Cryptographic processing device, and control method and device for cryptographic processing device
By introducing dynamic configuration area and static configuration area into the password processing device, dynamic configuration service processing files and combining password processing modules, the problem of single application scenarios caused by heterogeneous card solidification is solved, and efficient data encryption or decryption processing is achieved in multiple scenarios.
Patent Information
- Application Number
- CN202110089796.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-01-22
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2041-01-22
AI Technical Summary
The existing heterogeneous cards are solidified into a single service scenario during the generation process, resulting in a single application scenario of data encryption or decryption processing and inefficient application scenarios, which cannot adapt to the needs of different service scenarios.
Password processing equipment that adopts dynamic configuration area and static configuration area. The dynamic configuration area includes a service processing module, which can dynamically configure service processing files according to the service scenario, and encrypt or decrypt the processing combined with the password processing module, and supports multiple password algorithms.
The universality and efficient data encryption or decryption processing of password processing equipment in different service scenarios are realized, and the singularity and inefficiency problems caused by the coupling of encryption or decryption processing and service scenarios in the prior art are solved.
Smart Images

Figure CN113297588B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a cryptographic processing device, a control method and apparatus for the cryptographic processing device, an electronic device, and a computer storage medium. Background Art
[0002] Data encryption technology is an important means of ensuring data security. Using heterogeneous cards with encryption capabilities to encrypt service data for specific service processing scenarios is an effective approach. However, during the generation process, the internal functions of these cards are fixed based on the service scenario, making them applicable only to a single service scenario. Summary of the Invention
[0003] In order to solve the above technical problems or at least partially solve the above technical problems, embodiments of the present disclosure provide a cryptographic processing device, and a control method and apparatus for the cryptographic processing device.
[0004] In a first aspect, an embodiment of the present disclosure provides a password processing device, comprising a dynamic configuration area and a static configuration area, wherein the dynamic configuration area is provided with a service processing module, and the static configuration area is provided with a password processing module;
[0005] The service processing module can dynamically configure different service processing files, each of which corresponds to a service scenario. The service processing module is used to obtain service data to be cryptographically processed based on the service processing file and send the service data to be cryptographically processed to the cryptographic processing module.
[0006] The cryptographic processing module is used to perform cryptographic processing on the service data to be cryptographically processed based on a cryptographic algorithm, and feed back the cryptographically processed service data to the service processing module. The cryptographic processing includes encryption processing or decryption processing.
[0007] In a second aspect, an embodiment of the present disclosure further provides a method for controlling a cryptographic processing device, which is applied to an upper-level management device, comprising:
[0008] Generate a file loading request and send the file loading request to the service management server, wherein the file loading request includes an identifier of the preloaded service processing file;
[0009] The service processing file fed back by the service management server is received, and the service processing file is sent to the file management module of the password management device.
[0010] In a third aspect, an embodiment of the present disclosure further provides a method for controlling a cryptographic processing device, which is applied to a service management server, comprising:
[0011] receiving a file loading request sent by an upper-layer management device, wherein the file loading request includes an identifier of a preloaded service processing file;
[0012] The service processing file corresponding to the identifier is sent to the upper-level management device, so that the upper-level management device sends the service processing file to the file management module of the password management device.
[0013] In a fourth aspect, an embodiment of the present disclosure further provides a password processing method, which is applied to a password processing device, comprising:
[0014] Dynamically configuring different service processing files in the service processing module, and obtaining service data to be cryptographically processed based on the service processing files;
[0015] The service data to be cryptographically processed is cryptographically processed by a cryptographic processing module based on a cryptographic algorithm, and the cryptographically processed service data is fed back to the service processing module. The cryptographic processing includes encryption processing or decryption processing.
[0016] In a fifth aspect, an embodiment of the present disclosure further provides a control device for a cryptographic processing device, configured in an upper-level management device, comprising:
[0017] A file loading request generating module, configured to generate a file loading request and send the file loading request to the service management server, wherein the file loading request includes an identifier of a preloaded service processing file;
[0018] The service processing file receiving module is used to receive the service processing file fed back by the service management server and send the service processing file to the file management module of the password management device.
[0019] In a sixth aspect, an embodiment of the present disclosure further provides a control device for a cryptographic processing device, configured on a service management server, comprising:
[0020] A file loading request receiving module, configured to receive a file loading request sent by an upper-layer management device, wherein the file loading request includes an identifier of a preloaded service processing file;
[0021] The service processing file sending module is used to send the service processing file corresponding to the identifier to the upper management device, so that the upper management device can send the service processing file to the file management module of the password management device.
[0022] In a seventh aspect, an embodiment of the present disclosure further provides a password processing system, including:
[0023] The upper management device is used to generate a file loading request and send the file loading request to the service management server, wherein the file loading request includes an identifier of the preloaded service processing file;
[0024] The service management server is configured to receive a file loading request sent by the upper-layer management device, and send a service processing file corresponding to the identifier to the upper-layer management device;
[0025] The upper management device is further configured to receive the service processing file fed back by the service management server and send the service processing file to the file management module of the password management device;
[0026] The file management module of the password management device is configured to send the service processing file to the service processing module of the password management device;
[0027] The service processing module of the password management device is configured to obtain service data to be cryptographically processed based on the service processing file, and send the service data to be cryptographically processed to the password processing module of the password management device;
[0028] The password processing module of the password management device is used to perform password processing on the service data to be password processed based on a password algorithm, and feed back the password-processed service data to the service processing module. The password processing includes encryption processing or decryption processing.
[0029] In the eighth aspect, an embodiment of the present disclosure also provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the processor executes the control method provided by an embodiment of the present disclosure for any cryptographic processing device applied to an upper-level management device or to a service management server.
[0030] In the ninth aspect, an embodiment of the present disclosure also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the processor executes the control method provided by an embodiment of the present disclosure, which is applied to an upper-level management device or to any cryptographic processing device of a service management server.
[0031] The technical solution provided by the embodiments of the present disclosure has at least the following advantages compared with the existing technology: In the embodiments of the present disclosure, the service processing module in the cryptographic processing device has the function of dynamically configuring different service processing files. Based on this function, the cryptographic processing device can be applied to any service scenario with data encryption or decryption requirements, and realizes dynamic encryption processing or decryption processing for different service scenarios, thereby solving the problem that the data encryption or decryption processing is closely coupled with the specific service scenario in the existing solution (for example, the function of the encryption chip is solidified according to the service scenario), resulting in a relatively single application scenario for data encryption or decryption processing. At the same time, it also solves the problem that the encryption or decryption processing efficiency for different service scenarios is low due to the service scenario not supporting reconfiguration during the encryption or decryption processing process. It realizes the decoupling of data encryption or decryption processing from specific service scenarios, improves the versatility of data encryption or decryption processing for different service scenarios, and improves the efficiency of data encryption or decryption processing for different service scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale.
[0033] Figure 1 is a schematic structural diagram of a password processing device provided by an embodiment of the present disclosure;
[0034] Figure 2 is a structural diagram of another cryptographic processing device provided by an embodiment of the present disclosure;
[0035] Figure 3 This is a schematic diagram of an architecture for implementing interaction between an upper-layer management device and a cryptographic processing device provided by an embodiment of the present disclosure;
[0036] Figure 4 is a flowchart of a password processing method provided by an embodiment of the present disclosure;
[0037] Figure 5 is a flow chart of a method for controlling a cryptographic processing device provided by an embodiment of the present disclosure;
[0038] Figure 6 is a flow chart of another method for controlling a cryptographic processing device provided by an embodiment of the present disclosure;
[0039] Figure 7 It is a structural diagram of a control device of a cryptographic processing device provided by an embodiment of the present disclosure;
[0040] Figure 8is a structural diagram of a control device of another cryptographic processing device provided by an embodiment of the present disclosure;
[0041] Figure 9 is a schematic structural diagram of a password processing system provided by an embodiment of the present disclosure;
[0042] Figure 10 is a flowchart of a password processing method corresponding to a password processing system provided by an embodiment of the present disclosure;
[0043] Figure 11 A schematic structural diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0044] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0045] Figure 1 The figure is a schematic diagram of the structure of a cryptographic processing device provided in an embodiment of the present disclosure, which is used to exemplify the cryptographic processing device provided in an embodiment of the present disclosure. In an embodiment of the present disclosure, the cryptographic processing device can be implemented based on a field programmable gate array (FPGA). A field programmable gate array is a program-driven logic device, which lays the foundation for improving the versatility of the encryption or decryption scheme for service processing files in different service scenarios in the embodiment of the present disclosure. The cryptographic processing device of the embodiment of the present disclosure can be applied to various encryption and / or decryption algorithm scenarios, such as the national secret algorithm scenario. The specific application of the national secret algorithm can be set in the government and financial fields. In these two fields, government service data and financial service data may be generated. When there is a need for server encryption and / or decryption, trusted computing, encrypted storage, etc. for such service data, the cryptographic processing device provided by the embodiment of the present disclosure can be used to perform encryption and / or decryption processing. The specific processing method can be referred to the description in the following embodiment.
[0046] Optionally, the cryptographic processing device can be implemented in the form of a chip and deployed in a local server or a cloud server. This means that the technical solutions provided by the embodiments of the present disclosure are widely applicable to both data encryption and decryption processing on local servers and network data encryption and decryption processing on cloud servers. Specifically, the cryptographic processing device can be embedded in any server host via a pre-configured physical interface.
[0047] like Figure 1 As shown, the cryptographic processing device 100 includes a dynamic configuration area and a static configuration area. The functional modules or data included in the dynamic configuration area can be dynamically modified based on service processing requirements, while the functional modules or data included in the static configuration area cannot be modified. The dynamic configuration area is provided with a service processing module 101, and the static configuration area is provided with a cryptographic processing module 102.
[0048] The service processing module 101 can dynamically configure different service processing files. The service processing files correspond to service scenarios. The service processing module 101 is used to obtain service data to be cryptographically processed based on the service processing files and send the service data to be cryptographically processed to the cryptographic processing module 102. The service processing files in the service processing module 101 can be obtained by a user importing a file through a preset data interface of the cryptographic processing device 100; they can also be obtained from a local server or cloud server based on a file loading request triggered by a user; or they can be obtained from other interconnected devices through a network port deployed on the cryptographic processing device 100. Based on different service scenarios, the service processing files predefine the processing logic for obtaining the service data to be cryptographically processed. The specific content of the service processing files is not specifically limited in the present embodiment. Since they are set in the dynamic configuration area, they can be set or changed according to service processing requirements.
[0049] The cryptographic processing module 102 is responsible for performing cryptographic processing on the service data to be processed based on a cryptographic algorithm and feeding the processed service data back to the service processing module 101. Cryptographic processing includes encryption or decryption. The cryptographic algorithm can be any available encryption or decryption algorithm pre-configured in the cryptographic processing device 100 and is not specifically limited in this embodiment. Data transmission between the service processing module 101 and the cryptographic processing module 102 can be performed via a pre-set data path.
[0050] Optionally, the service scenario in the embodiment of the present disclosure includes at least one of a server application scenario, a trusted computing application scenario, or an encrypted storage application scenario.
[0051] In one exemplary embodiment, for a server application scenario, the interaction process between the service processing module 101 and the cryptographic processing module 102 may include: after the cryptographic processing device 100 receives specific scenario data from a data source, it uses the service processing file of the service processing module 101 based on the current service scenario (which predefines how to obtain the service data to be cryptographically processed from the received scenario data) to extract the service data to be encrypted or decrypted from the scenario data, and then sends it to the cryptographic processing module 102 for encryption or decryption; the cryptographic processing module 102 feeds back the encrypted or decrypted service data to the service processing module 101 again; the service processing module 101 re-encapsulates the encrypted or decrypted service data into scenario data, and sends the re-encapsulated scenario data to the data demander (the data demander and the source data provider may be the same or different) through the preset data interface of the cryptographic processing device 100.
[0052] In a second exemplary embodiment, for a trusted computing application scenario, the interaction process between the service processing module 101 and the cryptographic processing module 102 may include: after the cryptographic processing device 100 receives specific scenario data from a data source, the service processing module 101 extracts the encrypted source data (i.e., service data) based on the service processing file of the current service scenario (which predefines how to obtain encrypted source data from the received scenario data and how to perform trusted computing on the decrypted source data) and then sends it to the cryptographic processing module 102 for decryption processing; the cryptographic processing module 102 sends the decrypted source data to the service processing module 101, and the service processing module 101 performs trusted computing on the decrypted source data based on the service processing file of the current service scenario, and then sends the computing result to the cryptographic processing module 102 for encryption processing; the cryptographic processing module 102 sends the encrypted computing result to the service processing module 101; and the service processing module 101 sends the encrypted computing result to the data demander (the data demander and the source data provider may be the same or different) through the preset data interface of the cryptographic processing device 100.
[0053] Example 3: For an encrypted storage application scenario, the interaction process between the service processing module 101 and the password processing module 102 may include: in the data storage stage, after the password processing device 100 receives specific scenario data from the data source, it uses the service processing module 101 to extract the service data to be stored from the scenario data using the service processing file based on the current service scenario (which predefines how to obtain the service data to be cryptographically processed from the received scenario data) and then sends it to the password processing module 102 for encryption processing; the password processing module 102 feeds the encrypted service data back to the service processing module 101; the service processing module 101 sends the encrypted service data to the service processing module 101. The encrypted data is sent to the storage module so that the storage module stores the encrypted service data, wherein the storage module can be a functional module integrated in the cryptographic processing device 100, or a functional module in an electronic device independent of the cryptographic processing device 100; in the data reading stage, the service processing module 101 reads the required encrypted data from the aforementioned storage module based on the read request of the data demander, and sends it to the cryptographic processing module 102; the cryptographic processing module 102 decrypts the encrypted data and sends the decrypted data to the service processing module 101; the service processing module 101 sends the decrypted data to the data demander through the preset data interface of the cryptographic processing device 100.
[0054] Of course, the service scenarios to which the embodiments of the present disclosure are applicable are not limited to the descriptions in the above examples. Any service scenario that requires encryption or decryption processing can adopt the technical solutions provided by the embodiments of the present disclosure.
[0055] In the embodiment of the present disclosure, the service processing module 101 in the cryptographic processing device 100 is set in the dynamic configuration area and has the function of dynamically configuring different service processing files (or supporting the reconfiguration of service processing files). Based on this function, the cryptographic processing device 100 can be applied to any service scenario with data encryption or decryption requirements, and realize dynamic encryption processing or decryption processing for different service scenarios, thereby solving the problem that the data encryption or decryption processing is closely coupled with the specific service scenario in the existing solution (for example, the function of the encryption chip is solidified according to the service scenario), resulting in a relatively single application scenario for the data encryption or decryption processing. At the same time, it also solves the problem that the encryption or decryption processing efficiency for different service scenarios is low due to the service scenario not supporting reconfiguration. It realizes the decoupling of data encryption or decryption processing from the specific service scenario, improves the versatility of data encryption or decryption processing for different service scenarios, and improves the data encryption or decryption processing efficiency for different service scenarios.
[0056] In an optional implementation, the static configuration area of the cryptographic processing device 100 may further include other functional modules. Figure 2 is a structural diagram of another password processing device provided by an embodiment of the present disclosure, such as Figure 2 As shown, the dynamic configuration area of the cryptographic processing device 100 is provided with a service processing module 101, and the static configuration area is provided with a cryptographic processing module 102. Furthermore, the static configuration area is provided with a key storage module 103 for storing the cryptographic key of the cryptographic algorithm used by the cryptographic processing module 102. Different cryptographic algorithms correspond to different keys. When the cryptographic processing module 102 encrypts or decrypts service data, it can obtain the required key from the key storage module 103 according to the corresponding relationship between the encryption algorithm and the key. By storing the key separately, it can ensure the security of the key and help improve the efficiency of the encryption or decryption process.
[0057] Continue as Figure 2 As shown, in an optional embodiment, the static configuration area of the cryptographic processing device 100 is further provided with a file management module 104 for receiving a service processing file corresponding to a service scenario and configuring the service processing file to the service processing module 101. That is, the file management module 104 is used to implement the function of the service processing module 101 to perform file reconfiguration. The service processing file received by the file management module 104 can be a local file on the server where the cryptographic processing device 100 is installed. For example, the service processing file is sent to the file management module 104 by a user selecting or importing a file on the server. The service processing file received by the file management module 104 can also be a file transmitted to the server where the cryptographic processing device 100 is installed via the Internet. For example, the user triggers a file loading request on the server where the cryptographic processing device 100 is installed. The server obtains the service processing file from the Internet based on the service processing file identifier carried in the file loading request and sends it to the file management module 104.
[0058] In an optional embodiment, the static configuration area of the cryptographic processing device 100 further includes a user management module 106 for receiving first scenario data sent by the upper-level user management module and transmitting the first scenario data to the service processing module 101 in the dynamic configuration area. Data can be transmitted between the user management module 106 and the service processing module 101 based on a pre-set data path. A register path and an interrupt path can also be set between the two. The interrupt path can be used by the service processing module 101 to notify the user management module 106 that data has been received; the register path can be used to transmit configuration information related to the data path, which may include, for example, the timing and method of data transmission within the data path. The interrupt path and register path described above can control the data transmission process within the data path. Furthermore, the cryptographic processing module 102 and the service processing module 101 also share the register path between the service processing module 101 and the user management module 106.
[0059] The service processing module 101 is further configured to process the first scene data based on the service processing file to obtain service data to be cryptographically processed; and / or,
[0060] The service processing module 101 is further configured to process the service data after the password processing based on the service processing file, generate second scenario data, and send the second service scenario data to the user management module 106 in the static configuration area;
[0061] The user management module 106 is configured to feed back the second scenario data to the upper-layer user management module.
[0062] The user management module 106 and the upper-level user management module are functional modules that support each other. The upper-level user management module can be deployed in the cloud server where the password processing device 100 is installed and can be obtained by transparently transmitting the user management module 106. The upper-level user management module has an operation interface or user interface corresponding to the cloud server, allowing users to trigger visual operations on the first scene data, such as selecting scene data, triggering a request to load the scene data, and sending the obtained first scene data to the user management module 106. The user management module 106 and the upper-level user management module are equivalent to a data flow inlet and can be implemented using a physical function interface (PF) or a virtual function interface (VF).
[0063] Regarding the interaction between user management module 106 and upper-level user management modules, the service processing file defines not only how to obtain service data to be cryptographically processed from first-scenario data, but also the processing logic for processing the cryptographically processed service data to generate second-scenario data. The first-scenario data, second-scenario data, and the processing logic for generating the second-scenario data are all related to the specific service scenario and can be determined based on service processing requirements. The present disclosure does not impose any specific limitations on these.
[0064] Exemplarily, for a server application scenario, the first scenario data may be user information data for a large number of specific client users. The service processing file defines how to obtain the occupational information of a specified number of client users from the first scenario data, so that the service processing module 101 can obtain the occupational information of a specified number of client users from the first scenario data based on the service processing file as service data to be cryptographically processed, and then send it to the cryptographic processing module 102 for encryption processing; the service processing file also defines the processing logic of how to classify the encrypted occupational information according to the region where the client user is located, so that the service processing module 101 can classify the encrypted occupational information based on the service processing file, and obtain the occupational information classification result as the second scenario data, and then feed it back to the upper-level user management module through the user management module 106.
[0065] Furthermore, the user management module 106 is connected to the service processing module 101 via a PCIE interface. The PCIE interface is an end-to-end connection mode, where a functional module is connected at each end of a PCIE link, and the two functional modules are data sending and receiving ends for each other.
[0066] In an optional embodiment, as Figure 3 As shown, the cloud server host on which the cryptographic processing device 100 is installed is deployed with an upper-layer management device (i.e., upper-layer software), which can be implemented by deploying an upper-layer management driver, as shown in FIG. Figure 3As shown; the upper-layer management device 300 can specifically include an upper-layer user management module 306 and an upper-layer file management module 304. The upper-layer user management module 306 can be obtained by transparently transmitting the user management module 106. The upper-layer user management module 306 corresponds to an operation interface or user interface in the cloud server. It can be used to generate a file loading request based on the user operation on the operation interface or user interface, and send the file loading request to the cloud server. The file loading request includes the identifier of the preloaded service processing file so that the cloud server can obtain the corresponding service processing file; the upper-layer file management module 304 is used to receive the service processing file fed back by the cloud server and send the service processing file to the file management module 104 of the password management device; after receiving the service processing file, the file management module 104 configures it to the service processing module. The upper-layer file management module 304 and the file management module 104 are equivalent to a data flow inlet and can be implemented using a physical function interface (PF).
[0067] Continue as Figure 3 As shown, in the embodiment of the present disclosure, the user management module 106 and the file management module 104 in the cryptographic processing device are two isolated functional modules. Correspondingly, in the cloud server where the cryptographic processing device 100 is installed, the upper-level user management module 306 and the upper-level file management module 304 are also two isolated functional modules, that is, the implementation of user-executable operations and the operations implemented within the cloud server and the cryptographic processing device do not affect each other.
[0068] return Figure 2 Furthermore, the number of service processing files configured by the service processing module 101 can be at least one, for example, at least two. The multiple service processing files configured by the service processing module 101 can be for the same service scenario. For example, at least two service processing files are respectively used to obtain different types of service data in the same service scenario. The data types can be differentiated according to the data function or according to the data content. For example, the service data type can include user information data or service operation log data, etc., so that the cryptographic processing module 102 can encrypt or decrypt different types of service data respectively. The multiple service processing files configured by the service processing module 101 can also be respectively for different service scenarios, and each service processing file is used to obtain service data in this service scenario, so that the cryptographic processing module 102 can encrypt or decrypt service data in different service scenarios respectively. That is, in the embodiment of the present disclosure, the cryptographic processing device 100 supports the simultaneous execution of data encryption or decryption tasks for multiple service processing files, which helps to improve the processing efficiency of data encryption or decryption.
[0069] Furthermore, if the service processing module 101 is configured with at least two service processing files, the service processing module 101 may also determine the service processing file currently used to obtain the service data to be cryptographically processed based on a user selection operation or a file loading request triggered by the user. For example, the local server where the cryptographic processing device 100 is installed provides the user with an operation interface or user interface corresponding to the functions of the cryptographic processing device 100, allowing the user to select the desired service processing file.
[0070] Continue as Figure 2 As shown, in an optional embodiment, the static configuration area of the cryptographic processing device 100 is further provided with: an authentication module 105 for sending the firmware of the static configuration area to an external authentication chip (or cryptographic chip) 107 for authentication.
[0071] The firmware in the static configuration area includes the underlying program code within the cryptographic processing device 100, ensuring the functionality of the cryptographic processing device 100. The external authentication chip 107 provides data authentication, verifying the credibility of received data. The external authentication chip 107 and the cryptographic processing device 100 can be installed in the same server host, enabling data communication between them. The external authentication chip 107 can be implemented using any existing, authoritative and trustworthy authentication chip, and is not specifically limited in this disclosed embodiment.
[0072] For example, the external authentication chip 107 can be used to verify whether the firmware in the static configuration area contains untrusted programs, etc. Furthermore, when the authentication module 105 sends the firmware in the static configuration area to the external authentication chip 107 for authentication, it is also configured to calculate the firmware using a preset cryptographic algorithm (e.g., a hash algorithm) to obtain a first result file (or bit file), and then send this first result file and the firmware together to the external authentication chip 107 for authentication. For example, after obtaining the first result file and the firmware, the external authentication chip 107 can calculate the firmware using the same preset cryptographic algorithm to obtain a second result file. If the second result file is identical to the first result file, the received firmware is authentic, and the presence of untrusted programs, etc. in the firmware can be verified. If not, the cryptographic processing device 100 is confirmed to be authentic; otherwise, the cryptographic processing device 100 is confirmed to be untrusted. If the second result file is different from the first result file, the cryptographic processing device 100 can be directly confirmed to be untrusted.
[0073] By authenticating the firmware in the static configuration area of the cryptographic processing device 100 through the external authentication chip 107, the identity of the cryptographic processing device 100 can be authenticated, the credibility of the cryptographic processing device 100 can be confirmed, and the encryption or decryption function of the cryptographic processing device 100 can be effectively supervised.
[0074] Furthermore, the authentication module 105 of the cryptographic processing device 100 is further configured to send the service processing file to the external authentication chip 107 for authentication;
[0075] The file management module 104 is used to configure the service processing file to the service processing module 101 after the service processing file authentication is passed.
[0076] Specifically, the service processing file received by the cryptographic processing device 100 can first be distributed to the external authentication chip 107. After the external authentication chip 107 passes authentication, the service processing file is then configured to the service processing module 101 through the file management module 104. For example, the external authentication chip 107 can parse the service processing file to determine whether there is illegal or untrusted data in the service processing file. If so, authentication fails; otherwise, authentication succeeds. In addition to setting up a data loading path, a register path can also be set up between the file management module 104 and the service processing module 101. The register path can be used by the file management module 104 to obtain firmware status information or network port status information related to the service processing module 101, thereby enabling the file management module 104 to perform data maintenance or supervision.
[0077] By authenticating the service processing file through the external authentication chip 107, the security of the service processing file can be ensured, thereby ensuring the validity of the service data obtained based on the service processing file and the validity of the data encryption or decryption processing results.
[0078] In an optional embodiment, the dynamic configuration area of the cryptographic processing device 100 is provided with a network port 108 ; the network port 108 may include but is not limited to any interface with network data transmission function, such as an optical port.
[0079] The service processing module 101 is configured to receive first scene data sent by a service scene device (i.e., equivalent to a source data provider) through the network port 108, and process the first scene data based on the service processing file to obtain service data to be cryptographically processed; and / or,
[0080] The service processing module 101 is used to process the service data after the password processing based on the service processing file, generate second scene data, and send the second service scene data to the service scene device through the network port 108.
[0081] The service processing file not only defines how to obtain the service data to be cryptographically processed from the first scenario data, but also defines the processing logic of how to process the cryptographically processed service data to generate the second scenario data.
[0082] Exemplarily, for enterprise users, the service processing module 101 can receive the first scene data sent by the service scene device controlled by the enterprise user through the network port 108, and process the first scene data based on the service processing file to obtain the service data to be cryptographically processed, and then send the generated second service scene data to the service scene device through the network port 108, thereby improving the data encryption or decryption processing efficiency for enterprise users and improving the convenience of enterprise users in encrypting or decrypting service data.
[0083] Continue as Figure 2 As shown, in an optional embodiment, the dynamic configuration area of the cryptographic processing device 100 is further provided with a memory 109 for storing (including caching) service processing files or scenario data corresponding to the service scenario. The memory 109 can include any available module with storage function, such as a double data rate (DDR) synchronous dynamic random access memory, an erasable programmable read-only memory, or a random access memory.
[0084] For example, for scenarios where the service processing files or scenario data are local files or local data where the cryptographic processing device 100 is installed, such as trusted computing application scenarios or encrypted storage application scenarios, the cryptographic processing device 100 can store the service processing files or scenario data in the memory 109, and then the service processing module 101 can directly obtain the service processing files or scenario data from the memory 109, which helps to improve data acquisition efficiency.
[0085] It should be noted that Figure 1 or Figure 2 The functional modules shown in the figure are understood as specific limitations on the implementation of the password processing device. The password processing device may also include Figure 1 or Figure 2 Other functional modules not shown in the figure can be implemented by software and / or hardware. Exemplarily, the cryptographic processing device can also include a processor (such as a central processing unit, a graphics processing unit, etc.). A computer program (or computer-readable instructions) is stored in the memory. When the computer program is executed by the processor, the cryptographic processing device can implement various appropriate actions and processes, such as implementing the cryptographic processing method provided in the embodiment of the present disclosure. The method may include: using the service processing module to dynamically configure different service processing files, and obtaining service data to be cryptographically processed based on the service processing files; using the cryptographic processing module to perform cryptographic processing on the service data to be cryptographically processed based on the cryptographic algorithm, and feeding back the cryptographically processed service data to the service processing module. The cryptographic processing includes encryption processing or decryption processing.
[0086] The cryptographic processing device may also include an input / output (I / O) interface connected to the processor and memory via a bus. Furthermore, the cryptographic processing device may include a communication module that allows the cryptographic processing device to communicate with other devices wirelessly or wired to exchange data. For example, a computer program stored in the memory of the cryptographic processing device can be downloaded and installed from a network via the communication module. The program code contained in the memory can be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination of the foregoing.
[0087] In the above embodiments of the present disclosure, an example of setting a dynamic configuration area and a static configuration area is used for illustration, but in the specific implementation process, multiple static configuration areas may be included, and different static configuration areas may be configured with different versions of encryption algorithms and / or decryption algorithms, or different categories, to meet the needs of different users, so that users have more choices and can choose to use one or several static configuration areas to meet the specific needs of their own service scenarios. In the specific implementation process, users can configure the cryptographic processing device and enable one or several static configuration areas.
[0088] In addition, in the embodiment of the present disclosure, a plurality of functional modules can be set in the static configuration area, which can be specifically obtained through virtualization processing to obtain multiple functional modules with different functions, such as a password processing module, a key storage module, a user management module, a file management module, an authentication module, etc. According to actual needs, more functional modules can also be virtualized.
[0089] Figure 4 This is a flowchart of a password processing method provided by an embodiment of the present disclosure, which is applied to a password processing device and is used to exemplarily illustrate the functional implementation of the aforementioned password processing device.
[0090] like Figure 4 As shown, the password processing method provided by the embodiment of the present disclosure may include:
[0091] S101. Dynamically load different service processing files in a service processing module, and obtain service data to be cryptographically processed based on the service processing files.
[0092] S102: Perform cryptographic processing on the service data to be cryptographically processed based on a cryptographic algorithm using a cryptographic processing module, and feed the cryptographically processed service data back to the service processing module. The cryptographic processing includes encryption processing or decryption processing.
[0093] Of course, according to the various achievable functional modules of the aforementioned cryptographic processing device, the cryptographic processing method applied to the cryptographic processing device may also include other optional implementations corresponding to the various functional modules, and reference may be made to the above content for details.
[0094] In the embodiment of the present disclosure, by utilizing the service processing module in the cryptographic processing device, the service processing files corresponding to different service scenarios are dynamically configured, so that the cryptographic processing device can be applicable to any service scenario with data encryption or decryption requirements, and dynamic encryption processing or decryption processing for different service scenarios is realized, thereby realizing the decoupling of data encryption or decryption processing from specific service scenarios, improving the versatility of data encryption or decryption processing for different service scenarios, and improving the efficiency of data encryption or decryption processing for different service scenarios.
[0095] The password processing method in the embodiment of the present disclosure can also refer to the above-mentioned examples 1 and Figure 2 The illustrated embodiment includes more processes and steps to implement corresponding functions.
[0096] Figure 5 This is a flowchart of a control method for a cryptographic processing device provided by an embodiment of the present disclosure, which is used to exemplarily illustrate how to implement file or data loading in the dynamic configuration area of the cryptographic processing device. Figure 5 The control method of the cryptographic processing device shown can be executed by an upper-level management device, which can be implemented using software and / or hardware and can be integrated into a cloud server (or service management server) where the cryptographic processing device is installed.
[0097] The control method of the cryptographic processing device applied to the upper management apparatus can be executed in conjunction with the aforementioned cryptographic processing method applied to the cryptographic processing device. For matters not explained in detail in the following embodiments, reference can be made to the detailed explanation in any of the above embodiments.
[0098] For ease of understanding Figure 5 The method logic shown in , you can also refer to Figure 9 or Figure 10 The content shown in Figure 9 is a schematic diagram of the structure of a password processing system provided by an embodiment of the present disclosure. Figure 10 This is a flowchart of a password processing method corresponding to a password processing system provided by an embodiment of the present disclosure.
[0099] like Figure 5 As shown, the control method of the password processing device provided by the embodiment of the present disclosure may include:
[0100] S201: Generate a file loading request and send the file loading request to a service management server. The file loading request includes an identifier of a preloaded service processing file.
[0101] The identifier is used to uniquely identify the service processing file, so that the service management server can accurately obtain the required service processing file. The file loading request can be triggered based on the user's operation on the operation interface or user interface displayed in the cloud server.
[0102] Example 1: Generating a file loading request includes:
[0103] Display the user management interface;
[0104] Obtaining the first selection operation of the user to select a service to process a file based on the user management interface;
[0105] A file load request including an identification of a service process file is generated based on the selection operation.
[0106] The upper-level management device integrated into the service management server can be implemented in the form of a client. When a user has a file loading request, the client can be activated, causing the client to display a user login interface, which may include login information such as an account and password. The user can successfully log in by entering the correct account and password. After the user successfully logs in, the client displays a user management interface to the user, which may display a list or icons of multiple service processing files. Then, based on the user's first selection operation on the service processing file, the client determines the identifier of the service processing file selected by the user, and then generates a file loading request.
[0107] Example 2: generating a file loading request, including:
[0108] Display the user management command input window;
[0109] Obtaining a selection instruction for selecting a service processing file input by a user based on a user management instruction input window;
[0110] A file load request including an identification of the service process file is generated based on the selection instruction.
[0111] The upper-level management device integrated in the service management server is provided with a corresponding instruction input window in the service management server. The user can use the instruction window call method to request the upper-level management device to display the user management instruction input window; then, the user uses the input tool to input the selection instruction for the service processing file, and the selection instruction may include the identification of the service processing file, so that the upper-level management device can generate a file loading request including the identification of the service processing file according to the selection instruction.
[0112] Example 3: Generate a file loading request, including:
[0113] Get the file selection service page and display it;
[0114] Obtaining a second selection operation of the user selecting a corresponding service to process a file based on the file selection service page;
[0115] A file load request including an identification of the service process file is generated based on the second selection operation.
[0116] When a user has a file loading requirement, a file selection service page acquisition request can be first triggered in the service management server, for example, by a preset instruction or control in the service management server. The service management server sends a file selection service page to the upper-level management device according to the request, so that the upper-level management device can display the file selection service page to the user, and then generate a file loading request according to the user's page selection operation.
[0117] The above examples are only used to illustrate the embodiments of the present disclosure and should not be understood as specific limitations of the embodiments of the present disclosure. Other methods that can be used to generate file loading requests also fall within the scope of the embodiments of the present disclosure.
[0118] Furthermore, in an embodiment of the present disclosure, the upper-level management device sends a file loading request to the service management server, including: sending the file loading request to a network point of presence, so that the network point of presence routes the file loading request to the service management server.
[0119] The network point of presence may include but is not limited to a POP (pop-point-of-presence) point of presence. In the disclosed embodiment, the interaction between the upper-level user management module in the upper-level management apparatus and the user management module in the password processing device, and the interaction between the upper-level file management module in the upper-level management apparatus and the file management module in the password processing device, are two isolated interaction processes, that is, the data link supporting user operations and the data link within the service system are independent of each other, and the data link supporting user operations cannot directly access the data link within the service system. Therefore, the file loading request generated based on the user operation needs to be routed to the service management server by the network point of presence, so as to ensure the security of the data link within the service system.
[0120] S202: Receive the service processing file fed back by the service management server, and send the service processing file to the file management module of the password management device.
[0121] Based on the above technical solution, exemplarily, the upper management device includes an upper user management module and an upper file management module, the upper user management module generates a file loading request, and the upper file management module receives the service processing file fed back by the service management server.
[0122] Furthermore, the control method of the cryptographic processing device provided by the embodiment of the present disclosure may further include:
[0123] The upper-layer user management module receives the first scenario data sent by the service scenario device, and sends the first scenario data to the user management module of the password processing device; and / or,
[0124] Receive the second scene data sent by the user management module, and feed back the second scene data to the service scene device.
[0125] Specifically, the user management module receives the first scenario data sent by the upper-level user management module, and sends the first scenario data to the service processing module in the dynamic configuration area; the service processing module processes the first scenario data based on the service processing file to obtain service data to be cryptographically processed; the service processing module also processes the cryptographically processed service data based on the service processing file to generate second scenario data, and sends the second service scenario data to the user management module in the static configuration area; the user management module sends the second scenario data to the upper-level user management module.
[0126] Regarding the interaction between the user management module of the cryptographic processing device and the upper-level user management module of the upper-level management device, the service processing file not only defines how to obtain the service data to be cryptographically processed from the first scenario data, but also defines the processing logic for processing the cryptographically processed service data to generate the second scenario data. The first scenario data, the second scenario data, and the processing logic for generating the second scenario data are all related to the specific service scenario and can be determined according to the service processing requirements. The present disclosed embodiments do not specifically limit these.
[0127] In the embodiment of the present disclosure, through the interaction between the upper-level management device, the service management server and the cryptographic processing device, it is possible to control the cryptographic processing device to dynamically load the service processing file in the cloud server scenario, so that the cryptographic processing device can be applied to any service scenario with data encryption or decryption requirements, and realize dynamic encryption processing or decryption processing for different service scenarios. This solves the problem that the data encryption or decryption processing is closely coupled with the specific service scenario in the existing solution, resulting in a relatively single application scenario for the data encryption or decryption processing. At the same time, it also solves the problem that the encryption or decryption processing process has low efficiency for different service scenarios due to the service scenario not supporting reconfiguration. This realizes the decoupling of data encryption or decryption processing from the specific service scenario, improves the versatility of data encryption or decryption processing for different service scenarios, and improves the efficiency of data encryption or decryption processing for different service scenarios.
[0128] Figure 6This is a flowchart of another control method for a cryptographic processing device provided by an embodiment of the present disclosure, which is used to exemplarily illustrate how to implement file or data loading in the dynamic configuration area of the cryptographic processing device. Figure 6 The control method of the cryptographic processing device shown can be executed by a control device of the cryptographic processing device, which can be implemented using software and / or hardware and can be integrated into a cloud server (or service management server) where the cryptographic processing device is installed.
[0129] The control method of the cryptographic processing device applied to the service management server belongs to the same inventive concept as the control method of the cryptographic processing device applied to the upper-level management device mentioned above. The two are executed in coordination. For the contents not explained in detail in the following embodiments, please refer to the detailed explanation in the above embodiments.
[0130] For ease of understanding Figure 6 The method logic shown in , you can also refer to Figure 9 or Figure 10 As shown in Figure 6 As shown, the control method of the password processing device provided by the embodiment of the present disclosure may include:
[0131] S301: Receive a file loading request sent by an upper-level management device, where the file loading request includes an identifier of a preloaded service processing file.
[0132] S302: Send a service processing file corresponding to the identifier to an upper-level management apparatus, so that the upper-level management apparatus sends the service processing file to a file management module of the password management device.
[0133] Optionally, the upper-level management device includes an upper-level user management module and an upper-level file management module. Receiving a file loading request sent by the upper-level management device is receiving a file loading request sent by the upper-level user management module, and sending a service processing file corresponding to the identifier to the upper-level management device is sending a service processing file corresponding to the identifier to the upper-level file management module.
[0134] Based on the above technical solution, optionally, after receiving the file loading request sent by the upper-level management device, the control method of the cryptographic processing device provided by the embodiment of the present disclosure further includes: recording the identifier of the upper-level management device that sent the file loading request and the identifier of the service processing file in the status recording module;
[0135] Accordingly, before sending the service processing file corresponding to the identifier to the upper-level management apparatus, the control method of the password processing device provided by the embodiment of the present disclosure further includes:
[0136] The state record module is traversed to obtain the identifier of the upper management device that sends the file loading request and the identifier of the corresponding service processing file.
[0137] By recording and traversing the identification of the upper management device and the identification of the service processing file, the service management server can determine the file loading request currently received from the upper management device, thereby ensuring the validity of the service processing file sending.
[0138] Optionally, before sending the service processing file corresponding to the identifier to the upper-level management apparatus, the control method of the password processing device provided by the embodiment of the present disclosure further includes:
[0139] Sending a file acquisition request to the cloud storage device based on the identifier of the service processing file;
[0140] Receive a service processing file corresponding to the identifier fed back by the cloud storage device.
[0141] Cloud storage devices offer the advantages of large storage space and high storage flexibility. For cloud-based interactions, the service management server can retrieve the required service processing files from the cloud storage device and feed them back to the upper-level file management module. Of course, the service management server can also retrieve service processing files from other pre-defined storage locations, which is not specifically limited in this embodiment.
[0142] In the embodiment of the present disclosure, through the interaction between the upper-level management device, the service management server and the cryptographic processing device, it is possible to control the cryptographic processing device to dynamically load the service processing file in the cloud server scenario, so that the cryptographic processing device can be applied to any service scenario with data encryption or decryption requirements, and realize dynamic encryption processing or decryption processing for different service scenarios, thereby solving the problem that the data encryption or decryption processing is closely coupled with the specific service scenario in the existing solution, resulting in a relatively single application scenario for the data encryption or decryption processing. At the same time, it also solves the problem that the encryption or decryption processing process has low efficiency for different service scenarios due to the service scenario not supporting reconfiguration, realizes the decoupling of data encryption or decryption processing from the specific service scenario, improves the versatility of data encryption or decryption processing for different service scenarios, and improves the efficiency of data encryption or decryption processing for different service scenarios.
[0143] Figure 7 This is a structural diagram of a control device of a cryptographic processing device provided by an embodiment of the present disclosure. The control device can be implemented using software and / or hardware and can be configured in an upper-level management device.
[0144] like Figure 7 As shown, the control device 400 of the cryptographic processing device provided by the embodiment of the present disclosure may include a file loading request generating module 401 and a service processing file receiving module 402, wherein:
[0145] A file loading request generating module 401 is configured to generate a file loading request and send the file loading request to a service management server, wherein the file loading request includes an identifier of a preloaded service processing file;
[0146] The service processing file receiving module 402 is configured to receive the service processing file fed back by the service management server and send the service processing file to the file management module of the password management device.
[0147] Optionally, the upper-layer management device includes an upper-layer user management module and an upper-layer file management module. The upper-layer user management module generates file loading requests and receives service processing files fed back by the service management server. In other words, the file loading request generation module 401 can be referred to as the upper-layer user management module, or as a functional module integrated into the upper-layer user management module; similarly, the service processing file receiving module 402 can be referred to as the upper-layer file management module, or as a functional module integrated into the upper-layer file management module.
[0148] Optionally, the service processing file receiving module 402 may be referred to as an upper-layer file management module as an example. The upper-layer file management module includes:
[0149] A receiving unit, configured to receive a service processing file fed back by a service management server;
[0150] A sending unit, configured to send a service processing file to a file management module of a password management device;
[0151] Optionally, the sending unit is specifically configured to: send the file loading request to the network point of presence, so that the network point of presence routes the file loading request to the service management server.
[0152] Optionally, the upper user management module is further configured to: receive first scene data sent by the service scene device, and send the first scene data to the user management module; and / or,
[0153] Receive the second scene data sent by the user management module, and feed back the second scene data to the service scene device.
[0154] Optionally, taking the file loading request generating module 401 as an example, which can be called an upper-layer user management module, the upper-layer user management module includes:
[0155] A generation unit, used for generating a file loading request;
[0156] A sending unit, configured to send a file loading request to a service management server;
[0157] Optionally, the sending unit includes:
[0158] The first display unit is used to display the user management interface;
[0159] A first acquiring unit, configured to acquire a first selection operation of a user selecting a service processing file based on a user management interface;
[0160] A first generating unit is configured to generate a file loading request including an identifier of a service processing file based on a selection operation; or
[0161] The second display unit is used to display the user management instruction input window;
[0162] The second acquiring unit is configured to acquire a selection instruction for selecting a service processing file input by a user based on the user management instruction input window;
[0163] A second generating unit is configured to generate a file loading request including an identifier of the service processing file based on the selection instruction; or
[0164] The third display unit is used to obtain and display the file selection service page;
[0165] A third obtaining unit is used to obtain a second selection operation of the user selecting a corresponding service processing file based on the file selection service page;
[0166] The third generating unit is configured to generate a file loading request including an identifier of the service processing file based on the second selection operation.
[0167] The control device for a cryptographic processing device provided in an upper-level management apparatus according to the embodiments of the present disclosure can execute any of the control methods for a cryptographic processing device applied to an upper-level management apparatus provided in the embodiments of the present disclosure, and has the corresponding functional modules and beneficial effects. For matters not fully described in the embodiments of the present disclosure, reference may be made to the description of any of the method embodiments of the present disclosure.
[0168] Figure 8 This is a structural diagram of a control device of another cryptographic processing device provided by an embodiment of the present disclosure. The control device can be implemented using software and / or hardware and can be configured in a service management server.
[0169] like Figure 8 As shown, the control device 500 of the cryptographic processing device provided by the embodiment of the present disclosure may include a file loading request receiving module 501 and a service processing file sending module 502, wherein:
[0170] A file loading request receiving module 501 is configured to receive a file loading request sent by an upper-layer management device, wherein the file loading request includes an identifier of a preloaded service processing file;
[0171] The service processing file sending module 502 is used to send the service processing file corresponding to the identifier to the upper-level management device, so that the upper-level management device can send the service processing file to the file management module of the password management device.
[0172] Optionally, the upper-level management device includes an upper-level user management module and an upper-level file management module. Receiving a file loading request sent by the upper-level management device is receiving a file loading request sent by the upper-level user management module, and sending a service processing file corresponding to the identifier to the upper-level management device is sending a service processing file corresponding to the identifier to the upper-level file management module.
[0173] Optionally, the control device 500 of the cryptographic processing device provided in the embodiment of the present disclosure further includes:
[0174] A status recording module, used to record the identifier of the upper management device that sends the file loading request and the identifier of the service processing file;
[0175] Accordingly, the control device 500 of the cryptographic processing device provided in the embodiment of the present disclosure further includes:
[0176] The state traversal module is used to traverse the state recording module to obtain the identifier of the upper management device that sends the file loading request and the identifier of the corresponding service processing file.
[0177] Optionally, the control device 500 of the cryptographic processing device provided in the embodiment of the present disclosure further includes:
[0178] A file acquisition request sending module, used for sending a file acquisition request to the cloud storage device based on the identifier of the service processing file;
[0179] The service processing file receiving module is used to receive the service processing file corresponding to the identifier fed back by the cloud storage device.
[0180] The control device for a cryptographic processing device provided in the embodiments of the present disclosure and configured on a service management server can execute any of the control methods for a cryptographic processing device applied to a service management server provided in the embodiments of the present disclosure, and has the corresponding functional modules and beneficial effects. For matters not fully described in the embodiments of the present disclosure, reference can be made to the description of any of the method embodiments of the present disclosure.
[0181] Figure 9 This is a schematic diagram of the structure of a password processing system provided by an embodiment of the present disclosure. Figure 9 As shown, the password processing system 600 provided by the embodiment of the present disclosure may include an upper-layer management device 601, a service management server 602, and a password management device 603, wherein:
[0182] The upper management device 601 is used to generate a file loading request and send the file loading request to the service management server 602, where the file loading request includes an identifier of a preloaded service processing file;
[0183] The service management server 602 is configured to receive a file loading request sent by the upper-layer management device 601 and send a service processing file corresponding to the identifier to the upper-layer management device 601;
[0184] The upper management device 601 is further configured to receive the service processing file fed back by the service management server 602 and send the service processing file to the file management module of the password management device 603;
[0185] The file management module of the password management device 603 is used to send the service processing file to the service processing module of the password management device 603;
[0186] The service processing module of the password management device 603 is configured to obtain service data to be cryptographically processed based on the service processing file and send the service data to be cryptographically processed to the password processing module of the password management device 603;
[0187] The password processing module of the password management device 603 is used to perform password processing on the service data to be password processed based on the password algorithm, and feed back the password-processed service data to the service processing module. The password processing includes encryption processing or decryption processing.
[0188] Optionally, the upper-level management device 601 includes an upper-level user management module and an upper-level file management module. The upper-level user management module generates a file loading request and sends the file loading request to the service management server 602. The upper-level file management module receives the service processing file feedback from the service management server 602 and sends the service processing file to the file management module of the password management device 603.
[0189] It should be noted that the functions that can be realized by the upper management device 601, service management server 602 and password management device 603 in the password processing system 600 provided in the embodiment of the present disclosure are not limited to the above description. Figure 9 Not shown, other functional modules corresponding to optional implementations of the control method of the cryptographic processing device may also be included in the cryptographic processing system 600.
[0190] In the embodiment of the present disclosure, through the interaction between the upper-level management device, the service management server and the cryptographic processing device, it is possible to control the cryptographic processing device to dynamically load the service processing file in the cloud server scenario, so that the cryptographic processing device can be applied to any service scenario with data encryption or decryption requirements, and realize dynamic encryption processing or decryption processing for different service scenarios, thereby realizing the decoupling of data encryption or decryption processing from specific service scenarios, improving the versatility of data encryption or decryption processing for different service scenarios, and improving the efficiency of data encryption or decryption processing for different service scenarios.
[0191] Figure 10 It is a flowchart of a cryptographic processing method corresponding to a cryptographic processing system provided by an embodiment of the present disclosure, or a flowchart of the dynamic loading implementation of files in the dynamic configuration area of a cryptographic processing device in a cloud server, which is used to exemplify the embodiment of the present disclosure and should not be understood as a specific limitation of the embodiment of the present disclosure.
[0192] and, Figure 10 Only some functional modules of the upper-layer management apparatus 601 and the cryptographic processing device 603 are shown. For other functional modules that may be included in the upper-layer management apparatus 601 and the cryptographic processing device 603, reference may be made to other descriptions of the embodiments of the present disclosure.
[0193] like Figure 10 As shown, the upper-layer user management module in the upper-layer management device 601 can be obtained by transparently transmitting the user management module in the password processing device 603 and providing a visual user interface to the user. The upper-layer user management module can generate a file loading request based on user operations received on the user interface, such as selecting a service processing file. The upper-layer user management module sends the file loading request to a network point of presence (e.g., a Point of Presence (POP) point of presence), which then routes the file loading request to the service management server 602. After receiving the file loading request, the service management server 602 can interact with the upper-layer management device 601, for example, by pulling the file loading request from the upper-layer management device 601, to determine whether the currently received file loading request was sent by the upper-layer management device 601. The file loading request can include the identifier of a preloaded service processing file.
[0194] In the embodiment of the present disclosure, the interaction between the upper-level user management module in the upper-level management device 601 and the user management module in the password processing device 603, and the interaction between the upper-level file management module in the upper-level management device 601 and the file management module in the password processing device 603, are two isolated interaction processes, that is, the data link supporting user operations and the data link within the service system are independent of each other, and the data link supporting user operations cannot directly access the data link within the service system. Therefore, the file loading request generated by the user operation received based on the user interface needs to be routed to the service management server 602 by the network access point, so as to ensure the security of the data link within the service system.
[0195] The service management server 602 obtains the corresponding service processing file based on the service processing file identifier carried in the file loading request, and then feeds it back to the upper-layer file management module in the upper-layer management device 601. The service management server 602 can obtain the required service processing file from a cloud storage device or an object storage service (OSS), or from other preset storage locations, which is not specifically limited in the embodiment of the present disclosure.
[0196] The upper-level file management module sends the received service processing file to the file management module of the password management device 603; inside the password management device 603, the file management module sends the service processing file to the service processing module; the service processing module obtains the service data to be cryptographically processed based on the service processing file, and sends the service data to be cryptographically processed to the cryptographic processing module; the cryptographic processing module performs cryptographic processing on the service data to be cryptographically processed based on the cryptographic algorithm, and feeds back the cryptographically processed service data to the service processing module. The cryptographic processing includes encryption processing or decryption processing.
[0197] Furthermore, the service processing module can send the service data after the password processing to the user management module, and the user management module can feed the service data after the password processing back to the upper user management module. If the user has the need to view the data, he can view the service data after the password processing through the user interface or perform other data processing.
[0198] In the embodiment of the present disclosure, through the interaction between the upper-level management device, the service management server and the cryptographic processing device, it is possible to control the cryptographic processing device to dynamically load the service processing file in the cloud server scenario, so that the cryptographic processing device can be applied to any service scenario with data encryption or decryption requirements, and realize dynamic encryption processing or decryption processing for different service scenarios, thereby realizing the decoupling of data encryption or decryption processing from specific service scenarios, improving the versatility of data encryption or decryption processing for different service scenarios, and improving the efficiency of data encryption or decryption processing for different service scenarios.
[0199] Figure 11 A structural schematic diagram of an electronic device provided for an embodiment of the present disclosure is used to exemplify an electronic device that implements a control method for any cryptographic processing device in an embodiment of the present disclosure, or to exemplify an electronic device integrated with an upper-level management device for implementing the control method for the cryptographic processing device in an embodiment of the present disclosure. The electronic device can be, for example, a local host or a cloud server.
[0200] The following specifically refers to a schematic diagram of the structure of an electronic device 1100 suitable for implementing the embodiments of the present disclosure. The electronic device 1100 in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. The electronic device shown is merely an example and should not limit the functionality or scope of the embodiments of the present disclosure.
[0201] As shown in the figure, the electronic device 1100 may include a processor (e.g., a central processing unit, a graphics processing unit, etc.) 1101, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1102 or a program loaded from a storage device 1108 into a random access memory (RAM) 1103. Various programs and data required for the operation of the electronic device 1100 are also stored in the RAM 1103. The processor 1101, the ROM 1102, and the RAM 1103 are connected to each other via a bus 1104. An input / output (I / O) interface 1105 is also connected to the bus 1104.
[0202] Typically, the following devices may be connected to the I / O interface 1105: an input device 1106 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 1107 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1108 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1109. The communication device 1109 may allow the electronic device 1100 to communicate with other devices wirelessly or by wire to exchange data. Although the electronic device 1100 is shown as having various devices, it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or have alternatively.
[0203] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 1109, or installed from the storage device 1108, or installed from the ROM 1102. When the computer program is executed by the processor 1101, the functions defined in the control method of any cryptographic processing device provided by the embodiment of the present disclosure can be executed.
[0204] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. Computer-readable storage media may be, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.
[0205] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.
[0206] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0207] The above-mentioned computer-readable medium carries one or more programs. When the above-mentioned one or more programs are executed by the electronic device, the electronic device: generates a file loading request and sends the file loading request to the service management server, wherein the file loading request includes the identifier of the preloaded service processing file; receives the service processing file feedback from the service management server, and sends the service processing file to the file management module of the password management device.
[0208] Alternatively, the computer-readable medium carries one or more programs, and when the one or more programs are executed by the electronic device, the electronic device: receives a file loading request sent by an upper-level management device, wherein the file loading request includes an identifier of a preloaded service processing file; and sends a service processing file corresponding to the identifier to the upper-level management device, so that the upper-level management device sends the service processing file to the file management module of the password management device.
[0209] In embodiments of the present disclosure, computer program code for performing the operations of the present disclosure may be written in one or more programming languages or a combination thereof, including but not limited to object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0210] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0211] The units involved in the embodiments described in this disclosure may be implemented in software or hardware, wherein the name of a unit does not necessarily limit the unit itself.
[0212] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0213] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0214] According to one or more embodiments of the present disclosure, the present disclosure provides a computer-readable storage medium, which stores a computer program, and the computer program is used to execute the control method of any cryptographic processing device provided by the embodiments of the present disclosure, or to execute any cryptographic processing method provided by the embodiments of the present disclosure.
[0215] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0216] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to." The term "based on" means "based at least in part on." The term "an alternative embodiment" means "at least one alternative embodiment." Concepts such as "first" and "second" mentioned in this disclosure are merely used to distinguish different devices, modules, or units, and are not intended to limit the order or interdependence of the functions performed by these devices, modules, or units.
[0217] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0218] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also includes other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the above-mentioned disclosed concepts. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.
[0219] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details have been included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.
[0220] Although the subject matter has been described in language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims.
Claims
1. A cryptographic processing device, characterized in that: It includes a dynamic configuration area and a static configuration area, wherein the dynamic configuration area is provided with a service processing module and the static configuration area is provided with a password processing module; The service processing module can dynamically configure different service processing files, each of which corresponds to a service scenario. The service processing module is used to obtain service data to be cryptographically processed based on the service processing file and send the service data to be cryptographically processed to the cryptographic processing module, wherein the service scenario includes at least one of a server application scenario, a trusted computing application scenario, or an encrypted storage application scenario. The cryptographic processing module is used to perform cryptographic processing on the service data to be cryptographically processed based on a cryptographic algorithm, and feed the cryptographically processed service data back to the service processing module, wherein the cryptographic processing includes encryption processing or decryption processing; The service processing module is configured with multiple service processing files, each of which is for different service scenarios, and the password processing module simultaneously performs data encryption or decryption tasks for the multiple service processing files. There are multiple static configuration areas, each of which has a different encryption algorithm and / or decryption algorithm. The user can choose to enable one or more static configuration areas based on the needs of the service scenario.
2. The cryptographic processing device according to claim 1, wherein: The static configuration area is also provided with: The key storage module is used to store the key of the cryptographic algorithm.
3. The cryptographic processing device according to claim 1, wherein: The static configuration area is also provided with: The file management module is used to receive a service processing file corresponding to the service scenario and configure the service processing file to the service processing module.
4. The cryptographic processing device according to claim 3, wherein: The number of the service processing files configured by the service processing module is at least one.
5. The cryptographic processing device according to claim 3, wherein: The static configuration area is also provided with: The authentication module is used to send the firmware of the static configuration area to an external authentication chip for authentication.
6. The cryptographic processing device according to claim 5, wherein: The authentication module is further configured to send the service processing file to an external authentication chip for authentication; The file management module is used to configure the service processing file to the service processing module after the service processing file is authenticated.
7. The cryptographic processing device according to claim 1, wherein: The static configuration area is also provided with: A user management module, configured to receive first scenario data sent by the upper-layer user management module, and send the first scenario data to the service processing module in the dynamic configuration area; The service processing module is further configured to process the first scene data based on the service processing file to obtain service data to be cryptographically processed; and / or, The service processing module is further configured to process the service data after the password processing based on the service processing file to generate second scenario data, and send the second scenario data to the user management module of the static configuration area; The user management module is used to feed back the second scenario data to the upper-layer user management module.
8. The cryptographic processing device according to claim 7, wherein: The user management module and the service processing module are connected via a PCIE interface.
9. The cryptographic processing device according to claim 1, wherein: The dynamic configuration area is provided with a network port; The service processing module is configured to receive first scenario data sent by the service scenario device through the network port, and process the first scenario data based on the service processing file to obtain service data to be cryptographically processed; and / or, The service processing module is used to process the service data after password processing based on the service processing file, generate second scene data, and send the second scene data to the service scene device through the network port.
10. The cryptographic processing device according to claim 1, wherein: The cryptographic processing device is implemented based on a field programmable gate array.
11. The cryptographic processing device according to claim 1, wherein: The password processing device is deployed in a local server or a cloud server.
12. A method for controlling a cryptographic processing device, characterized in that: Applicable to upper-level management devices, including: Generating a file loading request and sending the file loading request to a service management server, the file loading request including an identifier of a preloaded service processing file, wherein the service processing file corresponds to a service scenario, the service scenario including at least one of a server application scenario, a trusted computing application scenario, or an encrypted storage application scenario, and the number of the service processing files is multiple, the multiple service processing files being targeted at different service scenarios, and the password management device simultaneously executing data encryption or decryption tasks for the multiple service processing files; Receive the service processing file fed back by the service management server, and issue the service processing file to the file management module of the password management device, wherein the password management device includes a static configuration area, the number of the static configuration areas is multiple, and the encryption algorithm and / or decryption algorithm of each static configuration area is different. The user chooses to enable one or more static configuration areas according to the requirements of the service scenario.
13. The control method according to claim 12, characterized in that: The upper management device includes an upper user management module and an upper file management module. The upper user management module generates a file loading request, and the upper file management module receives the service processing file fed back by the service management server.
14. The control method according to claim 13, characterized in that: The sending the file loading request to the service management server includes: The file loading request is sent to a network point of presence, so that the network point of presence routes the file loading request to a service management server.
15. The control method according to claim 13, characterized in that: Also includes: The upper-layer user management module receives the first scenario data sent by the service scenario device, and sends the first scenario data to the user management module; and / or, Receive the second scenario data sent by the user management module, and feed back to the service scenario device the second scenario data sent by the service scenario device.
16. The control method according to claim 12, characterized in that: The generating of the file loading request includes: Display the user management interface; Acquire a first selection operation of a user selecting a service processing file based on the user management interface; Generate a file loading request including the identifier of the service processing file based on the selection operation; or Display the user management command input window; Acquire a selection instruction for selecting a service processing file input by a user based on the user management instruction input window; Generate a file loading request including the identifier of the service processing file based on the selection instruction; or Get the file selection service page and display it; Acquire a second selection operation of the user selecting a corresponding service processing file based on the file selection service page; A file loading request including an identifier of the service processing file is generated based on the second selection operation.
17. A method for controlling a cryptographic processing device, characterized in that: Applies to service management servers, including: receiving a file loading request sent by an upper-level management device, the file loading request including an identifier of a preloaded service processing file, wherein the service processing file corresponds to a service scenario, the service scenario including at least one of a server application scenario, a trusted computing application scenario, or an encrypted storage application scenario, and the number of the service processing files is multiple, the multiple service processing files being targeted at different service scenarios, and the password management device simultaneously executing data encryption or decryption tasks for the multiple service processing files; A service processing file corresponding to the identifier is sent to the upper-level management device, so that the upper-level management device can issue the service processing file to the file management module of the password management device, wherein the password management device includes a static configuration area, the number of the static configuration areas is multiple, the encryption algorithm and / or decryption algorithm of each static configuration area is different, and the user chooses to enable one or more static configuration areas according to the requirements of the service scenario.
18. The control method according to claim 17, characterized in that: The upper-level management device includes an upper-level user management module and an upper-level file management module. Receiving the file loading request sent by the upper-level management device is receiving the file loading request sent by the upper-level user management module. Sending the service processing file corresponding to the identifier to the upper-level management device is sending the service processing file corresponding to the identifier to the upper-level file management module.
19. The control method according to claim 17, characterized in that: After receiving the file loading request sent by the upper management device, the method further includes: Recording in the status recording module the identifier of the upper management device that sends the file loading request and the identifier of the service processing file; Before sending the service processing file corresponding to the identifier to the upper management device, the method further includes: The state record module is traversed to obtain the identifier of the upper management device that sends the file loading request and the identifier of the corresponding service processing file.
20. The control method according to claim 17, characterized in that: Before sending the service processing file corresponding to the identifier to the upper management device, the method further includes: Sending a file acquisition request to a cloud storage device based on an identifier of the service processing file; Receive a service processing file corresponding to the identifier fed back by the cloud storage device.
21. A password processing method, characterized in that: Applicable to cryptographic processing equipment, including: Dynamically configuring different service processing files in the service processing module, and obtaining service data to be cryptographically processed based on the service processing files, wherein the service processing files correspond to service scenarios, and the service scenarios include at least one of a server application scenario, a trusted computing application scenario, or an encrypted storage application scenario. The service processing module is configured with multiple service processing files, and the multiple service processing files are targeted at different service scenarios. The cryptographic processing module simultaneously performs data encryption or decryption tasks for the multiple service processing files. The service data to be cryptographically processed is cryptographically processed by a cryptographic processing module based on a cryptographic algorithm, and the cryptographically processed service data is fed back to the service processing module. The cryptographic processing includes encryption processing or decryption processing. There are multiple cryptographic processing modules, and the encryption algorithm and / or decryption algorithm of each cryptographic processing module is different. The user chooses to enable one or more cryptographic processing modules according to the requirements of the service scenario.
22. A control device for a cryptographic processing device, characterized in that: Configured in the upper management device, including: a file loading request generation module, configured to generate a file loading request and send the file loading request to a service management server, wherein the file loading request includes an identifier of a preloaded service processing file, wherein the service processing file corresponds to a service scenario, wherein the service scenario includes at least one of a server application scenario, a trusted computing application scenario, or an encrypted storage application scenario, and wherein there are multiple service processing files, each of which is targeted at different service scenarios, and the password management device simultaneously performs data encryption or decryption tasks for the multiple service processing files; A service processing file receiving module is used to receive the service processing file fed back by the service management server and send the service processing file to the file management module of the password management device, wherein the password management device includes a static configuration area, the number of the static configuration areas is multiple, and the encryption algorithm and / or decryption algorithm of each static configuration area is different. The user chooses to enable one or more static configuration areas according to the requirements of the service scenario.
23. A control device for a cryptographic processing device, characterized in that: Configured on the service management server, including: a file loading request receiving module, configured to receive a file loading request sent by an upper-level management device, the file loading request including an identifier of a preloaded service processing file, wherein the service processing file corresponds to a service scenario, the service scenario including at least one of a server application scenario, a trusted computing application scenario, or an encrypted storage application scenario, and the number of the service processing files is multiple, each of the multiple service processing files being targeted at different service scenarios, and the password management device simultaneously executing data encryption or decryption tasks for the multiple service processing files; A service processing file sending module is used to send a service processing file corresponding to the identifier to the upper-level management device, so that the upper-level management device can send the service processing file to the file management module of the password management device, wherein the password management device includes a static configuration area, the number of the static configuration areas is multiple, the encryption algorithm and / or decryption algorithm of each static configuration area is different, and the user chooses to enable one or more static configuration areas according to the requirements of the service scenario.
24. A password processing system, characterized in that: include: an upper-layer management device, configured to generate a file loading request and send the file loading request to a service management server, wherein the file loading request includes an identifier of a preloaded service processing file, wherein the service processing file corresponds to a service scenario, and the service scenario includes at least one of a server application scenario, a trusted computing application scenario, or an encrypted storage application scenario; The service management server is configured to receive a file loading request sent by the upper-layer management device, and send a service processing file corresponding to the identifier to the upper-layer management device; The upper management device is further configured to receive the service processing file fed back by the service management server and send the service processing file to the file management module of the password management device; The file management module of the password management device is configured to send the service processing file to the service processing module of the password management device; The service processing module of the password management device is configured to obtain service data to be cryptographically processed based on the service processing file, and send the service data to be cryptographically processed to the password management device's password processing module, wherein the service processing module is configured with multiple service processing files, each of which is targeted at different service scenarios, and the password processing module simultaneously performs data encryption or decryption tasks for the multiple service processing files; The password processing module of the password management device is used to perform password processing on the service data to be password processed based on a password algorithm, and feed back the password-processed service data to the service processing module. The password processing includes encryption processing or decryption processing. There are multiple password processing modules, and the encryption algorithm and / or decryption algorithm of each password processing module is different. The user chooses to enable one or more password processing modules according to the requirements of the service scenario.
25. An electronic device, characterized in that: The invention comprises a memory and a processor, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the processor executes the control method of the cryptographic processing device according to any one of claims 12 to 16, or executes the control method of the cryptographic processing device according to any one of claims 17 to 20.
26. A computer-readable storage medium, characterized in that The storage medium stores a computer program. When the computer program is executed by a processor, the processor executes the control method of the cryptographic processing device according to any one of claims 12 to 16, or executes the control method of the cryptographic processing device according to any one of claims 17 to 20.
Citation Information
Patent Citations
File content encryption method and apparatus, and electronic device
CN109361717A
Data processing method based on integrated chip, computer equipment and storage medium
CN110580420A
Information encryption processing method, server, terminal, equipment and storage medium
CN111191255A
Data processing method and device
CN111722995A