Method for guaranteeing integrity of virtualization platform
By using hash value calculation and encryption storage methods during the engine installation and startup of the virtualization management platform, generating and backing up summary files, and performing integrity verification at startup, locking the rpm version of the core component package, the problems of virtualization platform integrity and security are solved, ensuring the integrity and functional stability of the virtualization platform.
Patent Information
- Application Number
- CN202411946657.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-05-09
AI Technical Summary
How to ensure the integrity of the virtualization platform, prevent the virtualization platform from being tampered with, and improve the security and reliability of the software.
During the installation and startup of the virtualization management platform, the summary file is generated and backed up by hash calculation and encrypting storage to ensure the integrity of the configuration file and perform integrity verification upon startup; at the same time, the rpm version of the core component package is locked to prevent version changes.
It effectively ensures that the core configuration files of the virtualization management platform are not tampered with, ensures the integrity of the virtualization platform startup process, and ensures the operational integrity and functional integrity of the virtualization platform by locking the rpm version of the core component package.
Smart Images

Figure CN119960904A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network virtualization, and in particular to a method for ensuring the integrity of a virtualization platform. Background Art
[0002] Virtualization is a resource management technology that abstracts system resources (CPU, memory, etc.) into shared resources and decouples physical hardware and operating systems. Virtualization technology allows multiple operating systems to run on a host system, allowing each operating system to run different applications independently; these operating systems can obtain resources from the host resource pool to maximize resource utilization.
[0003] Virtualization technology is the foundation of cloud computing and has a wide range of applications in cloud computing. For example, through server virtualization, cloud service providers can provide scalable and elastic computing resources, allowing users to rent these resources according to demand; through network virtualization resources, virtual networks with customized configurations can be created; through storage virtualization, storage resources can be abstracted from physical hardware, allowing more flexible and efficient data management, and by centrally managing storage resources from multiple devices, it can simplify storage allocation and expansion.
[0004] The hypervisor is a virtualization layer between the virtual machine and the underlying hardware device. The hypervisor can run directly on the hardware device to abstract the hardware resources and provide the upper-level virtual machine with the resources required for the operating environment, so that each virtual machine does not interfere with each other and runs independently in the same system.
[0005] Virtualization platform is used to create, manage and optimize virtualized environment, and is located between virtual machines and underlying hardware devices. Based on Hypervisor, virtualization platform can provide user visual interface and automation tools to simplify the creation, deployment, monitoring and maintenance of virtual machines, as well as resource management; the current mainstream virtualization platforms include KVM, XEN, VMWARE, etc.
[0006] The introduction of virtualization technology can bring benefits such as cost savings, improved resource utilization, flexibility, scalability, and isolation, but it also introduces problems such as complexity and security. Therefore, when introducing virtualization technology, it is also necessary to ensure the integrity of the virtualization platform, prevent the virtualization platform from being tampered with, and improve the security and reliability of the software. Summary of the invention
[0007] The purpose of this application is to address the problem of how to ensure the integrity of a virtualization platform and prevent the virtualization platform from being tampered with. This application provides a method for ensuring the integrity of a virtualization platform.
[0008] In order to achieve the above objectives, this application adopts the following technical solutions:
[0009] A method for ensuring the integrity of a virtualization platform includes performing the following steps during the installation and startup of a management platform engine:
[0010] During the installation of the engine, the configuration file generated by the engine is hashed by adding random factors and confusing the number of iterations, and a summary file is generated and stored encrypted.
[0011] When the engine is started, the integrity of the configuration file generated by the engine is verified; after the integrity verification is successful, the service is started.
[0012] Furthermore, during the installation of the engine, the hash value calculation of the configuration file content generated by the engine includes the following:
[0013] Read the contents of the configuration file generated by the engine;
[0014] Determine the current number of iterations N′ and perform hash calculation based on the random factor salt;
[0015] When the current number of iterations N′ is greater than 1, the configuration file content is hashed; wherein, each time the configuration file content is hashed, the value of the current number of iterations N′ is reduced by 1; when the configuration file content is hashed for the first time, the value of the current number of iterations N′ is the same as the value of the preset number of iterations N;
[0016] When the current number of iterations N′ is less than 1, a hash value is output, and the output hash value and the random factor salt corresponding to the hash value are stored.
[0017] Furthermore, a summary file is generated after a hash value calculation is performed on the content of the configuration file generated by the engine, the summary file is encrypted, stored and backed up, and the configuration file generated by the engine is backed up and the hash value is updated regularly.
[0018] Furthermore, during the installation and startup of the computing node, the following steps are performed:
[0019] When the engine manages the node, the hash value of the configuration file generated by the node is calculated, a summary file is generated and encrypted for storage;
[0020] When the node starts, the integrity of the content in the summary file is verified; after the integrity verification is successful, the service is started.
[0021] Furthermore, when the node is started, if the integrity check of the summary file content fails, the service refuses to start, and the node's status in the engine platform is unavailable.
[0022] Furthermore, when the engine manages the node, the generated summary file is encrypted, stored and backed up; at the same time, the interactive certificate file is added to the summary file after hash calculation.
[0023] Furthermore, the hash algorithm in the node process is the same as the hash algorithm in the engine process.
[0024] Furthermore, it also includes locking the rpm version of the core component package involved in the engine.
[0025] Furthermore, when locking the rpm version of the core component package involved in the engine, the following contents are included:
[0026] Specify the rpm version of the core component package through the versionlock.list list generated in the engine process;
[0027] The rpm version of the core component package is collected regularly and verified; when the rpm version of the core component package changes, the node status is unavailable.
[0028] Furthermore, the rpm version of the core component package is locked through the plug-in yum-versionlock.
[0029] Beneficial effects of this application
[0030] The present application provides a method for ensuring the integrity of a virtualization platform. During the installation of an engine, a highly secure hash algorithm is used. By adding random factors and confusing the number of iterations, the content of the configuration file generated by the engine is hashed to generate a summary file and encrypt it for storage, which can ensure that the core configuration file of the virtualization management platform is not tampered with. When the engine is started, the integrity of the content of the configuration file generated by the engine is checked; after the integrity check is successful, the service is started; if the check fails, the service refuses to start; the integrity of the startup process of the virtualization management platform is ensured.
[0031] In summary, the method for ensuring the integrity of the virtualization platform provided in the present application can ensure the integrity of the virtualization platform by ensuring that the core configuration files of the virtualization management platform are not tampered with and by ensuring the integrity of the startup process of the virtualization management platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0033] Figure 1 This is a diagram of the engine installation process.
[0034] Figure 2 This is a flowchart of how the engine manages nodes.
[0035] Figure 3 Schematic diagram of the hash calculation process.
[0036] Figure 4 Diagram of the checksum.service service setup.
[0037] Figure 5 A schematic diagram of the verification process. DETAILED DESCRIPTION
[0038] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present application. At the same time, in the description of the embodiments of the present application, the terms "first", "second", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more features. In the description of the embodiments of the present application, the meaning of "multiple" is two or more, unless otherwise clearly and specifically defined.
[0039] In order to solve the problem of how to ensure the integrity of the virtualization platform and prevent the virtualization platform from being tampered with, this embodiment provides a method for ensuring the integrity of the virtualization platform. Data integrity verification and encrypted storage backup methods are adopted in the engine service and the node service respectively, so as to ensure that the core configuration files of the virtualization platform are not tampered with and ensure the integrity of the startup process of the virtualization platform. By locking the rpm version of the core component package, the stable operation of the core functions of the virtualization component is guaranteed during the operation process and other system maintenance processes, thereby ensuring the operation integrity and functional integrity of the virtualization platform.
[0040] like Figures 1 to 5As shown, a method for ensuring the integrity of a virtualization platform provided in this embodiment includes performing the following steps during the installation and startup of a management platform engine:
[0041] During the installation of the engine, a random factor is added and the number of iterations is obfuscated to calculate the hash value of the configuration file generated by the engine, generate a summary file, and store it in encrypted form.
[0042] Specifically, in the process of generating core configuration files for engine, you can create database configuration files, database access control files, database certificate files, engine configuration files, rpm version list versionslock.list, httpd configuration files, Jboss configuration files, CA certificates, etc.
[0043] When the engine is started, the integrity of the configuration file generated by the engine is verified; after the integrity verification is successful, the service is started.
[0044] The method for ensuring the integrity of the virtualization platform provided in this embodiment uses a highly secure hash algorithm during the installation process of the engine. By adding random factors and confusing the number of iterations, the hash value of the configuration file content generated by the engine is calculated to generate a summary file and encrypt and store it, which can ensure that the core configuration file of the virtualization management platform is not tampered with. When the engine is started, the integrity of the configuration file content generated by the engine is checked; after the integrity check is successful, the service is started; if the check fails, the service refuses to start, thereby ensuring the integrity of the startup process of the virtualization management platform.
[0045] That is, the method for ensuring the integrity of the virtualization platform provided in this embodiment ensures the integrity of the virtualization platform by ensuring that the core configuration file of the virtualization management platform is not tampered with and by ensuring the integrity of the startup process of the virtualization management platform.
[0046] Preferably, if Figure 3 As shown, during the installation of the engine, when calculating the hash value of the configuration file content generated by the engine, the following contents can be included:
[0047] Read the contents of the configuration file generated by the engine;
[0048] Determine the current number of iterations N′ and perform hash calculation based on the random factor salt;
[0049] When the current number of iterations N′ is greater than 1, the configuration file content is hashed; wherein, each time the configuration file content is hashed, the value of the current number of iterations N′ is reduced by 1; when the configuration file content is hashed for the first time, the value of the current number of iterations N′ is the same as the value of the preset number of iterations N;
[0050] When the current number of iterations N′ is less than 1, a hash value is output, and the output hash value and the random factor salt corresponding to the hash value are stored.
[0051] It should be understood that the preset number of iterations N should be greater than 1.
[0052] Further preferably, the hash algorithm in this embodiment may be a SHA-256 algorithm, and its workflow may include the following:
[0053] First, initialize the hash value. The initialization hash value may be composed of 8 32-bit registers, each of which is assigned a specific initial value δ; wherein the specific initial value δ is a prime number. More preferably, the specific initial value δ is a small prime number, such as 2, 3, 5, 7, 11, 13, 17, 19.
[0054] Secondly, fill the bit length of the original message to get the input message. Specifically, fill the length K on the bit length L of the original message, and ensure that the remainder after L+1+K modulo 512 is 448; then add a 64-bit length field to get the input message.
[0055] Then, split the message blocks. Split the input message into 512-bit message blocks.
[0056] Finally, determine the hash value of the input message. The final hash value of the input message is determined by calculating the hash values of all message blocks separately. The final hash value is a fixed-length digital string, usually expressed as a hexadecimal number.
[0057] Furthermore, the configuration files involved in the engine are hashed to generate a summary file, which is encrypted, stored and backed up; at the same time, the configuration files involved in the engine are backed up regularly and the hash values are updated. After the integrity is compromised, the administrator can restore the system based on the backup files.
[0058] In order to further ensure the integrity of the virtualization platform, a method for ensuring the integrity of the virtualization platform provided in this embodiment further includes performing the following steps during the installation and startup of the computing node node:
[0059] When the engine manages the node, the configuration file generated by the node is hashed, a summary file is generated, and encrypted, stored, and backed up. At the same time, the interactive certificate file is hashed and added to the summary file.
[0060] In this embodiment, in the core configuration file generated by the engine managing the node, a node configuration file, a libvirt configuration file, a qemu configuration file, a qemu certificate, libvirt user authentication information, etc. are created.
[0061] When the node starts, the integrity of the content in the summary file is verified; after the integrity verification is successful, the service is started.
[0062] The method for ensuring the integrity of the virtualization platform provided in this embodiment uses a highly secure hash algorithm when the engine manages the node, calculates the hash value of the configuration file content generated by the node, generates a summary file, and encrypts and stores and backs it up, thereby ensuring that the core configuration file of the node is not tampered with. Preferably, the hash algorithm in the node process can be the same as the hash algorithm in the engine process. When the node is started, the integrity of the summary file content is checked; after the integrity check is successful, the service is started; if the check fails, the service refuses to start, and the node's status in the engine platform is also unavailable; thereby ensuring the integrity of the node startup process. In addition, after the integrity is compromised, the administrator can restore the system based on the backup file.
[0063] The method for ensuring the integrity of the virtualization platform provided in this embodiment is based on the integrity verification of the core configuration file generated by the engine and the summary file generated by the node, so as to achieve tamper-proofing of the configuration file and ensure the integrity of the virtualization platform.
[0064] In order to further ensure the integrity of the virtualization platform, a method for ensuring the integrity of the virtualization platform provided in this embodiment also includes the step of locking the core component package version to ensure the stable operation of the core functions of the virtualization component during operation and other system maintenance processes, thereby ensuring the operational integrity and functional integrity of the virtualization platform.
[0065] The steps to lock the core component package version include the following:
[0066] Lock the rpm version of the core component package involved in the engine. Since a versionlock.list list will be generated when the engine and node are installed. Therefore, this embodiment can specify the rpm version of the core component package through the versionlock.list list to prevent users from updating the rpm version of a specific core component package and destroying the stability of the engine. At the same time, the engine can regularly collect the rpm version of the node core component package and verify the rpm version of the node core component package. Once the rpm version of the node core component package is found to have changed, the node status will be set to unavailable.
[0067] Preferably, in this embodiment, the plug-in yum-versionlock can be used to lock the rpm version of a specific core component package, and the rpm version of a specific core component package can be prevented from being updated by creating an exclusion list. When yum-versionlock is used to lock the rpm version of a core component package, all other versions of the rpm version of the core component package will be excluded, and even if a new version of the rpm version of the core component package is available, it will not be installed. During the engine installation process, the manifest file versionslock.list required by yum-versionlock will be generated, and the rpm version of the core component package will be specified through the versionlock.list manifest. Specifically, a versionlock manifest will be generated after the engine installation is complete to perform version protection on core components such as qemu, kvm, and libvirt.
[0068] The engine relies on components to operate virtualized resources. This embodiment prevents the problem of affecting the engine compatibility due to the upgrade of these rpm packages caused by other system upgrades by locking the core component versions.
[0069] In the method for ensuring the integrity of the virtualization platform provided in this embodiment, integrity verification steps are provided in the startup of the engine service and the node service to prevent the configuration file from being tampered with and ensure the integrity of the virtualization platform.
[0070] Specifically, Figure 4 As shown, for the startup of the engine service and the node service, the checksum.service service can be set, that is, each time the engine service and the node service are started, they need to rely on the execution result of the checksum.service. Among them, the checksum.service service is used to verify the verification file and regularly maintain the backup and update of the verification file.
[0071] Figure 5 The entire engine and node verification process is shown; and Figure 5 In the view shown, this embodiment also shows the rpm version verification process of the core component package.
[0072] That is, the method for ensuring the integrity of the virtualization platform provided in this embodiment includes three verification contents: integrity verification of the configuration file content in the engine process, integrity verification of the summary file content in the node process, and rpm version verification of the core component package; among them, the integrity verification and version verification are verified using the interface provided by checksum.service.
[0073] The method for ensuring the integrity of the virtualization platform provided in this embodiment adopts data integrity verification and encrypted storage backup methods in the engine service and the node service respectively, thereby ensuring that the core configuration files of the virtualization platform are not tampered with, and ensuring the integrity of the virtualization platform startup process; by locking the rpm version of the core component package, the stable operation of the core functions of the virtualization component is guaranteed during the operation process and other system maintenance processes, thereby ensuring the operation integrity and functional integrity of the virtualization platform.
[0074] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referenced to each other. Each embodiment focuses on the differences between it and other embodiments.
[0075] The above is a description of a specific embodiment of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the specific order or sequential order shown in the process depicted in the drawings is not necessarily required to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0076] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A method for ensuring the integrity of a virtualization platform, characterized in that: During the installation and startup of the management platform engine, perform the following steps: During the installation of the engine, the configuration file generated by the engine is hashed by adding random factors and confusing the number of iterations, and a summary file is generated and stored encrypted. When the engine is started, the integrity of the configuration file generated by the engine is verified; after the integrity verification is successful, the service is started.
2. The method for ensuring the integrity of a virtualization platform according to claim 1, characterized in that: During the installation of the engine, the hash value calculation of the configuration file content generated by the engine includes the following: Read the contents of the configuration file generated by the engine; Determine the current number of iterations N′ and perform hash calculation based on the random factor salt; When the current number of iterations N′ is greater than 1, the configuration file content is hashed; wherein, each time the configuration file content is hashed, the value of the current number of iterations N′ is reduced by 1; when the configuration file content is hashed for the first time, the value of the current number of iterations N′ is the same as the value of the preset number of iterations N; When the current number of iterations N′ is less than 1, a hash value is output, and the output hash value and the random factor salt corresponding to the hash value are stored.
3. The method for ensuring the integrity of a virtualization platform according to claim 1, characterized in that: The content of the configuration file generated by the engine is hashed to generate a summary file, which is encrypted, stored and backed up. The configuration file generated by the engine is backed up and the hash value is updated regularly.
4. The method for ensuring the integrity of a virtualization platform according to any one of claims 1 to 3, characterized in that: It also includes the following steps during the installation and startup of the computing node: When the engine manages the node, the hash value of the configuration file generated by the node is calculated, a summary file is generated and encrypted for storage; When the node starts, verify the integrity of the content in the summary file; After the integrity check succeeds, start the service.
5. The method for ensuring the integrity of a virtualization platform according to claim 4, characterized in that: When the node is started, if the integrity check of the summary file content fails, the service refuses to start, and the node status in the engine platform is unavailable.
6. The method for ensuring the integrity of a virtualization platform according to claim 4, characterized in that: When the engine manages the node, the generated summary file is encrypted, stored, and backed up; at the same time, the interactive certificate file is added to the summary file after hash calculation.
7. The method for ensuring the integrity of a virtualization platform according to claim 4, characterized in that: The hash algorithm in the node process is the same as the hash algorithm in the engine process.
8. The method for ensuring the integrity of a virtualization platform according to any one of claims 5 to 7, characterized in that: It also includes the rpm versions of the core component packages involved in locking the engine.
9. The method for ensuring the integrity of a virtualization platform according to claim 8, characterized in that: When locking the rpm version of the core component package involved in the engine, the following contents are included: Specify the rpm version of the core component package through the versionlock.list list generated in the engine process; The rpm version of the core component package is collected regularly and verified; when the rpm version of the core component package changes, the node status is unavailable.
10. The method for ensuring the integrity of a virtualization platform according to claim 9, characterized in that: Use the yum-versionlock plugin to lock the rpm version of the core component package.