Cryptographic computing environment construction method based on virtualization

By combining virtual machine and container technology to build a two-layer virtualization architecture, the compatibility and scalability problems between virtualization technology and password computing environment are solved, resource utilization and system security are optimized, and an efficient and secure password computing environment is achieved.

CN120469766APending Publication Date: 2025-08-12NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510562961.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the prior art, virtualization technology is combined with a password computing environment with performance bottlenecks, compatibility issues and insufficient dynamic expansion capabilities, which affects the efficiency and security of password computing.

Method used

Using a combination of virtual machine technology and container technology, a two-layer virtualization architecture is built, and the isolation of virtual machines and the lightweight characteristics of containers is used to optimize resource utilization and enhance security, and improve system stability and compatibility through container security enhancement mechanisms.

Benefits of technology

It realizes a password computing environment with high resource utilization, strong security and high compatibility, supports dynamic expansion and flexible management, and improves the security and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120469766A_ABST
    Figure CN120469766A_ABST
Patent Text Reader

Abstract

The invention discloses a cryptographic computing environment construction method based on virtualization, which belongs to the field of cryptographic computing and comprises the following steps: step 1, a preparation stage: selecting a virtualization platform, an operating system and a container platform according to actual requirements of cryptographic computing; step 2, a construction stage: constructing an operation environment of cryptographic calculation; and step 3, a management stage: carrying out operation environment management so as to ensure safe and reliable operation of the password calculation operation environment. According to the invention, the resource utilization rate can be optimized, and the security and stability of the system can be enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cryptographic computing, and more specifically, to a method for constructing a cryptographic computing environment based on virtualization. Background Art

[0002] With the rapid development of global digitalization, information security has become a core issue concerning national security, economic development, and personal privacy protection. Cryptographic computing, as a crucial component of information security, is becoming increasingly important. Cryptographic computing is a technology that performs complex computations while protecting data privacy. It applies principles and methods related to the efficient and secure execution of data computations (encryption, decryption, authentication, and ciphertext computation) in cryptographic algorithms and protocols, targeting specific cryptographic applications. Cryptographic computing often involves complex cryptographic algorithms or protocols and requires significant computing resources. Furthermore, cryptographic protocols require parallel computing across multiple nodes, necessitating efficient parallel computing capabilities in the computing environment.

[0003] Virtualization technology can effectively utilize the resources of physical devices and improve resource utilization. It can also provide a well-isolated computing environment for cryptographic computations. Building a cryptographic computing environment based on virtualization technology ensures efficient execution of cryptographic computing tasks and effective protection of cryptographic data. However, current research on combining virtualization technology with cryptographic computing environment construction faces the following challenges:

[0004] (1) Performance bottleneck: Cryptographic calculations themselves require high computing resources, and combined with virtualization may further increase latency and resource consumption.

[0005] (2) Compatibility issues: The compatibility and interoperability between different virtualization platforms may affect the construction of the cryptographic computing environment.

[0006] (3) Dynamic scalability: How to dynamically adjust the configuration of virtualization resources and cryptographic computing when the load changes is an urgent problem to be solved. Summary of the Invention

[0007] The purpose of the present invention is to overcome the shortcomings of the existing technology and provide a method for constructing a cryptographic computing environment based on virtualization. It adopts a combination of virtual machine technology and container technology. The container provides the advantages of lightweight and rapid deployment, and the virtual machine technology provides a strong isolation and independent operating system environment. The combination of the two can solve the problem of constructing a cryptographic computing environment with low resource consumption and strong security isolation, which can not only optimize resource utilization, but also enhance the security and stability of the system.

[0008] The object of the present invention is achieved through the following solutions:

[0009] A method for constructing a cryptographic computing environment based on virtualization comprises the following steps:

[0010] Step 1, preparation phase: select the virtualization platform, operating system, and container platform based on the actual needs of cryptographic computing;

[0011] Step 2, construction phase: build the operating environment for cryptographic calculations;

[0012] Step 3, management phase: perform operating environment management to ensure the security and reliable operation of the cryptographic computing operating environment.

[0013] Furthermore, in step 2, the construction of the cryptographic computing operating environment specifically includes the following sub-steps:

[0014] S21, based on the selected virtualization platform, install the virtualization software and create a virtual machine according to the cryptographic calculation configuration requirements;

[0015] S22: Install container software, configure container network, and deploy container applications based on the selected container platform.

[0016] Furthermore, in step 3, the operation environment management specifically includes the following sub-steps:

[0017] Permission management: Manage the permissions for executing commands on the container platform to prevent the container platform from running in violation of regulations.

[0018] Furthermore, in step 3, the operation environment management specifically includes the following sub-steps:

[0019] Container management: Manage and control the virtual machines where containers run, and do not allow containers to run on unauthorized virtual machines.

[0020] Furthermore, in step 3, the operating environment management specifically includes the following sub-steps: Network management: control the network communication between containers and prohibit illegal communication.

[0021] Furthermore, in step S21, a host machine can deploy multiple virtual machines to build a virtualization layer, and the virtual machine configuration is configured with memory, CPU and disk according to actual computing power requirements.

[0022] Furthermore, in step S22, a container layer is constructed on a virtual machine according to the isolation and computing power requirements of the cryptographic application, and the deployment instances and quantity of the container application are adjusted as needed.

[0023] The beneficial effects of the present invention include:

[0024] (1) The present invention has the advantage of high resource utilization: by deploying multiple containers in a virtual machine, the resources of the hardware device are fully utilized and the overall computing density is improved.

[0025] (2) The present invention can build a highly secure computing environment: the isolation characteristics of the virtual machine effectively prevent the spread of security threats between containers and ensure the stable operation of the system.

[0026] (3) The present invention has the advantage of strong scalability: cryptographic applications are calculated in containers, and with the advantage of the scalability of container technology, efficient management and dynamic expansion and contraction of cryptographic applications can be achieved.

[0027] (4) The present invention has the advantage of high compatibility: it supports the construction of a cryptographic computing environment on general hardware devices and supports the coexistence of traditional cryptographic applications and containerized applications.

[0028] (5) The present invention designs a container security enhancement mechanism to improve the security protection capabilities of container images and container operations, providing a safe and reliable computing environment for cryptographic applications.

[0029] (6) The present invention designs a two-layer virtualization architecture. The first layer of virtualization is the virtual machine layer. Relying on the good isolation characteristics of the virtual machine, a relatively independent and secure operating environment is divided for the cryptographic application. The second layer of virtualization is the container layer. Taking advantage of the lightweight, programmable and schedulable characteristics of the container, the flexibility and compatibility of the deployment of the cryptographic application are improved. One host machine can deploy multiple virtual machines to build a virtualization layer, and the virtual machine configuration can be configured according to the actual computing power requirements for memory, CPU, and disk. On a virtual machine, a container layer can be built according to the isolation and computing power requirements of the cryptographic application, and the deployment instances and number of container applications can be adjusted as needed. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0031] Figure 1 This is a block diagram of the cryptographic computing environment system based on a two-layer virtualization architecture in an embodiment of the present invention;

[0032] Figure 2 This is a flowchart of the steps of a method for constructing a virtualized cryptographic computing environment system in an embodiment of the present invention. DETAILED DESCRIPTION

[0033] All features disclosed in all embodiments in this specification, or steps in all methods or processes implicitly disclosed, except for mutually exclusive features and / or steps, can be combined and / or expanded or replaced in any manner.

[0034] The specific implementation process of the present invention is as follows:

[0035] The invention introduces container technology into a virtualized environment, creating a two-tier virtualization architecture that leverages the advantages of containers (lightweight and rapid deployment) while retaining the secure isolation of virtual machines. Furthermore, the invention incorporates a container security enhancement mechanism that improves the security protection capabilities of container images and container operations, providing a secure and reliable computing environment for cryptographic applications.

[0036] Specifically, if Figure 1 and Figure 2 As shown, the present invention specifically designs a two-layer virtualization architecture. The first layer of virtualization is the virtual machine layer. Relying on the good isolation characteristics of the virtual machine, a relatively independent and secure operating environment is divided for the cryptographic application. The second layer of virtualization is the container layer. The lightweight, programmable, and schedulable characteristics of the container are used to improve the flexibility and compatibility of the deployment of cryptographic applications. One host machine can deploy multiple virtual machines to build a virtualization layer, and the virtual machine configuration can be configured for memory, CPU, and disk according to the actual computing power requirements. A container layer can be built on a virtual machine according to the isolation and computing power requirements of the cryptographic application, and the deployment instances and quantity of container applications can be adjusted as needed.

[0037] In other preferred embodiments, a method for constructing a cryptographic computing environment based on virtualization is provided, which includes a preparation phase, a construction phase, and a management phase.

[0038] Step 1, Preparation: During this stage, you must select a virtualization platform, operating system, and container platform based on your cryptographic computing needs. Specifically, virtualization platforms include VMware, QEMU-KVM, and VirtualBox; operating systems include Ubuntu, CentOS, and Windows; and container platforms include Docker and Containerd.

[0039] Step 2, construction phase: The construction phase requires building a running environment for cryptographic calculations.

[0040] 1) Install the virtualization software based on the selected virtualization platform and create a virtual machine according to the cryptographic calculation configuration requirements.

[0041] 2) Install the container software and configure the container network based on the selected container platform.

[0042] Step 3, management stage: To ensure the security and reliable operation of the cryptographic computing operating environment, it is necessary to design a trusted startup and trusted operation mechanism for the container.

[0043] 1) Container image security

[0044] a) Technical Principle

[0045] Digital Signature: Digitally sign container images to ensure the authenticity of the image source. Use tools such as Docker Content Trust (DCT) to sign images.

[0046] Hash verification: When loading an image, verify the image's hash value to ensure that the image has not been tampered with.

[0047] b) Implementation steps:

[0048] Configure image signature: Use OpenSSL to generate a key pair and output it to the file mykey.pem;

[0049] Container image signature: Use the docker trust sign-key mykey.pem command to sign the container image;

[0050] Verify the container signature image: Before starting the container, use the docker trust inspect command to verify the integrity of the container image.

[0051] 2) Container startup security

[0052] a) Integrity Verification: Enable the secure boot function in the container daemon process and configure the secure boot script to automatically perform verification when the container starts to ensure that key processes and files have not been tampered with.

[0053] b) Permission Verification: When creating a container image, a constraint configuration file must be added to the container image. This configuration file specifies the VM IDs that the container can run. When the container starts, the VM ID is obtained and compared with the ID in the constraint configuration file. If the ID is found, the container is allowed to start normally; otherwise, the container is not allowed to start normally.

[0054] It should be noted that within the scope of protection defined in the claims of the present invention, the following embodiments can be combined and / or expanded or replaced in any logical way from the above specific implementation methods, such as disclosed technical principles, disclosed technical features or implicitly disclosed technical features.

[0055] Example 1

[0056] A method for constructing a cryptographic computing environment system based on virtualization includes the following steps:

[0057] Step 1, preparation phase: select the virtualization platform, operating system, and container platform based on the actual needs of cryptographic computing;

[0058] Step 2, construction phase: build the operating environment for cryptographic calculations;

[0059] Step 3, management phase: perform operating environment management to ensure the security and reliable operation of the cryptographic computing operating environment.

[0060] Example 2

[0061] Based on Example 1, in step 2, the construction of the cryptographic computing operating environment specifically includes the following sub-steps:

[0062] S21, based on the selected virtualization platform, install the virtualization software and create a virtual machine according to the cryptographic calculation configuration requirements;

[0063] S22: Install container software, configure container network, and deploy container applications based on the selected container platform.

[0064] Example 3

[0065] On the basis of Example 1, in step 3, the operation environment management specifically includes the following sub-steps:

[0066] Permission management: Manage the permissions for executing commands on the container platform to prevent the container platform from running in violation of regulations.

[0067] Example 4

[0068] On the basis of Example 1, in step 3, the operation environment management specifically includes the following sub-steps:

[0069] Container management: Manage and control the virtual machines where containers run, and do not allow containers to run on unauthorized virtual machines.

[0070] Example 5

[0071] Based on Example 1, in step 3, the operating environment management is performed, specifically including the following sub-steps: Network management: Control network communications between containers and prohibit illegal communications.

[0072] Example 6

[0073] Based on Example 2, in step S21, a host machine can deploy multiple virtual machines to build a virtualization layer, and the virtual machine configuration is configured with memory, CPU and disk according to actual computing power requirements.

[0074] Example 7

[0075] Based on Example 6, in step S22, a container layer is constructed on a virtual machine according to the isolation and computing power requirements of the cryptographic application, and the deployment instances and quantity of the container application are adjusted as needed.

[0076] The units involved in the embodiments of the present invention may be implemented in software or hardware, and the units described may also be provided in a processor. In some cases, the names of these units do not limit the units themselves.

[0077] According to one aspect of an embodiment of the present invention, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in the various optional implementations described above.

[0078] As another aspect, embodiments of the present invention further provide a computer-readable medium, which may be included in the electronic device described in the above embodiments, or may exist independently and not incorporated into the electronic device. The computer-readable medium carries one or more programs, and when executed by the electronic device, the electronic device implements the methods described in the above embodiments.

Claims

1. A method for constructing a cryptographic computing environment based on virtualization, characterized in that: The steps include: Step 1, preparation phase: select the virtualization platform, operating system, and container platform based on the actual needs of cryptographic computing; Step 2, construction phase: build the operating environment for cryptographic calculations; Step 3, management phase: perform operating environment management to ensure the security and reliable operation of the cryptographic computing operating environment.

2. The method for constructing a virtualized cryptographic computing environment according to claim 1, wherein: In step 2, the construction of the cryptographic computing operating environment specifically includes the following sub-steps: S21, install virtualization software based on the selected virtualization platform and create a virtual machine based on the cryptographic calculation configuration requirements; S22: Install container software, configure container network, and deploy container applications based on the selected container platform.

3. The method for constructing a virtualized cryptographic computing environment according to claim 1, wherein: In step 3, the operation environment management is performed, which specifically includes the following sub-steps: Permission management: Manage the permissions for executing commands on the container platform to prevent the container platform from running in violation of regulations.

4. The method for constructing a cryptographic computing environment based on virtualization according to claim 1, characterized in that: In step 3, the operation environment management is performed, which specifically includes the following sub-steps: Container management: Manage and control the virtual machines where containers run, and do not allow containers to run on unauthorized virtual machines.

5. The method for constructing a cryptographic computing environment based on virtualization according to claim 1, wherein: In step 3, the operating environment management is performed, which specifically includes the following sub-steps: Network management: Control the network communication between containers and prohibit illegal communication.

6. The method for constructing a cryptographic computing environment based on virtualization according to claim 2, characterized in that: In step S21, a host machine can deploy multiple virtual machines to build a virtualization layer, and the virtual machine configuration is configured with memory, CPU and disk according to actual computing power requirements.

7. The method for constructing a virtualized cryptographic computing environment according to claim 6, wherein: In step S22, a container layer is constructed on a virtual machine according to the isolation and computing power requirements of the cryptographic application, and the deployment instances and quantity of the container application are adjusted as needed.

Citation Information

Cited By

  • Virtualization simulation system construction method for testing commercial password software

    CN121412136A