Virtual machine control method and device based on quantum key and storage medium

By using quantum keys to perform digital signature verification in virtual machine control, the problem of traditional keys being easily stolen and cracked is solved, and the security and reliability of the virtual machine are improved.

CN120074807APending Publication Date: 2025-05-30DIANKEYUN (BEIJING) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311620976.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the existing virtual machine control methods, the keys are easily stolen and cracked, resulting in low security and reliability of the virtual machine.

Method used

The virtual machine control method based on quantum key is adopted. By obtaining the virtual machine control request, the corresponding quantum key is determined, and the signature of the target virtual machine is digitally signed to ensure that the virtual machine is created or turned on when the verification is passed.

Benefits of technology

Using the non-theft and incrackable characteristics of quantum keys, the security and reliability of virtual machines are improved, potential risks are reduced, and key security is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074807A_ABST
    Figure CN120074807A_ABST
Patent Text Reader

Abstract

The invention provides a virtual machine control method and device based on a quantum key and a storage medium. The method comprises the steps of obtaining a virtual machine control request corresponding to a target virtual machine; the virtual machine control request comprises a virtual machine creation request or a virtual machine starting request; determining a quantum key corresponding to the virtual machine control request; the quantum keys comprise a first quantum key corresponding to the virtual machine creation request and a second quantum key corresponding to the virtual machine opening request; performing digital signature verification on the signature of the target virtual machine through the quantum key to obtain a verification result; the signature of the target virtual machine comprises a virtual machine mirror image file signature and a virtual machine file signature; under the condition that the verification result is passed, creating or starting a target virtual machine according to the instruction of the virtual machine control request; the problem that a virtual machine is low in safety and reliability can be solved. Potential risks can be reduced, the security of the secret key is ensured, and the security and reliability of the virtual machine are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to a virtual machine control method, device, and storage medium based on quantum keys. Background Art

[0002] With the rapid development of cloud computing, more and more enterprises are running and expanding their businesses by using cloud platforms. Consequently, the security issues of cloud platforms have attracted more and more attention. To ensure the business security of these enterprises, it is necessary to guarantee business security through the trusted control of virtual machines.

[0003] Currently, traditional virtual machine control methods include: generating key pairs, including public keys and private keys, through software or encryption cards; associating the public key with the virtual machine during the virtual machine creation process; and after the virtual machine is created, using the private key to start the virtual machine.

[0004] However, since the keys generated by software or encryption cards are easily stolen and cracked, the security of the keys themselves is an important link in virtual machine control. If the private key is leaked, an attacker can use this private key to access the virtual machine and its associated resources, resulting in problems of low security and reliability of the virtual machine. Summary of the Invention

[0005] In view of this, embodiments of the present invention provide a virtual machine control method, device, and storage medium based on quantum keys to eliminate or improve one or more defects existing in the prior art. It can solve the problem of low security and reliability of virtual machines.

[0006] One aspect of the present invention provides a virtual machine control method based on quantum keys, and the method includes the following steps:

[0007] Obtain a virtual machine control request corresponding to a target virtual machine; the virtual machine control request includes a virtual machine creation request or a virtual machine start request;

[0008] Determine a quantum key corresponding to the virtual machine control request; the quantum key includes a first quantum key corresponding to the virtual machine creation request and a second quantum key corresponding to the virtual machine start request;

[0009] Perform digital signature verification on the signature of the target virtual machine through the quantum key to obtain a verification result; the signature of the target virtual machine includes a virtual machine image file signature and a virtual machine file signature;

[0010] When the verification result passes, create or start the target virtual machine according to the indication of the virtual machine control request.

[0011] Optionally, when the virtual machine control request is a virtual machine creation request, perform digital signature verification on the signature of the target virtual machine using a quantum key to obtain a verification result, including:

[0012] Obtain the virtual machine image file corresponding to the target virtual machine from the image source; the virtual machine image file includes a virtual machine image file signature.

[0013] Perform signature verification on the virtual machine image file signature using the first quantum key to obtain a verification result.

[0014] Optionally, before obtaining the signed image file corresponding to the target virtual machine from the image source, further include:

[0015] Generate the first quantum key;

[0016] Perform digital signature on the virtual machine image file using the first quantum key to obtain a virtual machine image file signature; the virtual machine image file signature is stored in the metadata of the virtual machine image file.

[0017] Optionally, when the virtual machine control request is a virtual machine start request, before determining the quantum key corresponding to the virtual machine control request, further include:

[0018] Generate the second quantum key;

[0019] During the shutdown process of the target virtual machine, obtain the virtual machine file corresponding to the target virtual machine;

[0020] Perform digital signature on the virtual machine file using the second quantum key to obtain a virtual machine file signature; the virtual machine file signature is stored in the metadata of the virtual machine.

[0021] Optionally, perform digital signature verification on the signature of the target virtual machine using a quantum key to obtain a verification result, including:

[0022] Obtain the virtual machine file signature;

[0023] Perform signature verification on the virtual machine file signature using the second quantum key.

[0024] Optionally, before determining the quantum key corresponding to the virtual machine control request, further include:

[0025] Determine whether the quantum key is deactivated;

[0026] In the case where the quantum key is deactivated, end the virtual machine control request.

[0027] Optionally, determining the quantum key corresponding to the virtual machine control request includes:

[0028] Obtain the quantum key identifier corresponding to the quantum key;

[0029] Access the quantum key through the quantum key identifier.

[0030] Optionally, the virtual machine image files used by different target virtual machines are the same or different; the first quantum keys corresponding to different virtual machine image files are different; the second quantum keys used by different target virtual machines are the same.

[0031] Another aspect of the present invention provides a virtual machine control device based on a quantum key, including a processor and a memory. Computer instructions are stored in the memory, and the processor is configured to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the device implements the steps of the above-mentioned virtual machine control method based on a quantum key.

[0032] Another aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the steps of the above-mentioned virtual machine control method based on a quantum key are implemented.

[0033] For the virtual machine control method, device and storage medium based on a quantum key of the present invention, by obtaining a virtual machine control request corresponding to a target virtual machine; the virtual machine control request includes a virtual machine creation request or a virtual machine start request; determining the quantum key corresponding to the virtual machine control request; the quantum key includes a first quantum key corresponding to the virtual machine creation request and a second quantum key corresponding to the virtual machine start request; performing digital signature verification on the signature of the target virtual machine through the quantum key to obtain a verification result; the signature of the target virtual machine includes a virtual machine image file signature and a virtual machine file signature; when the verification result passes, creating or starting the target virtual machine according to the indication of the virtual machine control request; it can solve the problem of low security and reliability of virtual machines; during the process of creating a virtual machine, using the first quantum key for digital signature verification, and during the process of starting a virtual machine, using the second quantum key for digital signature verification, taking advantage of the characteristics of the quantum key itself that cannot be stolen or cracked, and combining the use of different quantum keys to control the creation and start of virtual machines, can reduce potential risks, ensure the security of the key, and improve the security and reliability of virtual machines.

[0034] Further, during the process of creating a target virtual machine, performing digital signature verification on the virtual machine image file required by the target virtual machine through the first quantum key can ensure the reliability of the virtual machine image file, thereby improving the reliability and security of the target virtual machine.

[0035] Further, during the process of starting a target virtual machine, performing digital signature verification on the virtual machine file of the target virtual machine through the second quantum key can prevent the virtual machine file from being tampered with, thereby further improving the reliability and security of the target virtual machine.

[0036] Furthermore, by prohibiting the quantum key module from disabling the quantum key to achieve the prohibition of controlling the virtual machine, the security of the service is guaranteed, and the security of the virtual machine can be further improved.

[0037] Additional advantages, objects, and features of the present invention will be partly set forth in the description which follows, and will partly become obvious to those of ordinary skill in the art upon examination of the following, or may be learned by practice of the present invention. The objects and other advantages of the present invention may be realized and attained by the structure particularly pointed out in the specification and the drawings.

[0038] Those skilled in the art will understand that the objects and advantages that can be achieved by the present invention are not limited to the above specifically described, and the above and other objects that the present invention can achieve will be more clearly understood from the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The drawings described herein are for further understanding of the present invention, form a part of this application, and do not limit the present invention.

[0040] Figure 1 It is a flowchart of a virtual machine control method based on a quantum key provided by an embodiment of the present invention;

[0041] Figure 2 It is a flowchart of a virtual machine control method based on a quantum key provided by an embodiment of the present invention;

[0042] Figure 3 It is a flowchart of a virtual machine control method based on a quantum key provided by an embodiment of the present invention;

[0043] Figure 4 It is a block diagram of a virtual machine control device based on a quantum key provided by an embodiment of the present invention;

[0044] Figure 5 It is a block diagram of a virtual machine control device based on a quantum key provided by another embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] To make the objects, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below in conjunction with the embodiments and the drawings. Here, the illustrative embodiments and descriptions thereof of the present invention are used to explain the present invention, but not to limit the present invention.

[0046] Here, it should also be noted that in order to avoid obscuring the present invention with unnecessary details, only the structures and / or processing steps closely related to the solution of the present invention are shown in the drawings, and other details less related to the present invention are omitted.

[0047] It should be emphasized that when the term "comprising / including" is used herein, it refers to the presence of features, elements, steps or components, but does not exclude the presence or addition of one or more other features, elements, steps or components.

[0048] Here, it should also be noted that if not otherwise specified, the term "connection" herein can not only refer to a direct connection, but also represent an indirect connection with an intermediate.

[0049] In the following, embodiments of the present invention will be described with reference to the accompanying drawings. In the drawings, the same reference numerals represent the same or similar components, or the same or similar steps.

[0050] The following provides a detailed introduction to the virtual machine control method based on quantum keys provided by the present application.

[0051] As Figure 1 shown, an embodiment of the present application provides a virtual machine control method based on quantum keys. The implementation of this method can rely on a computer program, which can run on computer devices such as smartphones, tablets, personal computers, or run on a server. This embodiment does not limit the running entity of this method. This method at least includes steps S101 to S104:

[0052] Step S101, obtain a virtual machine control request corresponding to the target virtual machine.

[0053] Among them, the virtual machine control request includes a virtual machine creation request or a virtual machine startup request. The virtual machine creation request refers to a request for creating a target virtual machine; the virtual machine startup request refers to a request for starting up the target virtual machine.

[0054] In this embodiment, the virtual machine control request is obtained through the Compute Service in the Cloud Platform. Through the Compute Service, users can create, manage and use virtual machine instances on the cloud platform, run application programs and process computing tasks.

[0055] Step S102, determine the quantum key corresponding to the virtual machine control request.

[0056] In this embodiment, the virtual machine control request includes a virtual machine creation request or a virtual machine startup request.

[0057] Correspondingly, the quantum key includes a first quantum key corresponding to the virtual machine creation request and a second quantum key corresponding to the virtual machine startup request. The quantum key utilizes the uncertainty and superposition principle of quantum mechanics to ensure that it cannot be stolen or cracked, thereby ensuring the security of the key. The present application can effectively guarantee the security of the service by combining the quantum key with the virtual machine file using the key management service.

[0058] When creating a target virtual machine, it is necessary to select a virtual machine image file as the basic environment of the target virtual machine. The virtual machine image file contains the installation files of the operating system and related configuration information.

[0059] In this embodiment, the first quantum key is used to verify the signature of the virtual machine image file of the target virtual machine. The virtual machine image files used by different target virtual machines may be the same or different; the first quantum keys used by different virtual machine image files are different.

[0060] For example: taking target virtual machine A and target virtual machine B as examples, when the virtual machine image file used by target virtual machine A is the same as the virtual machine image file used by target virtual machine B, the first quantum key used when creating target virtual machine A is the same as the first quantum key used when creating target virtual machine B; when the virtual machine image file used by target virtual machine A is different from the virtual machine image file used by target virtual machine B, the first quantum key used when creating target virtual machine A is different from the first quantum key used when creating target virtual machine B.

[0061] The second quantum key is used to verify the signature of the virtual machine file of the target virtual machine when the target virtual machine is started. The virtual machine files of different target virtual machines are different; the second quantum keys used by different target virtual machines are the same.

[0062] Before determining the quantum key corresponding to the virtual machine control request, it is also necessary to generate the quantum key first. In this embodiment, the cloud platform also includes a Key Management Service (KMS) and a Quantum Key Distribution (QKD) module. Among them, the key management service is used to call the quantum key module to generate a quantum key when receiving a key creation request. Each key management service is configured to access the quantum key module to enable it to access the quantum key module normally.

[0063] Among them, the key creation request includes a first quantum key request and a second quantum key request. During the deployment process of the cloud platform, the administrator controls the sending of the first quantum key creation request to the key management service, so that after receiving the first quantum key creation request, the key management service calls the quantum key module to generate and store the first quantum key, and the first quantum key corresponds to the virtual machine image file one by one; and, the administrator controls the sending of the second quantum key creation request to the key management service, and after receiving the second quantum key creation request, the key management service calls the quantum key module to generate the second quantum key.

[0064] In the case where the virtual machine control request is a virtual machine creation request, before obtaining the first quantum key, the administrator needs to upload the virtual machine image file used to create the target virtual machine to the image source, where the image source refers to a repository for storing or distributing virtual machine image files. Each computing service and the corresponding image source service of the image source are respectively configured with an access key management service to enable them to access the key management service normally.

[0065] In this embodiment, after the key management service generates a quantum key through the quantum key module, it creates a quantum key identifier corresponding to the quantum key. The quantum key identifier is used to uniquely specify the corresponding quantum key, including the first quantum key identifier corresponding to the first quantum key and the second quantum key identifier corresponding to the second quantum key. The quantum key is accessed through the quantum key identifier.

[0066] Specifically, determining the quantum key corresponding to the virtual machine control request includes: obtaining the quantum key identifier corresponding to the quantum key; accessing the quantum key through the quantum key identifier.

[0067] In addition, before determining the quantum key corresponding to the virtual machine control request, it further includes: determining whether the quantum key is deactivated; in the case where the quantum key is deactivated, ending the virtual machine control request.

[0068] In this embodiment, the quantum key can be deactivated by directly calling the quantum key module. After the deactivation of the quantum key is completed, the key management service can monitor the deactivated quantum key and set the status of the quantum key to the disabled state.

[0069] In the case where the status of the quantum key is the disabled state, the related virtual machine control request cannot be completed. For example, in the case where the key status of the first quantum key corresponding to the target virtual machine is the disabled state, after the computing service downloads the virtual machine image file from the image source, it uses the first quantum key to call the key service management interface to perform digital signature verification on the virtual machine image file. Since the first quantum key is disabled, the verification fails to return, and the computing service cannot execute the creation of the target virtual machine.

[0070] Or, in the case where the key status of the second quantum key is the disabled state, during the process of starting the virtual machine, the computing service uses the second quantum key to call the key management service interface to perform digital signature verification on the virtual machine file of the target virtual machine. Since the second quantum key is disabled, the verification fails to return, and the computing service cannot execute the start of the target virtual machine.

[0071] Step S103, perform digital signature verification on the signature of the target virtual machine through the quantum key to obtain a verification result.

[0072] In this embodiment, the signature of the target virtual machine includes the virtual machine image file signature and the virtual machine file signature. Digital signature verification of the signature of the target virtual machine using quantum keys includes, when creating the target virtual machine, using the first quantum key to perform signature verification on the signature of the virtual machine image file required for creating the target virtual machine; and when starting the target virtual machine, using the second quantum key to perform signature verification on the signature of the virtual machine file corresponding to the target virtual machine.

[0073] In this embodiment, after the administrator uploads the virtual machine image file used to create the target virtual machine to the image source, the administrator also needs to specify the first quantum key corresponding to the virtual machine image file in the manner identified by the first quantum key, so that the image source service can generate a signature request based on the virtual machine image file and the first quantum key corresponding to the virtual machine image file and send it to the key management service, so that the key management service can generate the corresponding virtual machine image file signature and then return it to the image source service for storage by the image source service. In this way, when the computing service creates the target virtual machine using the virtual machine image file, the computing service can obtain the virtual machine image file signature and the corresponding first quantum key while obtaining the virtual machine image file through the image source service. Therefore, when the virtual machine control request is a virtual machine creation request, the signature of the target virtual machine refers to the virtual machine image file signature. The key management service includes a key management interface. During the creation process of the target virtual machine, the key management service calls the key management interface to pass in the first quantum key, the virtual machine image file corresponding to the target virtual machine, and the virtual machine image signature for digital signature verification; after receiving the signature verification request sent by the computing service, the key management interface calls the quantum key module to perform digital signature verification and returns the verification result.

[0074] Specifically, when the virtual machine control request is a virtual machine creation request, digital signature verification of the signature of the target virtual machine using quantum keys to obtain a verification result includes: obtaining the virtual machine image file corresponding to the target virtual machine from the image source; the virtual machine image file includes the virtual machine image file signature. Performing signature verification on the virtual machine image file signature using the first quantum key to obtain a verification result.

[0075] Before obtaining the signature image file corresponding to the target virtual machine from the image source, it further includes: generating the first quantum key; performing digital signature on the virtual machine image file using the first quantum key to obtain the virtual machine image file signature.

[0076] Among them, the virtual machine image file signature is stored in the metadata of the virtual machine image file.

[0077] In this embodiment, during the shutdown process of the target virtual machine, the key management service interface is called through the second quantum key to digitally sign the virtual machine file of the target virtual machine. After receiving the digital signature request sent by the computing service, the key management service calls the quantum key module to generate the virtual machine file signature and return it.

[0078] Therefore, when the virtual machine control request is a virtual machine start request, the signature of the virtual machine refers to the virtual machine file signature of the target virtual machine. The signature verification is performed by calling the key management service interface and passing in the second quantum key, the virtual machine file of the target virtual machine, and the virtual machine file signature. After receiving the signature verification request sent by the computing service, the key management service interface calls the quantum key module to perform the signature verification and return the verification result.

[0079] Specifically, when the virtual machine control request is a virtual machine start request, before determining the quantum key corresponding to the virtual machine control request, it further includes: generating the second quantum key; during the shutdown process of the target virtual machine, obtaining the virtual machine file corresponding to the target virtual machine; digitally signing the virtual machine file with the second quantum key to obtain the virtual machine file signature.

[0080] Among them, the virtual machine file signature is stored in the metadata of the virtual machine.

[0081] Correspondingly, the digital signature verification of the signature of the target virtual machine is performed through the quantum key to obtain the verification result, including: obtaining the virtual file signature; performing the signature verification on the virtual file signature through the second quantum key.

[0082] In addition, before performing the digital signature verification of the signature of the target virtual machine through the quantum key to obtain the verification result, it further includes: determining whether the quantum key is deactivated; in the case where the quantum key is deactivated, ending the virtual machine control request.

[0083] In the case where the quantum key is deactivated, the relevant virtual machine control requests cannot be completed. For example, in the case where the second quantum key is deactivated, during the process of starting the target virtual machine, the second quantum key cannot be used for virtual machine file signature verification, and the signature verification always fails, so as to achieve the purpose of not being able to start the target virtual machine.

[0084] Step S104, in the case where the verification result passes, create or start the target virtual machine according to the indication of the virtual machine control request.

[0085] In the case where the virtual machine control request is a virtual machine creation request, if the verification result indicates that the digital signature verification is successful, then create the target virtual machine; if the verification result indicates that the digital signature verification fails, then it is determined that the data source of the virtual machine image file used by the target virtual machine is unreliable and creation is not allowed.

[0086] In the case where the virtual machine control request is a virtual machine startup request, if the verification result indicates that the digital signature verification is successful, start the target virtual machine; if the verification result indicates that the digital signature verification fails, determine that the virtual machine files used by the target virtual machine have been illegally modified and do not allow startup.

[0087] To more clearly understand the quantum key-based virtual machine control method provided by this application, an example of this method will be described below. In this example, referring to Figure 2 , this method at least includes steps S201 to S210:

[0088] Step S201, upload the virtual machine image file of the target virtual machine to the image source;

[0089] Step S202, use the first quantum key to call the key management service through the image source service, digitally sign the virtual machine image file and return it;

[0090] Step S203, store the virtual machine image file signature and the virtual machine image file in the image source repository through the image source service;

[0091] Step S204, in the case of receiving a virtual machine creation request, obtain the virtual machine image file from the image source through the computing service;

[0092] Step S205, obtain the virtual machine image file signature;

[0093] Step S206, the computing service uses the first quantum key to call the key management service to perform signature verification on the virtual machine image file signature;

[0094] Step S207, call the quantum key module through the key management service to perform digital signature verification on the virtual machine image file signature and return the verification result;

[0095] Step S208, determine whether the verification is successful. In the case of verification failure, execute step S209; otherwise, execute step S210;

[0096] Step S209, end the creation of the target virtual machine;

[0097] Step S210, execute the creation of the target virtual machine.

[0098] To more clearly understand the quantum key-based virtual machine control method provided by this application, another example of this method will be described below. In this example, referring to Figure 3 , this method at least includes steps S301 to S306:

[0099] Step S301, during the shutdown process of the target virtual machine, the computing service uses the second quantum key to call the key management service to digitally sign the virtual machine files and return them;

[0100] Step S301, when the computing service receives a virtual machine startup request, it uses the second quantum key to call the key management service interface for digital signature verification;

[0101] Step S303, the key management service calls the quantum key management module to perform digital signature verification and return the verification result;

[0102] Step S304, determine whether the verification is successful. If the verification fails, execute Step S305; otherwise, execute Step S306;

[0103] Step S305, end the startup of the target virtual machine;

[0104] Step S306, execute the startup of the target virtual machine.

[0105] In summary, the virtual machine control method based on quantum key provided by this application obtains a virtual machine control request corresponding to the target virtual machine; the virtual machine control request includes a virtual machine creation request or a virtual machine startup request; determines the quantum key corresponding to the virtual machine control request; the quantum key includes the first quantum key corresponding to the virtual machine creation request and the second quantum key corresponding to the virtual machine startup request; performs digital signature verification on the signature of the target virtual machine through the quantum key to obtain a verification result; the signature of the target virtual machine includes a virtual machine image file signature and a virtual machine file signature; when the verification result passes, create or start the target virtual machine according to the indication of the virtual machine control request; it can solve the problem of low security and reliability of the virtual machine; during the process of creating a virtual machine, use the first quantum key for digital signature verification, and during the process of starting a virtual machine, use the second quantum key for digital signature verification. Utilizing the characteristics of the quantum key itself that cannot be stolen or cracked, combined with using different quantum keys to control the creation and startup of the virtual machine, can reduce potential risks, ensure the security of the key, and improve the security and reliability of the virtual machine.

[0106] Furthermore, during the process of creating the target virtual machine, digitally signing and verifying the virtual machine image file required for the target virtual machine through the first quantum key can ensure the reliability of the virtual machine image file, thereby improving the reliability and security of the target virtual machine.

[0107] Furthermore, during the process of starting the target virtual machine, digitally signing and verifying the virtual machine files of the target virtual machine through the second quantum key can prevent the virtual machine files from being tampered with, thereby further improving the reliability and security of the target virtual machine.

[0108] Further, the quantum key is disabled through the quantum key module to implement the prohibition of controlling the virtual machine, so as to ensure the security of the service, and the security of the virtual machine can be further improved.

[0109] This embodiment provides a virtual machine control device based on a quantum key, as Figure 4 shown. The device includes at least the following modules: a request acquisition module 410, a key acquisition module 420, a signature verification module 430, and a virtual machine control module 440.

[0110] The request acquisition module 410 is used to acquire a virtual machine control request corresponding to a target virtual machine; the virtual machine control request includes a virtual machine creation request or a virtual machine startup request;

[0111] The key acquisition module 420 is used to determine a quantum key corresponding to the virtual machine control request; the quantum key includes a first quantum key corresponding to the virtual machine creation request and a second quantum key corresponding to the virtual machine startup request;

[0112] The signature verification module 430 is used to perform digital signature verification on the signature of the target virtual machine through the quantum key to obtain a verification result; the signature of the target virtual machine includes a virtual machine image file signature and a virtual machine file signature;

[0113] The virtual machine control module 440 is used to create or start the target virtual machine according to the indication of the virtual machine control request when the verification result passes.

[0114] For related details, refer to the above method and system embodiments.

[0115] It should be noted that: when the virtual machine control device based on a quantum key provided in the above embodiment performs virtual machine control based on a quantum key, only the above-mentioned division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the virtual machine control device based on a quantum key is divided into different functional modules to complete all or part of the functions described above. In addition, the virtual machine control device based on a quantum key provided in the above embodiment and the embodiment of the virtual machine control method based on a quantum key belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.

[0116] This embodiment provides a virtual machine control device based on a quantum key, as Figure 5 shown. The virtual machine control device based on a quantum key includes at least a processor 501 and a memory 502.

[0117] The processor 501 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 501 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 501 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 501 may be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 501 may further include an AI (Artificial Intelligence) processor, and the AI processor is used to process computational operations related to machine learning.

[0118] The memory 502 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 502 may further include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In some embodiments, the non-transitory computer-readable storage medium in the memory 502 stores computer instructions, and the processor 501 is configured to execute the computer instructions stored in the memory 502. When the computer instructions are executed by the processor 501, the device implements the method for controlling a virtual machine based on quantum keys provided in the method embodiments of the present application.

[0119] In some embodiments, the virtual machine control device based on quantum keys may optionally further include a peripheral device interface and at least one peripheral device. The processor 501, the memory 502, and the peripheral device interface may be connected through a bus or signal lines. Each peripheral device may be connected to the peripheral device interface through a bus, signal lines, or a circuit board. Schematically, the peripheral devices include, but are not limited to, a radio frequency circuit, a touch display screen, an audio circuit, and a power supply, etc.

[0120] Of course, the virtual machine control device based on quantum keys may also include fewer or more components, and this embodiment does not limit this.

[0121] Optionally, the present application further provides a computer-readable storage medium, in which a computer program is stored, and when the program is executed by a processor, the method for controlling a virtual machine based on a quantum key in the above method embodiment is implemented.

[0122] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0123] Obviously, the above-described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, those of ordinary skill in the art can make other different forms of changes or variations without making creative efforts, and all of them should belong to the scope of protection of the present application.

Claims

1. A virtual machine control method based on quantum keys, characterized in that, the method comprises the following steps: Obtain a virtual machine control request corresponding to a target virtual machine; the virtual machine control request includes a virtual machine creation request or a virtual machine startup request; Determine a quantum key corresponding to the virtual machine control request; the quantum key includes a first quantum key corresponding to the virtual machine creation request and a second quantum key corresponding to the virtual machine startup request; Perform digital signature verification on the signature of the target virtual machine through the quantum key to obtain a verification result; the signature of the target virtual machine includes the signature of the virtual machine image file and the signature of the virtual machine file; When the verification result passes, create or start the target virtual machine according to the indication of the virtual machine control request.

2. The virtual machine control method based on quantum keys according to claim 1, characterized in that, when the virtual machine control request is the virtual machine creation request, the performing digital signature verification on the signature of the target virtual machine through the quantum key to obtain a verification result includes: Obtain a virtual machine image file corresponding to the target virtual machine from an image source; the virtual machine image file includes a virtual machine image file signature; Perform signature verification on the virtual machine image file signature through the first quantum key to obtain the verification result.

3. The virtual machine control method based on quantum keys according to claim 2, characterized in that, before obtaining the signature image file corresponding to the target virtual machine from the image source, further includes: Generate the first quantum key; Perform digital signature on the virtual machine image file using the first quantum key to obtain the virtual machine image file signature; the virtual machine image file signature is stored in the metadata of the virtual machine image file.

4. The virtual machine control method based on quantum keys according to claim 1, characterized in that, when the virtual machine control request is the virtual machine startup request, before obtaining the quantum key corresponding to the virtual machine control request, further includes: Generate the second quantum key; During the shutdown process of the target virtual machine, obtain the virtual machine file corresponding to the target virtual machine; Perform digital signature on the virtual machine file through the second quantum key to obtain a virtual machine file signature; the virtual machine file signature is stored in the metadata of the virtual machine.

5. The virtual machine control method based on quantum keys according to claim 4, characterized in that, the performing digital signature verification on the signature of the target virtual machine through the quantum key to obtain a verification result includes: Obtain the virtual machine file signature; Perform signature verification on the virtual machine file signature through the second quantum key.

6. The virtual machine control method based on quantum keys according to claim 1, characterized in that, before determining the quantum key corresponding to the virtual machine control request, further includes: Determine whether the quantum key is deactivated; When the quantum key is deactivated, end the virtual machine control request.

7. The virtual machine control method based on quantum key according to claim 1, wherein, the determining the quantum key corresponding to the virtual machine control request includes: obtaining the quantum key identifier corresponding to the quantum key; determining the quantum key through the quantum key identifier.

8. The virtual machine control method based on quantum key according to claim 1, wherein, the virtual machine image files used by different target virtual machines are the same or different; the first quantum keys corresponding to different virtual machine image files are different; the second quantum keys used by different target virtual machines are the same.

9. A virtual machine control device based on quantum key, comprising a processor and a memory, wherein, computer instructions are stored in the memory, and the processor is configured to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the device implements the steps of the method according to any one of claims 1 to 8.

10. A computer-readable storage medium, on which a computer program is stored, wherein, when the program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 8.