The invention relates to the technical field of
information security, in particular to a trusted cryptographic module
security management method and
system. The
authorization role comprises a
password manager used for generating a trusted
password module key and setting a working mode and administrator
authorization data, an administrator used for generating a storage main key and user setting
authorization data, and a user used for using
password service; when the trusted password module is logged in, physical authorization is carried out on a
password manager in a safe environment, and role identification is carried out on an administrator and a user by executing data
encryption and decryption through the trusted password module.
Authorization roles of the trusted password module are set as the
password manager, the administrator and the user, different role tasks are distinct, and physical identification under a safe environment is carried out on the
password manager, so that role setting and task distinct can be effectively ensured, illegal users are prevented from
logging in and accessing the trusted password module, and role and identification
security management in the trusted cryptographic module is ensured.