Method and device for integrating cryptographic module in Docker, electronic equipment and medium
By using the storage volume mechanism in the Docker container to separate business data and password modules, independent packaging, deployment and update are achieved, solving the problems of difficulty and cost of cipher module update coordination in Docker technology, and improving development efficiency and system stability.
Patent Information
- Application Number
- CN202510592706.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-05-09
AI Technical Summary
When using Docker technology, the conventional way of making password modules into libraries and packaging them into mirror files with business applications is common, which has problems such as difficult to synchronize development progress, complex packaging, difficult and costly password module update coordination.
Through the storage volume mechanism, the business data and password modules are separated, and the independent packaging, deployment and update of business data and password modules are realized. The specific steps include extracting business data from the image file of the Docker container, analyzing the configuration module in the image file to determine the target instruction, determining the directory mapping relationship between the storage volume and the target server in the storage volume based on the target instruction, and reading the password module from the corresponding directory of the target server, and encrypting the service data based on the password module.
The separation of business data and password modules is achieved through the storage volume mechanism, allowing business data and password modules to be packaged, deployed and updated independently, solving the problems of difficult synchronization of development progress, complex packaging and difficult update coordination, reducing costs and improving efficiency.
Smart Images

Figure CN120144233A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of containers, and in particular to a method, device, electronic device and medium for integrating a password module in Docker. Background Art
[0002] In the process of the development of cloud computing, computing hardware resources tend to be virtualized, and virtual machines and container technologies are the most common. A virtual machine can virtualize a physical server into multiple logical hosts, each running a different operating system and application program, but the operation is cumbersome and prone to resource waste, thus giving rise to the lightweight virtualization technology of containers.
[0003] As a mainstream container technology, Docker does not need to integrate an operating system. By encapsulating the resources on which a business application depends into an image file and loading and running middleware on a target machine, it realizes the separation of the business application from the underlying device and process-level isolation, and has become a major technical means in cloud computing.
[0004] Passwords are the basis for ensuring the security of business applications and data. When users' services are migrated to the cloud, they need to rely on a password module for protection. When using Docker technology, the conventional method of making the password module into a library and packaging it with the business application into an image file has problems such as difficult synchronization of development progress, complex packaging, difficult coordination and high cost for updating the password module. Summary of the Invention
[0005] The present invention provides a method, device, electronic device and medium for integrating a password module in Docker. Through the storage volume mechanism, the separation of business data and the password module is realized, and the business data and the password module can be independently packaged, deployed and updated respectively.
[0006] According to one aspect of the present invention, there is provided a method for integrating a password module in Docker, the method comprising:
[0007] Extracting business data from the image file of the Docker container;
[0008] Analyzing the configuration module in the image file to determine a target instruction, determining the directory mapping relationship between the storage volume and the target server according to the target instruction in the storage volume, and reading the password module from the corresponding directory of the target server according to the directory mapping relationship between the storage volume and the target server; wherein, the Docker container mounts the storage volume; the target instruction is an instruction to run the password module from the storage volume;
[0009] Performing encryption processing on the business data based on the password module.
[0010] According to another aspect of the present invention, there is provided a device for integrating a password module in Docker, the device comprising:
[0011] A business data extraction module, configured to extract business data from the image file of a Docker container;
[0012] A password module reading module, configured to parse the configuration module in the image file to determine a target instruction, determine the directory mapping relationship between the storage volume and the target server in the storage volume according to the target instruction, and read the password module from the corresponding directory of the target server according to the directory mapping relationship between the storage volume and the target server; wherein, the Docker container mounts the storage volume; the target instruction is an instruction to run the password module from the storage volume;
[0013] An encryption module, configured to perform encryption processing on the business data based on the password module.
[0014] According to another aspect of the present invention, there is provided an electronic device, which includes:
[0015] At least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute a method for integrating a password module in Docker according to any embodiment of the present invention.
[0016] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement a method for integrating a password module in Docker according to any embodiment of the present invention when executed.
[0017] The technical solution of the embodiment of the present invention extracts business data from the image file of a Docker container, then parses the configuration module in the image file to determine a target instruction, determines the directory mapping relationship between the storage volume and the target server in the storage volume according to the target instruction, and reads the password module from the corresponding directory of the target server according to the directory mapping relationship between the storage volume and the target server, and performs encryption processing on the business data based on the password module. By means of the storage volume mechanism, this technical solution realizes the separation of business data and the password module, and the business data and the password module can be independently packaged, deployed, and updated respectively.
[0018] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Description of the Drawings
[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0020] Figure 1 It is a flowchart of a method for integrating a password module within Docker according to Embodiment 1 of the present invention;
[0021] Figure 2 It is a schematic diagram of integrating a password module within Docker provided by Embodiment 1 of the present application;
[0022] Figure 3 It is another schematic diagram of integrating a password module within Docker provided by Embodiment 1 of the present application;
[0023] Figure 4 It is a flowchart of a process for integrating a password module within Docker according to Embodiment 2 of the present invention;
[0024] Figure 5 It is a schematic structural diagram of a device for integrating a password module within Docker according to Embodiment 3 of the present invention;
[0025] Figure 6 It is a schematic structural diagram of an electronic device for implementing the method of integrating a password module within Docker in the embodiments of the present invention. Detailed implementation manners
[0026] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0027] It should be noted that terms such as "target" in the specification, claims and the above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0028] Embodiment 1
[0029] Figure 1 is a flowchart of a method for integrating a cryptographic module within Docker according to Embodiment 1 of the present invention. This embodiment is applicable to the situation of integrating a cryptographic module within Docker. This method can be executed by a device for integrating a cryptographic module within Docker, and the device for integrating a cryptographic module within Docker can be implemented in the form of hardware and / or software, and the device for integrating a cryptographic module within Docker can be configured in a device. For example, the device can be a device with communication and computing capabilities such as a background server. As Figure 1 shown, the method includes:
[0030] S110. Extract service data from the image file of the Docker container.
[0031] In this solution, the Docker container encapsulates the dependent resources of the service data into an image file. A Docker container middleware is deployed on the target server, and the Docker container middleware can load the image file and run it as a separate process on the target server.
[0032] In this embodiment, the image file consists of the container basic environment, service data, and the resources on which the service data depends. Among them, the service data covers user service applications, and user service applications refer to various software applications or systems developed and used to meet the needs of users in specific service scenarios.
[0033] Among them, Figure 2 is a schematic diagram of integrating a cryptographic module within Docker provided in Embodiment 1 of the present application. As Figure 2 shown, a configuration module I1 can be written to package the container basic environment, service data, configuration module I1, and other dependent resources into an image file B1. Among them, the configuration module consists of script files.
[0034] Specifically, a Docker container instance R1 is run through the Docker service middleware, and the image file B1 is read in, and then the business data therein is extracted.
[0035] S120. Analyze the configuration module in the image file to determine the target instruction, determine the directory mapping relationship between the storage volume and the target server in the storage volume according to the target instruction, and read the password module from the corresponding directory of the target server according to the directory mapping relationship between the storage volume and the target server; wherein, the Docker container mounts the storage volume; the target instruction is an instruction to run the password module from the storage volume.
[0036] In this embodiment, the target instruction is an instruction to run the password module from the storage volume, and the target instruction is stored in the configuration module in the image file.
[0037] Among them, in Docker, a storage volume is a mechanism for persisting data. The data in the container itself is temporary, and when the container is deleted, the data in the container will also be lost. By using a storage volume, data can be stored outside the container, so that even if the container is deleted, the data will not be lost and can be shared between different containers.
[0038] Further, as Figure 2 shown, there are mainly two ways to implement container mounting of a storage volume in Docker, namely using a bind mount and using a volume. A bind mount is to directly mount a directory or file on the target server into the container. A volume is storage managed by Docker and stored in a specific directory on the target server.
[0039] Specifically, as Figure 2 shown, a Docker container instance R1 is run through the Docker service middleware, the container mounts the storage volume D1, and maps the storage volume D1 to the directory D0 on the target server.
[0040] Further, the Docker container instance R1 runs and reads in the image file B1; R1 starts the business data software according to the configuration module I1, and starts the password module software from the storage volume D1. Through the above steps, the collaborative operation of the business data software and the password module software within the same container instance R1 is realized, and a functionally complete and flexibly configured application execution environment is built.
[0041] Optionally, analyzing the configuration module in the image file to determine the target instruction, determining the directory mapping relationship between the storage volume and the target server in the storage volume according to the target instruction, and reading the password module from the corresponding directory of the target server according to the directory mapping relationship between the storage volume and the target server includes:
[0042] Store the target instruction in the configuration module of the image file; and store the password module in the corresponding directory of the target server; and store the mapping relationship between the storage volume and the directory of the target server in the storage volume;
[0043] When running the configuration module in the image file, parse the configuration module in the image file to determine the target instruction; execute the target instruction to determine the mapping relationship between the storage volume and the directory of the target server in the storage volume; according to the mapping relationship between the storage volume and the directory of the target server, read the password module from the corresponding directory of the target server.
[0044] In this solution, the target instruction is an instruction to run the password module from the storage volume. Set up a storage volume D1 for the Docker container, write a configuration module I1, and add an instruction to run the password module from the storage volume D1.
[0045] Furthermore, package the container basic environment, business data, configuration module I1, and other dependent resources into an image file B1.
[0046] Among them, on the target server, create a new directory D0 under the logged-in user's directory, and deposit the password module software into D0.
[0047] Furthermore, run a Docker container instance R1 through the Docker service middleware. This container mounts the storage volume D1 and maps the storage volume D1 to the directory D0 of the target server. The Docker container instance R1 runs, reads in the image file B1; R1 starts the business data software according to the configuration module I1 and starts the password module software from the storage volume D1.
[0048] Through the storage volume mechanism, the separation of business data and the password module is achieved, and the business data and the password module can be independently packaged, deployed, and updated respectively.
[0049] Optionally, storing the password module in the corresponding directory of the target server includes:
[0050] In response to the operation instruction, modify the password module to generate a new password module, and store the new password module in the corresponding directory of the target server.
[0051] In this solution, when the password module needs to be updated, modify the password module in response to the operation instruction to generate a new password module, and write the new password module to the corresponding directory of the target server.
[0052] Further, after writing the new password module to the corresponding directory of the target server, perform a restart operation on the Docker container instance R1. The password module software built in this instance will be started through the storage volume D1. This deployment method can effectively isolate the impact of system restart on business data, realize the independent operation of the basic service and the business development environment, and thus provide a flexible operation space for the iterative upgrade of business data while ensuring the stable operation of the password module.
[0053] S130. Encrypt the business data based on the password module.
[0054] Among them, the password module includes symmetric encryption algorithms, asymmetric encryption algorithms, hash algorithms, etc.
[0055] In this solution, the password module is implemented as an independent software program with an IP (Internet Protocol) network communication interface. The business data is an independent software program that can communicate with the password module through the IP network interface. The business application software and the password module software define a set of interactive protocol messages to implement password security interaction services.
[0056] In this embodiment, the business data is encrypted according to the encryption policy and algorithm preset in the password module. Specifically, the password module will perform format verification and integrity check on the input business data to ensure the accuracy and integrity of the data before encryption. Then, according to the sensitivity of the data and business requirements, the most suitable encryption algorithm is selected from the rich encryption algorithm library. After the algorithm is selected, the password module will generate the corresponding encryption key. Driven by the key, the password module performs bit-by-bit or segment-by-segment encryption operations on the business data, converting the original and readable business data into ciphertext form, making it difficult to be illegally obtained and interpreted during transmission and storage.
[0057] Optionally, encrypting the business data based on the password module includes:
[0058] Determine the network interface of the password module and the network interface of the business data, and establish a communication connection between the password module and the business data based on the network interface of the password module and the network interface of the business data;
[0059] Call the password module to encrypt the business data.
[0060] Specifically, the password module is an independent software with an IP (Internet Protocol) network communication interface. The service data is separately packaged into an image file, and in its configuration module, it is set to start the password module software through this storage volume. When the image file is loaded and run, it will read the configuration module to start the password module software, so that both the service data and the password module software run in the container, and the two interact through the IP network interface.
[0061] In this solution, Figure 3 Another schematic diagram of integrating the password module within Docker provided in the first embodiment of this application is shown in Figure 3 As shown, the process of integrating the password module within Docker includes a packaging stage and a deployment and running stage. Packaging stage: Configure a storage volume named dm1 for Docker. Then, write a configuration module for the service data, and add a command in this module to start the password module from the specified storage volume dm1. After that, package the service data, the configuration module, and the required running resources to generate an image file. Deployment and running stage: Assume that the login user of the target server is user1. On the target server, create a new directory named cm1 in the home directory of user1, and write the password module software into this directory. Subsequently, map the storage volume dm1 of the Docker instance to the cm1 directory. The user starts a Docker instance named r1 through the Docker service middleware on the target server. In the start command, clearly require to mount the storage volume dm1. When the Docker instance r1 starts and loads the previously generated image file, it will automatically execute the configuration module, so that the service data and the password module software can run in the Docker instance. The service data will establish a connection with the password module application through a specific IP port and interact according to the negotiated network protocol packets to achieve the password security function.
[0062] Furthermore, if the password module software needs to be updated, just write the updated software into the cm1 directory of the target server, and then restart the Docker instance r1. Since the storage volume dm1 has been mapped to the cm1 directory, the Docker instance will start the updated password module through the storage volume dm1.
[0063] The technical solution of the embodiment of the present invention extracts business data from the image file of the Docker container, then parses the configuration module in the image file to determine the target instruction, determines the directory mapping relationship between the storage volume and the target server in the storage volume according to the target instruction, and reads the password module from the corresponding directory of the target server based on the directory mapping relationship between the storage volume and the target server, and encrypts the business data based on the password module. By executing this technical solution, through the storage volume mechanism, the separation of business data and the password module is realized, and the business data and the password module can be independently packaged, deployed, and updated respectively.
[0064] Embodiment 2
[0065] Figure 4 It is a flowchart of a process for integrating a password module in Docker provided by Embodiment 2 of the present invention. The relationship between this embodiment and the above embodiment is a detailed supplement to the integration of the password module in Docker. As Figure 4 shown, the method includes:
[0066] S410. Extract business data from the image file of the Docker container.
[0067] S420. Parse the configuration module in the image file to determine the target instruction, and read the password module from the storage volume according to the target instruction; wherein, the target instruction is an instruction to run the password module from the storage volume.
[0068] In this embodiment, the target instruction is an instruction to run the password module from the storage volume, and the target instruction is stored in the configuration module in the image file.
[0069] Among them, in Docker, a storage volume is a mechanism for persisting data. The data in the container itself is temporary, and when the container is deleted, the data in the container will also be lost. By using a storage volume, the data can be stored outside the container, so that even if the container is deleted, the data will not be lost and can be shared among different containers.
[0070] Furthermore, there are mainly two ways to implement container mounting of a storage volume in Docker, namely using a bind mount and using a volume. A bind mount is to directly mount a directory or file on the target server into the container. A volume is storage managed by Docker and stored in a specific directory on the target server.
[0071] Specifically, run a Docker container instance R1 through the Docker service middleware, and this container mounts the storage volume D1.
[0072] Further, the Docker container instance R1 runs and reads the mirror file B1; according to the configuration module I1, R1 starts the business data software and starts the password module software from the storage volume D1. Through the above steps, the collaborative operation of the business data software and the password module software within the same container instance R1 is achieved, and a functionally complete and flexibly configurable application execution environment is constructed.
[0073] Optionally, reading the password module from the storage volume according to the target instruction includes:
[0074] Storing the target instruction into the configuration module of the mirror file; and storing the password module into the storage volume;
[0075] When running the configuration module in the mirror file, parsing the configuration module in the mirror file to determine the target instruction; executing the target instruction to read the password module from the storage volume.
[0076] In this solution, the target instruction is an instruction to run the password module from the storage volume. A storage volume D1 is set for the Docker container, the configuration module I1 is written, and an instruction to run the password module from the storage volume D1 is added.
[0077] Among them, the basic container environment, business data, configuration module I1, and other dependent resources are packaged into a mirror file B1.
[0078] In this embodiment, the password module is stored in the storage volume D1.
[0079] Further, a Docker container instance R1 is run through the Docker service middleware, and this container is mounted with the storage volume D1. The Docker container instance R1 runs and reads the mirror file B1; according to the configuration module I1, R1 starts the business data software and reads the password module software from the storage volume D1.
[0080] Through the storage volume mechanism, the separation of business data and the password module is achieved, and the business data and the password module can be independently packaged, deployed, and updated respectively.
[0081] Optionally, storing the password module into the storage volume includes:
[0082] In response to the operation instruction, modifying the password module to generate a new password module, and storing the new password module into the storage volume.
[0083] In this solution, when the password module needs to be updated, in response to the operation instruction, the password module is modified to generate a new password module, and the new password module is written into the storage volume.
[0084] Further, after writing the new password module into the storage volume D1, perform a restart operation on the Docker container instance R1. The password module software built into this instance will be started through the storage volume D1. This deployment method can effectively isolate the impact of system restart on business data, realize the independent operation of the basic service and the business development environment, and thus provide a flexible operation space for the iterative upgrade of business data while ensuring the stable operation of the password module.
[0085] In this solution, during the software development stage, the business data software and the password module software adopt a parallel development mode and are advanced according to the plan in their respective independent development environments. The password module software, as an independent development unit, has a standard IP network interface and focuses on implementing password security functions; the business data software is also developed as an independent module, configured with an IP network interface, and is responsible for core business logic processing; the two parties jointly define a set of standardized protocol messages to achieve secure interaction between the business data software and the password module through the IP network, ensuring seamless integration of password functions. Write a configuration script file in the business data software and embed an instruction to start the password module from a specified storage volume; integrate and package the business data software, the configuration script, and the required running resources into an image file for subsequent deployment.
[0086] Further, in the target server environment, realize the efficient deployment and dynamic management of software through Docker container technology. Specifically, create a dedicated directory on the target server as the storage volume of the Docker instance, and write the password module software and the packaged image file respectively; the user executes a start command through the Docker service middleware on the target server, specifying to mount the above storage volume to trigger the creation of the Docker instance; when the Docker instance starts, it automatically loads the image file and executes the configuration script therein, so that the business data software and the password module software can run simultaneously in the container; the business data software establishes a connection with the password module through a preset IP port and performs data interaction based on the previously negotiated protocol messages to complete the password security function; when the password module software needs to be updated, only write the new version into the storage volume and restart the Docker instance to complete the upgrade, without redeploying the entire business system.
[0087] S430. Encrypt the business data based on the password module.
[0088] The technical solution of the embodiment of the present invention extracts business data from the image file of the Docker container, then parses the configuration module in the image file to determine the target instruction, reads the password module in the storage volume according to the target instruction, and encrypts the business data based on the password module. By executing this technical solution, through the storage volume mechanism, the separation of business data and the password module is realized, and the business data and the password module can be independently packaged, deployed, and updated respectively.
[0089] Embodiment III
[0090] Figure 5 It is a schematic structural diagram of a device integrating a password module in Docker provided by Embodiment III of the present invention. As Figure 5 shown, the device includes:
[0091] A business data extraction unit 510, configured to extract business data from the image file of the Docker container;
[0092] A password module reading unit 520, configured to parse the configuration module in the image file to determine the target instruction, determine the directory mapping relationship between the storage volume and the target server in the storage volume according to the target instruction, and read the password module from the corresponding directory of the target server according to the directory mapping relationship between the storage volume and the target server; wherein, the Docker container mounts the storage volume; the target instruction is an instruction to run the password module from the storage volume;
[0093] An encryption unit 530, configured to encrypt the business data based on the password module.
[0094] Optionally, the password module reading unit 520 includes:
[0095] A storage subunit, configured to store the target instruction in the configuration module of the image file; store the password module in the corresponding directory of the target server; and store the directory mapping relationship between the storage volume and the target server in the storage volume;
[0096] A password module reading subunit, configured to parse the configuration module in the image file to determine the target instruction when running the configuration module in the image file; execute the target instruction to determine the directory mapping relationship between the storage volume and the target server in the storage volume; and read the password module from the corresponding directory of the target server according to the directory mapping relationship between the storage volume and the target server.
[0097] Optionally, the storage subunit is specifically configured to:
[0098] In response to the operation instruction, modify the password module to generate a new password module, and store the new password module in the corresponding directory of the target server.
[0099] Optionally, the device further includes:
[0100] A password module determination unit, configured to parse a configuration module determination target instruction in the mirror file, and read a password module from a storage volume according to the target instruction; wherein, the target instruction is an instruction to run the password module from the storage volume.
[0101] Optionally, the password module determination unit includes:
[0102] A configuration subunit, configured to store the target instruction in a configuration module of the mirror file; and store the password module in the storage volume;
[0103] A password module determination subunit, configured to, when running the configuration module in the mirror file, parse the configuration module in the mirror file to determine a target instruction; execute the target instruction, and read the password module from the storage volume.
[0104] Optionally, the password module determination subunit is specifically configured to:
[0105] In response to an operation instruction, modify the password module, generate a new password module, and store the new password module in the storage volume.
[0106] Optionally, the encryption unit 530 is specifically configured to:
[0107] Determine a network interface of the password module and a network interface of service data, and establish a communication connection between the password module and the service data based on the network interface of the password module and the network interface of the service data;
[0108] Call the password module to perform an encryption process on the service data.
[0109] The device for integrating a password module in Docker provided by an embodiment of the present invention can execute the method for integrating a password module in Docker provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0110] Embodiment 4
[0111] Figure 6The structural schematic diagram of the electronic device 10 that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0112] As Figure 6 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0113] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0114] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a method for integrating a password module within Docker.
[0115] In some embodiments, a method for integrating a cryptographic module within Docker can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the method for integrating a cryptographic module within Docker described above can be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute the method for integrating a cryptographic module within Docker by any other suitable means (e.g., by means of firmware).
[0116] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0117] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer programs are executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0118] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0119] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0120] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0121] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0122] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0123] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for integrating a cryptographic module in a Docker, characterized in that: include: Extract business data from the image file of the Docker container; Parse the configuration module in the image file to determine the target instruction, determine the directory mapping relationship between the storage volume and the target server in the storage volume according to the target instruction, and read the password module from the corresponding directory of the target server according to the directory mapping relationship between the storage volume and the target server; wherein the Docker container mounts the storage volume; and the target instruction is an instruction to run the password module from the storage volume; The business data is encrypted based on the password module.
2. The method according to claim 1, characterized in that Parsing the configuration module in the image file to determine the target instruction, determining the directory mapping relationship between the storage volume and the target server in the storage volume according to the target instruction, and reading the password module from the corresponding directory of the target server according to the directory mapping relationship between the storage volume and the target server, including: The target instruction is stored in the configuration module of the image file; the password module is stored in the corresponding directory of the target server; and the mapping relationship between the storage volume and the directory of the target server is stored in the storage volume; When running the configuration module in the image file, the configuration module in the image file is parsed to determine the target instruction; the target instruction is executed to determine the directory mapping relationship between the storage volume and the target server in the storage volume; and according to the directory mapping relationship between the storage volume and the target server, the password module is read from the corresponding directory of the target server.
3. The method according to claim 2, characterized in that Store the password module in the corresponding directory of the target server, including: In response to the operation instruction, the password module is modified to generate a new password module, and the new password module is stored in a corresponding directory of the target server.
4. The method according to claim 1, characterized in that After extracting the business data from the image file of the Docker container, the method further includes: The configuration module in the image file is parsed to determine the target instruction, and the password module is read from the storage volume according to the target instruction; wherein the target instruction is an instruction to run the password module from the storage volume.
5. The method according to claim 4, characterized in that Reading a password module in a storage volume according to the target instruction includes: Storing the target instruction in the configuration module of the image file; and storing the password module in the storage volume; When the configuration module in the image file is run, the configuration module in the image file is parsed to determine the target instruction; the target instruction is executed, and the password module is read from the storage volume.
6. The method according to claim 5, characterized in that Store the cryptographic module in the storage volume, including: In response to the operation instruction, the password module is modified to generate a new password module, and the new password module is stored in the storage volume.
7. The method according to claim 1, characterized in that Encrypting the business data based on the password module includes: Determine a network interface of a cryptographic module and a network interface of business data, and establish a communication connection between the cryptographic module and the business data based on the network interface of the cryptographic module and the network interface of the business data; The cryptographic module is called to encrypt the business data.
8. A device for integrating a cryptographic module in a Docker, characterized in that: include: A business data extraction unit, used to extract business data from the image file of the Docker container; A password module reading unit, used to parse the configuration module in the image file to determine the target instruction, determine the directory mapping relationship between the storage volume and the target server in the storage volume according to the target instruction, and read the password module from the corresponding directory of the target server according to the directory mapping relationship between the storage volume and the target server; wherein the Docker container mounts the storage volume; and the target instruction is an instruction to run the password module from the storage volume; An encryption unit is used to encrypt the business data based on the password module.
9. An electronic device, characterized in that: The electronic device comprises: At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute a method for integrating a cryptographic module in a Docker as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement a method for integrating a cryptographic module in a Docker according to any one of claims 1 to 7 when executed.
Citation Information
Patent Citations
Method and device for deploying FreeSWITCH service, electronic equipment and storage medium
CN114124739A
Docker mirror image encryption and arrangement method and system
CN114978672A
Verification method and device for container software deployment permission, equipment and storage medium
CN115756515A
Container data encryption method and related equipment
CN119808113A
Method and apparatus for secure data mirroring a storage system
US20060015946A1
Cited By
Encryption system and method for high-value data in localization environment
CN121637540A
A high-value data encryption system and method in a localization environment
CN121637540B