Key management mechanism
A key management and key technology, applied in key distribution, can solve the problem of inability to solve the security of cryptographic device key management, the use of device keys cannot meet customer requirements, etc., to ensure safe use and ensure safe management. , Solve the effect of safe and reliable
Patent Information
- Authority / Receiving Office
- CN · China
- Current Assignee / Owner
- Publication Date
- 2011-03-16
- Estimated Expiration
- Not applicable · inactive patent
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention relates to the field of computer information security, in particular to a key management mechanism applied to information security equipment based on PKI technology to ensure safe and convenient key management in the equipment. Background technique
[0002] At present, in information security equipment based on PKI technology, the key management does not meet the requirements, the use of device keys cannot meet the requirements of not being open to application systems, and the keys are not generated and stored in a safe way; Keys other than the public key often appear outside the cryptographic device in plain text; the key stored inside the cryptographic device does not have an effective key protection mechanism, and there will be phenomena of dissection, detection, and illegal reading by outsiders; at the same time, the cryptographic device The internally stored key does not have a permission control mechanism, and illegal use and illega...
Examples
Embodiment 1
[0032] Key management mechanisms such as figure 1 , figure 2 and image 3 As shown, the steps are as follows:
[0033] Key management mechanism, the steps of the key management are as follows:
[0034] The first step: Initialize the cryptographic device in the initial state, that is, clear all keys in the key storage area of the cryptographic device, generate two 128-bit symmetric keys called component 1 and component 2, and convert component 1 to Stored in the key storage area of the cryptographic device, component 2 is temporarily stored in the memory;
[0035] The second step: regenerate the device signing key, that is, generate a pair of public and private keys as the signing key of the device and store it in the signing key storage area of the key, copy the device signing key to the device encryption key storage area, Put the cryptographic device in the ready state;
[0036] Step 3: Regenerate the administrator’s signature key, that is, generate a pair of publ...
Embodiment 2
[0048] According to the figure below, some characteristics and changing steps of the key are described in detail to ensure the safe management of the key. Through various initializations of the key, the initialization method and process are explained to ensure the safe use of the key, so as to solve the problem of cryptographic equipment in key management. And the problem of achieving safety and reliability in use.
[0049] 1. Key generation and storage:
[0050] 1. Device key: the signature key pair is generated by the cryptographic device during the original initialization, and the cryptographic device is in the ready state after the key is generated. In this state, you can export its public key to apply for a certificate from a certificate authority at any time. The device encryption key pair is generated by an external key management center, and its private key is protected by a device signature public key as a digital envelope, which can be downloaded to the encryption d...