Method and system for dynamic application of storage encryption
An encryption setting application method may include acquiring a virtual machine image including a script that describes a hooking operation of a booting process and an encryption setting operation; hooking the booting process based on the hooking operation after booting of a virtual machine starts; applying an encryption setting to the virtual machine based on the encryption setting operation; and restarting the booting process of the virtual machine.
1 . An encryption setting application method in a cloud environment including a host computer apparatus and physical storage, the method executed by at least one processor of the host computer apparatus and comprising:
acquiring a virtual machine image including a script that describes a hooking operation of a booting process for booting a virtual machine and an encryption setting operation for the virtual machine;
generating the virtual machine based on the virtual machine image;
booting the generated virtual machine based on the booting process;
hooking the booting process based on the hooking operation after booting of the virtual machine starts;
verifying whether the encryption setting is applied to the generated virtual machine, and when the encryption setting is not applied to the generated virtual machine, applying the encryption setting to the generated virtual machine by performing the following steps:
copying, to a memory included in the host computer apparatus, an initial file system temporarily loaded to the physical storage corresponding to the virtual machine to back up an initial setting of the physical storage associated with the initial file system;
loading an actual file system of the virtual machine, after copying to the memory, the initial file system temporarily loaded to the physical storage;
initializing the physical storage, after loading the actual file system, and applying the encryption setting to the physical storage to encrypt data of the physical storage; and restoring the initial file system copied to the memory so that the initial setting of the physical storage is restored; and
restarting the hooked booting process for booting the generated virtual machine.
2 . The method of claim 1 , wherein the initializing of the physical storage and the applying of the encryption setting comprises:
generating a first key to be used to encrypt data of the physical storage;
generating a key file by encrypting the first key using a second key of an owner of the virtual machine; and
storing the generated key file on a local storage.
3 . The method of claim 2 , wherein the applying of the encryption setting to the virtual machine comprises:
in response to the encryption setting being already applied to the virtual machine, decrypting the key file using the second key of the owner of the virtual machine.
4 . The method of claim 1 , wherein the virtual machine image further comprises a code for a remote access function, and the method further comprises:
setting communication with a key management service that manages a key of an owner of the virtual machine based on the remote access function.
5 . The method of claim 4 , wherein the applying of the encryption setting to the virtual machine comprises acquiring the key of the owner from the key management service.
6 . The method of claim 4 , wherein the setting of the communication with the key management service comprises using an access control list (ACL) of a secure shell (SSH)-based public key registration scheme based on the remote access function.
7 . A non-transitory computer-readable recording medium storing instructions that, when executed by a processor of a host computer apparatus, cause the processor to perform the encryption setting application method comprising:
acquiring a virtual machine image including a script that describes a hooking operation of a booting process for booting a virtual machine and an encryption setting operation for the virtual machine;
generating the virtual machine based on the virtual machine image;
booting the generated virtual machine based on the booting process;
hooking the booting process based on the hooking operation after booting of the virtual machine starts;
verifying whether the encryption setting is applied to the generated virtual machine, and when the encryption setting is not applied to the generated virtual machine, applying the encryption setting to the generated virtual machine by performing the following steps:
copying, to a memory included in the host computer apparatus, an initial file system temporarily loaded to a physical storage corresponding to the virtual machine to back up an initial setting of the physical storage associated with the initial file system;
loading an actual file system of the virtual machine, after copying to the memory, the initial file system temporarily loaded to the physical storage;
initializing the physical storage, after loading the actual file system, and applying the encryption setting to the physical storage to encrypt data of the physical storage; and
restoring the initial file system copied to the memory so that the initial setting of the physical storage is restored; and
restarting the hooked booting process for booting the virtual machine.
8 . A host computer apparatus comprising: at least one processor configured to execute computer-readable instructions, wherein the at least one processor is configured to:
acquire a virtual machine image including a script that describes a hooking operation of a booting process for booting a virtual machine and an encryption setting operation for the virtual machine,
generate the virtual machine based on the virtual machine image;
boot the generated virtual machine based on the booting process;
hook the booting process based on the hooking operation after booting of the virtual machine starts,
verifying whether the encryption setting is applied to the generated virtual machine, and when the encryption setting is not applied to the generated virtual machine, applying the encryption setting to the generated virtual machine by performing the following steps:
copying, to a memory included in the host computer apparatus, an initial file system temporarily loaded to a physical storage corresponding to the virtual machine to back up an initial setting of the physical storage associated with the initial file system;
loading an actual file system of the virtual machine, after copying to the memory, the initial file system temporarily loaded to the physical storage;
initializing the physical storage, after loading the actual file system, and applying the encryption setting to the physical storage to encrypt data of the physical storage; and
restoring the initial file system copied to the memory so that the initial setting of the physical storage is restored, and
restart the hooked booting process for booting the virtual machine.
9 . The host computer apparatus of claim 8 , wherein the at least one processor is further configured to
generate a first key to be used to encrypt data of the physical storage,
generate a key file by encrypting the first key using a second key of an owner of the virtual machine, and
store the generated key file on a local storage.
10 . The host computer apparatus of claim 8 , wherein the virtual machine image further comprises a code for a remote access function, and the at least one processor is further configured to set communication with a key management service that manages a key of an owner of the virtual machine based on the remote access function.
11 . The host computer apparatus of claim 10 , wherein the at least one processor is further configured to acquire the key of the owner from the key management service.