Method, system and device for isolating cryptographic components of vsms, and storage medium

By creating multiple password card device interfaces and communication queues on the host and assigning these interfaces when VSM starts, the problem of complexity and low reliability of VSM password component isolation architecture is solved, and more efficient and reliable password component isolation is achieved.

WO2025107824A1PCT designated stage expired Publication Date: 2025-05-30CHINA TELECOM QUANTUM TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/117361
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-22
Filing Date
2024-09-06
Publication Date
2025-05-30

Smart Images

  • Figure CN2024117361_30052025_PF_FP_ABST
    Figure CN2024117361_30052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a method, system and device for isolating cryptographic components of VSMs, and a storage medium. The method comprises: loading a cryptographic card driver on a host machine provided with an encryption card, and on the basis of n communication queues in the encryption card, creating n corresponding cryptographic card device interfaces; when a VSM is started, allocating a specified cryptographic card device interface to the VSM, so that the VSM accesses the corresponding cryptographic card device interface in a docker container; and by means of the corresponding cryptographic card device interface, accessing a resource allocated to the VSM in a cryptographic card. According to the present application, a plurality of device interfaces can be supported by means of a single cryptographic card, and by ensuring that each VSM exclusively occupies one cryptographic card device interface, the design complexity of an isolation architecture for cryptographic components of VSMs is reduced, and the reliability is improved.
Need to check novelty before this filing date? Find Prior Art

Description

VSM cryptographic component isolation method, system, device and storage medium

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on November 22, 2023, with application number 202311589442.X and invention name “VSM cryptographic component isolation method, system, device and storage medium”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of cryptographic application technology, and in particular to a method, system, device and storage medium for isolating cryptographic components of a VSM. Background Art

[0003] Cloud server cryptographic machines typically have only one physical cryptographic card. To ensure the security and reliability of cryptographic data within each VSM (Virtual Security Module), the cryptographic components between VSMs must be securely isolated and shared. Without hardware virtualization technologies like SRIOV (Single Root I / O Virtualization) for cryptographic component sharing, software virtualization is the only option. In traditional software virtualization, different virtual machines typically call cryptographic components through a unified Application Programming Interface (API) middle layer. This adds an API middle layer to the software design, complicating system design. Furthermore, if the API middle layer fails, all VSMs will be unable to provide cryptographic services properly, reducing reliability.

[0004] In the related art, the patent application document with publication number CN114238938A proposes setting the virtualization mode of the PCIE password card, which includes full virtualization and partial virtualization. The user selects partial virtualization or full virtualization by passing the value of the variable vf_mode during communication with the password card. When full virtualization is enabled, vf_mode is set to 1, and the storage areas separated from the password card are mapped one by one to the virtual password cards. When partial virtualization is enabled, vf_mode is set to 0, and a certain storage area in the password card is mapped to all virtual password cards. This solution configures and manages the password card in two ways: full virtualization and semi-virtualization, and manages the configuration of fd_mode to configure it to full virtualization or partial virtualization. Patent application publication number CN111541646A proposes a master control process that creates and monitors multiple worker processes. These worker processes are bound to several CPU (Central Processing Unit) cores, create and manage a pool of service threads, and allocate shared resources to these worker processes, all shared by multiple service threads within the pool. This approach also isolates resources from other worker processes. This solution, implemented in software, binds the multiple worker threads to different CPUs, improving the efficiency of password card calls and differing from virtualization. Patent application publication number CN116074003A uses software to establish a two-level cache, enabling the operation of multiple password cards to improve efficiency.

[0005] Summary of the Invention

[0006] The technical problem to be solved by this application is how to reduce the complexity of the VSM cryptographic component isolation architecture design and improve reliability.

[0007] This application solves the above technical problems through the following technical means:

[0008] This application proposes a method for isolating cryptographic components of a VSM, the method comprising:

[0009] Load the cryptographic card driver on the host machine equipped with the cryptographic card, and create corresponding n cryptographic card device interfaces based on the n communication queues in the cryptographic card;

[0010] After VSM is started, the specified password card device interface is assigned to VSM, so that VSM can access the corresponding password card device interface inside the Docker container;

[0011] Access the resources allocated to the VSM inside the password card through the corresponding password card device interface.

[0012] In some embodiments, the VSM uses Docker containers to implement virtualization.

[0013] In some embodiments, assigning a designated cryptographic card device interface to a VSM includes:

[0014] Use the device command to assign the specified password card device interface to the VSM.

[0015] In some embodiments, each cryptographic card device interface uses an independent communication queue, and the cryptographic card device interfaces are isolated from each other.

[0016] In addition, this application also proposes a VSM cryptographic component isolation system, which includes:

[0017] The cryptographic card device interface creation module is used to load the cryptographic card driver on the host machine equipped with the cryptographic card and create corresponding n cryptographic card device interfaces based on the n communication queues in the cryptographic card;

[0018] The interface allocation module is used to allocate the specified password card device interface to the VSM after the VSM is started, so that the VSM can access the corresponding password card device interface inside the Docker container;

[0019] The resource allocation module is used to access the resources allocated to the VSM in the password card through the corresponding password card device interface.

[0020] In some embodiments, the VSM uses Docker containers to implement virtualization.

[0021] In some embodiments, the interface allocation module is specifically configured to allocate a specified cryptographic card device interface to the VSM through a device command.

[0022] In some embodiments, each cryptographic card device interface uses an independent communication queue, and the cryptographic card device interfaces are isolated from each other.

[0023] In addition, the present application also proposes a cryptographic component isolation device for VSM, which includes a memory and a processor; wherein the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the above method.

[0024] In addition, the present application also proposes a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the above method is implemented.

[0025] The advantages of this application are:

[0026] This application creates n password card device interfaces on the host machine, each corresponding to a communication queue. When starting the VSM, the specified password card device is assigned to the VSM. Each VSM accesses the resources in the corresponding assigned password card through a communication queue. A single password card can support multiple device interfaces while ensuring that each VSM exclusively occupies a password card device interface, thereby reducing the complexity of the VSM's password component isolation architecture design and improving reliability.

[0027] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0029] FIG1 is a flow chart of a cryptographic component isolation method of a VSM proposed in one embodiment of the present application;

[0030] FIG2 is a schematic diagram of the communication queue isolation principle proposed in an embodiment of the present application;

[0031] FIG3 is a schematic structural diagram of a cryptographic component isolation system of a VSM proposed in one embodiment of the present application;

[0032] FIG4 is a block diagram of a cryptographic component isolation device of a VSM provided in one embodiment of the present application;

[0033] FIG5 is a schematic diagram of a computer-readable storage medium provided in an embodiment of the present application. Specific embodiments

[0034] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0035] As shown in FIG1 , the embodiment of the present application discloses a method for isolating a cryptographic component of a VSM, the method comprising the following steps:

[0036] S10, loading the cryptographic card driver on the host machine equipped with the cryptographic card, and creating corresponding n cryptographic card device interfaces based on n communication queues in the cryptographic card;

[0037] In this embodiment, the storage areas separated from the storage area of ​​the password card correspond one-to-one to the created password card device interfaces (virtual password cards). A virtual password machine management system is provided on the host machine. After a virtual password machine is created, the management system allocates an unused password card device interface to the virtual password machine, so that each virtual password machine can access its own storage area on the password card.

[0038] S20. After the VSM is started, the specified password card device interface is allocated to the VSM, so that the VSM can access the corresponding password card device interface inside the Docker container;

[0039] S30. Access the resources allocated to the VSM in the password card through the corresponding password card device interface.

[0040] This embodiment creates n cryptographic card device interfaces on the host machine, each corresponding to a communication queue. When the VSM is started, the designated cryptographic card device is assigned to the VSM. Each VSM accesses the resources within the corresponding cryptographic card through a communication queue. A single cryptographic card can support multiple device interfaces while ensuring that each VSM exclusively uses a cryptographic card device interface. This reduces the complexity of the VSM's cryptographic component isolation architecture and improves reliability. Furthermore, this embodiment communicates directly with virtual machines through communication queues, eliminating the need for a two-level cache, thus avoiding the problem of excessive memory usage and complex software design.

[0041] In some embodiments, the VSM uses Docker containers to implement virtualization.

[0042] It should be noted that virtual machines can be implemented using either KVM (Kernel-based Virtual Machine) or Docker. Docker is used because it has the following advantages over KVM:

[0043] (1) Lightweight: Docker containers are lighter than KVM virtual machines and can start up faster, in seconds. This makes Docker more flexible and efficient in handling rapid deployment and expansion.

[0044] (2) Resource Utilization: Docker containers have higher resource utilization, while KVM virtual machines usually require more resources. This gives Docker an advantage in improving resource utilization and reducing costs.

[0045] (3) Performance Overhead: Docker containers implement virtualization at the operating system level, directly reusing the local host's operating system, so the performance overhead is relatively small. KVM, on the other hand, is a hardware-level virtualization technology that requires additional CPU and memory to complete OS (Operating System) functions, resulting in a relatively large performance overhead.

[0046] (4) Containerized Applications: Docker can easily implement container applications, making application packaging, deployment, and expansion simpler and more efficient. KVM, on the other hand, is relatively complex in handling container applications and requires more configuration and management.

[0047] In some embodiments, the steps of implementing cryptographic machine virtualization with a Docker container in this embodiment include:

[0048] (1) Create a basic image of a virtual cryptographic machine.

[0049] (2) Write a Dockerfile file to package the application, dependent library files, scripts, etc., and build a virtual cryptographic machine image.

[0050] (3) After the virtual cipher machine is started, a virtual network card is created and communication with the outside world is carried out through the virtual network card.

[0051] In some embodiments, assigning a designated cryptographic card device interface to a VSM includes:

[0052] Use the device command to assign the specified password card device interface to the VSM.

[0053] Specifically, VSM uses Docker containers for virtualization. When starting a VSM, you assign a specific cryptographic card device to it using the --device command option. This allows the VSM to exclusively use a cryptographic card device interface. Once the VSM is started, the cryptographic card device interface can be accessed from within the container, isolating the cryptographic components between different VSMs.

[0054] In some embodiments, each cryptographic card device interface uses an independent communication queue, and each communication queue is isolated from each other.

[0055] Different VSMs access the resources allocated to the virtual machine inside the password card through different assigned password card communication queue interfaces, so as to achieve resource isolation between different VSMs, as shown in Figure 2.

[0056] In addition, as shown in FIG3 , the embodiment of the present application also discloses a VSM cryptographic component isolation system, which includes:

[0057] The cryptographic card device interface creation module 10 is used to load the cryptographic card driver on the host machine equipped with the cryptographic card, and to create corresponding n cryptographic card device interfaces based on n communication queues in the cryptographic card;

[0058] The interface allocation module 20 is used to allocate the specified password card device interface to the VSM after the VSM is started, so that the VSM can access the corresponding password card device interface inside the docker container;

[0059] The resource allocation module 30 is used to access the resources allocated to the VSM in the password card through the corresponding password card device interface.

[0060] In some embodiments, the VSM uses Docker containers to implement virtualization.

[0061] In some embodiments, the interface allocation module is specifically configured to allocate a specified cryptographic card device interface to the VSM through a device command.

[0062] In some embodiments, each cryptographic card device interface uses an independent communication queue, and the cryptographic card device interfaces are isolated from each other.

[0063] In addition, the embodiment of the present application also discloses a VSM cryptographic component isolation device, as shown in FIG4 , including a processor 401, a communication interface 402, a memory 403, and a communication bus 404, wherein the processor 401, the communication interface 402, and the memory 403 communicate with each other through the communication bus 404.

[0064] Memory 403, used for storing computer programs;

[0065] The processor 401 is configured to implement the above-mentioned VSM cryptographic component isolation method when executing the program stored in the memory 403 .

[0066] The communication bus mentioned in the terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.

[0067] The communication interface is used for communication between the above terminal and other devices.

[0068] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.

[0069] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0070] In addition, as shown in FIG5 , an embodiment of the present application further discloses a computer-readable storage medium 501 on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned VSM cryptographic component isolation method is implemented.

[0071] It should be noted that the logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device), or in conjunction with such instruction execution system, apparatus, or device. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by an instruction execution system, apparatus, or device, or in conjunction with such instruction execution system, apparatus, or device. More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection portion having one or more wires (electronic device), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and portable compact disc read-only memory (CDROM). Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or otherwise processing it in a suitable manner if necessary, and then storing it in a computer memory.

[0072] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0073] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present application. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.

[0074] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of such features. Throughout the description of this application, "plurality" means at least two, for example, two, three, etc., unless otherwise specifically defined.

[0075] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A method for isolating cryptographic components of a VSM, wherein: The method comprises: Loading a cryptographic card driver on a host machine equipped with an encryption card, and creating corresponding n cryptographic card device interfaces based on n communication queues in the encryption card; After the virtual cryptographic machine is started, the designated cryptographic card device interface is allocated to the virtual cryptographic machine, so that the virtual cryptographic machine accesses the corresponding cryptographic card device interface inside the Docker container; The resources allocated to the virtual cryptographic machine inside the cryptographic card are accessed through the corresponding cryptographic card device interface.

2. The cryptographic component isolation method of VSM as claimed in claim 1, wherein: The virtual cryptographic machine uses the docker container to achieve virtualization.

3. The cryptographic component isolation method of VSM as claimed in claim 2, wherein: The virtual cryptographic machine uses the docker container to achieve virtualization, including: Constructing a virtual cryptographic machine image of the virtual cryptographic machine; In response to the startup of the virtual cryptographic machine, a virtual network card is created, and the virtual cryptographic machine communicates with the outside world through the virtual network card.

4. The cryptographic component isolation method of VSM as claimed in claim 1, wherein: The step of allocating the designated cryptographic card device interface to the virtual cryptographic machine comprises: The specified cryptographic card device interface is allocated to the virtual cryptographic machine through the device command.

5. The cryptographic component isolation method of VSM as claimed in claim 1, wherein: Each cryptographic card device interface uses an independent communication queue, and each communication queue is isolated from each other.

6. A cryptographic component isolation system for a VSM, wherein: The system comprises: A cryptographic card device interface creation module, used to load a cryptographic card driver on a host machine equipped with an encryption card, and to create corresponding n cryptographic card device interfaces based on n communication queues in the encryption card; An interface allocation module is used to allocate a specified cryptographic card device interface to the virtual cryptographic machine after the virtual cryptographic machine is started, so that the virtual cryptographic machine can access the corresponding cryptographic card device interface inside the Docker container; The resource allocation module is used to access the resources allocated to the virtual cryptographic machine inside the cryptographic card through the corresponding cryptographic card device interface.

7. The cryptographic component isolation system of VSM as claimed in claim 6, wherein: The virtual cryptographic machine uses the docker container to achieve virtualization.

8. The cryptographic component isolation system of VSM as claimed in claim 7, wherein: The virtual cryptographic machine uses the docker container to achieve virtualization, including: Constructing a virtual cryptographic machine image of the virtual cryptographic machine; In response to the startup of the virtual cryptographic machine, a virtual network card is created, and the virtual cryptographic machine communicates with the outside world through the virtual network card.

9. The cryptographic component isolation system of VSM as claimed in claim 6, wherein: The interface allocation module is specifically used to allocate the specified cryptographic card device interface to the virtual cryptographic machine through a device command.

10. The cryptographic component isolation system of VSM according to claim 6, wherein: Each cryptographic card device interface uses an independent communication queue, and the cryptographic card device interfaces are isolated from each other.

11. A cryptographic component isolation device for a VSM, wherein: The device includes a memory and a processor; wherein the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the method according to any one of claims 1 to 5.

12. A computer-readable storage medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • System supporting hardware visualization

    CN106874065A

  • Cryptographic device virtualization method and equipment

    CN108228316A

  • Kubernetes component configuration method and device, equipment and medium

    CN114995956A

  • VSM password component isolation method, system and device and storage medium

    CN117592133A

  • Managing containers and container hosts in a virtualized computer system

    US20170371693A1