A bare metal cloud hard drive data encryption device, method, equipment and medium based on national secret algorithm

Through a data encryption solution based on national secret algorithms, the challenges of storage space expansion and data security management of bare metal servers are solved, the secure storage and independent controllability of data are achieved, and dependence on imported technology is avoided.

CN119227112BActive Publication Date: 2025-09-23SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411414226.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-11
Publication Date
2025-09-23
Estimated Expiration
2044-10-11

AI Technical Summary

Technical Problem

Bare metal servers present challenges in storage space expansion and data security management, especially in distributed storage environments. Existing encryption technologies are transparent to cloud service providers and pose security risks.

Method used

A data encryption solution based on the national secret algorithm is adopted, including a block storage management module, a key management module, a storage encryption module and a bare metal product module. Keys are created and managed through the national secret algorithm to implement encrypted volume type definition and data mirror storage, and data encryption processing is performed in combination with OpenStack and Ceph.

Benefits of technology

It improves the security and controllability of bare metal cloud hard drive data, avoids dependence on imported technology, and ensures the security and independent controllability of data during transmission and storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119227112B_ABST
    Figure CN119227112B_ABST
Patent Text Reader

Abstract

The present application discloses a bare metal cloud hard drive data encryption device, method, equipment and medium based on a national secret algorithm, relating to the field of cloud computing technology, including: a block storage management module, used to receive a bare metal cloud hard drive data encryption request, and generate an encrypted volume creation requirement based on the parsed encryption requirement information; a key management module, used to trigger an encryption algorithm selection operation, and create and manage a target key and a target key ID corresponding to the encrypted volume creation requirement based on the target national secret algorithm; a block storage management module, used to obtain target key information including the target key ID, and create and verify a target encrypted cloud hard drive based on the target key information; a storage encryption module, used to create and store target image information corresponding to the hard drive data to be encrypted in the bare metal cloud hard drive data encryption request based on the verification result; a bare metal product module, used to generate and mount a bare metal instance according to the bare metal cloud hard drive data encryption request, and complete the encryption of the bare metal hard drive data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cloud computing technology, and in particular to a bare metal cloud hard drive data encryption device, method, equipment and medium based on a national secret algorithm. Background Art

[0002] New technologies and applications are accelerating the digital transformation of traditional industries, leading to massive data growth. Enterprises are faced with the need to store and manage ever-increasing amounts of data, much of which includes sensitive and critical information. The need for data protection is growing, and enterprises need to encrypt the storage and transmission of sensitive data to prevent data leaks, ensure data integrity, confidentiality, and availability, and protect against data leakage, tampering, or loss.

[0003] Currently, the underlying technologies for cloud drives include centralized storage and distributed storage. Centralized storage, based on a unified controller, allows for convenient server-side data encryption. However, the key is stored in the cloud provider's centralized storage. Therefore, cloud drive encryption is transparent to the cloud service provider, posing certain security risks. Distributed storage primarily uses device mapping for cloud drive encryption, with Linux Unified Key Setup (LUKS) being the most widely used encryption technology. The general process involves mounting the cloud drive to a bare metal device using device mapping on a Smart NIC, and transparently transmitting the encrypted mapped device to the bare metal device.

[0004] Bare metal servers are cloud computing services that provide direct access to physical servers without a virtualization layer. The primary advantages of bare metal servers are their high performance and low latency, making them ideal for applications requiring high-performance computing or low-latency networking. However, bare metal servers also present challenges, one of which is how to expand the storage space of the physical servers and ensure the security and manageability of that storage. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide a bare metal cloud hard drive data encryption device, method, equipment, and medium based on the national secret algorithm, which can ensure the storage security and manageability of data on the bare metal hard drive. The specific solution is as follows:

[0006] In the first aspect, the present application discloses a bare metal cloud hard disk data encryption device based on the national secret algorithm, including: a block storage management module, a key management module, a storage encryption module, and a bare metal product module, wherein:

[0007] The block storage management module is configured to receive a bare metal cloud hard disk data encryption request sent by the client through a first data transmission channel connected to the client, parse the bare metal cloud hard disk data encryption request to obtain encryption requirement information, and generate a corresponding encrypted volume creation requirement based on the encryption requirement information;

[0008] The key management module is configured to obtain the encrypted volume creation requirement through a key creation interface connected to the block storage management module, trigger an encryption algorithm selection operation to determine a target national encryption algorithm, and create and manage a target key and target key ID corresponding to the encrypted volume creation requirement based on the target national encryption algorithm;

[0009] The block storage management module is configured to obtain target key information including the target key ID through the key query interface of the key management module, define an encrypted volume type based on the target key information, create and verify a target encrypted cloud hard disk based on the encrypted volume type, and then send the target key information to the storage encryption module through a second data transmission channel connected to the storage encryption module;

[0010] The storage encryption module is configured to create target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request based on the verification result of the key attribute in the target key information, and store the target image information in the target encrypted cloud hard disk;

[0011] The bare metal product module is used to generate a corresponding bare metal instance according to the bare metal cloud hard disk data encryption request, and perform a distributed mounting operation on the target encrypted cloud hard disk to the bare metal instance to complete the encryption of the bare metal hard disk data.

[0012] Optionally, the key management module includes:

[0013] A key creation unit is used to select a target national encryption algorithm through a pre-written multi-national encryption algorithm integration plug-in, so as to create a target key and a target key ID corresponding to the encrypted volume creation requirement based on the target national encryption algorithm.

[0014] Optionally, the block storage management module includes:

[0015] An encrypted volume type definition unit, configured to define an encrypted volume type according to the encryption type corresponding to the target national encryption algorithm, the target key ID, and the key query interface URL;

[0016] An encrypted cloud hard disk creation unit, configured to create a target encrypted cloud hard disk in the cloud hard disk management of the block storage management module based on the encrypted volume type;

[0017] The encrypted cloud hard disk verification unit is used to obtain an encryption key according to the target key ID corresponding to the encrypted volume type and the key query interface URL, and determine whether the target encrypted cloud hard disk corresponding to the successful acquisition of the encryption key has passed the verification.

[0018] Optionally, the bare metal cloud hard drive data encryption device based on the national encryption algorithm further includes:

[0019] The data processing module is used to perform data alignment processing on the hard disk data in the bare metal cloud hard disk data encryption request to synthesize the hard disk data to be encrypted.

[0020] Optionally, the storage encryption module includes:

[0021] An interface modification unit, configured to modify a block device creation interface in a Ceph block device library to add current attribute information in the current block device creation interface to obtain an updated block device creation interface;

[0022] The interface verification unit is used to verify the interface attributes of the updated block device creation interface based on the key attributes in the target key information. If the verification passes, the target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request is created.

[0023] Optionally, the bare metal product module includes:

[0024] The instance generation unit is used to select a target smart network card model according to the bare metal cloud hard disk data encryption request, create a bare metal instance according to the target smart network card model, and record the bare metal instance through a preset instance identifier.

[0025] Optionally, the bare metal product module includes:

[0026] The uninstallation unit is configured to uninstall the target encrypted cloud hard disk in the bare metal instance using a preset uninstallation instruction when an uninstallation request for uninstalling the target encrypted cloud hard disk is detected.

[0027] Secondly, this application discloses a bare metal cloud hard drive data encryption method based on a national secret algorithm, including:

[0028] Receiving a bare metal cloud hard disk data encryption request sent by the client through a first data transmission channel connected to the client, parsing the bare metal cloud hard disk data encryption request to obtain encryption requirement information, and generating a corresponding encrypted volume creation requirement based on the encryption requirement information;

[0029] Obtain the encrypted volume creation requirement through the key creation interface, trigger the encryption algorithm selection operation to determine the target national encryption algorithm, and create and manage the target key and target key ID corresponding to the encrypted volume creation requirement based on the target national encryption algorithm;

[0030] Obtain target key information including the target key ID through the key query interface, define an encrypted volume type based on the target key information, and create and verify a target encrypted cloud hard disk based on the encrypted volume type;

[0031] Obtaining the target key information through the second data transmission channel, creating target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request based on the verification result of the key attribute in the target key information, and storing the target image information in the target encrypted cloud hard disk;

[0032] A corresponding bare metal instance is generated according to the bare metal cloud hard disk data encryption request, and a distributed mounting operation is performed on the target encrypted cloud hard disk to mount it to the bare metal instance to complete the encryption of the bare metal hard disk data.

[0033] In a third aspect, the present application discloses an electronic device, comprising:

[0034] Memory, used to store computer programs;

[0035] A processor is configured to execute the computer program to implement the steps of the aforementioned method for encrypting data of a bare metal cloud hard drive based on a national encryption algorithm.

[0036] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the aforementioned disclosed bare metal cloud hard drive data encryption method based on the national secret algorithm are implemented.

[0037] It can be seen that the present application provides a bare metal cloud hard disk data encryption device based on the national secret algorithm, including: a block storage management module, a key management module, a storage encryption module, and a bare metal product module, wherein the block storage management module is used to receive a bare metal cloud hard disk data encryption request sent by the client through a first data transmission channel connected to the client, and parse the bare metal cloud hard disk data encryption request to obtain encryption requirement information, and generate a corresponding encryption volume creation requirement according to the encryption requirement information; the key management module is used to obtain the encryption volume creation requirement through a key creation interface connected to the block storage management module, trigger an encryption algorithm selection operation to determine a target national secret algorithm, and create and manage a target key and target key ID corresponding to the encryption volume creation requirement based on the target national secret algorithm; the block storage management module is used to obtain the encryption volume creation requirement through the key management interface connected to the block storage management module, trigger an encryption algorithm selection operation to determine a target national secret algorithm, and create and manage a target key and target key ID corresponding to the encryption volume creation requirement based on the target national secret algorithm; The key query interface of the processing module obtains the target key information containing the target key ID to define the encryption volume type based on the target key information, and creates and verifies the target encrypted cloud hard disk based on the encryption volume type, and then sends the target key information to the storage encryption module through the second data transmission channel connected to the storage encryption module; the storage encryption module is used to create the target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request based on the verification result of the key attribute in the target key information, and store the target image information in the target encrypted cloud hard disk; the bare metal product module is used to generate a corresponding bare metal instance according to the bare metal cloud hard disk data encryption request, and perform a distributed mount operation on the target encrypted cloud hard disk to the bare metal instance to complete the encryption of the bare metal hard disk data. It can be seen that by combining the bare metal server and the application of the national encryption algorithm in data storage security, the bare metal cloud hard disk can use the national encryption function, effectively protect the security of user data during transmission and storage, ensure that data is not easily stolen and decrypted, improve the security and controllability of data, and meet the user's needs for data security. Using national secret algorithms for encryption can avoid the risk of relying on imported technology and improve the independent controllability of information security. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0039] Figure 1 This is a schematic diagram of the structure of a bare metal cloud hard drive data encryption device based on the national secret algorithm disclosed in this application;

[0040] Figure 2 This is a flowchart of data encryption and writing for a bare metal cloud hard drive based on a national encryption algorithm disclosed in this application;

[0041] Figure 3 This is a flowchart of reading data after the bare metal cloud hard disk data is encrypted based on the national encryption algorithm disclosed in this application;

[0042] Figure 4 This is a flowchart of a bare metal cloud hard drive data encryption method based on a national secret algorithm disclosed in this application;

[0043] Figure 5 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0044] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0045] New technologies and applications are accelerating the digital transformation of traditional industries, leading to massive data growth. Enterprises are faced with the need to store and manage ever-increasing amounts of data, much of which includes sensitive and critical information. The need for data protection is growing, and enterprises need to encrypt the storage and transmission of sensitive data to prevent data leaks, ensure data integrity, confidentiality, and availability, and protect against data leakage, tampering, or loss.

[0046] Currently, the underlying technologies for cloud drives include centralized storage and distributed storage. Centralized storage, based on a unified controller, allows for convenient data encryption on the server side. However, the key is stored in the cloud provider's centralized storage. Therefore, cloud drive encryption is transparent to the cloud service provider, posing certain security risks. Distributed storage primarily uses device mapping for cloud drive encryption, with Linux's LUKS encryption technology being the most widely used. The general process involves mounting the cloud drive to bare metal using device mapping on a Smart NIC, and transparently transmitting the encrypted mapped device to the bare metal.

[0047] Bare metal servers are cloud computing services that provide direct access to physical servers without a virtualization layer. The primary advantages of bare metal servers are their high performance and low latency, making them ideal for applications requiring high-performance computing or low-latency networking. However, bare metal servers also present challenges, one of which is how to expand the storage space of the physical servers and ensure the security and manageability of that storage.

[0048] To this end, the present invention provides a bare metal cloud hard drive data encryption solution based on the national secret algorithm, which can ensure the storage security and manageability of data in the bare metal hard drive.

[0049] Reference Figure 1 As shown, the embodiment of the present invention discloses a bare metal cloud hard disk data encryption device based on the national secret algorithm, including: a block storage management module 11, a key management module 12, a storage encryption module 13, and a bare metal product module 14, wherein:

[0050] The block storage management module 11 is configured to receive a bare metal cloud hard disk data encryption request sent by the client through a first data transmission channel connected to the client, parse the bare metal cloud hard disk data encryption request to obtain encryption requirement information, and generate a corresponding encrypted volume creation requirement based on the encryption requirement information;

[0051] The key management module 12 is configured to obtain the encrypted volume creation requirement through a key creation interface connected to the block storage management module 11, trigger an encryption algorithm selection operation to determine a target national encryption algorithm, and create and manage a target key and target key ID corresponding to the encrypted volume creation requirement based on the target national encryption algorithm;

[0052] The block storage management module 11 is configured to obtain target key information including the target key ID through the key query interface of the key management module 12, define an encrypted volume type based on the target key information, create and verify a target encrypted cloud hard disk based on the encrypted volume type, and then send the target key information to the storage encryption module 13 through a second data transmission channel connected to the storage encryption module 13;

[0053] The storage encryption module 13 is configured to create target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request based on the verification result of the key attribute in the target key information, and store the target image information in the target encrypted cloud hard disk;

[0054] The bare metal product module 14 is used to generate a corresponding bare metal instance according to the bare metal cloud hard disk data encryption request, and perform a distributed mounting operation on the target encrypted cloud hard disk to the bare metal instance to complete the encryption of the bare metal hard disk data.

[0055] It can be understood that the cloud computing platform uses OpenStack Ironic (the bare metal service component of the OpenStack project) for bare metal management, Cinder Volume (the block storage service component of Cinder in OpenStack) for virtual block storage management, and Ceph (the storage system) for underlying data storage. The device includes modules such as a key management module 12, a block storage management module 11, a bare metal product module 13, and a storage encryption module 13. The key management module 12 manages various key algorithms and can be used to create and manage national secret keys. The block storage management module 11 connects to the storage encryption module 13 to manage encrypted cloud hard disk devices and read and write data. The bare metal product module 14 creates bare metal instances and, based on block storage management capabilities, mounts and unmounts block storage and reads and writes data. The storage encryption module 13 supports data encryption, writing, and decryption on the client side by modifying the Ceph librbd library (a client library for operating block devices (Rados BlockDevice, RBD) in the Ceph distributed storage system). Encrypted cloud hard disks are created according to the national secret encryption algorithm selected by the user, enabling encrypted storage of bare metal cloud hard disk data and improving the security of user data.

[0056] The key management module 12 includes:

[0057] The key creation unit 121 is used to select a target national encryption algorithm through a pre-written multi-national encryption algorithm integration plug-in, so as to create a target key and a target key ID corresponding to the encrypted volume creation requirement based on the target national encryption algorithm.

[0058] It is understandable that the key management module 12 provides users with a visual key management interface to implement the creation, acquisition, update and deletion of national secret algorithms. The present invention is based on the OpenStack barbican capability and mainly has two core functions: support for national secret algorithms and key management. Regarding the support of national secret algorithms, according to the requirements of the Barbican plug-in, a plug-in for the national secret algorithm is written based on plugin.interface.secret_store.SecretStoreBase and integrated into barbican to implement support for the national secret algorithm, so that the national secret algorithm can be used in barbican to encrypt, decrypt or sign data. Key management implements the creation, query, activation / deactivation, and deletion of national secret keys. After creation or import, the key is hosted in barbican. Barbican encrypts the key according to its own unique algorithm and then stores it in the database. No one, including the administrator, can view the key plaintext. The key management module 12 exposes the key creation interface, key query interface, online encryption interface, online decryption interface, etc. Specifically, the key creation unit 121 selects a target national encryption algorithm, such as the SM4 (Symmetric Block Encryption Algorithm), from an integrated plug-in that integrates multiple national encryption algorithms. Using the SM4 algorithm, it creates a target key and a corresponding target key ID corresponding to the encrypted volume creation request sent by the block storage management module. Other modules can then query key information related to the target key based on the target key ID.

[0059] The block storage management module 11 includes:

[0060] The encrypted volume type definition unit 111 is configured to define the encrypted volume type according to the encryption type corresponding to the target national encryption algorithm, the target key ID, and the key query interface URL;

[0061] An encrypted cloud hard disk creation unit 112 is configured to create a target encrypted cloud hard disk in the cloud hard disk management of the block storage management module based on the encrypted volume type;

[0062] The encrypted cloud hard disk verification unit 113 is configured to obtain an encryption key according to the target key ID corresponding to the encrypted volume type and the key query interface URL, and determine whether the target encrypted cloud hard disk corresponding to successful encryption key acquisition has passed verification.

[0063] It is understood that the block storage management module 11 provides users with a cloud hard drive management interface. Based on this module, users can perform operations such as creating, expanding, mounting, and unmounting cloud hard drives. The storage encryption module, integrated with the OpenStack Cinder service, enables the creation of custom encrypted volume types. Encrypted volume types include attributes such as the encryption type, master key, and key URL (Uniform Resource Locator). 1) The volume type stores key-related attributes; 2) When creating an encrypted volume based on the volume type and the backend is RBD, the key information is passed to librbd. Specifically, the block storage management module 11 enables the creation of encrypted cloud hard drives.

[0064] 1) The encrypted volume type definition unit 111 creates an encrypted volume type (volume-type): This adds an encrypted volume type to the volume types in the block storage management module 11. The encrypted volume type includes attributes such as the encryption type (encry-type), the master key (master-key), and the key URL (key-url). The master key is the target key ID generated by the key management module 12, and the key URL is the URL for obtaining the encryption key based on the master key.

[0065] 2) Encrypted cloud hard disk creation unit 112 creates an encrypted volume of the encrypted volume type: creates an encrypted volume, ie, a target encrypted cloud hard disk, in the cloud hard disk management of the block storage management module 11, mainly to obtain the properties of the corresponding encrypted volume type.

[0066] 3) The encrypted cloud disk verification unit 113 verifies the key attributes. This requires obtaining an encryption key (target key) based on the master key and key URL. Successful retrieval indicates verification success, while failure indicates verification failure. If verification fails, a message indicating encrypted cloud disk creation failure is returned. If verification passes, the RBD backend is called to continue creating the encrypted image.

[0067] The bare metal cloud hard drive data encryption device based on the national secret algorithm also includes:

[0068] The data processing module is used to perform data alignment processing on the hard disk data in the bare metal cloud hard disk data encryption request to synthesize the hard disk data to be encrypted.

[0069] The storage encryption module 13 includes:

[0070] The interface modification unit 131 is configured to modify the block device creation interface in the Ceph block device library to add current attribute information in the current block device creation interface to obtain an updated block device creation interface;

[0071] The interface verification unit 132 is used to verify the interface attributes of the updated block device creation interface based on the key attributes in the target key information. If the verification passes, target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request is created.

[0072] It is understood that the storage encryption module 13 is further used to create encrypted images. Specifically, the interface modification unit 131 is used to modify the rbd_create interface in the Ceph librbd library, adding three attributes: encryption type (encry-type), master key (master-key), and key URL (key-url). The interface verification unit 132 is used to verify the key attributes. If the verification fails, the creation failure is returned. If the verification succeeds, the image creation continues and the encryption attributes are stored in the omap of the image rbd_header object. The Cinder volume service uses the rbd_create interface with the added encrypted image creation function.

[0073] In this way, the storage encryption module 13 supports data encryption and decryption on the client by modifying the Ceph librbd library, thereby realizing encrypted reading and writing of distributed storage cloud hard disks. The steps are as follows:

[0074] 1) Create an encrypted image and store key-related attributes in the omap of the rbd header object;

[0075] 2) When opening the image, the encryption type is loaded and, based on the encryption type, the encryption key is obtained by communicating with the key server network;

[0076] 3) When the client writes data, the data is aligned and encrypted, and then the ciphertext is sent to the OSD (Object Storage Device) for storage;

[0077] 4) When the client reads data, it reads the ciphertext stored in the OSD, decrypts it, and returns it to the client;

[0078] 5) Encrypted mirror rbd mirror off-site encrypted backup;

[0079] 6) Decrypt the encrypted image into a non-encrypted image;

[0080] 7) Encrypt and store the non-encrypted image.

[0081] The bare metal product module 14 includes:

[0082] The instance generation unit 141 is configured to select a target smart network card model according to the bare metal cloud hard disk data encryption request, create a bare metal instance according to the target smart network card model, and record the bare metal instance using a preset instance identifier.

[0083] The bare metal product module 14 includes:

[0084] The uninstallation unit 142 is configured to uninstall the target encrypted cloud hard disk in the bare metal instance using a preset uninstallation instruction when an uninstallation request for uninstalling the target encrypted cloud hard disk is detected.

[0085] It is understood that the bare metal product management module 14 can automatically install the operating system, initialize the network, and other operations based on user image, network, and storage requirements, providing bare metal instances on the cloud, providing excellent computing performance and data security for core databases, key application systems, high-performance computing, big data, and other businesses. Based on the capabilities of the bare metal smart network card, it is possible to mount distributed storage cloud hard drives to expand the storage space of the bare metal and meet the user's large-capacity storage needs. It is also possible to mount cloud hard drives that support encryption types to achieve encrypted reading and writing of data.

[0086] The bare metal product management module 14 implements the creation of bare metal instances and the mounting of cloud hard disks. The specific mounting steps are as follows:

[0087] 1) On the Bare Metal product management page, select the Smart NIC model to create a Bare Metal instance and record the instanceId of the Bare Metal instance.

[0088] 2) Modify the nova-compute service's get_volume_connector(instanceId) interface for obtaining instance connector information to support returning whether the instance is a Smart NIC model.

[0089] 3) nova-compute calls IronicDriver to perform mount / unmount operations: nova.virt.block_device.DriverVolumeBlockDevice._volume_attach calls the driver's attach_volume to complete the mount and calls detach_volume to complete the unmount.

[0090] IronicDriver calls ironic-api through ironicclient to perform mount / unmount operations;

[0091] After the request is sent, IronicDriver will periodically check whether the volume is mounted successfully. If it is mounted successfully, the volume information will be written to the extra field of the node. If the mount is not completed within 3 minutes, it will be treated as a timeout and the mount will fail.

[0092] 4) Ironiccliet responds to mount / unmount requests:

[0093] In the NodeManager class of ironicclient, add attach_volume and detach_volume to respond to API requests for mounting volumes to nodes;

[0094] The path is <node-uuid> / volume;

[0095] 5) The API sends the attach / detach request to Ironic-Conductor via RPC, calling Ironic's Cinder Storage interface - CinderStorage to perform the mount / unmount operation;

[0096] 6) CinderStorage interface completes the mount / unmount operation:

[0097] To be compatible with Ironic's existing Cinder interface, the new mount logic is executed based on the volume type being rbd and the node port being is_smartnic. If the RBD volume is mounted to a smart NIC, the original mount logic is used in all other cases.

[0098] 7) The driver uses the netmiko module to call the ssh command to complete the volume mounting and unmounting operations:

[0099] After the mount is complete, pci is returned, and pci_index identifies the volume mount information on the SmartNIC instance. After the unmount is complete, the volume information is returned and the volume information is removed from the extra field of the node.

[0100] 8) After nova-compute issues the mount command, IronicDriver calls ironic-api to complete the mount. At this time, IronicDriver waits for the mount result.

[0101] By periodically checking the node's extra dictionary, determine whether the mount is successful. If successful, format the mount information into an InstanceDeviceMetadata instance and update it to the instance's device_metadata.

[0102] If it is uninstallation, the uninstallation is successful after detecting that the extra field of the node has no corresponding volume.

[0103] 9) Mounting / unmounting completed.

[0104] After the mount is successful, the mount information connection_info is saved to the block_device_mapping data table of nova; Cinder is notified that the volume attachment has been completed and the volume status is changed to in-use; after the unmount is successful, Cinder is notified and the volume attachment delete operation is performed.

[0105] like Figure 2 As shown, Figure 2 The specific process of writing data encryption is disclosed: modify the image opening interface in the librbd library to add a judgment on whether it is an encrypted image. If it is an encrypted image, load the key information from the omap of the rbd_header object, communicate with the key server network based on the key server interface URL and the master key, and obtain the encryption key. If the encryption key cannot be obtained, exit.

[0106] The librbd client data writing process uses the national encryption algorithm to encrypt data. The specific encryption process is as follows:

[0107] 1) Obtain the encryption key;

[0108] 2) The original data block is aligned with 4k at the beginning and end;

[0109] The data block is divided into header_4k, middle, and tail_4k. Header_4k is the new address after the first address is aligned 4k forward, and tail_4k is the new address after the tail address is aligned 4k backward minus 4k. Header_4k and tail_4k are two 4k data blocks. You need to initiate data read from the image first (for the specific process, see Read Data Decryption). The header_4k and tail_4k data are integrated with the read header_4k_old and tail_4k_old to synthesize 4k-length data: header_4k_new and tail_4k_new.

[0110] 3) Data encryption;

[0111] Call the national encryption algorithm to encrypt the three blocks of data header_4k_new, middle and tail_4k_new, combine the encrypted data header_4k_encry, middle_encry and tail_4k_encry into one data block, and call the librbd normal write interface to store the encrypted data in Ceph OSD.

[0112] Read data decryption

[0113] Modify the image opening interface in the librbd library to add a check for encrypted images. If the image is encrypted, load the key information from the omap of the rbd_header object, communicate with the key server network based on the key server interface URL and the master key, and obtain the encryption key. If the encryption key cannot be obtained, exit.

[0114] like Figure 3 As shown, the librbd client data reading process decryption supports the national encryption algorithm. The specific reading data decryption process is as follows:

[0115] 1) Obtain the encryption key;

[0116] 2) The read data block address is aligned with the first and last 4k;

[0117] Record the starting address src_addr and ending address dest_addr of the data block to be read. Divide the data block into header_4k, middle, and tail_4k. Header_4k is the new address after the first address is aligned 4k forward, and tail_4k is the tail address aligned 4k backward. Call librbd's normal read API to obtain the encrypted data [header_4k, tail_4k+4k].

[0118] 3) Data decryption;

[0119] The national encryption algorithm is called to decrypt the [header_4k, tail_4k+4k] data block, and the data of the starting address src_addr and the ending address dest_addr are obtained and returned to the client.

[0120] Combining bare metal servers and the application of national encryption algorithms in data storage security, bare metal cloud hard drives can use national encryption functions, effectively protecting the security of user data during transmission and storage, ensuring that data is not easily stolen and decrypted, improving data security and controllability, and meeting users' needs for data security.

[0121] It can be seen that the present application provides a bare metal cloud hard disk data encryption device based on the national secret algorithm, including: a block storage management module, a key management module, a storage encryption module, and a bare metal product module, wherein the block storage management module is used to receive a bare metal cloud hard disk data encryption request sent by the client through a first data transmission channel connected to the client, and parse the bare metal cloud hard disk data encryption request to obtain encryption requirement information, and generate a corresponding encryption volume creation requirement according to the encryption requirement information; the key management module is used to obtain the encryption volume creation requirement through a key creation interface connected to the block storage management module, trigger an encryption algorithm selection operation to determine a target national secret algorithm, and create and manage a target key and target key ID corresponding to the encryption volume creation requirement based on the target national secret algorithm; the block storage management module is used to obtain the encryption volume creation requirement through the key management interface connected to the block storage management module, trigger an encryption algorithm selection operation to determine a target national secret algorithm, and create and manage a target key and target key ID corresponding to the encryption volume creation requirement based on the target national secret algorithm; The key query interface of the processing module obtains the target key information containing the target key ID to define the encryption volume type based on the target key information, and creates and verifies the target encrypted cloud hard disk based on the encryption volume type, and then sends the target key information to the storage encryption module through the second data transmission channel connected to the storage encryption module; the storage encryption module is used to create the target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request based on the verification result of the key attribute in the target key information, and store the target image information in the target encrypted cloud hard disk; the bare metal product module is used to generate a corresponding bare metal instance according to the bare metal cloud hard disk data encryption request, and perform a distributed mount operation on the target encrypted cloud hard disk to the bare metal instance to complete the encryption of the bare metal hard disk data. It can be seen that by combining the bare metal server and the application of the national encryption algorithm in data storage security, the bare metal cloud hard disk can use the national encryption function, effectively protect the security of user data during transmission and storage, ensure that data is not easily stolen and decrypted, improve the security and controllability of data, and meet the user's needs for data security. Using national secret algorithms for encryption can avoid the risk of relying on imported technology and improve the independent controllability of information security.

[0122] Reference Figure 4 As shown, the present invention provides a bare metal cloud hard disk data encryption method based on the national encryption algorithm, including:

[0123] Step S11: receiving a bare metal cloud drive data encryption request sent by the client through a first data transmission channel connected to the client, parsing the bare metal cloud drive data encryption request to obtain encryption requirement information, and generating a corresponding encrypted volume creation requirement based on the encryption requirement information;

[0124] Step S12: Obtain the encrypted volume creation requirement through the key creation interface, trigger an encryption algorithm selection operation to determine the target national encryption algorithm, and create and manage the target key and target key ID corresponding to the encrypted volume creation requirement based on the target national encryption algorithm;

[0125] Step S13: Obtain target key information including the target key ID through the key query interface, define an encrypted volume type based on the target key information, and create and verify a target encrypted cloud hard disk based on the encrypted volume type;

[0126] Step S14: Obtain the target key information through the second data transmission channel, create target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request based on the verification result of the key attribute in the target key information, and store the target image information in the target encrypted cloud hard disk;

[0127] Step S15: Generate a corresponding bare metal instance according to the bare metal cloud hard disk data encryption request, and perform a distributed mounting operation on the target encrypted cloud hard disk to the bare metal instance to complete the encryption of the bare metal hard disk data.

[0128] For the specific implementation process of the above steps, please refer to the aforementioned disclosed embodiment content, which will not be repeated here.

[0129] It can be seen that the present application receives a bare metal cloud hard disk data encryption request sent by the client through a first data transmission channel connected to the client, and parses the bare metal cloud hard disk data encryption request to obtain encryption requirement information, and generates a corresponding encryption volume creation requirement based on the encryption requirement information; obtains the encryption volume creation requirement through the key creation interface, triggers the encryption algorithm selection operation to determine the target national encryption algorithm, and creates and manages the target key and target key ID corresponding to the encryption volume creation requirement based on the target national encryption algorithm; obtains the target key information containing the target key ID through the key query interface to define the encryption volume type based on the target key information, and creates and verifies the target encrypted cloud hard disk based on the encryption volume type; obtains the target key information through the second data transmission channel, and creates the target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request based on the verification result of the key attribute in the target key information, and stores the target image information in the target encrypted cloud hard disk; generates a corresponding bare metal instance according to the bare metal cloud hard disk data encryption request, and performs a distributed mount operation on the target encrypted cloud hard disk to mount it to the bare metal instance to complete the encryption of the bare metal hard disk data. This demonstrates that by combining bare metal servers with the application of national encryption algorithms for data storage security, bare metal cloud drives can be encrypted using national encryption, effectively protecting user data during transmission and storage, ensuring data is less susceptible to theft and decryption, and improving data security and controllability, meeting user needs for data security. Using national encryption algorithms avoids the risks of relying on imported technology and improves independent controllability of information security.

[0130] Furthermore, the embodiment of the present application also discloses an electronic device, Figure 5 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram should not be considered as any limitation to the scope of application of the present application.

[0131] Figure 5 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps of the bare metal cloud hard drive data encryption method based on the national encryption algorithm disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0132] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0133] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 can be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.

[0134] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0135] Among them, the operating system 221 is used to manage and control the various hardware devices and computer programs 222 on the electronic device 20 to enable the processor 21 to calculate and process the massive data 223 in the memory 22. It can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the bare metal cloud hard disk data encryption method based on the national secret algorithm executed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include computer programs that can be used to complete other specific tasks. In addition to including data transmitted from an external device received by the electronic device, the data 223 can also include data collected by its own input and output interface 25.

[0136] Furthermore, this application discloses a computer-readable storage medium for storing a computer program. When executed by a processor, the computer program implements the aforementioned method for encrypting data on a bare metal cloud drive based on a national encryption algorithm. The specific steps of this method can be found in the corresponding content disclosed in the aforementioned embodiments and will not be further elaborated here.

[0137] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. Reference can be made to the descriptions of the identical or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and the relevant parts can be referred to the descriptions of the methods.

[0138] Professionals may further appreciate that the units and algorithmic steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application. The steps of the method or algorithm described in conjunction with the embodiments disclosed herein can be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory RAM (Random Access Memory), memory, read-only memory ROM (Read Only Memory), electrically programmable EPROM (Electrically Programmable Read Only Memory), electrically erasable programmable EEPROM (Electric Erasable Programmable Read Only Memory), registers, hard disk, removable disk, CD-ROM (Compact Disc-Read Only Memory), or any other form of storage medium known in the technical field.

[0139] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprise," "include," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a set of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.

[0140] The above is a detailed introduction to the solution provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.

Claims

1. A bare metal cloud hard disk data encryption device based on the national secret algorithm, characterized in that: include: Block storage management module, key management module, storage encryption module, bare metal product module, among which, The block storage management module is configured to receive a bare metal cloud hard disk data encryption request sent by the client through a first data transmission channel connected to the client, parse the bare metal cloud hard disk data encryption request to obtain encryption requirement information, and generate a corresponding encrypted volume creation requirement based on the encryption requirement information; The key management module is configured to obtain the encrypted volume creation requirement through a key creation interface connected to the block storage management module, trigger an encryption algorithm selection operation to determine a target national encryption algorithm, and create and manage a target key and target key ID corresponding to the encrypted volume creation requirement based on the target national encryption algorithm; The block storage management module is configured to obtain target key information including the target key ID through the key query interface of the key management module, define an encrypted volume type based on the target key information, create and verify a target encrypted cloud hard disk based on the encrypted volume type, and then send the target key information to the storage encryption module through a second data transmission channel connected to the storage encryption module; The storage encryption module is configured to create target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request based on the verification result of the key attribute in the target key information, and store the target image information in the target encrypted cloud hard disk; The bare metal product module is used to generate a corresponding bare metal instance according to the bare metal cloud hard disk data encryption request, and perform a distributed mounting operation on the target encrypted cloud hard disk to the bare metal instance to complete the encryption of the bare metal hard disk data.

2. The bare metal cloud hard disk data encryption device based on the national secret algorithm according to claim 1 is characterized in that: The key management module includes: A key creation unit is used to select a target national encryption algorithm through a pre-written multi-national encryption algorithm integration plug-in, so as to create a target key and a target key ID corresponding to the encrypted volume creation requirement based on the target national encryption algorithm.

3. The bare metal cloud hard disk data encryption device based on the national secret algorithm according to claim 1 is characterized in that: The block storage management module includes: An encrypted volume type definition unit, configured to define an encrypted volume type according to the encryption type corresponding to the target national encryption algorithm, the target key ID, and the key query interface URL; An encrypted cloud hard disk creation unit, configured to create a target encrypted cloud hard disk in the cloud hard disk management of the block storage management module based on the encrypted volume type; The encrypted cloud hard disk verification unit is used to obtain an encryption key according to the target key ID corresponding to the encrypted volume type and the key query interface URL, and determine whether the target encrypted cloud hard disk corresponding to the successful acquisition of the encryption key has passed the verification.

4. The bare metal cloud hard disk data encryption device based on the national secret algorithm according to claim 1 is characterized in that: Also includes: The data processing module is used to perform data alignment processing on the hard disk data in the bare metal cloud hard disk data encryption request to synthesize the hard disk data to be encrypted.

5. The bare metal cloud hard disk data encryption device based on the national secret algorithm according to claim 1 is characterized in that: The storage encryption module includes: An interface modification unit, configured to modify a block device creation interface in a Ceph block device library to add current attribute information in the current block device creation interface to obtain an updated block device creation interface; The interface verification unit is used to verify the interface attributes of the updated block device creation interface based on the key attributes in the target key information. If the verification passes, the target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request is created.

6. The bare metal cloud hard disk data encryption device based on the national secret algorithm according to claim 1 is characterized in that: The bare metal product module includes: The instance generation unit is used to select a target smart network card model according to the bare metal cloud hard disk data encryption request, create a bare metal instance according to the target smart network card model, and record the bare metal instance through a preset instance identifier.

7. The bare metal cloud hard disk data encryption device based on the national secret algorithm according to claim 1 is characterized in that: The bare metal product module includes: The uninstallation unit is configured to uninstall the target encrypted cloud hard disk in the bare metal instance using a preset uninstallation instruction when an uninstallation request for uninstalling the target encrypted cloud hard disk is detected.

8. A bare metal cloud hard disk data encryption method based on a national secret algorithm, characterized in that: include: Receiving a bare metal cloud hard disk data encryption request sent by the client through a first data transmission channel connected to the client, parsing the bare metal cloud hard disk data encryption request to obtain encryption requirement information, and generating a corresponding encrypted volume creation requirement based on the encryption requirement information; Obtain the encrypted volume creation requirement through the key creation interface, trigger the encryption algorithm selection operation to determine the target national encryption algorithm, and create and manage the target key and target key ID corresponding to the encrypted volume creation requirement based on the target national encryption algorithm; Obtain target key information including the target key ID through the key query interface, define an encrypted volume type based on the target key information, and create and verify a target encrypted cloud hard disk based on the encrypted volume type; Obtaining the target key information through the second data transmission channel, creating target image information corresponding to the hard disk data to be encrypted in the bare metal cloud hard disk data encryption request based on the verification result of the key attribute in the target key information, and storing the target image information in the target encrypted cloud hard disk; A corresponding bare metal instance is generated according to the bare metal cloud hard disk data encryption request, and a distributed mounting operation is performed on the target encrypted cloud hard disk to mount it to the bare metal instance to complete the encryption of the bare metal hard disk data.

9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor is configured to execute the computer program to implement the steps of the bare metal cloud hard disk data encryption method based on the national encryption algorithm as claimed in claim 8.

10. A computer-readable storage medium, characterized in that Used to store computer programs; wherein, when the computer program is executed by the processor, the steps of the bare metal cloud hard disk data encryption method based on the national secret algorithm as claimed in claim 8 are implemented.

Citation Information

Patent Citations

  • Cloud hard disk encryption mounting method and device, electronic equipment and storage medium

    CN113407242A

  • Data encryption system, method and device, storage medium and electronic equipment

    CN116582267A