU plugged into a local server pre - generates a pair of public and private keys using the RSA algorithm;
[0013] During the installation phase, the PXE Rom Driver running on the DPU downloads the business operating system to be installed on the cloud hard disk from an image server;
[0014] The DPU performs a hash operation on the critical files of the business operating system and stores the obtained measurement value in the DPU;
[0015] The management device S - PF working on the DPU side calls the public key to encrypt the critical files of the business operating system;
[0016] The public key stored on the DPU is passed to the business operating system through the Smbios table or ACPI constructed by the PXE Rom Driver;
[0017] The encrypted business operating system with the public key is transmitted to the cloud hard disk through the local server;
[0018] After the BIOS of the local server is started, the PXE Rom Driver in the DPU is loaded. The management device M-PF working on the local server side decrypts the key files of the business operating system on the cloud hard disk through the PXE Rom Driver by calling the private key, so that the business operating system on the cloud hard disk is installed.
[0019] Furthermore, a method for encrypting and measuring key files of a cloud hard disk based on DPU further includes:
[0020] When the installed business operating system runs on the cloud hard disk, if the user needs to encrypt a specified file in a specified partition on the cloud hard disk, the business operating system performs a hash operation on the specified file in the specified partition, and stores the measured value obtained by the operation into the DPU through the local server via the management device M-PF. At the same time, the business operating system parses the public key transmitted by Smbios or ACPI, and encrypts the specified file in the specified partition using the public key.
[0021] Furthermore, a method for encrypting and measuring key files of a cloud hard disk based on DPU further includes:
[0022] When the installed business operating system runs on the cloud hard disk, if the user needs to restore a specified file in a specified partition on the cloud hard disk, the M_PF driver running on the cloud hard disk drives the management device M-PF. The management device M-PF reads the private key from the DPU through the local server and passes it back to the cloud hard disk. The cloud hard disk decrypts the specified file in the specified partition using the private key, and at the same time performs a hash operation on the specified file in the specified partition, and compares whether the measured values before and after decryption are the same. If they are not the same, the specified file in the specified partition has been tampered with or damaged. If they are the same and the decryption is successful, the specified file in the specified partition is successfully restored.
[0023] Furthermore, a method for encrypting and measuring key files of a cloud hard disk based on DPU further includes:
[0024] When the local server that is currently interacting with the business operating system on the cloud hard disk experiences business congestion, the business operating system on the cloud hard disk will be transferred by the cloud management platform to another local server with idle business. When rescheduled back to the original local server, after the BIOS of the original local server starts, it loads the PXE Rom Driver in the DPU. The PXE Rom Driver decrypts the key files of the business operating system on the cloud hard disk by calling the private key through the management device M-PF. At the same time, the DPU recalculates the hash of the key files of the rescheduled business operating system and compares the measurement value obtained from this calculation with the measurement value stored in the DPU before the business operating system was transferred. If the private key can decrypt and the measurement values obtained from the two calculations are the same, it indicates that the business operating system was not damaged during the transfer process.
[0025] Further, a method for encrypting and measuring key files of a cloud hard disk based on a DPU further includes:
[0026] When the PXE Rom Driver decrypts the key files of the business operating system on the cloud hard disk by calling the private key through the management device M-PF, if the private key cannot decrypt, the BIOS of the original local server will pop up an alarm, and the user will handle the business operating system according to the alarm.
[0027] Further, the user handling the business operating system according to the alarm includes: the PXE Rom Driver running on the DPU redownloads the business operating system to be installed on the cloud hard disk from the image server and completes the reinstallation of the redownloaded business operating system on the cloud hard disk; or, the DPU regenerates a pair of public and private keys using the RSA algorithm and completes the reinstallation of the redownloaded business operating system on the cloud hard disk using the regenerated public and private keys.
[0028] Further, the DPU includes a System on Chip (SOC) and a non-volatile device Flash ROM. After the SOC of the on-chip operating system pre-generates a pair of public and private keys using the RSA algorithm, it writes the public and private keys to the agreed positions in the non-volatile device Flash ROM.
[0029] Further, a method for encrypting and measuring key files of a cloud hard disk based on a DPU further includes:
[0030] After the local server connects to the Adapter Connect, the DPU powers on and self-starts. The SOC of the on-chip operating system generates a pair of public and private keys using the RSA algorithm and writes the public and private keys to the agreed positions in the non-volatile device Flash ROM.
[0031] Second aspect, a system for encrypting and measuring critical files of a cloud hard disk based on a DPU, the system includes a local server, a DPU running plugged into the local server, a management device M-PF working on the local server side, and a management device S-PF working on the DPU side. Among them, the DPU pre-generates a pair of public key and private key using the RSA algorithm;
[0032] During the installation stage, the PXE Rom Driver running on the DPU downloads the business operating system to be installed on the cloud hard disk from the image server; the DPU performs a hash operation on the critical files of the business operating system, and stores the obtained measurement value in the DPU. Then, the management device S-PF is used to call the public key to encrypt the critical files of the business operating system. At the same time, the public key stored on the DPU is passed to the business operating system through the Smbios table or ACPI constructed by the PXE Rom Driver. Finally, the encrypted business operating system carrying the public key is transmitted to the cloud hard disk through the local server;
[0033] After the BIOS of the local server is started, the PXE Rom Driver in the DPU is loaded, and the management device M-PF decrypts the critical files of the business operating system on the cloud hard disk by calling the private key through the PXE Rom Driver, so that the cloud hard disk completes the installation of the business operating system.
[0034] Third aspect, a device for encrypting and measuring critical files of a cloud hard disk based on a DPU, the device includes: a host computer and a memory for storing a computer program that can run on the host computer; among them, when the host computer is used to run the computer program, it executes the steps of any method in the first aspect.
[0035] Beneficial effects:
[0036] 1. A method for encrypting and measuring critical files of a cloud hard disk based on a DPU generates and stores a public key and a private key on the DPU side, which belongs to out-of-band storage. Compared with storing the public key and private key on the local server and the cloud hard disk, the security is higher; the key generated by the DPU performs hash measurement, encryption and decryption on the critical files in the business operating system startup file and installation package file, ensuring that the business operating system on the cloud hard disk runs in a safe environment, fundamentally realizing the full measurement of the business operating system, avoiding the insecure method of using the installation package file of the business operating system to measure itself, and being able to ensure that the business operating system started by the cloud hard disk is safe.
[0037] 2. A method for encrypting and measuring critical files of a cloud hard disk based on DPU. The whole process runs directly on the hardware, that is, the operating environment of the present invention is a bare-metal scenario. At the same time, the present invention measures and encrypts critical files by obtaining the public key on the System on Chip (SOC). This can ensure the security of the critical files that users care about. That is to say, the present invention can achieve the security of the business operating system and the security of the critical files that users care about on a bare-metal server.
[0038] 3. A method for encrypting and measuring critical files of a cloud hard disk based on DPU. The public key and private key generated by the DPU side also participate in the encryption, decryption, and restoration of specified files during the operation of the installed business operating system on the cloud hard disk, improving the security during the operation of the business operating system on the cloud hard disk.
[0039] 4. A method for encrypting and measuring critical files of a cloud hard disk based on DPU. After the business operating system is rescheduled back to the original local server by the cloud management platform, if the private key cannot decrypt the critical files of the business operating system on the cloud hard disk, the BIOS of the original local server will pop up an alarm, facilitating users to make further processing.
[0040] 5. A method for encrypting and measuring critical files of a cloud hard disk based on DPU. The public key and private key are generated by the DPU side and written into the agreed positions of the non-volatile device Flash ROM. That is to say, the public key and private key of the present invention are not stored on the local server and the cloud hard disk, belonging to out-of-band storage, with higher security. Moreover, the non-volatile device Flash ROM of the DPU has a write protection function, making it not easy to leak and be damaged. At the same time, the transmission path of the secret key is DPU -> Flash ROM -> PXE RomDriver (uefi) -> placed on the business operating system of the cloud hard disk through the Smbios table or ACPI - business operating system. The whole process is encrypted transmission to ensure that the key is not leaked and damaged.
[0041] 6. A system for encrypting and measuring critical files of a cloud hard disk based on DPU. The public key and private key are generated and stored by the DPU side, belonging to out-of-band storage. Compared with storing the public key and private key on the local server and the cloud hard disk, it has higher security. The secret key generated by the DPU performs hash measurement, encryption, and decryption on the critical files in the business operating system startup files and installation package files, ensuring that the business operating system on the cloud hard disk runs in a secure environment, fundamentally realizing the full measurement of the business operating system, avoiding the insecure way of using the installation package file of the business operating system to measure itself, and being able to ensure the security of the business operating system starting from the cloud hard disk.
[0042] 7. A device for encrypting and measuring critical files of a cloud hard disk based on DPU generates and stores public and private keys on the DPU side, which belongs to out-of-band storage. Compared with storing public and private keys on a local server and a cloud hard disk, it has higher security. The key generated by the DPU performs hash measurement, encryption, and decryption on critical files in the business operating system startup file and installation package file, ensuring that the business operating system on the cloud hard disk runs in a secure environment, fundamentally realizing the full measurement of the business operating system, avoiding the insecure method of the installation package file of the business operating system measuring itself, and being able to ensure that the business operating system started by the cloud hard disk is secure. Description of the Drawings
[0043] Figure 1 It is a flowchart of a method for encrypting and measuring critical files of a cloud hard disk based on DPU.
[0044] Figure 2 It is a flowchart of the DPU generating a key using the RSA algorithm.
[0045] Figure 3 It is a flowchart of installing a business operating system on a cloud hard disk.
[0046] Figure 4 It is a flowchart of a user encrypting a specified file in a specified partition on a cloud hard disk.
[0047] Figure 5 It is a flowchart of a user restoring a specified file in a specified partition on a cloud hard disk.
[0048] Figure 6 It is a flowchart of a user processing a business operating system according to an alarm. Detailed Embodiments
[0049] The following combines the drawings and gives embodiments to describe the present invention in detail.
[0050] The basic principle of the present invention is as follows: starting from the DPU card, it aims to encrypt and measure the key files of the business operating system OS (Operating System). First, at the installation stage, the on-chip operating system SOC of the DPU measures and encrypts the key files of the installation image, including but not limited to vmlinx, initrd, grub, cfg, etc., and then sends them to the cloud management platform (such as OpenStack). Specifically, the SOC generates a pair of public and private keys. The public key encrypts the cloud OS installation file and sends it to the cloud management platform through the installation network. During the installation process, the server BIOS loads the PXE Rom driver on the DPU card and downloads the installation image initially scheduled by the cloud management platform (which has been encrypted at this time). It decrypts first and then measures to restore the original file, and then installs the business OS. Secondly, during the startup and running stage of the business OS, at the startup stage, the local server BIOS loads the PXE Rom Driver on the DPU, decrypts it with the private key, and detects the measured value (a string of hash numbers) to ensure the security of the started cloud hard disk OS. Finally, through the PXE Rom Driver of the DPU, the public key is encrypted and passed to the business OS through the smbios table. The business OS obtains the public key after decryption and encrypts the specified partition file with the public key, making the key file not easily cracked. If the public key of the business OS is lost or damaged, a failure will occur when decrypting with the private key during the startup stage of the business OS. At this time, the PXE Rom Driver of the DPU will prompt an alarm message, and the user can, according to the prompt message, request the SOC to generate a public key and a private key again.
[0051] Specifically, as Figure 1 shown, a method for encrypting and measuring key files of a cloud hard disk based on DPU includes:
[0052] S1: The DPU running on the local server is pre-configured to generate a pair of public and private keys using the RSA algorithm; among them, as Figure 2 shown, the DPU includes an on-chip operating system SOC and a non-volatile device Flash ROM. After the local server is connected to the Adapter Connect, the DPU powers on and starts self-booting. The on-chip operating system SOC starts and initializes the management device M-PF on the Host side (visible to the server). The on-chip operating system SOC pre-generates a pair of public and private keys using the RSA algorithm and writes the public and private keys into the agreed positions of the non-volatile device Flash ROM; for example, by manually running commands to generate a pair of public and private keys, including but not limited to, for example:
[0053] #openssl genrsa - out private.key 1024
[0054] #openssl rsa -in private.key -pubout -out pub.key
[0055] It should be noted that RSA is an asymmetric encryption method based on the difficult - to - decompose theory of the product of large prime numbers in number theory. It uses the public - private key method for encryption and decryption. Among them, the public key is used for encryption and is publicly available to everyone, while the private key is used for decryption and is generated and held only by DPU manufacturers.
[0056] S2: During the installation stage, the PXE Rom Driver running on the DPU downloads the business operating system to be installed on the cloud hard disk from the image server;
[0057] S3: The DPU performs a hash operation on the key files of the business operating system and stores the obtained measurement value in the DPU;
[0058] S4: The management device S - PF working on the DPU side calls the public key to encrypt the key files of the business operating system; it should be noted that the management device S - PF is a special management device generated through FPGA logic on the side of the on - chip operating system SOC.
[0059] S5: The public key stored on the DPU is passed to the business operating system through the Smbios table or ACPI constructed by the PXE Rom Driver;
[0060] S6: The encrypted business operating system with the public key is transmitted to the cloud hard disk through the local server;
[0061] S7: After the BIOS of the local server starts, it loads the PXE Rom Driver in the DPU. The management device M - PF working on the local server side calls the private key through the PXE Rom Driver to decrypt the key files of the business operating system on the cloud hard disk, so that the business operating system installation on the cloud hard disk is completed, as Figure 3 shown.
[0062] It should be noted that the key files of the business operating system are the kernel startup files in the business operating system installation package, such as vmlinux, initrd, grub, cfg related to system security, and the configuration files of the kernel under / etc / , etc.
[0063] Optionally, when the installed business operating system runs on the cloud hard disk, if the user needs to encrypt a specified file in a specified partition on the cloud hard disk, the business operating system performs a hash operation on the specified file in the specified partition, and stores the measured value obtained by the operation in the DPU via the local server through the management device M-PF. At the same time, the business operating system parses the public key transmitted by Smbios or ACPI, and encrypts the specified file in the specified partition with the public key, as Figure 4 shown.
[0064] When the installed business operating system runs on the cloud hard disk, if the user needs to restore a specified file in a specified partition on the cloud hard disk, the M_PF driver running on the cloud hard disk drives the management device M-PF. The management device M-PF reads the private key from the DPU through the local server and sends it back to the cloud hard disk. The cloud hard disk decrypts the specified file in the specified partition with the private key, and at the same time performs a hash operation on the specified file in the specified partition, and compares whether the measured values before and after decryption are the same. If they are not the same, the specified file in the specified partition has been tampered with or damaged. If they are the same and the decryption is successful, the specified file in the specified partition is successfully restored, as Figure 5 shown.
[0065] It should be noted that when the local server interacting with the business operating system on the cloud hard disk is congested, the business operating system on the cloud hard disk will be transferred by the cloud management platform to another local server with idle services. Since the files concerned by the user have been measured and encrypted before the business operating system is transferred away, in order to ensure that the key files are not lost, when rescheduled back to the original local server, after the BIOS of the original local server starts, it loads the PXE Rom Driver in the DPU. The PXE Rom Driver decrypts the key files of the business operating system on the cloud hard disk by calling the private key through the management device M-PF. At the same time, the DPU re-performs a hash operation on the key files of the rescheduled business operating system, and compares the measured value obtained by this operation with the measured value stored in the DPU before the business operating system is transferred away. If the private key can decrypt and the measured values obtained by the two operations are the same, it means that the business operating system has not been damaged during the transfer process.
[0066] Among them, when the PXE Rom Driver decrypts the key files of the business operating system on the cloud hard disk by calling the private key through the management device M-PF, if the private key cannot decrypt, it means that the public key has expired or is illegal, and the BIOS of the original local server will pop up an alarm, and the user will process the business operating system according to the alarm.
[0067] Optionally, the user's processing of the business operating system according to the alert includes: the PXERom Driver running on the DPU redownloads the business operating system to be installed on the cloud hard disk from the image server, and completes the reinstallation of the redownloaded business operating system on the cloud hard disk; or, the DPU regenerates a pair of public and private keys using the RSA algorithm, and uses the regenerated public and private keys to complete the reinstallation of the redownloaded business operating system on the cloud hard disk, as Figure 6 shown.
[0068] It should be noted that the above processes all run directly on the hardware, that is, the operating environment of the method for encrypting and measuring key files of a cloud hard disk based on DPU provided by the present invention is a bare metal scenario; through the above steps, it can be ensured that the business operating system starting from the cloud hard disk is secure. At the same time, by obtaining the public key on the on-chip operating system SOC to measure and encrypt the key files, the present invention can ensure the security of the key files concerned by the user.
[0069] As another implementation manner, the present invention also provides a system for encrypting and measuring key files of a cloud hard disk based on DPU, characterized in that the system includes a local server, a DPU plugged into and running on the local server, a management device M-PF working on the local server side, and a management device S-PF working on the DPU side. Among them, the DPU pre-generates a pair of public and private keys using the RSA algorithm;
[0070] During the installation stage, the PXE Rom Driver running on the DPU downloads the business operating system to be installed on the cloud hard disk from the image server; the DPU performs a hash operation on the key files of the business operating system, and stores the obtained measurement value in the DPU. Then, the management device S-PF is used to call the public key to encrypt the key files of the business operating system. At the same time, the public key stored on the DPU is passed to the business operating system through the Smbios table or ACPI constructed by the PXE Rom Driver. Finally, the encrypted business operating system carrying the public key is transmitted to the cloud hard disk through the local server;
[0071] After the BIOS of the local server is started, the PXE Rom Driver in the DPU is loaded, and the management device M-PF calls the private key through the PXE Rom Driver to decrypt the key files of the business operating system on the cloud hard disk, so that the cloud hard disk completes the installation of the business operating system.
[0072] As another implementation manner, the present invention further provides a device for encrypting and measuring key files of a cloud hard disk based on a DPU. The device includes: a host computer and a memory for storing a computer program capable of running on the host computer; wherein, when the host computer is used to run the computer program, each step of the method for encrypting and measuring key files of a cloud hard disk based on a DPU as described above is executed.
[0073] In summary, the above are only the preferred embodiments of the present invention, and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for encrypting and measuring key files of a cloud hard disk based on DPU, characterized in that The method includes: The DPU running on the local server pre-uses the RSA algorithm to generate a pair of public and private keys; During the installation stage, the PXE Rom Driver running on the DPU downloads the business operating system to be installed on the cloud hard disk from the image server; The DPU performs a hash operation on the key files of the business operating system and stores the obtained measurement value in the DPU; The management device S-PF working on the DPU side calls the public key to encrypt the key files of the business operating system; The public key stored on the DPU is passed to the business operating system through Smbiostable or ACPI constructed by the PXE Rom Driver; The encrypted business operating system with the public key is transmitted to the cloud hard disk through the local server; After the BIOS of the local server is started, the PXE Rom Driver in the DPU is loaded, and the management device M-PF working on the local server side calls the private key through the PXE Rom Driver to decrypt the key files of the business operating system on the cloud hard disk, so that the cloud hard disk completes the installation of the business operating system; The DPU includes a system-on-chip operating system SOC and a non-volatile device Flash ROM. After the system-on-chip operating system SOC pre-uses the RSA algorithm to generate a pair of public and private keys, the public key and the private key are written into the specified positions of the non-volatile device Flash ROM.
2. The method for encrypting and measuring key files of a cloud hard disk based on DPU according to claim 1, wherein, It also includes: When the installed business operating system runs on the cloud hard disk, if the user needs to encrypt the specified file in the specified partition of the cloud hard disk, the business operating system performs a hash operation on the specified file in the specified partition, and stores the obtained measurement value in the DPU through the management device M-PF via the local server. At the same time, the business operating system parses the public key transmitted by Smbios or ACPI and encrypts the specified file in the specified partition with the public key.
3. The method for encrypting and measuring key files of a cloud hard disk based on DPU according to claim 1, wherein, It also includes: When the installed business operating system runs on the cloud hard disk, if the user needs to restore the specified file in the specified partition of the cloud hard disk, the M-PF driver running on the cloud hard disk drives the management device M-PF. The management device M-PF reads the private key from the DPU through the local server and passes it back to the cloud hard disk. The cloud hard disk decrypts the specified file in the specified partition with the private key, and at the same time performs a hash operation on the specified file in the specified partition, and compares whether the measurement values before and after decryption are the same. If they are not the same, the specified file in the specified partition has been tampered with or damaged. If they are the same and the decryption is successful, the specified file in the specified partition is successfully restored.
4. The method for encrypting and measuring key files of a cloud hard disk based on DPU according to claim 1, wherein, It also includes: When there is a business congestion on the local server that is currently interacting with the business operating system on the cloud hard disk, the business operating system on the cloud hard disk will be transferred by the cloud management platform to another local server with idle business. When rescheduled back to the original local server, after the BIOS of the original local server starts, it loads the PXE Rom Driver in the DPU. The PXE RomDriver decrypts the key files of the business operating system on the cloud hard disk by calling the private key through the management device M-PF. At the same time, the DPU recalculates the hash of the key files of the rescheduled business operating system and compares the measurement value obtained from this calculation with the measurement value stored in the DPU before the business operating system was transferred. If the private key can decrypt and the measurement values obtained from the two calculations are the same, it indicates that the business operating system was not damaged during the transfer process.
5. The method for encrypting and measuring key files of a cloud hard disk based on DPU according to claim 4, wherein, It further includes: When the PXE Rom Driver calls the private key through the management device M-PF to decrypt the key files of the business operating system on the cloud hard disk, if the private key cannot decrypt, the BIOS of the original local server will pop up an alarm, and the user will handle the business operating system according to the alarm.
6. The method for encrypting and measuring key files of a cloud hard disk based on DPU according to claim 5, wherein, The user's handling of the business operating system according to the alarm includes: the PXE Rom Driver running on the DPU downloads the business operating system to be installed on the cloud hard disk from the image server again and completes the reinstallation of the redownloaded business operating system on the cloud hard disk; or, the DPU regenerates a pair of public and private keys using the RSA algorithm and completes the reinstallation of the redownloaded business operating system on the cloud hard disk using the regenerated public and private keys.
7. The method for encrypting and measuring key files of a cloud hard disk based on DPU according to claim 1, wherein, It further includes: After the local server is connected to the Adapter Connect, the DPU powers on and starts self-booting. The on-chip operating system SOC generates a pair of public and private keys using the RSA algorithm and writes the public and private keys to the agreed positions in the non-volatile device Flash ROM.
8. A system for encrypting and measuring critical files of a cloud hard disk based on DPU, characterized in that, The system includes a local server, a DPU running plugged into the local server, a management device M-PF working on the local server side, and a management device S-PF working on the DPU side. Among them, the DPU pre-generates a pair of public and private keys using the RSA algorithm; During the installation stage, the PXE Rom Driver running on the DPU downloads the business operating system to be installed on the cloud hard disk from the image server; the DPU calculates the hash of the key files of the business operating system and stores the obtained measurement value in the DPU, and then calls the public key through the management device S-PF to encrypt the key files of the business operating system. At the same time, the public key stored on the DPU is passed to the business operating system through the Smbiostable or ACPI constructed by the PXE Rom Driver. Finally, the encrypted business operating system with the public key is transmitted to the cloud hard disk through the local server; After the BIOS of the local server is started, the PXE Rom Driver in the DPU is loaded, and the management device M-PF decrypts the key files of the business operating system on the cloud hard disk through the PXE Rom Driver by calling the private key, so that the business operating system installation on the cloud hard disk is completed; The DPU includes a System on Chip (SOC) for the on-chip operating system and a non-volatile device Flash ROM. After the SOC for the on-chip operating system generates a pair of public and private keys in advance using the RSA algorithm, the public and private keys are written into the specified locations in the non-volatile device Flash ROM.
9. An apparatus for encrypting and measuring critical files of a cloud hard disk based on DPU, characterized in that, The device includes: a host computer and a memory for storing a computer program that can run on the host computer; wherein, when the host computer runs the computer program, it executes the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Full-disk encryption and decryption method and system based on network card ROM
CN111177773A
Data processing system, method and device
CN116521360A
BIOS startup method and data processing method
US20190121981A1