Data processing method and device, equipment and medium

By setting a unique key for each virtual machine and encrypting data in the target virtual machine, the problem of data security risk propagation in the same virtual machine manager is solved, and the security of all virtual machine data under the virtual machine manager is improved.

CN120256029AActive Publication Date: 2025-07-04INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510756698.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-07-04
Estimated Expiration
2045-06-06

AI Technical Summary

Technical Problem

Different virtual machine data are stored in the same virtual machine manager. If a virtual machine has data security risks, it will cause all virtual machine data under the entire virtual machine manager to face security risks.

Method used

Set a different key for each virtual machine, and when receiving the data to be encrypted from the server, it uses its corresponding key to encrypt it in the target virtual machine, and store the encrypted ciphertext to the trusted storage area of the target virtual machine to ensure that the data of each virtual machine is stored in the same virtual machine manager in the form of ciphertext.

Benefits of technology

By setting a unique encryption key for each virtual machine, the data security risk of a single virtual machine will not affect other virtual machine data, improving the security of all virtual machine data under the virtual machine manager.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120256029A_ABST
    Figure CN120256029A_ABST
Patent Text Reader

Abstract

The invention discloses a data processing method and device, equipment and a medium in the technical field of computers. The virtual machine manager sets different secret keys for different virtual machines, and for the to-be-encrypted data sent by each server, based on the target virtual machine bound with the corresponding server, the to-be-encrypted data is encrypted by using the secret key corresponding to the target virtual machine, so that the encryption efficiency of the to-be-encrypted data is improved. And storing the encrypted ciphertext to a trusted storage area to which the target virtual machine belongs. In the scheme, the virtual machines correspond to different encryption keys, the data of different virtual machines are stored in the same virtual machine manager in a ciphertext form, the data security risk of a single virtual machine cannot influence the data of other virtual machines, and the security of the data of all virtual machines under the virtual machine manager is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and particularly to a data processing method, apparatus, device, and medium. Background Art

[0002] Currently, different virtual machine data is stored in the same virtual machine manager. If a virtual machine has a data security risk, it forms a security opening, resulting in the possibility of security risks for all virtual machine data under the virtual machine manager.

[0003] Therefore, how to improve the security of all virtual machine data under the virtual machine manager is a problem that needs to be solved by those skilled in the art. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a data processing method, apparatus, device, and medium to improve the security of all virtual machine data under the virtual machine manager.

[0005] In a first aspect, this application provides a data processing method applied to a virtual machine manager. The virtual machine manager is provided with multiple virtual machines, including: receiving connection requests sent by each server; selecting idle virtual machines from the multiple virtual machines according to the connection requests, and respectively binding the selected virtual machines to each server; where each virtual machine corresponds to a different key; if receiving encrypted data to be encrypted sent by a target server among the servers, in the target virtual machine bound to the target server, encrypting the encrypted data to be encrypted using the key corresponding to the target virtual machine, and storing the ciphertext obtained by encryption in the trusted storage area to which the target virtual machine belongs.

[0006] In a second aspect, this application provides a data processing apparatus applied to a virtual machine manager. The virtual machine manager is provided with multiple virtual machines, including: a receiving module for receiving connection requests sent by each server; a binding module for selecting idle virtual machines from the multiple virtual machines according to the connection requests, and respectively binding the selected virtual machines to each server; where each virtual machine corresponds to a different key; a storage module for, if receiving encrypted data to be encrypted sent by a target server among the servers, encrypting the encrypted data to be encrypted using the key corresponding to the target virtual machine in the target virtual machine bound to the target server, and storing the ciphertext obtained by encryption in the trusted storage area to which the target virtual machine belongs.

[0007] In a third aspect, this application provides an electronic device, including: a memory for storing a computer program; a processor for executing the computer program to implement the data processing method disclosed above.

[0008] Fourthly, the present application provides a non-volatile storage medium for storing a computer program, where the computer program, when executed by a processor, implements the data processing method disclosed above.

[0009] Fifthly, the present application provides a computer program product including a computer program / instructions, which, when executed by a processor, implement the steps of the data processing method disclosed above.

[0010] As can be seen from the above solutions, the present application provides a data processing method applied to a virtual machine manager. There are multiple virtual machines in the virtual machine manager, including: receiving connection requests sent by each server; selecting idle virtual machines from the multiple virtual machines according to the connection requests, and binding the selected virtual machines to each server respectively; where each virtual machine corresponds to a different key; if encrypted data to be encrypted sent by a target server among the servers is received, in the target virtual machine bound to the target server, encrypt the data to be encrypted by using the key corresponding to the target virtual machine, and store the ciphertext obtained by encryption in the trusted storage area to which the target virtual machine belongs.

[0011] It can be seen that the virtual machine manager in the present application sets different keys for different virtual machines, and for the encrypted data to be encrypted sent by each server, based on the target virtual machine bound to the corresponding server, and uses the key corresponding to the target virtual machine to encrypt the data to be encrypted, and stores the ciphertext obtained by encryption in the trusted storage area to which the target virtual machine belongs. In this solution, each virtual machine corresponds to a different encryption key, and the data of different virtual machines are stored in the same virtual machine manager in ciphertext form. The data security risk of a single virtual machine will not affect the data of other virtual machines, improving the security of all virtual machine data under the virtual machine manager.

[0012] Correspondingly, a data processing device, equipment and medium provided by the present application also have the above technical effects. Description of the Drawings

[0013] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0014] Figure 1 It is a flowchart of a data processing method disclosed in the present application; Figure 2 It is a schematic diagram of a data processing system disclosed in the present application; Figure 3Schematic diagram of a data processing device disclosed in this application; Figure 4 Schematic diagram of an electronic device disclosed in this application; Figure 5 Structural diagram of a server provided by this application; Figure 6 Structural diagram of a terminal provided by this application. Detailed implementation manners

[0015] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other examples obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0016] Currently, different virtual machine data is stored in the same virtual machine manager. If a virtual machine has a data security risk, this virtual machine forms a security opening, resulting in the possibility of data security risks for all virtual machines under the virtual machine manager. For this reason, this application provides a data processing solution that can enable each virtual machine to correspond to a different encryption key, and different virtual machine data is stored in the same virtual machine manager in ciphertext form. The existence of a data security risk in a single virtual machine will not affect the data of other virtual machines, improving the security of all virtual machine data under the virtual machine manager.

[0017] See Figure 1 As shown, an embodiment of this application discloses a data processing method applied to a virtual machine manager. There are multiple virtual machines in the virtual machine manager, including: S101. Receive connection requests sent by each server.

[0018] In this embodiment, a security reinforcement model TDX is provided in the virtual machine manager. TDX is a trusted medium that provides interfaces for creating, deleting, and scheduling the execution of Trust Domain. This intermediary that is independent of the control of the virtual machine manager manages the Key ID provided by MKTME (Total Memory-Encryption Multi-Key) to isolate the virtual machine manager outside the trusted storage area. TDX can solve the data trust problem from the physical level, but the processor based on TDX is expensive. Therefore, in this embodiment, only TDX is provided in the virtual machine manager to save costs. The trusted storage area can be obtained by partitioning from the trusted memory in the TDX trust domain.

[0019] It should be noted that multiple TDX-based virtual machines are created in the virtual machine manager. That is to say, each virtual machine has its own corresponding trusted storage area, and the relevant data of each virtual machine has achieved trust based on TDX. Each server with a communication connection to the virtual machine manager is used to run user tasks. After the generated user data is screened, it will be sent as data to be encrypted to the virtual machine manager for storage. In one implementation, the creation process of any virtual machine includes: determining an available trusted storage area (i.e., an idle trusted storage area); creating the current virtual machine in the available trusted storage area; generating a key corresponding to the current virtual machine based on the creation timestamp, identification code (i.e., UUID), and virtual machine identification information (i.e., virtual machine ID) of the current virtual machine. Specifically, the creation timestamp, identification code, and virtual machine identification information can be concatenated to obtain the key.

[0020] S102. Select idle virtual machines from multiple virtual machines according to the connection request, and bind the selected virtual machines to each server respectively; wherein, each virtual machine corresponds to a different key.

[0021] In one implementation, binding the selected virtual machines to each server respectively includes: binding the virtual machine identification information of each selected virtual machine to the server identification information of each server one by one. The virtual machine identification information includes information such as virtual machine IP and virtual machine code; the server identification information includes information such as server IP and server device code.

[0022] S103. If the data to be encrypted sent by the target server in each server is received, in the target virtual machine bound to the target server, use the key corresponding to the target virtual machine to encrypt the data to be encrypted, and store the encrypted ciphertext in the trusted storage area to which the target virtual machine belongs.

[0023] In one implementation, using the key corresponding to the target virtual machine to encrypt the data to be encrypted in the target virtual machine bound to the target server includes: running the target virtual machine in the trusted storage area, and enabling the target virtual machine to encrypt the data to be encrypted using the key. The data to be encrypted is obtained by the target server filtering its own global data to be stored based on its own exclusive data filtering policy. The data filtering policies in different servers can be the same or different.

[0024] To ensure the correctness of the data to be encrypted during the transmission process, before encrypting the data to be encrypted with the key corresponding to the target virtual machine in the target virtual machine bound to the target server, it further includes: verifying the data to be encrypted; if the verification passes, execute the step of encrypting the data to be encrypted with the key corresponding to the target virtual machine in the target virtual machine bound to the target server and other subsequent steps. If the verification fails, send a retransmission message to the target server to enable the target server to resend the data to be encrypted, and execute the step of verifying the data to be encrypted and other subsequent steps until the verification passes.

[0025] In one example, the process by which the target server obtains the data stored therein from the virtual machine manager includes: the target server sending a data acquisition request to the virtual machine manager, the virtual machine manager querying based on this request to obtain the corresponding data ciphertext in the trusted storage area to which the target virtual machine belongs, decrypting the data ciphertext to obtain the data plaintext, and returning the data plaintext to the target server, thereby enabling flexible query of important data. Correspondingly, the process by which the target server updates the data stored in the virtual machine manager includes: the target server sending a data update request to the virtual machine manager, the virtual machine manager updating the corresponding data ciphertext in the trusted storage area to which the target virtual machine belongs based on this request, and returning an update completion message to the target server, thereby enabling flexible update of the encrypted data in the virtual machine manager.

[0026] It can be seen that the virtual machine manager in this embodiment sets different keys for different virtual machines, and for the data to be encrypted sent by each server, based on the target virtual machine bound to the corresponding server, encrypts the data to be encrypted with the key corresponding to the target virtual machine, and stores the encrypted ciphertext in the trusted storage area to which the target virtual machine belongs. In this solution, each virtual machine corresponds to a different encryption key, and the data of different virtual machines is stored in the same virtual machine manager in ciphertext form. The data security risk of a single virtual machine will not affect the data of other virtual machines, improving the security of all virtual machine data under the virtual machine manager.

[0027] Please refer to Figure 2, a server SUT0 is set up in the intranet area as the master console, where TDX-based deployment is performed to protect the important user data in all servers within the local area network. Specifically, data screening policies are set in each of the servers SUT1 - SUT4 within the local area network to screen important data from the globally to-be-stored data in the corresponding server as the data to be encrypted; the servers SUT1 - SUT4 report the screened important data to the master console through the TCP / IP network. After the master console receives the data, it uses the TDX deployment environment to perform data encryption processing. After the data encryption processing, the encrypted data is saved locally. When the user updates this data, the updated data is actively reported to the master console, and the master console updates the corresponding stored data.

[0028] In this embodiment, multiple virtual machines are provided in the master console, and one virtual machine is bound to one server. A specific data encryption and storage process includes: the server SUT1 sends a connection request to the master console SUT0. After the master console SUT0 receives the connection request, it binds a virtual machine ID to the server SUT1 and responds and confirms to the server SUT1, so that the corresponding virtual machine in the master console SUT0 successfully establishes a connection with the server SUT1; the server SUT1 sends the data to be encrypted to the master console. After the virtual machine bound to the server SUT1 successfully verifies the data to be encrypted, the data to be encrypted is encrypted and stored in the trusted storage area corresponding to the virtual machine. If the data verification fails, an instruction is returned to the server SUT1, requiring the server SUT1 to re-transmit this data, and then re-verify it until the verification is successful before encrypting. The process for the server SUT1 to obtain the encrypted data is the opposite of the above process and will not be elaborated here.

[0029] It should be noted that in the TDX trusted domain, it is required that the key pair is globally unique to the virtual machine name to avoid duplication. Therefore, the key can include a timestamp, a UUID, and a virtual machine ID. UUID is the abbreviation of Universally Unique Identifier, which is a software construction standard and is also part of the Open Software Foundation organization in the field of distributed computing environments. For example: the composition of the key key of virtual machine 1: the creation time of virtual machine 1 + UUID1 + the ID of virtual machine 1; the composition of the key key of virtual machine 2: the creation time of virtual machine 2 + UUID2 + the ID of virtual machine 2. In this way, a data shielding wall is established between virtual machine 1 and virtual machine 2.

[0030] That is to say, the data between each virtual machine is isolated, namely: data sharing and exchange cannot be carried out between virtual machine 1, virtual machine 2, virtual machine 3, and virtual machine 4 pairwise, ensuring the security of data between different virtual machine services. The isolation of virtual machines is achieved by MKTME allocating different keys to different virtual machines. The key of the virtual machine is the key to TDX encryption, which is specifically hardware-encrypted jointly by the TDX CPU and memory. Correspondingly, from the user's perspective, the user data on the server corresponding to each virtual machine is isolated, ensuring the security of different user data.

[0031] In one example, a data processing flow includes: Step1: Deploy the master TDX server and enable the TDX function.

[0032] Specifically, deploy a server SUT0 based on the TDX function, and install the latest version of the CentOS system on it; then modify the grub.cfg startup item to enable the TDX function, compile the TDX installation package, install and create TDX.Repo, and then restart the operating system to confirm that the TDX function is enabled successfully.

[0033] Step2: Deploy the controlled servers and configure the network.

[0034] Deploy ordinary servers SUT1, SUT2, SUT3, etc., and install the latest version of the CentOS system on them respectively. Set the network address IP of the servers to ensure that the servers are successfully connected to the network.

[0035] Step3: Connect the network to achieve the interconnection between the master TDX server and the controlled servers.

[0036] Specifically, TCP / IP (Transmission Control Protocol / Internet Protocol), RDMA (Remote Direct Memory Access), etc. can be used to enable the controlled servers such as SUT1, SUT2, and SUT3 to successfully connect to SUT0.

[0037] Step4: Deploy the unique important data screening strategy in the controlled servers to perform TDX security protection on important user data.

[0038] Deploy the unique important data screening strategy in each ordinary server to extract the important user data therein, and then report the extracted data to SUT0 through the TCP / IP network. SUT0 encrypts and stores these data.

[0039] In this embodiment, the TDX function can be used to encrypt and store important data as needed, and the user data in different controlled servers is isolated from each other, which can prevent data leakage and loss and implement the data protection function.

[0040] Next, a data processing device provided by an embodiment of the present application will be introduced. A data processing device described below can be referred to each other with other embodiments described in this article.

[0041] See Figure 3 As shown, an embodiment of the present application discloses a data processing device, which is applied to a virtual machine manager. There are multiple virtual machines in the virtual machine manager, including: a receiving module, configured to receive connection requests sent by each server; a binding module, configured to select idle virtual machines from multiple virtual machines according to the connection requests, and respectively bind the selected virtual machines to each server; wherein, each virtual machine corresponds to a different key; a storage module, configured to, if receiving the data to be encrypted sent by a target server in each server, in the target virtual machine bound to the target server, encrypt the data to be encrypted by using the key corresponding to the target virtual machine, and store the obtained ciphertext in the trusted storage area to which the target virtual machine belongs.

[0042] In one implementation manner, the binding module is specifically configured to: one-to-one bind the virtual machine identification information of each selected virtual machine and the server identification information of each server.

[0043] In one implementation manner, the storage module is specifically configured to: run the target virtual machine in the trusted storage area, and enable the target virtual machine to encrypt the data to be encrypted by using the key.

[0044] In one implementation manner, before encrypting the data to be encrypted by using the key corresponding to the target virtual machine in the target virtual machine bound to the target server, it further includes: a verification module, configured to verify the data to be encrypted; if the verification passes, execute the step of encrypting the data to be encrypted by using the key corresponding to the target virtual machine in the target virtual machine bound to the target server and subsequent other steps. If the verification fails, send a retransmission message to the target server, so that the target server resends the data to be encrypted, and execute the step of verifying the data to be encrypted and subsequent other steps until the verification passes.

[0045] In one implementation manner, the creation process of any virtual machine includes: determining an available trusted storage area; creating the current virtual machine in the available trusted storage area; generating a key corresponding to the current virtual machine based on the creation timestamp, identification code, and virtual machine identification information of the current virtual machine.

[0046] In one embodiment, the data to be encrypted is obtained by the target server filtering its own globally stored data based on its own exclusive data filtering policy.

[0047] Among them, for the more specific working processes of each module and unit in this embodiment, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.

[0048] It can be seen that this embodiment provides a data processing device, which can enable each virtual machine to correspond to a different encryption key, and the data of different virtual machines is stored in the same virtual machine manager in ciphertext form. The data security risk of a single virtual machine will not affect the data of other virtual machines, improving the security of all virtual machine data under the virtual machine manager.

[0049] Next, an electronic device provided by an embodiment of the present application will be introduced. The electronic device described below can be referred to each other with other embodiments described in this article.

[0050] See Figure 4 As shown, an embodiment of the present application discloses an electronic device, including: a memory 401 for storing a computer program; a processor 402 for executing the computer program to implement the method disclosed in any of the foregoing embodiments.

[0051] In this embodiment, when the processor executes the computer program stored in the memory, the following steps can be specifically implemented: receiving connection requests sent by each server; selecting idle virtual machines from multiple virtual machines according to the connection requests, and binding the selected virtual machines to each server respectively; where each virtual machine corresponds to a different key; if receiving data to be encrypted sent by the target server among each server, in the target virtual machine bound to the target server, encrypting the data to be encrypted by using the key corresponding to the target virtual machine, and storing the encrypted ciphertext in the trusted storage area to which the target virtual machine belongs.

[0052] In this embodiment, when the processor executes the computer program stored in the memory, the following steps can be specifically implemented: binding the virtual machine identification information of each selected virtual machine and the server identification information of each server one by one.

[0053] In this embodiment, when the processor executes the computer program stored in the memory, the following steps can be specifically implemented: running the target virtual machine in the trusted storage area, and enabling the target virtual machine to encrypt the data to be encrypted by using the key.

[0054] In this embodiment, when the processor executes the computer program stored in the memory, the following steps may be specifically implemented: verifying the data to be encrypted; if the verification passes, then executing the step of encrypting the data to be encrypted with the key corresponding to the target virtual machine in the target virtual machine bound to the target server and subsequent other steps.

[0055] In this embodiment, when the processor executes the computer program stored in the memory, the following steps may be specifically implemented: if the verification fails, then sending a retransmission message to the target server to enable the target server to retransmit the data to be encrypted, and executing the step of verifying the data to be encrypted and subsequent other steps until the verification passes.

[0056] In this embodiment, when the processor executes the computer program stored in the memory, the following steps may be specifically implemented: determining an available trusted storage area; creating a current virtual machine in the available trusted storage area; generating a key corresponding to the current virtual machine based on the creation timestamp, identification code, and virtual machine identification information of the current virtual machine.

[0057] Further, an embodiment of the present application also provides an electronic device. Among them, the above-mentioned electronic device may be either a Figure 5 server as shown, or a Figure 6 terminal as shown. Figure 5 and Figure 6 are both structural diagrams of electronic devices shown according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation on the scope of use of the present application.

[0058] Figure 5 This is a schematic structural diagram of a server provided by an embodiment of the present application. The server may specifically include: at least one processor, at least one memory, a power supply, a communication interface, an input / output interface, and a communication bus. Among them, the memory is used to store a computer program, and the computer program is loaded and executed by the processor to implement the relevant steps in the data processing disclosed in any of the foregoing embodiments.

[0059] In this embodiment, the power supply is used to provide working voltage for each hardware device on the server; the communication interface can create a data transmission channel between the server and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface is used to obtain external input data or output data to the outside, and the specific interface type can be selected according to specific application needs, and no specific limitation is made here.

[0060] In addition, as a carrier for resource storage, the memory can be a read-only memory, a random access memory, a magnetic disk, an optical disc, etc. The resources stored thereon include an operating system, computer programs, data, etc. The storage method can be temporary storage or permanent storage.

[0061] Among them, the operating system is used to manage and control each hardware device and computer program on the server to enable the processor to perform operations and processing on the data in the memory. It can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer programs that can be used to complete the data processing methods disclosed in any of the foregoing embodiments, the computer programs can further include computer programs that can be used to complete other specific tasks. In addition to data such as update information of application programs, the data can also include data such as developer information of application programs.

[0062] Figure 6 A schematic structural diagram of a terminal provided by an embodiment of the present application. The terminal may specifically include, but is not limited to, a smart phone, a tablet computer, a notebook computer, a desktop computer, etc.

[0063] Generally, the terminal in this embodiment includes: a processor and a memory.

[0064] Among them, the processor may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor can be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor can also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor can be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor can also include an AI (Artificial Intelligence) processor, and the AI processor is used to process computational operations related to machine learning.

[0065] The memory may include one or more computer non-volatile storage media, which may be non-transitory. The memory may also include high-speed random access memory, as well as non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory is at least used to store the following computer programs. After the computer programs are loaded and executed by the processor, the relevant steps in the data processing method executed by the terminal side disclosed in any of the foregoing embodiments can be implemented. In addition, the resources stored in the memory may also include an operating system and data, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system may include Windows, Unix, Linux, etc. The data may include, but is not limited to, update information of the application program.

[0066] In some embodiments, the terminal may further include a display screen, an input / output interface, a communication interface, sensors, a power supply, and a communication bus.

[0067] Those skilled in the art can understand that Figure 6 the structure shown in

[0068] does not constitute a limitation on the terminal, and may include more or fewer components than those shown in the figure.

[0069] A non-volatile storage medium is used to store a computer program. When the computer program is executed by a processor, the data processing method disclosed in the foregoing embodiments is implemented. Among them, the non-volatile storage medium is a computer-readable non-volatile storage medium. As a carrier for storing resources, it may be a read-only memory, a random access memory, a disk, or an optical disc, etc. The resources stored thereon include an operating system, a computer program, and data, etc., and the storage method may be temporary storage or permanent storage.

[0070] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, the following steps may be specifically implemented: receiving connection requests sent by each server; selecting idle virtual machines from multiple virtual machines according to the connection requests, and binding the selected virtual machines to each server respectively; where each virtual machine corresponds to a different key; if encrypted data to be encrypted sent by a target server among each server is received, in the target virtual machine bound to the target server, the encrypted data to be encrypted is encrypted using the key corresponding to the target virtual machine, and the ciphertext obtained by encryption is stored in the trusted storage area to which the target virtual machine belongs.

[0071] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, the following steps may be specifically implemented: Bind the virtual machine identification information of each selected virtual machine to the server identification information of each server one by one.

[0072] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, the following steps may be specifically implemented: Run the target virtual machine in the trusted storage area, and enable the target virtual machine to encrypt the data to be encrypted using a key.

[0073] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, the following steps may be specifically implemented: Verify the data to be encrypted; if the verification passes, then execute the step of encrypting the data to be encrypted using the key corresponding to the target virtual machine in the target virtual machine bound to the target server and subsequent other steps.

[0074] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, the following steps may be specifically implemented: If the verification fails, send a retransmission message to the target server to enable the target server to re-send the data to be encrypted, and execute the step of verifying the data to be encrypted and subsequent other steps until the verification passes.

[0075] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, the following steps may be specifically implemented: Determine an available trusted storage area; create the current virtual machine in the available trusted storage area; generate a key corresponding to the current virtual machine based on the creation timestamp, identification code, and virtual machine identification information of the current virtual machine.

[0076] Next, a computer program product provided by an embodiment of the present application will be introduced. The computer program product described below may be referred to each other with other embodiments described herein.

[0077] A computer program product includes computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the data processing method disclosed above are implemented.

[0078] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments may be referred to each other.

[0079] The steps of the methods or algorithms described in connection with the embodiments disclosed herein may be implemented directly in hardware, in software modules executed by a processor, or in a combination thereof. The software modules may be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of non-volatile storage medium known in the art.

[0080] Specific examples are used in this article to illustrate the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A data processing method, characterized in that, Applied to a virtual machine manager, in which there are multiple virtual machines, including: Receiving connection requests sent by each server; Selecting idle virtual machines from the multiple virtual machines according to the connection requests, and respectively binding the selected virtual machines to each server; wherein, each virtual machine corresponds to a different key; If receiving the data to be encrypted sent by a target server among the servers, in the target virtual machine bound to the target server, encrypting the data to be encrypted by using the key corresponding to the target virtual machine, and storing the ciphertext obtained by encryption in the trusted storage area to which the target virtual machine belongs.

2. The method according to claim 1, wherein Respectively binding the selected virtual machines to each server includes: One-to-one binding the virtual machine identification information of each selected virtual machine and the server identification information of each server.

3. The method according to claim 1, characterized in that In the target virtual machine bound to the target server, encrypting the data to be encrypted by using the key corresponding to the target virtual machine includes: Running the target virtual machine in the trusted storage area, and enabling the target virtual machine to encrypt the data to be encrypted by using the key.

4. The method according to claim 1, wherein Before encrypting the data to be encrypted by using the key corresponding to the target virtual machine in the target virtual machine bound to the target server, further including: Verifying the data to be encrypted; If the verification passes, then execute the step of encrypting the data to be encrypted by using the key corresponding to the target virtual machine in the target virtual machine bound to the target server and subsequent other steps.

5. The method according to claim 4, characterized in that Further including: If the verification fails, then sending a retransmission message to the target server to enable the target server to re-send the data to be encrypted, and executing the step of verifying the data to be encrypted and subsequent other steps until the verification passes.

6. The method according to any one of claims 1 to 5, characterized in that, The creation process of any virtual machine includes: Determining an available trusted storage area; Creating the current virtual machine in the available trusted storage area; Generating a key corresponding to the current virtual machine based on the creation timestamp, identification code and virtual machine identification information of the current virtual machine.

7. The method according to any one of claims 1 to 5, characterized in that, The data to be encrypted is obtained by the target server filtering its own global data to be stored based on its own exclusive data filtering policy.

8. A data processing device, characterized in that, Applied to a virtual machine manager, in which there are multiple virtual machines, including: A receiving module, configured to receive connection requests sent by each server; A binding module, configured to select idle virtual machines from the multiple virtual machines according to the connection requests, and respectively bind the selected virtual machines to each server; wherein, each virtual machine corresponds to a different key; A storage module, configured to, if receiving the data to be encrypted sent by a target server among the servers, in the target virtual machine bound to the target server, encrypt the data to be encrypted by using the key corresponding to the target virtual machine, and store the ciphertext obtained by encryption in the trusted storage area to which the target virtual machine belongs.

9. An electronic device, characterized in that, Including: A memory, configured to store a computer program; A processor, configured to execute the computer program to implement the method according to any one of claims 1 to 7.

10. A non-volatile storage medium, characterized in that, For storing a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Virtual machine safety protection method and virtual machine safety protection device

    CN103023920A

  • Virtual machine disk data encryption and decryption method and device, equipment and storage medium

    CN113285804A

  • Security virtual machine starting method, related equipment and storage medium

    CN118467105A

  • Virtual machine safety isolation system under network environment

    WO2018000537A1