Key management method, device and system for distributed cryptographic card

By establishing a connection between the server and multiple password cards, the key management method of distributed password cards is realized, and the problems of high-speed and low-latency password computing and key management in distributed cloud environments are solved, improving security.

CN115225269BActive Publication Date: 2025-05-20OPEN SECURITY RES INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210868461.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-22
Publication Date
2025-05-20
Estimated Expiration
2042-07-22

AI Technical Summary

Technical Problem

The prior art is difficult to realize high-speed and low-latency cryptographic operations and key management in a distributed cloud environment, while avoiding the plaintext of data in the business process in the network environment.

Method used

By establishing a connection between the server and multiple password cards, each password card is set in one terminal, and the key management method of a distributed password card is realized. The password card receives the key usage request of the business process. If there is a cache, the key will be provided directly. If there is no cache, the key request will be generated and sent to the server. The server obtains and sends the key to the password card.

Benefits of technology

It realizes high-speed and low-latency password computing and key management in a distributed cloud environment, avoiding the data plain text in the business process appearing in the network environment, and improving overall security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115225269B_ABST
    Figure CN115225269B_ABST
Patent Text Reader

Abstract

A key management method, device and system for distributed password cards, wherein a server is connected to a plurality of password cards, and each password card is arranged in a terminal; first, the password card receives a key use request sent by a business process in the terminal; based on the key use request, the password card determines whether the password card has a key corresponding to the business identifier of the requested password operation cached; if there is a cache, the key is directly obtained, and the password operation is performed on the business process based on the key; if there is no cache, a key request is generated and sent to the server; then, the server receives the key request, obtains the key according to the key request, and sends the key to the password card; finally, after receiving the key sent by the server, the password card uses the key to perform a password operation on the business process; thus, the present invention provides a high-speed, low-latency password operation and key acquisition method for the business process, while avoiding the appearance of plain text data in the business process in the network environment, thereby improving security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information system security, and particularly relates to a key management method, device and system for a distributed cryptographic card. Background Art

[0002] Cryptographic algorithms are the basis for the security of information system services. Business systems use cryptographic algorithms to authenticate access terminals and encrypt data traffic to protect data security. For example, website services based on https use the TLS security protocol and related cryptographic suites to ensure data security between website servers and browsers. The security of cryptographic algorithms depends on the cryptographic operation environment and the management mechanism of key management. Generally speaking, cryptographic operations and key management are implemented in an independent Hardware Security Module (HSM), which provides an access interface externally to implement the invocation of cryptographic algorithms and the protection of keys. This independent module narrows the protection boundary of the cipher, limits the invocation entry, creates an "isolated" operating environment for cryptographic operations, and improves the security of cryptographic operations.

[0003] Common hardware cryptographic modules on the information service side include PCIE cryptographic cards, cryptographic machines, signature verification servers, etc. Classified by type, they can be divided into the form of a board card (cryptographic card) and the form of a server (cryptographic machine, etc.).

[0004] The cryptographic card is inserted into the server where the service is located through the PCIE slot, and calls the key management and cryptographic operation functions of the PCIE through standard interfaces such as the "GM / T 0018 Specification for the Application Interface of Cryptographic Module Cryptographic Devices" and JCE. Due to the extremely high bandwidth of the PCIE bus, this implementation method can provide high-speed and low-latency cryptographic operation functions for business systems. However, since the service key is stored in the cryptographic card, the cryptographic card can only provide services for the business of the current physical host and is suitable for small business systems, with poor flexibility in key management. In business models such as multi-physical host load balancing, it is necessary to manually back up the key securely from one cryptographic card and restore it to the cryptographic card of other business hosts. Some cryptographic card products do not provide backup and recovery functions and cannot implement this function. In a distributed cloud environment, business applications may be elastically deployed to different physical machines along with virtual machines, but the cryptographic card devices on the physical machines may not have the keys of this business application, and the cryptographic card is not applicable to such scenarios.

[0005] Password modules in the form of servers such as cipher machines and signature verification servers provide services through the network. The password module server listens for network messages. The business system sends password operation requests to the IP address and port of the password module server to obtain the corresponding results of the password operation. The keys are uniformly managed by the password module server. This method can be applied in a distributed cloud environment. The business service only needs to configure the IP address and port of the password module server to communicate and request the password operation function. When the business is deployed on different physical machines, since the keys are uniformly stored in the password module server, the stability of the business keys can still be ensured. However, when using the server-form password module, the requests for password operations will be forwarded through switches and network devices. Although the key information is not leaked during this process, there may be a risk that the plaintext of the business data is monitored. Generally, when deploying, the business services of the password module server and the business server are unified in a relatively secure domain. Even so, the risk of this calling method is still higher than that of locally calling a password card. In addition, requesting password operations through the network requires forwarding through network devices such as network cards, routers, and switches, and its calling latency is relatively high, making it inapplicable to low-latency scenarios; for large-volume password operations such as encryption and decryption operations, all plain / ciphertexts need to be forwarded through the network, and the operation efficiency is restricted by the network bandwidth and cannot be further accelerated.

[0006] In order to integrate different password modules such as cipher machines, there is currently a solution for a password resource pool. This solution adds an intermediate layer between devices such as cipher machines and signature verification servers and the business to uniformly schedule password devices and operation requests. When in use, the business sends requests to the service interface of the resource pool, and the resource pool further sends the requests to different password module devices. The disadvantages of the network-based resource pool are similar to those of the server-form password module, with the risk of plaintext being forwarded by network devices, and the password operation efficiency and latency being affected by the network.

[0007] In summary, there is currently a certain demand for high-speed, low-latency key management and acquisition, and for avoiding the appearance of plaintext data in the business process in the network. Summary of the Invention

[0008] The main technical problem to be solved by the present invention is how to perform high-speed, low-latency password operations and securely acquire keys, and avoid the appearance of plaintext data in the business process in the network environment.

[0009] According to a first aspect, in one embodiment, a key management method for a distributed password card is provided, which is applied to a server. The server is connected to multiple password cards; each password card is disposed in a terminal.

[0010] The key management method includes:

[0011] Receive one or more key requests, where the key requests include a service identifier requesting cryptographic operations and a cryptographic card identifier sending the key requests;

[0012] According to one or more of the key requests, obtain one or more keys corresponding to the service identifier requesting cryptographic operations, where the keys correspond one-to-one with the key requests;

[0013] Send one or more of the keys to the corresponding cryptographic card according to the cryptographic card identifier; the keys are used to perform cryptographic operations on the service process requesting cryptographic operations.

[0014] According to a second aspect, in an embodiment, a key management method for a distributed cryptographic card is provided, which is applied to a cryptographic card. The cryptographic card is connected to a server, and the server is connected to multiple cryptographic cards; each cryptographic card is disposed in a terminal;

[0015] The key management method includes:

[0016] Receive a key usage request sent by a service process requesting cryptographic operations in the terminal, where the key usage request includes a service identifier requesting cryptographic operations;

[0017] Based on the key usage request, determine whether the cryptographic card has cached the key corresponding to the service identifier requesting cryptographic operations;

[0018] If there is a cache, directly obtain the key corresponding to the service identifier requesting cryptographic operations, and perform cryptographic operations on the service process requesting cryptographic operations based on the key;

[0019] If there is no cache, generate and send the key request to the server; the key request includes a service identifier requesting cryptographic operations and a cryptographic card identifier corresponding to the cryptographic card;

[0020] Receive the key sent by the server, and perform cryptographic operations on the service process requesting cryptographic operations based on the key.

[0021] According to a third aspect, in an embodiment, a key management device for a distributed cryptographic card is provided, which is applied to a server. The server is connected to multiple cryptographic cards; each cryptographic card is disposed in a terminal;

[0022] The key management device includes:

[0023] A first receiving module, configured to receive one or more key requests, where the key requests include a service identifier requesting cryptographic operations and a cryptographic card identifier sending the key requests;

[0024] The first key acquisition module is used to acquire one or more keys corresponding to the service identifier of the service for which the request is to be encrypted, according to one or more of the said key requests, and the keys correspond one-to-one with the key requests;

[0025] The key sending module is used to send one or more of the said keys to the corresponding cryptographic card according to the cryptographic card identifier; the keys are used to perform cryptographic operations on the service process for which the request is to be encrypted.

[0026] According to a fourth aspect, in one embodiment, a key management device for a distributed cryptographic card is provided, which is applied to a cryptographic card. The cryptographic card is connected to a server, and the server is connected to multiple cryptographic cards; each of the cryptographic cards is disposed in a terminal;

[0027] The key management device includes:

[0028] The second receiving module is used to receive a key usage request sent by a service process for which the request is to be encrypted in the terminal, and the key usage request includes the service identifier of the service for which the request is to be encrypted;

[0029] The judgment module is used to judge, based on the key usage request, whether the cryptographic card has cached the key corresponding to the service identifier of the service for which the request is to be encrypted;

[0030] The second key acquisition module is used to directly acquire the key corresponding to the service identifier of the service for which the request is to be encrypted if there is a cache, and perform cryptographic operations on the service process for which the request is to be encrypted based on the key corresponding to the service identifier of the service for which the request is to be encrypted;

[0031] The key request sending module is used to generate and send the key request to the server if there is no cache; the key request includes the service identifier of the service for which the request is to be encrypted and the cryptographic card identifier corresponding to the cryptographic card;

[0032] The third key acquisition module is used to receive the key sent by the server and perform cryptographic operations on the service process for which the request is to be encrypted based on the key.

[0033] According to a fifth aspect, in one embodiment, a key management system for a distributed cryptographic card is provided, which includes multiple cryptographic cards and a server. The server is connected to multiple cryptographic cards; each of the cryptographic cards is disposed in a terminal;

[0034] The server is used for:

[0035] Receiving one or more key requests, where the key requests include the service identifier of the service for which the request is to be encrypted and the cryptographic card identifier of the cryptographic card that sends the key request;

[0036] Obtain one or more keys corresponding to the service identifier for which the requested cryptographic operation is to be performed according to one or more of the said key requests, where the keys correspond one-to-one with the key requests;

[0037] Send one or more of the said keys to the corresponding cryptographic card according to the cryptographic card identifier; the keys are used to perform cryptographic operations on the service process for which the requested cryptographic operation is to be performed.

[0038] The cryptographic card is used for:

[0039] Receive a key usage request sent by a service process in the terminal that requests a cryptographic operation, where the key usage request includes the service identifier for which the requested cryptographic operation is to be performed;

[0040] Based on the key usage request, determine whether the cryptographic card has cached the key corresponding to the service identifier for which the requested cryptographic operation is to be performed;

[0041] If there is a cache, directly obtain the key corresponding to the service identifier for which the requested cryptographic operation is to be performed, and perform a cryptographic operation on the service process for which the requested cryptographic operation is to be performed based on the key corresponding to the service identifier for which the requested cryptographic operation is to be performed;

[0042] If there is no cache, generate and send the key request to the server; the key request includes the service identifier for which the requested cryptographic operation is to be performed and the cryptographic card identifier corresponding to the cryptographic card;

[0043] Receive the key sent by the server, and perform a cryptographic operation on the service process for which the requested cryptographic operation is to be performed based on the key.

[0044] According to the key management method, device and system of the distributed cryptographic card in the above embodiment, the server is connected to multiple cryptographic cards, and each cryptographic card is set in a terminal; First, the cryptographic card receives a key usage request sent by a service process in the terminal that requests a cryptographic operation; the cryptographic card determines whether the cryptographic card has cached the key corresponding to the service identifier for which the requested cryptographic operation is to be performed based on the key usage request; if there is a cache, directly obtain the key, and perform an encryption operation on the service process for which the requested cryptographic operation is to be performed based on the key; if there is no cache, generate and send a key request to the server; then, the server receives the key request, obtains the key according to the key request, and sends the key to the cryptographic card; finally, after the cryptographic card receives the key sent by the server, it uses the key to respond to the service process cryptographic operation request; thus, the present invention provides high-speed, low-latency cryptographic operations and secure key acquisition for the service process, while avoiding the appearance of data in plaintext in the network environment during the service process, improving security. Description of the Drawings

[0045] Figure 1 It is a schematic structural diagram of a key management system of a distributed cryptographic card for an embodiment;

[0046] Figure 2 Flowchart of the key management method for a distributed cryptographic card according to an embodiment;

[0047] Figure 3 Flowchart of the key management method for a distributed cryptographic card according to another embodiment;

[0048] Figure 4 Schematic structural diagram of the key management device for a distributed cryptographic card according to an embodiment;

[0049] Figure 5 Schematic structural diagram of the key management device for a distributed cryptographic card according to another embodiment. Detailed implementation manners

[0050] The present invention will be further described in detail below in conjunction with the accompanying drawings through specific implementation manners. Similar elements in different implementation manners are labeled with related similar element numbers. In the following implementation manners, many detailed descriptions are provided to enable a better understanding of the present application. However, those skilled in the art can easily recognize that some of the features can be omitted in different situations, or can be replaced by other elements, materials, or methods. In some cases, some operations related to the present application are not shown or described in the specification to avoid the core part of the present application being overwhelmed by excessive descriptions. For those skilled in the art, it is not necessary to describe these related operations in detail, and they can fully understand the related operations based on the descriptions in the specification and the general technical knowledge in the art.

[0051] In addition, the features, operations, or characteristics described in the specification can be combined in any appropriate manner to form various implementation manners. At the same time, the steps or actions in the method description can also be reordered or adjusted in an obvious manner by those skilled in the art. Therefore, the various sequences in the specification and the drawings are only for clearly describing a certain embodiment and do not mean that they are the necessary sequences, unless it is stated that a certain sequence must be followed.

[0052] The serial numbers assigned to the components in this article, such as "first", "second", etc., are only used to distinguish the described objects and do not have any sequential or technical meanings. And the "connection" and "coupling" mentioned in this application, unless otherwise specified, both include direct and indirect connections (couplings).

[0053] In an embodiment of the present invention, multiple password cards are respectively arranged in multiple terminals to form a distributed password card. In addition to having a PCIE interface, the password card also has a network interface, and the network interface is used to connect each password card to a server for key management. In this way, when a certain service process in a terminal needs to perform password operations, the service process sends a key usage request to the password card set in the terminal. Based on the received key usage request, the password card sends a key request to the server. Based on the received key request, the server searches for and obtains the key from the memory, and then sends the key to the password card. After receiving the key, the terminal uses the key to perform password operations on the service process. In addition, the password card can cache the keys received historically. When the same service process obtains the key again, the password card does not need to obtain the key from the server and can directly send the cached key to the terminal to perform password operations on the same service process.

[0054] Please refer to Figure 1 , Figure 1 For a key management system of a distributed password card in an embodiment, hereinafter referred to as the key management system, the key management system includes: multiple terminals 10, multiple password cards 20, and a server 30. The multiple terminals 10 and the multiple password cards 20 are in one-to-one correspondence, and each password card 20 is arranged in the corresponding terminal 10. The password card 20 is connected to the server 30 through a network.

[0055] The password card 20 includes a PCIE interface and a network interface. The password card 20 is accessed into the terminal 10 through the PCIE interface. Among them, the service process runs in different terminals 10 in the form of a virtual machine or an independent process. Since the key and the service process are in one-to-one correspondence, that is, when the same service process runs in different terminals 10, the corresponding key is the same; when different service processes run in the same terminal 10, the corresponding keys are also different.

[0056] Please refer to Figure 2 , Figure 2 For a flowchart of a key management method for a distributed password card applied to a password card in an embodiment, hereinafter referred to as the key management method, the key management method includes the following steps.

[0057] Step 101: The password card 20 receives a key usage request sent by a service process in the terminal 10 that requests password operations. The key usage request includes a service identifier for requesting password operations, and the service identifier for requesting password operations is used to identify the service process that requests password operations. Since the key and the service process are in a one-to-one correspondence, the password card 20 can identify the required key only based on the service identifier for requesting password operations. It should be noted that the terminal 10 in Step 101 is a terminal device accessed by the password card 20 through the PCIE interface, and the service process that requests password operations refers to a virtual machine or an independent process running in the terminal 10.

[0058] Step 102: Based on the key usage request, the password card 20 determines whether it has cached the key corresponding to the service identifier for requesting password operations. The password card 20 has a certain cache space internally, but its cache space is small and can only cache a small number of keys.

[0059] Step 103: If there is a cache, directly obtain the key corresponding to the service identifier for requesting password operations, and perform an encryption operation on the service process that requests password operations based on the key corresponding to the service identifier for requesting password operations. After receiving the key usage request, the password card 20 first determines whether the key has been cached before. If it has been cached, it can be directly sent to the service process for encryption without having to obtain it from the server 30 through the network. To a certain extent, the efficiency of password operations of the service process is improved.

[0060] Step 104: If there is no cache, the password card 20 generates and sends a key request to the server 30; the key request includes the service identifier for requesting password operations and the password card identifier corresponding to the password card. Since the cache space of the password card 20 is limited and cannot store too many keys, when the key corresponding to the service process that requests password operations is not cached in the password card 20, the password card 20 needs to send a key request to the server 30 to obtain the key. In the process of the password card 20 obtaining the key from the server 30, although it is carried out in a network environment, only the key is transmitted in the network environment, and the data of the service process is not transmitted in the network environment. Therefore, there is no risk of plaintext forwarding existing in the existing cipher machine scheme. In addition, when the key is transmitted through the network between the server 30 and the password card 20, the key is also encrypted.

[0061] Step 105: The password card 20 receives the key sent by the server 30 and encrypts the service process requesting password operation based on the key. The password card 20 involved in the embodiments of the present invention is an existing password card, which is built with a dedicated password algorithm chip and can perform password operations on the data in the service process. Specifically, regarding the password card 20's response to the service process password operation request using the key, the password operation request can adopt any existing password operation method, which will not be elaborated here.

[0062] Since the password card 20 has a certain cache space, after receiving the key sent by the server 30, while encrypting the service process based on the key, the password card 20 also caches the received key if the cache space permits. If the cache space in the password card 20 is insufficient, the previously cached key is deleted and then the received key is cached. In this way, the password card 20 does not need to repeatedly obtain the key for the same service process, improving the efficiency of password operations.

[0063] In one embodiment, in the key management system of distributed password cards, multiple password cards 20 can synchronously send key requests to the server 30, and the server 30 synchronously processes the received multiple key requests and sends the keys to each password card 20.

[0064] Please refer to Figure 3 , Figure 3 which is a flowchart of a key management method for a distributed password card applied to a server in an embodiment, hereinafter referred to as the key management method. The key management method includes the following steps.

[0065] Step 201: The server 30 receives one or more key requests. Among them, the key request includes the service identifier requesting password operation and the password card identifier sending the key request. The server 30 can simultaneously receive key requests sent by multiple password cards 20, that is, receive multiple key requests, or only receive a key request sent by one password card 20, that is, receive one key request. The key request contains the service identifier corresponding to the service process requesting password operation and the password card identifier of the password card sending the key request, so that the server 30 can find the corresponding key and send the found key to the corresponding password card 20.

[0066] Step 202: The server 30 obtains one or more keys corresponding to the service identifier for which the password operation is requested according to one or more key requests, and the keys correspond to the key requests one by one. In an embodiment, the keys in the server 30 are stored in the memory. After receiving a key request, the server 30 needs to parse the key request to obtain the service identifier for which the password operation is requested, and then based on the service identifier for which the password operation is requested, search for the corresponding key in the memory. For the case of receiving multiple key requests, the processing of a single key request is the same. The server 30 can parse the multiple key requests one by one according to a preset rule and search for the corresponding keys; or it can parse the multiple key requests synchronously and then search for the corresponding keys sequentially or synchronously.

[0067] Step 203: The server 30 sends one or more keys to the corresponding password card according to the password card identifier; wherein, the keys are used to perform password operations on the service process for which the password operation is requested. In the above step 202, when the server 30 parses the received key request, it will simultaneously obtain the password card identifier. Based on the password card identifier, the server 30 sends the key to the corresponding password card 20.

[0068] In this embodiment, the password operation and caching after the password card 20 receives the key have been described in the above embodiment and will not be elaborated here one by one.

[0069] There is consistency between the server 30 provided in the embodiment of the present invention and each password card 20. When the server 30 receives a key deletion request, while deleting the corresponding key, the server 30 also sends a deletion request to each password card 20 so that the password card 20 can also delete the key deleted by the server 30 from its cache.

[0070] In an embodiment, the server 30 is further configured to: receive a key deletion request, where the key deletion request includes the identifier of the key to be deleted; based on the key deletion request, search for and delete the key corresponding to the identifier of the key to be deleted in the memory, and obtain the sending information of the key corresponding to the identifier of the key to be deleted within a preset time, where the sending information includes the password card identifier corresponding to the password card to which the key corresponding to the identifier of the key to be deleted is sent within a preset time; based on the sending information of the key corresponding to the identifier of the key to be deleted within a preset time, generate and send a deletion request to the corresponding password card 20 to delete the key corresponding to the identifier of the key to be deleted cached in the password card 20. In this way, the consistency between the 20 password cards and the server 30 is maintained.

[0071] In this embodiment, only the protected key is transmitted in the network environment connected between the password card 20 and the server 30, and the data of the service process is not directly transmitted, avoiding the appearance of the clear text of the service process data in the network environment and improving the overall security. Among them, the key transmitted between the password card 20 and the server 30 is also encrypted. The specific encryption method is as follows:

[0072] After the password card 20 and the server 30 establish a connection, the entire system needs to be initialized, that is, the password card 20 and the server 30 generate and exchange to establish identity authentication. The server 30 obtains the device identity information of the password card 21. The device identity information includes the password card identifier and the public key of the password card. That is, the public key of the password card corresponds to the password card 20 one by one. The server 30 saves the public key of the password card obtained during initialization to the memory. After normal operation, the server 30 looks up the public key of the password card corresponding to the password card identifier from the memory according to the password card identifier parsed and obtained from the received key request; uses the public key of the password card to encrypt and protect the corresponding key, and sends the encrypted and protected key to the corresponding password card 20; after the password card 20 receives the encrypted and protected key and decrypts it, the complete key can be obtained. Thus, it not only avoids the transmission of clear text data in the network environment in the service process requesting password operations, but also ensures the security of the key.

[0073] Based on the key management method provided in the above embodiment, please refer to Figure 4 , this embodiment also provides a key management device for a distributed password card applied to the server 30. The key management device provided in this embodiment includes: a first receiving module 301, a first key obtaining module 302, and a key sending module 303.

[0074] The first receiving module 301 is used to receive one or more key requests, where the key request includes the service identifier requesting password operations and the password card identifier sending the key request.

[0075] The first key obtaining module 302 is used to obtain one or more keys corresponding to the service identifier requesting password operations according to one or more key requests, and the keys correspond to the key requests one by one.

[0076] The key sending module 303 is used to send one or more of the keys to the corresponding password card according to the password card identifier; the key is used to perform password operations on the service process requesting password operations.

[0077] Each module in the key management device provided in this embodiment corresponds one by one to Figure 3 the method steps in the key management method shown, and its specific implementation manners have been described in detail in the above embodiment and will not be elaborated here.

[0078] Please refer to Figure 5 Figure 5 , this embodiment also provides a key management device for a distributed cryptographic card applied to the cryptographic card 20. The key management device provided in this embodiment includes: a second receiving module 401, a judging module 402, a second key obtaining module 403, a key request sending module 404, and a third key obtaining module 405.

[0079] The second receiving module 401 is configured to receive a key usage request sent by a service process that requests cryptographic operations in the terminal 10. The key usage request includes a service identifier for which cryptographic operations are requested.

[0080] The judging module 402 is configured to judge, based on the key usage request, whether the cryptographic card has cached a key corresponding to the service identifier for which cryptographic operations are requested.

[0081] The second key obtaining module 403 is configured to directly obtain the key corresponding to the service identifier for which cryptographic operations are requested if there is a cache, and perform cryptographic operations on the service process that requests cryptographic operations based on the key corresponding to the service identifier for which cryptographic operations are requested.

[0082] The key request sending module 404 is configured to generate and send a key request to the server if there is no cache; the key request includes a service identifier for which cryptographic operations are requested and a cryptographic card identifier corresponding to the cryptographic card.

[0083] The third key obtaining module 405 is configured to receive the key sent by the server and perform cryptographic operations on the service process that requests cryptographic operations based on the key.

[0084] Each module in the key management device provided in this embodiment corresponds one by one to Figure 2 the method steps in the key management method shown, and its specific implementation manners have been described in detail in the above embodiments and will not be elaborated here.

[0085] It should be noted that the cryptographic operations involved in the embodiments of the present invention include: data encryption and decryption, signature verification, and message authentication code generation and verification, etc.

[0086] In the embodiments of the present invention, compared with the traditional cryptographic card solution, the present invention provides a unified and flexible key management solution, which can adapt to the available environments in cloud environments and distributed environments. Compared with the traditional cryptographic service module and cryptographic resource pool solutions, the present invention provides high-speed and low-latency cryptographic computing capabilities for service processes, and at the same time avoids the appearance of data plaintext in the service process in the network environment, improving the overall security.

[0087] Those skilled in the art can understand that all or part of the functions of the various methods in the above embodiments can be implemented in a hardware manner or in a computer program manner. When all or part of the functions in the above embodiments are implemented in a computer program manner, the program can be stored in a computer-readable storage medium. The storage medium may include: read-only memory, random access memory, magnetic disk, optical disk, hard disk, etc. The above functions can be realized by a computer executing the program. For example, the program is stored in the memory of the device, and when the processor executes the program in the memory, the above-mentioned all or part of the functions can be realized. In addition, when all or part of the functions in the above embodiments are implemented in a computer program manner, the program can also be stored in a storage medium such as a server, another computer, magnetic disk, optical disk, flash drive or mobile hard disk, and saved to the memory of the local device by downloading or copying, or the system of the local device is updated. When the processor executes the program in the memory, all or part of the functions in the above embodiments can be realized.

[0088] The above uses specific examples to elaborate on the present invention, which is only used to help understand the present invention and is not intended to limit the present invention. For those skilled in the art of the present invention, based on the idea of the present invention, several simple deductions, deformations or substitutions can also be made.

Claims

1. A key management method for a distributed cryptographic card, characterized in that: Applicable to a server for key management, the server is connected to multiple password cards; each of the password cards is set in a terminal, and multiple password cards are respectively set in multiple terminals to form a distributed password card, the password card has a PCIE interface and a network interface, the PCIE interface is used to connect the password card to the terminal where it is set, and the network interface is used to connect each password card to the server for key management; The key management method comprises: Receiving one or more key requests, wherein the key request includes a service identifier for requesting cryptographic operation and a cryptographic card identifier for sending the key request, wherein the service identifier for requesting cryptographic operation is used to identify a service process for requesting cryptographic operation; According to one or more key requests, obtaining one or more keys corresponding to the service identifier of the requested cryptographic operation, wherein the keys correspond to the key requests one by one; One or more of the keys are sent to the corresponding password card according to the password card identifier; the keys are used by the corresponding password card to perform a cryptographic operation on a business process that requests a cryptographic operation.

2. The key management method according to claim 1, characterized in that: Acquiring one or more keys corresponding to the service identifier of the requested cryptographic operation according to one or more key requests includes: According to one or more of the key requests, a key matching the service identifier for requesting cryptographic operation in the key request is searched and obtained in the memory.

3. The key management method according to claim 1 or 2, characterized in that: Also includes: Receiving a key deletion request, wherein the key deletion request includes an identifier of a key to be deleted; Based on the key deletion request, searching and deleting the key corresponding to the key identifier to be deleted in the memory, and obtaining the sending information of the key corresponding to the key identifier to be deleted within a preset time, wherein the sending information includes the password card identifier corresponding to the password card to which the key corresponding to the key identifier to be deleted is sent within the preset time; Based on the sending information of the key corresponding to the key identifier to be deleted within a preset time, a deletion request is generated and sent to the corresponding password card to delete the key corresponding to the key identifier to be deleted cached in the password card.

4. The key management method according to claim 1, characterized in that: Prior to receiving one or more key requests, further comprising: The device identity information of the plurality of password cards is obtained and saved, wherein the device identity information includes a password card identifier and a password card public key, and the device identity information corresponds to the password card one by one.

5. The key management method according to claim 4, characterized in that: Sending one or more keys to the corresponding password card according to the password card identifier includes: According to the password card identifier, obtaining the password card public key corresponding to the password card identifier; The corresponding key is encrypted and protected by using the public key of the password card, and the encrypted key is sent to the corresponding password card.

6. A key management method for a distributed cryptographic card, characterized in that: Applied to a password card, the password card is connected to a server for key management, the server is connected to multiple password cards; each password card is set in a terminal, multiple password cards are respectively set in multiple terminals to form a distributed password card, the password card has a PCIE interface and a network interface, the PCIE interface is used to connect the password card to the terminal where it is set, and the network interface is used to connect each password card to the server for key management; The key management method comprises: Receiving a key usage request sent by a service process requesting cryptographic operation in the terminal, the key usage request including a service identifier requesting cryptographic operation, the service identifier requesting cryptographic operation being used to identify the service process requesting cryptographic operation; Based on the key use request, determining whether the cryptographic card has a cached key corresponding to the service identification request for requesting cryptographic operation; If there is a cache, directly obtain the key corresponding to the business identifier requesting the cryptographic operation, and perform the cryptographic operation on the business process requesting the cryptographic operation based on the key; If there is no cache, generating and sending the key request to the server; the key request includes the service identifier for requesting cryptographic operation and the password card identifier corresponding to the password card; The key sent by the server is received, and a cryptographic operation is performed on the business process requesting the cryptographic operation based on the key.

7. The key management method according to claim 6, characterized in that: After receiving the key sent by the server, the method further includes: The key received from the server is cached.

8. A key management device for a distributed cryptographic card, characterized in that: Applicable to a server for key management, the server is connected to multiple password cards; each of the password cards is set in a terminal, and multiple password cards are respectively set in multiple terminals to form a distributed password card, the password card has a PCIE interface and a network interface, the PCIE interface is used to connect the password card to the terminal where it is set, and the network interface is used to connect each password card to the server for key management; The key management device comprises: A first receiving module, configured to receive one or more key requests, wherein the key request includes a service identifier for requesting cryptographic operation and a cryptographic card identifier for sending the key request, wherein the service identifier for requesting cryptographic operation is used to identify a service process for requesting cryptographic operation; A first key acquisition module, configured to acquire, according to one or more key requests, one or more keys corresponding to the service identifier of the request cryptographic operation, wherein the keys correspond to the key requests in a one-to-one manner; The key sending module is used to send one or more keys to the corresponding password card according to the password card identifier; the key is used by the corresponding password card to perform a cryptographic operation on the business process requesting the cryptographic operation.

9. A key management device for a distributed cryptographic card, characterized in that: Applied to a password card, the password card is connected to a server for key management, the server is connected to multiple password cards; each password card is set in a terminal, multiple password cards are respectively set in multiple terminals to form a distributed password card, the password card has a PCIE interface and a network interface, the PCIE interface is used to connect the password card to the terminal where it is set, and the network interface is used to connect each password card to the server for key management; The key management device comprises: A second receiving module is used to receive a key usage request sent by a service process requesting a cryptographic operation in the terminal, wherein the key usage request includes a service identifier requesting a cryptographic operation, and the service identifier requesting a cryptographic operation is used to identify the service process requesting a cryptographic operation; A judgment module, used for judging whether the password card has cached the key corresponding to the service identifier of the requested cryptographic operation based on the key use request; A second key acquisition module is used to directly acquire the key corresponding to the business identifier for requesting cryptographic operation if there is a cache, and perform cryptographic operation on the business process for requesting cryptographic operation based on the key corresponding to the business identifier for requesting cryptographic operation; A key request sending module, used for generating and sending the key request to the server if there is no cache; the key request includes a service identifier for requesting cryptographic operation and a password card identifier corresponding to the password card; The third key acquisition module is used to receive the key sent by the server, and perform cryptographic operation on the business process requesting cryptographic operation based on the key.

10. A key management system for a distributed cryptographic card, characterized in that: The invention comprises a plurality of password cards and a server for key management, wherein the server is connected to the plurality of password cards; each of the password cards is arranged in a terminal, and the plurality of password cards are arranged in a plurality of terminals respectively to form a distributed password card, wherein the password card has a PCIE interface and a network interface, wherein the PCIE interface is used to connect the password card to the terminal in which it is arranged, and the network interface is used to connect each password card to the server for key management; The server is used to: Receiving one or more key requests, wherein the key request includes a service identifier for requesting cryptographic operation and a cryptographic card identifier for sending the key request, wherein the service identifier for requesting cryptographic operation is used to identify a service process for requesting cryptographic operation; According to one or more key requests, obtaining one or more keys corresponding to the service identifier of the requested cryptographic operation, wherein the keys correspond to the key requests one by one; Sending one or more of the keys to the corresponding password card according to the password card identifier; the keys are used by the corresponding password card to perform a cryptographic operation on a business process that requests a cryptographic operation; The password card is used for: Receiving a key usage request sent by a service process requesting cryptographic operation in the terminal, wherein the key usage request includes a service identifier requesting cryptographic operation; Based on the key use request, determining whether the cryptographic card has a cached key corresponding to the service identifier of the cryptographic operation request; If there is a cache, directly obtain the key corresponding to the business identifier for requesting the cryptographic operation, and perform the cryptographic operation on the business process for requesting the cryptographic operation based on the key corresponding to the business identifier for requesting the cryptographic operation; If there is no cache, generating and sending the key request to the server; the key request includes the service identifier for requesting cryptographic operation and the password card identifier corresponding to the password card; The key sent by the server is received, and a cryptographic operation is performed on the business process requesting the cryptographic operation based on the key.

Citation Information

Patent Citations

  • Data protection method and device, storage medium and electronic equipment

    CN111132150A