Key management method, device and system
By introducing key management network elements into the business system, ciphertext of key components is distributed and ciphertext is decrypted and generated by decrypting the first key, the risk of key leakage is solved, key security is improved, and hardware resource requirements are reduced.
Patent Information
- Application Number
- CN202010567928.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-19
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2040-06-19
AI Technical Summary
The prior art is difficult to effectively protect the security of keys, resulting in the risk of key leakage.
By introducing key management network elements into the service system, the ciphertext of the key component is used to store the ciphertext in a distributed manner, and the private key decryption is used to generate the first key for performing the key operation.
It improves the security of key component storage, reduces the risk of key leakage, and does not require professional hardware equipment, reducing hardware resource requirements.
Smart Images

Figure CN113824553B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of encryption technology, and in particular to a key management method, device and system. Background Art
[0002] In business systems, encryption technology is usually used to encrypt business-sensitive data in order to ensure the confidentiality and consistency of storage and transmission of business-sensitive data, such as encrypted storage of customer certificate information, encrypted transmission of transaction amounts, and signature tamper-proofing of customer account balances. Encryption technology usually uses encryption algorithms, decryption algorithms, and keys.
[0003] Since the algorithms (such as encryption algorithms and decryption algorithms) themselves are public, the business system must ensure the security of the keys. If the keys are leaked, when the ciphertext of the business-sensitive data is obtained, the ciphertext of the business-sensitive data can be decrypted according to the decryption algorithm to obtain the original text of the business-sensitive data, thereby leaking the business-sensitive data. Therefore, in order not to leak business-sensitive data, the security of the keys must be guaranteed to prevent the keys from being leaked. Summary of the invention
[0004] The embodiments of the present application provide a key management method, device and system to solve the problem of key leakage.
[0005] In order to achieve the above objectives, the embodiments of the present application adopt the following technical solutions:
[0006] In a first aspect, an embodiment of the present application provides a key management method, which is executed by a key management network element. The method may include: the key management network element selects M key storage addresses from N key storage addresses in response to a key operation request, one key storage address can be used to obtain a ciphertext of a key component from a key component management network element, obtain the ciphertext of the M key components according to the M key storage addresses, use the private key of the key management network element to decrypt the ciphertext of the M key components to obtain the plaintext of the M key components, generate a first key based on the plaintext of the M key components, and use the first key and the identifier (identifier, ID) of the first key to perform corresponding key operations.
[0007] Based on the method described in the first aspect, the key component can be encrypted into a ciphertext of the key component and then distributedly stored on the key component management network element, and the key management network element is triggered to save the ciphertext storage address corresponding to the ciphertext storing the key component on the key management network element, so that after receiving the key operation request, the key management network element selects a ciphertext storage address from the existing ciphertext storage address, obtains the ciphertext of M key components according to the selected key storage address, uses the private key of the key management network element to decrypt the ciphertext of the M key components to obtain the plaintext of the M key components, generates a first key based on the plaintext of the M key components, and uses the first key to perform the corresponding key operation. Since there are many key component management network elements, and the key components are distributed in a large number of key component management network elements in the form of ciphertext, it is difficult for attackers / criminals to obtain key components from a large number of key component management network elements, thereby ensuring the security of key component storage, and then ensuring the security of the key generated according to the key components. At the same time, there is no need for professional hardware equipment such as quantum key distribution equipment and encryption machines to ensure the security of key component storage, reducing hardware resource requirements.
[0008] In one possible design, the method also includes: receiving registration requests sent by N key component management network elements to indicate that the key component management network elements store ciphertexts of key components, and in response to the registration requests sent by the N key component management network elements, storing the address information of the N key component management network elements as N ciphertext storage addresses; or, using the serial numbers of the ciphertexts of the N key components as the N ciphertext storage addresses, and storing the serial numbers of the ciphertexts of the N key components in correspondence with the address information of the N key component management network elements.
[0009] Based on this possible design, the key management network element can obtain the ciphertext with key components generated by the key component management network element through the existing registration process, thereby reducing signaling overhead; at the same time, the key management network element can store the address information of the key component management network element as the ciphertext storage address, or number the ciphertext of the key component and store the serial number of the ciphertext of the key component as the storage address, thereby increasing storage flexibility and storage pressure.
[0010] In one possible design, the address information of each key component management network element is included in the registration request sent by the key component management network element. Based on this possible design, the address information of the key component management network element can be explicitly indicated to the key management network element through the existing registration process, reducing signaling overhead.
[0011] In a possible design, the address information of the key component management network element includes any one of the address information of the key component management network element ID, the key component management network element uniform resource locator (URL), and the key component management network element file transfer protocol (FTP). Based on this possible design, the key component management network element ID or URL or FTP can be used as the address information of the key component management network element to support different transmission protocols, thereby improving the application scenarios and design flexibility of the solution.
[0012] In one possible design, the method also includes: storing the correspondence between M ciphertext storage addresses and the ID of the first key, so that the subsequent key management network element can obtain / trace the key component used to generate the first key according to the correspondence, thereby avoiding the risk of key component leakage caused by directly storing the key component. At the same time, it is easy to find the key component used to generate the first key, thereby improving the efficiency of key component search.
[0013] In one possible design, the method further includes: determining to update the first key; selecting K ciphertext storage addresses from N ciphertext storage addresses, obtaining corresponding ciphertexts of K key components different from the ciphertexts of M key components according to the K ciphertext storage addresses, using the private key of the key management network element to decrypt the ciphertexts of the K key components respectively to obtain the plaintexts of the K key components, generating a second key based on the plaintexts of the K key components, and using the second key to update the first ciphertext, the first ciphertext is the ciphertext obtained by performing an encryption operation on the first plaintext according to the first key and the ID of the first key, and the first ciphertext includes the ID of the first key. Based on this possible design, the new K key components can be used to update the first key to obtain the updated second key, and the updated second key can be used to update the original ciphertext encrypted by the first key, so as to ensure that the key and the ciphertext encrypted by the key are updated synchronously, thereby improving the accuracy of subsequent decryption of the ciphertext using the key and other key operations.
[0014] In a possible design, the ciphertext of K key components is different from the ciphertext of M key components, including: K is different from M; or, K is the same as or different from M, and the ciphertext storage address of the ciphertext of K key components is completely different from the ciphertext storage address of the ciphertext of M key components; or, K is the same as or different from M, and the ciphertext storage address of the ciphertext of K key components is partially or completely the same as the ciphertext storage address of the ciphertext of M key components, and the ciphertexts of the key components corresponding to the same ciphertext storage address are different. Based on this possible design, different numbers of key components can be used to update the first key, or the updated key components can be used to update the first key, and the update method is flexible and diverse.
[0015] In a possible design, updating the first ciphertext using the second key includes: determining M ciphertext storage addresses according to the ID of the first key included in the first ciphertext and the correspondence between the M ciphertext storage addresses and the ID of the first key, obtaining the corresponding M key component ciphertexts according to the M ciphertext storage addresses, decrypting the ciphertexts of the M key components respectively using the private key of the key management network element to obtain the plaintexts of the M key components, generating the first key based on the plaintexts of the M key components, performing a decryption operation on the first ciphertext using the first key to obtain the first plaintext, and performing an encryption operation on the first plaintext using the second key and the ID of the second key to obtain the second ciphertext. Based on this possible design, each time an operation such as decryption / encryption is performed, the ciphertext storage address is determined based on the correspondence between the M ciphertext storage addresses and the ID of the first key, the key component is obtained from the key component management network element according to the ciphertext storage address, and the decryption / encryption operation is performed according to the obtained key component, and the key component for generating the key does not need to be directly stored in the key management network element, thereby ensuring the security of the key component storage.
[0016] In a possible design, the method further includes: when all first ciphertexts are updated, updating the correspondence between the M ciphertext storage addresses and the ID of the first key to the correspondence between the K ciphertext storage addresses and the ID of the second key, and the ID of the first key is the same as or different from the ID of the second key. Based on this possible design, after the key is updated with the new key component, the correspondence between the key storage address and the key ID can be updated in time, so that the new key component can be found according to the new correspondence, and the key management operation can be accurately performed.
[0017] In a possible design, determining to update the first key includes: if a preset update period arrives, then determining to update the first key; or if any key component of the M key components is updated, then determining to update the first key; or if a request to update the ciphertext encrypted by the first key is received, then determining to update the first key. Based on this possible design, the key can be updated in a timely manner under different trigger conditions, ensuring the continuous security of the key and the ciphertext encrypted by the key in the business system, and reducing the risk of key and ciphertext leakage.
[0018] In one possible design, generating a first key based on plaintexts of the M key components includes: using any of the following algorithms to calculate the plaintexts of the M key components to obtain the first key: a password-based key derivation function (PBKDF) 2, a secure hash algorithm (SHA) 256, a hash-based message authentication code (HMAC) algorithm. Based on this possible design, the first key can be calculated based on any of a plurality of algorithms, thereby improving the flexibility of system design.
[0019] In a possible design, the key management network element includes a platform network element; the key component management network element includes one or more network elements of a front-end user operation network element, a back-end management operation network element, a document service network element, a log service network element, a scheduled task service network element, and a notification service network element. Based on this possible design, different types of key component management network elements can be used to generate and disperse key components to ensure the security of key storage.
[0020] In one possible design, the key operation includes any one of encryption, decryption, key update, and ciphertext update. Based on this possible design, the method described in the first aspect can be applied to application scenarios such as encryption, decryption, key update, and ciphertext update, thereby improving the adaptability and design flexibility of the method.
[0021] In a second aspect, the present application provides a device, which may be a key management network element or a chip or system on chip in a key management network element, or a module or unit in a key management network element for implementing the key management method described in an embodiment of the present application, or other modules or units capable of implementing the method executed by the key management network element. The device may implement the functions performed by the key management network element in the above-mentioned first aspect or each possible design. In one design, the device may include a module unit or means corresponding to the method / operation / step / action described in the first aspect, and the module, unit, or means may be implemented by hardware, software, or by hardware executing the corresponding software implementation. The hardware or software includes one or more modules or units corresponding to the above-mentioned functions. For example, the device may include: a processing unit;
[0022] The processing unit is configured to select M ciphertext storage addresses from N ciphertext storage addresses in response to a key operation request, wherein each ciphertext storage address is used to obtain a ciphertext of a key component from a key component management network element, and each ciphertext of the key component is obtained by encrypting the plaintext of the corresponding key component with the public key of the key management network element, and M is an integer greater than 2 and less than or equal to N. The processing unit is further configured to obtain the corresponding ciphertexts of the M key components according to the M ciphertext storage addresses, decrypt the ciphertexts of the M key components respectively using the private key of the key management network element to obtain the plaintexts of the M key components, generate a first key based on the plaintexts of the M key components, and perform the corresponding key operation using the first key and the ID of the first key.
[0023] The specific implementation of the device can refer to the behavior function of the terminal in the data transmission method provided by the first aspect or any possible design of the first aspect, and will not be repeated here. Therefore, the device provided by the second aspect can achieve the same beneficial effect as the first aspect or any possible design of the first aspect.
[0024] In a third aspect, a device is provided, which may be a key management network element or a chip or system on chip in a key management network element, or other modules or units capable of implementing a key management network element side method. The device may implement the functions performed by the key management network element in the first aspect or each possible design, and the functions may be implemented by hardware. In one possible design, the device may include: a processor and a communication interface, the processor being used to respond to a key operation request, select M ciphertext storage addresses from N ciphertext storage addresses, obtain the corresponding ciphertexts of M key components according to the M ciphertext storage addresses, use the private key of the key management network element to decrypt the ciphertexts of the M key components respectively, obtain the plaintexts of the M key components, generate a first key based on the plaintexts of the M key components, and use the first key and the ID of the first key to perform the corresponding key operation. In another possible design, the device may also include a memory, the memory being used to store computer instructions and / or data. When the device is running, the processor executes the computer instructions stored in the memory, so that the device performs the key management method described in the first aspect or any possible design of the first aspect. In the embodiment of the present application, the communication interface may be a transceiver, an interface circuit, a bus interface, a pin or other device capable of realizing the transceiver function.
[0025] In a fourth aspect, a computer-readable storage medium is provided, which stores instructions, and when the computer-readable storage medium is run on a computer, the computer can execute the key management method described in the first aspect or any possible design of the above aspects.
[0026] In a fifth aspect, a computer program product comprising instructions is provided. The computer program product may include program instructions. When the computer program product runs on a computer, the computer can execute the key management method described in the first aspect or any possible design of the above aspects.
[0027] In a sixth aspect, a chip system is provided, the chip system includes a processor and a communication interface, and the chip system can be used to implement the functions performed by the key management network element in the above-mentioned first aspect or any possible design of the first aspect. For example, the processor is used to respond to a key operation request, select M ciphertext storage addresses from N ciphertext storage addresses, obtain the corresponding M key component ciphertexts according to the M ciphertext storage addresses, use the private key of the key management network element to decrypt the ciphertexts of the M key components respectively, obtain the plaintexts of the M key components, generate a first key based on the plaintexts of the M key components, and use the first key and the ID of the first key to perform the corresponding key operation. In a possible design, the chip system also includes a memory, the memory is used to store program instructions and / or data, and when the chip system is running, the processor executes the program instructions stored in the memory, so that the chip system executes the key management method described in the above-mentioned first aspect or any possible design of the first aspect. The chip system can be composed of a chip, or it can include a chip and other discrete devices, without limitation.
[0028] In a seventh aspect, an embodiment of the present application further provides a service system, which includes the device as described in the second aspect or the third aspect and a key component management network element. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 This is a schematic diagram of the key hierarchical management structure;
[0030] Figure 2 A schematic diagram of the architecture of a business system provided in an embodiment of the present application;
[0031] Figure 3 A schematic diagram of the architecture of a business system provided in an embodiment of the present application;
[0032] Figure 4 A flowchart of a key management method provided in an embodiment of the present application;
[0033] Figure 5 A flowchart of another key management method provided in an embodiment of the present application;
[0034] Figure 6 A flowchart of another key management network element provided in an embodiment of the present application;
[0035] Figure 7 A schematic diagram of the composition of a device 70 provided in an embodiment of the present application;
[0036] Figure 8 A schematic diagram of the composition of a device 80 provided in an embodiment of the present application. DETAILED DESCRIPTION
[0037] In the business system, in order to ensure that the key is not leaked, a hierarchical protection method is used to manage the key securely. Figure 1 This is a schematic diagram of the key hierarchical management structure, such as Figure 1 As shown in the figure, the key is divided into three layers: the first layer is the root key, also known as the master key, the second layer is the key encryption key (KEK), and the third layer is the work key (WK). The downstream keys provide encryption protection for the upper layer keys, such as the root key provides encryption protection for the KEK, and the KEK provides encryption protection for the WK. The root key, KEK, and WK are introduced below:
[0038] Among them, WK can provide confidentiality and integrity protection for sensitive data stored locally and data that needs to be transmitted over insecure channels, and can also provide cryptographic services such as authentication and signature. WK is directly used by upper-layer applications. WK can include keys used for storage encryption, pre-shared keys, message authentication code (MAC) keys, signature private keys, etc. Figure 1 As shown, WK may include authentication working keys, storage working keys, signature working keys, and transmission working keys. Different working keys can encrypt different types of business data, and different working keys can correspond to different encryption scenarios. In order to distinguish the encryption scenarios corresponding to the working keys, a key feature code is set corresponding to each encryption scenario, and the encryption scenario corresponding to the working key is identified by the key feature code. The authentication working keys may include password encryption storage keys, personal identification number (PIN) encryption storage keys, and machine-machine interface authentication encryption keys. The storage working keys may include user sensitive data encryption storage keys and configuration data encryption storage keys. The signature working keys may include transaction data signature storage keys and MAC keys. The transmission working keys may include data encryption transmission keys.
[0039] Among them, KEK can provide confidentiality protection for the working key. The ciphertext of the working key encrypted with KEK is stored in the business system, and KEK itself is protected by the root key. For simpler cryptographic application systems with low security requirements, the function of KEK can be directly performed by the root key. Figure 1As shown, KEK can include authentication key encryption key, storage key encryption key, signature key encryption key, and transmission key encryption key. Different KEKs can encrypt different types of WKs. Different KEKs can correspond to different encryption scenarios. In order to distinguish the encryption scenarios corresponding to KEKs, a key feature code is set for each encryption scenario corresponding to KEK. The key feature codes corresponding to different encryption scenarios are different. The encryption scenarios corresponding to KEKs are identified by key feature codes. The authentication key encryption key can provide confidentiality protection for authentication working keys, the storage key encryption key can provide confidentiality protection for storage working keys, the signature key encryption key can provide confidentiality protection for signature working keys, and the transmission key encryption key can provide confidentiality protection for transmission working keys.
[0040] The root key is located at the bottom of the key management hierarchy. The root key can provide confidentiality protection for upper-level keys (such as key encryption keys or working keys). The ciphertext of the key encryption key encrypted with the root key is stored in the business system. Figure 1 As can be seen from the architecture shown, the key at the bottom (such as the root key) has no other keys to provide confidentiality protection for it, and its security is relatively low.
[0041] In order to protect the security of the root key, in the actual application of the business system, the root key is synthesized based on several fixed key components. For example, the key management network element and the terminal device each generate a key component, which is distributed to the virtual encryption machine through the quantum key distribution device. The virtual encryption machine itself also generates a key component. The virtual encryption machine synthesizes the three key components generated by itself, the key management network element, and the terminal device to obtain the root key. The root key is used to encrypt and protect KEK, and the KEK is used to encrypt and protect WK. However, in this way of synthesizing the root key, there are only three key components, which are relatively few, and the probability of being obtained by malicious attackers is high, and the security of the root key is not high; at the same time, it is necessary to add professional hardware equipment such as quantum key distribution equipment and virtual encryption machines to ensure the security of the key components, and the hardware resource requirements are large.
[0042] To solve the above problems, an embodiment of the present application provides a key management method: a key component management network element (such as a service network element) in a service system generates and stores the ciphertext of the key component, and informs the key management network element through a registration process that the key component management network element generates the ciphertext with the key component. The key management network element itself does not save the key component, but records the ciphertext storage address corresponding to the ciphertext of the key component. Subsequently, when a key operation request is received, M ciphertext storage addresses are selected from the recorded ciphertext storage addresses, and the ciphertexts of the M key components are obtained from the key component management network element according to the M ciphertext storage addresses, and then the ciphertexts of the M key components are decrypted according to the private key of the key management network element to obtain the plaintexts of the M key components, and a first key is generated according to the plaintexts of the M key components, and the corresponding key operation is performed using the first key. In this way, a key component can be generated by each key component management network element in the service system. The number of key components is large, and it is difficult to obtain all key components. At the same time, the key management network element itself does not store key components, but only records the ciphertext storage address, synthesizes the key based on the randomly selected key components, and takes advantage of the large-scale cluster system's anti-attack advantages to ensure the security of key component storage. In addition, professional hardware equipment such as quantum key distribution equipment and encryption machines are not required to ensure the security of key component storage, which reduces the demand for hardware resources while ensuring the security of the root key.
[0043] The key management method provided in the embodiment of the present application is described below in conjunction with the drawings in the specification.
[0044] The key management method provided in the embodiment of the present application can be applied to Figure 2 The business system shown, such as Figure 2 As shown, the service system may include: a key management network element 101 and multiple key component management network elements 102. For example, the service system may include N key component management network elements 102, where N is an integer greater than 2.
[0045] Among them, the key management network element 101 can provide key management, encryption / decryption key and other operations, is responsible for generating and regularly updating the root key, KEK and WK, and recording the ciphertext storage address corresponding to the ciphertext of the key component.
[0046] Specifically, the key management network element 101 is used to respond to a key operation request, select M ciphertext storage addresses from N ciphertext storage addresses, obtain the ciphertexts of the corresponding M key components according to the M ciphertext storage addresses, use the private key of the key management network element 101 to decrypt the ciphertexts of the M key components respectively to obtain the plaintexts of the M key components, generate a first key based on the plaintexts of the M key components, and use the first key and the ID of the first key to perform corresponding key operations.
[0047] Among them, the key component management network element 102 can be used to generate plaintext of key components and encrypt and store plaintext of key components. For example, key component management can be used to generate plaintext of key components, and use the public key of the key management network element 101 to encrypt the plaintext of key components to obtain the ciphertext of key components.
[0048] Furthermore, the key management network element 101 can also be used to record / store the correspondence between the ID of the first key and the M ciphertext storage addresses, so that the key component used to generate the first key can be traced back according to the correspondence, the first key can be generated again according to the traced back key component, and the encryption or decryption operation can be performed using the first key.
[0049] Furthermore, the key management network element 101 can also be used to select K ciphertext storage addresses from N ciphertext storage addresses, obtain K key components different from the M key components according to the K ciphertext storage addresses, and update the first key according to the K key components to obtain the second key.
[0050] It should be noted that Figure 2 This is only an exemplary architecture diagram. Figure 2 In addition to the functional units shown in , the system may also include other functional network elements, such as: a database, etc., which is not limited in the embodiments of the present application. Figure 2 The names of the devices in the Figure 2 In addition to the names shown, each device can also be named with other names, such as replaced with network element names with the same or similar functions, without limitation.
[0051] Optionally, the key management network element and key component management network element in the embodiment of the present application may also be referred to as a key management device, which may be a desktop computer, a portable computer, a network server, a mobile phone, a tablet computer, a wireless terminal, an embedded device, a chip system, etc., which is not specifically limited in the embodiment of the present application. In the embodiment of the present application, the chip system may be composed of a chip, or may include a chip and other discrete devices.
[0052] Optionally, the related functions of the key management network element and the key component management network element in the embodiment of the present application can be implemented by one device, or by multiple devices together, or by one or more functional modules in one device, and the embodiment of the present application does not specifically limit this. It can be understood that the above functions can be network elements in hardware devices, or software functions running on dedicated hardware, or a combination of hardware and software, or virtualized functions instantiated on a platform (such as a cloud platform).
[0053] For example, the key management network element and the key component management network element are implemented by one or more functional modules in a device, such as Figure 3 As shown, the key management network element and the key component management network element can be deployed on an application (APP) of a device, and the related functions of the key management network element and the key component management network element can be virtualized functions instantiated on the APP platform. Figure 3 The business system shown may also include a database, which may include multiple database management network elements, such as N MySQLs.
[0054] exist Figure 3 In the business system shown, the key management network element can be called a platform network element, and the key component management network element can be called a business network element. For example, the key component management network element can be any one or more of the frontend operation (frontend portal) network element, backend operation (backend portal) network element, document service (document service) network element, log service (logservice) network element, scheduled task service (task job service) network element, and notification service (notificationservice) network element on the APP. Among them, the frontend operation network element can be used to provide frontend services to users, and provide Web site pages for users to directly operate. The backend operation network element can be used to provide administrators with management Web site pages. The document service network element can be a network element that provides document services, realizing functions such as document storage and export. The log service network element can be a network element that provides log services, realizing functions such as audit log collection. The scheduled task service network element can be a network element that provides scheduled task services, which is used to perform certain operations in the background at a fixed time. The notification service network element can be a network element that provides notification services, such as being responsible for sending text messages to users.
[0055] Combine the following Figure 2 The business system shown is Figure 2 Taking the service system shown as including N key component management network elements as an example, the key management method provided in the embodiment of the present application is described. It should be noted that the actions, terms, etc. involved in the various embodiments of the present application can refer to each other. The message name or parameter name in the message exchanged between the various network elements in the embodiment of the present application is only an example, and other names can also be used in the specific implementation. For example, "generate" in the embodiment of the present application can also be understood as "synthesize", "include" in the embodiment of the present application can also be understood as "carry", etc., "store" in the embodiment of the present application can also be understood as "record" or "save", etc., which are uniformly explained here, and the embodiment of the present application does not make specific limitations on this.
[0056] Figure 4 A flowchart of a key management method provided in an embodiment of the present application is shown in FIG. Figure 4As shown, this may include:
[0057] Step 401: Each of the N key component management network elements generates a ciphertext of a key component.
[0058] Wherein, N is an integer greater than 2, N can be pre-configured as needed, and N key component management network elements can be Figure 2 Any N key component management network elements in. In order to increase the security of the ciphertext of the key component, the more key component management network elements that execute step 401, the more dispersed the network elements that generate the ciphertext of the key component, the more difficult it is to obtain the key component for generating the first key, and the higher the security of the ciphertext of the key component. In the present application, N key component management network elements have the function of generating the ciphertext of the key component, and the execution of step 401 is used as an example for explanation. A key component management network element can generate the ciphertext of one key component, or it can generate the ciphertext of two or more key components. The ciphertexts of key components generated by different key component management network elements can be the same or different, without limitation. The embodiment of the present application is explained by taking the example of a key component management network element generating the ciphertext of one key component.
[0059] Exemplarily, the key component management network element may generate the ciphertext of the key component in the following manner: the key component management network element generates the plaintext of the key component, and uses the public key of the key management network element to encrypt the plaintext of the key component to obtain the ciphertext of the key component. For example, the key component management network element may input the public key of the key management network element and the plaintext of the key component as input parameters into a hash algorithm to obtain the ciphertext of the key component. Among them, the hash algorithm may include a secure hash algorithm (SHA) 256 or a hash-based message authentication code (HMAC) algorithm, etc., without limitation.
[0060] Among them, the plaintext of the key component can be used to generate a first key, such as a root key. The plaintext of the key component can be a 32-bit hexadecimal number. The longer the length of the plaintext of the key component, the more secure the first key generated using the plaintext of the key component. The key component management network element can use a secure random algorithm or a key derivation algorithm to generate the plaintext of the key component. Specifically, the process of the key component management network element generating the plaintext of the key component can refer to the existing technology and will not be repeated here.
[0061] Among them, the public key of the key management network element corresponds to the private key of the key management network element. The public key of the key management network element and the private key of the key management network element are a key pair obtained through an encryption algorithm. The public key of the key management network element is the public part of the key pair, and the private key of the key management network element is the non-public part, which is a key known only to the key management network element. The public key of the key management network element is usually used to encrypt session keys, verify digital signatures, or encrypt data that can be decrypted with the corresponding private key of the key management network element. The key pair obtained by the encryption algorithm can be guaranteed to be unique worldwide. When using this key pair, if one of the keys is used to encrypt a piece of data, the other key must be used to decrypt it. For example, if the data is encrypted with the public key of the key management network element, it must be decrypted with the private key of the key management network element. If it is encrypted with the private key of the key management network element, it must also be decrypted with the public key of the key management network element, otherwise the decryption will not be successful.
[0062] Before executing step 401, the key management network element may generate a public key of the key management network element and a private key of the key management network element, and pre-configure the public key of the key management network element to the N key component management network elements. Alternatively, the key component management network element may send a request message to the key management network element to request the public key of the key management network element, and the key management network element sends the public key of the key management network element to the key component management network element in response to the request message sent by the key component management network element.
[0063] Further, after any key component management of the N key component management network elements generates the ciphertext of the key component, it sends a registration request to the key management network element, and the registration request can be used to indicate that the key component management network element stores / generates the ciphertext of the cryptographic component. It should be noted that, in addition to the registration request, the key component management network element can also notify the key management network element that the key component management network element stores / generates the ciphertext of the cryptographic component through other new messages or existing messages, without limitation.
[0064] The registration request may carry the address information of the key component management network element, or may not carry the address information of the key component management network element. When the registration request does not carry the address information of the key component management network element, the key component management network element may send the registration request to the key management network element through a transmission tunnel between the key component management network element and the key management network element, wherein the transmission tunnel corresponds to the key component management network element, and the key component management network element can be identified according to the identification information of the transmission tunnel.
[0065] In each embodiment of the present application, the address information of the key component management network element can be used to indicate / identify the key component management network element. The address information of the key component management network element can be any one of the address information of the ID of the key component management network element, the uniform resource locator (URL) of the key component management network element, the file transfer protocol (FTP) of the key component management network element, and the identification information of the transmission tunnel between the key component management network element and the key management network element. It can also be other identifiers that can identify the key component management network element. The ID of the key component management network element can be the number or index of the key component management network element in the service system. There is a corresponding relationship between the URL / FTP of the key component management network element and the ID of the key component management network element.
[0066] For example, assuming that there are four key component management network elements: key component management network element 1 to key component management network element 4, 001 to 004 can be used to identify the four key component management network elements, such as 001 identifies key component management network element 1, 002 identifies key component management network element 2, 003 identifies key management network element 3, and 004 identifies key component management network element 4; or, the following URLs are used: http: / / 192.168.1.1 / 1 / part1.cred, http: / / 192.168.1.1 / 2 / part2.cred, http: / / 192.168.1.1 / 3 / pa rt3.cred, http: / / 192.168.1.1 / 4 / part4.cred are used to identify key component management network elements 1 to 4, or the following FTP is used: ftp: / / 192.168.1.1 / 1 / part1.cred, ftp: / / 192.168.1.1 / 2 / part2.cred, ftp: / / 192.168.1.1 / 3 / part3.cred, ftp: / / 192.168.1.1 / 4 / part4.cred are used to identify key component management network elements 1 to 4.
[0067] Step 402: The key management network element records N ciphertext storage addresses.
[0068] Among them, the N ciphertext storage addresses correspond to N key component management network elements that generate the ciphertext of the key component, and each ciphertext storage address is used to obtain the ciphertext of a key component from a key component management network element.
[0069] In one example, the ciphertext storage address is the address information of the key component management network element. For example, assuming that there are four key component management network elements: key component management network element 1 to key component management network element 4, and the IDs of these four key component management network elements are 001, 002, 003, and 004, respectively, the key management network element can record 4 ciphertext storage addresses, and these 4 ciphertext storage addresses can be {001, 002, 003, 004}.
[0070] In another example, the ciphertext storage address may be the serial numbers of the ciphertexts of the N key components, and the serial numbers of the ciphertexts of the N key components and the address information of the N key component management network elements may be stored in correspondence. For example, the serial numbers of the ciphertexts of the N key components and the address information of the N key component management network elements may be stored in correspondence in the form of a list or an array. For example, suppose there are four key component management network elements: key component management network element 1 to key component management network element 4, the IDs of these four key component management network elements are 001, 002, 003, and 004 respectively, and the serial numbers of the ciphertexts of the key components generated by key component management network element 1 to key component management network element 4 are 1, 2, 3, and 4 respectively. Then the key management network element can record the correspondence between the serial numbers: 1, 2, 3, and 4 and the IDs of the key component management network elements: 001, 002, 003, and 004 in the following Table 1, or it can be recorded in the form of an array: {serial number 1, 001}, {serial number 2, 002}, {serial number 3, 003}, {serial number 4, 004}.
[0071] Table 1
[0072] Serial number ID of the key component management network element 1 001 2 002 3 003 4 004
[0073] It should be noted that in the present application, the serial numbers of the ciphertexts of the N key components can be sequentially numbered from small to large or from large to small, or can be random numbers, without limitation. The serial numbers of the ciphertexts of different key components are different.
[0074] In one example, the address information of the key component management network element is carried in a registration request. The key management network element can receive registration requests sent by N key component management network elements, and in response to the registration requests sent by the N key component management network elements, obtain the address information of the key component management network element from the registration request, and store / record the address information of the N key component management network elements as N ciphertext storage addresses; or, number the ciphertexts of the N key components, use the serial numbers of the ciphertexts of the key components as the N ciphertext storage addresses, and store / record the serial numbers of the ciphertexts of the N key components and the address information of the N key component management network elements in correspondence.
[0075] In another example, the address information of the key component management network element is not carried in the registration request. The key management network element can receive the registration requests sent by N key component management network elements through the transmission tunnel between it and the N key component management network elements, and in response to the registration requests sent by the N key component management network elements, store / record the identification information of the N transmission tunnels as N ciphertext storage addresses; or, number the ciphertexts of the N key components, use the serial numbers of the ciphertexts of the key components as the N ciphertext storage addresses, and store / record the serial numbers of the ciphertexts of the N key components and the identification information of the N transmission tunnels in correspondence.
[0076] Step 403: The key management network element selects M ciphertext storage addresses from the N ciphertext storage addresses in response to the key operation request.
[0077] Wherein, M can be an integer greater than 2 and less than or equal to N. The specific value of M can be pre-set to the key management network element. For example, before the key management network element is run, the administrator configures the value of M to the key management network element through a graphical interface or a configuration file. After the configuration is completed, the value of M will be stored in the database or the key management network element for use by the key management network element during operation. It should be noted that the value of M can be adjusted dynamically, such as periodically updating the value of M.
[0078] Among them, the key operation request can be used to request the key management network element to perform the corresponding key operation. The key operation can include any operation such as encryption, decryption, key update, ciphertext update, etc. The key operation request can include any request such as encryption request, ciphertext update request, key update request, ciphertext update request, etc. The encryption request can be used to request to encrypt the original text of the business data, the ciphertext update request can be used to request to decrypt the ciphertext of the business data, the key update request can be used to request to update the key used to encrypt the plaintext of the business data, and the ciphertext update request can be used to request to update the ciphertext, etc. Business data can refer to data that needs to be encrypted and stored, and can include user keys, transaction data, user sensitive data, etc. For example, a user uses the foreground service to reset the user key. After the user enters the old key and the new key, the foreground user operation network element can send an update ciphertext request carrying the ciphertext of the old key to the key management network element, requesting the key management network element to decrypt and obtain the original text of the old key. If the original text of the old key is consistent with the user input, the foreground user operation network element can send an encryption request carrying the original text of the new key to the key management network element, requesting the key management network element to encrypt and obtain the ciphertext of the new key and store it.
[0079] Among them, the key management network element selects M ciphertext storage addresses from N ciphertext storage addresses in response to the key operation request, which may refer to the key operation request as a trigger condition. After the key management network element receives the key operation request, the key management network element is triggered to randomly select M ciphertext storage addresses from the N ciphertext storage addresses, or sequentially select M ciphertext storage addresses, etc. For example, taking M as 3 as an example, after the key management network element receives the key operation request, it may select 3 ciphertext storage addresses from the above Table 1 in response to the key operation request: sequence number 1, sequence number 2, and sequence number 3.
[0080] Step 404: the key management network element obtains the corresponding M key component ciphertexts according to the M ciphertext storage addresses, and uses the private key of the key management network element to decrypt the ciphertexts of the M key components respectively to obtain the plaintexts of the M key components.
[0081] Exemplarily, the key management network element can obtain address information of M key component management network elements based on M ciphertext storage addresses, and send acquisition requests to the M key component management network elements based on the address information of the M key component management network elements, requesting to obtain the ciphertext of the key component. After receiving the acquisition request, each of the M key component management network elements sends the ciphertext of the key component to the key management network element, and the key management network element receives the ciphertext of the M key components returned by the M key component management network elements.
[0082] Among them, the key management network element obtains the address information of M key component management network elements according to M ciphertext storage addresses, which may include: the ciphertext storage address is the address information of the key component management network element, and the key management network element directly uses the selected M ciphertext storage addresses as the address information of the M key component management network elements; or, the ciphertext storage address is the serial number of the ciphertext of the key component, and the key management network element uses the M address information corresponding to the selected M serial numbers as the address information of the M key component management network elements.
[0083] Among them, the private key of the key management network element is as described in step 401, and the key management network element uses the private key of the key management network element to decrypt the ciphertext of the key component to obtain the plaintext of the key component, which may include: the key component management network element can input the private key of the key management network element and the ciphertext of the key component as input parameters into the hash algorithm (such as SHA256 or HMAC algorithm) to obtain the plaintext of the key component.
[0084] Step 405: The key management network element generates a first key based on the plain texts of the M key components, and uses the first key and the ID of the first key to perform corresponding key operations.
[0085] The first key may be the root key. The ID of the first key may uniquely identify the first key, and the ID of the first key may be configured by a key management network element. For example, the ID of the first key may be 1001.
[0086] Exemplarily, the key management network element may use any of the following algorithms to calculate the plaintext of the M key components to obtain the first key: PBKDF2, SHA256, HMAC algorithm. Taking the HMAC algorithm as an example, the key management network element may input the plaintext of the M key components as input parameters into the HMAC algorithm to obtain the first key.
[0087] Exemplarily, the key management network element uses the first key and the ID of the first key to perform corresponding key operations, which may include: the key management network element generates a secure random number of a fixed length, concatenates the secure random number with the ID of the first key to obtain an initialization vector (IV), and performs corresponding key operations according to the initialization vector and the first key. If the key operation is encryption, the first original text is encrypted according to the initialization vector and the first key to obtain the first ciphertext. If the key operation is decryption, the first ciphertext is decrypted according to the initialization vector and the first key to obtain the first original text. If the key operation is to update the key or update the ciphertext, the first key is updated to obtain the second key, the first ciphertext is first decrypted according to the initialization vector and the first key to obtain the first original text, and then a new IV is generated according to the ID of the second key, and the first original text is encrypted according to the new IV and the second key to obtain the second ciphertext.
[0088] In this application, the length of the secure random number can be preconfigured. Concatenating the secure random number with the ID of the first key can include: arranging the ID of the first key after the secure random number. For example, assuming that the secure random number is 234653465534542 and the ID of the first key is 1001, the initial vector obtained by concatenating the secure random number with the ID of the first key can be: 2346534655345421001.
[0089] The first original text described in the present application may be the original text of the KEK, or the original text of the WK or the original text of the business data, etc. The first ciphertext may be the ciphertext of the KEK, or the ciphertext of the WK or the ciphertext of the business data, and the ciphertext encrypted by the first ciphertext may include the ID of the first key. The relevant descriptions of the KEK, WK and business data may refer to the above and will not be repeated here.
[0090] based on Figure 4The method shown can store the ciphertext of the key component in a distributed manner on the key component management network element, and trigger the key management network element to save the ciphertext storage address corresponding to the ciphertext storing the key component on the key management network element, so that after receiving the key operation request, the key management network element selects the ciphertext storage address from the existing ciphertext storage address, obtains the ciphertext of M key components according to the selected key storage address, decrypts the ciphertext of the M key components to obtain the plaintext of the M key components, generates a first key based on the plaintext of the M key components, and uses the first key to perform the corresponding key operation. Since there are many key component management network elements, and the key components are distributed in a large number of key component management network elements in the form of ciphertext, it is difficult for an attacker to obtain the key components from a large number of key component management network elements, thereby ensuring the security of the key component storage, and then ensuring the security of the first key generated by the key component. At the same time, there is no need for professional hardware equipment such as quantum key distribution equipment and encryption machines to ensure the storage security of key components, reducing hardware resource requirements.
[0091] Furthermore, Figure 4 In the method shown, in order to facilitate the key management network element to trace back to the first key, the corresponding key operation is performed according to the first key. Figure 4 The method shown may also include: the key management network element stores the correspondence between M ciphertext storage addresses and the ID of the first key, so that the key management network element finds the M ciphertext storage addresses corresponding to the M key components used to generate the first key according to the correspondence, generates the first key according to the M ciphertext storage addresses, and performs encryption / decryption operations according to the first key.
[0092] Exemplarily, the correspondence between M ciphertext storage addresses stored by the key management network element and the ID of the first key may include: the key management network element records the M ciphertext storage addresses in a file / array, which corresponds to the ID of the first key; or, in a case where there is only one first key, the key management network element marks the M ciphertext storage addresses selected from the N ciphertext storage addresses, such as one ciphertext storage address among the M ciphertext storage addresses corresponds to a first flag bit, and the ciphertext storage address corresponding to the first flag bit can be used to obtain the key component used to generate the first key, and the M ciphertext storage addresses corresponding to the first flag bit correspond to the ID of the first key by default.
[0093] Correspondingly, the unselected ciphertext storage addresses among the N ciphertext storage addresses may also be marked, such as the unselected ciphertext storage addresses may correspond to the second flag bit, and the key component for generating the first key cannot be obtained using the ciphertext storage address corresponding to the second flag bit. Alternatively, the unselected ciphertext storage addresses among the N ciphertext storage addresses are not marked and are not restricted.
[0094] Among them, the first flag bit and the second flag bit can be binary bit numbers "0", "1" or binary bit numbers "1", "0", and can also be other symbols or numbers, such as: the string "true" can be used to indicate that the corresponding ciphertext storage address can be used to find the key component for generating the first key, and the string "false" can be used to indicate that the corresponding ciphertext storage address is not selected to obtain the key component. For example, as described in Table 2 below, there are 4 ciphertext storage addresses, among which the ciphertext storage addresses corresponding to sequence numbers 1, 2, and 3 are selected and marked as "true", and the ciphertext storage address corresponding to sequence number 4 is not selected and marked as "false".
[0095] Table 2
[0096] Serial number ID of the key component management network element Flags 1 001 true 2 002 true 3 003 true 4 004 false
[0097] Furthermore, Figure 4 In the method shown, in order to ensure the continued validity and security of the key in the business system, it is necessary to regularly update the first key or update the first key according to user needs to ensure the timeliness of the first key, prevent the first key from being attacked, and ensure the security of the first key and the ciphertext encrypted by the first key. Specifically, the method may include:
[0098] The key management network element determines to update the first key, selects K ciphertext storage addresses from N ciphertext storage addresses; obtains the ciphertexts of the corresponding K key components according to the K ciphertext storage addresses, uses the private key of the key management network element to decrypt the ciphertexts of the K key components respectively, obtains the plaintexts of the K key components, and generates a second key based on the plaintexts of the K key components; uses the second key to update the first ciphertext.
[0099] Among them, the relevant description of the private key of the key management network element is as described in step 401. The key management network element obtains the corresponding ciphertexts of K key components according to K ciphertext storage addresses, and generates the second key based on the plaintext of the K key components. The process can refer to the above-mentioned key management network element obtaining the corresponding ciphertexts of N key components according to N ciphertext storage addresses, and generating the first key based on the plaintext of the N key components, and will not be repeated here.
[0100] Among them, K can be an integer greater than 2 and less than or equal to N, and the ciphertext of the K key components is different from the ciphertext of the M key components. For example, K is different from M, that is, the number of key components used to generate the first key is different from the number of key components used to generate the second key; or, K is the same as or different from M, and the ciphertext storage address of the ciphertext of the K key components is completely different from the ciphertext storage address of the ciphertext of the M key components; or, K is the same as or different from M, the ciphertext storage address of the ciphertext of the K key components is partially or completely the same as the ciphertext storage address of the ciphertext of the M key components, and the ciphertexts of the key components corresponding to the same ciphertext storage address are different.
[0101] Exemplarily, if any of the following conditions (1) to (3) is met, it is determined to update the first key:
[0102] Condition (1): The preset update period arrives.
[0103] The preset update period can be set as required without limitation. The preset update period can refer to a time period for updating the first key, and the first key is updated when the preset update period is reached.
[0104] Condition (2): a key component among the M key components used to generate the first key is updated, such as any key component among the M key components is updated.
[0105] For example, a key component management network element among the M key component management network elements corresponding to the M ciphertext storage addresses, such as the first key component management network element, generates a new key component, and encrypts the new key component using the public key of the key management network element to obtain the ciphertext of the new key component. The first key component management network element indicates information to the key management network element, and the indication information can be used to instruct the first key component management network element to generate the ciphertext of the new key component. The key management network element receives the indication information, learns that the original key component for generating the first key has changed, and determines to update the first key.
[0106] Condition (3): the key management network element receives a request to update the ciphertext encrypted by the first key, such as receiving a request to update the first ciphertext. The first ciphertext may refer to a type of ciphertext encrypted by the first key.
[0107] For example, assuming that the first ciphertext is the ciphertext of the customer's ID card information, when the business network element that manages the customer's ID card information needs to re-encrypt the customer's ID card information, the business network element can send an update request to the key management network element, requesting to update the ciphertext of the customer's ID card information. The key management network element receives the update request, determines to update the first key, and uses the new key to encrypt the customer's ID card information.
[0108] Exemplarily, the key management network element using the second key to update the first ciphertext may include: determining M ciphertext storage addresses based on the ID of the first key included in the first ciphertext and the correspondence between the M ciphertext storage addresses and the ID of the first key, obtaining the ciphertexts of the corresponding M key components based on the M ciphertext storage addresses, using the private key of the key management network element to decrypt the ciphertexts of the M key components respectively to obtain the plaintexts of the M key components, generating a first key based on the plaintexts of the M key components, using the first key to perform a decryption operation on the first ciphertext to obtain the first plaintext; using the second key and the ID of the second key to perform an encryption operation on the first plaintext to obtain the second ciphertext.
[0109] Among them, the ID of the second key can be allocated by the key management network element itself, and the ID of the second key can be the same as or different from the ID of the first key without restriction.
[0110] Furthermore, in order to facilitate the key management network element to trace back the second key and perform corresponding key operations according to the second key, the key management network element may store the correspondence between K ciphertext storage addresses and the ID of the second key.
[0111] Among them, in order to distinguish whether K ciphertext storage addresses or M ciphertext storage addresses are specifically used to address the key component used to generate the key, the key management network element can set the state of the correspondence between the K ciphertext storage addresses and the ID of the second key to effective or available, and set the correspondence between the M ciphertext storage addresses and the ID of the first key to history or outdated. Subsequently, when the key management network element finds that the correspondence between the M ciphertext storage addresses and the ID of the first key is in the history state, the key management network element can use the first key to perform a decryption operation on other ciphertexts encrypted by the first key to obtain plaintext, and find the correspondence between the K ciphertext storage addresses with an effective state and the ID of the second key, further obtain the plaintext of the K key components according to the correspondence between the K ciphertext storage addresses and the ID of the first key, generate the second key based on the plaintext of the K key components, and use the second key to perform an encryption operation on the decrypted plaintext to achieve the purpose of updating the ciphertext.
[0112] Furthermore, Figure 4 In the method shown, in order to reduce the storage pressure, Figure 4 The method shown may also include: when all first ciphertexts are updated, updating the correspondence between the M ciphertext storage addresses and the ID of the first key to the correspondence between the K ciphertext storage addresses and the ID of the second key, or deleting the correspondence between the M ciphertext storage addresses and the ID of the first key, and only saving the correspondence between the K ciphertext storage addresses and the ID of the second key.
[0113] Combine the following Figure 3 The service system shown in the figure uses the first key as the first root key, and the key management network element management Figure 1 The three-layer key system shown in the figure has a key component management network element. Figure 3 Taking the service network element in as an example, the process of the key management network element generating the first root key using the key components, encrypting the original text of KEK using the first root key, encrypting the original text of WK using the original text of KEK, and encrypting the service data using the original text of WK is described:
[0114] Figure 5 A flowchart of a key management method provided in an embodiment of the present application is shown in FIG. Figure 5 As shown, it may include steps 501 to 516, wherein steps 501 to 503 correspond to Figure 4 In the method shown, the service network element generates a ciphertext of a key component, the key management network element learns that the service network element generates a ciphertext with a key component, records the ciphertext storage address, and selects M ciphertext storage addresses from the recorded ciphertext storage addresses in response to a key operation request. Step 505 corresponds to Figure 4 The method shown is a process of further acquiring plaintexts of M key components according to the selected M ciphertext storage addresses, and generating a first root key according to the plaintexts of the M ciphertext components.
[0115] Step 501: Figure 3 Each service network element generates a ciphertext of a key component, and each service network element sends a registration request to the key management network element respectively.
[0116] Exemplarily, the key management network element pre-configures the public key of the key management network element to each service network element, each service network element generates a key component, and uses the public key of the key management component to generate the ciphertext of the key component. The service network element sends a registration request carrying the address information of the service network element to the key management network element. During the registration process, the service network element does not directly provide the ciphertext of the key component to the key management network element, but instead notifies the key management network element that the service network element has generated / holds the ciphertext of the key component.
[0117] Step 502: The key management network element records the ciphertext storage address in response to the registration request sent by each service network element, such as recording the ciphertext storage address in a key component record table.
[0118] Specifically, the way in which the key management network element records the ciphertext storage address can refer to the description in step 402, which will not be described in detail.
[0119] Step 503: In response to the key operation request, the key management network element selects M ciphertext storage addresses from the recorded ciphertext storage addresses, and records the selected M ciphertext storage addresses.
[0120] The description of key operation request can be found in Figure 4 It has been described in the previous section and will not be elaborated here.
[0121] Exemplarily, the key management network element may randomly select M ciphertext storage addresses from the recorded ciphertext storage addresses, and record the selected M ciphertext storage addresses separately in a file, or, mark the corresponding M ciphertext storage addresses selected in the key component record table described in step 502 as true.
[0122] Step 504: The key management network element generates the original text of KEK and the original text of WK.
[0123] Exemplarily, the key management network element can generate multiple KEK originals and multiple WK originals based on secure random numbers through a key derivation algorithm, such as PBKDF2. Specifically, this method can refer to the prior art and will not be described in detail.
[0124] Among them, in this application, one KEK corresponds to one encryption scenario, and one WK corresponds to one encryption scenario. The key management network element can manage WK and KEK according to the encryption scenario. For example, the encryption of different types of business data is different encryption scenarios, and different WKs are used; the key management network element can divide WK into different categories, and use different KEKs to encrypt different categories of WKs as different encryption scenarios. The key management network element assigns a unique key feature code within the business system to identify the encryption scenario. The key management network element generates a KEK or WK for each encryption scenario, and assigns a unique key ID within the business system to each key.
[0125] For example, as shown in Table 3, different encryption scenarios correspond to different key feature codes. The encryption scenario corresponding to key feature code WK_10001 is password encryption storage, that is, the business system stores the ciphertext in the database after encrypting the user's password, and uses the WK corresponding to this key feature code; WK_10002 is used for the scenario where the business system signs key transaction data to prevent tampering, WK_10003 is used for the scenario where the business system signs MAC, and WK_10004 is used for the scenario where the business system encrypts and stores user sensitive data. In this way, different types of WKs are defined to encrypt business data in different encryption scenarios. Similarly, the key feature code KEK_10001 is used for scenarios where the business system encrypts signature-type WKs. In this case, the WK of the transaction data signature business of type WK_10002 can be encrypted and protected with the KEK_10001 type KEK. The key feature code KEK_10002 is used for scenarios where storage-type WKs are encrypted. In this way, different types of KEKs are used to encrypt WKs in different encryption scenarios.
[0126] Table 3
[0127] Key signature Key level Encryption scenario WK_10001 Working Key Password encrypted storage (storage class) WK_10002 Working Key Transaction data signature storage (signature class) WK_10003 Working Key MAC signature (signature class) WK_10004 Working Key Encrypted storage of user sensitive data (storage class) KEK_10001 Key Encryption Key Signature Class WK Encryption KEK_10002 Key Encryption Key Storage Class WK Encryption
[0128] Step 505: The key management network element obtains the ciphertexts of the M key components according to the M ciphertext storage addresses, uses the private key of the key management network element to decrypt the ciphertexts of the M key components respectively to obtain the ciphertexts of the M key components, and generates a first root key according to the plaintexts of the M key components.
[0129] Specifically, the process shown in step 505 can refer to Figure 4 It has been described in the previous section and will not be elaborated here.
[0130] Step 506: The key management network element uses the first root key to encrypt the original text of the KEK to obtain the ciphertext of the KEK.
[0131] Exemplarily, the key management network element may perform encryption calculation on the first root key and the original text of the KEK based on a hash algorithm to obtain the ciphertext of the KEK.
[0132] Furthermore, the key management network element may record relevant information of all KEKs, and relevant information of a KEK may include the key ID of the KEK, the key feature code corresponding to the KEK, the ciphertext of the KEK, the status: effective, and other related information. For example, the key management network element may record relevant information of the KEK with a key ID of 10001 and the KEK with a key ID of 10002 in the key record table shown in Table 4 below. The key ID of the KEK may be allocated by the key management network element, and different KEKs may correspond to different key IDs.
[0133] Table 4
[0134]
[0135] Step 507: The key management network element performs an encryption operation on the original text of WK according to the original text of KEK and the key ID of KEK to obtain the ciphertext of WK.
[0136] Exemplarily, the key management network element may generate a secure random number of a fixed length, concatenate the secure random number with the key ID of KEK as IV1, and encrypt the original text of WK according to IV1 and the original text of KEK to obtain the ciphertext of WK.
[0137] Among them, the ciphertext of WK includes IV1, that is, IV1 used to encrypt the original text of WK can be extracted from the ciphertext of WK.
[0138] For example, taking KEK_10002 as an example to encrypt WK_10004, the key management network element generates a secure random number "234653465534542", and concatenates the KEK's key ID with the secure random number to obtain IV1 "23465346553454210002". The KEK's key ID is "10002" and concatenated into IV1. After encrypting the original text of WK with IV1 and the original text of KEK, the ciphertext of WK is: "23465346553454210002HSHGHrete45HFDGDSFggygertGDSFtrewtjjKkjhKJKarawWQsdfgerGewrtJDwW".
[0139] Furthermore, the key management network element can record relevant information of all WKs. The relevant information of a WK may include the key ID of the WK, the key feature code corresponding to the WK, the ciphertext of the WK, the status: effective and other related information. For example, the key management network element can record the relevant information of the WK with a key ID of 10004 in the key record table, as shown in Table 5 below. Among them, the key ID of the WK can be assigned by the key management network element itself, and different WKs correspond to different key IDs. In addition, it should be noted that in the present application, the relevant information of the KEK and the relevant information of the WK can be recorded in the same key record table as shown in Table 5 below, or in different key record tables, without limitation.
[0140] Table 5
[0141]
[0142] As can be seen from the above, the ciphertext of WK with key ID 10004 in Table 5 above is composed of the secure random number, key ID of KEK, and IV1 of KEK in Table 6 below, where IV1 can be configured to be spliced on the left or right side of "the ciphertext obtained by encrypting the original text of WK", without restriction. In the embodiment of the present application, it is configured to be spliced on the left side.
[0143] Table 6
[0144]
[0145] The above steps 501 to 507 are the process of generating the first root key, the ciphertext of KEK, and the ciphertext of WK. Furthermore, the business data can be encrypted according to the original text of WK to obtain the ciphertext of the business data. The following example of encrypting the customer's identity document information will illustrate the business data encryption process:
[0146] Step 508: The service network element sends an encryption request to the key management network element, requesting encryption of service data.
[0147] The business data may be user sensitive data, such as customer identity document information. The encryption request may carry the original text of the business data and the key feature code corresponding to the encryption scenario when encrypting the business data.
[0148] For example, customer ID information belongs to user sensitive data. When storing customer ID information, the service network element needs to encrypt it before storing it. At the same time, the encrypted storage of ID information belongs to the sensitive data encryption storage scenario. The key feature code used for the encrypted ID information preset by the service network element is WK_10004. Therefore, when requesting to encrypt customer ID information, the service network element can carry the original text of the customer ID information (ID123456) and the corresponding key feature code WK_10004 in the encryption request and send it to the key management network element.
[0149] Step 509: The key management network element receives the encryption request, and determines, based on the key feature code carried in the encryption request, relevant records of WK corresponding to the key feature code with an effective status: the key ID of WK and the ciphertext of WK.
[0150] For example, the key management network element can obtain the key feature code WK_10004 from the encryption request, and use the key feature code WK_10004 as the index to query the key record table shown in Table 5 above, and find the relevant records of WK with the key feature code WK_10004 and the status effective from the key record table: the key ID of WK is 10004, and the ciphertext of WK is "23465346553454210002HSHGHrete45HFDGDSFggygertGDSFtrewtjjKkjhKJKarawWQsdfgerGewrtJDwW".
[0151] Step 510: The key management network element obtains IV1 according to the ciphertext of WK, and obtains the key ID of the KEK used to encrypt WK according to IV1.
[0152] Exemplarily, the key management network element can extract the IV1 used to encrypt the WK and the key ID of the KEK spliced in IV1 from the left or right side of the ciphertext of WK according to the splicing position configuration of IV according to the ciphertext of WK. For example, assuming that IV1 is "23465346553454210002", the key ID of the KEK used to encrypt the WK is "10002".
[0153] Step 511: The key management network element finds the relevant record of KEK from the key record table according to the key ID of KEK: the ciphertext of KEK.
[0154] Exemplarily, the key management network element may use the key ID of the KEK as an index, search the key record table shown in Table 5 to obtain the key record of the KEK with the key ID being 10002, and obtain the ciphertext of the KEK from the key record of the KEK.
[0155] Step 512: The key management network element obtains the ciphertexts of the M key components according to the recorded M ciphertext storage addresses, decrypts the ciphertexts of the M key components using the private key of the key management network element to obtain the plaintexts of the M key components, generates a first root key according to the plaintexts of the M key components, and obtains the original text of the KEK according to the first root key and the ciphertext of the KEK.
[0156] Step 513: The key management network element obtains the original text of WK according to the original text of KEK and the ciphertext of WK in step 509.
[0157] Step 514: The key management network element obtains IV2 according to the key ID of WK, and performs encryption operation on the original text of the service data according to IV2 and the original text of WK to obtain the ciphertext of the service data.
[0158] Exemplarily, the key management network element may use a secure random number generator to generate a 16-byte secure random number 534534563247899, and concatenate the secure random number with the key ID (10004) to obtain IV2: 53453456324789910004. Assume that the encryption algorithm for user sensitive data is pre-configured as the Advanced Encryption Standard (AES) 256 algorithm, and the original text of the customer identity document information is ID123456. The key management network element encrypts the customer identity document information and obtains the ciphertext: "HGASDGrwetarw23423hfdsGSDFHsdfsdSHAFSDTYhjgdSGDHGfg DFGETrfeJgRE"; after splicing IV2 with the ciphertext on the left end, the ciphertext of the business data is obtained: 53453456324789910004HGASDGrwetarw23423hfdsGSDFHsdfsdSHAFSDTYhjgdSGDHGfgDF GETrfeJgREt".
[0159] Step 515: The key management network element returns the ciphertext of the service data to the service network element.
[0160] Step 516: The service network element receives the ciphertext of the service data and saves the ciphertext of the service data.
[0161] Exemplarily, the service network element may store the ciphertext of the service data and the ID of the service data in correspondence with each other. The ID of the service data may be allocated by the service network element itself without restriction.
[0162] For example, if the business data is customer identity document information, the business network element may store the ciphertext of the customer identity document information and the customer ID in the data table shown in Table 7 below.
[0163] Table 7
[0164]
[0165] based on Figure 5 The method shown is that the service network element generates and maintains the ciphertext of the key component. The key management network element itself does not save the ciphertext of the key component, but only records the corresponding relationship between the ciphertext of the key component and the service network element. The ciphertext of the key component generated by some service network elements is randomly selected from the large-scale service network elements to synthesize the root key, and the ciphertext storage address of the ciphertext of the key component used by the root key is recorded for subsequent use in synthesizing the root key. With the advantage of the large-scale cluster system's anti-attack ability, the security of the key component storage is guaranteed. At the same time, no professional hardware equipment such as quantum key distribution equipment and encryption machines are required to ensure the security of key component storage, which reduces the hardware resource requirements and saves costs on the basis of ensuring the security of the root key.
[0166] Combine the following Figure 3 In the system shown, the first key is the first root key, the second key is the second root key, and the key management network element management Figure 1 The three-layer key system, the key component management network element is Figure 3 Taking the service network element in as an example, the process of root key, KEK update, WK update and ciphertext update of service data is described.
[0167] Figure 6 A flowchart of another key management method provided in an embodiment of the present application is as follows: Figure 6 As shown, it may include steps 601 to 613.
[0168] Step 601: The key management network element updates the first root key and obtains an updated second root key.
[0169] Exemplarily, the key management network element may update the first root key when any one of conditions (1) to (3) is met. Figure 4 The method described above will not be described in detail here.
[0170] Specifically, the key management network element may select K ciphertext storage addresses from the recorded ciphertext storage addresses, obtain the ciphertexts of K key components according to the K ciphertext storage addresses, use the private key of the key management network element to decrypt the ciphertexts of M key components respectively to obtain the ciphertexts of M key components, and generate the second root key according to the plaintexts of the M key components. A detailed description of this process can be found in Figure 4 The method described above will not be described in detail here.
[0171] Furthermore, the key management network element records the selected K ciphertext storage addresses.
[0172] Step 602: The key management network element obtains the original text of the first KEK whose ciphertext needs to be updated.
[0173] Among them, the original text of the first KEK can be Figure 5 The original text of part or all of the KEK generated in step 504 is shown. For example, the first KEK may be a KEK with a key feature code of KEK_10010.
[0174] Specifically, the key management network element may determine by itself which ciphertexts of the KEKs need to be updated, for example, it may determine to update the ciphertexts of the KEKs corresponding to certain encryption scenarios.
[0175] Step 603: The key management network element uses the second root key to encrypt the original text of the first KEK to obtain the ciphertext of the first KEK.
[0176] Further, the key management network element may record relevant information of the first KEK, and the relevant information of the first KEK may include the key ID of the first KEK, the key feature code of the first KEK, the ciphertext of the first KEK, the state: effective, and other related information. For example, the key management network element may assign a key ID: 10003 to the first KEK, and record the relevant information of the first KEK with the key ID of 10003 in the key record table shown in Table 8 below.
[0177] Further, the key management network element uses the key feature code of the first KEK as an index to search for a related record of a KEK corresponding to the key feature code of the first KEK in the key record table and whose status is effective, and changes the status in the related record to history, that is, marking the original ciphertext of the first KEK as outdated and old ciphertext. For example, as shown in Table 8 below, the status in the related record with the key ID of 10002 is changed to history.
[0178] Table 8
[0179]
[0180] Step 604: The key management network element determines the first WK whose ciphertext needs to be updated.
[0181] Among them, the original text of the first WK can be Figure 5 The original text of part or all of the WK generated in step 504 is shown. For example, the first WK may be a WK with a key feature code of WK_10004.
[0182] Specifically, the key management network element may determine by itself which ciphertexts of the WK need to be updated, for example, it may determine to update the ciphertexts of the WK corresponding to certain encryption scenarios.
[0183] Step 605: The key management network element uses the original text of the KEK and the key ID of the KEK to encrypt the original text of the first WK to obtain the ciphertext of the first WK.
[0184] Specifically, the key management network element uses the original text of the KEK and the key ID of the KEK to encrypt the original text of the first WK to obtain the ciphertext of the first WK. Figure 5 It has been described in the previous section and will not be elaborated here.
[0185] It should be noted that, if there are two related records of KEKs with the same key characteristic code in the key record table, the key management network element can encrypt the original text of the first WK with the key ID of the KEK corresponding to the effective status.
[0186] Further, the key management network element may record relevant information of the first WK, and the relevant information of the first WK may include the key ID of the first WK, the key feature code of the first WK, the ciphertext of the first WK, the state: effective, and other related information. For example, the key management network element may assign a key ID: 10005 to the first WK, and record the relevant information of the first WK with the key ID of 10005 in the key record table shown in Table 8 below.
[0187] Further, the key management network element uses the key feature code of the first WK as an index to search for a related record of the WK corresponding to the key feature code of the first WK in the key record table and whose status is effective, and changes the status in the related record to history, that is, marking the original ciphertext of the first WK as outdated and old ciphertext. For example, as shown in Table 9 below, the status in the related record with the key ID of 10004 is changed to history.
[0188] Table 9
[0189]
[0190] The above steps 601 to 605 are the process of updating the root key, updating the ciphertext of KEK, and updating the ciphertext of WK. Furthermore, the ciphertext of the business data can be updated by re-encrypting the business data according to the original text of WK after the ciphertext is updated. The following example of re-encrypting the customer's identity document information is used to illustrate the process of updating the ciphertext of business data:
[0191] Step 606: The service network element sends a ciphertext update request, requesting to update the ciphertext of the service data.
[0192] The business data may be user sensitive data, such as customer identity document information. The ciphertext update request may carry the ciphertext of the business data.
[0193] For example, customer identity document information is user sensitive data. When the service network element needs to display the plain text of the service data, the service gateway searches the database shown in Table 7 above according to the customer ID to obtain the ciphertext of the corresponding service data: 53453456324789910004HGASDGrwetarw23423hfdsGSDFHsdfsdSHAFSDTYhjgdSGDHGfgDFGETrfeJgREt, and carries the ciphertext of the service data in the ciphertext update request to the key management network element, requesting the key management network element to decrypt the ciphertext of the service data.
[0194] Step 607: The key management network element receives the ciphertext update request, obtains IV2 according to the ciphertext of the service data carried in the ciphertext update request, and obtains the key ID of the WK used to encrypt the service data according to IV2.
[0195] Exemplarily, the key management network element can be configured according to the splicing position of IV, and intercept IV2 from the left or right side of the ciphertext of the business data, and extract the key ID of WK used for encryption from IV2. For example, if IV2 is "53453456324789910004", the key ID of WK used for encryption extracted from IV2 is "10004".
[0196] Step 608: The key management network element determines relevant information of WK corresponding to the key ID of WK, such as the ciphertext of WK and the key feature code of WK, based on the key ID of WK.
[0197] Exemplarily, the key management network element queries the key record table shown in Table 9 above with the key ID of WK: 10004 as the index, and obtains the relevant records of WK whose key ID is 10004 from the key record table: key feature code WK_10004, ciphertext of WK is "23465346553454210002HSHGHrete45HFDGDSFggygertGDSF trewtjjKkjhKJKarawWQsdfgerGewrtJDwW", and the status is history.
[0198] Step 609: The key management network element obtains IV1 based on the ciphertext of WK, obtains the key ID of the KEK used to encrypt WK based on IV1, finds the relevant record of KEK from the key record table based on the key ID of KEK: the ciphertext of KEK, uses the first root key to decrypt the ciphertext of KEK to obtain the original text of KEK, uses the original text of KEK and the key ID of KEK to decrypt the ciphertext of WK to obtain the original text of WK.
[0199] For example, the ciphertext of WK is encrypted by KEK. The key management network element can extract the IV1 used to encrypt the WK and the key ID of KEK from the ciphertext of WK. If the IV1 is "23465346553454210002", the key ID of KEK used to encrypt the WK is "10002". The ciphertext of KEK is obtained according to the key ID "10002" of KEK. The key management network element obtains the plaintext of M key components according to the serial number records of the ciphertexts of the M key components, synthesizes the first root key, and obtains the original text of KEK according to the first root key and the ciphertext of KEK. The original text of WK is obtained according to the original text of KEK, IV1, and the ciphertext of WK.
[0200] Step 610: The key management network element decrypts the ciphertext of the service data according to the original text of WK and IV2 to obtain the original text of the service data.
[0201] Step 611: The key management network element uses the key feature code determined in step 607 as an index to query the key record table, find the relevant record of the WK corresponding to the key feature code and whose status is effective, that is, the relevant record of the WK after the ciphertext is updated (such as WK_e), generate IV3 according to the key ID in the relevant record of the WK after the ciphertext is updated, encrypt the original text of the business data to obtain the new ciphertext of the business data: ciphertext_e of the business data.
[0202] For example, the key management network element determines that the key characteristic code determined in step 607 is WK_10004, and determines the relevant information of WK_e with a status of effective from Table 9 according to the key characteristic code WK_10004, obtains IV3 according to the key ID 10005 of WK_e, and encrypts the original text of the business data according to IV3 and the original text of WK_e (that is, the original text of WK with the key characteristic code WK_10004) to obtain a new ciphertext of the business data: the ciphertext of the business data_e.
[0203] Step 612: The key management network element returns the ciphertext _e of the service data to the service network element;
[0204] Step 613: The service network element receives the ciphertext _e of the service data and updates the ciphertext of the service data, such as replacing the original ciphertext of the service data with the ciphertext _e of the service data.
[0205] based on Figure 6In the method shown, the key management network element updates the root key by reselecting the root key component and recording the serial number of the ciphertext of the reselected root key component; the ciphertext record of the KEK / WK key record before and after the update is saved in the key record table, and distinguished by the status and key ID. When encrypting, the key management network element carries the KEK / WK key ID used for WK / business data encryption in the ciphertext of the WK key / the ciphertext of the business data. When decrypting, the key ID is obtained based on the ciphertext of the key, and the key record is determined from the key record table according to the key ID and decrypted. At the same time, when the key management network element determines that the status of the KEK / WK key ID carried in the ciphertext of the WK key / the ciphertext of the business data is history, it determines the corresponding KEK / WK key record with an effective status, generates a new WK key ciphertext / the ciphertext of the business data according to the KEK / WK key record with an effective status, and updates the corresponding WK key ciphertext / the ciphertext of the business data. In the process of updating KEK / WK, there is no need to determine the ciphertexts of all WK-related ciphertexts / business data in the system and make corresponding updates. The key update process is simple and time-saving. The decentralized update of the ciphertexts of the WK-related ciphertexts / business data is achieved without affecting the operation of the business system.
[0206] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the interaction between each node. It can be understood that in order to realize the above functions, each node, such as a key management network element, includes a hardware structure and / or software module corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiment disclosed in this document, the method of the embodiment of the present application can be implemented in the form of hardware, software, or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0207] The embodiment of the present application can divide the key management network element into functional modules according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.
[0208] Figure 7The structure diagram of a device 70 is shown. The device 70 may be a key management network element, a chip in a key management network element, a system on chip, or other devices capable of implementing the functions of the key management network element in the above method. The device 70 may be used to perform the functions of the key management network element involved in the above method embodiment. As an implementable manner, Figure 7 The device 70 shown includes: a processing unit 701;
[0209] The processing unit 701 is configured to select M ciphertext storage addresses from the N ciphertext storage addresses in response to the key operation request. For example, the processing unit 701 is configured to support the device 70 to perform step 403 .
[0210] The processing unit 701 is further configured to obtain the corresponding ciphertexts of the M key components according to the M ciphertext storage addresses, decrypt the ciphertexts of the M key components respectively using the private key of the key management network element to obtain the plaintexts of the M key components, generate a first key based on the plaintexts of the M key components, and perform corresponding key operations using the first key and the ID of the first key. For example, the processing unit 701 is configured to support the device 70 in executing steps 404 and 405.
[0211] Furthermore, the key management network element further includes: a transceiver unit 702;
[0212] The transceiver unit 702 is used to receive registration requests sent by N key component management network elements, where each registration request sent by the key component management network element is used to indicate that the key component management network element stores the ciphertext of the key component;
[0213] The processing unit 701 is also used to respond to the registration requests sent by the N key component management network elements, and store the address information of the N key component management network elements as N ciphertext storage addresses; or, use the serial numbers of the ciphertexts of the N key components as the N ciphertext storage addresses, and store the serial numbers of the ciphertexts of the N key components and the address information of the N key component management network elements in correspondence.
[0214] Specifically, the above Figure 4-Figure 6 All relevant contents of each step involved in the illustrated method embodiment can be referred to the functional description of the corresponding functional module, and will not be repeated here. Figure 4-Figure 6 The method shown in the figure has the function of the key management network element in the key management method shown in the figure, so it can achieve the same effect as the above-mentioned key management method.
[0215] In this embodiment, the device 70 can also be presented in the form of dividing various functional modules in an integrated manner. The "functional module" here can refer to an application specific integrated circuit (ASIC), a circuit, a processor and a memory that executes one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions. In a simple embodiment, a person skilled in the art can imagine that the function / implementation process of the processing unit 701 in the device 70 can be implemented by the processor calling the computer execution instructions stored in the memory. Figure 7 The function / implementation process of the transceiver unit 702 can be implemented through the signal interface.
[0216] For example, as another possible implementation method, the key management network element may adopt Figure 8 The structure shown, or including Figure 8 Parts shown. Figure 8 A schematic diagram of the composition of a device 80 provided in an embodiment of the present application, the device 80 may be a key management network element, a chip in a key management network element, a system on chip, or other devices capable of implementing the functions of the key management network element in the above method, etc. The device 80 may include a processor 801, a communication line 802, and a communication interface 803. Further, the device 80 may also include a memory 804. Among them, the processor 801, the memory 804, and the communication interface 803 may be connected through a communication line 802. Among them, the processor 801 may integrate the functions of the above-mentioned processing unit 701. The communication interface 803 may integrate the functions of the above-mentioned transceiver unit 702.
[0217] The processor 801 may be a central processing unit (CPU), a general processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 801 may also be other devices with processing functions, such as circuits, devices, or software modules, without limitation.
[0218] The communication line 802 is used to transmit information between the components included in the device 80.
[0219] The communication interface 803 is used to communicate with other devices or other communication networks (such as Ethernet, radio access network (RAN), wireless local area networks (WLAN)), etc. The communication interface 803 can be a module, a circuit, a transceiver, a network interface or any device capable of achieving communication.
[0220] The memory 804 is used to store instructions, where the instructions may be computer programs.
[0221] Among them, the memory 804 can be a read-only memory (ROM) or other types of static storage devices that can store static information and / or instructions, or a random access memory (RAM) or other types of dynamic storage devices that can store information and / or instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc), magnetic disk storage medium, other magnetic storage devices, without limitation.
[0222] It should be noted that the memory 804 may exist independently of the processor 801 or may be integrated with the processor 801. The memory 804 may be used to store instructions or program codes or some data, etc. The memory 804 may be located in the device 80 or outside the device 80, without limitation.
[0223] The processor 801 is used to execute instructions stored in the memory 804 to implement the key management method provided in the following embodiments of the present application. In one example, the processor 801 may include one or more CPUs. As an optional implementation, the device 80 includes multiple processors.
[0224] As an optional implementation, the apparatus 80 further includes an output device 805 and an input device 806. Exemplarily, the input device 806 is a device such as a keyboard, a mouse, a microphone or a joystick, and the output device 805 is a device such as a display screen and a speaker.
[0225] It should be noted that the device 80 can be a desktop computer, a portable computer, a network server, a mobile phone, a tablet computer, a wireless terminal, an embedded device, a chip system or a Figure 8In addition, Figure 8 The structure shown in the figure does not constitute a limitation on the communication device, except Figure 8 In addition to the components shown, the communication device may include more or fewer components than shown, or combine certain components, or arrange the components differently.
[0226] In the embodiment of the present application, the chip system may be composed of a chip, or may include a chip and other discrete devices.
[0227] The embodiment of the present application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be completed by a computer program to instruct the relevant hardware, and the program can be stored in the above computer-readable storage medium. When the program is executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be a terminal device of any of the above embodiments, such as: an internal storage unit including a data sending end and / or a data receiving end, such as a hard disk or memory of a terminal device. The above computer-readable storage medium can also be an external storage device of the above terminal device, such as a plug-in hard disk equipped on the above terminal device, a smart memory card (smart media card, SMC), a secure digital (secure digital, SD) card, a flash card (flash card), etc. Further, the above computer-readable storage medium can also include both an internal storage unit of the above terminal device and an external storage device. The above computer-readable storage medium is used to store the above computer program and other programs and data required by the above terminal device. The above computer-readable storage medium can also be used to temporarily store data that has been output or is to be output.
[0228] The present application also provides a computer instruction. All or part of the process in the above method embodiment can be completed by computer instructions to instruct related hardware (such as computers, processors, network devices, and terminals, etc.). The program can be stored in the above computer-readable storage medium.
[0229] It should be understood that in the embodiments of the present application, "B corresponding to A" means that B is associated with A. For example, B can be determined based on A. It should also be understood that determining B based on A does not mean determining B only based on A, but B can also be determined based on A and / or other information. In addition, the "connection" that appears in the embodiments of the present application refers to various connection methods such as direct connection or indirect connection to achieve communication between devices, and the embodiments of the present application do not impose any limitation on this.
[0230] In the description of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship, for example, A / B can represent A or B; "and / or" in the present application is only a kind of association relationship describing the associated objects, indicating that there can be three relationships, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In addition, in the description of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or its similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple. In addition, in order to facilitate the clear description of the technical solution of the embodiment of the present application, in the embodiment of the present application, the words "first" and "second" are used to distinguish the same or similar items with basically the same functions and effects. Those skilled in the art will appreciate that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit the difference. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.
[0231] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0232] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0233] The units described as separate components may or may not be physically separated, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0234] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0235] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium, including several instructions to enable a device, such as a single-chip microcomputer, a chip, etc., or a processor (processor) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks or optical disks.
[0236] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A key management method, applied to a key management network element, It is characterized in that The method comprises: In response to the key operation request, randomly select M ciphertext storage addresses from N ciphertext storage addresses, wherein each ciphertext storage address is used to obtain a ciphertext of a key component from a key component management network element, and the ciphertext of each key component is obtained by encrypting the plaintext of the key component generated by the corresponding key component network element using the public key of the key management network element, and M is an integer greater than 2 and less than or equal to N; the key component network element includes: one or more service network elements of a foreground user operation network element, a background management operation network element, a document service network element, a log service network element, a scheduled task service network element, and a notification service network element; Obtain the corresponding ciphertexts of the M key components according to the M ciphertext storage addresses, use the private key of the key management network element to decrypt the ciphertexts of the M key components respectively to obtain the plaintexts of the M key components, generate a first key based on the plaintexts of the M key components, and use the first key and the identification ID of the first key to perform corresponding key operations.
2. The method according to claim 1, It is characterized in that The method further comprises: Receiving registration requests sent by N key component management network elements, each registration request sent by a key component management network element is used to indicate that the key component management network element stores a ciphertext of a key component; In response to the registration requests sent by the N key component management network elements, the address information of the N key component management network elements is stored as the N ciphertext storage addresses; or, the serial numbers of the ciphertexts of the N key components are used as the N ciphertext storage addresses, and the serial numbers of the ciphertexts of the N key components are stored correspondingly to the address information of the N key component management network elements.
3. The method according to claim 2, It is characterized in that The address information of each key component management network element is included in the registration request sent by the key component management network element.
4. The method according to claim 2 or 3, It is characterized in that The address information of the key component management network element includes any one of the address information of the ID of the key component management network element, the uniform resource locator URL of the key component management network element, and the file transfer protocol FTP of the key component management network element.
5. The method according to claim 1, It is characterized in that The method further comprises: The correspondence between the M ciphertext storage addresses and the ID of the first key is stored.
6. The method according to claim 5, It is characterized in that The method further comprises: Determine to update the first key; randomly select K ciphertext storage addresses from the N ciphertext storage addresses, where K is an integer greater than 2 and less than or equal to N; Obtaining corresponding ciphertexts of K key components according to the K ciphertext storage addresses, decrypting the ciphertexts of the K key components respectively using the private key of the key management network element to obtain plaintexts of the K key components, and generating a second key based on the plaintexts of the K key components; the ciphertexts of the K key components are different from the ciphertexts of the M key components; The second key is used to update a first ciphertext, where the first ciphertext is a ciphertext obtained by performing an encryption operation on a first plaintext according to the first key and an ID of the first key, and the first ciphertext includes the ID of the first key.
7. The method according to claim 6, It is characterized in that The ciphertext of the K key components is different from the ciphertext of the M key components in that: The K is different from the M; or, The K is the same as or different from the M, and the ciphertext storage address of the ciphertext of the K key components is completely different from the ciphertext storage address of the ciphertext of the M key components; or, The K is the same as or different from the M, the ciphertext storage addresses of the ciphertexts of the K key components are partially or completely the same as the ciphertext storage addresses of the ciphertexts of the M key components, and the ciphertexts of the key components corresponding to the same ciphertext storage address are different.
8. The method according to claim 6 or 7, It is characterized in that The updating of the first ciphertext using the second key comprises: determining the M ciphertext storage addresses according to the ID of the first key included in the first ciphertext and the correspondence between the M ciphertext storage addresses and the ID of the first key; Obtaining corresponding ciphertexts of M key components according to the M ciphertext storage addresses, decrypting the ciphertexts of the M key components respectively using the private key of the key management network element to obtain plaintexts of the M key components, generating the first key based on the plaintexts of the M key components, and performing a decryption operation on the first ciphertext using the first key to obtain a first plaintext; An encryption operation is performed on the first plaintext using the second key and the ID of the second key to obtain a second ciphertext.
9. The method according to claim 8, It is characterized in that The method further comprises: When all the first ciphertexts are updated, the correspondence between the M ciphertext storage addresses and the ID of the first key is updated to the correspondence between the K ciphertext storage addresses and the ID of the second key, and the ID of the first key is the same as the ID of the second key.
10. The method according to claim 6, It is characterized in that The determining to update the first key includes: if a preset update period arrives, determining to update the first key; or, If any key component among the M key components is updated, then determining to update the first key; or, If a request for updating the ciphertext encrypted by the first key is received, it is determined to update the first key.
11. The method according to claim 1, It is characterized in that Generating a first key based on the plaintext of the M key components comprises: The first key is obtained by calculating the plaintext of the M key components using any of the following algorithms: password-based key derivation function PBKDF2, secure hash algorithm SHA256, hash message authentication code HMAC algorithm.
12. The method according to claim 1, It is characterized in that The key management network element includes a platform network element.
13. The method according to claim 1, It is characterized in that The key operation includes any one of encryption, decryption, key update, and ciphertext update.
14. A key management network element, It is characterized in that The key management network element includes: A processing unit, configured to randomly select M ciphertext storage addresses from N ciphertext storage addresses in response to a key operation request, wherein each ciphertext storage address is used to obtain a ciphertext of a key component from a key component management network element, and each ciphertext of the key component is obtained by encrypting the plaintext of the key component generated by the corresponding key component network element using the public key of the key management network element, and M is an integer greater than 2 and less than or equal to N; the key component network element includes: one or more service network elements of a foreground user operation network element, a background management operation network element, a document service network element, a log service network element, a scheduled task service network element, and a notification service network element; The processing unit is also used to obtain the corresponding M key components' ciphertexts according to the M ciphertext storage addresses, use the private key of the key management network element to decrypt the M key components' ciphertexts respectively to obtain the M key components' plaintexts, generate a first key based on the plaintexts of the M key components, and use the first key and the identification ID of the first key to perform corresponding key operations.
15. The key management network element according to claim 14, It is characterized in that The key management network element further includes: a transceiver unit; The transceiver unit is used to receive registration requests sent by N key component management network elements, each registration request sent by the key component management network element is used to indicate that the key component management network element stores the ciphertext of the key component; The processing unit is further used to store the address information of the N key component management network elements as the N ciphertext storage addresses in response to the registration requests sent by the N key component management network elements; or, to use the serial numbers of the ciphertexts of the N key components as the N ciphertext storage addresses, and store the serial numbers of the ciphertexts of the N key components in correspondence with the address information of the N key component management network elements.
16. The key management network element according to claim 15, It is characterized in that The address information of each key component management network element is included in the registration request sent by the key component management network element.
17. The key management network element according to claim 15 or 16, It is characterized in that The address information of the key component management network element includes any one of the address information of the ID of the key component management network element, the uniform resource locator URL of the key component management network element, and the file transfer protocol FTP of the key component management network element.
18. The key management network element according to claim 14, It is characterized in that The processing unit is further used to store the corresponding relationship between the M ciphertext storage addresses and the ID of the first key.
19. The key management network element according to claim 18, It is characterized in that The processing unit is further used to determine to update the first key; randomly select K ciphertext storage addresses from the N ciphertext storage addresses, where K is an integer greater than 2 and less than or equal to N; Obtaining corresponding ciphertexts of K key components according to the K ciphertext storage addresses, decrypting the ciphertexts of the K key components respectively using the private key of the key management network element to obtain plaintexts of the K key components, and generating a second key based on the plaintexts of the K key components; the ciphertexts of the K key components are different from the ciphertexts of the M key components; The second key is used to update a first ciphertext, where the first ciphertext is a ciphertext obtained by performing an encryption operation on a first plaintext according to the first key and an ID of the first key, and the first ciphertext includes the ID of the first key.
20. The key management network element according to claim 19, It is characterized in that The ciphertext of the K key components is different from the ciphertext of the M key components in that: The K is different from the M; or, The K is the same as or different from the M, and the ciphertext storage address of the ciphertext of the K key components is completely different from the ciphertext storage address of the ciphertext of the M key components; or, The K is the same as or different from the M, the ciphertext storage addresses of the ciphertexts of the K key components are partially or completely the same as the ciphertext storage addresses of the ciphertexts of the M key components, and the ciphertexts of the key components corresponding to the same ciphertext storage address are different.
21. The key management network element according to claim 19 or 20, It is characterized in that The processing unit is specifically configured to determine the M ciphertext storage addresses according to the ID of the first key included in the first ciphertext and the correspondence between the M ciphertext storage addresses and the ID of the first key; Obtaining corresponding ciphertexts of M key components according to the M ciphertext storage addresses, decrypting the ciphertexts of the M key components respectively using the private key of the key management network element to obtain plaintexts of the M key components, generating the first key based on the plaintexts of the M key components, and performing a decryption operation on the first ciphertext using the first key to obtain a first plaintext; An encryption operation is performed on the first plaintext using the second key and the ID of the second key to obtain a second ciphertext.
22. The key management network element according to claim 21, It is characterized in that The processing unit is also used to update the correspondence between the M ciphertext storage addresses and the ID of the first key to the correspondence between the K ciphertext storage addresses and the ID of the second key after all the first ciphertexts are updated, and the ID of the first key is the same as the ID of the second key.
23. The key management network element according to claim 19, It is characterized in that The processing unit is specifically configured to determine to update the first key if a preset update period arrives; or If any key component among the M key components is updated, determining to update the first key; or, If a request for updating the ciphertext encrypted by the first key is received, it is determined to update the first key.
24. The key management network element according to claim 14, It is characterized in that The processing unit is specifically used to use any one of the following algorithms to calculate the plaintext of the M key components to obtain the first key: password-based key derivation function PBKDF2, secure hash algorithm SHA256, hash message authentication code HMAC algorithm.
25. The key management network element according to claim 14, It is characterized in that The key management network element includes a platform network element.
26. The key management network element according to claim 14, It is characterized in that The key operation includes any one of encryption, decryption, key update, and ciphertext update.
27. A business system, It is characterized in that The business system includes: a key management network element and a key component management network element; A key management network element, configured to randomly select M ciphertext storage addresses from N ciphertext storage addresses in response to a key operation request, wherein each ciphertext storage address is used to obtain a ciphertext of a key component from a key component management network element, and each ciphertext of a key component is obtained by encrypting the plaintext of a key component generated by a corresponding key component network element using a public key of the key management network element, and M is an integer greater than 2 and less than or equal to N; the key component network elements include: one or more service network elements of a foreground user operation network element, a background management operation network element, a document service network element, a log service network element, a scheduled task service network element, and a notification service network element; Obtain the corresponding M key component ciphertexts according to the M ciphertext storage addresses, use the private key of the key management network element to decrypt the ciphertexts of the M key components respectively to obtain the plaintexts of the M key components, generate a first key based on the plaintexts of the M key components, and use the first key and the ID of the first key to perform corresponding key operations.
28. A device, It is characterized in that The device includes a processor, and the processor is used to execute the key management method according to any one of claims 1-13.
29. A computer program product, It is characterized in that The computer program product comprises computer instructions, and when the computer instructions are executed on a computer, the computer is enabled to execute the key management method according to any one of claims 1 to 13.
30. A computer readable storage medium, It is characterized in that The computer-readable storage medium includes computer instructions, and when the computer instructions are executed on a computer, the computer is enabled to execute the key management method according to any one of claims 1 to 13.
Citation Information
Patent Citations
Key management method, system and device
CN111245597A