WO2017114103A1 - 一种云加密机的处理方法及装置 - Google Patents
一种云加密机的处理方法及装置 Download PDFInfo
- Publication number
- WO2017114103A1 WO2017114103A1 PCT/CN2016/108657 CN2016108657W WO2017114103A1 WO 2017114103 A1 WO2017114103 A1 WO 2017114103A1 CN 2016108657 W CN2016108657 W CN 2016108657W WO 2017114103 A1 WO2017114103 A1 WO 2017114103A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- target
- application container
- node
- application
- computing node
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/40—Support for services or applications
Definitions
- the present invention relates to the field of information security, and in particular, to a method and an apparatus for processing a cloud encryption machine.
- the prior art external application usually invokes the encryption machine in the following two ways: (1) the application writes an instruction that the encryption machine can process when the encryption machine needs to be called, and the application server directly connects to the encryption machine, and transmits the above instruction to the instruction.
- the encryption machine performs a call to the encryption machine; (2) the application invokes an encryption machine in a cluster consisting of multiple encryption machines through a proxy server, in which case the application side needs to develop a program that interacts with the proxy server.
- the instructions that the generated encryption machine can process are transmitted to the encryption machine through the proxy server to execute the call to the encryption machine.
- the logical processing functions of the encryption machines required for different applications may be different, so the interactive programs of the proxy servers corresponding to each application may also be different.
- the above-mentioned prior art external application invokes the encryption machine in the following way: if the application directly connects multiple encryption machines to send instructions, it is necessary to manage and maintain the connection of each connected encryption machine, bringing the application itself. Higher use cost; if the application calls the encryption machine through proxy access, the application also needs to develop the corresponding proxy server according to the requirements, which also increases the application cost, and the existing encryption machine sets the password at the factory. Operation container, if needed Adding a container for cryptographic operations of other applications needs to be added back to the factory, and the resources in a hardware encryption machine are not fully utilized.
- the prior art method of calling the encryption machine has the problem that the operation and maintenance cost of the external application calling encryption machine is high and the resource utilization rate of the encryption machine is low.
- the embodiment of the invention provides a method and a device for processing a cloud encryption machine, which are used to solve the problem of high operation and maintenance cost of the external application calling encryption machine and low resource utilization of the encryption machine in the prior art.
- the method of the present invention includes a processing method of a cloud encryption machine, the method comprising: receiving an application container configuration command, where the application container configuration command includes a target application identifier; acquiring an internal computing node State information, wherein each application container is configured to perform a security operation for an application, the state information including application container information contained in each internal computing node; state information according to each internal computing node and the application
- the target application identifier in the program container configuration command determines a target internal computing node; and executes the application container configuration command on the target internal computing node.
- the application container configuration command is a configuration command for adding an application container;
- the state information of each internal operation node further includes resource information of each internal computing node;
- Determining the target internal computing node according to the state information of each internal computing node and the target application identifier in the application container configuration command including:
- the executing the application container configuration command on the target internal computing node includes:
- the application container configuration command is a configuration command for deleting an application container
- Determining the target internal computing node according to the status information of each node and the target application identifier in the application container configuration command including:
- the executing the application container configuration command on the target internal computing node includes:
- the configuration relationship table of the target internal operation node includes a mapping relationship between the target internal operation node and an application container on the target internal operation node.
- the method further includes:
- the determining, according to the configuration relationship table, the first internal operation node corresponding to the target application container corresponding to the application identifier including:
- an embodiment of the present invention further provides a processing apparatus for an encryption machine, the apparatus comprising: a receiving configuration command unit, configured to receive an application container configuration command, and the application container configuration command Included in the target application identifier; the acquisition status information unit is configured to obtain status information of each internal computing node, wherein each application container is configured to perform a security operation for an application, the status information including each internal operation An application container information included in the node; a determining unit, configured to determine a target internal computing node according to status information of each internal computing node and a target application identifier in the application container configuration command; The application container configuration command is executed on the target internal computing node.
- the application container configuration command is a configuration command for adding an application container;
- the state information of each internal operation node further includes resource information of each internal operation node;
- the determining unit is specifically configured to: determine, according to resource information of each internal computing node, a target internal computing node that has an idle resource;
- the execution unit is specifically configured to: add a target application container corresponding to the target application identifier on the target internal operation node; update a configuration relationship table of the target internal operation node, where the target internal operation node
- the configuration relationship table includes a mapping relationship between the target internal operation node and the application container on the target internal operation node.
- the application container configuration command is a configuration command for deleting an application container
- the determining unit is specifically configured to: determine an internal computing node that includes an application container corresponding to the target application identifier as the target internal computing node;
- the execution unit is specifically configured to: delete the target application container on the target internal computing node;
- the configuration relationship table of the target internal operation node includes a mapping relationship between the target internal operation node and an application container on the target internal operation node.
- the device further includes: a receiving message unit, configured to receive the application identifier Known pending messages;
- Obtaining a relationship table and a state unit configured to obtain a configuration relationship table of each internal operation node and a busy state of the target application container corresponding to the application identifier;
- a sending unit configured to send the to-be-processed message to the target application container in the second internal computing node, so that the target application container uses a key to secure the to-be-processed message operating.
- determining the first internal computing node unit is specifically configured to:
- an embodiment of the present invention provides an electronic device, including: a transceiver and a processor;
- the transceiver is configured to receive an application container configuration command, where the application container configuration command includes a target application identifier;
- the processor is configured to obtain state information on each internal computing node, wherein each application container is configured to perform a security operation on an application, where the state information includes an application container included in each internal computing node Information; determining a target internal computing node according to status information of each internal computing node and a target application identifier in the application container configuration command; executing the application container configuration command on the target internal computing node.
- the application container configuration command is a configuration command for adding an application container;
- the state information of each internal operation node further includes resource information of each internal computing node;
- the processor is specifically configured to:
- the configuration relationship table of the target internal operation node includes a mapping relationship between the target internal operation node and an application container on the target internal operation node.
- the application container configuration command is a configuration command for deleting an application container
- the processor is specifically configured to:
- the configuration relationship table of the target internal operation node includes a mapping relationship between the target internal operation node and an application container on the target internal operation node.
- the transceiver is further configured to: receive a to-be-processed message that includes an application identifier;
- the processor is further configured to:
- processor is specifically configured to:
- an embodiment of the present invention provides a non-transitory computer readable storage medium, where the non-transitory computer readable storage medium stores computer instructions, where the computer instructions are used to cause the computer to execute any of the above The processing method of the cloud encryption machine.
- an embodiment of the present invention provides a computer program product, the computer program product comprising a computing program stored on a non-transitory computer readable storage medium, the computer program comprising program instructions, when the program instruction is When the computer executes, the computer is caused to execute the processing method of the cloud encryption machine according to any one of the above.
- the cloud encryption machine includes a plurality of internal computing nodes, and each internal computing node integrates an application container for multiple applications, and thus each The internal computing node can perform corresponding cryptographic operations for different application call requests, which fully improves resource utilization.
- the cloud encryption machine includes a management center, and the external application calls the management center to the internal computing node.
- a configuration command occurs to complete the configuration of the logical processing function of each application container corresponding to the cloud encryption machine and the configuration of the application container. It can be seen that the external application can complete the rational configuration of the cloud encryption machine through the management center, and the external application itself can be used to develop a proxy server, which reduces the operation and maintenance cost of the external application calling the encryption machine.
- FIG. 1 is a structural diagram of a novel cloud encryption machine according to an embodiment of the present invention
- FIG. 2 is a schematic flowchart of a key management method of a cloud encryption machine according to an embodiment of the present invention
- FIG. 3 is a schematic flowchart of a packet processing method of a cloud encryption machine according to an embodiment of the present disclosure
- FIG. 4 is a schematic structural diagram of a processing apparatus of a cloud encryption machine according to an embodiment of the present disclosure
- FIG. 5 is a schematic structural diagram of a packet processing apparatus of a cloud encryption machine according to an embodiment of the present disclosure
- FIG. 6 is a schematic structural diagram of an electronic device according to an embodiment of the present invention.
- cloud computing Cloud Computing
- Cloud is an increase, use, and delivery mode of related services based on the Internet, and generally involves using the Internet.
- Providing dynamically scalable and often virtualized resources, cloud is a metaphor for the Internet and the Internet.
- the embodiment of the present invention provides a new type of cloud encryption machine structure diagram.
- the cloud encryption machine structure diagram mainly includes two parts: a management center and a computing center.
- each internal computing node may contain multiple application containers, for example, APP1 container, APPn, etc. in the figure, the so-called application container refers to data dedicated to one application. Processing the request's encryption and decryption operations container, different application containers respectively processing data processing requests of different applications.
- Each application container contains the appropriate key and arithmetic logic.
- the so-called arithmetic logic usually refers to cryptographic operations such as authentication and encryption.
- the application containers of each internal computing node are not necessarily identical. There may be more than one application container in each internal computing node. The specific number is determined according to actual needs, but each application container can only execute with it. The corresponding application's message processing request.
- the management center includes a configuration relationship table, which includes the key used by the computing center and all the logic. For specific external application requirements, part of the logic can be selected from all the logic of the application. In addition, both the management center and the computing center provide a unified interface for external application calls.
- the embodiment of the present invention provides a schematic flowchart of a processing method of a cloud encryption machine.
- the specific implementation method includes:
- Step S101 Receive an application container configuration command, where the application container configuration command includes a target application identifier.
- Step S102 Acquire state information of each application container set on each internal operation node, where each application container is used to perform a security operation for one application, and the state information includes an application included in each internal operation node.
- Container information Acquire state information of each application container set on each internal operation node, where each application container is used to perform a security operation for one application, and the state information includes an application included in each internal operation node.
- Step S103 determining a target internal computing node according to status information of each internal computing node and a target application identifier in the application container configuration command.
- Step S104 executing the application container configuration command on the target internal computing node.
- the configuration command of the target application container may be an initialization instruction of an external application or a certain external application, or may be an application efficiency of the external application based on the cloud encryption machine, and adjust the application in the cloud encryption machine.
- the instruction of the number of program containers may also be an instruction of an administrator received by the management center.
- step S102 the internal computing node on the cloud encryption machine periodically reports the state information of each application container on the internal computing node to the management center; or after receiving the configuration command of the application container in the management center, each of the cloud encryption machines is The internal computing node sends a status information acquisition request.
- the application container corresponding to the external application in the cloud encryption machine is an APP1 container.
- the POS acquiring application needs to invoke the cloud encryption machine to perform encryption for each POS transaction, it is necessary to pre-initialize the operation logic of each APP1 container in the cloud encryption machine to be encrypted, and fill in the corresponding key.
- the specific initialization method is: the POS acquiring application sends an initialization request including the receipt application identifier to the management center, where the initialization request includes the key and operation logic of the acquiring application as encryption, and then the management center is from the cloud encryption machine.
- each internal computing node Take the identification information corresponding to the application container, find all the APP1 containers, and then configure the operation logic of all APP1 containers to be encrypted and fill in the key of the acquiring application. At this point, the initialization process of the acquiring application is completed, and the subsequent POS acquiring application can directly send a message processing request to the cloud encrypting machine portal.
- the application container configuration command is a configuration command for adding an application container;
- the state information of each internal operation node further includes resource information of each internal operation node;
- Determining the target internal computing node according to the state information of each internal computing node and the target application identifier in the application container configuration command including:
- the executing the application container configuration command on the target internal computing node includes:
- the configuration relationship table of the target internal operation node includes a mapping relationship between the target internal operation node and an application container on the target internal operation node.
- the POS acquiring application may send a configuration command for adding the target application container to the management center, based on the command.
- the management center and the computing center interact to achieve the purpose of adding the APP1 container.
- the POS acquiring application sends a configuration command for adding the APP1 container to the management center, and then the management center obtains the resource information of each internal computing node of the cloud encryption machine, and finds the target internal computing node that still has the spare resource from all the internal computing nodes.
- the APP1 container is added to the internal operation nodes of these targets, and the new number is determined based on the requirements of the internal resources of the internal computing node and the number of new configuration commands.
- the management center needs to update the configuration relationship table of the internal computing node and the application container in the management center according to the state of the computing center at this time. For example, the internal computing node 1 has two APP1s before.
- the container becomes the three APP1 containers. In this case, the configuration relationship table is updated, so that the subsequent operation center obtains the configuration relationship table from the management center and processes the packets of the POS acquiring application.
- the application container configuration command is a configuration command for deleting an application container
- Determining the target internal computing node according to the state information of each application container and the target application identifier in the application container configuration command including:
- the executing the application container configuration command on the target internal computing node includes:
- the configuration relationship table of the target internal operation node includes a mapping relationship between the target internal operation node and an application container on the target internal operation node.
- the POS acquiring application sends a configuration command for deleting all APP1 containers to the management center, and the management center obtains all internal computing nodes including the APP1 container from the cloud encryption machine, and then deletes the APP1 containers on the internal computing nodes, of course, if the POS The acquiring application sends a configuration command to delete the APP1 container to the management center.
- the management center also obtains all internal computing nodes including the APP1 container from the computing center, and then deletes the APP1 container on some internal computing nodes. After the management center completes the deletion, The configuration relationship table in the management center is also updated, so that the subsequent computing center obtains the configuration relationship table from the management center and processes the packets of the POS acquiring application.
- the management center can receive the configuration command of the new application container of the external application, for example, by adding the above configuration command, for example, adding an online transaction application to the UnionPay device, so the current cloud encryption machine does not exist.
- the corresponding application container at this time, the cloud encryption machine cannot process the online transaction application, so the online transaction application can send the information to the management center.
- the management center updates the configuration table in the center, and sends the key and operation logic corresponding to the online transaction application to the computing center side, so the cloud encryption machine is idle.
- the application container corresponding to the online transaction application is added to the internal operation node of the resource.
- the processing method of the embodiment of the present invention facilitates the management and maintenance of the cloud encryption machine, and the cloud encryption machine integrates multiple application containers for each internal computing node, so that the cloud The encryption machine is equivalent to the cloud encryption machine pool, and the performance is improved, and the waste of resources is avoided.
- the other internal computing nodes can continue to process the message, which plays a role of load balancing.
- the embodiment of the present invention further provides a schematic diagram of a packet processing method of the cloud encryption machine, as shown in FIG. 3, where the cloud encryption machine can receive the pending processing sent by the application.
- the message is then computed based on the configured application container, specifically:
- Step S201 Receive a to-be-processed message that includes an application identifier.
- Step S202 acquiring a configuration relationship table of each internal operation node and a busy state of the target application container corresponding to the application identifier;
- Step S203 determining, according to the configuration relationship table, a first internal operation node corresponding to the target application corresponding to the application identifier;
- Step S204 selecting, from the first internal operation node, a second internal operation node corresponding to the target application container in an idle state;
- Step S205 Send the to-be-processed message to the target application container in the second internal operation node, so that the target application container uses a key to perform a security operation on the to-be-processed message.
- the message received by the POS acquiring application for each transaction is obtained by the cloud encrypting machine through a unified interface provided by the external application, and the interface is obtained from the management center based on the APP1 identifier in the packet. Find the internal operation node corresponding to the APP1 container, and then distribute each message to an internal operation node containing the APP1 container, and then these internal operation nodes will report The text performs the safe operation of the corresponding arithmetic logic.
- a backup interface is added to the interface, and the interface is added to the interface, and the interface is added to the interface.
- the interface is interconnected with the previous interface through the HA (load balancing) mechanism, and the purpose of the cloud encryption machine is to avoid the impact of a interface crash.
- the interface of the cloud encryption machine can also actively filter the packet to be processed when the packet is distributed, specifically: parsing the Internet Protocol IP address corresponding to the to-be-processed packet; determining whether the IP address is included in the cloud The IP address whitelist is preset in the encryption machine; if yes, the first internal computing node corresponding to the target application corresponding to the application identifier is determined according to the configuration relationship table.
- the computing center obtains a whitelist of IP addresses from the management center.
- the whitelist specifies that the packets sent by the IP address must be processed, and the packets sent by the other IP addresses are filtered out and are not processed. It is necessary to filter certain conditions before the internal operation node processes, which can increase the efficiency of encryption processing, and can also actively intercept messages that are not processed.
- the embodiment of the present invention further provides a processing device for a cloud encryption machine, which can execute the foregoing method embodiments.
- the apparatus provided by the embodiment of the present invention includes: a receiving configuration command unit 401, an acquiring state information unit 402, a determining unit 403, and an executing unit 404, where:
- Receiving a configuration command unit 401 configured to receive an application container configuration command, where the application container configuration command includes a target application identifier;
- the obtaining status information unit 402 is configured to obtain status information of each internal computing node, wherein each application container is configured to perform a security operation for an application, the status information including an application container included in each internal computing node information;
- a determining unit 403 configured to determine a target internal computing node according to status information of each internal computing node and a target application identifier in the application container configuration command;
- the executing unit 404 is configured to execute the application container configuration command on the target internal computing node.
- the state information of each internal computing node further includes resource information of each internal computing node.
- the determining unit 403 is specifically configured to: determine, according to resource information of each internal computing node, a target internal computing node that has an idle resource;
- the execution unit 404 is specifically configured to: add a target application container corresponding to the target application identifier on the target internal operation node; update a configuration relationship table of the target internal operation node, and the target internal operation node
- the configuration relationship table includes a mapping relationship between the target internal operation node and the application container on the target internal operation node.
- the application container configuration command is a configuration command for deleting an application container
- the determining unit 403 is specifically configured to: determine an internal computing node that includes an application container corresponding to the target application identifier as the target internal computing node;
- the execution unit 404 is specifically configured to: delete the target application container on the target internal operation node; update a configuration relationship table of the target internal operation node, and the configuration relationship table of the target internal operation node includes a target internal The mapping relationship between the compute node and the application container on the target internal compute node.
- the embodiment of the present invention further provides a schematic diagram of the message processing device of the cloud encryption machine, as shown in FIG. 5, where the cloud encryption machine can receive the pending processing sent by the application.
- the message is then operated based on the configured application container, including: a received message unit 501, an acquisition relationship table and status unit 502, a first internal operation node unit 503, a second internal operation node unit 504, and a sending unit. 505, where:
- the receiving message unit 501 is configured to receive a to-be-processed message that includes an application identifier.
- the sending unit 505 is configured to send the to-be-processed message to the target application container in the second internal computing node, so that the target application container uses the key to perform the to-be-processed message. Safe operation.
- the determining the first internal operation node unit 503 is specifically configured to: parse the Internet Protocol IP address corresponding to the to-be-processed message; and determine whether the IP address is included in a whitelist of the IP address preset by the cloud encryption machine. If yes, determining, according to the configuration relationship table, a first internal computing node corresponding to the target application corresponding to the application identifier.
- the embodiment of the present invention provides a novel cloud encryption machine.
- the cloud encryption machine includes multiple internal computing nodes, and each internal computing node integrates applications for multiple applications. Container, so each internal computing node can perform corresponding cryptographic operations for different application call requests, which greatly improves resource utilization;
- the cloud encryption machine includes a management center, and the external application calls the management center.
- a configuration command is generated to the internal computing node to complete the configuration of the logical processing function of each application container corresponding to the cloud encryption machine and the configuration of the application container in the cloud encryption machine.
- the external application can complete the rationalization configuration of the computing center through the management center, and the external application itself can be used to redevelop a proxy server, which reduces the operation and maintenance cost of the external application calling the encryption machine.
- FIG. 6 is a schematic structural diagram of an electronic device provided by the present invention, the electronic device 600 includes: a transceiver 601, a processor 602, a memory 603, and a bus system 604;
- the memory 603 is used to store a program.
- the program can include program code, the program code including computer operating instructions.
- the memory 603 may be a random access memory (RAM) or a non-volatile memory, such as at least one disk storage. Only one memory is shown in the figure, of course, the memory can also be set to a plurality as needed. Memory 603 can also be a memory in processor 602.
- the memory 603 stores the following elements, executable modules or data structures, or a subset thereof, or an extended set thereof:
- Operation instructions include various operation instructions for implementing various operations.
- Operating system Includes a variety of system programs for implementing various basic services and handling hardware-based tasks.
- Processor 602 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the foregoing method may be completed by an integrated logic circuit of hardware in the processor 602 or an instruction in a form of software.
- the processor 602 described above may be a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or discrete hardware. Component.
- DSP digital signal processor
- ASIC application specific integrated circuit
- FPGA field programmable gate array
- the methods, steps, and logical block diagrams disclosed in the embodiments of the present application can be implemented or executed.
- the general purpose processor may be a microprocessor or the processor or any conventional processor or the like.
- the steps of the method disclosed in the embodiments of the present application may be directly implemented by the hardware decoding processor, or may be performed by a combination of hardware and software modules in the decoding processor.
- the software module can be located in a conventional storage medium such as random access memory, flash memory, read only memory, programmable read only memory or electrically erasable programmable memory, registers, and the like.
- the storage medium is located in the memory 603, and the processor 602 reads the information in the memory 603 and performs the following steps in conjunction with its hardware:
- the transceiver 601 is configured to receive an application container configuration command, where the application container configuration command includes a target application identifier;
- the processor 602 is configured to obtain state information on each internal computing node, where each application container is configured to perform a security operation on an application, where the state information includes an application included in each internal computing node.
- Container information determining a target internal computing node according to status information of each internal computing node and a target application identifier in the application container configuration command; executing the application container configuration command on the target internal computing node.
- the status information of each internal computing node further includes resource information of each internal computing node
- the processor 602 is specifically configured to: determine, according to resource information of each internal computing node, a target internal computing node that has an idle resource;
- the configuration relationship table of the target internal operation node includes a mapping relationship between the target internal operation node and an application container on the target internal operation node.
- the application container configuration command is a configuration command for deleting an application container
- the processor is specifically configured to:
- the configuration relationship table of the target internal operation node includes a mapping relationship between the target internal operation node and an application container on the target internal operation node.
- the transceiver 601 is further configured to: receive a to-be-processed message that includes an application identifier;
- the processor 602 is further configured to: obtain a configuration relationship table of each internal operation node, and a busy state of the target application container corresponding to the application identifier;
- processor 602 is specifically configured to:
- the electronic device of the embodiment of the invention exists in various forms, including but not limited to:
- Mobile communication devices These devices are characterized by mobile communication functions and are mainly aimed at providing voice and data communication. Such devices include: smart phones (such as iPhone), multimedia phones, functional phones, and low-end phones.
- Ultra-mobile personal computer equipment This type of equipment belongs to the category of personal computers, has computing and processing functions, and generally has mobile Internet access.
- Such terminals include: PDAs, MIDs, and UMPC devices, such as the iPad.
- Portable entertainment devices These devices can display and play multimedia content. Such devices include: audio, video players (such as iPod), handheld game consoles, e-books, and smart toys and portable car navigation devices.
- the server consists of a processor, a hard disk, a memory, a system bus, etc.
- the server is similar to a general-purpose computer architecture, but because of the need to provide highly reliable services, processing power and stability High reliability in terms of reliability, security, scalability, and manageability.
- the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .
- the present invention provides a non-transitory computer readable storage medium storing computer instructions for causing the computer to perform the cloud of any of the above The processing method of the encryption machine.
- the present invention also provides a computer program product comprising a computing program stored on a non-transitory computer readable storage medium, the computer program comprising program instructions, when the program instructions are executed by a computer And causing the computer to execute the processing method of the cloud encryption machine according to any one of the above.
- the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
- the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
- These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
- the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Multimedia (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Telephonic Communication Services (AREA)
- Storage Device Security (AREA)
- Computer And Data Communications (AREA)
Abstract
本发明公开了一种云加密机的处理方法及装置,该方法包括:接收应用程序容器配置命令,所述应用程序容器配置命令中包含目标应用程序标识;获取每个内部运算节点的状态信息,其中,每个应用程序容器用于针对一个应用程序执行安全操作,所述状态信息包括每个内部运算节点包含的应用程序容器信息;根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点;在所述目标内部运算节点上执行所述应用程序容器配置命令,用以解决现有技术中外部应用调用加密机的运维成本高且加密机的资源利用率低的问题。
Description
本申请要求在2015年12月28日提交中华人民共和国知识产权局、申请号为201511004741.8,发明名称为“一种云加密机的处理方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本发明涉及信息安全领域,尤其涉及一种云加密机的处理方法及装置。
目前,随着网络应用的日益广泛以及不同领域的业务种类的日益丰富,借助加密机进行安全性信息(即对安全性要求较高的信息,例如金融卡密码等)的交互变得越来越重要。
现有技术外部应用通常采用以下两种方式调用加密机:(1)应用在需要调用加密机时预先编写生成加密机能够处理的指令,应用对应的应用服务器直接连接加密机,将上述指令传送到该加密机以执行对加密机的调用;(2)应用通过代理服务器调用多个加密机组成的集群中的某个加密机,在这种情况下应用侧需开发与该代理服务器交互的程序,将应用生成的加密机能够处理的指令,通过代理服务器传送到加密机,以执行对加密机的调用。不同应用需要用到的加密机的逻辑处理功能有可能不同,因此每个应用对应开发的代理服务器的交互程序也可能不相同。
然而,上述现有技术外部应用调用加密机的方式存在以下问题:若应用直接连接多个加密机进行指令的发送,需要对每个连接的加密机进行连接的管理和维护,给应用自身带来较高的使用成本;若应用通过代理访问的方式调用加密机,应用也需要根据需求开发相应的代理服务器,同样增加应用的使用成本,同时现有的加密机中是在出厂时设定了密码运算的容器,若需要
新增其他应用的密码运算的容器,需要返厂增加,同时也使得一个硬件加密机中的资源没有得到充分的利用。
综上,现有技术的调用加密机的方式存在外部应用调用加密机的运维成本高且加密机的资源利用率低的问题。
发明内容
本发明实施例提供一种云加密机的处理方法及装置,用以解决现有技术中外部应用调用加密机的运维成本高且加密机的资源利用率低的问题。
第一方面,本发明方法包括一种云加密机的处理方法,该方法包括:接收应用程序容器配置命令,所述应用程序容器配置命令中包含目标应用程序标识;获取每个内部运算节点上的状态信息,其中,每个应用程序容器用于针对一个应用程序执行安全操作,所述状态信息包括每个内部运算节点包含的应用程序容器信息;根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点;在所述目标内部运算节点上执行所述应用程序容器配置命令。
优选地,若所述应用程序容器配置命令为增加应用程序容器的配置命令;所述每个内部运算节点的状态信息中还包括每个内部运算节点的资源信息;
所述根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点,包括:
根据每个内部运算节点的资源信息,确定具有空闲资源的目标内部运算节点;
所述在所述目标内部运算节点上执行所述应用程序容器配置命令,包括:
在所述目标内部运算节点上新增所述目标应用程序标识对应的目标应用程序容器;
更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映
射关系。
优选地,若所述应用程序容器配置命令为删除应用程序容器的配置命令;
所述根据每个节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点,包括:
将包含所述目标应用程序标识对应的应用程序容器的内部运算节点确定为所述目标内部运算节点;
所述在所述目标内部运算节点上执行所述应用程序容器配置命令,包括:
在所述目标内部运算节点上删除所述目标应用程序容器;
更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
进一步地,所述更新所述目标内部运算节点的配置关系表之后,还包括:
接收包含应用程序标识的待处理报文;
获取每个内部运算节点的配置关系表和所述应用程序标识对应的目标应用程序容器的忙闲状态;
根据所述配置关系表,确定所述应用程序标识对应的目标应用程序容器对应的第一内部运算节点;
从所述第一内部运算节点中选择处于空闲状态的目标应用程序容器对应的第二内部运算节点;
将所述待处理报文发送至所述第二内部运算节点中的所述目标应用程序容器,以使所述目标应用程序容器使用密钥对所述待处理报文进行安全操作。
进一步地,所述根据所述配置关系表,确定所述应用程序标识对应的目标应用程序容器对应的第一内部运算节点,包括:
解析所述待处理的报文对应的因特网协议IP地址;
判断所述IP地址是否包含于云加密机预设的IP地址白名单中;
若是,则根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点。
第二方面,基于同样的发明构思,本发明实施例进一步地提供一种加密机的处理装置,该装置包括:接收配置命令单元,用于接收应用程序容器配置命令,所述应用程序容器配置命令中包含目标应用程序标识;获取状态信息单元,用于获取每个内部运算节点的状态信息,其中,每个应用程序容器用于针对一个应用程序执行安全操作,所述状态信息包括每个内部运算节点包含的应用程序容器信息;确定单元,用于根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点;执行单元,用于在所述目标内部运算节点上执行所述应用程序容器配置命令。
优选地,若所述应用程序容器配置命令为增加应用程序容器的配置命令;所述每个内部运算节点的状态信息中还包括各每个内部运算节点的资源信息;
所述确定单元具体用于:根据每个内部运算节点的资源信息,确定具有空闲资源的目标内部运算节点;
所述执行单元具体用于:在所述目标内部运算节点上新增所述目标应用程序标识对应的目标应用程序容器;更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
优选地,若所述应用程序容器配置命令为删除应用程序容器的配置命令;
所述确定单元具体用于:将包含所述目标应用程序标识对应的应用程序容器的内部运算节点确定为所述目标内部运算节点;
所述执行单元具体用于:在所述目标内部运算节点上删除所述目标应用程序容器;
更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
进一步地,所述装置还包括:接收报文单元,用于接收包含应用程序标
识的待处理报文;
获取关系表和状态单元,用于获取每个内部运算节点的配置关系表和所述应用程序标识对应的目标应用程序容器的忙闲状态;
确定第一内部运算节点单元,用于根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点;
确定第二内部运算节点单元,用于从所述第一内部运算节点中选择处于空闲状态的目标应用程序容器对应的第二内部运算节点;
发送单元,用于将所述待处理报文发送至所述第二内部运算节点中的所述目标应用程序容器,以使所述目标应用程序容器使用密钥对所述待处理报文进行安全操作。
进一步地,所述确定第一内部运算节点单元具体用于:
解析所述待处理的报文对应的因特网协议IP地址;
判断所述IP地址是否包含于云加密机预设的IP地址白名单中;
若是,则根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点。
第三方面,本发明实施例提供一种电子设备,包括:收发器、处理器;
所述收发器,用于接收应用程序容器配置命令,所述应用程序容器配置命令中包含目标应用程序标识;
所述处理器,用于获取每个内部运算节点上的状态信息,其中,每个应用程序容器用于针对一个应用程序执行安全操作,所述状态信息包括每个内部运算节点包含的应用程序容器信息;根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点;在所述目标内部运算节点上执行所述应用程序容器配置命令。
优选地,若所述应用程序容器配置命令为增加应用程序容器的配置命令;所述每个内部运算节点的状态信息中还包括每个内部运算节点的资源信息;
所述处理器具体用于:
根据每个内部运算节点的资源信息,确定具有空闲资源的目标内部运算
节点;
在所述目标内部运算节点上新增所述目标应用程序标识对应的目标应用程序容器;
更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
优选地,若所述应用程序容器配置命令为删除应用程序容器的配置命令;
所述处理器具体用于:
将包含所述目标应用程序标识对应的应用程序容器的内部运算节点确定为所述目标内部运算节点;
在所述目标内部运算节点上删除所述目标应用程序容器;
更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
进一步地,所述收发器还用于:接收包含应用程序标识的待处理报文;
所述处理器还用于:
获取每个内部运算节点的配置关系表和所述应用程序标识对应的目标应用程序容器的忙闲状态;
根据所述配置关系表,确定所述应用程序标识对应的目标应用程序容器对应的第一内部运算节点;
从所述第一内部运算节点中选择处于空闲状态的目标应用程序容器对应的第二内部运算节点;
将所述待处理报文发送至所述第二内部运算节点中的所述目标应用程序容器,以使所述目标应用程序容器使用密钥对所述待处理报文进行安全操作。
进一步地,所述处理器具体用于:
解析所述待处理的报文对应的因特网协议IP地址;
判断所述IP地址是否包含于云加密机预设的IP地址白名单中;
若是,则根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点。
第四方面,本发明实施例提供一种非暂态计算机可读存储介质,所述非暂态计算机可读存储介质存储计算机指令,所述计算机指令用于使所述计算机执行上述任一项所述的云加密机的处理方法。
第五方面,本发明实施例提供一种计算机程序产品,所述计算机程序产品包括存储在非暂态计算机可读存储介质上的计算程序,所述计算机程序包括程序指令,当所述程序指令被计算机执行时,使所述计算机执行上述任一项所述的云加密机的处理方法。
本发明实施例通过提供一种新型的云加密机,一方面该云加密机中包含多个内部运算节点,每个内部运算节点中都集成了针对多个应用程序的应用程序容器,因此每个内部运算节点可以针对不同的应用程序的调用请求执行相应的密码运算,充分的提高了资源的利用率;另一方面,云加密机中包含管理中心,外部应用通过调用管理中心,向内部运算节点发生配置命令,完成对应云加密机的每个应用程序容器的逻辑处理功能的配置和应用程序容器的配置。可见,外部应用可以通过管理中心完成云加密机的合理化配置,无需外部应用自身再去开发一套代理服务器,降低了外部应用调用加密机的运维成本。
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例描述中所需要使用的附图作简要介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域的普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。
图1为本发明实施例提供的一种新型云加密机结构图;
图2为本发明实施例提供的一种云加密机的密钥管理方法流程示意图;
图3为本发明实施例提供的一种云加密机的报文处理方法流程示意图;
图4为本发明实施例提供的一种云加密机的处理装置结构示意图;
图5为本发明实施例提供的一种云加密机的报文处理装置结构示意图;
图6为本发明实施例提供一种电子设备架构示意图。
为了使本发明的目的、技术方案和优点更加清楚,下面将结合附图对本发明作进一步地详细描述,显然,所描述的实施例仅仅是本发明一部份实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其它实施例,都属于本发明保护的范围。
需要说明的是,本发明实施中云加密机的处理方法,是基于目前的云计算技术,所谓云计算(Cloud Computing)是基于互联网的相关服务的增加、使用和交付模式,通常涉及通过互联网来提供动态易扩展且经常是虚拟化的资源,云是网络、互联网的一种比喻说法。
基于上述云计算技术,本发明实施例提供一种新型的云加密机结构图,参见图1所示,该云加密机结构图中,主要包括两个部分:管理中心和运算中心。
其中,运算中心中有多个内部运算节点,每个内部运算节点中可能包含多个应用程序容器,例如,图中的APP1容器、APPn等,所谓应用程序容器指的是专门处于一个应用的数据处理请求的加解密运算容器,不同的应用程序容器分别处理不同的应用的数据处理请求。每个应用程序容器中包含相应的密钥和运算逻辑。所谓运算逻辑通常指的是鉴权、加密等密码运算。每个内部运算节点的应用程序容器并不一定完全相同,每个内部运算节点中的同一个应用程序容器可能有多个,具体数目根据实际需要确定,但是每个应用程序容器只能执行与之对应的应用的报文处理请求。
管理中心中包括一个配置关系表,该表中包括运算中心要用到的密钥和所有的运算逻辑,针对特定的外部应用需求,可以从该应用的所有的运算逻辑选择部分运算逻辑。另外,管理中心和运算中心均提供了一个统一的接口供外部应用调用。
基于背景技术中提到的现有技术的缺陷,本发明实施例提供一种云加密机的处理方法流程示意图,参见图2所示,具体地实现方法包括:
步骤S101,接收应用程序容器配置命令,所述应用程序容器配置命令中包含目标应用程序标识。
步骤S102,获取每个内部运算节点上设置的各应用程序容器的状态信息,其中,每个应用程序容器用于针对一个应用程序执行安全操作,所述状态信息包括每内部运算节点包含的应用程序容器信息。
步骤S103,根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点。
步骤S104,在所述目标内部运算节点上执行所述应用程序容器配置命令。
在步骤S101中,上述目标应用程序容器的配置命令可以是某个外部应用或某几个外部应用的初始化指令,也可以是外部应用基于云加密机的工作效率状况,调整云加密机中的应用程序容器数量的指令,也可以是管理中心接收的管理员的指令。
在步骤S102中,云加密机上的内部运算节点周期性向管理中心上报该内部运算节点上各应用程序容器的状态信息;或者在管理中心接收到应用程序容器的配置命令后,向云加密机的各内部运算节点发送状态信息获取请求。
假设外部应用是一个POS收单应用,云加密机中与该外部应用对应的应用程序容器是APP1容器。当POS收单应用需要调用云加密机进行每笔POS交易的加密时,需要预先初始化云加密机中每个APP1容器的运算逻辑为加密,并灌入相应的密钥。具体初始化方法为:POS收单应用向管理中心发送一个包含该收单应用标识的初始化请求,该初始化请求中包含该收单应用的密钥和运算逻辑为加密,然后管理中心从云加密机的每个内部运算节点中获
取应用程序容器对应的标识信息,找出所有的APP1容器,然后配置所有APP1容器的运算逻辑为加密,并灌入该收单应用的密钥。至此,该收单应用的初始化过程就完成了,后续POS收单应用可以直接向云加密机的入口发送报文处理请求。
进一步地,若所述应用程序容器配置命令为增加应用程序容器的配置命令;所述每个内部运算节点的状态信息中还包括每个内部运算节点的资源信息;
所述根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点,包括:
根据每个内部运算节点的资源信息,确定具有空闲资源的目标内部运算节点;
所述在所述目标内部运算节点上执行所述应用程序容器配置命令,包括:
在所述目标内部运算节点上新增所述目标应用程序标识对应的目标应用程序容器;
更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
举例来说,若短时间内POS收单应用中交易量骤增,那么为了要提高云加密机的处理效率,POS收单应用可以向管理中心发送增加目标应用程序容器的配置命令,基于该命令,管理中心和运算中心进行交互,可以实现增加APP1容器的目的。具体为,POS收单应用向管理中心发送增加APP1容器的配置命令,然后管理中心获取云加密机每个内部运算节点的资源信息,从所有内部运算节点中找到仍存在空余资源的目标内部运算节点,然后在这些目标内部运算节点上新增APP1容器,新增的数目基于内部运算节点的空余资源情况以及配置命令的新增数量的要求决定。当云加密机中新增了APP1容器后,管理中心需要根据运算中心此时的状态,更新管理中心中关于内部运算节点和应用程序容器的配置关系表,例如内部运算节点1之前有2个APP1
容器,执行完配置命令之后变成了3个APP1容器,此时更新配置关系表,以便于后续运算中心从管理中心获取配置关系表,处理POS收单应用的报文。
进一步地,若所述应用程序容器配置命令为删除应用程序容器的配置命令;
所述根据各应用程序容器的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点,包括:
将包含所述目标应用程序标识对应的应用程序容器的内部运算节点确定为所述目标内部运算节点;
所述在所述目标内部运算节点上执行所述应用程序容器配置命令,包括:
在所述目标内部运算节点上删除所述目标应用程序容器;
更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
比如说,若一段时间内POS收单应用中交易量减少,甚至可以确定在一段时间内该收单应用不会有交易,那么为了释放云加密机中资源供其它应用使用,此时,就需要根据实际需要减少云加密机中的APP1容器的数量,甚至完全删除掉。具体为:POS收单应用向管理中心发送删除全部APP1容器的配置命令,管理中心从云加密机中获取所有包含APP1容器的内部运算节点,然后删除这些内部运算节点上的APP1容器,当然若POS收单应用向管理中心发送删除部分APP1容器的配置命令,管理中心也是从运算中心中获取所有包含APP1容器的内部运算节点,然后删除部分内部运算节点上的APP1容器,当管理中心完成删除之后,同样更新该管理中心中的配置关系表,以便于后续运算中心从管理中心获取配置关系表,处理POS收单应用的报文。
进一步地,管理中心除了利用完成上述配置命令,也可以接收外部应用的新增应用程序容器的配置命令,比如在银联装置中新增了一个网上交易应用,那么目前云加密机中并不存在与之对应的应用程序容器,此时云加密机就无法处理这一网上交易应用,因此该网上交易应用可以向管理中心发送关
于该应用的新增应用程序的命令,管理中心接收配置命令后,更新本中心中的配置表,将网上交易应用对应的密钥和运算逻辑发送至运算中心侧,云加密机因此在有空闲资源的内部运算节点上新增网上交易应用对应的应用程序容器。
从上述云加密机的处理过程,可见,通过本发明实施例的处理方法,方便了对云加密机的管理和维护,另外云加密机每个内部运算节点集成了多个应用程序容器,使得云加密机相当于云加密机池,性能得到提高,也避免了资源的浪费,同时假若一个内部运算节点发生故障,其余内部运算节点也可以继续处理报文,起到了负载均衡的作用。
云加密机在完成初始化或者调整应用程序容器的命令后,本发明实施例进一步提供云加密机的报文处理方法流程示意图,如图3所示,图中云加密机可以接收应用发送的待处理的报文,然后基于配置完成的应用程序容器进行运算,具体为:
步骤S201,接收包含应用程序标识的待处理报文;
步骤S202,获取每个内部运算节点的配置关系表和所述应用程序标识对应的目标应用程序容器的忙闲状态;
步骤S203,根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点;
步骤S204,从所述第一内部运算节点中选择处于空闲状态的目标应用程序容器对应的第二内部运算节点;
步骤S205,将所述待处理报文发送至所述第二内部运算节点中的所述目标应用程序容器,以使所述目标应用程序容器使用密钥对所述待处理报文进行安全操作。
假设接收的是POS收单应用发送的关于每笔交易的报文,云加密机通过对外部应用提供的统一的接口,该接口基于报文中的APP1标识,从管理中心中获取的配置关系表中,查找APP1容器对应的内部运算节点,然后将每条报文分发到一个包含APP1容器的内部运算节点上,然后这些内部运算节点将报
文进行相应运算逻辑的安全操作。
考虑到接口需要对报文进行分发处理,假如正在分发处理时,该接口突然崩溃,必然会严重影响后续的处理,因此,本发明实施例,进一步地,在接口新增了备用的接口,备用的接口与之前接口通过HA(负载均衡)机制互联,用的云加密机的目的,避免一个接口出现崩溃带来的影响。
同时,云加密机的接口在分发报文时,也可以主动过滤要处理的报文,具体为:解析所述待处理的报文对应的因特网协议IP地址;判断所述IP地址是否包含于云加密机预设的IP地址白名单中;若是,则根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点。
具体地,运算中心从管理中心上获取IP地址白名单,这个白名单规定那个IP地址发送过来的报文必须处理,其余IP地址发送过来的报文则过滤掉,不再处理,这样做的效果是在内部运算节点处理之前先进行一定条件的过滤,一来可以增加加密的处理效率,另外也可以主动拦截不要进行处理的报文。
基于相同的技术构思,本发明实施例还提供一种云加密机的处理装置,该装置可执行上述方法实施例。本发明实施例提供的装置如图4所示,包括:接收配置命令单元401、获取状态信息单元402、确定单元403、执行单元404,其中:
接收配置命令单元401,用于接收应用程序容器配置命令,所述应用程序容器配置命令中包含目标应用程序标识;
获取状态信息单元402,用于获取每个内部运算节点的状态信息,其中,每个应用程序容器用于针对一个应用程序执行安全操作,所述状态信息包括每个内部运算节点包含的应用程序容器信息;
确定单元403,用于根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点;
执行单元404,用于在所述目标内部运算节点上执行所述应用程序容器配置命令。
进一步地,若所述应用程序容器配置命令为增加应用程序容器的配置命
令;所述每个内部运算节点的状态信息中还包括各每个内部运算节点的资源信息。
所述确定单元403具体用于:根据每个内部运算节点的资源信息,确定具有空闲资源的目标内部运算节点;
所述执行单元404具体用于:在所述目标内部运算节点上新增所述目标应用程序标识对应的目标应用程序容器;更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
进一步地,若所述应用程序容器配置命令为删除应用程序容器的配置命令;
所述确定单元403具体用于:将包含所述目标应用程序标识对应的应用程序容器的内部运算节点确定为所述目标内部运算节点;
所述执行单元404具体用于:在所述目标内部运算节点上删除所述目标应用程序容器;更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
云加密机在完成初始化或者调整应用程序容器的命令后,本发明实施例进一步提供云加密机的报文处理装置示意图,如图5所示,图中云加密机可以接收应用发送的待处理的报文,然后基于配置完成的应用程序容器进行运算,包括:接收报文单元501、获取关系表和状态单元502、确定第一内部运算节点单元503、确定第二内部运算节点单元504、发送单元505,其中:
接收报文单元501,用于接收包含应用程序标识的待处理报文;
获取关系表和状态单元502,用于获取每个内部运算节点的配置关系表和所述应用程序标识对应的目标应用程序容器的忙闲状态;
确定第一内部运算节点单元503,用于根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点;
确定第二内部运算节点单元504,用于从所述第一内部运算节点中选择处
于空闲状态的目标应用程序容器对应的第二内部运算节点;
发送单元505,用于将所述待处理报文发送至所述第二内部运算节点中的所述目标应用程序容器,以使所述目标应用程序容器使用密钥对所述待处理报文进行安全操作。
进一步地,所述确定第一内部运算节点单元503具体用于:解析所述待处理的报文对应的因特网协议IP地址;判断所述IP地址是否包含于云加密机预设的IP地址白名单中;若是,则根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点。
综上所述,本发明实施例通过提供一种新型的云加密机,一方面该云加密机中包含多个内部运算节点,每个内部运算节点中都集成了针对多个应用程序的应用程序容器,因此每个内部运算节点可以针对不同的应用程序的调用请求执行相应的密码运算,充分的提高了资源的利用率;另一方面,云加密机中包含管理中心,外部应用通过调用管理中心,向内部运算节点发生配置命令,完成对应云加密机的每个应用程序容器的逻辑处理功能的配置和云加密机中应用程序容器的配置。可见,外部应用可以通过管理中心完成运算中心的合理化配置,无需外部应用自身再开发一套代理服务器,降低了外部应用调用加密机的运维成本。
基于相同的技术构思,本申请实施例提供另一种电子设备。图6为本发明提供的电子设备的结构示意图,该电子设备600包括:收发器601、处理器602、存储器603、总线系统604;
其中,存储器603,用于存放程序。具体地,程序可以包括程序代码,程序代码包括计算机操作指令。存储器603可能为随机存取存储器(random access memory,简称RAM),也可能为非易失性存储器(non-volatile memory),例如至少一个磁盘存储器。图中仅示出了一个存储器,当然,存储器也可以根据需要,设置为多个。存储器603也可以是处理器602中的存储器。
存储器603存储了如下的元素,可执行模块或者数据结构,或者它们的子集,或者它们的扩展集:
操作指令:包括各种操作指令,用于实现各种操作。
操作系统:包括各种系统程序,用于实现各种基础业务以及处理基于硬件的任务。
上述本申请实施例揭示的方法可以应用于处理器602中,或者说由处理器602实现。处理器602可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器602中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器602可以是通用处理器、数字信号处理器(DSP)、专用集成电路(ASIC)、现场可编程门阵列(FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本申请实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器603,处理器602读取存储器603中的信息,结合其硬件执行以下步骤:
所述收发器601,用于接收应用程序容器配置命令,所述应用程序容器配置命令中包含目标应用程序标识;
所述处理器602,用于获取每个内部运算节点上的状态信息,其中,每个应用程序容器用于针对一个应用程序执行安全操作,所述状态信息包括每个内部运算节点包含的应用程序容器信息;根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点;在所述目标内部运算节点上执行所述应用程序容器配置命令。
可选的,若所述应用程序容器配置命令为增加应用程序容器的配置命令;所述每个内部运算节点的状态信息中还包括每个内部运算节点的资源信息;
所述处理器602具体用于:根据每个内部运算节点的资源信息,确定具有空闲资源的目标内部运算节点;
在所述目标内部运算节点上新增所述目标应用程序标识对应的目标应用程序容器;
更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
可选的,若所述应用程序容器配置命令为删除应用程序容器的配置命令;
所述处理器具体用于:
将包含所述目标应用程序标识对应的应用程序容器的内部运算节点确定为所述目标内部运算节点;
在所述目标内部运算节点上删除所述目标应用程序容器;
更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
进一步地,所述收发器601还用于:接收包含应用程序标识的待处理报文;
所述处理器602还用于:获取每个内部运算节点的配置关系表和所述应用程序标识对应的目标应用程序容器的忙闲状态;
根据所述配置关系表,确定所述应用程序标识对应的目标应用程序容器对应的第一内部运算节点;
从所述第一内部运算节点中选择处于空闲状态的目标应用程序容器对应的第二内部运算节点;
将所述待处理报文发送至所述第二内部运算节点中的所述目标应用程序容器,以使所述目标应用程序容器使用密钥对所述待处理报文进行安全操作。
进一步地,所述处理器602具体用于:
解析所述待处理的报文对应的因特网协议IP地址;
判断所述IP地址是否包含于云加密机预设的IP地址白名单中;
若是,则根据所述配置关系表,确定所述应用程序标识对应的目标应用
程序对应的第一内部运算节点。
本发明实施例的电子设备以多种形式存在,包括但不限于:
(1)移动通信设备:这类设备的特点是具备移动通信功能,并且以提供话音、数据通信为主要目标。这类设备包括:智能手机(例如iPhone)、多媒体手机、功能性手机,以及低端手机等。
(2)超移动个人计算机设备:这类设备属于个人计算机的范畴,有计算和处理功能,一般也具备移动上网特性。这类终端包括:PDA、MID和UMPC设备等,例如iPad。
(3)便携式娱乐设备:这类设备可以显示和播放多媒体内容。该类设备包括:音频、视频播放器(例如iPod),掌上游戏机,电子书,以及智能玩具和便携式车载导航设备。
(4)服务器:提供计算服务的设备,服务器的构成包括处理器、硬盘、内存、系统总线等,服务器和通用的计算机架构类似,但是由于需要提供高可靠的服务,因此在处理能力、稳定性、可靠性、安全性、可扩展性、可管理性等方面要求较高。
(5)其他具有数据交互功能的电子装置。
本领域技术人员可以理解实现上述实施例方法中的全部或部分步骤是可以通过程序来指令相关的硬件来完成,该程序存储在一个存储介质中,包括若干指令用以使得一个设备(可以是单片机,芯片等)或处理器(processor)执行本申请各个实施例方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。
另外,本发明还提供一种非暂态计算机可读存储介质,所述非暂态计算机可读存储介质存储计算机指令,所述计算机指令用于使所述计算机执行上述任一项所述的云加密机的处理方法。
另外,本发明还提供一种计算机程序产品,所述计算机程序产品包括存储在非暂态计算机可读存储介质上的计算程序,所述计算机程序包括程序指令,当所述程序指令被计算机执行时,使所述计算机执行上述任一项所述的云加密机的处理方法。
本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
尽管已描述了本发明的优选实施例,但本领域内的技术人员一旦得知了基本创造性概念,则可对这些实施例作出另外的变更和修改。所以,所附权利要求意欲解释为包括优选实施例以及落入本发明范围的所有变更和修改。
显然,本领域的技术人员可以对本发明进行各种改动和变型而不脱离本发明的精神和范围。这样,倘若本发明的这些修改和变型属于本发明权利要求及其等同技术的范围之内,则本发明也意图包含这些改动和变型在内。
Claims (17)
- 一种云加密机的处理方法,其特征在于,该方法包括:接收应用程序容器配置命令,所述应用程序容器配置命令中包含目标应用程序标识;获取每个内部运算节点上的状态信息,其中,每个应用程序容器用于针对一个应用程序执行安全操作,所述状态信息包括每个内部运算节点包含的应用程序容器信息;根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点;在所述目标内部运算节点上执行所述应用程序容器配置命令。
- 如权利要求1所述的方法,其特征在于,若所述应用程序容器配置命令为增加应用程序容器的配置命令;所述每个内部运算节点的状态信息中还包括每个内部运算节点的资源信息;所述根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点,包括:根据每个内部运算节点的资源信息,确定具有空闲资源的目标内部运算节点;所述在所述目标内部运算节点上执行所述应用程序容器配置命令,包括:在所述目标内部运算节点上新增所述目标应用程序标识对应的目标应用程序容器;更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
- 如权利要求1所述的方法,其特征在于,若所述应用程序容器配置命令为删除应用程序容器的配置命令;所述根据每个节点的状态信息和所述应用程序容器配置命令中的目标应 用程序标识,确定目标内部运算节点,包括:将包含所述目标应用程序标识对应的应用程序容器的内部运算节点确定为所述目标内部运算节点;所述在所述目标内部运算节点上执行所述应用程序容器配置命令,包括:在所述目标内部运算节点上删除所述目标应用程序容器;更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
- 如权利要求2或3所述的方法,其特征在于,所述更新所述目标内部运算节点的配置关系表之后,还包括:接收包含应用程序标识的待处理报文;获取每个内部运算节点的配置关系表和所述应用程序标识对应的目标应用程序容器的忙闲状态;根据所述配置关系表,确定所述应用程序标识对应的目标应用程序容器对应的第一内部运算节点;从所述第一内部运算节点中选择处于空闲状态的目标应用程序容器对应的第二内部运算节点;将所述待处理报文发送至所述第二内部运算节点中的所述目标应用程序容器,以使所述目标应用程序容器使用密钥对所述待处理报文进行安全操作。
- 如权利要求4所述的方法,其特征在于,所述根据所述配置关系表,确定所述应用程序标识对应的目标应用程序容器对应的第一内部运算节点,包括:解析所述待处理的报文对应的因特网协议IP地址;判断所述IP地址是否包含于云加密机预设的IP地址白名单中;若是,则根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点。
- 一种云加密机的处理装置,其特征在于,该装置包括:接收配置命令单元,用于接收应用程序容器配置命令,所述应用程序容器配置命令中包含目标应用程序标识;获取状态信息单元,用于获取每个内部运算节点的状态信息,其中,每个应用程序容器用于针对一个应用程序执行安全操作,所述状态信息包括每个内部运算节点包含的应用程序容器信息;确定单元,用于根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点;执行单元,用于在所述目标内部运算节点上执行所述应用程序容器配置命令。
- 如权利要求6所述的装置,其特征在于,若所述应用程序容器配置命令为增加应用程序容器的配置命令;所述每个内部运算节点的状态信息中还包括各每个内部运算节点的资源信息;所述确定单元具体用于:根据每个内部运算节点的资源信息,确定具有空闲资源的目标内部运算节点;所述执行单元具体用于:在所述目标内部运算节点上新增所述目标应用程序标识对应的目标应用程序容器;更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
- 如权利要求6所述的装置,其特征在于,若所述应用程序容器配置命令为删除应用程序容器的配置命令;所述确定单元具体用于:将包含所述目标应用程序标识对应的应用程序容器的内部运算节点确定为所述目标内部运算节点;所述执行单元具体用于:在所述目标内部运算节点上删除所述目标应用程序容器;更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
- 如权利要求7或8所述的装置,其特征在于,还包括:接收报文单元,用于接收包含应用程序标识的待处理报文;获取关系表和状态单元,用于获取每个内部运算节点的配置关系表和所述应用程序标识对应的目标应用程序容器的忙闲状态;确定第一内部运算节点单元,用于根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点;确定第二内部运算节点单元,用于从所述第一内部运算节点中选择处于空闲状态的目标应用程序容器对应的第二内部运算节点;发送单元,用于将所述待处理报文发送至所述第二内部运算节点中的所述目标应用程序容器,以使所述目标应用程序容器使用密钥对所述待处理报文进行安全操作。
- 如权利要求9所述的装置,其特征在于,所述确定第一内部运算节点单元具体用于:解析所述待处理的报文对应的因特网协议IP地址;判断所述IP地址是否包含于云加密机预设的IP地址白名单中;若是,则根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点。
- 一种电子设备,其特征在于,包括:收发器、处理器;所述收发器,用于接收应用程序容器配置命令,所述应用程序容器配置命令中包含目标应用程序标识;所述处理器,用于获取每个内部运算节点上的状态信息,其中,每个应用程序容器用于针对一个应用程序执行安全操作,所述状态信息包括每个内部运算节点包含的应用程序容器信息;根据每个内部运算节点的状态信息和所述应用程序容器配置命令中的目标应用程序标识,确定目标内部运算节点;在所述目标内部运算节点上执行所述应用程序容器配置命令。
- 如权利要求11所述的电子设备,其特征在于,若所述应用程序容器配置命令为增加应用程序容器的配置命令;所述每个内部运算节点的状态信 息中还包括每个内部运算节点的资源信息;所述处理器具体用于:根据每个内部运算节点的资源信息,确定具有空闲资源的目标内部运算节点;在所述目标内部运算节点上新增所述目标应用程序标识对应的目标应用程序容器;更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
- 如权利要求11所述的电子设备,其特征在于,若所述应用程序容器配置命令为删除应用程序容器的配置命令;所述处理器具体用于:将包含所述目标应用程序标识对应的应用程序容器的内部运算节点确定为所述目标内部运算节点;在所述目标内部运算节点上删除所述目标应用程序容器;更新所述目标内部运算节点的配置关系表,所述目标内部运算节点的配置关系表包括目标内部运算节点与目标内部运算节点上的应用程序容器的映射关系。
- 如权利要求12或13所述的电子设备,其特征在于,所述收发器还用于:接收包含应用程序标识的待处理报文;所述处理器还用于:获取每个内部运算节点的配置关系表和所述应用程序标识对应的目标应用程序容器的忙闲状态;根据所述配置关系表,确定所述应用程序标识对应的目标应用程序容器对应的第一内部运算节点;从所述第一内部运算节点中选择处于空闲状态的目标应用程序容器对应的第二内部运算节点;将所述待处理报文发送至所述第二内部运算节点中的所述目标应用程序容器,以使所述目标应用程序容器使用密钥对所述待处理报文进行安全操作。
- 如权利要求14所述的电子设备,其特征在于,所述处理器具体用于:解析所述待处理的报文对应的因特网协议IP地址;判断所述IP地址是否包含于云加密机预设的IP地址白名单中;若是,则根据所述配置关系表,确定所述应用程序标识对应的目标应用程序对应的第一内部运算节点。
- 一种非暂态计算机存储介质,其特征在于,所述非暂态计算机可读存储介质存储有计算机可执行指令,所述计算机可执行指令用于使所述计算机执行权利要求1至5任一项所述的方法。
- 一种计算机程序产品,其特征在于,所述计算机程序产品包括存储在非暂态计算机可读存储介质上的计算程序,所述计算机程序包括所述计算机可执行指令,当所述计算机可执行指令被计算机执行时,使所述计算机执行权利要求1至5任一项所述的方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201511004741.8A CN105933270B (zh) | 2015-12-28 | 2015-12-28 | 一种云加密机的处理方法及装置 |
| CN201511004741.8 | 2015-12-28 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017114103A1 true WO2017114103A1 (zh) | 2017-07-06 |
Family
ID=56839964
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/108657 Ceased WO2017114103A1 (zh) | 2015-12-28 | 2016-12-06 | 一种云加密机的处理方法及装置 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN105933270B (zh) |
| WO (1) | WO2017114103A1 (zh) |
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111585758A (zh) * | 2020-05-07 | 2020-08-25 | 成都农村商业银行股份有限公司 | 一种密钥管理平台及密钥管理方法 |
| CN118802815A (zh) * | 2024-04-12 | 2024-10-18 | 中国移动通信有限公司研究院 | 数据处理方法、装置、电子设备、存储介质及计算机程序产品 |
| WO2024260219A1 (zh) * | 2023-06-19 | 2024-12-26 | 华为技术有限公司 | 报文管控方法、装置及系统 |
| CN119603272A (zh) * | 2024-11-25 | 2025-03-11 | 北京密码云芯科技有限公司 | 虚拟密码机的管理方法、装置、设备、介质和产品 |
| US12380253B2 (en) | 2016-09-15 | 2025-08-05 | Nuts Holdings, Llc | Structured data folding with transmutations |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105933270B (zh) * | 2015-12-28 | 2019-01-22 | 中国银联股份有限公司 | 一种云加密机的处理方法及装置 |
| CN107623699A (zh) * | 2017-10-23 | 2018-01-23 | 山东渔翁信息技术股份有限公司 | 一种基于云环境的加密系统 |
| CN113282950B (zh) * | 2021-07-26 | 2021-12-21 | 阿里云计算有限公司 | 加密机的运维方法、装置、设备及系统 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040167959A1 (en) * | 2003-02-21 | 2004-08-26 | International Business Machines Corporation | Autonomic service routing using observed resource requirement for self-optimization |
| CN1662004A (zh) * | 2004-02-27 | 2005-08-31 | 华为技术有限公司 | 一种实现会话发起协议应用服务器多业务处理的方法 |
| CN103634339A (zh) * | 2012-08-22 | 2014-03-12 | 中国银联股份有限公司 | 虚拟加密机装置、金融加密机及加密报文的方法 |
| CN104683350A (zh) * | 2015-03-13 | 2015-06-03 | 北京深思数盾科技有限公司 | 一种可扩展的信息安全服务系统及方法 |
| CN105095317A (zh) * | 2014-05-23 | 2015-11-25 | 中国银联股份有限公司 | 分布式数据库服务管理系统 |
| CN105933270A (zh) * | 2015-12-28 | 2016-09-07 | 中国银联股份有限公司 | 一种云加密机的处理方法及装置 |
-
2015
- 2015-12-28 CN CN201511004741.8A patent/CN105933270B/zh active Active
-
2016
- 2016-12-06 WO PCT/CN2016/108657 patent/WO2017114103A1/zh not_active Ceased
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040167959A1 (en) * | 2003-02-21 | 2004-08-26 | International Business Machines Corporation | Autonomic service routing using observed resource requirement for self-optimization |
| CN1662004A (zh) * | 2004-02-27 | 2005-08-31 | 华为技术有限公司 | 一种实现会话发起协议应用服务器多业务处理的方法 |
| CN103634339A (zh) * | 2012-08-22 | 2014-03-12 | 中国银联股份有限公司 | 虚拟加密机装置、金融加密机及加密报文的方法 |
| CN105095317A (zh) * | 2014-05-23 | 2015-11-25 | 中国银联股份有限公司 | 分布式数据库服务管理系统 |
| CN104683350A (zh) * | 2015-03-13 | 2015-06-03 | 北京深思数盾科技有限公司 | 一种可扩展的信息安全服务系统及方法 |
| CN105933270A (zh) * | 2015-12-28 | 2016-09-07 | 中国银联股份有限公司 | 一种云加密机的处理方法及装置 |
Cited By (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12380253B2 (en) | 2016-09-15 | 2025-08-05 | Nuts Holdings, Llc | Structured data folding with transmutations |
| CN111585758A (zh) * | 2020-05-07 | 2020-08-25 | 成都农村商业银行股份有限公司 | 一种密钥管理平台及密钥管理方法 |
| WO2024260219A1 (zh) * | 2023-06-19 | 2024-12-26 | 华为技术有限公司 | 报文管控方法、装置及系统 |
| EP4718823A4 (en) * | 2023-06-19 | 2026-04-01 | Huawei Tech Co Ltd | METHOD, APPARATUS AND SYSTEM FOR MANAGING AND CONTROLLING MESSAGES |
| CN118802815A (zh) * | 2024-04-12 | 2024-10-18 | 中国移动通信有限公司研究院 | 数据处理方法、装置、电子设备、存储介质及计算机程序产品 |
| CN119603272A (zh) * | 2024-11-25 | 2025-03-11 | 北京密码云芯科技有限公司 | 虚拟密码机的管理方法、装置、设备、介质和产品 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN105933270B (zh) | 2019-01-22 |
| CN105933270A (zh) | 2016-09-07 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2017114103A1 (zh) | 一种云加密机的处理方法及装置 | |
| US20190236300A1 (en) | Service processing method and apparatus, data sharing system, and storage medium | |
| US11068597B2 (en) | Out of band management of basic input/output system secure boot variables | |
| US8943319B2 (en) | Managing security for computer services | |
| CN107577516B (zh) | 虚拟机密码重置方法、装置和系统 | |
| US20250088373A1 (en) | Validating Certificate Bundles With Asymmetric Keys | |
| CN116527397B (zh) | 云计算节点的安全配置 | |
| US11785082B2 (en) | Domain replication across regions | |
| EP3736718B1 (en) | A tpm-based secure multiparty computing system using a non-bypassable gateway | |
| TW201703485A (zh) | 編排實體與虛擬交換器以執行安全邊界之系統及方法 | |
| US20220365801A1 (en) | Cloud shell extension framework | |
| US20220052878A1 (en) | Techniques for utilizing multiple network interfaces for a cloud shell | |
| US11924086B2 (en) | Load-based management for NVME over TCP connections | |
| US20230376333A1 (en) | Single hop approach for distributed block storage via a network virtualization device | |
| US12530219B2 (en) | Time-bound live migration with minimal stop-and-copy | |
| CN111866092A (zh) | 消息传输的方法、装置、电子设备和可读存储介质 | |
| US9503420B2 (en) | Logical network separation method and apparatus | |
| WO2025188423A1 (en) | Virtual agent for container orchestration system | |
| WO2020242657A1 (en) | Connectivity migration in a virtual execution system | |
| US20260056916A1 (en) | Data migration using counter hashing | |
| US9021157B2 (en) | Reliable socket transfer based on initializing and re-initializing a communication link and retaining a connected state | |
| CN111490885A (zh) | 一种处理设备错误信息的方法、电子设备和存储介质 | |
| HK40097763A (zh) | 数据处理方法、装置、存储介质、电子设备及产品 | |
| CN116262177A (zh) | 云游戏登录方法、装置、计算机、存储介质及程序产品 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16880893 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16880893 Country of ref document: EP Kind code of ref document: A1 |