A method for backing up, restoring and destroying device keys

By introducing detection modules and comparison modules into the key management server, the problems of low security of key backup and cumbersome recovery process in the prior art are solved, and efficient and secure key backup and recovery methods are realized.

CN114238937BActive Publication Date: 2025-05-09SHENZHEN COMTOP INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111340379.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-12
Publication Date
2025-05-09
Estimated Expiration
2041-11-12

AI Technical Summary

Technical Problem

In existing key backup and recovery methods, the security of the key is not effectively protected, resulting in illegal users being prone to stealing confidential information, and the recovery process is cumbersome and slow.

Method used

By introducing detection modules and comparison modules into the key management server, the validity of the key verification code is detected, and through the comparison algorithm and storage number, the backup key is generated and restored, ensuring the security and efficiency of the key in the backup and recovery process.

Benefits of technology

Improves the security and efficiency of key backup and recovery, prevents illegal users from stealing keys, and simplifies the recovery process, making it faster and safer.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114238937B_ABST
    Figure CN114238937B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of key backup and recovery, and in particular to a method for device key backup, recovery and key destruction, comprising a device and an execution flow chart, wherein a first device selects key backup or key backup recovery; a detection module in a key management server detects whether a key has a valid mark and its correctness, and determines whether the key needs to be destroyed according to the judgment result; a comparison module compares the algorithm, and after the comparison is successful, a corresponding storage number is assigned by a key storage module in a storage module; a second device stores the backed-up key; the present invention provides an efficient and highly secure key backup, recovery and key destruction method, wherein a mark in a key verification code generated by the first device is detected by the detection module, and an algorithm is compared by the comparison module, and two layers of protection make the key backup process safer; when performing key recovery, matching of the corresponding storage number can make the recovery speed faster.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of key backup and recovery, and in particular to a method for device key backup, recovery and key destruction. Background Art

[0002] Today's society has entered the information age, and computers and the Internet have penetrated into every field of society. With the advancement of the national economic informatization process and the rise of new network services such as e-commerce, society is increasingly dependent on computers and the Internet. The information age calls for information security, and people's requirements for information security are also getting higher and higher.

[0003] In modern information systems, cryptographic technology is used to keep information confidential, and its security actually depends on the security protection of the key. In an information security system, the cryptographic system and cryptographic algorithm can be public, and even the cryptographic device used can be lost. As long as the key is not leaked, the confidential information is still safe. Once the key is lost or wrong, not only the legitimate user cannot extract the information, but the illegal user may also steal the information. Therefore, key management occupies a very important position in the entire confidentiality system and becomes a key issue in the information security system. Its purpose is to ensure the security of the data confidentiality system.

[0004] In the existing key backup and recovery, there are not too many restrictions on the key, which reduces the security of the backup key and makes it easy for illegal users to steal confidential information. In addition, when performing key recovery, the existing recovery process is relatively cumbersome and slow. Summary of the invention

[0005] Technical issues solved

[0006] In view of the above-mentioned shortcomings of the prior art, the present invention provides a method for device key backup, recovery and key destruction, which solves the problems that in the existing key backup and recovery, there are not too many restrictions on the key, resulting in reduced security of the backup key, illegal users can easily steal confidential information, and the existing recovery process is cumbersome and slow.

[0007] Technical Solution

[0008] To achieve the above objectives, the present invention is implemented through the following technical solutions:

[0009] A method for backing up, restoring and destroying a device key comprises the following steps:

[0010] S1: The device key is backed up and restored. The first device selects key backup or key recovery. If backup is selected, S2 is executed; if recovery is selected, S3 is executed.

[0011] S2: Perform key backup and execute S201.

[0012] S201: The first device initiates a backup request, and at the same time, the first device generates a key verification code.

[0013] S202: The detection module in the key management server detects the key verification code generated by the first device.

[0014] S203: The detection module determines whether the flag of the key verification code is valid. If it is valid, execute S204; if it is invalid, execute S205.

[0015] S204: The key management server compares the key verification code through the comparison module based on the algorithm and key stored in the storage module.

[0016] S205: The backup is terminated and the key is destroyed.

[0017] S206: The comparison module determines whether the key verification code provided by the first device is consistent with the algorithm and key stored in the key server. If they are consistent, S207 is executed; if they are inconsistent, S205 is executed.

[0018] S207: The key management server will compile the corresponding storage numbers K1, K2, K3...Kn in sequence for the successfully compared keys and algorithms, thereby generating a backup key.

[0019] S208: The key management server sends the backed-up key to the second device to complete the storage of the backup key.

[0020] S3: Perform key recovery and execute S310.

[0021] S301: The first device initiates a recovery request and uploads the key to be recovered to the key management server in the form of a verification code.

[0022] S302: The detection module of the key management server detects the recovery key verification code uploaded by the first device.

[0023] S303: The detection module determines whether the flag of the restored key verification code is valid. If it is valid, execute S304; if it is invalid, execute S305.

[0024] S304: The comparison module determines whether the storage number of the recovery key verification code is the same as the storage number of the backup key in the second device. If they are the same, execute S306; if they are different, execute S305.

[0025] S305: Resume termination and upload error status.

[0026] S306: The second device returns the successful comparison information and key information to the key management server.

[0027] S307: The key management server sends the key needed by the first device to recover the key to the first device, thereby completing key recovery.

[0028] Furthermore, the key recovery is performed based on the backup key stored in the second device after the key backup is completed.

[0029] When performing key recovery, the first device uploads the key to be recovered. After the detection module passes the valid flag detection of the key, the comparison module compares it with the backup key stored in the second device after the key backup work is completed. When the comparison results are the same (for example, the required recovery key uploaded by the first device is A-K5-algorithm-key, and the backup key backed up in the key management server is also A-K5-algorithm-key), the backup key and the comparison success information are sent back to the key management server, and the key management server sends the backup key to the first device to complete the key recovery. When the comparison results are different, for example, the required recovery key uploaded by the first device is A-K8-algorithm-key, and the storage module in the key server does not store the key, the comparison fails, the recovery is terminated, and the error message is uploaded, and the recovery failure information is sent to the first device. Using the above method, when performing key recovery, by comparing the previously stored keys, the recovery process is faster; compared with the prior art, by comparing the valid flags, storage numbers and algorithms one by one, the key recovery process is safer and it is not easy for illegal users to steal the keys and crack the protection information.

[0030] Furthermore, the valid flag is A, and the corresponding storage numbers are: K1, K2, K3...Kn.

[0031] Furthermore, the key verification code is in the format of A-algorithm-key.

[0032] Furthermore, the backup key is in the format of A-Kx-algorithm-key.

[0033] The valid mark A provides primary protection for the key. The key management server will remove the key without the valid mark A and destroy the key. The algorithm will provide advanced protection for the key. The comparison module in the key management server will compare the algorithm provided by the first device with the algorithm of the algorithm storage module in the storage module. If the comparison is successful, the key storage module will assign the corresponding storage number. For example, the format of the key verification code to be backed up is A-algorithm-key. After the algorithm comparison is passed, the format of the backup key is A-K1-algorithm-key. The backup key is sent to the second device, and the second device stores the key. If the comparison fails, the backup is terminated and the key verification code is destroyed. When using the above method for backup, the key verification code with different valid marks or no valid mark can be effectively eliminated to reduce the workload of the comparison module, so that the comparison module is more efficient when performing algorithm comparison, will not be affected by other factors, and is faster when backing up the key; in addition, the two protections of detecting the valid mark and comparing the algorithm make the key safer when backing up.

[0034] Furthermore, the device includes a first device, a key management server and a second device.

[0035] Furthermore, the key management server includes a detection module, a comparison module and a storage module, wherein the storage module includes the key storage module and the algorithm storage module.

[0036] The first device selects key backup or key backup recovery;

[0037] The detection module in the key management server detects whether the key has a valid flag and whether the valid flag is correct, and decides whether the key needs to be destroyed based on the judgment result;

[0038] The comparison module will compare the algorithm in the key with the correct and valid mark with the original algorithm storage module in the storage module. After the comparison is successful, the key storage module in the storage module will assign the corresponding storage number;

[0039] The second device stores the backed-up key.

[0040] Beneficial Effects

[0041] Compared with the known public technology, the technical solution provided by the present invention has the following beneficial effects:

[0042] The present invention provides an efficient and highly secure key backup, recovery and key destruction method. The detection module detects a flag in a key verification code generated by a first device, and the comparison module compares the algorithm. The two-layer protection makes the key backup process safer, and the key that fails the detection and comparison can be directly destroyed to avoid affecting the entire backup process. When recovering the key, the matching of the corresponding storage number can make the recovery speed faster and safer. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0044] Figure 1 is a flow chart of the steps of the present invention;

[0045] Figure 2 It is a schematic diagram of the connection of each module of the present invention;

[0046] Figure 3 A schematic diagram of the backup key format of the present invention;

[0047] The numbers in the figure represent: 1. first device; 2. key management server; 3. second device; 21. detection module; 22. comparison module; 23. storage module; 231. key storage module; 232. algorithm storage module. DETAILED DESCRIPTION

[0048] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0049] The present invention will be further described below in conjunction with the embodiments.

[0050] Example 1

[0051] This embodiment discloses Figure 1 A method for backing up, restoring and destroying a device key is shown, comprising the following steps:

[0052] S1: The device key is backed up and restored. The first device 1 selects key backup or key restoration. If backup is selected, S2 is executed; if restoration is selected, S3 is executed.

[0053] S2: Perform key backup and execute S201.

[0054] S201: The first device initiates a backup request, and the first device 1 generates a key verification code.

[0055] S202: The detection module 21 in the key management server 2 detects the key verification code generated by the first device 1.

[0056] S203: The detection module 21 determines whether the flag of the key verification code is valid. If it is valid, S204 is executed; if it is invalid, S205 is executed.

[0057] S204: The key management server compares the key verification code through the comparison module 22 based on the algorithm and key stored in the storage module 23.

[0058] S205: The backup is terminated and the key is destroyed.

[0059] S206: The comparison module 22 determines whether the key verification code provided by the first device 1 is consistent with the algorithm and key stored in the key server. If they are consistent, S207 is executed; if they are inconsistent, S205 is executed.

[0060] S207: The key management server will compile the corresponding storage numbers K1, K2, K3...Kn in sequence for the successfully compared keys and algorithms, thereby generating a backup key.

[0061] S208: The key management server 2 sends the backup key to the second device 3 to complete the storage of the backup key.

[0062] S3: Perform key recovery and execute S310.

[0063] S301: The first device 1 initiates a recovery request and uploads the key to be recovered to the key management server 2 in the form of a verification code.

[0064] S302: The detection module 21 of the key management server 2 detects the recovery key verification code uploaded by the first device 1.

[0065] S303: the detection module 21 determines whether the flag of the restored key verification code is valid, if valid, execute S304; if invalid, execute S305.

[0066] S304: The comparison module 22 determines whether the storage number of the recovery key verification code is the same as the storage number of the backup key in the second device 3. If they are the same, S306 is executed; if they are different, S305 is executed.

[0067] S305: Resume termination and upload error status.

[0068] S306: The second device 3 returns the successful comparison information and key information to the key management server 2.

[0069] S307: The key management server 2 sends the key that the first device 1 needs to recover to the first device 1, and completes the key recovery.

[0070] The present invention provides an efficient and highly secure key backup, recovery and key destruction method. The detection module detects a flag in a key verification code generated by a first device, and the comparison module compares the algorithm. The two-layer protection makes the key backup process safer, and the key that fails the detection and comparison can be directly destroyed to avoid affecting the entire backup process. When recovering the key, the matching of the corresponding storage number can make the recovery speed faster and safer.

[0071] Example 2

[0072] This embodiment discloses a method for recovering a key based on a backup key stored in a second device after key backup is completed:

[0073] When performing key recovery, the first device uploads the key to be recovered. After the detection module passes the valid flag detection of the key, the comparison module compares it with the backup key stored in the second device after the key backup work is completed. When the comparison results are the same (for example, the required recovery key uploaded by the first device is A-K5-algorithm-key, and the backup key backed up in the key management server is also A-K5-algorithm-key), the backup key and the comparison success information are sent back to the key management server, and the key management server sends the backup key to the first device to complete the key recovery. When the comparison results are different, for example, the required recovery key uploaded by the first device is A-K8-algorithm-key, and the storage module in the key server does not store the key, the comparison fails, the recovery is terminated, and the error message is uploaded, and the recovery failure information is sent to the first device. Using the above method, when performing key recovery, by comparing the previously stored keys, the recovery process is faster; compared with the prior art, by comparing the valid flags, storage numbers and algorithms one by one, the key recovery process is safer and it is not easy for illegal users to steal the keys and crack the protection information.

[0074] Example 3

[0075] This embodiment discloses Figure 3 The key verification code format, backup key format, and detection, comparison, and storage methods shown are:

[0076] The valid mark A provides primary protection for the key. The key management server will remove the key without the valid mark A and destroy the key. The algorithm will provide advanced protection for the key. The comparison module in the key management server will compare the algorithm provided by the first device with the algorithm of the algorithm storage module in the storage module. If the comparison is successful, the key storage module will assign the corresponding storage number. For example, the format of the key verification code to be backed up is A-algorithm-key. After the algorithm comparison is passed, the format of the backup key is A-K1-algorithm-key. The backup key is sent to the second device, and the second device stores the key. If the comparison fails, the backup is terminated and the key verification code is destroyed. When using the above method for backup, the key verification code with different valid marks or no valid mark can be effectively eliminated to reduce the workload of the comparison module, so that the comparison module is more efficient when performing algorithm comparison, will not be affected by other factors, and is faster when backing up the key; in addition, the two protections of detecting the valid mark and comparing the algorithm make the key safer when backing up.

[0077] Example 4

[0078] This embodiment discloses Figure 2 The following shows how the modules are connected and the different steps that each module handles:

[0079] The first device selects key backup or key backup recovery;

[0080] The detection module in the key management server detects whether the key has a valid flag and whether the valid flag is correct, and decides whether the key needs to be destroyed based on the judgment result;

[0081] The comparison module will compare the algorithm in the key with the correct and valid mark with the original algorithm storage module in the storage module. After the comparison is successful, the key storage module in the storage module will assign the corresponding storage number;

[0082] The second device stores the backed-up key.

[0083] In summary, the present invention provides an efficient and highly secure key backup, recovery and key destruction method. The detection module detects the flag in the key verification code generated by the first device, and the comparison module compares the algorithm. The two layers of protection make the key backup process safer, and the key that fails the detection and comparison can be directly destroyed to avoid affecting the entire backup process. When recovering the key, the matching of the corresponding storage number can make the recovery speed faster and safer.

[0084] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for backing up, restoring and destroying a device key, characterized in that: The method comprises the following steps: S1: The device key is backed up and restored. The first device selects key backup or key recovery. If backup is selected, S2 is executed; if recovery is selected, S3 is executed. S2: Perform key backup and execute S201; S201: The first device initiates a backup request, and the first device generates a key verification code; S202: The detection module in the key management server detects the key verification code generated by the first device; S203: The detection module determines whether the key verification code flag is valid. If it is valid, execute S204; if it is invalid, execute S205; S204: The key management server compares the key verification code through the comparison module based on the algorithm and key stored in the storage module; S205: The backup is terminated and the key is destroyed; S206: The comparison module determines whether the key verification code provided by the first device is consistent with the algorithm and key stored in the key server. If they are consistent, S207 is executed; if they are inconsistent, S205 is executed; S207: The key management server writes the corresponding storage numbers K1, K2, K3...Kn in sequence with the successfully matched keys and algorithms, thereby generating a backup key; S208: The key management server sends the backup key to the second device to complete the storage of the backup key; S3: Perform key recovery and execute S310; S301: The first device initiates a recovery request and uploads the key to be recovered to the key management server in the form of a verification code; S302: The detection module of the key management server detects the recovery key verification code uploaded by the first device; S303: The detection module determines whether the flag of the restored key verification code is valid. If it is valid, execute S304; if it is invalid, execute S305; S304: The comparison module determines whether the storage number of the recovery key verification code is the same as the storage number of the backup key in the second device. If they are the same, execute S306; if they are different, execute S305; S305: Resume termination and upload error status; S306: The second device returns the successful comparison information and key information to the key management server; S307: The key management server sends the key needed by the first device to recover the key to the first device, thereby completing key recovery.

2. A method for backing up, restoring and destroying a device key according to claim 1, characterized in that: The key recovery is performed based on the backup key stored in the second device after the key backup is completed.

3. A method for backing up, restoring and destroying device keys according to claim 1, characterized in that: The mark is A, and the corresponding storage numbers are: K1, K2, K3...Kn.

4. A method for backing up, restoring and destroying device keys according to claim 3, characterized in that: The key verification code is in the format of A-algorithm-key.

5. A method for backing up, restoring and destroying a device key according to claim 3, characterized in that: The backup key is in the format of A-Kx-algorithm-key.

6. A method for backing up, restoring and destroying a device key according to claim 1, characterized in that: The device includes a first device, a key management server and a second device.

7. A method for backing up, restoring and destroying a device key according to claim 6, characterized in that: The key management server includes a detection module, a comparison module and a storage module, wherein the storage module includes a key storage module and an algorithm storage module.

Citation Information

Patent Citations

  • Key backup and recovery method and system for secure chip service key

    CN106685645A

  • Block chain account key backup and recovery methods and systems

    CN109474424A