Secret key rotation method and system based on registration center, and medium
By setting up a key rotation mechanism in the registry center, the security service device periodically detects and generates new key configuration data, and the application service device updates the security module, thus solving the problem of the registry center lacking key rotation functionality and achieving low-cost protection of sensitive data.
Patent Information
- Application Number
- CN202511233145.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2025-11-14
AI Technical Summary
Existing registry centers such as Nacos and Consul do not provide encryption and key rotation functions, which cannot meet the requirement of regularly changing encryption keys in information security.
By setting key configuration rotation data and rotation conditions in the registration center, the security service device periodically detects and generates new key configuration data, and the application service device updates the security module to achieve key rotation.
Without adding extra management services, the system achieves secure protection of sensitive configuration data in the registry center, meeting the data protection requirements for information security.
Smart Images

Figure CN120956413A_ABST
Abstract
Description
Technical Field
[0001] This application relates to at least the field of information security technology, and in particular to a key rotation method, system and medium based on a registry center. Background Technology
[0002] In application architectures based on a service registry, the registry plays a role in service registration and discovery. Application configuration management involves sensitive data, making the encryption and protection of this sensitive data crucial. Furthermore, to ensure data security, information security requirements also mandate the regular replacement of encryption keys.
[0003] Commonly used application registries, such as Nacos (Dynamic Naming and Configuration Service, a cloud-native dynamic service discovery, configuration management, and service management platform) and Consul (a service networking solution that enables teams to manage secure network connections between services and across on-premises and multi-cloud environments and runtimes), do not provide corresponding encryption and key rotation features. Summary of the Invention
[0004] To address the aforementioned shortcomings, this application provides a key rotation method, system, and medium based on a registry center, in order to solve the following technical problem: how to implement key rotation based on a registry center.
[0005] Firstly, this application provides a key rotation method based on a registration center, the method comprising:
[0006] The registry center sets the key configuration rotation data of the registered application service instances to the rotation detection state. The key configuration rotation data includes key configuration data and key configuration data rotation conditions.
[0007] The security service device periodically obtains the key configuration rotation data that is currently in the rotation detection state from the registration center. If it detects that the obtained key configuration rotation data meets the key configuration data rotation conditions, it generates new key configuration data and sends it to the registration center.
[0008] The registry center sends new key configuration data to the application service device so that the application service device can update the application service instance based on the received new key configuration data.
[0009] Furthermore, the application service device updates the application service instance based on the received new key configuration data, specifically including:
[0010] The application service device creates a new security module for the application service instance based on the received new key configuration data, loads the new key configuration data into the new security module, associates the application service instance with the new security module, and then deletes the old security module of the application service instance that contained the old key configuration data.
[0011] Furthermore, the registry center sets the key configuration rotation data of registered application service instances to rotation detection status. The key configuration rotation data includes key configuration data and key configuration data rotation conditions, specifically including:
[0012] The registration center obtains the initialization key configuration data and key configuration data rotation conditions of the application service instance based on the application service's sensitive data information security protection requirements;
[0013] The registration center receives a startup request from the application service instance from the application service device, obtains the initialization key configuration data of the application service instance based on the startup request, and sends it to the application service device so that the application service device can start the application service instance according to the initialization key configuration data and create an initialization security module for the application service instance. The initialization security module is used to load the initialization key configuration data of the application service instance.
[0014] The registration center receives a registration request from an application service instance from an application service device. The registration request includes the Internet Protocol IP address and port information used by the application service instance after startup. The registration center records the IP address and port information of the application service instance in the registration request and sets the key configuration rotation data of the application service instance to the rotation detection state.
[0015] Furthermore, among which:
[0016] The key configuration data includes at least one of the following: database access key, data encryption transmission key, and application access security key. Each type of key configuration data has its own rotation conditions. One application service can correspond to the startup of multiple application service instances. The initialization of key configuration data is implemented manually, or a brand new key configuration data is obtained after the started application service instance is deregistered without being sent to the application service device.
[0017] Furthermore, the security service device periodically obtains key configuration rotation data currently in rotation detection status from the registration center. If the obtained key configuration rotation data meets the key configuration data rotation conditions, new key configuration data is generated and sent to the registration center, specifically including:
[0018] The security service device calls the first dedicated application programming interface (API) of the registration center according to a set cycle, and obtains the key configuration rotation data that is currently in the rotation detection state through the first dedicated API;
[0019] The security service device parses the key configuration rotation data, checks whether the key configuration data is valid, and if so, determines whether the key configuration data rotation condition has been met. If so, it generates new key configuration data.
[0020] The security service device sends the new key configuration data to the registry center via a second dedicated API.
[0021] Secondly, this application provides a key rotation system based on a registration center, the system comprising:
[0022] The registry center is used to set the key configuration rotation data of registered application service instances to the rotation detection state. The key configuration rotation data includes key configuration data and key configuration data rotation conditions.
[0023] The security service device connects to the registry center and periodically obtains the key configuration rotation data that is currently in the rotation detection state from the registry center. If the obtained key configuration rotation data is detected to meet the key configuration data rotation conditions, new key configuration data is generated and sent to the registry center.
[0024] The registry center is also used to send new key configuration data to application service devices, so that the application service devices can update application service instances based on the received new key configuration data.
[0025] Furthermore, the application service equipment specifically includes:
[0026] The key rolling update module includes an old security module and a new security module for the application service instance. It is used to create a new security module for the application service instance based on the received new key configuration data, load the new key configuration data into the new security module, associate the application service instance with the new security module, and then delete the old security module of the application service instance that contains the old key configuration data.
[0027] Furthermore, the registration center specifically includes:
[0028] The initialization unit is used to obtain the initialization key configuration data and key configuration data rotation conditions of the application service instance according to the sensitive data information security protection requirements of the application service. The key configuration data includes at least one of the database access key, data encryption transmission key, and application access security key. Each key configuration data has its own rotation conditions. One application service can correspond to multiple application service instances. The initialization key configuration data is implemented by manual processing, or obtained by obtaining a brand new key configuration data after the application service instance that has been started is deregistered without sending it to the application service device.
[0029] The startup unit, connected to the initialization unit, is used to receive a startup request from the application service instance of the application service device, obtain the initialization key configuration data of the application service instance according to the startup request, and send it to the application service device so that the application service device can start the application service instance according to the initialization key configuration data, and create an initialization security module for the application service instance. The initialization security module is used to load the initialization key configuration data of the application service instance.
[0030] The registration unit, connected to the startup unit, is used to receive registration requests from application service instances from application service devices. The registration request includes the Internet Protocol IP address and port information used by the application service instance after startup. The unit records the IP address and port information of the application service instance in the registration request and sets the key configuration rotation data of the application service instance to the rotation detection state.
[0031] Furthermore, security service equipment specifically includes:
[0032] The acquisition unit is used to call the first dedicated application programming interface (API) of the registration center according to a set period, and obtain the key configuration rotation data that is currently in the rotation detection state through the first dedicated API;
[0033] The parsing and detection rotation unit is connected to the acquisition unit. It is used to parse the key configuration rotation data, detect whether the key configuration data is valid, and if so, determine whether the key configuration data rotation condition has been met. If so, it generates new key configuration data.
[0034] The update sending unit, connected to the parsing and detection rotation unit, is used to send new key configuration data to the registry center via a second specialized API.
[0035] Thirdly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the key rotation method or key rotation system based on a registry center as described above.
[0036] This application provides a key rotation method, system, and medium based on a registry center, and explores a key rotation scheme based on a registry center. It achieves the security of sensitive configuration data in the registry center at a low cost without the need for additional management services, while also meeting the data protection requirements of information security. Attached Figure Description
[0037] Figure 1 This is a flowchart of a key rotation method based on a registry center, according to an embodiment of this application.
[0038] Figure 2This is a schematic diagram of a key rotation system based on a registration center, according to an embodiment of this application.
[0039] Figure 3 This is a schematic diagram of another key rotation method based on a registration center according to an embodiment of this application;
[0040] Figure 4 This is a flowchart of another key rotation method based on a registry center, according to an embodiment of this application;
[0041] Figure 5 This is a flowchart of a key parsing detection rotation update method according to an embodiment of this application. Detailed Implementation
[0042] To enable those skilled in the art to better understand the technical solution of this application, the embodiments of this application will be further described in detail below with reference to the accompanying drawings.
[0043] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining this application and are not intended to limit this application.
[0044] It is understood that, without conflict, the various embodiments and features in the embodiments of this application can be combined with each other.
[0045] It is understood that, for ease of description, only the parts relevant to this application are shown in the accompanying drawings, while parts unrelated to this application are not shown in the drawings.
[0046] It is understood that each module or unit involved in the embodiments of this application may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple modules or units may be integrated into one entity structure.
[0047] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this application may occur in a different order than that marked in the accompanying drawings.
[0048] It is understood that the flowcharts and block diagrams of this application illustrate the architecture, functions, and operations of possible implementations of systems, devices, and methods according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, unit, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagrams and flowcharts may be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.
[0049] It is understood that the modules and units involved in the embodiments of this application can be implemented by software or by hardware. For example, the modules and units can be located in the processor.
[0050] Example 1:
[0051] like Figure 1 As shown, this application provides a key rotation method based on a registry center, the method comprising:
[0052] S1. The registration center sets the key configuration rotation data of the registered application service instance to the rotation detection state. The key configuration rotation data includes key configuration data and key configuration data rotation conditions.
[0053] S2. The security service device periodically obtains the key configuration rotation data that is currently in the rotation detection state from the registration center. If it detects that the obtained key configuration rotation data meets the key configuration data rotation conditions, it generates new key configuration data and sends it to the registration center.
[0054] S3. The registration center sends new key configuration data to the application service device so that the application service device can update the application service instance based on the received new key configuration data.
[0055] In this embodiment, as Figure 1 The method shown is applicable to, for example, Figure 2 The system shown is described. The method and system explore a key rotation scheme based on a registry center, which achieves the security of sensitive configuration data in the registry center at a low cost without the need for additional management services, while also meeting the data protection requirements of information security.
[0056] More specifically, this embodiment provides a key rotation method based on a service registry. The service registry, acting as the "traffic hub" of the microservice ecosystem, provides dynamic coordination capabilities for distributed systems by uniformly managing service registration and discovery. Common service registries lack data protection functions, and key rotation is mostly limited to identity authentication; general key schemes require corresponding key management services. This embodiment is essentially a functional extension based on the service registry service, requiring no additional management services. The service registry manages application service configurations and provides registration and discovery functions. The service registry's management of application service configurations includes managing key rotation, rotating the key configuration data of application service instances registered in the service registry. By setting rotation conditions and rotation detection status in the service registry, the security service device interacts with the service registry to periodically detect key rotation conditions and update key configuration data that meets the conditions.
[0057] In one implementation, in step S3, the application service device updates the application service instance based on the received new key configuration data, specifically including:
[0058] The application service device creates a new security module for the application service instance based on the received new key configuration data, loads the new key configuration data into the new security module, associates the application service instance with the new security module, and then deletes the old security module of the application service instance that contained the old key configuration data.
[0059] In this embodiment, as Figure 2 and 3 As shown, the application service device provides application services by running application service instances, and the security service device provides key detection and rotation security services to the registry center at least. The application service provides associated management of key configuration data for each application service instance by running a security module. When key configuration data needs to be changed, the security module is updated on a rolling basis to replace the old and new key configuration data. In a microservice architecture, if an application service restarts, each instance of that application service needs to be restarted individually. This is a requirement to ensure business continuity. After restarting an application instance, a new instance needs to be registered with the registry center, thereby automatically updating the instance's IP (Internet Protocol) and port information to the registry center. In this embodiment, after receiving a key update request, the application service uses the new configuration to restart the security module on a rolling basis. Even if the key rotation is successful and the new valid key takes effect, there is no need to restart the application service instance.
[0060] In one implementation, S1, the registration center sets the key configuration rotation data of the registered application service instances to a rotation detection state. The key configuration rotation data includes key configuration data and key configuration data rotation conditions, specifically including:
[0061] The registration center obtains the initialization key configuration data and key configuration data rotation conditions of the application service instance based on the application service's sensitive data information security protection requirements;
[0062] The registration center receives a startup request from the application service instance from the application service device, obtains the initialization key configuration data of the application service instance based on the startup request, and sends it to the application service device so that the application service device can start the application service instance according to the initialization key configuration data and create an initialization security module for the application service instance. The initialization security module is used to load the initialization key configuration data of the application service instance.
[0063] The registration center receives a registration request from an application service instance from an application service device. The registration request includes the Internet Protocol IP address and port information used by the application service instance after startup. The registration center records the IP address and port information of the application service instance in the registration request and sets the key configuration rotation data of the application service instance to the rotation detection state.
[0064] In this embodiment, in a distributed system and microservice architecture, the registry center is one of the core components, functioning similarly to the system's "address book" or "command center," primarily addressing issues such as dynamic service management, high availability, and efficient collaboration. Figure 3 The diagram illustrates an application architecture based on a registry center. The registry center provides configuration management, service registration, and discovery capabilities for application services. During initialization (startup), an application service queries the registry center for the necessary configuration data, uses this data to initialize itself, and registers the corresponding service instance with the registry center—specifically, its IP address and port information—to facilitate access and invocation by other services. The basic interaction logic between the application service and the registry center is as follows: after successful startup, the application service registers its instance with the registry center for subsequent use. For example, when application service A needs to call application service B, it selects a service instance, such as B1, through the registry center, and B1 receives and processes the request. Subsequently, the security service interacts with the registry center, providing encryption and security for sensitive configuration data. When necessary, it can inspect and rotate the encrypted configuration data, triggering application service updates to use the new configuration. For instance, it might periodically read key-related configuration data, parse and inspect this data, and trigger key rotation if certain conditions are met.
[0065] In one embodiment, wherein:
[0066] The key configuration data includes at least one of the following: database access key, data encryption transmission key, and application access security key. Each type of key configuration data has its own rotation conditions. One application service can correspond to the startup of multiple application service instances. The initialization of key configuration data is implemented manually, or a brand new key configuration data is obtained after the started application service instance is deregistered without being sent to the application service device.
[0067] In this embodiment, in the application architecture based on the registry center, the registry center plays the role of configuration management, service registration, and discovery. Configuration management involves configuring sensitive data such as database access keys, data encryption keys, and application access keys; therefore, encrypting and protecting this sensitive data is crucial. To ensure data security, information security requirements mandate the periodic replacement of encryption keys. Keys are specifically associated with applications and related to their business logic. For example, if an application uses a database, it will configure a database access key; if it requires data encryption, it will involve a data encryption transmission key. A service instance refers to an instance that specifically provides software services for an application service; one application service can start multiple service instances simultaneously. A security service can be understood as a specific application service that satisfies key detection and rotation. Initializing key configuration data is only used for application instance initialization, and initializing the security module is only used during application initialization. At this time, the database access key is used to initialize the database connection, the data encryption key is used to initialize the encryption module, and the application access key is used for open interface calls.
[0068] In one embodiment, S2, the security service device periodically obtains key configuration rotation data currently in rotation detection state from the registration center. If the obtained key configuration rotation data is detected to meet the key configuration data rotation conditions, new key configuration data is generated and sent to the registration center, specifically including:
[0069] The security service device calls the first dedicated application programming interface (API) of the registration center according to a set cycle, and obtains the key configuration rotation data that is currently in the rotation detection state through the first dedicated API;
[0070] The security service device parses the key configuration rotation data, checks whether the key configuration data is valid, and if so, determines whether the key configuration data rotation condition has been met. If so, it generates new key configuration data.
[0071] The security service device sends the new key configuration data to the registry center via a second dedicated API.
[0072] In this embodiment, as Figure 4 As shown, the main key rotation process is divided into two sub-processes: sensitive configuration query and key rotation.
[0073] Sensitive Configuration Query: The security service triggers a process periodically according to the configuration and the agreed time. Detection and key rotation are passive operations, relying on scheduled tasks for periodic triggering. The period can be set according to the minimum update interval of the key configuration data of all application service instances in the registry center. Each update interval can be obtained from each rotation condition. The security service calls the registry center's key query interface. This dedicated interface is a built-in API (Application Programming Interface) of the registry center, and configuration can only be read or updated through this API. Upon receiving the call request, the registry center returns sensitive configurations that meet the conditions (key configuration rotation data currently in the rotation detection state), such as the agreed configuration parameter name dAesKey. The interface response configuration is parsed, and the value of the parameter dAesKey is read.
[0074] Key rotation: The security service parses the key and checks its validity and compliance with rotation conditions. If rotation is required, a new sensitive configuration is generated. Validity means the key can be parsed to reveal the complete data encryption key. Rotation conditions can be configured according to different scenarios; for example, rotation is required if the key's validity period is less than one month. The security service calls the registry center interface to update the newly generated sensitive configuration. Because the key has an expiration date, it cannot be used after the expiration date and must be rotated to a new key within its validity period. The registry center responds to the configuration update request and automatically executes the application update command. The application service receives the request and uses the new configuration to restart the application service's security module, indicating successful key rotation.
[0075] like Figure 5 The diagram illustrates the sub-processes of security service parsing, detecting, rotating, and updating keys. These sub-processes include: After obtaining the sensitive configuration data for detection, the security service first parses the configuration data to obtain the key data that can be detected, such as the agreed-upon key parameter dAesKey; it reads the time parameter data, checks the time validity, and determines whether key rotation is needed based on the agreed-upon time period configuration. The specific time parameter can be determined according to the business scenario; if the time parameter is valid but does not meet the rotation rules, no processing is performed, and the process ends; if the time parameter is valid and meets the rotation rules, key rotation is triggered, generating new sensitive configuration data; using the new sensitive configuration data, a sensitive configuration update is triggered, completing the key rotation.
[0076] This embodiment integrates multiple technologies such as data encryption and a registry center to protect the encryption keys for sensitive data. It also provides a mechanism for regularly updating sensitive configurations based on the registry center's open API. Without adding extra storage and key management services, it can achieve a low-cost security solution that meets information security requirements for sensitive data encryption configuration and key rotation, and enables regular updates of sensitive configurations to meet information security requirements.
[0077] Example 2:
[0078] like Figure 2 As shown, this application provides a key rotation system based on a registration center, the system comprising:
[0079] The registry center is used to set the key configuration rotation data of registered application service instances to the rotation detection state. The key configuration rotation data includes key configuration data and key configuration data rotation conditions.
[0080] The security service device connects to the registry center and periodically obtains the key configuration rotation data that is currently in the rotation detection state from the registry center. If the obtained key configuration rotation data is detected to meet the key configuration data rotation conditions, new key configuration data is generated and sent to the registry center.
[0081] The registry center is also used to send new key configuration data to application service devices, so that the application service devices can update application service instances based on the received new key configuration data.
[0082] In one embodiment, the application service device specifically includes:
[0083] The key rolling update module includes an old security module and a new security module for the application service instance. It is used to create a new security module for the application service instance based on the received new key configuration data, load the new key configuration data into the new security module, associate the application service instance with the new security module, and then delete the old security module of the application service instance that contains the old key configuration data.
[0084] In one embodiment, the registration center specifically includes:
[0085] The initialization unit is used to obtain the initialization key configuration data and key configuration data rotation conditions of the application service instance according to the sensitive data information security protection requirements of the application service.
[0086] The startup unit, connected to the initialization unit, is used to receive a startup request from the application service instance of the application service device, obtain the initialization key configuration data of the application service instance according to the startup request, and send it to the application service device so that the application service device can start the application service instance according to the initialization key configuration data, and create an initialization security module for the application service instance. The initialization security module is used to load the initialization key configuration data of the application service instance.
[0087] The registration unit, connected to the startup unit, is used to receive registration requests from application service instances from application service devices. The registration request includes the Internet Protocol IP address and port information used by the application service instance after startup. The unit records the IP address and port information of the application service instance in the registration request and sets the key configuration rotation data of the application service instance to the rotation detection state.
[0088] In one embodiment, wherein:
[0089] The key configuration data includes at least one of the following: database access key, data encryption transmission key, and application access security key. Each type of key configuration data has its own rotation conditions. One application service can correspond to the startup of multiple application service instances. The initialization of key configuration data is implemented manually, or a brand new key configuration data is obtained after the started application service instance is deregistered without being sent to the application service device.
[0090] In one embodiment, the security service device specifically includes:
[0091] The acquisition unit is used to call the first dedicated application programming interface (API) of the registration center according to a set period, and obtain the key configuration rotation data that is currently in the rotation detection state through the first dedicated API;
[0092] The parsing and detection rotation unit is connected to the acquisition unit. It is used to parse the key configuration rotation data, detect whether the key configuration data is valid, and if so, determine whether the key configuration data rotation condition has been met. If so, it generates new key configuration data.
[0093] The update sending unit, connected to the parsing and detection rotation unit, is used to send new key configuration data to the registry center via a second specialized API.
[0094] Example 3:
[0095] Embodiment 3 of this application provides a computer-readable storage medium storing a computer program. When the computer program is run by a processor, it implements the key rotation method based on the registry center as described in Embodiment 1, or the key rotation system based on the registry center as described in Embodiment 2.
[0096] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program units, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage systems, or any other medium that can be used to store desired information and is accessible to a computer.
[0097] Additionally, this application may provide a computer system including a memory and a processor. The memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the registry-based key rotation method as described in Embodiment 1. This computer system may be a registry-based key rotation system as described in Embodiment 2.
[0098] The memory is connected to the processor. The memory can be flash memory, read-only memory or other types of memory. The processor can be a central processing unit or a microcontroller.
[0099] Embodiments 1-3 of this application provide a key rotation method, system, and medium based on a registry center, exploring a key rotation scheme based on a registry center. This scheme achieves the security of sensitive configuration data in the registry center at a low cost without the need for additional management services, while also meeting the data protection requirements for information security.
[0100] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of this application, and this application is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and substance of this application, and these modifications and improvements are also considered to be within the scope of protection of this application.
Claims
1. A key rotation method based on a registry center, characterized in that, The method includes: The registry center sets the key configuration rotation data of the registered application service instances to the rotation detection state. The key configuration rotation data includes key configuration data and key configuration data rotation conditions. The security service device periodically obtains the key configuration rotation data that is currently in the rotation detection state from the registration center. If it detects that the obtained key configuration rotation data meets the key configuration data rotation conditions, it generates new key configuration data and sends it to the registration center. The registry center sends new key configuration data to the application service device so that the application service device can update the application service instance based on the received new key configuration data.
2. The method according to claim 1, characterized in that, The application service device updates the application service instance based on the received new key configuration data, specifically including: The application service device creates a new security module for the application service instance based on the received new key configuration data, loads the new key configuration data into the new security module, associates the application service instance with the new security module, and then deletes the old security module of the application service instance that contained the old key configuration data.
3. The method according to claim 2, characterized in that, The registry center sets the key configuration rotation data of registered application service instances to rotation detection status. The key configuration rotation data includes key configuration data and key configuration data rotation conditions, specifically including: The registration center obtains the initialization key configuration data and key configuration data rotation conditions of the application service instance based on the application service's sensitive data information security protection requirements; The registration center receives a startup request from the application service instance from the application service device, obtains the initialization key configuration data of the application service instance based on the startup request, and sends it to the application service device so that the application service device can start the application service instance according to the initialization key configuration data and create an initialization security module for the application service instance. The initialization security module is used to load the initialization key configuration data of the application service instance. The registration center receives a registration request from an application service instance from an application service device. The registration request includes the Internet Protocol IP address and port information used by the application service instance after startup. The registration center records the IP address and port information of the application service instance in the registration request and sets the key configuration rotation data of the application service instance to the rotation detection state.
4. The method according to claim 3, characterized in that, in: The key configuration data includes at least one of the following: database access key, data encryption transmission key, and application access security key. Each type of key configuration data has its own rotation conditions. One application service can correspond to the startup of multiple application service instances. The initialization of key configuration data is implemented manually, or a brand new key configuration data is obtained after the started application service instance is deregistered without being sent to the application service device.
5. The method according to any one of claims 1-4, characterized in that, The security service device periodically retrieves key configuration rotation data currently in rotation detection status from the registry center. If the retrieved key configuration rotation data meets the key configuration data rotation conditions, new key configuration data is generated and sent to the registry center, specifically including: The security service device calls the first dedicated application programming interface (API) of the registration center according to a set cycle, and obtains the key configuration rotation data that is currently in the rotation detection state through the first dedicated API; The security service device parses the key configuration rotation data, checks whether the key configuration data is valid, and if so, determines whether the key configuration data rotation condition has been met. If so, it generates new key configuration data. The security service device sends the new key configuration data to the registry center via a second dedicated API.
6. A key rotation system based on a registration center, characterized in that, The system includes: The registry center is used to set the key configuration rotation data of registered application service instances to the rotation detection state. The key configuration rotation data includes key configuration data and key configuration data rotation conditions. The security service device connects to the registry center and periodically obtains the key configuration rotation data that is currently in the rotation detection state from the registry center. If the obtained key configuration rotation data is detected to meet the key configuration data rotation conditions, new key configuration data is generated and sent to the registry center. The registry center is also used to send new key configuration data to application service devices, so that the application service devices can update application service instances based on the received new key configuration data.
7. The system according to claim 6, characterized in that, Application service equipment, specifically including: The key rolling update module includes an old security module and a new security module for the application service instance. It is used to create a new security module for the application service instance based on the received new key configuration data, load the new key configuration data into the new security module, associate the application service instance with the new security module, and then delete the old security module of the application service instance that contains the old key configuration data.
8. The system according to claim 7, characterized in that, The registration center specifically includes: The initialization unit is used to obtain the initialization key configuration data and key configuration data rotation conditions of the application service instance according to the sensitive data information security protection requirements of the application service. The key configuration data includes at least one of the database access key, data encryption transmission key, and application access security key. Each key configuration data has its own rotation conditions. One application service can correspond to multiple application service instances. The initialization key configuration data is implemented by manual processing, or obtained by obtaining a brand new key configuration data after the application service instance that has been started is deregistered without sending it to the application service device. The startup unit, connected to the initialization unit, is used to receive a startup request from the application service instance of the application service device, obtain the initialization key configuration data of the application service instance according to the startup request, and send it to the application service device so that the application service device can start the application service instance according to the initialization key configuration data, and create an initialization security module for the application service instance. The initialization security module is used to load the initialization key configuration data of the application service instance. The registration unit, connected to the startup unit, is used to receive registration requests from application service instances from application service devices. The registration request includes the Internet Protocol IP address and port information used by the application service instance after startup. The unit records the IP address and port information of the application service instance in the registration request and sets the key configuration rotation data of the application service instance to the rotation detection state.
9. The system according to any one of claims 6-8, characterized in that, Security service equipment, specifically including: The acquisition unit is used to call the first dedicated application programming interface (API) of the registration center according to a set period, and obtain the key configuration rotation data that is currently in the rotation detection state through the first dedicated API; The parsing and detection rotation unit is connected to the acquisition unit. It is used to parse the key configuration rotation data, detect whether the key configuration data is valid, and if so, determine whether the key configuration data rotation condition has been met. If so, it generates new key configuration data. The update sending unit, connected to the parsing and detection rotation unit, is used to send new key configuration data to the registry center via a second specialized API.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the key rotation method based on a registry center as described in any one of claims 1-5 or the key rotation system based on a registry center as described in any one of claims 6-9.