Data encryption method and related equipment

By generating a request address and using hardware device parameters to generate a key, the problem of low security in software-derived key encryption is solved, achieving a higher level of trust and resistance to attacks in the encryption process.

CN121967057APending Publication Date: 2026-05-01JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD
Filing Date
2026-02-12
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing software-based methods for derived key encryption suffer from low security, as the keys are vulnerable to attack and can be copied infinitely, and lack physical protection.

Method used

By generating a request address, the characteristics of the derived key service are detected. The derived key interface of the predefined trusted execution environment is used to obtain the key generated by the hardware device parameters of the target manufacturer, and then the key is encrypted in combination with the encryption algorithm to ensure the uniqueness of the key and its resistance to physical attacks.

Benefits of technology

It improves the credibility and resilience of the encryption process, enhances overall security, and prevents keys from being copied indefinitely and from physical attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967057A_ABST
    Figure CN121967057A_ABST
Patent Text Reader

Abstract

The invention provides a data encryption method and related equipment, and relates to the technical field of data encryption, and the method comprises the steps: generating a request address in response to an encryption request for a user key; the request address is used for requesting to generate a derived key; based on the request address, detecting to obtain a derived key service feature, and determining a target manufacturer corresponding to the derived key service feature; obtaining a derived key of the target manufacturer through a predefined derived key interface for providing a trusted execution environment; the derived key is a key generated by hardware equipment parameters of the target manufacturer; and according to the derived key of the target manufacturer and the encryption algorithm, encrypting the user key to obtain an encryption result. The encryption process based on the hardware derived key is completed by detecting the derived key service characteristics, and compared with a software derived key mode, the reliability is higher, the risk resistance and the physical attack resistance are higher, and the overall safety is higher.
Need to check novelty before this filing date? Find Prior Art

Description

Data encryption methods and related equipment Technical Field

[0001] This disclosure relates to the field of data encryption technology, and in particular to a data encryption method and related equipment. Background Technology

[0002] With the development of Internet technology, data security is receiving increasing attention. In the encryption process of keys, the relevant technologies generally adopt a software-based approach to derive keys and encrypt them. This approach has several security problems. For example, the software-generated keys are mainly stored in memory or on disk without physical protection, making them vulnerable to attacks. Keys can be obtained through various means and can be copied and transferred an unlimited number of times during their lifespan. Although convenient to use, they are easy to spread.

[0003] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0004] The purpose of this disclosure is to provide a data encryption method and related equipment, which at least to some extent solves the problem of low security in many aspects of the existing technology that uses software-based methods to derive keys and encrypt data.

[0005] Other features and advantages of this disclosure will become apparent from the following detailed description, or may be learned in part from practice of this disclosure.

[0006] According to a first aspect of this disclosure, a data encryption method is provided, the method comprising: generating a request address in response to an encryption request for a user key; the request address being used to request the generation of a derived key; based on the request address, detecting derived key service characteristics and determining a target vendor corresponding to the derived key service characteristics; obtaining a derived key of the target vendor through a predefined derived key interface that provides a trusted execution environment; the derived key being a key generated from hardware device parameters of the target vendor; and encrypting the user key according to the derived key of the target vendor and an encryption algorithm to obtain an encryption result.

[0007] In one possible embodiment, the encryption request includes a container runtime class; generating a request address in response to the encryption request for the user key includes: obtaining the container runtime class through a controller component created in a physical node; identifying the target vendor through the container runtime class, and generating a request address.

[0008] In one possible embodiment, the method further includes: creating a virtual machine in a physical node of a K8S cluster; creating the controller component in the virtual machine; the controller component running as a container in the virtual machine of the K8S cluster; and providing a secure operating environment for the controller component to run as a confidential container by launching an object component in the virtual machine, based on a trusted execution environment provided by the hardware.

[0009] In one possible embodiment, the step of detecting derived key service characteristics based on the request address and determining the target vendor corresponding to the derived key service characteristics includes: monitoring the request address through a key generation interface service; if the request address is being monitored, resolving the request address through the key generation interface service and detecting the derived key service characteristics; the key generation interface service is an interface service created based on a REST architecture; and determining the target vendor corresponding to the derived key service characteristics.

[0010] In one possible embodiment, the request address is used to provide a representational state transition interface service, wherein the request address is the same for encrypted requests for user keys from different vendors.

[0011] In one possible embodiment, the derived key interface includes derived key interfaces corresponding to different vendors; obtaining the derived key of the target vendor through a predefined derived key interface that provides a trusted execution environment includes: calling the derived key interface corresponding to the target vendor through a key generation interface service to obtain the derived key sent by the target vendor.

[0012] According to another aspect of this disclosure, a data encryption apparatus is provided, comprising: a generation unit, configured to generate a request address in response to an encryption request for a user key; the request address being used to request the generation of a derived key; a determination unit, configured to detect derived key service characteristics based on the request address and determine a target vendor corresponding to the derived key service characteristics; a derived key acquisition unit, configured to obtain a derived key of the target vendor through a predefined derived key interface providing a trusted execution environment; the derived key being a key generated from hardware device parameters of the target vendor; and an encryption unit, configured to encrypt the user key according to the derived key of the target vendor and an encryption algorithm to obtain an encryption result.

[0013] In one possible embodiment, it further includes: a building unit for creating a virtual machine in a physical node of the K8S cluster; creating the controller component in the virtual machine; the controller component running as a container in the virtual machine of the K8S cluster; and providing a secure operating environment for the controller component to run as a confidential container by launching an object component in the virtual machine based on a trusted execution environment provided by the hardware.

[0014] According to another aspect of this disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform the method of any one of the first aspects by executing the executable instructions.

[0015] According to another aspect of this disclosure, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the method of any one of the first aspects.

[0016] According to another aspect of this disclosure, a computer program product or computer program is also provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method described in the first aspect above.

[0017] This disclosure provides a data encryption method and related apparatus, relating to the field of data encryption technology. The method includes: generating a request address in response to an encryption request for a user key; using the request address to request the generation of a derived key; detecting derived key service characteristics based on the request address and determining the target vendor corresponding to the derived key service characteristics; obtaining the target vendor's derived key through a predefined derived key interface that provides a trusted execution environment; the derived key being a key generated from the hardware device parameters of the target vendor; and encrypting the user key according to the target vendor's derived key and an encryption algorithm to obtain an encryption result. By detecting derived key service characteristics, the encryption process based on hardware derived keys is completed. Compared to software derived key methods, this approach offers higher reliability, stronger resistance to risks and physical attacks, and higher overall security.

[0018] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0019] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0020] Figure 1 shows a flowchart of a data encryption method according to an embodiment of the present disclosure; Figure 2 shows a flowchart of generating a request address according to an embodiment of the present disclosure; Figure 3 shows a flowchart of determining a target manufacturer according to an embodiment of the present disclosure; Figure 4 shows a flowchart of performing data encryption according to an embodiment of the present disclosure; Figure 5 shows a schematic diagram of a data encryption device according to an embodiment of the present disclosure; Figure 6 shows a schematic diagram of an electronic device according to an embodiment of the present disclosure. Detailed Implementation

[0021] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that this disclosure will be more comprehensive and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0022] Furthermore, the accompanying drawings are merely illustrative of this disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0023] Because the relevant technologies generally use a software-based approach to derive the key and encrypt it, this method has many security problems.

[0024] For example, software-generated keys are primarily stored in memory or on disk. Although they can be encrypted, the keys themselves are still accessible in memory. This makes them vulnerable to various attacks, such as memory dumps and buffer overflow attacks. Furthermore, software-generated keys lack physical protection; any attacker with access to the device storing the keys can potentially steal them through various means (e.g., side-channel attacks, cold starts). During their lifespan, software-generated keys can be copied and transferred an unlimited number of times. While convenient to use, this ease of distribution poses a potential risk.

[0025] Based on this, embodiments of this disclosure provide a data encryption method and related equipment, relating to the field of data encryption technology. The method includes: generating a request address in response to an encryption request for a user key; the request address being used to request the generation of a derived key; based on the request address, detecting derived key service characteristics and determining the target vendor corresponding to the derived key service characteristics; obtaining the target vendor's derived key through a predefined derived key interface that provides a trusted execution environment; the derived key being a key generated from the hardware device parameters of the target vendor; and encrypting the user key according to the target vendor's derived key and an encryption algorithm to obtain an encryption result. By detecting derived key service characteristics, the encryption process based on hardware derived keys is completed. Compared to software derived key methods, this approach offers higher reliability, stronger resistance to risks and physical attacks, and higher overall security.

[0026] Furthermore, hardware-derived keys, typically stored in hardware security modules, cannot be directly exported. Even if an attacker gains physical access to the device, they cannot directly extract the key, resulting in higher security. Hardware security modules can also incorporate temperature and voltage sensors and can even be configured to self-destruct to prevent attacks and tampering, offering strong resistance to physical attacks. Moreover, the hardware device parameters form a hardware root of trust, ensuring the uniqueness and verifiability of the key. Software-generated keys lack this root of trust; their lifecycle is tightly bound to the hardware device. When the hardware is destroyed, the key also becomes invalid, providing a unique and corresponding security guarantee that a derived key is used only on a specific hardware instance. As can be seen from the above, derived keys generated based on hardware device parameters offer a higher level of security, reliability, and resistance to physical attacks, resulting in overall higher security.

[0027] This disclosure describes the method through the following embodiments.

[0028] Figure 1 shows a flowchart of a data encryption method according to an embodiment of the present disclosure. As shown in Figure 1, the method includes the following steps: S102: In response to an encryption request for a user key, a request address is generated, which is used to request the generation of a derived key.

[0029] In one possible embodiment, the encryption request for the user key can determine which hardware vendor the user key to be encrypted in this encryption request belongs to, and a request address can be generated based on the corresponding hardware vendor to generate a derived key (sealingkey).

[0030] In one possible embodiment, the request address may be for a local service used to provide a RESTful API for representing state transitions, which can further ensure the security of obtaining the derived key.

[0031] For example, the request address can be an encrypted request for user keys from different vendors, based on the Hypertext Transfer Protocol, IP address, port number, and access path. The request address is the same, but vendor information is not present in the request address. For instance, the address could be represented as: http: / / same IP address:same port number / access path. The access path could be tee / sealingkey.

[0032] S104: Based on the request address, detect the derived key service characteristics and determine the target vendor corresponding to the derived key service characteristics.

[0033] In one possible embodiment, derived key service characteristics are detected by parsing the request address, and the corresponding target vendor is determined based on the derived key service characteristics.

[0034] S106: Obtain the target vendor's derived key through a predefined derived key interface that provides a trusted execution environment. The derived key is a key generated from the target vendor's hardware device parameters.

[0035] In one possible embodiment, the hardware device parameters may include: a unique hardware identifier, which may include at least one of the following: chip serial number, central processing unit identification (CPU ID). The unique hardware identifier may also include other parameters, which will not be listed here. This disclosure does not limit the specific unique hardware identifier.

[0036] S108: Encrypt the user key based on the target manufacturer's derived key and encryption algorithm to obtain the encryption result.

[0037] In one possible embodiment, the encryption algorithm can employ the AES-256-CBC algorithm, encrypting the user key based on a derived key. The derived key, generated from hardware device parameters, is used as an encryption parameter in the encryption process to obtain the encryption result. The encrypted result is then stored. Throughout the encryption process, the user does not need to concern themselves with the hardware.

[0038] The above method generates a derived key from hardware device parameters and encrypts the user key using an encryption algorithm. Compared with the software-derived key method, this method has higher credibility, stronger resistance to risks and physical attacks, and higher overall security.

[0039] In one possible embodiment, for S102, the encryption request may include a container runtime class. Different vendors use different hardware, and the corresponding hardware vendor can be identified through the container runtime class. In this embodiment, the container runtime class can also be used for container lifecycle management, resource management, etc.

[0040] Figure 2 shows a flowchart of generating a request address in an embodiment of this disclosure. As shown in Figure 2, it includes the following steps: S202: Obtain the container runtime class through the controller component created in the physical node.

[0041] In one possible embodiment, the controller component may be running as a container within a Kubernetes cluster.

[0042] In one possible embodiment, the overall process runs in a trusted execution environment (TEE) provided by the hardware. A virtual machine can be created on a physical node of the K8S cluster, and a controller component can be created in the virtual machine. Based on the trusted execution environment provided by the hardware, guest components are started in the virtual machine to provide a secure operating environment for the controller component to run as a confidential container.

[0043] Based on this, a secure operating environment can be provided for the overall encryption process, further improving the security of user key encryption.

[0044] S204: Identify the target vendor and generate a request address through the container runtime class.

[0045] In one possible embodiment, by obtaining the container runtime class specified by the user, determining the target vendor, and generating a request address, it is possible to obtain derived keys of different vendors based on different container runtime classes.

[0046] In one possible implementation, a derived key generated based on hardware device parameters is combined with a confidential container. Through a container runtime class, a hardware-based derived key encryption process can be provided at runtime, or the user key can be encrypted directly through the controller component during user deployment, achieving a multi-vendor hardware-based encryption method for the user key. Users only need to specify the container runtime class to complete the user key encryption process.

[0047] Regarding S104, Figure 3 shows a flowchart of determining a target vendor in an embodiment of this disclosure. As shown in Figure 3, it includes the following steps: S302: Listen for the request address through the key generation interface service. The key generation interface service is an interface service created based on the REST architecture.

[0048] Here, "rest" can be understood as a descriptive state transition, and its specific details will not be elaborated upon.

[0049] S304: If the request address is being monitored, the request address is parsed through the key generation interface service, and the characteristics of the derived key service are detected.

[0050] S306: Determine the target vendor corresponding to the derived key service features.

[0051] In one possible embodiment, the key generation interface service can be an interface service (api-server-rest) created based on a REST architecture. The key generation interface service can be deployed in a virtual machine, and the process of parsing the request address and probing the characteristics of the derived key service can be defined in the key generation interface service.

[0052] The key generation interface service determines that the request address has been generated by listening to the port number in the request address. After listening to the request address, it calls the processing logic to detect the characteristics of the derived key service and determine the target vendor.

[0053] For example, for vendor A, it can be determined whether there is a service file that is only used by vendor A. For vendor B, it can be determined whether the character set settings or certain fields exist. In this way, if the derived key service characteristics are detected, the corresponding target vendor can be determined based on the detected derived key service characteristics.

[0054] In one possible embodiment, after determining the target vendor, the operation of obtaining the derived key (get_sealing_key) in the key generation interface service is executed, which calls the predefined derived key interface to obtain the derived key of the target vendor.

[0055] In one possible embodiment, the derived key interface includes derived key interfaces corresponding to different vendors. The derived key interface is an interface that abstracts the derived capabilities of hardware from different vendors and is a differentially compiled interface.

[0056] The derivation key sent by the target vendor is obtained by calling the target vendor's corresponding derivation key interface through the key generation interface service. The derivation key can be obtained by the target vendor through the derivation key interface. It should be noted that the derivation key interfaces are all interfaces in the trusted execution environment (tee interface).

[0057] Figure 4 shows a flowchart of a data encryption process in an embodiment of this disclosure. As shown in Figure 4, it includes: a K8S cluster 410, a virtual machine 420, a controller component 430, a key generation interface service 440, a derived key interface 450, and a physical node 460.

[0058] In this embodiment of the disclosure, a virtual machine 420 is built on a node of the K8S cluster, and a secure operating environment is built based on the object component and the trusted execution environment provided by the hardware. A controller component 430 is created in the virtual machine and the controller component 430 is run in the K8S cluster as a confidential container.

[0059] The controller component 430 receives the container runtime class specified by the user, determines the target vendor, and generates a request address. The request address can provide RESTful API services only locally to further improve the security of obtaining the derived key. The key generation interface service 440 listens for the request address and detects the characteristics of the derived key service to determine the target vendor. By executing the operation of obtaining the derived key (get_sealing_key), the derived key interface 450 of the target vendor is called. Each vendor transmits the derived key through the derived key interface 450 that is connected to the physical node 460. Based on the obtained derived key, the controller component 430 uses an encryption algorithm to complete the encryption process of the user key, obtains the encryption result, and stores it.

[0060] Furthermore, in this embodiment of the disclosure, different derived key interface services can be compiled differently for different platforms.

[0061] In this embodiment, the encryption not only employs hardware-generated derived keys for better security compared to existing software-generated derived keys, but also uses a confidential container combined with the hardware-generated derived key process to complete the encryption of user keys, further enhancing the security of the encryption process. Furthermore, an interface adaptation layer is used to adapt to hardware-based derived key methods from different manufacturers. The derived key interfaces of different hardware manufacturers are pre-abstracted, and the confidential container project provides hardware manufacturers with an entry point for the key encryption process. This enables encryption of user keys based on hardware derived keys from multiple manufacturers, allowing manufacturers to complete encryption simply by specifying the container runtime class, without needing to concern themselves with the specific encryption process.

[0062] Based on the same inventive concept as the above-described method embodiments, this application also provides a data encryption device. Figure 5 shows a schematic diagram of the structure of a data encryption device provided in this application embodiment.

[0063] The device 50 includes: a generation unit 501, used to generate a request address in response to an encryption request for a user key; the request address is used to request the generation of a derived key; a determination unit 502, used to detect derived key service characteristics based on the request address and determine the target vendor corresponding to the derived key service characteristics; a derived key acquisition unit 503, used to obtain the derived key of the target vendor through a predefined derived key interface that provides a trusted execution environment; the derived key is a key generated from the hardware device parameters of the target vendor; and an encryption unit 504, used to encrypt the user key according to the derived key of the target vendor and an encryption algorithm to obtain an encryption result.

[0064] Those skilled in the art will understand that various aspects of the present invention can be implemented as systems, methods, or program products. Therefore, various aspects of the present invention can be specifically implemented in the following forms: entirely in hardware, entirely in software (including firmware, microcode, etc.), or in a combination of hardware and software, collectively referred to herein as “circuit,” “module,” or “system.”

[0065] The electronic device 600 according to this embodiment of the present invention will now be described with reference to FIG6. The electronic device 600 shown in FIG6 is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of the present invention.

[0066] As shown in Figure 6, the electronic device 600 is presented in the form of a general-purpose computing device. The components of the electronic device 600 may include, but are not limited to: at least one processing unit 610, at least one storage unit 620, and a bus 630 connecting different system components (including storage unit 620 and processing unit 610).

[0067] The storage unit stores program code, which can be executed by the processing unit 610, causing the processing unit 610 to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of the present invention.

[0068] Storage unit 620 may include readable media in the form of volatile storage units, such as random access memory (RAM) 6201 and / or cache memory 6202, and may further include read-only memory (ROM) 6203.

[0069] Storage unit 620 may also include a program / utility 6204 having a set (at least one) program module 6205, such program module 6205 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.

[0070] Bus 630 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.

[0071] Electronic device 600 can also communicate with one or more external devices 640 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 600, and / or with any device that enables electronic device 600 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 650. Furthermore, electronic device 600 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 660. As shown, network adapter 660 communicates with other modules of electronic device 600 via bus 630. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0072] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.

[0073] In exemplary embodiments of this disclosure, a computer-readable storage medium is also provided, on which a program product capable of implementing the methods described above is stored. In some possible embodiments, various aspects of the present invention may also be implemented as a program product comprising program code that, when the program product is run on a terminal device, causes the terminal device to perform the steps of the various exemplary embodiments of the present invention described in the "Exemplary Methods" section above.

[0074] A program product for implementing the above-described method according to embodiments of the present invention is described. This product may employ a portable compact disc read-only memory (CD-ROM) and include program code, and may run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, the readable storage medium may be any tangible medium containing or storing a program that may be used by or in conjunction with an instruction execution system, apparatus, or device.

[0075] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0076] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting programs for use by or in conjunction with an instruction execution system, apparatus, or device.

[0077] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0078] Program code for performing the operations of this invention can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0079] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0080] Furthermore, although the steps of the method in this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result. Additional or alternative steps may be omitted, multiple steps may be combined into one step, and / or a step may be broken down into multiple steps.

[0081] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the methods according to the embodiments of this disclosure.

[0082] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the appended claims.

Claims

1. A data encryption method, characterized in that, The method includes: generating a request address in response to an encryption request for a user key; the request address being used to request the generation of a derived key; based on the request address, detecting derived key service characteristics and determining the target vendor corresponding to the derived key service characteristics; obtaining the derived key of the target vendor through a predefined derived key interface that provides a trusted execution environment; the derived key being a key generated from the hardware device parameters of the target vendor; and encrypting the user key according to the derived key of the target vendor and an encryption algorithm to obtain an encryption result.

2. The method according to claim 1, characterized in that, The encryption request includes a container runtime class; the step of generating a request address in response to an encryption request for a user key includes: obtaining the container runtime class through a controller component created in a physical node; identifying the target vendor through the container runtime class, and generating a request address.

3. The method according to claim 2, characterized in that, The method further includes: creating a virtual machine in a physical node of a K8S cluster; creating the controller component in the virtual machine; the controller component running as a container in the virtual machine of the K8S cluster; and providing a secure operating environment for the controller component to run as a confidential container by launching an object component in the virtual machine based on a trusted execution environment provided by the hardware.

4. The method according to claim 1, characterized in that, The step of detecting derived key service characteristics based on the request address and determining the target vendor corresponding to the derived key service characteristics includes: listening to the request address through a key generation interface service; the key generation interface service is an interface service created based on a REST architecture; if the request address is being listened to, the request address is parsed through the key generation interface service, and the derived key service characteristics are detected; the target vendor corresponding to the derived key service characteristics is determined.

5. The method according to any one of claims 2-4, characterized in that, The request address is used to provide a representational state transition interface service, wherein the request address is the same for encrypted requests for user keys from different vendors.

6. The method according to claim 1, characterized in that, The derived key interface includes derived key interfaces corresponding to different vendors; obtaining the derived key of the target vendor through a predefined derived key interface that provides a trusted execution environment includes: calling the derived key interface corresponding to the target vendor through the key generation interface service to obtain the derived key sent by the target vendor.

7. A data encryption device, characterized in that, include: The generation unit is used to generate a request address in response to an encryption request for the user key; The request address is used to request the generation of a derived key; The determining unit is used to detect derived key service characteristics based on the request address and determine the target vendor corresponding to the derived key service characteristics; the derived key obtaining unit is used to obtain the derived key of the target vendor through a predefined derived key interface that provides a trusted execution environment; the derived key is a key generated from the hardware device parameters of the target vendor; The encryption unit is used to encrypt the user key according to the derived key and encryption algorithm of the target manufacturer to obtain the encryption result.

8. An electronic device, characterized in that, include: processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform the method of any one of claims 1 to 6 by executing the executable instructions.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the method described in any one of claims 1 to 6.

10. A computer program product comprising: A computer program or instruction, characterized in that, when executed by a processor, the computer program or instruction implements the method described in any one of claims 1 to 6.