Data storage encryption service resource allocation method and device, electronic equipment and computer program product

By unifying the management of encryption service resources through a data storage encryption system, monitoring and analyzing the actual usage of encryption services in business systems in real time, and adaptively allocating resources, the problem of unreasonable resource allocation in existing technologies is solved, and more efficient and flexible encryption service resource allocation is achieved.

CN121887378APending Publication Date: 2026-04-17CHINA SATENT NETWORK APPLICATION RESEARCH INSTITUTE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA SATENT NETWORK APPLICATION RESEARCH INSTITUTE CO LTD
Filing Date
2024-10-15
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

The existing data storage encryption service resource allocation scheme is not scientific enough and the resource allocation is not reasonable enough, resulting in the inefficient use of encrypted computing resources and insufficient flexibility.

Method used

The data storage encryption system provides unified management of encryption service resources, real-time monitoring and analysis of the actual usage of encryption services in business systems, and adaptive resource allocation to meet the diverse needs of different business systems.

Benefits of technology

It improves the rationality and flexibility of encryption service resource allocation, meets the encryption service needs of different business systems, reduces the cost of building cryptographic infrastructure on the business side, and improves the efficiency and rationality of data storage encryption services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887378A_ABST
    Figure CN121887378A_ABST
Patent Text Reader

Abstract

The invention discloses a data storage encryption service resource allocation method and device, electronic equipment and a computer program product, the method is executed by a data storage encryption system, and the method comprises the following steps: receiving a data storage encryption service application of a business system, including business system information and encryption service information; determining encryption service actual use information of the business system according to the data storage encryption service application, wherein the encryption service actual use information is obtained by monitoring and analyzing encryption service use data of the business system in a preset monitoring period; and distributing encryption service resources for the business system according to the data storage encryption service application and the encryption service actual use information. According to the method, the distribution of the encryption service resources is uniformly managed through the data storage encryption system, and the actual use condition of the encryption service of the business system can be automatically monitored and analyzed, so that the encryption service resources are adaptively distributed, the distribution rationality and flexibility are improved, and the encryption requirements of different business systems are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of encryption service management technology, and in particular to a method, apparatus, electronic device, and computer program product for allocating data storage encryption service resources. Background Technology

[0002] When business systems use data storage encryption computing resources in a traditional way, although all business systems use data storage encryption services through the cryptographic operation interface provided by the hardware device, some applications encrypt quickly while others encrypt slowly. This situation occurs because multiple application systems need to share the data storage encryption service capabilities provided by the hardware resources in a preemptive manner, resulting in the inefficient use of encryption computing resources.

[0003] Therefore, the existing data storage encryption service resource allocation scheme is not scientific enough, the resource allocation is not reasonable enough, and the business system can only call the computing interface and use the encryption service in a fixed pattern, which requires improvement in flexibility. Summary of the Invention

[0004] This application provides a method, apparatus, electronic device, and computer program product for allocating data storage encryption service resources, so as to improve the rationality and flexibility of data storage encryption service resource allocation.

[0005] The embodiments of this application adopt the following technical solutions:

[0006] In a first aspect, embodiments of this application provide a method for allocating data storage encryption service resources, wherein the method for allocating data storage encryption service resources is executed by a data storage encryption system, and the method for allocating data storage encryption service resources includes:

[0007] Receive a data storage encryption service application from a business system, wherein the data storage encryption service application includes business system information and encryption service information;

[0008] Based on the data storage encryption service application, the actual usage information of the encryption service of the business system obtained by analysis within a preset monitoring period is determined. The actual usage information of the encryption service is obtained by monitoring and analyzing the encryption service usage data of the business system within the preset monitoring period.

[0009] Based on the data storage encryption service application and the actual usage information of the encryption service of the business system, encryption service resources are allocated to the business system so that the business system can use the encryption service resources to encrypt data storage.

[0010] Optionally, determining the actual usage information of the encryption service of the business system obtained from analysis within a preset monitoring period based on the data storage encryption service application includes:

[0011] Within a preset monitoring period, acquire data on the use of encrypted services by various business systems;

[0012] The encryption service usage data of each of the aforementioned business systems are monitored and analyzed to obtain the actual encryption service usage information of each business system within the preset monitoring period.

[0013] Based on the actual usage information of encryption services of each business system within the preset monitoring period and the business system identifier carried in the data storage encryption service application, the actual usage information of encryption services of the business system corresponding to the business system identifier is determined.

[0014] Optionally, allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes:

[0015] The application for the data storage encryption service shall be approved;

[0016] If the approval is granted, the encryption service resources corresponding to the business system are generated based on the actual usage information of the encryption service of the business system, and the approval message is sent to the business system.

[0017] The business system is granted permission to use the encryption service resources, so that the business system can use the encryption service resources to encrypt data storage.

[0018] Optionally, allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes:

[0019] After sending an approval message to the business system, the system receives a sub-application system creation request initiated by the business system, so that the business system can create a sub-application system through the data storage encryption system.

[0020] Receive the encryption service resource allocation request from the business system, wherein the encryption service resource allocation request refers to the request to allocate encryption service resources to the sub-application system created by the business system;

[0021] The sub-application system is granted permission to use the encryption service resource according to the encryption service resource allocation request, so that the sub-application system can use the encryption service resource to encrypt data storage.

[0022] Optionally, the method for allocating the data storage encryption service resources further includes:

[0023] Determine the maximum frequency value of the data storage encryption service used by the sub-application system. The maximum frequency value of the data storage encryption service is based on the specification of the business system or calculated based on the data used by the encryption service of the business system.

[0024] The maximum frequency value of the data storage encryption service used by the sub-application system is stored.

[0025] Optionally, the method for allocating the data storage encryption service resources further includes:

[0026] Receive data storage encryption requests from sub-application systems;

[0027] Based on the data storage encryption request, query the maximum frequency value of the data storage encryption service used by the sub-application system;

[0028] The frequency at which the sub-application system uses the data storage encryption service is controlled based on the maximum frequency value of the sub-application system's use of the data storage encryption service and the number of times the sub-application system has currently used the data storage encryption service.

[0029] Optionally, allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes:

[0030] If the newly created sub-application system of the business system is of a different type than the already created sub-application system, then an encryption service resource with a different encryption service resource than the one corresponding to the already created sub-application system will be generated for the newly created sub-application system.

[0031] If the data storage encryption system provides data storage encryption services for multiple different business systems, then different encryption service resources are generated for the same sub-application systems of different business systems.

[0032] Optionally, after receiving a data storage encryption service request from a business system, the method for allocating the data storage encryption service resources further includes:

[0033] Determine whether the data storage encryption service application carries encryption service designated allocation information, wherein the encryption service designated allocation information includes at least one of a designated amount of encryption service resources and a designated allocation method;

[0034] If the data storage encryption service application contains encryption service allocation information and the analysis conditions of the preset monitoring period are not currently triggered, encryption service resources are allocated to the business system according to the encryption service allocation information.

[0035] Optionally, the step of allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes:

[0036] Based on the data storage encryption service application and the actual encryption service usage information of the business system, the usage quota and usage method of the encryption service resources are allocated to the business system, including exclusive mode and shared mode.

[0037] Secondly, embodiments of this application also provide a data storage encryption service resource allocation device, wherein the data storage encryption service resource allocation device is applied to a data storage encryption system, and the data storage encryption service resource allocation device includes:

[0038] The first receiving unit is used to receive a data storage encryption service application from a business system, wherein the data storage encryption service application includes business system information and encryption service information.

[0039] The first determining unit is used to determine, based on the data storage encryption service application, the actual usage information of the encryption service of the business system obtained by analysis within a preset monitoring period. The actual usage information of the encryption service is obtained by monitoring and analyzing the encryption service usage data of the business system within the preset monitoring period.

[0040] The allocation unit is used to allocate encryption service resources to the business system based on the data storage encryption service application and the actual usage information of the encryption service of the business system, so that the business system can use the encryption service resources to perform data storage encryption.

[0041] Thirdly, embodiments of this application also provide an electronic device, including:

[0042] Processor; and

[0043] A memory configured to store computer-executable instructions, which, when executed, cause the processor to perform any of the aforementioned methods for allocating data storage encryption service resources.

[0044] Fourthly, embodiments of this application also provide a computer program product, including a computer program or instructions, which, when executed by a processor, implement the allocation method for data storage encryption service resources described above.

[0045] The above-mentioned at least one technical solution adopted in this application embodiment can achieve the following beneficial effects: The data storage encryption service resource allocation method of this application embodiment is executed by the data storage encryption system. First, it receives the data storage encryption service application from the business system, which includes business system information and encryption service information. Then, based on the data storage encryption service application, it determines the actual encryption service usage information of the business system obtained from analysis within a preset monitoring period. The actual encryption service usage information is obtained after monitoring and analyzing the encryption service usage data of the business system within the preset monitoring period. Finally, based on the data storage encryption service application and the actual encryption service usage information of the business system, it allocates encryption service resources to the business system so that the business system can use the encryption service resources for data storage encryption. The data storage encryption service resource allocation method of this application embodiment manages the allocation of encryption service resources in a unified manner through the data storage encryption system. It can automatically monitor and analyze the actual usage of encryption services in the business system, and adaptively and flexibly allocate encryption service resources according to the actual usage of encryption services. This improves the rationality and flexibility of encryption service resource allocation and meets the diverse encryption service usage needs of different business systems. Attached Figure Description

[0046] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0047] Figure 1 This is a flowchart illustrating a method for allocating data storage encryption service resources according to an embodiment of this application.

[0048] Figure 2 This is a schematic diagram illustrating the resource allocation process for a data storage encryption service in an embodiment of this application.

[0049] Figure 3 This is a schematic diagram of the structure of a data storage encryption service resource allocation device according to an embodiment of this application;

[0050] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation

[0051] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0052] The technical solutions provided by the various embodiments of this application are described in detail below with reference to the accompanying drawings.

[0053] To facilitate understanding of the embodiments of this application, an example of an existing encryption service resource allocation scheme is provided:

[0054] Suppose there are 10 business systems using the data storage encryption service, namely system A, system B... system J, sharing 100Mbps of encryption service computing resources. System A is the first to request computing resources and is allocated 50Mbps of computing resources. System B is the second to request computing resources and is allocated 30Mbps of computing resources. The remaining 20Mbps of computing resources are allocated to systems C through J according to the time of the request. After completing its first task, when system A, which was the first to request computing resources, requests computing resources again, it will compete with systems B through J for resources again.

[0055] It can be seen that the current resource scheduling methods for data storage encryption services are not scientific and the resource allocation is not reasonable.

[0056] Based on this, embodiments of this application provide a method for allocating data storage encryption service resources, such as... Figure 1 The diagram illustrates a flowchart of a method for allocating data storage encryption service resources according to an embodiment of this application. The method is executed by a data storage encryption system and includes at least the following steps S110 to S130:

[0057] Step S110: Receive a data storage encryption service application from the business system. The data storage encryption service application includes business system information and encryption service information.

[0058] The data storage encryption service resource allocation method in this application embodiment is executed by a data storage encryption system that uniformly manages data storage encryption service resources. When allocating data storage encryption service resources, it is necessary to first receive a data storage encryption service application initiated by a business system. The business system in this application embodiment can be various types of business systems such as traditional network architecture, public cloud architecture, and private cloud architecture.

[0059] A data storage encryption service application indicates that a business system currently requires encryption service resources. The application must include business system information and related encryption service information. Business system information may include, for example, the business system name and ID. Related encryption service information may include, for example, the type of encryption service to be used, traffic usage, usage duration, and service lifecycle. It should be noted that the specific dimensions of information included are flexible and can be set by the user according to actual business needs; no specific limitations are imposed here.

[0060] Step S120: Based on the data storage encryption service application, determine the actual usage information of the encryption service of the business system obtained by analysis within a preset monitoring period. The actual usage information of the encryption service is obtained by monitoring and analyzing the encryption service usage data of the business system within the preset monitoring period.

[0061] Although business systems can include information related to the encryption service resources they need when initiating a data storage encryption service application, the encryption service resource information specified by the business system is not always reasonable. Therefore, this application embodiment conducts regular and dynamic monitoring and analysis of the actual use of encryption service resources by each business system that needs to use encryption services in the production environment, thereby analyzing the actual use and characteristics of encryption service resources by the business system, which serves as the main basis for subsequent resource allocation.

[0062] The length of the monitoring period can be flexibly set according to the characteristics of different business systems using encryption services and the needs of actual scenarios, and no specific limit is made here.

[0063] Step S130: Based on the data storage encryption service application and the actual usage information of the encryption service of the business system, allocate encryption service resources to the business system so that the business system can use the encryption service resources to perform data storage encryption.

[0064] The business system information and encryption service information in the data storage encryption service application reflect the subjective needs of the business system itself, while the actual usage information of the encryption service obtained from monitoring and analysis reflects the more objective needs of the business system. Therefore, by comprehensively considering the data storage encryption service application and the actual usage information of the encryption service, encryption service resources can be allocated to the business system more flexibly, while meeting the needs of the business system as much as possible.

[0065] The data storage encryption service resource allocation method of this application embodiment manages the allocation of encryption service resources in a unified manner through the data storage encryption system. It can automatically monitor and analyze the actual usage of encryption services in business systems, and adaptively and flexibly allocate encryption service resources according to the actual usage of encryption services. This improves the rationality and flexibility of encryption service resource allocation and meets the diverse encryption service usage needs of different business systems.

[0066] In some embodiments of this application, determining the actual usage information of the encryption service of the business system obtained from the data storage encryption service application within a preset monitoring period includes: acquiring encryption service usage data of each business system within the preset monitoring period; monitoring and analyzing the encryption service usage data of each business system to obtain the actual usage information of the encryption service of each business system within the preset monitoring period; and determining the actual usage information of the encryption service of the business system corresponding to the business system identifier based on the actual usage information of the encryption service of each business system within the preset monitoring period and the business system identifier carried in the data storage encryption service application.

[0067] In analyzing the actual usage information of encryption services in various business systems, this application embodiment can collect encryption service usage data of various business systems within a certain period. The encryption service usage data mainly includes basic information such as business system name and business system ID, as well as encryption service application data and actual usage data of encryption service resources in a period, such as the amount of encryption service resources applied for each time, the amount of encryption service resources actually used each time, the number of times encryption service resources are actually used, the usage frequency, encryption service category, etc.

[0068] After collecting a certain amount of encryption service usage data, certain analytical strategies can be employed to analyze this data, revealing the actual usage and characteristics of encryption services in the business system, as well as the requirements for encryption service resources. The analytical methods used can be traditional statistical methods, or machine learning algorithms or deep learning models. Those skilled in the art can flexibly choose the appropriate analytical method based on existing technology and actual needs; no specific limitations are imposed here.

[0069] This application embodiment can monitor and analyze the actual usage information of encryption services for each business system according to different monitoring cycles based on the characteristics of encryption service usage by different business systems, and update it regularly. Based on the maintained actual usage information of encryption services for multiple business systems and the business system ID information carried in the currently received data storage encryption service application, the actual usage information of encryption services for the current business system can be obtained.

[0070] This application embodiment automatically monitors each business system using the data storage encryption system. By continuously learning from the traffic consumed by the business system and the type of the business system, an adaptive system for allocating data storage encryption services can be formed, thereby enabling the elastic supply of data storage encryption service resources to the business system according to actual needs.

[0071] In some embodiments of this application, allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes: approving the data storage encryption service application; if the application is approved, generating encryption service resources corresponding to the business system based on the actual encryption service usage information of the business system, and sending an approval message to the business system; and allocating permission for the business system to use the encryption service resources, so that the business system can use the encryption service resources for data storage encryption.

[0072] To ensure the security of encrypted service resource usage, this embodiment of the application can first approve data storage encryption service applications initiated by business systems before allocating encryption service resources. This primarily verifies the legitimacy of the business system's identity and whether it has the authority to use the encryption service, serving as access control for the business system. The specific verification method can be based on existing legitimacy verification methods and is not specifically limited here. If the data storage encryption service application is approved, it means that the business system can use the services provided by the data encryption service system, and an approval message can be sent to the business system. Conversely, if the application is rejected, the data storage encryption system will notify the business system of the rejection message.

[0073] If approved, corresponding virtual encryption service resources can be generated for the business system based on its actual usage of encryption services. Since the virtual storage encryption service needs to run on cryptographic devices, it is also necessary to allocate cryptographic device resources to support cryptographic operations for the business system according to the service specifications, and bind the cryptographic devices to the generated virtual storage encryption service. Finally, permissions to use the virtual encryption service resources are granted to the business system, enabling it to subsequently use the allocated virtual encryption service resources for encryption.

[0074] For example, if the current business system requests an encryption service resource quota of 30Mbps, but the monitoring and analysis results show that the actual demand for encryption service resources of the business system is 20Mbps, that is, 20Mbps is sufficient to meet the encryption needs of the business system, then a virtual encryption service resource of 20Mbps can be generated for the business system based on the remaining encryption service resources for its subsequent encryption use.

[0075] In some embodiments of this application, allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes: after sending an approval message to the business system, receiving a sub-application system creation request initiated by the business system, so that the business system can create a sub-application system through the data storage encryption system; receiving an encryption service resource allocation request from the business system, wherein the encryption service resource allocation request refers to a request to allocate encryption service resources to the sub-application system created by the business system; and allocating permission for the sub-application system to use the encryption service resources according to the encryption service resource allocation request, so that the sub-application system can use the encryption service resources for data storage encryption.

[0076] As mentioned above, in this embodiment of the application, when allocating encryption service resources to the business system, the data storage encryption service application initiated by the business system can be approved first, and then a notification message of the approval result can be sent to the business system.

[0077] Since business systems are typically composed of many sub-functional modules, and different modules may have different encryption requirements, if the business system's application is approved, the business system can further create and manage the encryption service requirements of the sub-application systems by calling the Human-Machine Interface (HMI) of the application management module of the data storage encryption system. This is an efficient and secure method. The business system creates the sub-application system by calling the HMI of the application management module and inputting the basic application information and other application information. The basic application information can include the application system name, application system type, and other application information defined by the business system. It can also specify the types of encryption services and encryption levels required by the sub-application system.

[0078] After the sub-application system is created, the business system can further call the HMI of the application management module of the data storage encryption system to initiate an encryption service resource allocation request to the application management module. The encryption service resource allocation request here refers to the request to allocate the amount of data storage encryption service resources needed by the newly created sub-application system. The allocation method can be exclusive allocation or shared allocation. The specific allocation method can be specified by the business system. For example, some critical system business and non-critical business systems can be specified. However, the data storage encryption system will also monitor the actual usage of these business systems to determine a more reasonable allocation method.

[0079] Upon receiving the aforementioned request for allocation of encrypted service resources, the system can further allocate access to and use of the generated virtual encrypted service resources to the sub-application systems created by the business system. That is, in this embodiment, the creation of sub-application systems and the generation of virtual encrypted services with a fixed total capacity for the business system can be parallel processes. Once the data storage encryption system approves the request, it can generate the corresponding virtual encrypted service resources for the business system without waiting for the creation of the sub-application systems. Similarly, once the business system receives the approval message, it can initiate a request to create the sub-application systems without waiting for the resource generation result from the data encryption storage service system, thereby improving the overall process efficiency.

[0080] In some embodiments of this application, before allocating access to and use of a specified storage encryption service to a sub-application system, the data storage encryption system may also determine the existing available quota of the storage encryption service capability. When the available quota of the storage encryption service capability is greater than or equal to the maximum percentage of storage encryption service used by the sub-application system, the data storage encryption system may allocate access to and use of the specified storage encryption service to the sub-application system in the manner of exclusive allocation or shared allocation, and report the application allocation amount information to the application management module.

[0081] Conversely, the data storage encryption system will report the failure of allocating the amount in an exclusive manner to the business system. The problem can be resolved by expanding the encryption system's equipment, changing the allocation method of the business system, or adjusting the maximum percentage of storage encryption service used by the application system. Then, the data storage encryption system will allocate access and use permissions for the specified storage encryption service to the application system.

[0082] In this application embodiment, the information for allocating amounts to a sub-application system may include application information, service information, allocation method, and allocation amount value. Application information includes application ID and application name; service information includes virtual service ID, service type, and service specification; allocation method refers to exclusive allocation amount or shared allocation amount; allocation amount value, if it is exclusive allocation, needs to specify a value of 1% to 100%, and if it is shared allocation method, no allocation amount value needs to be specified.

[0083] In some embodiments of this application, the method for allocating data storage encryption service resources further includes: determining the maximum frequency value of the data storage encryption service used by the sub-application system, wherein the maximum frequency value of the data storage encryption service is based on the specification of the business system or calculated based on the encryption service usage data of the business system; and storing the maximum frequency value of the data storage encryption service used by the sub-application system.

[0084] After receiving a request for encryption service resource allocation, the application management module can further determine the maximum frequency at which the sub-application system uses the data storage encryption service. The maximum frequency refers to the maximum number of times the sub-application system uses the data storage encryption service per unit of time. This maximum frequency can be specified by the business system based on the sub-application system's usage needs, or it can be obtained by the data encryption storage system monitoring and analyzing the encryption service usage data of the sub-application system. For example, it can monitor the storage encryption service usage of the sub-application system over a week, including the number, frequency, and processing time of encryption requests. Simultaneously, it can monitor the encryption service system's performance metrics, such as response time, throughput, and resource utilization, to assess whether the encryption service system is approaching or has reached its performance limits. Finally, the calculated maximum frequency of the sub-application system's encryption service usage is stored as a basis for subsequent dynamic adjustment of the encryption service usage frequency of the sub-application system.

[0085] It should be noted that when the available quota of data storage encryption service capability is less than the maximum percentage of storage encryption service used by the sub-application system, the maximum frequency value of storage encryption service capability that the sub-application system can use can be calculated by the allocation method and the amount of encryption service resources allocated. For example, under the shared allocation method, if it was originally required to use 100Mbps to complete encryption for 1 day, it can now be used for 5 days to complete encryption at 100Mbps, and the storage encryption service quota already used by the existing application system will be recalculated.

[0086] In some embodiments of this application, the method for allocating data storage encryption service resources further includes: receiving a data storage encryption request from a sub-application system; querying the maximum frequency value of the sub-application system using the data storage encryption service based on the data storage encryption request; and controlling the frequency of the sub-application system using the data storage encryption service based on the maximum frequency value of the sub-application system using the data storage encryption service and the number of times the sub-application system has currently used the data storage encryption service.

[0087] Based on the aforementioned embodiments, when a sub-application system needs to access the data storage encryption service, it can first initiate a data storage encryption request. After receiving the request from the sub-application system, the data storage encryption system can first query the maximum frequency value at which the sub-application system can use the storage encryption service, and determine the maximum encryption service frequency that can be supported under the current conditions based on the current storage encryption service capacity, i.e., the availability of current system resources such as CPU, memory, storage, and network bandwidth. This allows for dynamic control of the frequency at which the sub-application system uses the storage encryption service, thereby improving the efficiency and rationality of encryption service usage.

[0088] In some embodiments of this application, allocating encryption service resources to the business system based on the data storage encryption service application and the actual usage information of the encryption service of the business system includes: if the newly created sub-application system of the business system is of a different type than the already created sub-application system, then generating encryption service resources for the newly created sub-application system that are different from the encryption service resources corresponding to the already created sub-application system; if the data storage encryption system provides data storage encryption services for multiple different business systems, then generating different encryption service resources for the same sub-application system of different business systems.

[0089] On the one hand, considering that different sub-application systems have different encryption requirements, when the type of newly built application system in the business system is different from that of the existing application system, the virtual storage encryption service generated by the data storage encryption system for the newly built sub-application system is different from the virtual storage encryption service used by the existing sub-application system. It also stores whether the sub-application system can access and use the data storage encryption system and the maximum frequency value of using the encryption service, thereby ensuring that different sub-application systems independently use different virtual encryption service resources, thus meeting the encryption requirements of different sub-application systems.

[0090] On the other hand, when a data storage encryption system provides storage encryption services to different business systems, considering that the business logic and requirements of different business systems are also different, even the same sub-application systems of different business systems, such as those with the same application name, will have different encryption requirements. Therefore, the data storage encryption system of this application embodiment can also provide different virtual storage encryption services to the same sub-application systems of different business systems, thereby meeting the encryption requirements of the same sub-application systems of different business systems.

[0091] In some embodiments of this application, after receiving a data storage encryption service application from a business system, the method for allocating data storage encryption service resources further includes: determining whether the data storage encryption service application carries encryption service specified allocation information, wherein the encryption service specified allocation information includes at least one of a specified amount of encryption service resources and a specified allocation method; and, if the data storage encryption service application contains encryption service specified allocation information and the analysis conditions of a preset monitoring period are not currently triggered, allocating encryption service resources to the business system according to the encryption service specified allocation information.

[0092] In the aforementioned embodiments, the allocation of encryption service resources by the data storage encryption service system is primarily based on monitoring and analyzing the actual encryption service usage of various business systems. The main purpose is to optimize the allocation of encryption service resources to business systems and improve the efficiency of encryption service usage. However, in the initial stage of monitoring, the amount of data accumulated is insufficient. At this time, resource allocation can be mainly based on the allocation information specified by the business systems. For example, business systems can specify the amount and allocation method of encryption service resources according to their own needs.

[0093] In some embodiments of this application, allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes: allocating a usage quota and usage method for the encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system, wherein the usage method includes exclusive usage and shared usage.

[0094] The information allocated to the business system in this application embodiment may specifically include the allocation of the usage quota of encryption service resources and the allocation of the usage method. The usage method may be an exclusive method or a shared method. An exclusive method means that only one business system can exclusively use the allocated encryption service resources, while a shared method means that multiple business systems can share the allocated encryption service resources.

[0095] For ease of understanding of the above embodiments, as Figure 2 The diagram illustrates a data storage encryption service resource allocation process according to an embodiment of this application. First, the business system initiates a data storage encryption service application to the data storage encryption system. Upon receiving the application, the data storage encryption system reviews it and returns a notification message indicating the review result (approved / rejected) to the business system.

[0096] Then, if the data storage encryption system is approved, it will generate a fixed total capacity of encryption service resources for the business system based on the actual usage of encryption services obtained from monitoring and analysis. After receiving the approval message, the business system will send a sub-application system creation request to the application management module of the data storage encryption system, and the application management module will create the sub-application system. After the sub-application system is successfully created, the business system will further initiate a request to allocate encryption service resources to the sub-application system.

[0097] Since the data storage encryption system generates a fixed total capacity of encryption service resources for the business system after the business system has been approved, it can directly allocate access to and use of the encryption service resources to the sub-application system after receiving the above allocation request, so that the sub-application system can use the encryption service resources to perform data storage encryption.

[0098] In addition, before assigning permissions to sub-application systems to access and use the encrypted service resources, the application management module first determines the maximum frequency value of the encrypted service used by the sub-application system and saves it in the data storage encryption system. In this way, in the subsequent encryption stage, the data storage encryption system can dynamically control the frequency of the sub-application system's use of the storage encryption service by combining the maximum frequency value of the encrypted service used by the sub-application system.

[0099] Finally, during the actual encryption phase, the system can first receive data storage encryption requests from sub-application systems and determine whether the sub-application system has permission to use the encryption service. If not, the data storage encryption request from the sub-application system is directly rejected. If the sub-application system has permission, the system can further determine whether the sub-application system is currently exceeding the maximum frequency limit by combining the maximum frequency value of the sub-application system's use of the encryption service. If it exceeds the limit, the request is placed in a queue to wait; otherwise, the data storage encryption request from the sub-application system is processed.

[0100] In summary, this application has achieved at least the following technical effects:

[0101] 1) This application can be applied to business systems with traditional network architecture, public cloud architecture and private cloud architecture at the same time, reducing the cost of building cryptographic infrastructure on the business side;

[0102] 2) The data storage encryption service resource allocation scheme adopted in this application can dynamically and flexibly provide corresponding encryption services according to actual functional requirements, thus meeting the increasingly rich cryptographic application needs of business systems.

[0103] 3) By optimizing the analysis of encrypted resources, the efficiency and rationality of data storage encryption services have been improved;

[0104] 4) It reduces the cost of repeated investment by users.

[0105] This application embodiment also provides a data storage encryption service resource allocation device 300, such as... Figure 3 The diagram shows a structural schematic of a data storage encryption service resource allocation device according to an embodiment of this application. The data storage encryption service resource allocation device is applied to a data storage encryption system. The data storage encryption service resource allocation device 300 includes at least: a first receiving unit 310, a first determining unit 320, and an allocation unit 330, wherein:

[0106] The first receiving unit 310 is used to receive a data storage encryption service application from a business system, wherein the data storage encryption service application includes business system information and encryption service information.

[0107] The first determining unit 320 is used to determine, based on the data storage encryption service application, the actual usage information of the encryption service of the business system obtained by analysis within a preset monitoring period. The actual usage information of the encryption service is obtained by monitoring and analyzing the encryption service usage data of the business system within the preset monitoring period.

[0108] The allocation unit 330 is used to allocate encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system, so that the business system can use the encryption service resources to perform data storage encryption.

[0109] In some embodiments of this application, the first determining unit 320 is specifically used for: acquiring encryption service usage data of each business system within a preset monitoring period; monitoring and analyzing the encryption service usage data of each business system to obtain actual encryption service usage information of each business system within the preset monitoring period; and determining the actual encryption service usage information of the business system corresponding to the business system identifier based on the actual encryption service usage information of each business system within the preset monitoring period and the business system identifier carried in the data storage encryption service application.

[0110] In some embodiments of this application, the allocation unit 330 is specifically used for: approving the data storage encryption service application; if the approval is successful, generating encryption service resources corresponding to the business system based on the actual usage information of the encryption service of the business system, and sending an approval message to the business system; and allocating permissions for the business system to use the encryption service resources, so that the business system can use the encryption service resources to perform data storage encryption.

[0111] In some embodiments of this application, the allocation unit 330 is specifically configured to: after sending an approval message to the business system, receive a sub-application system creation request initiated by the business system, so that the business system can create a sub-application system through the data storage encryption system; receive an encryption service resource allocation request from the business system, wherein the encryption service resource allocation request refers to a request to allocate encryption service resources to the sub-application system created by the business system; and allocate permission for the sub-application system to use the encryption service resources according to the encryption service resource allocation request, so that the sub-application system can use the encryption service resources for data storage encryption.

[0112] In some embodiments of this application, the data storage encryption service resource allocation device 300 further includes: a second determining unit, configured to determine the maximum frequency value of the data storage encryption service used by the sub-application system, wherein the maximum frequency value of the data storage encryption service is based on the specification of the business system or calculated based on the encryption service usage data of the business system; and a storage unit, configured to store the maximum frequency value of the data storage encryption service used by the sub-application system.

[0113] In some embodiments of this application, the data storage encryption service resource allocation device 300 further includes: a second receiving unit, configured to receive a data storage encryption request from a sub-application system; a querying unit, configured to query the maximum frequency value of the sub-application system using the data storage encryption service based on the data storage encryption request; and a control unit, configured to control the frequency of the sub-application system using the data storage encryption service based on the maximum frequency value of the sub-application system using the data storage encryption service and the number of times the sub-application system has currently used the data storage encryption service.

[0114] In some embodiments of this application, the allocation unit 330 is specifically used to: if the type of the newly created sub-application system of the business system is different from that of the already created sub-application system, generate encryption service resources for the newly created sub-application system that are different from the encryption service resources corresponding to the already created sub-application system; if the data storage encryption system provides data storage encryption services for multiple different business systems, generate different encryption service resources for the same sub-application system of different business systems.

[0115] In some embodiments of this application, the data storage encryption service resource allocation device further includes: a third determining unit, configured to determine, after receiving a data storage encryption service application from a business system, whether the data storage encryption service application carries encryption service designated allocation information, wherein the encryption service designated allocation information includes at least one of a designated amount of encryption service resources and a designated allocation method; the allocation unit 330 is specifically configured to: allocate encryption service resources to the business system according to the encryption service designated allocation information when the data storage encryption service application contains encryption service designated allocation information and the analysis conditions of the preset monitoring period are not currently triggered.

[0116] In some embodiments of this application, the allocation unit 330 is specifically used to: allocate a usage quota and usage method of encryption service resources to the business system based on the data storage encryption service application and the actual usage information of the encryption service of the business system, wherein the usage method includes exclusive mode and shared mode.

[0117] It is understood that the above-mentioned data storage encryption service resource allocation device can implement each step of the data storage encryption service resource allocation method provided in the foregoing embodiments. The relevant explanations of the data storage encryption service resource allocation method are applicable to the data storage encryption service resource allocation device, and will not be repeated here.

[0118] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Please refer to it. Figure 4 At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and memory. The memory may include main memory, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk drive. Of course, the electronic device may also include other hardware required for other business operations.

[0119] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0120] Memory is used to store programs. Specifically, programs may include program code, which includes computer operation instructions. Memory may include main memory and non-volatile memory, and provides instructions and data to the processor.

[0121] The processor reads the corresponding computer program from non-volatile memory into main memory and then runs it, forming a data storage encryption service resource allocation device at the logical level. The processor executes the program stored in memory and specifically performs the following operations:

[0122] Receive a data storage encryption service application from a business system, wherein the data storage encryption service application includes business system information and encryption service information;

[0123] Based on the data storage encryption service application, the actual usage information of the encryption service of the business system obtained by analysis within a preset monitoring period is determined. The actual usage information of the encryption service is obtained by monitoring and analyzing the encryption service usage data of the business system within the preset monitoring period.

[0124] Based on the data storage encryption service application and the actual usage information of the encryption service of the business system, encryption service resources are allocated to the business system so that the business system can use the encryption service resources to encrypt data storage.

[0125] The above is as stated in this application. Figure 1 The method executed by the data storage encryption service resource allocation device disclosed in the illustrated embodiment can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0126] This application also proposes a computer program product that stores one or more programs, each program including instructions that, when executed by an electronic device including multiple applications, enable the electronic device to perform... Figure 1 The method executed by the data storage encryption service resource allocation device in the illustrated embodiment is specifically used to perform:

[0127] Receive a data storage encryption service application from a business system, wherein the data storage encryption service application includes business system information and encryption service information;

[0128] Based on the data storage encryption service application, the actual usage information of the encryption service of the business system obtained by analysis within a preset monitoring period is determined. The actual usage information of the encryption service is obtained by monitoring and analyzing the encryption service usage data of the business system within the preset monitoring period.

[0129] Based on the data storage encryption service application and the actual usage information of the encryption service of the business system, encryption service resources are allocated to the business system so that the business system can use the encryption service resources to encrypt data storage.

[0130] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0131] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0132] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0133] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0134] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0135] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0136] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0137] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0138] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0139] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of this application should be included within the scope of the claims of this application.

Claims

1. A method of allocating data storage encryption service resources, wherein, The allocation method for the data storage encryption service resources is executed by the data storage encryption system, and the allocation method for the data storage encryption service resources includes: Receive a data storage encryption service application from a business system, wherein the data storage encryption service application includes business system information and encryption service information; Based on the data storage encryption service application, the actual usage information of the encryption service of the business system obtained by analysis within a preset monitoring period is determined. The actual usage information of the encryption service is obtained by monitoring and analyzing the encryption service usage data of the business system within the preset monitoring period. Based on the data storage encryption service application and the actual usage information of the encryption service of the business system, encryption service resources are allocated to the business system so that the business system can use the encryption service resources to encrypt data storage.

2. The method of allocating data storage encryption service resources according to claim 1, wherein, The step of determining the actual usage information of the encryption service of the business system obtained from analysis within a preset monitoring period based on the data storage encryption service application includes: Within a preset monitoring period, acquire data on the use of encrypted services by various business systems; The encryption service usage data of each of the aforementioned business systems are monitored and analyzed to obtain the actual encryption service usage information of each business system within the preset monitoring period. Based on the actual usage information of encryption services of each business system within the preset monitoring period and the business system identifier carried in the data storage encryption service application, the actual usage information of encryption services of the business system corresponding to the business system identifier is determined.

3. The method of claim 1, wherein the data storage encryption service resource is allocated based on a type of the data storage encryption service resource. The step of allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes: The application for the data storage encryption service shall be approved; If the approval is granted, the encryption service resources corresponding to the business system are generated based on the actual usage information of the encryption service of the business system, and the approval message is sent to the business system. The business system is granted permission to use the encryption service resources, so that the business system can use the encryption service resources to encrypt data storage.

4. The method of allocating data storage encryption service resources according to claim 3, wherein, The step of allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes: After sending an approval message to the business system, the system receives a sub-application system creation request initiated by the business system, so that the business system can create a sub-application system through the data storage encryption system. Receive the encryption service resource allocation request from the business system, wherein the encryption service resource allocation request refers to the request to allocate encryption service resources to the sub-application system created by the business system; The sub-application system is granted permission to use the encryption service resource according to the encryption service resource allocation request, so that the sub-application system can use the encryption service resource to encrypt data storage.

5. The method of allocating data storage encryption service resources according to claim 4, wherein, The method for allocating data storage encryption service resources further includes: Determine the maximum frequency value of the data storage encryption service used by the sub-application system. The maximum frequency value of the data storage encryption service is based on the specification of the business system or calculated based on the data used by the encryption service of the business system. The maximum frequency value of the data storage encryption service used by the sub-application system is stored.

6. The method of allocating data storage encryption service resources according to claim 4, wherein, The method for allocating data storage encryption service resources further includes: Receive data storage encryption requests from sub-application systems; Based on the data storage encryption request, query the maximum frequency value of the data storage encryption service used by the sub-application system; The frequency at which the sub-application system uses the data storage encryption service is controlled based on the maximum frequency value of the sub-application system's use of the data storage encryption service and the number of times the sub-application system has currently used the data storage encryption service.

7. The method for allocating data storage encryption service resources according to claim 4, wherein, The step of allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes: If the newly created sub-application system of the business system is of a different type than the already created sub-application system, then an encryption service resource with a different encryption service resource than the one corresponding to the already created sub-application system will be generated for the newly created sub-application system. If the data storage encryption system provides data storage encryption services for multiple different business systems, then different encryption service resources are generated for the same sub-application systems of different business systems.

8. The method for allocating data storage encryption service resources according to claim 1, wherein, After receiving a data storage encryption service request from a business system, the method for allocating data storage encryption service resources further includes: Determine whether the data storage encryption service application carries encryption service designated allocation information, wherein the encryption service designated allocation information includes at least one of a designated amount of encryption service resources and a designated allocation method; If the data storage encryption service application contains encryption service allocation information and the analysis conditions of the preset monitoring period are not currently triggered, encryption service resources are allocated to the business system according to the encryption service allocation information.

9. The method for allocating data storage encryption service resources according to any one of claims 1 to 8, wherein, The step of allocating encryption service resources to the business system based on the data storage encryption service application and the actual encryption service usage information of the business system includes: Based on the data storage encryption service application and the actual encryption service usage information of the business system, the usage quota and usage method of the encryption service resources are allocated to the business system, including exclusive mode and shared mode.

10. A device for allocating data storage encryption service resources, wherein, The data storage encryption service resource allocation device is applied to the data storage encryption system, and the data storage encryption service resource allocation device includes: The first receiving unit is used to receive a data storage encryption service application from a business system, wherein the data storage encryption service application includes business system information and encryption service information. The first determining unit is used to determine, based on the data storage encryption service application, the actual usage information of the encryption service of the business system obtained by analysis within a preset monitoring period. The actual usage information of the encryption service is obtained by monitoring and analyzing the encryption service usage data of the business system within the preset monitoring period. The allocation unit is used to allocate encryption service resources to the business system based on the data storage encryption service application and the actual usage information of the encryption service of the business system, so that the business system can use the encryption service resources to perform data storage encryption.

11. An electronic device, comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, cause the processor to perform the data storage encryption service resource allocation method of any one of claims 1 to 9.

12. A computer program product comprising a computer program or instructions, wherein the computer program or instructions, when executed by a processor, implement the data storage encryption service resource allocation method of any one of claims 1 to 9.