Automatic encryption and decryption system for cloud files
Abstract
An automatic encryption and decryption system for cloud files is to directly add an information security module to the cloud service platform system, and use the method of intercepting system commands. The group will verify the operating behavior of the system, and perform real-time data encryption and decryption during the process of reading and writing storage devices or files.

Term
No projected expiry on record.
- Priority and filed
- Granted
- Today
8 claims: 8 independent, 0 dependent
- 1一種雲端檔案自動加解密系統,係指一雲端服務平台資料安全防護模組,其係建置於雲端服務平台系統上的資訊安全模組,不需另外架設硬體模組,即可達成資料加密之目的,其中包含:一雲端虛擬主機管理安全模組,用以攔截雲端虛擬主機管理指令,並控制管理流程;一金鑰管控模組,進行該虛擬主機資訊與金鑰資訊比對,以驗證該虛擬主機之管理指令是否來自有權限人員的操作,並可暫存該金鑰資訊,以提升權限驗證的效率;一金鑰管理伺服器,接收來自該金鑰管控模組的金鑰資訊要求,依照該虛擬主機資訊參數回傳相對應的該金鑰資訊;一雲端虛擬主機系統I\O攔截模組,攔截該雲端虛擬主機I\O資訊,以取得在資料處理流程中讀取或寫入儲存設備的資料;以及一資料加解密模組,負責加解密由該雲端虛擬主機系統I\O攔截模組所送來的讀取或寫入儲存設備資料。
- 2如申請專利範圍第1項所述之雲端檔案自動加解密系統,其中該雲端服務平台系統可為Xen或KVM等雲端虛擬化系統。
- 3如申請專利範圍第1項所述之雲端檔案自動加解密系統,其中該雲端虛擬主機管理安全模組為嵌入於雲端虛擬主機管理系統中,可攔截及控管該雲端虛擬主機管理指令。
- 4如申請專利範圍第1項所述之雲端檔案自動加解密系 統,其中該金鑰管理伺服器採用標準的金鑰管理協定KMIP(Key Management Interoperability Protocol)以保護金鑰資訊的安全。
- 5如申請專利範圍第1項所述之雲端檔案自動加解密系統,其中該金鑰管理伺服器採用具安全性的傳輸協定SSL(Secure Sockets Layer)保護金鑰資訊傳送安全。
- 6如申請專利範圍第1項所述之雲端檔案自動加解密系統,其中該雲端虛擬主機系統I\O攔截模組嵌入於雲端虛擬主機I\O模組中,用以攔截雲端虛擬主機I\O資訊,藉以取得在資料處理流程中讀取或寫入儲存設備的資料。
- 7如申請專利範圍第1項所述之雲端檔案自動加解密系統,其中該資料加解密模組使用磁碟加密演算法,可支援CBC、LRW、XEX、XTS、CMC and EME或ESSIV等加密演算法。
- 8如申請專利範圍第1項所述之雲端檔案自動加解密系統,其中該資料加解密模組使用磁碟加密演算法可搭配128 bits、192 bits、256 bits金鑰對進行資料的加解密。
Independent claims8
27 paragraphs, as filed
Cloud file automatic encryption and decryption system
The present invention relates to a cloud file automatic encryption and decryption system, in particular to a data access encryption and decryption system applied to cloud platform virtualization host services. The information security module is directly added to the cloud service platform system, and the operation behavior of the virtualized host is verified by intercepting system commands, as well as the encryption and decryption of the accessed data. It is also equipped with a key management server to protect the security of key storage.
The continuous improvement of the information industry, network infrastructure and network technology has led to the advent of the era of cloud services, making cloud services the hottest topic recently. Cloud services use the network to communicate with multiple hosts for computing tasks; or allow users to use a variety of connected devices, such as personal computers, laptops, and smartphones, through the network connection at any time Access and use integrated information services and resources provided by cloud service providers anywhere.
Cloud services use a large number of virtualization technologies and architectures, and the resulting information security management problems are different from those in the traditional information security field. In addition, the host equipment and data of cloud virtualization host services are built and stored in the service providers computer room. , Which is not within the control of users. This feature makes large enterprises have great doubts when using cloud services. In order to increase the trust of users, in addition to the development of cloud service information security management, it is also necessary to provide data storage Store security protection to improve user acceptance of virtualized hosting services.
In practice, the protection of data storage security can be achieved by data encryption, and it can be divided into two types according to the different aspects of protection. One is built on the user's virtual host, which requires additional installation programs. , And user habits may need to be changed when data encryption is performed, resulting in low user acceptance; another way is to build on the cloud service platform system so that data encryption does not affect users. The existing data storage protection methods built on the cloud service platform all use additional hardware modules to encrypt storage devices and access control, and their construction costs are relatively high.
In view of the various shortcomings derived from the above-mentioned conventional methods, the inventor of this case is eager to improve and innovate, and after painstaking research, finally successfully developed the invention to solve the problem of cloud virtualization host data storage protection.
The purpose of the present invention is to provide an automatic encryption and decryption system for cloud files, which uses an information security module to verify the operation behavior of the system, and perform real-time encryption and decryption of host data access, so as to improve the information security of cloud platform virtualization host services The purpose of protection: By intercepting the system I\O, the data encryption process does not need to change the system operation process, so as to achieve the purpose of not affecting the user's operating habits. Using the method of building an information security module on the cloud service platform system can reduce the cost of building a cloud platform system. The purpose of this book.
A cloud file automatic encryption and decryption system that achieves the above-mentioned purpose of the invention is a data access encryption and decryption system applied to the cloud platform virtualization host service. An information security module is added to the system data processing flow, including the cloud virtual host management security module Group, key management and control module, cloud virtual host system I\O interception module, encryption and decryption module, and a key management server to protect the security of key storage. The information security module uses the method of intercepting system commands. When the virtual host performs operations that change system data such as opening, transferring, backing up, and closing, the information security module verifies the operation behavior of the system and reads it. Real-time data encryption and decryption during the process of writing storage devices or files.
Please refer to Figure 1, which is a schematic diagram of the implementation structure of an automatic encryption and decryption system for cloud files of the present invention. It includes a cloud service platform data security protection module 1, which is an information security module built on the cloud service platform system. The software-based system security module does not require additional hardware modules. The cloud service platform system can be a cloud service virtualization platform system such as Xen or KVM.
The cloud service platform data security protection module 1 includes a cloud virtual host management security module 11 embedded in the cloud virtual host management system. The interception point is set in the cloud virtual host management module to intercept cloud virtual host management commands, such as : Virtual host turn on, transfer, backup, turn off After intercepting the management command, it will call the cloud virtual host management security module 11 in the cloud service platform data security protection module 1 to direct the data processing process from the cloud virtual host management module to the cloud virtual host management security module. After the security module has completed the information verification process, the data processing flow is returned to the cloud virtual host management module to complete the normal data processing flow.
The cloud virtual host management security module 11 will request the key management control module 12 to compare the virtual host information with the key information to verify whether the management command of the virtual host comes from the operation of authorized personnel. After the information comparison is completed The key management and control module 12 will return the verification result to the cloud virtual host management security module 11. When the verification information result is correct, the cloud virtual host management security module 11 will release the intercepted cloud virtual host management command to enable The management process correctly performs operations such as opening, transferring, backing up, and closing the virtual host; if the result of the verification information is incorrect, the execution of the cloud virtual host management command will be blocked.
When the key management and control module 12 receives a verification request from the cloud virtual host management security module 11, it will first compare it with the key information that already exists in the key management and control module 12. If there is no corresponding key information, then Use the virtual host information to request key information from the key management server 13. After the key information is returned, the information will be compared. When the information is verified correctly, the key management module 12 will temporarily store the key information in the module. Group, in order to facilitate the next verification to use, so as to improve the efficiency of authorization verification, the temporary storage of key information will start from the virtual The opening of the virtual host ends with the closing of the virtual host.
The key management server 13 is responsible for receiving the key information request sent by the key management control module 12, and returns corresponding key information to the key management control module 12 according to the virtual host information parameters. The key management server 13 uses the standard key management protocol KMIP (Key Management Interoperability Protocol), and the communication protocol with the key management control module 12 uses the secure transmission protocol SSL (Secure Sockets Layer) to protect Security of key information.
The cloud virtual host system I\O interception module 14 is embedded in the cloud virtual host I\O module, and the interception point is set in the cloud virtual host I\O module to intercept the cloud virtual host I\O information to obtain the Read or write data from storage devices in the data processing flow. After intercepting the I\O information, it will call the cloud virtual host system I\O interception module 14 in the cloud service platform data security protection module 1, and direct the data processing flow from the cloud virtual host I\O module to the cloud virtual The host system I\O interception module, after the security module has completed the data encryption and decryption processing, the data processing flow is returned to the cloud virtual host I\O module to complete the normal data processing flow.
The I\O interception module 14 of the cloud virtual host system will send the acquired data to the data encryption and decryption module 15 to decrypt the read data and encrypt the written data. After the data encryption and decryption is completed and sent back, the cloud virtual The host system I\O interception module 14 will release the intercepted cloud virtual host I\O action, so that the data processing flow can continue correctly. Due to virtual hosting The data read from the storage device has been decrypted in the cloud virtual host system, so the virtual host can correctly identify the data content without data error or unrecognition; and the data written by the virtual host to the storage device is also virtualized in the cloud Encryption is performed in the host system, so the data stored in the device is encrypted.
The data encryption and decryption module 15 is responsible for encrypting and decrypting the read or write storage device data sent by the cloud virtual host system I\O interception module 14. The encryption and decryption algorithm of the data encryption and decryption module 15 uses the disk encryption algorithm It can support encryption algorithms such as CBC, LRW, XEX, XTS, CMC and EME or ESSIV, with a 128-bit or 256-bit key pair for data encryption and decryption. The encryption and decryption key pair is generated by the data encryption and decryption module 15 requesting information from the key management and control module 12 based on the storage device information, and the information includes derivative information of the virtual host key pair.
The cloud file automatic encryption and decryption system provided by the present invention has the following advantages when compared with other conventional technologies:
1. The system provided by the present invention is a data access protection method built on a cloud service platform. An information security module is added to the data processing flow. By intercepting system commands, it can verify that the virtual host is turned on, off, and system operations Whether the action with changing data comes from the operation of authorized personnel to improve the information security protection of the cloud platform virtualization host service.
2. The system provided by the present invention is a data access protection method built on a cloud service platform, and an information security module is added to the data processing flow. Use the method of intercepting system I\O to achieve the purpose of data encryption. And achieve the purpose of not changing the user's operating habits.
3. The system provided by the present invention is a software information security module, which can achieve the purpose of data encryption without additional hardware modules, and can reduce the construction cost of the cloud service platform system.
4. The data encryption and decryption module provided by the present invention uses disk encryption algorithms, which can support CBC, LRW, XEX, XTS, CMC and EME or ESSIV encryption algorithms, and can be used with 128 bits or 256 bits key pairs. Encryption and decryption of data.
5. The key management and control module provided by the present invention is matched with the key management server, adopts the standard key management protocol KMIP (Key Management Interoperability Protocol), and the key information transmission protocol uses the secure transmission protocol SSL (Secure Sockets Layer) to protect the security of key information.
6. The present invention can be used in all related cloud service platform systems.
The above detailed description is a specific description of a feasible embodiment of the present invention, but this embodiment is not intended to limit the scope of the patent of the present invention. Any equivalent implementation or modification that does not deviate from the technical spirit of the present invention shall be included in In the scope of the patent in this case.
To sum up, this case is not only innovative in terms of technical ideas, but also has the above-mentioned multiple functions that are not available in the conventional traditional system. It has fully met the requirements of novel and progressive statutory invention patents. An application is filed in accordance with the law. Your office approves this invention patent application to encourage invention and achieve virtue.
<p>1Cloud service platform data security protection module</p><p>11Cloud virtual host management security module</p><p>12Key Management and Control Module</p><p>13Key Management Server</p><p>14Cloud virtual host system I\O interception module</p><p>15Data encryption and decryption module</p>
Please refer to the detailed description of the present invention and its accompanying drawings to further understand the technical content of the present invention and its objectives and effects; the relevant drawings are: Figure 1 is a schematic diagram of the implementation structure of a cloud file automatic encryption and decryption system of the present invention;
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN102291391A | Cites | China | Examiner |
| CN102546181A | Cites | China | Examiner |
| US6081597A | Cites | United States of America | Examiner |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- I474189
- Application
- 101127550
Titles2
- Chinese
- 雲端檔案自動加解密系統
- English
- Cloud file automatic encryption and decryption system
Classification
- IPC, 2
- G06F15 167
- G06F21 62