Shared encryption and decryption method and device
By double encryption of ZMK ciphertext in the cloud cluster server system, the problem that the encryption machine cluster cannot be shared in the existing technology is solved, and a secure and resource sharing shared encryption and decryption method is realized, reducing costs and improving computing resource utilization.
Patent Information
- Application Number
- CN202210211998.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-04
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2042-03-04
AI Technical Summary
The encryptor cluster of existing cloud cluster server systems cannot be shared, or the security needs to be reduced during sharing, resulting in high costs, low computing resource utilization, and security risks.
By encrypting the ZMK ciphertext stored in each system with the LMK encryption of the shared encryption machine cluster and then encrypting it with the SPK of the encryption machine of each system, each system avoids the transmission key using the same local master key, and ensuring security while achieving shared encryption and decryption.
While realizing shared encryption, it ensures security between various systems, realizes resource sharing, reduces costs, and improves computing resource utilization.
Smart Images

Figure CN114567438B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a shared encryption and decryption method and device. Background Art
[0002] This section is intended to provide a background or context to the embodiments of the invention recited in the claims. No admission is made that the description herein is prior art by inclusion in this section.
[0003] At present, each cloud cluster server system is configured with an independent encryption machine cluster. Encryption machine clusters of different systems cannot be shared, or can only be shared under the condition of reduced security. If an independent encryption machine cluster is configured for each system, the cost is high and the computing resource utilization rate is also low; however, if a shared encryption machine cluster is configured for multiple systems, since the local master key configured inside the encryption machine is the same, each system needs to use the same local master key to encrypt the transmission key or data. If one system is hacked, the other systems will be at risk. Summary of the invention
[0004] An embodiment of the present invention provides a shared encryption method, which is used to ensure the security between various systems, realize resource sharing, reduce costs, and improve computing resource utilization when implementing shared encryption. The method is applied to a first key server associated with a first system, and the method includes:
[0005] Receiving a data encryption request sent by the first system, wherein the data encryption request includes data to be encrypted;
[0006] Obtain a first transmission key ZMK ciphertext and a data encryption key ZPK ciphertext from the first system, wherein the ZPK ciphertext is encrypted with the ZMK plaintext, the first ZMK ciphertext is encrypted with the local master key LMK of the shared encryption machine cluster, and then encrypted with the first encryption key SPK of the first encryption machine associated with the first system;
[0007] Decrypt the first ZMK ciphertext using the first SPK of the first encryption machine to obtain the second ZMK ciphertext encrypted by the LMK of the shared encryption machine cluster;
[0008] Send the ZPK ciphertext, the second ZMK ciphertext and the data to be encrypted to the shared encryption machine cluster, so that the shared encryption machine cluster uses LMK to decrypt the second ZMK ciphertext to obtain ZMK plaintext, uses ZMK plaintext to decrypt the ZPK ciphertext to obtain ZPK plaintext, and uses ZPK plaintext to encrypt the data to be encrypted to obtain encrypted data ciphertext;
[0009] Receive encrypted data ciphertext provided by the shared encryption machine cluster;
[0010] The encrypted data ciphertext is sent to a second key server associated with the second system.
[0011] The embodiment of the present invention further provides a shared decryption method, which is used to ensure the security between various systems, realize resource sharing, reduce costs, and improve computing resource utilization when implementing shared decryption. The method is applied to a second key server associated with a second system, and the method includes:
[0012] Receiving encrypted data ciphertext and data encryption key ZPK ciphertext sent by a first key server associated with the first system, wherein the ZPK ciphertext is encrypted in plain text with a transmission key ZMK;
[0013] Obtain a third ZMK ciphertext from the second system, encrypt the third ZMK ciphertext with the local master key LMK of the shared encryption machine cluster, and then encrypt it with the second encryption key SPK of the second encryption machine associated with the second system;
[0014] Decrypt the third ZMK ciphertext using the second SPK of the second encryption machine to obtain the second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster;
[0015] Send the ZPK ciphertext, the second ZMK ciphertext and the encrypted data ciphertext to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain the ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain the ZPK plaintext, and uses the ZPK plaintext to decrypt the encrypted data ciphertext to obtain the data plaintext;
[0016] Receive the plaintext data provided by the shared encryption machine cluster.
[0017] The embodiment of the present invention further provides a shared encryption device, which is used to ensure the security between various systems, realize resource sharing, reduce costs, and improve computing resource utilization when implementing shared encryption. The device is applied to a first key server associated with a first system, and the device includes:
[0018] A first receiving module, configured to receive a data encryption request sent by a first system, wherein the data encryption request includes data to be encrypted;
[0019] A key acquisition module is used to obtain a first transmission key ZMK ciphertext and a data encryption key ZPK ciphertext from the first system, wherein the ZPK ciphertext is encrypted with the ZMK plaintext, and the first ZMK ciphertext is encrypted with the local master key LMK of the shared encryption machine cluster and then encrypted with the first encryption key SPK of the first encryption machine associated with the first system;
[0020] A decryption module, used to decrypt the first ZMK ciphertext using the first SPK of the first encryption machine to obtain the second ZMK ciphertext encrypted by the LMK of the shared encryption machine cluster;
[0021] A shared encryption module is used to send the ZPK ciphertext, the second ZMK ciphertext and the data to be encrypted to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain the ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain the ZPK plaintext, and uses the ZPK plaintext to encrypt the data to be encrypted to obtain the encrypted data ciphertext;
[0022] The second receiving module is used to receive the encrypted data ciphertext provided by the shared encryption machine cluster;
[0023] The sending module is used to send the encrypted data ciphertext to the second key server associated with the second system.
[0024] The embodiment of the present invention further provides a shared decryption device, which is used to ensure the security between various systems, realize resource sharing, reduce costs, and improve computing resource utilization when implementing shared decryption. The device is applied to a second key server associated with a second system, and the device includes:
[0025] A first receiving module, used for receiving an encrypted data ciphertext and a data encryption key ZPK ciphertext sent by a first key server associated with the first system, wherein the ZPK ciphertext is encrypted in plain text with a transmission key ZMK;
[0026] A key acquisition module is used to obtain a third ZMK ciphertext from the second system, the third ZMK ciphertext is encrypted with a local master key LMK of the shared encryption machine cluster, and then encrypted with a second encryption key SPK of a second encryption machine associated with the second system;
[0027] A local decryption module, used to decrypt the third ZMK ciphertext using the second SPK of the second encryption machine to obtain the second ZMK ciphertext encrypted by the LMK of the shared encryption machine cluster;
[0028] A shared decryption module is used to send the ZPK ciphertext, the second ZMK ciphertext and the encrypted data ciphertext to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain the ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain the ZPK plaintext, and uses the ZPK plaintext to decrypt the encrypted data ciphertext to obtain the data plaintext;
[0029] The second receiving module is used to receive the plaintext data provided by the shared encryption machine cluster.
[0030] An embodiment of the present invention further provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned shared encryption and decryption method when executing the computer program.
[0031] An embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned shared encryption and decryption method is implemented.
[0032] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the above-mentioned shared encryption and decryption method is implemented.
[0033] In an embodiment of the present invention, a first key server associated with a first system receives a data encryption request sent by the first system, where the data encryption request includes data to be encrypted; obtains a first transmission key ZMK ciphertext and a data encryption key ZPK ciphertext from the first system, where the ZPK ciphertext is encrypted with ZMK plaintext, and the first ZMK ciphertext is encrypted with a local master key LMK of a shared encryption machine cluster, and then encrypted with a first encryption key SPK of a first encryption machine associated with the first system; uses the first SPK of the first encryption machine to decrypt the first ZMK ciphertext to obtain a second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster; sends the ZPK ciphertext, the second ZMK ciphertext, and the data to be encrypted to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain ZPK plaintext, and uses the ZPK plaintext to encrypt the data to be encrypted to obtain an encrypted data ciphertext; receives the encrypted data ciphertext provided by the shared encryption machine cluster; and sends the encrypted data ciphertext to a second key server associated with the second system. Compared with the technical solution in the prior art that encryption machine clusters of different systems cannot be shared, or can only be shared under reduced security, the ZMK ciphertext stored in each system is encrypted with the LMK of the shared encryption machine cluster and then encrypted with the SPK of the encryption machine of each system. This can avoid that each system uses the same local master key to encrypt the transmission key. While achieving shared encryption, the security between the systems is guaranteed, resource sharing is achieved, costs are reduced, and computing resource utilization is improved.
[0034] In an embodiment of the present invention, a second key server associated with a second system receives an encrypted data ciphertext and a data encryption key ZPK ciphertext sent by a first key server associated with a first system, the ZPK ciphertext being encrypted with a transmission key ZMK plaintext; a third ZMK ciphertext is obtained from the second system, the third ZMK ciphertext is encrypted with a local master key LMK of a shared encryption machine cluster, and then encrypted with a second encryption key SPK of a second encryption machine associated with the second system; the third ZMK ciphertext is decrypted using the second SPK of the second encryption machine to obtain a second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster; the ZPK ciphertext, the second ZMK ciphertext and the encrypted data ciphertext are sent to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain ZPK plaintext, and uses the ZPK plaintext to decrypt the encrypted data ciphertext to obtain data plaintext; and the data plaintext provided by the shared encryption machine cluster is received. Compared with the technical solution in the prior art that encryption machine clusters of different systems cannot be shared, or can only be shared under reduced security, by encrypting the ZMK ciphertext stored in each system with the LMK of the shared encryption machine cluster and then encrypting it with the SPK of the encryption machine of each system, it is possible to avoid that each system uses the same local master key to encrypt the transmission key. When using the shared encryption machine cluster for decryption, the security of the system can be guaranteed, resource sharing can be achieved, costs can be reduced, and the utilization of computing resources can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0036] Figure 1 This is a schematic diagram of the existing encryption machine cluster distribution;
[0037] Figure 2 To use Figure 1 The flowchart of encryption by the encryption machine cluster shown;
[0038] Figure 3 A flowchart of a shared encryption method applied to a first key server provided in an embodiment of the present invention;
[0039] Figure 4 A flowchart of a transmission key encryption method of a first system provided in an embodiment of the present invention;
[0040] Figure 5A flowchart of a shared decryption method applied to a second key server provided in an embodiment of the present invention;
[0041] Figure 6 A flow chart of a transmission key encryption method of a second system provided in an embodiment of the present invention;
[0042] Figure 7 This is an architecture diagram of a shared encryption machine cluster provided in an embodiment of the present invention;
[0043] Figure 8 A schematic diagram of a shared encryption device applied to a first key server provided in an embodiment of the present invention;
[0044] Fig. 9 A schematic diagram of another shared encryption device applied to a first key server provided in an embodiment of the present invention;
[0045] Fig.10 A schematic diagram of a shared decryption device applied to a second key server provided in an embodiment of the present invention;
[0046] Fig.11 This is a schematic diagram of another shared decryption device applied to a second key server provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0047] To make the purpose, technical solution and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are further described in detail below in conjunction with the accompanying drawings. Here, the exemplary embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.
[0048] In the description of this specification, the terms "include", "including", "have", "contain", etc. are all open terms, which mean including but not limited to. The descriptions with reference to the terms "one embodiment", "a specific embodiment", "some embodiments", "for example", etc. mean that the specific features, structures or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures or characteristics described may be combined in a suitable manner in any one or more embodiments or examples. The order of steps involved in each embodiment is used to schematically illustrate the implementation of the present application, and the order of steps is not limited and can be appropriately adjusted as needed.
[0049] Terminology explanation:
[0050] Encryption machine: A host encryption device that has been identified and approved for use by the national commercial encryption authority. Its main functions are to implement various cryptographic algorithms and safely store secret keys.
[0051] In order to understand this scheme more clearly, the following first briefly introduces the existing standard encryption system.
[0052] Figure 1 The following is a schematic diagram of the existing encryption machine cluster distribution: Figure 1 As shown in Figure 1, each system has its own encryption machine cluster. The encryption process is as follows: Figure 2 As shown, it mainly includes the following steps:
[0053] The first step is to set the local master key. The sender and the receiver import their respective local master keys (LMK1 and LMK2) into the encryption machine. The key is a different key set by the sender and the receiver.
[0054] The second step is to synchronize the transmission key. The sender and the receiver synchronize the transmission key ZMK in advance, and the key remains unchanged for a long time. The sender uses LMK1 in the encryption machine to encrypt ZMK to obtain the ciphertext ZMK(E1), and the receiver uses LMK2 in its own encryption machine to encrypt ZMK to obtain the ciphertext ZMK(E2). The two encryption results are different, but the plaintext is the same. (At this time, ZMK(E1) and ZMK(E2) can be safely stored in their respective systems, and only the encryption machines to which they belong can decrypt them).
[0055] The third step is to transfer the data encryption key. The sender randomly generates a data encryption key ZPK, then uses ZMK to encrypt ZPK to obtain ZPK(E), and then transmits ZPK(E) to the receiver through the network. The receiver uses ZMK to decrypt ZPK(E) to obtain the ZPK plaintext. Both parties have completed the synchronization of the working key.
[0056] Step 4: Encrypt data. The sender uses ZPK to encrypt data and obtains ciphertext. The receiver uses ZPK to decrypt and obtain plaintext.
[0057] In view of the above introduction to the existing standard encryption system, the research found that the encryption machine will have the following problems when it is not shared:
[0058] 1. Usually every system has a usage peak. If a small number of encryption machines are deployed, it will not be able to meet the needs of the system during the peak period; if a large number of encryption machines are deployed, they will be idle most of the time, which will cause a waste of computing power.
[0059] 2. It is difficult to adjust the number of encryption machines in the encryption machine cluster of the same system, and each adjustment requires the replacement of the secret key of the hardware encryption machine.
[0060] 3. The encryption machine exists in the form of hardware. It is costly to deploy an encryption machine for each system.
[0061] However, if the encryption machine cluster can be shared, the encryption machine is configured with a master key. Once shared, each system has to use the same master key for encryption and decryption. In theory, if the master key of the hardware encryption machine in system A and system B is the same, if system A is hacked, the data of system B can also be easily decrypted, which reduces the security of the system.
[0062] Therefore, the embodiments of the present invention provide a shared encryption and decryption method and device, which can ensure the security between various systems while implementing shared encryption and decryption.
[0063] like Figure 3 FIG. 1 is a flowchart of a shared encryption method provided by an embodiment of the present invention, which is applied to a first key server associated with a first system. The method includes the following steps:
[0064] Step 301: receiving a data encryption request sent by a first system, wherein the data encryption request includes data to be encrypted;
[0065] Step 302: Obtain a first transmission key ZMK ciphertext and a data encryption key ZPK ciphertext from the first system, wherein the ZPK ciphertext is encrypted with the ZMK plaintext, and the first ZMK ciphertext is encrypted with the local master key LMK of the shared encryption machine cluster, and then encrypted with the first encryption key SPK of the first encryption machine associated with the first system;
[0066] Step 303: Decrypt the first ZMK ciphertext using the first SPK of the first encryption machine to obtain the second ZMK ciphertext encrypted by the LMK of the shared encryption machine cluster;
[0067] Step 304: Send the ZPK ciphertext, the second ZMK ciphertext, and the data to be encrypted to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain the ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain the ZPK plaintext, and uses the ZPK plaintext to encrypt the data to be encrypted to obtain the encrypted data ciphertext;
[0068] Step 305: receiving the encrypted data ciphertext provided by the shared encryption machine cluster;
[0069] Step 306: Send the encrypted data ciphertext to the second key server associated with the second system.
[0070] In an embodiment of the present invention, a data encryption request sent by a first system is received, the data encryption request includes data to be encrypted; a first transmission key ZMK ciphertext and a data encryption key ZPK ciphertext are obtained from the first system, the ZPK ciphertext is encrypted with ZMK plaintext, the first ZMK ciphertext is encrypted with the local master key LMK of the shared encryption machine cluster, and then encrypted with the first encryption key SPK of the first encryption machine associated with the first system; the first ZMK ciphertext is decrypted using the first SPK of the first encryption machine to obtain a second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster; the ZPK ciphertext, the second ZMK ciphertext and the data to be encrypted are sent to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain ZPK plaintext, and uses the ZPK plaintext to encrypt the data to be encrypted to obtain the encrypted data ciphertext; the encrypted data ciphertext provided by the shared encryption machine cluster is received; and the encrypted data ciphertext is sent to the second key server associated with the second system. Compared with the technical solution in the prior art that encryption machine clusters of different systems cannot be shared, or can only be shared under reduced security, the ZMK ciphertext stored in each system is encrypted with the LMK of the shared encryption machine cluster and then encrypted with the SPK of the encryption machine of each system. This can avoid that each system uses the same local master key to encrypt the transmission key. While achieving shared encryption, the security between the systems is guaranteed, resource sharing is achieved, costs are reduced, and computing resource utilization is improved.
[0071] In the embodiment of the present invention, Figure 4 A flow chart of a transmission key encryption method of a first system provided in an embodiment of the present invention is as follows Figure 4 As shown, this may include:
[0072] Step 401: Obtain the ZMK plaintext pre-synchronized by the first system and the second system;
[0073] Step 402: Encrypt the ZMK plaintext using the LMK pre-imported into the shared encryption machine cluster to obtain a second ZMK ciphertext;
[0074] Step 403: Encrypt the second ZMK ciphertext using the first SPK pre-imported into the first encryption machine to obtain the first ZMK ciphertext;
[0075] Step 404: Store the first ZMK ciphertext in the first system.
[0076] In this way, when the transmission key ZMK is encrypted by the LMK of the shared encryption machine cluster, it is encrypted again with the encryption key SPK of each system's encryption machine, and finally stored in each system. During the shared encryption process, it can avoid that each system uses the same local master key to encrypt the transmission key, thereby improving the security between systems.
[0077] In the embodiment of the present invention, the above step 306 may include:
[0078] The ZPK ciphertext is sent to the second key server so that the second key server decrypts the encrypted data ciphertext.
[0079] The embodiment of the present invention also provides a shared decryption method, which is applied to a second key server associated with a second system, such as Figure 5 FIG. 1 is a flowchart of a shared decryption method provided by an embodiment of the present invention, the method comprising the following steps:
[0080] Step 501: receiving encrypted data ciphertext and data encryption key ZPK ciphertext sent by a first key server associated with a first system, wherein the ZPK ciphertext is encrypted in plain text with a transmission key ZMK;
[0081] Step 502: Obtain a third ZMK ciphertext from the second system, encrypt the third ZMK ciphertext with the local master key LMK of the shared encryption machine cluster, and then encrypt it with the second encryption key SPK of the second encryption machine associated with the second system;
[0082] Step 503: Decrypt the third ZMK ciphertext using the second SPK of the second encryption machine to obtain the second ZMK ciphertext encrypted by the LMK of the shared encryption machine cluster;
[0083] Step 504: Send the ZPK ciphertext, the second ZMK ciphertext and the encrypted data ciphertext to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain the ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain the ZPK plaintext, and uses the ZPK plaintext to decrypt the encrypted data ciphertext to obtain the data plaintext;
[0084] Step 505: Receive the plaintext data provided by the shared encryption machine cluster.
[0085] In an embodiment of the present invention, a second key server associated with a second system receives an encrypted data ciphertext and a data encryption key ZPK ciphertext sent by a first key server associated with a first system, the ZPK ciphertext being encrypted with a transmission key ZMK plaintext; a third ZMK ciphertext is obtained from the second system, the third ZMK ciphertext is encrypted with a local master key LMK of a shared encryption machine cluster, and then encrypted with a second encryption key SPK of a second encryption machine associated with the second system; the third ZMK ciphertext is decrypted using the second SPK of the second encryption machine to obtain a second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster; the ZPK ciphertext, the second ZMK ciphertext and the encrypted data ciphertext are sent to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain ZPK plaintext, and uses the ZPK plaintext to decrypt the encrypted data ciphertext to obtain data plaintext; and the data plaintext provided by the shared encryption machine cluster is received. Compared with the technical solution in the prior art that encryption machine clusters of different systems cannot be shared, or can only be shared under reduced security, by encrypting the ZMK ciphertext stored in each system with the LMK of the shared encryption machine cluster and then encrypting it with the SPK of the encryption machine of each system, it is possible to avoid that each system uses the same local master key to encrypt the transmission key. When using the shared encryption machine cluster for decryption, the security of the system can be guaranteed, resource sharing can be achieved, costs can be reduced, and the utilization of computing resources can be improved.
[0086] In the embodiment of the present invention, Figure 6 A flow chart of a transmission key encryption method of a second system provided in an embodiment of the present invention is shown in FIG. Figure 6 As shown, this may include:
[0087] Step 601: Obtain the ZMK plaintext pre-synchronized by the first system and the second system;
[0088] Step 602: Encrypt the ZMK using the LMK pre-imported into the shared encryption machine cluster to obtain a second ZMK ciphertext;
[0089] Step 603: Encrypt the second ZMK ciphertext using the second SPK pre-imported into the second encryption machine to obtain a third ZMK ciphertext;
[0090] Step 604: Store the third ZMK ciphertext in the second system.
[0091] In this way, when the transmission key ZMK is encrypted by the LMK of the shared encryption machine cluster, it is encrypted again with the encryption key SPK of each system's encryption machine, and finally stored in each system. During the shared decryption process, it can avoid that each system uses the same local master key to encrypt the transmission key, thereby improving the security between systems.
[0092] Figure 7 The architecture diagram of the shared encryption machine cluster provided by the embodiment of the present invention is as follows: Figure 7 As shown, the first system (A system application cluster) and the second system (B system application cluster) are respectively configured with a separate encryption machine (A system key encryption machine and B system key encryption machine), and the first system is associated with the first key server (A system key server), the second system is associated with the second key server (B system key server), and the first key server and the second key server are associated with a shared encryption machine cluster (shared load server).
[0093] It should be noted that, in the embodiment of the present invention, in order to ensure the data security of the encryption process, the shared server cluster only receives encryption requests or decryption requests sent by the key server associated with each system, and the shared server cluster can set a key server whitelist, so as to provide encryption and decryption services for multiple systems.
[0094] In addition, in an embodiment of the present invention, when the first system sends encrypted data to the second system, the first system and the second system may be systems both connected to a shared encryption machine cluster, and call the shared encryption machine cluster for encryption or decryption through their respective associated key servers; or, either the first system or the second system has a separate encryption machine cluster and does not use the shared encryption machine cluster for encryption and decryption, for example, the first system encrypts through an encryption machine cluster that only serves the first system, and the second system decrypts through the shared encryption machine cluster; or the first system encrypts through a shared encryption machine cluster, and the second system decrypts through an encryption machine cluster that only serves the second system.
[0095] Combine the following Figure 7 For the above Figure 3-Figure 6 The shared encryption and decryption methods shown in the figure are introduced in detail. Figure 7 As shown, in the embodiment of the present invention, the first system may transmit the data to be encrypted to the second system, and the second system may decrypt the encrypted data to obtain the data in plain text. The specific encryption and decryption process may be as follows:
[0096] Step 1: Preparation
[0097] During the specific implementation, first, the local master key LMK needs to be imported into the shared encryption machine cluster, the first encryption key SPK needs to be imported into the first encryption machine associated with the first system, and the second encryption key SPK needs to be imported into the second encryption machine associated with the second system.
[0098] It should be noted that the local master key LMK can be used to encrypt the transmission key or data, and the encryption key SPK of each system can be used to encrypt the data stored locally in the system.
[0099] Step 2: Synchronize the transmission key ZMK
[0100] In specific implementation, the transmission key ZMK plaintext pre-synchronized by the first system and the second system needs to be encrypted before being stored in the local system. Therefore, the first key server of the first system encrypts the ZMK plaintext using LMK to obtain the second ZMK ciphertext; encrypts the second ZMK ciphertext using the first SPK of the first encryption machine to obtain the first ZMK ciphertext; stores the first ZMK ciphertext in the first system; and the second key server of the second system encrypts the ZMK using LMK to obtain the second ZMK ciphertext; encrypts the second ZMK ciphertext using the second SPK of the second encryption machine to obtain the third ZMK ciphertext; stores the third ZMK ciphertext in the second system.
[0101] Step 3: Generate data transmission key SPK
[0102] During specific implementation, the first system randomly generates a data transmission key SPK, encrypts it in plain text with ZMK, and stores it in the first system.
[0103] Step 4: Data encryption process
[0104] During specific implementation, the first system sends a data encryption request to its associated first key server, and the data encryption request includes the data to be encrypted; the first key server obtains the first ZMK ciphertext and ZPK ciphertext from the first system; the first SPK of the first encryption machine is used to decrypt the first ZMK ciphertext to obtain the second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster.
[0105] The ZPK ciphertext, the second ZMK ciphertext and the data to be encrypted are sent to the shared encryption machine cluster. The shared encryption machine cluster uses LMK to decrypt the second ZMK ciphertext to obtain ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain ZPK plaintext, uses the ZPK plaintext to encrypt the data to be encrypted to obtain the encrypted data ciphertext, and sends the encrypted data ciphertext to the first key server.
[0106] The first key server sends the received encrypted data ciphertext and ZPK ciphertext to the key server of the second system.
[0107] Step 5: Data decryption process
[0108] During the specific implementation, the second key server associated with the second system receives the encrypted data ciphertext and the data encryption key ZPK ciphertext sent by the first key server; obtains the third ZMK ciphertext from the second system; uses the second SPK of the second encryption machine to decrypt the third ZMK ciphertext to obtain the second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster.
[0109] The ZPK ciphertext, the second ZMK ciphertext and the encrypted data ciphertext are sent to the shared encryption machine cluster. The shared encryption machine cluster uses LMK to decrypt the second ZMK ciphertext to obtain ZMK plaintext, uses ZMK plaintext to decrypt the ZPK ciphertext to obtain ZPK plaintext, uses ZPK plaintext to decrypt the encrypted data ciphertext to obtain data plaintext, and sends the data plaintext to the second key server.
[0110] The shared encryption and decryption method provided in the embodiment of the present invention has the following beneficial effects:
[0111] 1. Providing a shared encryption machine cluster can achieve resource sharing, reduce costs, and improve computing resource utilization.
[0112] 2. Each different system is equipped with an encryption machine to store its own key. The ZMK encrypted by the shared encryption machine is re-encrypted by the key, so that each system in the cluster of related shared encryption machines can be independent of each other. If the security module of any system fails, it will not affect other systems, thus improving the security between systems. Moreover, the encryption machine has a small amount of calculation, so a low-cost model can be selected to save costs.
[0113] The present invention also provides a shared encryption device, as described in the following embodiments. Since the principle of the device to solve the problem is similar to that of the shared encryption and decryption method, the implementation of the device can refer to the implementation of the shared encryption and decryption method, and the repeated parts will not be repeated.
[0114] like Figure 8 FIG. 1 is a schematic diagram of a shared encryption device provided by an embodiment of the present invention, which is applied to a first key server associated with a first system, and the device includes:
[0115] A first receiving module 801 is used to receive a data encryption request sent by a first system, where the data encryption request includes data to be encrypted;
[0116] A key acquisition module 802 is used to acquire a first transmission key ZMK ciphertext and a data encryption key ZPK ciphertext from the first system, wherein the ZPK ciphertext is encrypted with the ZMK plaintext, and the first ZMK ciphertext is encrypted with the local master key LMK of the shared encryption machine cluster and then encrypted with the first encryption key SPK of the first encryption machine associated with the first system;
[0117] Decryption module 803, used to decrypt the first ZMK ciphertext using the first SPK of the first encryption machine to obtain the second ZMK ciphertext encrypted by the LMK of the shared encryption machine cluster;
[0118] The shared encryption module 804 is used to send the ZPK ciphertext, the second ZMK ciphertext and the data to be encrypted to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain the ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain the ZPK plaintext, and uses the ZPK plaintext to encrypt the data to be encrypted to obtain the encrypted data ciphertext;
[0119] The second receiving module 805 is used to receive the encrypted data ciphertext provided by the shared encryption machine cluster;
[0120] The sending module 806 is used to send the encrypted data ciphertext to the second key server associated with the second system.
[0121] In one embodiment of the present invention, Fig. 9 As shown, Figure 8 The device shown also includes a transmission key encryption module 901, which is used before the first receiving module receives the data encryption request sent by the first system:
[0122] Obtain the ZMK plaintext pre-synchronized by the first system and the second system;
[0123] The ZMK plaintext is encrypted using the LMK pre-imported into the shared encryption machine cluster to obtain the second ZMK ciphertext;
[0124] Encrypt the second ZMK ciphertext using the first SPK pre-imported into the first encryption machine to obtain the first ZMK ciphertext;
[0125] The first ZMK ciphertext is stored in the first system.
[0126] In one embodiment of the present invention, the sending module is further used for:
[0127] The ZPK ciphertext is sent to the second key server so that the second key server decrypts the encrypted data ciphertext.
[0128] The present invention also provides a shared decryption device, as described in the following embodiments. Since the principle of the device to solve the problem is similar to that of the shared encryption and decryption method, the implementation of the device can refer to the implementation of the shared encryption and decryption method, and the repeated parts will not be repeated.
[0129] like Fig.10 FIG. 1 is a schematic diagram of a shared decryption device provided by an embodiment of the present invention, which is applied to a second key server associated with a second system, and the device includes:
[0130] The first receiving module 1001 is used to receive the encrypted data ciphertext and the data encryption key ZPK ciphertext sent by the first key server associated with the first system, wherein the ZPK ciphertext is encrypted in plain text with the transmission key ZMK;
[0131] The key acquisition module 1002 is used to obtain a third ZMK ciphertext from the second system, the third ZMK ciphertext is encrypted with the local master key LMK of the shared encryption machine cluster, and then encrypted with the second encryption key SPK of the second encryption machine associated with the second system;
[0132] A local decryption module 1003 is used to decrypt the third ZMK ciphertext using the second SPK of the second encryption machine to obtain the second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster;
[0133] The shared decryption module 1004 is used to send the ZPK ciphertext, the second ZMK ciphertext and the encrypted data ciphertext to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain the ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain the ZPK plaintext, and uses the ZPK plaintext to decrypt the encrypted data ciphertext to obtain the data plaintext;
[0134] The second receiving module 1005 is used to receive the data plaintext provided by the shared encryption machine cluster.
[0135] In one embodiment of the present invention, Fig.11 As shown, Fig.10 The device shown also includes a transmission key encryption module 1101, which is used before the first receiving module receives the encrypted data ciphertext and the data encryption key ZPK ciphertext sent by the first key server associated with the first system:
[0136] Obtain the ZMK plaintext pre-synchronized by the first system and the second system;
[0137] Encrypt the ZMK using the LMK pre-imported into the shared encryption machine cluster to obtain the second ZMK ciphertext;
[0138] The second ZMK ciphertext is encrypted using the second SPK pre-imported into the second encryption machine to obtain a third ZMK ciphertext;
[0139] The third ZMK ciphertext is stored in the second system.
[0140] An embodiment of the present invention further provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned shared encryption and decryption method when executing the computer program.
[0141] An embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned shared encryption and decryption method is implemented.
[0142] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the above-mentioned shared encryption and decryption method is implemented.
[0143] The shared encryption and decryption method provided in the embodiment of the present invention has the following beneficial effects:
[0144] 1. Providing a shared encryption machine cluster can achieve resource sharing, reduce costs, and improve computing resource utilization.
[0145] 2. Each different system is equipped with an encryption machine to store its own key. The ZMK encrypted by the shared encryption machine is re-encrypted by the key, so that each system in the cluster of related shared encryption machines can be independent of each other. If the security module of any system fails, it will not affect other systems, thus improving the security between systems. Moreover, the encryption machine has a small amount of calculation, so a low-cost model can be selected to save costs.
[0146] In an embodiment of the present invention, a first key server associated with a first system receives a data encryption request sent by the first system, where the data encryption request includes data to be encrypted; obtains a first transmission key ZMK ciphertext and a data encryption key ZPK ciphertext from the first system, where the ZPK ciphertext is encrypted with ZMK plaintext, and the first ZMK ciphertext is encrypted with a local master key LMK of a shared encryption machine cluster, and then encrypted with a first encryption key SPK of a first encryption machine associated with the first system; uses the first SPK of the first encryption machine to decrypt the first ZMK ciphertext to obtain a second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster; sends the ZPK ciphertext, the second ZMK ciphertext, and the data to be encrypted to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain ZPK plaintext, and uses the ZPK plaintext to encrypt the data to be encrypted to obtain an encrypted data ciphertext; receives the encrypted data ciphertext provided by the shared encryption machine cluster; and sends the encrypted data ciphertext to a second key server associated with the second system. Compared with the technical solution in the prior art that encryption machine clusters of different systems cannot be shared, or can only be shared under reduced security, the ZMK ciphertext stored in each system is encrypted with the LMK of the shared encryption machine cluster and then encrypted with the SPK of the encryption machine of each system. This can avoid that each system uses the same local master key to encrypt the transmission key. While achieving shared encryption, the security between the systems is guaranteed, resource sharing is achieved, costs are reduced, and computing resource utilization is improved.
[0147] In an embodiment of the present invention, a second key server associated with a second system receives an encrypted data ciphertext and a data encryption key ZPK ciphertext sent by a first key server associated with a first system, the ZPK ciphertext being encrypted with a transmission key ZMK plaintext; a third ZMK ciphertext is obtained from the second system, the third ZMK ciphertext is encrypted with a local master key LMK of a shared encryption machine cluster, and then encrypted with a second encryption key SPK of a second encryption machine associated with the second system; the third ZMK ciphertext is decrypted using the second SPK of the second encryption machine to obtain a second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster; the ZPK ciphertext, the second ZMK ciphertext and the encrypted data ciphertext are sent to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain ZPK plaintext, and uses the ZPK plaintext to decrypt the encrypted data ciphertext to obtain data plaintext; and the data plaintext provided by the shared encryption machine cluster is received. Compared with the technical solution in the prior art that encryption machine clusters of different systems cannot be shared, or can only be shared under reduced security, by encrypting the ZMK ciphertext stored in each system with the LMK of the shared encryption machine cluster and then encrypting it with the SPK of the encryption machine of each system, it is possible to avoid that each system uses the same local master key to encrypt the transmission key. When using the shared encryption machine cluster for decryption, the security of the system can be guaranteed, resource sharing can be achieved, costs can be reduced, and the utilization of computing resources can be improved.
[0148] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0149] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0150] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0151] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0152] The specific embodiments described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A shared encryption method, It is characterized in that A first key server associated with a first system includes: Receiving a data encryption request sent by the first system, wherein the data encryption request includes data to be encrypted; Obtain a first transmission key ZMK ciphertext and a data encryption key ZPK ciphertext from the first system, wherein the ZPK ciphertext is obtained by encrypting the ZPK plaintext with the ZMK plaintext, and the first ZMK ciphertext is obtained by encrypting the first ZMK plaintext with the local master key LMK of the shared encryption machine cluster and then with the first encryption key SPK of the first encryption machine associated with the first system; Decrypt the first ZMK ciphertext using the first SPK of the first encryption machine to obtain the second ZMK ciphertext encrypted by the LMK of the shared encryption machine cluster; Send the ZPK ciphertext, the second ZMK ciphertext and the data to be encrypted to the shared encryption machine cluster, so that the shared encryption machine cluster uses LMK to decrypt the second ZMK ciphertext to obtain ZMK plaintext, uses ZMK plaintext to decrypt the ZPK ciphertext to obtain ZPK plaintext, and uses ZPK plaintext to encrypt the data to be encrypted to obtain encrypted data ciphertext; Receive encrypted data ciphertext provided by the shared encryption machine cluster; The encrypted data ciphertext is sent to a second key server associated with the second system.
2. The method according to claim 1, It is characterized in that Before receiving the data encryption request sent by the first system, the method further includes: Obtain the ZMK plaintext pre-synchronized by the first system and the second system; The ZMK plaintext is encrypted using the LMK pre-imported into the shared encryption machine cluster to obtain the second ZMK ciphertext; Encrypt the second ZMK ciphertext using the first SPK pre-imported into the first encryption machine to obtain the first ZMK ciphertext; The first ZMK ciphertext is stored in the first system.
3. The method according to claim 1, It is characterized in that Sending the encrypted data ciphertext to a second key server associated with the second system includes: The ZPK ciphertext is sent to the second key server so that the second key server decrypts the encrypted data ciphertext.
4. A shared decryption method, It is characterized in that A second key server associated with a second system includes: Receiving encrypted data ciphertext and data encryption key ZPK ciphertext sent by a first key server associated with the first system, wherein the ZPK ciphertext is obtained by encrypting the ZPK plaintext with the transmission key ZMK plaintext; Obtain a third ZMK ciphertext from the second system, where the third ZMK ciphertext is obtained by encrypting the third ZMK plaintext with the local master key LMK of the shared encryption machine cluster and then with the second encryption key SPK of the second encryption machine associated with the second system; Decrypt the third ZMK ciphertext using the second SPK of the second encryption machine to obtain the second ZMK ciphertext encrypted with the LMK of the shared encryption machine cluster; Send the ZPK ciphertext, the second ZMK ciphertext and the encrypted data ciphertext to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain the ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain the ZPK plaintext, and uses the ZPK plaintext to decrypt the encrypted data ciphertext to obtain the data plaintext; Receive the plaintext data provided by the shared encryption machine cluster.
5. The method according to claim 4, It is characterized in that Before receiving the encrypted data ciphertext and the data encryption key ZPK ciphertext sent by the first key server associated with the first system, the method further includes: Obtain the ZMK plaintext pre-synchronized by the first system and the second system; Encrypt the ZMK using the LMK pre-imported into the shared encryption machine cluster to obtain the second ZMK ciphertext; The second ZMK ciphertext is encrypted using the second SPK pre-imported into the second encryption machine to obtain a third ZMK ciphertext; The third ZMK ciphertext is stored in the second system.
6. A shared encryption device, It is characterized in that A first key server associated with a first system includes: A first receiving module, configured to receive a data encryption request sent by a first system, wherein the data encryption request includes data to be encrypted; A key acquisition module is used to acquire a first transmission key ZMK ciphertext and a data encryption key ZPK ciphertext from the first system, wherein the ZPK ciphertext is obtained by encrypting the ZPK plaintext with the ZMK plaintext, and the first ZMK ciphertext is obtained by encrypting the first ZMK plaintext with the local master key LMK of the shared encryption machine cluster and then with the first encryption key SPK of the first encryption machine associated with the first system; A decryption module, used to decrypt the first ZMK ciphertext using the first SPK of the first encryption machine to obtain the second ZMK ciphertext encrypted by the LMK of the shared encryption machine cluster; A shared encryption module is used to send the ZPK ciphertext, the second ZMK ciphertext and the data to be encrypted to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain the ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain the ZPK plaintext, and uses the ZPK plaintext to encrypt the data to be encrypted to obtain the encrypted data ciphertext; The second receiving module is used to receive the encrypted data ciphertext provided by the shared encryption machine cluster; The sending module is used to send the encrypted data ciphertext to the second key server associated with the second system.
7. The device according to claim 6, It is characterized in that It also includes a transmission key encryption module, which is used for: before the first receiving module receives the data encryption request sent by the first system: Obtain the ZMK plaintext pre-synchronized by the first system and the second system; The ZMK plaintext is encrypted using the LMK pre-imported into the shared encryption machine cluster to obtain the second ZMK ciphertext; Encrypt the second ZMK ciphertext using the first SPK pre-imported into the first encryption machine to obtain the first ZMK ciphertext; The first ZMK ciphertext is stored in the first system.
8. The device according to claim 6, It is characterized in that The sending module is also used to: The ZPK ciphertext is sent to the second key server so that the second key server decrypts the encrypted data ciphertext.
9. A shared decryption device, It is characterized in that A second key server associated with a second system includes: A first receiving module is used to receive encrypted data ciphertext and data encryption key ZPK ciphertext sent by a first key server associated with the first system, wherein the ZPK ciphertext is obtained by encrypting the ZPK plaintext with the transmission key ZMK plaintext; A key acquisition module is used to obtain a third ZMK ciphertext from the second system, where the third ZMK ciphertext is obtained by encrypting the third ZMK plaintext with the local master key LMK of the shared encryption machine cluster and then with the second encryption key SPK of the second encryption machine associated with the second system; A local decryption module, used to decrypt the third ZMK ciphertext using the second SPK of the second encryption machine to obtain the second ZMK ciphertext encrypted by the LMK of the shared encryption machine cluster; A shared decryption module is used to send the ZPK ciphertext, the second ZMK ciphertext and the encrypted data ciphertext to the shared encryption machine cluster, so that the shared encryption machine cluster uses the LMK to decrypt the second ZMK ciphertext to obtain the ZMK plaintext, uses the ZMK plaintext to decrypt the ZPK ciphertext to obtain the ZPK plaintext, and uses the ZPK plaintext to decrypt the encrypted data ciphertext to obtain the data plaintext; The second receiving module is used to receive the plaintext data provided by the shared encryption machine cluster.
10. The device according to claim 9, It is characterized in that It also includes a transmission key encryption module, which is used for: before the first receiving module receives the encrypted data ciphertext and the data encryption key ZPK ciphertext sent by the first key server associated with the first system: Obtain the ZMK plaintext pre-synchronized by the first system and the second system; Encrypt the ZMK using the LMK pre-imported into the shared encryption machine cluster to obtain the second ZMK ciphertext; The second ZMK ciphertext is encrypted using the second SPK pre-imported into the second encryption machine to obtain a third ZMK ciphertext; The third ZMK ciphertext is stored in the second system.
11. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, It is characterized in that When the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.
12. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.
13. A computer program product, It is characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Method and system for inter-system secret key synchronization
CN104320248A
Data migration method and system
CN109905384A
Cited By
Information processing system
US12483391B2
Information processing system
US20240356732A1