Method and system for quickly checking disk integrity of virtual machine
By determining the calculation and verification timing points in the virtual machine disk, and using the hash value verification method, the problem of virtual machine disk integrity verification is solved, and fast and accurate integrity checks and tampering positioning is achieved.
Patent Information
- Application Number
- CN202411942571.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-05-09
AI Technical Summary
The prior art is difficult to effectively verify the integrity of virtual machine disks, especially in operations such as dynamic migration, snapshots and cloning. Traditional methods cannot meet the requirements in practical applications.
By determining the timing of the hash value of the virtual machine disk, the virtual machine disk hash value is calculated at the current moment by using the split virtual machine disk file and compression function, and the hash value of the virtual machine disk is verified by comparing the hash value of the current and previous moments to verify the integrity of the virtual machine disk.
It realizes rapid and accurate verification of the integrity of the virtual machine disk, can effectively determine whether the disk has been tampered with, and improves verification efficiency, and can accurately locate the specific location of the tampering behavior.
Smart Images

Figure CN119960672A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of virtual machine integrity verification, and in particular to a method and system for quickly verifying the integrity of a virtual machine disk. Background Art
[0002] With the rapid development of cloud computing technology, virtual machines have been widely used in enterprise and personal computing environments. Virtual machines provide users with flexible, efficient and scalable computing resources, allowing multiple operating systems and applications to run in parallel on the same physical server, thereby improving the utilization of hardware resources and reducing costs.
[0003] During the operation of a virtual machine, the disk is a key component for storing data, and its integrity is crucial to the normal operation of the virtual machine and the security of the data. The integrity of the virtual machine disk may be damaged due to a variety of reasons, such as malicious attacks, unexpected power outages, hardware failures, etc. If the integrity of the virtual machine disk is damaged, it may lead to serious consequences such as data loss, system crashes, service interruptions, etc., causing great losses to users.
[0004] Traditional disk integrity verification methods are mainly targeted at physical disks, and do not take into account the particularity of virtual machine disks. Virtual machine disks usually exist in the form of files on physical storage devices, and their storage structure and access methods are different from physical disks. In addition, dynamic migration, disk and memory snapshots, cloning and other operations in the virtual machine environment also bring new challenges to virtual machine disk integrity verification.
[0005] In recent years, with the increasing popularity of virtual machines and the increasing complexity of application scenarios, the demand for virtual machine disk integrity verification has become very urgent. Some existing solutions have certain limitations in terms of accuracy, efficiency, coverage scenarios, etc., and cannot meet the requirements of practical applications. Therefore, reliable virtual machine disk integrity verification technology has important practical significance and application value. Summary of the invention
[0006] The purpose of this specification is to provide a method for quickly verifying the integrity of a virtual machine disk, which can solve the problem in the prior art that a single-factor aging model has a large error in estimating the remaining life of an in-service cable.
[0007] The embodiments of this specification are implemented as follows:
[0008] In a first aspect, this specification provides a method for quickly verifying the integrity of a virtual machine disk, mainly comprising:
[0009] According to the construction and startup process of the virtual machine disk, determine the calculation time and verification time of the virtual machine disk hash value;
[0010] At the calculation timing point and the verification timing point, by segmenting the virtual machine disk file and the compression function, a hash value of the virtual machine disk at the current moment is calculated, and the hash value of the virtual machine disk has a unique corresponding relationship with the content of the virtual machine disk;
[0011] When the virtual machine disk is in a corresponding state, the verification result is obtained by comparing the virtual machine disk hash value at the current moment with the virtual machine disk hash value at the previous moment, wherein the virtual machine disk is in a corresponding state means that the state of the virtual machine at the previous moment and the state of the virtual machine at the current moment have a corresponding relationship;
[0012] According to the verification result, it is determined whether to start the virtual machine or whether to create the virtual machine disk.
[0013] In a second aspect, this specification provides a system for quickly verifying the integrity of a virtual machine disk, mainly comprising:
[0014] A determination module, used to determine a calculation timing and a verification timing of a virtual machine disk hash value according to a construction and startup process of the virtual machine disk;
[0015] A calculation module, used for calculating the hash value of the virtual machine disk at the current moment by segmenting the virtual machine disk file and the compression function at the calculation time point and the verification time point, wherein the hash value of the virtual machine disk has a unique corresponding relationship with the content of the virtual machine disk;
[0016] A verification module, used to obtain a verification result by comparing a hash value of the virtual machine disk at a current moment with a hash value of the virtual machine disk at a previous moment when the virtual machine disk is in a corresponding state, wherein the virtual machine disk being in a corresponding state means that the state of the virtual machine at a previous moment has a corresponding relationship with the state of the virtual machine at a current moment;
[0017] An execution module is used to determine whether to start the virtual machine or create the virtual machine disk according to the verification result.
[0018] The embodiments of this specification have at least the following advantages or beneficial effects:
[0019] This method of quickly verifying the integrity of a virtual machine disk enables the control platform (i.e., the control platform of the virtual machine) to modify the data or content in the virtual machine disk at a specific time point, and the behavior of modifying the data or content in the above virtual machine disk at other time points is the behavior of tampering with the data, so that the integrity of the virtual machine disk can be effectively determined, that is, when the data or content in the virtual machine disk is tampered with, it is determined that the virtual machine disk does not have integrity, thereby achieving the effect of accurately monitoring the tampering time period. Moreover, the above method of splitting the virtual machine disk file can effectively improve the efficiency of the above virtual machine disk hash value calculation, and can also accurately locate the specific location where the virtual machine disk is tampered. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions of the embodiments of this specification, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present specification and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.
[0021] Figure 1 A flowchart of a method for quickly verifying the integrity of a virtual machine disk provided in this specification;
[0022] Figure 2 A schematic diagram of the Merkle tree provided for this specification;
[0023] Figure 3 A schematic diagram of the process of calculating the virtual machine disk hash value when creating the virtual machine disk provided in this manual;
[0024] Figure 4 A schematic diagram of the process of calculating and verifying the virtual machine disk hash value when the virtual machine is stopped and started provided in this manual;
[0025] Figure 5 A flowchart of the virtual machine disk unplugging, disk binding time calculation, and virtual machine disk hash value verification process provided in this manual;
[0026] Figure 6 A flowchart of virtual machine snapshots, virtual machine startup time calculation, and virtual machine disk hash value verification provided in this manual;
[0027] Figure 7 A schematic diagram of a system for quickly verifying the integrity of a virtual machine disk provided in this specification. DETAILED DESCRIPTION
[0028] In order to make the purpose, technical solutions and advantages of the embodiments of this specification more clear, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are part of the embodiments of this specification, not all of the embodiments. Generally, the components of the embodiments of this specification described and shown in the drawings here can be arranged and designed in various different configurations.
[0029] Please refer to Figures 1 to 6 An embodiment of the present specification provides a method for quickly verifying the integrity of a virtual machine disk, which mainly includes:
[0030] Step 102: Determine the calculation timing and verification timing of the virtual machine disk hash value according to the construction and startup process of the virtual machine disk;
[0031] Step 104: at the calculation timing point and the verification timing point, by segmenting the virtual machine disk file and the compression function, a hash value of the virtual machine disk at the current moment is calculated, and the hash value of the virtual machine disk has a unique corresponding relationship with the content of the virtual machine disk;
[0032] Step 106: When the virtual machine disk is in a corresponding state, a verification result is obtained by comparing the hash value of the virtual machine disk at the current moment with the hash value of the virtual machine disk at the previous moment, wherein the virtual machine disk being in a corresponding state means that the state of the virtual machine at the previous moment and the state of the virtual machine at the current moment have a corresponding relationship;
[0033] Step 108: Determine whether to start the virtual machine or create the virtual machine disk according to the verification result.
[0034] In this embodiment, the above virtual machine disk hash value has a unique corresponding relationship with the data or content in the virtual machine disk. When the data or content in the virtual machine disk is tampered with or modified, the corresponding hash value will change.
[0035] In this embodiment, the storage format of the files in the virtual machine disk is qcow2 format. In detail, by storing the disk image file of the virtual machine in the above qcow2 format, when the data needs to be modified, it will not be modified at the original location of the virtual machine disk, but space will be allocated at the new location of the virtual machine disk, and data or content will be written. The above method can prevent the unused space in the virtual machine disk from being pre-allocated, thereby avoiding the occurrence of holes. Moreover, through the above storage method, only the modified data can be stored without repeatedly storing the original data and content. It can be seen that the above method can also effectively reduce the physical file size of the above virtual machine disk, thereby making the calculation time of the above verification method shorter and the verification speed faster.
[0036] In this embodiment, the above-mentioned method of optimizing the virtual machine disk storage format can effectively handle the allocation and release of disk space, thereby reducing unnecessary computing resource consumption caused by file holes.
[0037] In this embodiment, through the above method, the control platform (i.e., the control platform of the virtual machine) can modify the data or content in the virtual machine disk at a specific time point, and the behavior of modifying the data or content in the virtual machine disk at other time points is the behavior of tampering with the data, so that the integrity of the virtual machine disk can be effectively determined, that is, when the data or content in the virtual machine disk is tampered, it is determined that the virtual machine disk does not have integrity, thereby achieving the effect of accurately monitoring the tampering time period. Moreover, the above method of splitting the virtual machine disk file can effectively improve the efficiency of the above virtual machine disk hash value calculation, and can also accurately locate the specific location where the virtual machine disk is tampered.
[0038] In this embodiment, the method of splitting the virtual machine disk file and the compression function is to adopt the blake3 hash algorithm, which can significantly speed up the calculation speed of the virtual machine disk hash value, and at the same time can effectively improve the accuracy and reliability of the virtual machine disk hash value, thereby achieving the effect of improving the efficiency of the integrity verification of the entire virtual machine disk.
[0039] In this embodiment, one implementation of step 102 is as follows:
[0040] Step 112: According to the construction and startup process of the virtual machine disk, determine the time of creating the virtual machine disk, the time of suspending the virtual machine disk, the time of stopping the virtual machine disk, the time of unplugging the virtual machine disk, and the time of snapshotting the virtual machine as the calculation timing points of the virtual machine disk hash value.
[0041] In this embodiment, at the time of creation of the virtual machine disk, the virtual machine disk hash value is calculated to determine whether the virtual machine disk at this time has integrity. If it has, metadata of the virtual machine disk volume is created. The metadata includes the properties of the disk, that is, all attribute data such as the size and affiliation of the disk, so as to facilitate subsequent precise supervision of the tampering time period.
[0042] In this embodiment, a hook (i.e., the behavioral logic for calling an execution event) is set before creating the metadata (i.e., the disk attribute) of the virtual machine disk volume (i.e., the disk file). Through the above method, the main code of the virtual machine platform (the control platform that controls multiple virtual machines at the same time) can be kept unchanged. It only needs to call the corresponding hook when calculating the virtual machine disk hash value, verifying the virtual machine disk hash value, starting the virtual machine, and binding the virtual machine disk. The effect of the above method can be achieved. It can be seen that the above hook mechanism can effectively improve the applicability of the above virtual machine platform.
[0043] In this embodiment, the above-mentioned calculation timing point can be the moment when the above-mentioned start command, stop command, disk unplug command, disk bind command, virtual machine snapshot command reaches the local virtual machine, or the time point before the above-mentioned command is executed after being processed by the processing module of the local virtual machine and transmitted to libvirt.
[0044] In this embodiment, the virtual machine disk being in a corresponding state means that the virtual machine is in a corresponding state of stopping and starting, a corresponding state of pulling out a disk and binding a disk, and a corresponding state of a virtual machine snapshot and a virtual machine startup.
[0045] In this embodiment, the virtual machine disk hash value is calculated when the virtual machine is stopped (or before the stop time), and the virtual machine disk hash value is calculated before the virtual machine is started. By verifying whether the hash values at the above two times are consistent, it is determined whether the virtual machine disk has been tampered with during the time period between the virtual machine stop time or before the stop time and the start time, that is, whether it has integrity. If it has integrity, the virtual machine is started.
[0046] In this embodiment, the virtual machine stop state is triggered by successively triggering a virtual machine shutdown event and a virtual machine stopped event, and the virtual machine suspension state is triggered by successively triggering a virtual machine suspension time and a virtual machine stopped time.
[0047] In this embodiment, the suspended state of the virtual machine is a paused state of the virtual machine, and the corresponding states of the virtual machine being stopped and started include a shutdown state of the virtual machine and a stopped state caused by the suspension of the virtual machine.
[0048] In this embodiment, through the above method, it can be determined whether the virtual machine is stopped normally, such as stopped due to normal shutdown, or stopped abnormally, such as stopped due to power failure or other circumstances.
[0049] In this embodiment, one implementation of step 104 is as follows:
[0050] Step 122: continuously divide the file of the virtual machine disk to obtain continuous blocks of specific bytes;
[0051] Step 124: assemble the continuous blocks of specific bytes into a Merkle tree, wherein the Merkle tree includes a child node, a parent node, and a root node, and the child node is the continuous block;
[0052] Step 126: Calculate the hash value of the virtual machine disk at the current moment according to the Merkle tree and the compression function. In this embodiment, the Merkle tree has a first subtree and a second subtree. The first subtree includes the previous The second subtree contains continuous blocks of bytes, and the second subtree contains continuous blocks of remaining bytes, where m is the total number of specific bytes, n is the total number of bytes of the file of the virtual machine disk, and nPm.
[0053] In this embodiment, m is the total number of bytes of consecutive blocks, that is, m is 1024. n is the total number of bytes of the file of the virtual machine disk, that is, the cumulative sum of bytes of each consecutive block.
[0054] In this embodiment, according to the specific requirements of the blake3 hash algorithm, the file of the virtual machine disk is divided into 1024-byte continuous blocks. If the last continuous block is less than 1024 bytes, it is also a valid continuous block.
[0055] In the above manner, the continuous blocks obtained by division are organized into a Merkle tree, and all the continuous blocks are located at the child nodes of the Merkle tree from left to right.
[0056] In this embodiment, the first subtree contains the front part of the disk file. Bytes, the second subtree contains the remaining bytes. Taking 4 consecutive blocks as an example, namely c0, c1, c2, and c4, the first subtree contains c0 and c1 child nodes, and the second subtree contains c2 and c4 child nodes. The c0 and c1 child nodes have a first parent node, and the c2 and c4 child nodes have a second parent node. The first parent node and the second parent node have a root node.
[0057] In this embodiment, one implementation of step 126 is as follows:
[0058] Step 132: Calculate the hash value of each child node by using the compression function;
[0059] Step 134: Calculate the hash value of the parent node corresponding to the child node according to the hash value of each child node;
[0060] Step 136: Calculate the hash value of the virtual machine disk at the current moment according to the hash value of each parent node.
[0061] In this embodiment, the compression function takes the initial hash value of the child node as input, and updates the hash value of the child node in an iterative manner to obtain the iteratively updated hash value of the virtual machine disk.
[0062] In this embodiment, the hash values corresponding to the child nodes, parent nodes and root nodes are defined as the persistent state vector. The initial persistent state vector, continuous blocks, the number of compressed bytes and an indicator of whether it is the last round of compression are used as input. The Mix function is iterated to iterate and update the little-endian 32 bytes of the persistent state vector of the root node, that is, the hash value of the virtual machine disk at the current moment.
[0063] In this embodiment, one implementation of step 108 is as follows:
[0064] Step 142: determine whether the hash value of the virtual machine disk at the current moment is consistent with the hash value of the virtual machine disk at the previous moment, when the current moment is the virtual machine startup moment, the previous moment is the virtual machine stop moment or the virtual machine snapshot moment, when the current moment is the disk binding moment, the previous moment is the virtual machine disk unplug moment;
[0065] Step 144: If they are consistent, start the virtual machine or bind the virtual machine disk.
[0066] In this embodiment, when creating a virtual machine disk, the virtual machine disk hash value is calculated, and metadata of the virtual machine disk volume can be created after the calculation.
[0067] In this embodiment, when the virtual machine is suspended, the virtual machine disk hash value is calculated, and when the virtual machine is started, the virtual machine disk hash value is calculated. By comparing whether the virtual machine disk hash values at the above two times are consistent, it is determined whether the virtual machine disk has integrity in the above time period. If so, the virtual machine is started.
[0068] In this embodiment, the virtual machine disk hash value is calculated before the virtual machine disk is unplugged, and the virtual machine disk hash value is calculated before the virtual machine disk is bound. It is determined whether the virtual machine disk hash values at the above two times are consistent, and whether the virtual machine disk has integrity in the above time period. If so, the virtual machine disk is bound.
[0069] In this embodiment, when creating a virtual machine snapshot, the hash value of the parent file of the snapshot file is calculated, and all disks mounted on the virtual machine are traversed. When the virtual machine is restored to a certain historical snapshot moment, the hash value of the virtual machine disk is calculated to determine whether the virtual machine disk has integrity during the above time period. If so, the virtual machine is restored to a certain historical snapshot moment.
[0070] In this embodiment, the above-mentioned virtual machine snapshot specifically records the state of the virtual machine disk and the stored data or content at a time point. When the virtual machine disk needs to be restored to a certain historical time point, the virtual machine can be restored to the state at the above historical time point based on the virtual machine disk state and stored data or content corresponding to the above historical time point.
[0071] Please refer to Figure 7 Another embodiment of the present specification provides a system for quickly verifying the integrity of a virtual machine disk, mainly comprising:
[0072] A first determination module 202 is used to determine a calculation timing and a verification timing of a virtual machine disk hash value according to a construction and startup process of the virtual machine disk;
[0073] The calculation module 204 is used to calculate the virtual machine disk hash value at the current moment by segmenting the virtual machine disk file and the compression function at the calculation timing point and the verification timing point, and the virtual machine disk hash value has a unique corresponding relationship with the content of the virtual machine disk;
[0074] Verification module 206, used to obtain verification results by comparing the hash value of the virtual machine disk at the current moment with the hash value of the virtual machine disk at the previous moment when the virtual machine disk is in a corresponding state, wherein the virtual machine disk being in a corresponding state means that the state of the virtual machine at the previous moment and the state of the virtual machine at the current moment have a corresponding relationship;
[0075] The execution module 208 is used to determine whether to start the virtual machine or create the virtual machine disk according to the verification result.
[0076] Through the above method, the control platform (i.e., the control platform of the virtual machine) can modify the data or content in the virtual machine disk at a specific time point, and the behavior of modifying the data or content in the virtual machine disk at other time points is the behavior of tampering with the data, so that the integrity of the virtual machine disk can be effectively determined, that is, when the data or content in the virtual machine disk is tampered, it is determined that the virtual machine disk does not have integrity, thereby achieving the effect of accurately monitoring the tampering time period. Moreover, the above method of splitting the virtual machine disk file can effectively improve the efficiency of the above virtual machine disk hash value calculation, and can also accurately locate the specific location where the virtual machine disk is tampered.
[0077] In this embodiment, the first determination module 202 is used to determine the time of creating a virtual machine disk, the time of suspending a virtual machine disk, the time of stopping a virtual machine disk, the time of unplugging a virtual machine disk, and the time of snapshotting a virtual machine as the calculation time point of the virtual machine disk hash value according to the construction and startup process of the virtual machine disk. In this way, it is possible to determine whether the virtual machine is stopped normally, such as a stop caused by a normal shutdown, or abnormally stopped, such as a stop caused by a power failure or other circumstances.
[0078] In this embodiment, the calculation module 204 is used to continuously divide the file of the virtual machine disk to obtain continuous blocks of specific bytes; the continuous blocks of specific bytes are organized into a Merkle tree, the Merkle tree includes child nodes, parent nodes and root nodes, and the child nodes are the continuous blocks; according to the Merkle tree, through the compression function, the hash value of the virtual machine disk at the current moment is calculated. Through the compression function, the hash value of each child node is calculated; according to the hash value of each child node, the hash value of the parent node corresponding to the child node is calculated; according to the hash value of each parent node, the hash value of the virtual machine disk at the current moment is calculated. Through the above, the hash value of the virtual machine disk can be quickly calculated.
[0079] In this embodiment, the verification module 206 is used to determine whether the hash value of the virtual machine disk at the current moment is consistent with the hash value of the virtual machine disk at the previous moment, when the current moment is the virtual machine startup moment, the previous moment is the virtual machine stop moment or the virtual machine snapshot moment, when the current moment is the disk binding moment, the previous moment is the virtual machine disk unplug moment; if they are consistent, the virtual machine is started or the virtual machine disk is bound. The above method can effectively improve the efficiency of verifying the integrity of the virtual machine disk.
[0080] Based on the same invention, another embodiment of the present specification further provides a computer-readable storage medium, wherein the computer-readable storage medium stores one or more programs, and when the one or more programs are executed by an electronic device including multiple application programs, the electronic device executes Figure 1 The corresponding embodiment provides a method for quickly verifying the integrity of a virtual machine disk.
[0081] In this specification, each embodiment is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0082] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0083] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, this specification may be in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, this specification may be in the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0084] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that has the function specified in a box.
[0085] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0086] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0087] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0088] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0089] The above is only an embodiment of the present application and is not intended to limit this specification. For those skilled in the art, this specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification should be included in the scope of the claims of this specification.
Claims
1. A method for quickly verifying the integrity of a virtual machine disk, characterized in that: include: According to the construction and startup process of the virtual machine disk, determine the calculation time and verification time of the virtual machine disk hash value; At the calculation timing point and the verification timing point, by segmenting the virtual machine disk file and the compression function, a hash value of the virtual machine disk at the current moment is calculated, and the hash value of the virtual machine disk has a unique corresponding relationship with the content of the virtual machine disk; When the virtual machine disk is in a corresponding state, the verification result is obtained by comparing the virtual machine disk hash value at the current moment with the virtual machine disk hash value at the previous moment, wherein the virtual machine disk is in a corresponding state means that the state of the virtual machine at the previous moment and the state of the virtual machine at the current moment have a corresponding relationship; According to the verification result, it is determined whether to start the virtual machine or whether to create the virtual machine disk.
2. The method for quickly verifying the integrity of a virtual machine disk according to claim 1, characterized in that: The step of determining the calculation timing and verification timing of the virtual machine disk hash value according to the virtual machine disk construction and startup process includes: According to the construction and startup process of the virtual machine disk, the time of creating the virtual machine disk, the time of suspending the virtual machine disk, the time of stopping the virtual machine disk, the time of unplugging the virtual machine disk, and the time of snapshotting the virtual machine are determined as the calculation time points of the virtual machine disk hash value.
3. The method for quickly verifying the integrity of a virtual machine disk according to claim 2, characterized in that: The virtual machine disk being in a corresponding state means that the virtual machine is in a corresponding state of stopping and starting, a corresponding state of pulling out a disk and binding a disk, and a corresponding state of a virtual machine snapshot and a virtual machine startup.
4. The method for quickly verifying the integrity of a virtual machine disk according to claim 1, characterized in that: The step of calculating the hash value of the virtual machine disk at the current moment by segmenting the virtual machine disk file and the compression function at the calculation timing point and the verification timing point includes: Continuously divide the files of the virtual machine disk to obtain continuous blocks of specific bytes; Organizing continuous blocks of specific bytes into a Merkle tree, wherein the Merkle tree includes a child node, a parent node, and a root node, wherein the child node is the continuous block; According to the Merkle tree, the hash value of the virtual machine disk at the current moment is calculated through the compression function.
5. The method for quickly verifying the integrity of a virtual machine disk according to claim 4, characterized in that: The Merkle tree has a first subtree and a second subtree, wherein the first subtree includes the The second subtree contains continuous blocks of bytes, and the second subtree contains continuous blocks of remaining bytes, wherein m is the total number of specific bytes, n is the total number of bytes of the file of the virtual machine disk, and n>m.
6. The method for quickly verifying the integrity of a virtual machine disk according to claim 4, characterized in that: The step of calculating the hash value of the virtual machine disk at the current moment according to the Merkle tree and through the compression function includes: Calculate the hash value of each of the child nodes by using the compression function; According to the hash value of each child node, calculate the hash value of the parent node corresponding to the child node; According to the hash value of each parent node, the hash value of the virtual machine disk at the current moment is calculated.
7. The method for quickly verifying the integrity of a virtual machine disk according to claim 6, characterized in that: The compression function takes the initial hash value of the child node as input, and updates the hash value of the child node in an iterative manner to obtain the iteratively updated virtual machine disk hash value.
8. The method for quickly verifying the integrity of a virtual machine disk according to claim 1, characterized in that: The storage format of the files in the virtual machine disk is qcow2 format.
9. The method for quickly verifying the integrity of a virtual machine disk according to claim 3, characterized in that: The step of determining whether to start the virtual machine or create the virtual machine disk according to the verification result includes: Determine whether the hash value of the virtual machine disk at the current moment is consistent with the hash value of the virtual machine disk at the previous moment, when the current moment is the virtual machine startup moment, the previous moment is the virtual machine stop moment or the virtual machine snapshot moment, when the current moment is the disk binding moment, the previous moment is the virtual machine disk unplug moment; If they are consistent, start the virtual machine or bind the virtual machine disk.
10. A system for quickly verifying the integrity of a virtual machine disk, characterized in that: include: A first determination module is used to determine a calculation timing point and a verification timing point of a virtual machine disk hash value according to a construction and startup process of the virtual machine disk; A calculation module, used for calculating the hash value of the virtual machine disk at the current moment by segmenting the virtual machine disk file and the compression function at the calculation time point and the verification time point, wherein the hash value of the virtual machine disk has a unique corresponding relationship with the content of the virtual machine disk; A verification module, used to obtain a verification result by comparing a hash value of the virtual machine disk at a current moment with a hash value of the virtual machine disk at a previous moment when the virtual machine disk is in a corresponding state, wherein the virtual machine disk being in a corresponding state means that the state of the virtual machine at a previous moment has a corresponding relationship with the state of the virtual machine at a current moment; An execution module is used to determine whether to start the virtual machine or create the virtual machine disk according to the verification result.