Shared Management Information-Based Stateless Encryption / Decryption Gateway Operating System and Method Interworking with Hardware Security Module
Patent Information
- Application Number
- KR1020260090811
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2026-05-19
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2046-05-19
Smart Images

Figure R1020260090811_ABST
Abstract
Description
Technology Field
[0001] The present invention relates to a stateless encryption / decryption gateway operation system and method based on hardware security module interlocking shared management information. Background Technology
[0003] Recently, the importance of cryptographic operations such as data encryption, decryption, digital signatures, digital signature verification, and key management has been increasing in various application fields requiring security, including finance, public services, healthcare, artificial intelligence services, and blockchain services. While these cryptographic operations can be processed using software, the use of hardware security modules is widely employed to prevent the external leakage of critical keys and to ensure the reliability of cryptographic operations.
[0004] The hardware security module stores keys in a protected area and can process cryptographic operations without exposing the stored keys externally. Accordingly, external application systems can establish a highly secure cryptographic operation environment by utilizing the hardware security module.
[0005] However, conventional external application systems face the problem of having to directly implement device-specific calling methods, library calling methods, session management methods, key location management methods, and fault handling methods to interact with hardware security modules. For example, external application systems may need to directly handle hardware security module calling interfaces such as PKCS#11, directly verify slots or partitions where keys are stored, and directly process session creation, session reuse, session retrieval, and switching to another hardware security module node in the event of a failure.
[0006] Furthermore, when processing cryptographic operation requests using multiple gateway instances or multiple processing paths, if key-related information, access permission information, session-related information, or processing status information is stored individually within each processing path, information inconsistencies between processing paths may occur. In this case, the availability of a key, determination of access rights, the processing location of the hardware security module, or the status of connected resources may be determined differently depending on which processing path handles the cryptographic operation request.
[0007] In addition, when adding processing paths due to increased traffic or removing processing paths for failure or maintenance, operational complexity may increase because state information within existing processing paths must be transferred to new processing paths or sessions of processing paths to be removed must be cleaned up. In particular, when key-related change requests, such as key creation, key deletion, key repurposing, or access permission changes, are processed simultaneously by multiple processing paths, key state inconsistencies or duplicate changes may occur. Prior art literature
[0009] Republic of Korea Published Patent 10-2021-0009565 The problem to be solved
[0010] The objective of the present invention is to provide a stateless encryption / decryption gateway operating system and method based on hardware security module interoperability shared management information, which enables an external application system to process encryption operation requests without directly implementing the detailed calling method, connection resource management method, or equipment-specific encryption operation commands of the hardware security module.
[0011] Furthermore, the objective of the present invention is to provide a hardware security module-linked stateless encryption / decryption gateway operating system and method based on shared management information that can maintain consistency of keys, permissions, connection resources, and processing conditions among multiple processing paths by processing encryption / decryption requests using shared management information without storing state information required for processing encryption / decryption requests in a fixed manner within a specific processing path.
[0012] Furthermore, the objective of the present invention is to provide a hardware security module-linked shared management information-based stateless encryption / decryption gateway operating system and method that can reliably process cryptographic operation requests using shared management information even when the addition or removal of processing paths, failure of hardware security module nodes, or requests for changes related to keys occur. means of solving the problem
[0014] According to the stateless encryption / decryption gateway operating system based on shared management information linked to a hardware security module of the present invention, the encryption / decryption gateway operating system linked to a hardware security module comprises: a request receiving module that receives an encryption operation request from an external application system; a shared management information management module that manages shared management information commonly used for processing the encryption operation request; a processing condition determining module that determines a hardware security module processing condition corresponding to the encryption operation request using the shared management information; a hardware security module linkage module that converts the encryption operation request into a request that can be processed by the hardware security module according to the hardware security module processing condition, and transmits the converted request to the hardware security module to obtain an encryption operation result; and a result providing module that provides the encryption operation result to the external application system. The encryption / decryption gateway operating system processes the encryption operation request using the shared management information without fixedly storing state information required for processing the encryption operation request within a specific processing path.
[0015] Additionally, the hardware security module interlocking module comprises: a connection resource securing module that secures a connection resource available for communication with the hardware security module; a request forwarding module that transmits the request converted using the secured connection resource to the hardware security module; a result receiving module that receives the cryptographic operation result from the hardware security module; and a connection resource management module that manages the connection resource so that it can be reused or recovered after receiving the cryptographic operation result.
[0016] Additionally, the hardware security module includes a plurality of hardware security module nodes, and the hardware security module interlocking module includes: a target node determination module that determines a target node among the plurality of hardware security module nodes corresponding to the cryptographic operation request; a target node status check module that checks the operational status of the target node; and a delivery target change module that changes the delivery target of the cryptographic operation request to another hardware security module node when a failure is detected in the target node.
[0017] Additionally, the encryption / decryption gateway operating system further comprises: a processing path status checking module that checks the throughput of the encryption operation request or the operational status of the processing path; a processing path participation module that involves an additional processing path when additional processing resources are required; and a processing path removal module that removes the processing path to be removed after restricting the reception of new requests for the processing path to be removed, wherein the additional processing path processes the encryption operation request using the shared management information.
[0018] Additionally, the shared management information management module comprises: a lock information setting module that sets lock information associated with the shared management information when a change request related to a key is received; a conflict request restriction module that restricts the processing of other change requests that may conflict with the change request while the lock information is set; and a lock information release module that releases the lock information after the processing of the change request is completed.
[0019] In addition, the request receiving module verifies the authentication information received from the external application system, and the processing condition determining module determines whether the cryptographic operation request can be processed using the authentication information and the access authority information included in the shared management information.
[0020] In addition, the encryption / decryption gateway operating system further includes a management information providing module that provides one or more of the operating status of the hardware security module, the processing status of the encryption operation request, and the shared management information to an administrator terminal.
[0021] In addition, the shared management information management module manages version information to distinguish between the shared management information prior to the change and the shared management information after the change when the shared management information is changed, and the processing condition determination module determines the shared management information to be applied at the time of processing the cryptographic operation request using the version information.
[0022] Additionally, the processing condition determination module compares the key-related information included in the cryptographic operation request with the key identification information and hardware security module location information included in the shared management information, and if the comparison result shows that the key-related information and the hardware security module location information do not correspond to each other, it restricts the processing of the cryptographic operation request or re-checks the shared management information.
[0023] In addition, the connection resource management module verifies the validity of the connection resource by utilizing one or more of the usage status, error history, and last usage time of the connection resource, and after reclaiming the invalid connection resource, provides a replacement connection resource.
[0024] In addition, if a failure is detected in the target node, the above-mentioned forwarding target change module recovers the connection resources associated with the target node where the failure was detected, secures connection resources corresponding to another hardware security module node, and then changes the forwarding target of the cryptographic operation request.
[0025] In addition, the processing path removal module restricts the reception of new requests for the processing path to be removed, checks whether the cryptographic operation request being processed in the processing path to be removed has been completed and whether the connection resources have been recovered, and removes the processing path to be removed if the cryptographic operation request being processed has been completed and the connection resources have been recovered.
[0026] Additionally, the lock information setting module sets lock information including key identification information and the type of change request in response to a change request related to a key, and the conflict request restriction module restricts the processing of change requests that may conflict with the type of change request included in the lock information among other change requests that are identical or related to the key identification information.
[0027] In addition, the shared management information management module manages request identification information for distinguishing the cryptographic operation request and processing status information of the cryptographic operation request in conjunction with the shared management information, and the processing condition determination module restricts duplicate processing of the same cryptographic operation request using the request identification information and the processing status information.
[0029] The present invention is a method for operating an encryption / decryption gateway linked with a hardware security module, comprising: a request receiving step of receiving an encryption operation request from an external application system; a processing condition determining step of determining a hardware security module processing condition corresponding to the encryption operation request using shared management information commonly used for processing the encryption operation request; a request conversion step of converting the encryption operation request into a request that can be processed by the hardware security module according to the hardware security module processing condition; a calculation result acquisition step of transmitting the converted request to the hardware security module to obtain an encryption operation result; and a result providing step of providing the encryption operation result to the external application system; wherein the encryption / decryption gateway operation method processes the encryption operation request using the shared management information without fixedly storing state information required for processing the encryption operation request within a specific processing path. Effects of the invention
[0031] The hardware security module interlocking shared management information-based stateless encryption / decryption gateway operating system and method according to the present invention can reduce the development burden of external application systems and simplify the implementation of hardware security module interlocking by enabling external application systems to transmit encryption operation requests without directly implementing the library calling method, connection resource management method, or equipment-specific encryption operation commands of the hardware security module.
[0032] In addition, the hardware security module-linked stateless encryption / decryption gateway operation system and method according to the present invention can maintain consistent processing standards for encryption operation requests even in environments where processing paths are added or removed by processing using shared management information without storing state information required for processing encryption operation requests in a fixed manner within a specific processing path.
[0033] In addition, the hardware security module interlocking shared management information-based stateless encryption / decryption gateway operating system and method according to the present invention can improve the processing stability of encryption operation requests while restricting incorrect key usage, unauthorized encryption operation requests, or invalid connection resource usage by determining hardware security module processing conditions using shared management information and managing connection resources so that they can be reused or recovered.
[0034] In addition, the stateless encryption / decryption gateway operating system and method based on hardware security module interlocking shared management information according to the present invention can change the delivery target, reclaim connection resources, or process lock information even in situations involving failure of a hardware security module node, addition or removal of processing paths, or conflicts in key change requests, thereby improving the scalability, high availability, and operational stability of the encryption / decryption gateway operating system. Brief explanation of the drawing
[0036] FIG. 1 is a configuration diagram showing a stateless encryption / decryption gateway operation system based on hardware security module interlocking shared management information according to a preferred embodiment of the present invention. FIG. 2 is a configuration diagram showing a shared management information management module of a stateless encryption / decryption gateway operating system based on shared management information linked to a hardware security module according to a preferred embodiment of the present invention. FIG. 3 is a configuration diagram showing a hardware security module linkage module of a stateless encryption / decryption gateway operating system based on shared management information for hardware security module linkage according to a preferred embodiment of the present invention. FIG. 4 is a configuration diagram showing a stateless encryption / decryption gateway operation system based on hardware security module interlocking shared management information according to a preferred embodiment of the present invention. Specific details for implementing the invention
[0037] The advantages and features of the present invention and the methods for achieving them will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, the present invention is not limited to the embodiments disclosed below but may be implemented in various different forms. These embodiments are provided merely to ensure that the disclosure of the present invention is complete and to fully inform those skilled in the art of the scope of the invention, and the present invention is defined only by the scope of the claims. Throughout the specification, the same reference numerals refer to the same components.
[0038] Hereinafter, the present invention will be described with reference to drawings for explaining a stateless encryption / decryption gateway operation system based on hardware security module (2) interlocking shared management information according to embodiments of the present invention.
[0039] Referring to FIG. 1, the hardware security module (2) interlocked stateless encryption / decryption gateway operating system based on shared management information according to the present invention may include a request receiving module (10), a shared management information management module (20), a processing condition determination module (30), a hardware security module interlocking module (40), and a result providing module (50).
[0040] First, in the present invention, the hardware security module (2) may be a security device that stores a key in a protected area and processes cryptographic operations. For example, the hardware security module (2) may be a Hardware Security Module (HSM), or a device that provides a PKCS#11 (Public-Key Cryptography Standards #11) or a corresponding cryptographic device call interface, such as SafeNet Luna.
[0041] In addition, in the present invention, statelessness may refer to an operational state in which state information required for processing cryptographic operation requests is not fixedly stored within a specific gateway instance or a specific processing path, but is verified through shared management information that can be commonly verified by multiple processing paths. The state information may include key identification information, key usage information, access permission information, session-related information, processing condition information, event log information, or connection status information.
[0042] Specifically, the request receiving module (10) can receive a cryptographic operation request from an external application system (1).
[0043] The request receiving module (10) can verify authentication information received from an external application system (1).
[0044] The cryptographic operation request may be a request transmitted by an external application system (1) to a hardware security module (2) linked shared management information-based stateless encryption / decryption gateway operating system to use the key management function or cryptographic operation function of the hardware security module (2).
[0045] That is, after the request receiving module (10) receives a cryptographic operation request, it can transmit the cryptographic operation request or the request information included in the cryptographic operation request to an internal processing flow so that the processing condition determination module (30) can determine the processing condition of the hardware security module (2) using shared management information.
[0046] The external application system (1) may be a web server, application server, business system, financial system, public system, medical system, artificial intelligence service system, blockchain service system, or other system that intends to use the cryptographic operation function of the hardware security module (2).
[0047] Additionally, the request receiving module (10) can provide a point of contact in a standard external call format so that the external application system (1) does not have to directly implement the PKCS#11 library call of the hardware security module (2). For example, the request receiving module (10) can receive a call in the REST (Representational State Transfer) API (Application Programming Interface) format.
[0048] A cryptographic operation request may be one or more of a key generation request, a key deletion request, a key lookup request, a symmetric key encryption request, a symmetric key decryption request, an asymmetric key encryption request, an asymmetric key decryption request, a digital signature generation request, a digital signature verification request, and an encrypted data packaging request.
[0049] The key generation request may be a request to generate a new key inside the hardware security module (2) or in a security area managed by the hardware security module (2).
[0050] A key deletion request may be a request to delete a created or registered key or change it to an unusable state.
[0051] A key lookup request may be a request to check identification information, usage information, or status information of a key that can be used by an external application system (1).
[0052] A symmetric key encryption request may be a request to encrypt data using the same key, and a symmetric key decryption request may be a request to decrypt ciphertext using the same key.
[0053] An asymmetric key encryption request may be a request to encrypt data using a public key or corresponding key information, and an asymmetric key decryption request may be a request to decrypt data using a private key or corresponding security key information.
[0054] A request for electronic signature generation may be a request to generate an electronic signature value for data to be signed, and a request for electronic signature verification may be a request to verify whether there is a correspondence between the signature value and the data to be verified.
[0055] An encrypted data wrapping request may be a request to provide encrypted data and related metadata in a format available to an external application system (1). For example, an encrypted data wrapping request may be a JSON Web Encryption (JWE) wrapping request, and may be a request to provide encrypted data, key identification information, encryption processing method information, and necessary additional information in a format that can be transmitted or stored by an external application system (1) by wrapping them in a defined data structure.
[0056] The request receiving module (10) can verify the request body, request header, call path, request item, request identification information, external application system (1) identification information, key-related information, input data, password processing method information, or authentication information included in the cryptographic operation request. The request receiving module (10) can organize the verified information into internal request information that can be used by the processing condition determination module (30) or the processing flow described later, and transmit it.
[0057] For example, an external application system (1) may transmit a symmetric key encryption request containing key identification information and data to be encrypted to a stateless encryption / decryption gateway operating system based on shared management information linked to a hardware security module (2). The request receiving module (10) may verify the data to be encrypted in the request body and verify the key identification information and the external application system (1) identification information in the request header or the request body. The request receiving module (10) may organize the verified information into internal request information and transmit it to the processing condition determination module (30).
[0058] As another example, an external application system (1) may transmit a request for electronic signature generation including data to be signed and key-related information, and a request receiving module (10) may verify the data to be signed and key-related information and transmit it to a processing condition determination module (30). As yet another example, an external application system (1) may transmit a request for electronic signature verification including a signature value, data to be verified, and key-related information to be used for verification.
[0059] Authentication information may be information for verifying whether an external application system (1), user, or client that sent the cryptographic operation request has the authority to send the cryptographic operation request. The authentication information may be a token, API key, request signature, certificate, session identification information, or a combination thereof. If the authentication information is missing or not in the correct format, the request receiving module (10) may not forward the cryptographic operation request to subsequent processing and may provide an error response.
[0060] The request receiving module (10) may provide call format guidance information to an external application system (1) or an application developer. The call format guidance information may be information for the external application system (1) to determine which path, which request item, and which response format the cryptographic operation request should be sent. For example, the call format guidance information may be provided as an OpenAPI or Swagger specification.
[0061] The request receiving module (10) can receive cryptographic operation requests not only via REST-style calls but also via message-based calls, internal service calls, or other external calls. Additionally, the request receiving module (10) can receive cryptographic operation requests in JSON (JavaScript Object Notation), XML (eXtensible Markup Language), binary data, or other request formats.
[0062] According to the request receiving module (10) described above, the external application system (1) can transmit cryptographic operation requests without directly implementing the library calling method, connection resource management method, or equipment-specific calling command of the hardware security module (2). Accordingly, the development burden of the external application system (1) is reduced, and the impact of detailed implementation changes of the hardware security module (2) on the external application system (1) can be reduced.
[0064] The shared management information management module (20) can manage shared management information that is commonly used for processing cryptographic operation requests.
[0065] Referring to FIG. 2, this shared management information management module (20) may include a lock information setting module (21), a collision request limiting module (22), and a lock information release module (23).
[0066] The lock information setting module (21) can set lock information linked to shared management information when a change request related to the key is received.
[0067] The conflict request limiting module (22) can limit the processing of other change requests that may conflict with the change request while lock information is set.
[0068] The lock information release module (23) can release the lock information after the processing of the change request is completed.
[0069] At this time, the shared management information may not be state information fixedly stored within a specific processing path, but may be information managed so that multiple processing paths or multiple gateway instances can commonly check it. The shared management information may be used when the processing condition determination module (30) determines the processing conditions of the hardware security module (2), and may be used when the hardware security module linkage module (40) links with the hardware security module (2).
[0070] Additionally, shared management information may include shared metadata, shared session information, key metadata, access policy, session token, event log, audit log, client registration information, license information, hardware security module (2) registration information, or cluster management information.
[0071] Shared management information may include, for example, one or more of key identification information, key usage information, access permission information, session-related information, and event log information.
[0072] Key identification information may be information for distinguishing keys stored in the hardware security module (2).
[0073] Key usage information may be information indicating whether the key can be used for encryption, decryption, digital signature generation, digital signature verification, or encrypted data packaging.
[0074] Access rights information may be information indicating whether a specific external application system (1), user, or authority group can use a specific key or a specific cryptographic operation.
[0075] Session-related information may be information indicating a connection resource, session token, session state, or connection state used for communication with the hardware security module (2).
[0076] Event log information may be information representing the processing history, error history, authorization verification history, or management history of cryptographic operation requests.
[0077] Shared management information may be stored in a distributed storage or a high-availability storage. For example, shared management information may be stored in a PostgreSQL-based distributed database cluster or a high-availability database cluster. However, the storage method of shared management information is not limited to a specific database and may be implemented in other distributed storage, high-availability storage, key-value store, or database cluster that multiple processing paths can access in common.
[0078] Shared management information can be managed at the key unit, external application system (1) unit, user authority unit, hardware security module (2) node unit, partition unit, or processing path unit. For example, for a single key, key identification information, key usage information, access authority information, and location information can be managed together. As another example, for a single external application system (1), a list of available keys, types of allowed cryptographic operations, and authentication information can be managed together.
[0079] Lock information may be information configured in conjunction with shared management information to restrict the simultaneous processing of change requests for the same key or related keys across multiple processing paths. Change requests related to a key may be key creation requests, key deletion requests, key renewal requests, key usage change requests, key access permission change requests, or key revocation requests.
[0080] For example, if a request for deletion for a specific key is processed by one processing path while a request for update for the same key is received by another processing path, the lock information setting module (21) can set lock information associated with the key, and the conflict request limiting module (22) can limit the processing of the update request. When the processing of the deletion request is completed, the lock information release module (23) can release the lock information, and subsequent requests can be processed using the updated shared management information.
[0081] Lock information can be set by key unit, key group unit, partition unit, external application system (1) unit, or change request type unit. Lock information may expire after a certain period of time and may be released by administrator verification or an automatic recovery procedure in the event of an error. The shared management information management module (20) may store the time of setting the lock information, the time of releasing the lock information, the history of restrictions on potential change requests, or the processing results of change requests as event record information or audit logs.
[0082] According to the shared management information management module (20) above, since multiple processing paths can verify the same shared management information, the same key, authority, access resources, and processing criteria can be applied regardless of which processing path processes the cryptographic operation request.
[0083] Accordingly, the dependency of state information on a specific processing path can be reduced, and the addition or removal of processing paths can be facilitated. Additionally, using lock information can reduce key state inconsistencies or duplicate processing even when key change requests occur simultaneously across multiple processing paths.
[0085] The processing condition determination module (30) can determine the processing conditions of the hardware security module (2) corresponding to the cryptographic operation request using shared management information.
[0086] At this time, the processing condition determination module (30) can determine whether the cryptographic operation request can be processed using the access rights information included in the authentication information and shared management information.
[0087] The processing condition of the hardware security module (2) may be a condition that determines one or more of the key, authority, password processing method, processing location of the hardware security module (2), and connection resources required to process the password operation request. The input of the processing condition determination module (30) may be a password operation request and shared management information, and the output of the processing condition determination module (30) may be the processing condition of the hardware security module (2).
[0088] The processing condition determination module (30) can determine the key to be used for a cryptographic operation request by comparing key-related information included in the cryptographic operation request with key identification information stored in shared management information. Key metadata may include information regarding the key's creation time, key status, key usage, partition to which the key belongs, or the types of cryptographic operations allowed for the key. The processing condition determination module (30) can use the key usage information to determine whether the requested cryptographic operation is allowed for the corresponding key.
[0089] The processing condition determination module (30) can determine the cryptographic processing method to be applied to the cryptographic operation request. The cryptographic processing method may be information regarding a symmetric key algorithm, an asymmetric key algorithm, a hash algorithm, a digital signature algorithm, or an encrypted data packaging method. For example, when a symmetric key encryption request is received, the processing condition determination module (30) can determine an applicable symmetric key algorithm by checking the key usage information and request items stored in the shared management information.
[0090] The processing condition determination module (30) can determine the processing location of the hardware security module (2). The processing location may be information for identifying a slot, partition, node, cluster, or logical security area of the hardware security module (2). In a multi-partition environment, the processing location may be determined after verifying whether the partition to which the key belongs corresponds to the access rights of the external application system (1).
[0091] The processing condition determination module (30) can determine conditions related to connection resources. The connection resources may be a session, session token, session handle, connection object, or logical connection unit used for communication with the hardware security module (2). The processing condition determination module (30) can determine the connection resource conditions that the hardware security module integration module (40) can use by checking the session token, session status, or connection availability status included in the shared management information.
[0092] The processing condition determination module (30) can determine whether a cryptographic operation request can be processed using authentication information and access authority information. The authentication information may be, for example, a JSON Web Token (JWT), an API key, a request signature, a certificate, or a combination thereof. The access authority information may be information indicating whether an external application system (1), a user, an administrator, a password manager, or an authority group can use a specific key or a specific cryptographic operation.
[0093] The processing condition determination module (30) can determine whether a cryptographic operation request can be processed using Crypto Officer authority or role-based access control information. Crypto Officer authority may be authority related to key management or security policy management of the hardware security module (2). Role-based access control information may indicate the scope of authority by role, such as an administrator, password manager, auditor, external application system (1), or general user.
[0094] The processing condition determination module (30) can determine whether a cryptographic operation request can be processed using client registration information or license information. For example, it can check whether an external application system (1) is a registered client and check the key range, type of cryptographic operation, or call limit allowed to the registered client. In addition, it can determine whether a specific cryptographic operation function, a specific hardware security module (2) node, or a specific throughput range is available based on the license information.
[0095] The processing condition determination module (30) can determine the processing conditions of the hardware security module (2) to ensure key routing accuracy. For example, the processing condition determination module (30) can use key identification information and location information to determine the processing conditions so that a cryptographic operation request leads to the correct hardware security module (2), slot, partition, or node.
[0096] The processing condition determination module (30) may restrict the processing of a cryptographic operation request if it fails to determine the processing condition. For example, if the key identification information is not confirmed in the shared management information, the key usage information does not correspond to the requested cryptographic operation, the access permission information is insufficient, or the available connection resources are not confirmed, the processing condition determination module (30) may cause one or more of the following to occur: request rejection, error response, reconfirmation, or administrator notification.
[0097] According to the above processing condition determination module (30), a cryptographic operation request is not simply transmitted to the hardware security module (2), but can be processed after the key, authority, cryptographic processing method, processing location, and connection resource are verified using shared management information. Accordingly, unauthorized requests or the use of incorrect keys can be restricted, and consistent processing standards can be applied even in a multi-hardware security module (2) environment.
[0099] The hardware security module linkage module (40) can convert a cryptographic operation request into a request that can be processed by the hardware security module (2) according to the processing conditions of the hardware security module (2).
[0100] And, the hardware security module linkage module (40) can transmit the converted request to the hardware security module (2) to obtain the cryptographic operation result.
[0101] As shown in FIG. 3, the hardware security module linkage module (40) may include a connection resource securing module (41), a request transmission module (42), a result reception module (43), and a connection resource management module (44).
[0102] The connection resource securing module (41) can secure a connection resource that can be used for communication with the hardware security module (2).
[0103] The request transmission module (42) can transmit the converted request to the hardware security module (2) using the secured connection resources.
[0104] The result receiving module (43) can receive the cryptographic operation result from the hardware security module (2).
[0105] And, the connection resource management module (44) can manage the connection resources so that they can be reused or recovered after receiving the result of the cryptographic operation.
[0106] Additionally, when the hardware security module (2) includes a plurality of hardware security module (2) nodes, as shown in FIG. 3, the hardware security module linkage module (40) may include a target node determination module (45), a target node status check module (46), and a delivery target change module (47).
[0107] The target node determination module (45) can determine the target node corresponding to the cryptographic operation request among the multiple hardware security module (2) nodes.
[0108] The target node status check module (46) can check the operation status of the target node.
[0109] The forwarding target change module (47) can change the forwarding target of the cryptographic operation request to another hardware security module (2) node when a failure is detected at the target node.
[0110] The hardware security module integration module (40) can relay and convert cryptographic operation requests so that an external application system (1) does not have to directly implement the detailed calling method of the hardware security module (2). The hardware security module integration module (40) can call the PKCS#11 library or the libCryptoki2 library, for example, using the Go language and CGO bindings. The hardware security module (2) may be equipment such as SafeNet Luna, or other hardware security modules (2) that provide a PKCS#11 or equivalent cryptographic device calling interface.
[0111] The hardware security module linkage module (40) can check whether a key corresponding to a password operation request is accessible by using partition-based permission separation, password manager permission verification, or a key handle cache. The key handle cache may be temporary management information used to reduce the time required for key search or key identification procedures when repeatedly calling a key stored in the hardware security module (2).
[0112] For example, when a symmetric key encryption request is received, the hardware security module integration module (40) can convert it into an encryption request that the hardware security module (2) can process using key identification information, encryption algorithm information, input data, and connection resource information. As another example, when a digital signature generation request is received, the hardware security module integration module (40) can convert it into a digital signature request that the hardware security module (2) can process using signature target data, key identification information, and digital signature algorithm information.
[0113] The connection resource may be a session, a session handle, a connection object, or a logical connection unit required for calling a hardware security module (2). The connection resource acquisition module (41) may select an available session from a plurality of pre-prepared sessions, and if there are no available sessions, it may prepare a new session or wait until one of the sessions becomes available. The connection resource management module (44) may handle session pools, session caches, session reuse, session retrieval, session reconnection, handling of session shortages, retrieval of expired sessions, or creation of replacement sessions.
[0114] After the result of the cryptographic operation is received, the session in a normal state can be converted to a reusable state, and the session in an error state or an expired state can be reclaimed. The connection resource management module (44) can prepare a new session to replace the reclaimed session. This reduces the connection cost with the hardware security module (2) and reduces the processing delay for repeated cryptographic operation requests.
[0115] When multiple hardware security module (2) nodes are used, the target node can be determined using one or more of the key location information, slot status, partition status, node status, access authority information, or connection resource status. The target node status check module (46) can check the response status, connection status, whether a connection resource can be created, whether an error has occurred, or the load status of the target node.
[0116] The forwarding target change module (47) can change the forwarding target of a cryptographic operation request to another hardware security module (2) node if a failure is detected at the target node. For example, if a failure is detected at the active node, the forwarding target change module (47) can change the forwarding target to a standby node. In this case, the connection resource acquisition module (41) can reacquire the connection resource corresponding to the changed hardware security module (2) node.
[0117] The hardware security module integration module (40) can reduce the possibility of interruption of cryptographic operation requests in the event of a failure by using an HSM HA group, active / standby nodes, HA slot routing, health-check, and automatic failover. Failure response can be performed by periodic status checks, status checks before a request, status checks after an error occurs, or a combination thereof.
[0118] According to the above hardware security module linkage module (40), the external application system (1) does not need to directly implement the detailed calling method, connection resource management method, or failure response method of the hardware security module (2). Accordingly, the development cost of the external application system (1) is reduced, the cost of connecting with the hardware security module (2) is reduced, and the possibility of interruption of cryptographic operation requests in the event of a failure can be reduced.
[0120] The result providing module (50) can provide the cryptographic operation result to an external application system (1).
[0121] That is, the result providing module (50) can provide the cryptographic operation result obtained from the hardware security module linkage module (40) in a response format that can be verified by an external application system (1). The cryptographic operation result may be an encryption result, a decryption result, a key management result, a digital signature generation result, a digital signature verification result, an encrypted data packaging result, or an error result.
[0122] For example, the result of a cryptographic operation for an encryption request may include a ciphertext, information on the completion of encryption processing, the result of packaging the encrypted data, or request identification information.
[0123] The result of the cryptographic operation for the decryption request may include decrypted data, information on the completion of the decryption process, or information on the failure of decryption.
[0124] The result of a cryptographic operation for a request to generate an electronic signature may include a signature value, signature algorithm information, or signature processing completion information.
[0125] The result of a cryptographic operation for a digital signature verification request may include information on whether the verification was successful, the reason for the verification failure, or the verification result.
[0126] The result of a cryptographic operation for a key generation request may include identification information of the generated key, key generation completion information, or key generation failure information.
[0127] The result of the cryptographic operation for a key deletion request may include information on the completion of key deletion, information on the handling of key unusability, or information on the failure of key deletion.
[0128] The result of a cryptographic operation for a key lookup request may include key identification information, key usage information, key status information, or accessibility information.
[0129] The result of the cryptographic operation for the encrypted data packaging request may include encrypted data, key identification information, cryptographic processing method information, and packaging data available in an external application system (1).
[0130] The result providing module (50) can provide the cryptographic operation result in the form of a REST API response, but is not limited thereto, and may be JSON, XML, binary data, or other external call response formats.
[0131] In the event that an error occurs, the result providing module (50) may provide an error result regarding one or more of the following: request format error, authentication failure, lack of authority, key identification failure, key usage mismatch, lack of connection resources, hardware security module (2) response failure, target node failure, or cryptographic operation failure. The internal error code or equipment-specific response information returned by the hardware security module (2) may be converted into an error code, error message, or retry availability information that can be verified by an external application system (1).
[0132] The result providing module (50) can provide the cryptographic operation result and the request identification information by matching them with each other. The request identification information may be information for an external application system (1) to distinguish multiple cryptographic operation requests, and the result providing module (50) can include the request identification information in the response so that the external application system (1) can verify the correspondence relationship between the request and the result.
[0133] According to the result providing module (50) described above, the external application system (1) can receive the cryptographic operation results organized by the stateless encryption / decryption gateway operating system based on the hardware security module (2) integration shared management information, without directly interpreting the call results of the hardware security module (2). Accordingly, the integration implementation of the external application system (1) can be simplified, and the application developer does not have to directly handle the equipment-specific response format or error handling method of the hardware security module (2).
[0135] The hardware security module (2) interlocking shared management information-based stateless encryption / decryption gateway operating system according to the present invention may further include a processing path status check module (61), a processing path participation module (62), a processing path removal module (63), and a management information provision module (70), as shown in FIG. 4.
[0136] The processing path status check module (61) can check the throughput of the cryptographic operation request or the operating status of the processing path.
[0137] The processing path participation module (62) can participate in additional processing paths if additional processing resources are needed.
[0138] The processing path removal module (63) can remove the processing path to be removed after restricting the reception of new requests for the processing path to be removed.
[0139] At this time, the additional processing path can process cryptographic operation requests using shared management information.
[0140] A processing path may be a logical processing unit that receives or is passed a cryptographic operation request and processes the request using shared management information. For example, a processing path may be a logical processing unit selected by a gateway instance, container, process, server node, or external distribution device.
[0141] The processing path status check module (61) can check one or more of the throughput of cryptographic operation requests, processing waiting amount, response time, error rate, connection resource usage, load status of the processing path, or response capability of the processing path. The processing path status check module (61) can determine whether additional processing resources are required using the checked throughput or operating status.
[0142] For example, if the throughput of cryptographic operation requests exceeds a predetermined standard, the response delay of an existing processing path increases, or the usage of connection resources increases, it may be determined that additional processing resources are required. In this case, the processing path participation module (62) may include a new gateway instance, container, process, or server node as an additional processing path.
[0143] The additional processing path can process cryptographic operation requests using shared management information without copying state information from within the existing processing path. For example, the additional processing path can process cryptographic operation requests after checking key identification information, key usage information, access rights information, session-related information, or hardware security module (2) processing conditions managed by the shared management information management module (20). Such processing can be scale-out compatible.
[0144] The processing path removal module (63) can remove the processing path to be removed after restricting the reception of new requests for the processing path to be removed when the removal of the processing path is necessary. The processing path to be removed may be a processing path that has failed, a processing path that requires maintenance, a processing path that is no longer needed due to reduced throughput, or a processing path designated as a target for removal by an operator.
[0145] For example, if the processing path to be removed is linked with the hardware security module (2) using a session handle, the processing path removal module (63) may restrict the reception of new requests and allow the ongoing cryptographic operation request to be completed, and remove the processing path to be removed after the session handle in use is switched to a reusable state or retrieved. Such processing may correspond to Scale-in.
[0146] According to the above processing path status check module (61), processing path participation module (62), and processing path removal module (63), processing resources can be horizontally increased when traffic increases, and even in the event of a processing path failure or removal, other processing paths can continue to process cryptographic operation requests using shared management information. Accordingly, high availability and scalability of the stateless encryption / decryption gateway operating system based on shared management information linked to the hardware security module (2) can be secured even in a large-scale traffic environment.
[0148] The management information provision module (70) can provide one or more of the operating status of the hardware security module (2), the processing status of the cryptographic operation request, and shared management information to the administrator terminal.
[0149] The management information provision module (70) can enable an administrator or operator to check the operating status, security status, and cryptographic operation processing status of the stateless encryption / decryption gateway operating system based on shared management information linked with the hardware security module (2). The administrator terminal may be a web browser, an operator console, a management computer, a control system, or an external operating system.
[0150] The management information provision module (70) can provide one or more of the load, temperature, connection resource usage, session usage, node status, slot status, partition status, failure status, or response availability of the hardware security module (2) to the administrator terminal. In addition, it can provide the number of processing requests for cryptographic operations, the number of successful processing requests, the number of failed processing requests, the processing status by request type, the processing status by external application system (1), the processing delay status, the error occurrence history, or the failure response history.
[0151] The management information provision module (70) can provide one or more of the shared management information, such as key identification information, key usage information, access rights information, session-related information, event record information, key inventory, client registration information, license information, or hardware security module (2) registration information, to the administrator terminal.
[0152] The management information provision module (70) can be implemented in the form of an integrated management server or an integrated monitoring dashboard. The integrated monitoring dashboard may be a screen that visually provides hardware security module (2) equipment resources, API call statistics, key inventory, event logs, and failure status. For example, the integrated monitoring dashboard may be implemented as a React / Vite-based web UI.
[0153] The management information provision module (70) can provide different management information depending on the authority of the administrator account and the password manager account. For example, a general administrator can check the operating status of the hardware security module (2) and the processing status of password operation requests, and a password manager can additionally check information related to key generation, key deletion, key usage change, access authority change, or hardware security module (2) registration information change. The password manager account can correspond to the Crypto Officer account.
[0154] The management information provision module (70) can provide hardware security module (2) registration information, HA cluster configuration information, external application system (1) registration information, or license information to the administrator terminal. In addition, it can provide the operating status, failure information, or event log information of the hardware security module (2) to an external monitoring system through SNMP (Simple Network Management Protocol), Syslog, or other external operation linkage methods.
[0155] The management information provision module (70) can provide multilingual support or a responsive screen. For example, the management information provision module (70) can provide a Korean or English screen and can adjust the display format according to the screen size or connection environment of the administrator terminal.
[0156] The management information provision module (70) may provide a test input screen in which an application developer can test input the format of a cryptographic operation request. For example, the test input screen may be provided in the form of a REST API Playground. On the test input screen, the application developer can input a key generation request, an encryption request, a decryption request, a digital signature generation request, or a digital signature verification request, and check the response result for the request.
[0157] The test input screen may be provided in a test environment separated from the operating environment. Additionally, the test input screen may be configured to restrict the use of operating keys or to utilize test keys or test hardware security module (2) partitions. Accordingly, the application developer can verify the format of the cryptographic operation request and the response result without affecting the actual operating data or operating keys.
[0158] According to the above management information provision module (70), the status of the hardware security module (2) and the stateless encryption / decryption gateway operating system based on shared management information linked to the hardware security module (2) can be checked in a unified manner. Accordingly, the burden of operation management is reduced, and failures, privilege anomalies, connection resource overloads, or key management anomalies can be detected early. In addition, if a test input screen is provided, the application developer can check the input format, response format, and error response of the cryptographic operation request before writing code.
[0160] Meanwhile, another embodiment of the stateless encryption / decryption gateway operation system based on shared management information linked to the hardware security module (2) according to the present invention will be described in detail.
[0161] The stateless encryption / decryption gateway operating system based on shared management information linked to the hardware security module (2) of the present invention can manage version information to distinguish between the shared management information before and after a change. The version information may be information for distinguishing the time when the shared management information is updated, the updated item, the updating subject, or the update order. For example, when key usage information, access authority information, session-related information, or the location information of the hardware security module (2) changes, the shared management information management module (20) can generate or update version information that distinguishes between the shared management information before the change and the shared management information after the change.
[0163] Additionally, the processing condition determination module (30) can determine the shared management information to be applied at the time of processing the cryptographic operation request using version information. For example, if the time at which the cryptographic operation request is received and the time at which the shared management information is changed are close to each other, the processing condition determination module (30) can check the version information to determine whether to apply the shared management information before the change or the shared management information after the change to the cryptographic operation request. Accordingly, even in an environment where multiple processing paths use shared management information, the ambiguity regarding the application criteria for key, authority, session, or location information can be reduced.
[0165] The stateless encryption / decryption gateway operating system based on shared management information linked to the hardware security module (2) according to the present invention can compare key-related information included in the encryption operation request, key identification information included in the shared management information, and the location information of the hardware security module (2) with each other. The location information of the hardware security module (2) may be information indicating a slot, partition, node, cluster, or logical security area where the key is stored or used. The processing condition determination module (30) can determine the processing condition of the hardware security module (2) if the key-related information and the location information of the hardware security module (2) correspond to each other, and if they do not correspond to each other, it can restrict the processing of the encryption operation request or re-verify the shared management information.
[0166] For example, when an external application system (1) transmits an encryption request using a specific key, the processing condition determination module (30) can compare the key-related information included in the encryption request with the key identification information stored in the shared management information and verify the slot or partition information to which the key belongs. If, as a result of the comparison, the key identification information and the slot or partition information do not correspond to each other, the processing condition determination module (30) can restrict the transmission of the encryption operation request to an incorrect hardware security module (2) node. Accordingly, the accuracy of key routing can be improved.
[0168] The stateless encryption / decryption gateway operation system based on shared management information linked to the hardware security module (2) according to the present invention can verify the validity of the connection resources used for communication with the hardware security module (2). The connection resource management module (44) can verify whether the connection resources are valid by using one or more of the usage status of the connection resources, error history, or the last time of use. For example, a connection resource that has not been used for a certain period of time or longer, a connection resource that has repeatedly experienced errors, or a connection resource whose connection status with the hardware security module (2) cannot be verified may be determined to be an invalid connection resource.
[0169] The connection resource management module (44) can reclaim invalid connection resources and provide alternative connection resources. For example, if an expired session handle is identified, the connection resource management module (44) can reclaim the session handle and provide a new session for the same hardware security module (2) node or another corresponding hardware security module (2) node. Accordingly, the failure of cryptographic operation requests due to invalid connection resources can be reduced while maintaining the efficiency of reusing connection resources.
[0171] The stateless encryption / decryption gateway operation system based on shared management information linked to a hardware security module (2) according to the present invention can process the recovery of connection resources and the change of the delivery target in conjunction when a failure is confirmed in a target node among a plurality of hardware security module (2) nodes. When a failure is confirmed in a target node, the delivery target change module (47) can first recover the connection resources associated with the target node where the failure was confirmed. After that, the delivery target change module (47) can secure connection resources corresponding to another hardware security module (2) node and change the delivery target of the encryption operation request.
[0172] For example, if a response error or connection error is detected at the active node, the forwarding target change module (47) can reclaim the session associated with the active node and secure a session corresponding to the standby node. Subsequently, the cryptographic operation request can be forwarded to the standby node. According to this processing, the stability of the failure transition process can be improved because, rather than simply changing the forwarding target, connection resources remaining at the failed node are cleared and connection resources with another node are secured.
[0174] The stateless encryption / decryption gateway operating system based on shared management information linked to the hardware security module (2) according to the present invention can sequentially process the restriction on receiving new requests, confirmation of completion of requests in progress, and confirmation of recovery of connection resources when removing a processing path. The processing path removal module (63) can restrict the processing path to be removed from receiving new encryption operation requests. Subsequently, the processing path removal module (63) can check whether encryption operation requests already being processed in the processing path to be removed have been completed and whether connection resources used in the processing path have been recovered.
[0175] When a cryptographic operation request currently being processed is completed and the connection resource is reclaimed, the processing path removal module (63) can remove the processing path to be removed. For example, if a specific gateway instance needs to be removed due to traffic reduction or maintenance, the gateway instance can reclaim the session handle after it has finished providing the result of the ongoing cryptographic operation request while the reception of new requests is restricted. After that, the gateway instance can be removed. Accordingly, the possibility of interruption of cryptographic operation requests during the processing path removal process can be reduced.
[0177] The stateless encryption / decryption gateway operating system based on shared management information linked to the hardware security module (2) according to the present invention may set lock information including key identification information and the type of change request to reduce conflicts in change requests related to the key. When a key creation request, key deletion request, key renewal request, key usage change request, key access authority change request, or key revocation request is received, the lock information setting module (21) may include key identification information corresponding to the change request and the type of change request in the lock information.
[0178] The conflict request restriction module (22) can restrict the processing of other change requests that have key identification information identical to or related to the key identification information included in the lock information, if the types of the change requests may conflict with each other. For example, if a request to change the use of a key or a request to change access rights for the same key is received while a request to delete a specific key is being processed, the conflict request restriction module (22) can delay or restrict the processing of the request. Accordingly, inconsistencies in key status or duplicate changes can be reduced.
[0180] The stateless encryption / decryption gateway operating system based on shared management information linked to the hardware security module (2) according to the present invention may manage request identification information and processing status information in conjunction with shared management information to limit duplicate processing of encryption operation requests. The request identification information may be information for distinguishing encryption operation requests transmitted by an external application system (1), and the processing status information may be information indicating which state the encryption operation request is in among received, processing in progress, completed, failed, or retryable.
[0181] The processing condition determination module (30) can restrict duplicate processing of the same cryptographic operation request by using request identification information and processing status information. For example, if an external application system (1) retransmits the same encryption request due to a network error, the processing condition determination module (30) checks the request identification information and processing status information stored in the shared management information and, for requests that have already been completed, provides the existing processing result or restricts duplicate processing. As another example, if a request currently being processed is retransmitted, subsequent requests may be made to wait until the request is completed.
[0182] The management of request identification information and processing status information as described above can also be useful in situations involving failure switching or changes in processing paths. For example, if a failure occurs while one processing path is handling a cryptographic operation request and another processing path must take over processing the request, the other processing path can determine whether the request has already been processed or requires reprocessing by checking the request identification information and processing status information included in the shared management information. Accordingly, duplicate processing, omission processing, or unnecessary reprocessing of cryptographic operation requests can be reduced even in a stateless processing environment.
[0184] Meanwhile, the encryption / decryption gateway operation method according to the present invention may include a request reception step, a processing condition determination step, a request conversion step, a calculation result acquisition step, and a result provision step.
[0185] First, in the request reception stage, a request for cryptographic operation can be received from an external application system (1).
[0186] In the processing condition determination step, the processing conditions of the hardware security module (2) corresponding to the cryptographic operation request can be determined using shared management information that is commonly used for processing the cryptographic operation request.
[0187] In the request conversion step, a cryptographic operation request can be converted into a request that can be processed by the hardware security module (2) according to the processing conditions of the hardware security module (2).
[0188] In the operation result acquisition step, the converted request can be transmitted to the hardware security module (2) to obtain the cryptographic operation result.
[0189] In the result provision step, the result of the cryptographic operation can be provided to an external application system (1).
[0190] State information required for processing cryptographic operation requests is not fixedly stored within a specific processing path, but can be processed using shared management information.
[0191] Since the details regarding the functions, inputs, processing, and results of each step related to the present method are identical to or correspond to the description of the stateless encryption / decryption gateway operating system based on shared management information linked to the hardware security module (2) described above, the descriptions of the request receiving module (10), shared management information management module (20), processing condition determination module (30), hardware security module linkage module (40), and result providing module (50) described above may also be applied to the present method to the extent of overlap.
[0192] For example, when a symmetric key encryption request is received, the data to be encrypted and key-related information can be verified in the request reception stage. In the processing condition determination stage, key identification information, key usage information, access rights information, encryption algorithm information, and session information can be verified using shared management information. In the request conversion stage, the request can be converted into a call format to the hardware security module (2). In the operation result acquisition stage, the encryption result can be obtained from the hardware security module (2). In the result provision stage, the encryption result can be provided to an external application system (1).
[0193] As another example, when a request for electronic signature verification is received, the signature value, data to be verified, and key-related information may be verified in the request reception stage. In the processing condition determination stage, the key to be used for verification, access rights, and encryption processing method may be determined using shared management information. In the request conversion stage, the electronic signature verification request may be converted into a request that can be processed by the hardware security module (2). In the operation result acquisition stage, the verification result may be obtained, and in the result provision stage, information on whether the verification was successful or failed may be provided to an external application system (1).
[0194] This method can be processed in a single processing path or in one of multiple processing paths. Even when multiple processing paths are used, each processing path can process cryptographic operation requests using shared management information, without permanently storing the state information required for processing cryptographic operation requests within a specific processing path.
[0195] Accordingly, this method can maintain consistent processing standards for cryptographic operation requests even in environments where processing paths are added or removed, and can stably provide encryption and decryption processing using a hardware security module (2) even in large-scale traffic environments.
[0198] A person skilled in the art to which the present invention pertains will understand that the present invention may be implemented in other specific forms without altering its technical concept or essential features. Therefore, the embodiments described above should be understood as illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims set forth below rather than by the detailed description above, and all modifications or variations derived from the meaning and scope of the claims and their equivalents should be interpreted as being included within the scope of the present invention. Furthermore, the order of operation of the configurations described in the above process does not necessarily need to be performed in a chronological order, and it is understood that even if the order of execution of each configuration and step is changed, such a process may fall within the scope of the present invention as long as it satisfies the essence of the present invention. Explanation of the symbols
[0200] 1: External application system 2: Hardware security module 10: Request receiving module 20: Shared Management Information Management Module 21: Lock Information Setting Module 22: Collision Request Limiting Module 23: Lock Information Unlock Module 30: Processing condition determination module 40: Hardware Security Module Interfacing Module 41: Connection Resource Acquisition Module 42: Request forwarding module 43: Result receiving module 44: Connection Resource Management Module 45: Target Node Determination Module 46: Target Node Status Check Module 47: Change delivery target module 50: Result providing module 61: Processing path status check module 62: Processing path participation module 63: Processing path removal module 70: Management Information Provision Module
Claims
Claim 1 An encryption / decryption gateway operating system linked with a hardware security module comprises: a request receiving module that receives an encryption operation request from an external application system; a shared management information management module that manages shared management information commonly used for processing the encryption operation request; a processing condition determination module that determines a hardware security module processing condition corresponding to the encryption operation request using the shared management information; a hardware security module linkage module that converts the encryption operation request into a request that can be processed by the hardware security module according to the hardware security module processing condition, and transmits the converted request to the hardware security module to obtain an encryption operation result; and a result providing module that provides the encryption operation result to the external application system. The encryption / decryption gateway operating system processes the encryption operation request using the shared management information without fixedly storing state information required for processing the encryption operation request within a specific processing path. The encryption / decryption gateway operating system further comprises: a processing path status checking module that checks the throughput of the encryption operation request or the operational status of the processing path; and a processing path participation module that involves an additional processing path when additional processing resources are required. A decryption gateway operating system further comprising: a processing path removal module that removes the processing path to be removed after restricting the reception of new requests for the processing path to be removed, wherein the additional processing path processes the cryptographic operation request using the shared management information. Claim 2 In claim 1, the hardware security module interlocking module comprises: a connection resource securing module that secures a connection resource available for communication with the hardware security module; a request forwarding module that forwards the request converted using the secured connection resource to the hardware security module; a result receiving module that receives the cryptographic operation result from the hardware security module; and a connection resource management module that manages the connection resource so that it can be reused or recovered after receiving the cryptographic operation result; an encryption / decryption gateway operating system. Claim 3 In claim 1, the hardware security module comprises a plurality of hardware security module nodes, and the hardware security module interlocking module comprises: a target node determination module that determines a target node among the plurality of hardware security module nodes corresponding to the cryptographic operation request; a target node status check module that checks the operational status of the target node; and a delivery target change module that changes the delivery target of the cryptographic operation request to another hardware security module node when a failure is detected in the target node; an encryption / decryption gateway operating system. Claim 4 delete Claim 5 In claim 1, the shared management information management module comprises: a lock information setting module that sets lock information associated with the shared management information when a change request related to a key is received; a conflict request limiting module that limits the processing of other change requests that may conflict with the change request while the lock information is set; and a lock information release module that releases the lock information after the processing of the change request is completed; an encryption / decryption gateway operating system. Claim 6 In claim 1, the request receiving module verifies authentication information received from the external application system, and the processing condition determining module determines whether the encryption operation request can be processed using the authentication information and access rights information included in the shared management information. Claim 7 In claim 1, the encryption / decryption gateway operating system further comprises a management information providing module that provides one or more of the operating status of the hardware security module, the processing status of the encryption operation request, and the shared management information to an administrator terminal. Claim 8 A method for operating an encryption / decryption gateway linked with a hardware security module, comprising: a request receiving step of receiving an encryption operation request from an external application system; a processing condition determining step of determining a hardware security module processing condition corresponding to the encryption operation request using shared management information commonly used for processing the encryption operation request; a request conversion step of converting the encryption operation request into a request that can be processed by the hardware security module according to the hardware security module processing condition; a calculation result acquisition step of transmitting the converted request to the hardware security module to obtain an encryption operation result; and a result providing step of providing the encryption operation result to the external application system; wherein the state information required for processing the encryption operation request is not fixedly stored within a specific processing path, and the encryption operation request is processed using the shared management information, and the processing path status checking step of checking the throughput of the encryption operation request or the operating status of the processing path; a processing path participation step of participating in an additional processing path when additional processing resources are required; and a processing path removal step of removing the processing path to be removed after restricting the reception of new requests for the processing path to be removed, wherein the additional processing path processes the encryption operation request using the shared management information.
Citation Information
Patent Citations
Multi-cloud service system and method for efficient resource utilization
KR1020220071573A
Hybrid security system and method thereof
KR1020250098272A
Apparatus and method for multiplexing hardware security module
KR1020080054792A
Method, server and computer program for mediating between client server and Hardware Security Module
KR1020260022137A
Key export techniques
KR102311843B1