Unlock instant, AI-driven research and patent intelligence for your innovation.

Private key safe storage and distribution method and device

A secure storage and private key technology, applied in the field of secure storage and distribution of private keys, can solve the problems of increasing manufacturer costs, adding hardware security chips, increasing operation and maintenance costs, etc., to achieve the effect of protecting security and saving costs

Active Publication Date: 2018-08-17
GUIZHOU BAISHANCLOUD TECH CO LTD
View PDF4 Cites 1 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] For the above two methods, there are different degrees of disadvantages. Specifically: for the first method, when the keyless server is far away from the CDN edge node, the remote keyless solution will increase the delay of the SSL handshake, and for the user, Additional maintenance of the keyless server is required, which increases the user's operation and maintenance costs
For method 2, due to the huge number of edge node cache servers, adding hardware security chips will increase the manufacturer's cost
In addition, the huge number of edge node cache servers also tests the security management capabilities of CDN manufacturers. If the cache servers themselves have loopholes, there is a possibility of private key leakage even if a security chip is added.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Private key safe storage and distribution method and device
  • Private key safe storage and distribution method and device
  • Private key safe storage and distribution method and device

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0051] figure 1 It is a flowchart of a private key security processing method in an embodiment, and the method includes:

[0052] Step 101, the private key security storage center receives the target domain name and the private key corresponding to the target domain name, encrypts the private key, and stores the target domain name and the encrypted private key corresponding to the target domain name;

[0053] Step 102, the private key security storage center receives the private key acquisition request from the edge node, parses out the target domain name from the private key acquisition request, queries and extracts the encrypted private key corresponding to the target domain name, and decrypts the encrypted private key to obtain the private key , and send this private key to the aforementioned edge node.

[0054] Specifically, the private key secure storage center includes an API module, a processing module, a storage device, and an encryption and decryption device. Specif...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a private key safe storage and distribution method and device. The method comprises the steps that a private key safe storage center receives a target domain name and a privatekey corresponding to the target domain name, encrypts the private key and stores the target domain name and the encrypted private key corresponding to the target domain name; and the private key safestorage center receives a private key acquisition request from an edge node, analyzes the target domain name from the private key acquisition request, inquires and extracts the encrypted private keycorresponding to the target domain name, decrypts the encrypted private key to obtain the private key, and sends the private key to the edge node. According to the method, all private keys are encrypted and stored in the private key safe storage center uniformly, the private key plaintexts are not stored on a medium directly, so that the private key is protected effectively; and special hardware is not deployed on the edge node, so that the cost is saved.

Description

technical field [0001] The invention relates to the field of cloud computing processing, in particular to a method and device for securely storing and distributing private keys. Background technique [0002] One of the biggest challenges in using a security-oriented HTTP channel (Hyper Text Transfer Protocol over Secure Socket Layer, HTTPS) in a Content Delivery Network (CDN) scenario is the security of the private key. The edge nodes of the CDN undertake the task of handshaking Secure Sockets Layer (SSL) with the client. Therefore, the edge nodes of the CDN need to have the ability to use the private key. The most common way is to deploy the private key to the edge node. In this way, when there are a large number of CDN edge nodes, the number of copies of the private key will be very large. From a security point of view, this undoubtedly increases the risk of private key leakage. [0003] There are two methods to solve this problem in the prior art. In the first method, th...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L9/08H04L9/32H04L29/06H04L29/12
CPCH04L9/0819H04L9/0822H04L9/0894H04L9/3226H04L9/3263H04L63/06H04L63/0823H04L63/083H04L63/10H04L63/16H04L61/4511
Inventor 杨洋苗辉
Owner GUIZHOU BAISHANCLOUD TECH CO LTD