A data encryption and decryption method, system and storage medium for a multi-tenant model

Through the data encryption and decryption method of the multi-tenant model, centralized management of keys and decryption operations is solved, and the problem of enterprises distribute management of keys and decryption algorithms in multiple application systems is reduced, and the risk of data leakage is simplified.

CN115242382BActive Publication Date: 2025-06-13GUANLAN NETWORK HANGZHOU CO LTD +3
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210780036.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-04
Publication Date
2025-06-13
Estimated Expiration
2042-07-04

AI Technical Summary

Technical Problem

In the prior art, enterprises need to distribute management of keys and encryption and decryption algorithms in multiple application systems, resulting in increased management and maintenance difficulties and increased risk of data leakage.

Method used

Using the multi-tenant model data encryption and decryption method, the application system only needs to communicate with the encryption and decryption server to realize centralized encryption and decryption services.

Benefits of technology

It reduces the risk of data leakage in the application system, simplifies the management and maintenance process of enterprises, and through centralized key management, enterprises can issue and replace keys more conveniently.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115242382B_ABST
    Figure CN115242382B_ABST
Patent Text Reader

Abstract

This application relates to the technical field of data security services, and particularly to a data encryption and decryption method, system and storage medium for a multi-tenant model, which includes that an encryption and decryption server receives a service start instruction; the encryption and decryption server receives plaintext data and an encryption identifier corresponding to the plaintext data sent by an application system based on an encryption instruction; the encryption and decryption server verifies the encryption identifier; after the verification passes, the encryption and decryption server obtains a key from a hardware security module to encrypt the plaintext data to obtain corresponding ciphertext data; the encryption and decryption server receives ciphertext data and a decryption identifier corresponding to the ciphertext data sent by the application system based on a decryption instruction; the encryption and decryption server verifies the decryption identifier; after the verification passes, the encryption and decryption server obtains a key from the hardware security module to decrypt the ciphertext data to obtain corresponding plaintext data. This application has the effect of implementing centralized encryption and decryption services to facilitate enterprise management and maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data security services, and in particular, to a data encryption and decryption method, system, and storage medium for a multi-tenant model. Background Art

[0002] With the advent of the digital age, data simultaneously possesses multiple attributes such as national security, digital economy, social governance, and personal privacy. With the enactment and implementation of multiple national laws, a new situation of data security governance in the new era is gradually emerging. Facing the torrent of big data, how to respond to data security issues and protect user privacy is a measure that every enterprise must consider and take.

[0003] One of the key points of data security is to perform encrypted storage for sensitive data, which is also a necessary condition to meet regulatory compliance. The technical differences in various application programs in related technologies for independently completing data encryption are very large: encryption algorithms, salting methods, and storage structures are all different, which is not conducive to management and maintenance.

[0004] Taking the encryption of information such as user name, mobile phone number, and ID card number as an example, the related technologies include the following steps:

[0005] Developers of the application system add AES or other encryption and decryption algorithms in the code to implement encryption and decryption methods; encrypt and store the key or store it in the security software in the application system; find the code where the name, mobile phone number, and ID card number are stored, add an encryption method, and record the returned ciphertext and iv; find the code where the name, mobile phone number, and ID card number are stored, add a decryption method, and pass the ciphertext and iv when calling.

[0006] However, using the methods in related technologies, the encryption and decryption algorithms need to be implemented by the application system itself. Moreover, if there are many application systems in an enterprise, the keys and encryption and decryption algorithms will be scattered in each application system, which is not conducive to the enterprise's management and maintenance. Summary of the Invention

[0007] In order to implement a centralized encryption and decryption service for easy enterprise management and maintenance, this application provides a data encryption and decryption method, system, and storage medium for a multi-tenant model.

[0008] In a first aspect, a data encryption and decryption method for a multi-tenant model provided by this application adopts the following technical solution:

[0009] A data encryption and decryption method for a multi-tenant model, characterized by including:

[0010] The encryption and decryption server receives a service start instruction;

[0011] The encryption and decryption server receives the plaintext data sent by the application system based on an encryption instruction and an encryption identifier corresponding to the plaintext data, and the encryption and decryption identifier is pre-stored in the encryption and decryption toolkit integrated in the application system;

[0012] The encryption and decryption server verifies the encryption identifier;

[0013] After the verification passes, the encryption and decryption server obtains the corresponding key from the hardware security module and encrypts the plaintext data with the key to obtain the corresponding ciphertext data;

[0014] The encryption and decryption server sends the ciphertext data to the application system to complete the encryption.

[0015] In some embodiments, the encryption and decryption server receives the ciphertext data sent by the application system based on a decryption instruction and a decryption identifier corresponding to the ciphertext data, and the decryption identifier is pre-stored in the encryption and decryption toolkit integrated in the application system;

[0016] The encryption and decryption server verifies the decryption identifier;

[0017] After the verification passes, the encryption and decryption server obtains the corresponding key from the hardware security module and decrypts the ciphertext data with the key to obtain the corresponding plaintext data;

[0018] The encryption and decryption server sends the plaintext data to the application system to complete the decryption.

[0019] In some embodiments, both the encryption identifier and the decryption identifier include an apiSign, and the apiSign is a signature. The generation process of the apiSign specifically includes the following steps:

[0020] The application program obtains the apiSignKey issued by the enterprise side and sends the apiSignKey to the encryption and decryption toolkit. The apiSignKey is pre-sent by the encryption and decryption server to the enterprise side through a private channel;

[0021] The encryption and decryption toolkit obtains the apiSignKey and adds the corresponding timestamp and random number to obtain a signature factor set;

[0022] Encrypt the signature factor set using a signature encryption method to generate the corresponding apiSign.

[0023] In some embodiments, the verification of the encryption and decryption identifier or the decryption identifier by the encryption and decryption server includes the following steps:

[0024] The encryption / decryption server calls the myapiSignKey corresponding to the apiSignKey in the application;

[0025] The encryption / decryption server decodes the apiSign to obtain a signature factor set, obtains the timestamp and random number within the signature factor set, and adds the timestamp and random number to the myapiSignKey to obtain a verified signature factor set;

[0026] Use a signature encryption method to encrypt the verified signature factor set to generate a corresponding myapiSign, and compare the myapiSign with the apiSign;

[0027] If the myapiSign is equal to the apiSign, the verification passes.

[0028] In some embodiments, the encryption identifier further includes a keyID, where the keyID is a unique identifier of the key. The encryption / decryption server obtains the corresponding key from the hardware security module and encrypts the plaintext data with the key to obtain corresponding ciphertext data, including the following steps:

[0029] The encryption / decryption server obtains the keyID in the encryption identifier and obtains the key matching the keyID from the hardware security module;

[0030] Use the key to encrypt the plaintext data to obtain corresponding ciphertext, add the key to the ciphertext, and then add a random vector to the ciphertext to obtain ciphertext data with a multi - element structure. The combined structure of the ciphertext data is encrypt-{keyID}-{iv}-{ciphertext}, where encrypt is a fixed prefix, iv is the random vector for this encryption, and the ciphertext is the string obtained by base64 encoding the encrypted data.

[0031] In some embodiments, the encryption / decryption server obtains the corresponding key from the hardware security module and decrypts the ciphertext data with the key, including the following steps:

[0032] The encryption / decryption server obtains the parameter of keyID in the ciphertext data through {keyID} in the ciphertext data, and obtains the key matching the keyID from the hardware security module according to the parameter of keyID;

[0033] The encryption / decryption server obtains the parameter of the random vector in the ciphertext data through {iv} in the ciphertext data;

[0034] The encryption / decryption server decrypts the ciphertext data by using the key and the random variable.

[0035] In some embodiments, the encryption / decryption server determines whether the received data is plaintext data or ciphertext data. If the received data is plaintext data, it determines whether the plaintext data is sent by the application system based on an encryption instruction. If not, it cancels the encryption and generates a corresponding error report, and returns the error report and the plaintext data to the application system together. If the received data is ciphertext data, it determines whether the ciphertext data is sent by the application system based on a decryption instruction. If not, it cancels the decryption and generates a corresponding error report, and returns the error report and the ciphertext data to the application system together.

[0036] In some embodiments, after the encryption / decryption server performs encryption or decryption, the encryption / decryption toolkit stores the ciphertext data or plaintext data, and screens the ciphertext data stored in the encryption / decryption toolkit within a preset time to determine whether all the ciphertext data are multi-structured data. If there is ciphertext data that is not multi-structured data, it identifies the corresponding application program according to the {keyID} in the ciphertext data, and sends the ciphertext data to the application program for re-encryption.

[0037] In a second aspect, a data encryption / decryption system for a multi-tenant model provided by the present application adopts the following technical solution:

[0038] A data encryption / decryption system for a multi-tenant model, characterized in that it includes an application system, an encryption / decryption toolkit, an encryption / decryption server, and a hardware security module, wherein

[0039] The application system is used to receive an encryption instruction and send plaintext data based on the encryption instruction; the application system is also used to receive a decryption instruction and send ciphertext data based on the decryption instruction;

[0040] The encryption / decryption toolkit is integrated in the application system, and is used to receive the plaintext data and ciphertext data sent by the application system, and store the encryption identifier corresponding to the plaintext data sent by the application program or the decryption identifier corresponding to the ciphertext data. When the application system receives an encryption instruction, it sends the plaintext data and the encryption identifier to the encryption / decryption server. When the application system receives a decryption instruction, it sends the ciphertext data and the decryption identifier to the encryption / decryption server;

[0041] The encryption and decryption server is used to receive a service start instruction, and receive plaintext data and an encryption identifier. The encryption and decryption server verifies the encryption identifier. After the verification passes, the encryption and decryption server obtains the corresponding key from the hardware security module and encrypts the plaintext data with the key to obtain the corresponding ciphertext data. The encryption and decryption server sends the ciphertext data to the application system to complete the encryption;

[0042] The encryption and decryption server is used to receive a service start instruction, and is also used to receive ciphertext data and a decryption identifier. The encryption and decryption server verifies the decryption identifier. After the verification passes, the encryption and decryption server obtains the corresponding key from the hardware security module and decrypts the ciphertext data with the key to obtain the corresponding plaintext data. The encryption and decryption server sends the plaintext data to the application program to complete the decryption;

[0043] The hardware security module is used to add, delete keys according to user configuration, and store the keys for the encryption and decryption server to obtain the keys.

[0044] In some of the embodiments, the ciphertext data is multi-structured data, and the combined structure of the multi-structured data is encrypt-{keyID}-{iv}-{ciphertext}, where encrypt is a fixed prefix, iv is the random vector for this encryption, and the ciphertext is the string after the encrypted data is base64 encoded.

[0045] In a third aspect, a computer storage medium provided by the present application adopts the following technical solution:

[0046] A computer storage medium, on which a computer program is stored, characterized in that when the computer program is executed by a processor, it implements a data encryption and decryption method for a multi-tenant model.

[0047] In summary, the present application includes at least one of the following beneficial technical effects:

[0048] 1. The present application provides encryption and decryption HTTP / HTTPS services based on multi-tenant technology. When facing multiple application systems, each application system does not need to develop its own separate encryption and decryption algorithms, nor does it need to care about the storage location and storage status of the keys. When all application systems perform encryption and decryption operations, they are all carried out through the encryption and decryption server, and the keys are all stored in the hardware security module based on third-party authentication. The enterprise side does not need to consider the location of the keys, thereby reducing the risk of data leakage of the application system and facilitating enterprise management and maintenance;

[0049] 2. The centralized encryption and decryption service can centrally manage the keys, facilitating enterprise managers to issue keys and regularly replace keys;

[0050] 3. The ciphertext data has a multi-ciphertext structure set for innovation, enabling decryption directly through the ciphertext without the need to provide additional keys and salts during unlocking. The standardized ciphertext structure also facilitates enterprise management and maintenance. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 is a schematic diagram of the overall structure of the data encryption and decryption method for the multi-tenant model in the embodiments of the present application;

[0052] Figure 2 is a schematic diagram of the principle of the data encryption and decryption system for the multi-tenant model in the embodiments of the present application;

[0053] Figure 3 is a schematic diagram of the modules of the data encryption and decryption system for the multi-tenant model in the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0054] To more clearly understand the purpose, technical solutions, and advantages of the present application, the present application will be described and illustrated below with reference to the accompanying drawings and embodiments. However, those of ordinary skill in the art should understand that the present application can be implemented without these details. In some cases, well-known methods, processes, systems, components, and / or circuits that have been described at a higher level are not described in detail to avoid obscuring various aspects of the present application. For those of ordinary skill in the art, it is obvious that various changes can be made to the disclosed embodiments of the present application, and the general principles defined in the present application can be applied to other embodiments and application scenarios without departing from the principles and scope of the present application. Therefore, the present application is not limited to the illustrated embodiments, but conforms to the broadest scope consistent with the scope claimed in the present application.

[0055] Unless otherwise defined, the technical terms or scientific terms involved in the present application shall have the general meaning understood by those of ordinary skill in the technical field to which the present application belongs. The terms used in the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. Words such as "a", "an", "one", "the", "these", etc. used in the present application do not indicate a limitation in quantity and can be singular or plural. The terms "include", "comprise", "have" and any variations thereof involved in the present application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that includes a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products, or devices.

[0056] In this application, "a plurality of" refers to two or more. Usually, the character " / " indicates that the objects associated before and after are in an "or" relationship. The terms "first", "second", "third", etc. involved in this application are only used to distinguish similar objects and do not represent a specific order for the objects.

[0057] The terms "system", "engine", "unit", "module", and / or "block" involved in this application are a way to distinguish different components, elements, parts, components, assemblies, or functions at different levels by level. These terms can be replaced by other expressions that can achieve the same purpose. Generally, the "module", "unit", or "block" involved in this application refers to a collection of logic or software instructions embodied in hardware or firmware. The "module", "unit", or "block" described in this application can be implemented as software and / or hardware, and in the case of being implemented as software, they can be stored in any type of non-volatile computer-readable storage medium or storage device.

[0058] In some embodiments, the software module / unit / block can be compiled and linked into an executable program. It will be appreciated that the software module can be called from other modules / units / blocks or from itself, and / or can be called in response to a detected event or interruption. The software module / unit / block configured to execute on a computing device can be set on a computer-readable storage medium, such as an optical disc, digital video disc, flash drive, disk, or any other tangible medium, or as a digital download (and can initially be stored in a compressed or installable format that requires installation, decompression, or decryption before execution). Such software code can be partially or entirely stored on the storage device of the computing device being executed and applied in the operation of the computing device. The software instructions can be embedded in firmware, such as EPROM. It will also be appreciated that the hardware module / unit / block can be included in connected logic components, such as gates and flip-flops, and / or can be included in programmable units, such as programmable gate arrays or processors. The module / unit / block or computing device function described herein can be implemented as a software module / unit / block and can also be represented by hardware or firmware. Generally, the module / unit / block described herein can be combined with other modules / units / blocks, or although they are physically organized or stored, they can also be divided into sub-modules / sub-units / sub-blocks. This description can apply to a system, an engine, or a part thereof.

[0059] It will be understood that when a unit, engine, module or block is referred to as being "on", "connected" or "coupled to" another unit, engine, module or block, it can be directly on the other unit, engine, module or block, connected or coupled to it or communicating with it, or there can be intermediate units, engines, modules or blocks, unless the context clearly dictates otherwise. In this application, the term "and / or" can include any one or more of the related listed items or a combination thereof.

[0060] The following further elaborates on this application in conjunction with the attached Figures 1-3 for a more detailed description.

[0061] Embodiments of this application disclose a data encryption and decryption method for a multi-tenant model.

[0062] As Figure 1 shown, a data encryption and decryption method for a multi-tenant model includes:

[0063] S100, the encryption and decryption server receives a service start instruction.

[0064] The start instruction is issued by the user to notify the encryption and decryption server to prepare for the encryption and decryption task.

[0065] S200, the encryption and decryption server receives the plaintext data sent by the application system based on the encryption instruction and the encryption identifier corresponding to the plaintext data. The encryption identifier is pre-stored in the encryption and decryption toolkit integrated in the application program.

[0066] As Figure 1 and Figure 2 shown, the application system is an operating environment used by the enterprise side, generally composed of a computer hardware system, system software, and application software. The basic computer hardware system consists of an arithmetic unit and a controller, a memory, a peripheral interface, and peripheral devices. The system software includes an operating system, a compiler, a database management system, various high-level languages, etc. The application software consists of general support software and various application software packages. Multiple users can use different application systems, and one user can also use multiple application environments.

[0067] The enterprise side sends an encryption instruction to the application system, and the application program sends the plaintext data and the encryption identifier corresponding to the plaintext data to the encryption and decryption server. The encryption identifier is pre-stored in the encryption and decryption toolkit integrated in the application program.

[0068] The encryption and decryption toolkit is also called the encryption and decryption sdk. The sdk is a collection of development tools developed by software development engineers of some projects for specific platforms, hardware platforms, operating systems, software frameworks, etc. for use in application software development. The sdk includes, in a broad sense, a collection of related documents, examples, and tools for assisting in the development of a certain type of software.

[0069] An encryption and decryption toolkit with highly encapsulated encryption and decryption functions, supporting functions such as local caching and object-oriented access, simplifies the access and use of application programs.

[0070] The application system can choose to enable the local caching function of the encryption and decryption toolkit to reduce network request overhead. The local caching function temporarily stores the plaintext data or ciphertext data after encryption and decryption locally, which is presented in the form of key / value. The key is the plaintext data, the value is the ciphertext data, and the key is the ciphertext and the value is the plaintext.

[0071] The encryption identifier includes apiSign and keyID. apiSign is the signature used for subsequent verification with the port of the subsequent encryption and decryption server, and keyID is the unique identifier of the key, which is used for the subsequent encryption and decryption server to find the key associated with the plaintext data.

[0072] S300, the encryption and decryption server verifies the encryption identifier.

[0073] The encryption and decryption server verifies the encryption identifier by verifying the apiSign in the encryption identifier. Among them, the generation process of apiSign is as follows:

[0074] S310, the application program obtains the apiSignKey issued by the enterprise side and sends the apiSignKey into the encryption and decryption toolkit.

[0075] S320, the encryption and decryption toolkit obtains the apiSignKey and adds the corresponding timestamp and random number to obtain the signature factor set.

[0076] S330, uses the signature encryption method to encrypt the signature factor set to generate the corresponding apiSign.

[0077] apiSignKey is pre-sent to the enterprise side through a private channel, and each application system corresponds to a separate apiSignKey. In order to make the signature unique, a timestamp and a random number also need to be added to the apiSignKey to obtain the signature factor set. Uniqueness means that in order to prevent others from reusing request parameters, the uniqueness of the request needs to be ensured, that is, the corresponding request can only be used once, so even if others take the complete link of the request, it is invalid.

[0078] The role of the random number is: add a random number to the request, and the encryption and decryption server records the random number. If there are multiple data refreshes, it can be judged according to the random number to see if the random number of this request appears in the previous requests. If it appears repeatedly, it means that this request has appeared before.

[0079] The function of the timestamp is as follows: When the encryption and decryption server uniformly records a large number of random numbers, it will increase the burden and computing volume of the server. At this time, a timestamp is added, and the size of the timestamp can be adjusted. For example, it can be set to 5 minutes. After the 5-minute period has passed, all the random number records in the encryption and decryption server are cleared, and the signature request becomes invalid. In this way, the timestamp is used to determine whether a signature verification request has expired. Even if someone obtains the complete signature verification request, it is still invalid.

[0080] The signature encryption method when encrypting the signature factor set is MD5 in this embodiment. A brief description of the MD5 algorithm can be: MD5 processes the input information in 512-bit groups, and each group is further divided into 16 32-bit sub-groups. After a series of processes, the output of the algorithm consists of four 32-bit groups. After concatenating these four 32-bit groups, a 128-bit hash value is generated. It mainly includes four steps: padding, initializing variables, processing group data, and output. MD5 adds a unique "fingerprint" to the signature. When this signature is sent to the server, the server recalculates based on the data in the signature and adds another "fingerprint" using MD5. Finally, it checks whether the two "fingerprints are the same" to determine whether the signature has been tampered with.

[0081] After generating apiSign, the verification of the encryption identifier by the encryption and decryption server includes the following steps:

[0082] S340, the encryption and decryption server calls the myapiSignKey corresponding to the apiSignKey in the application program.

[0083] The encryption and decryption server will send an apiSignKey to the application system of the enterprise side through a private channel in advance, and at the same time generate and store the same myapiSignKey as the apiSignKey. When the application program makes a verification request to the port of the encryption and decryption server, the encryption and decryption server calls the same myapiSignKey as the apiSignKey to achieve a unique connection between the encryption and decryption server and a certain application program among multiple application programs.

[0084] S350, the encryption and decryption server decodes apiSign to obtain the signature factor set, obtains the timestamp and random number in the signature factor set, and adds the timestamp and random number to myapiSignKey to obtain the verification signature factor set.

[0085] Encryption and decryption obtain the timestamp and random number in the signature factor set by decrypting apiSign or directly, and add the timestamp and random number to myapiSignKey to obtain the verification signature factor set. The verification signature factor set is used to verify the signature factor set.

[0086] S360, encrypt the verification signature factor set using the signature encryption method to generate the corresponding myapiSign, and compare myapiSign with apiSign.

[0087] Use the MD5 algorithm to encrypt myapiSignKey, timestamp, and random number, and obtain the corresponding myapiSign. Compare myapiSign with apiSign to see if the two values are the same, so as to determine whether the verification has been tampered with or is unique.

[0088] S370, if myapiSign is equal to apiSign, the verification passes.

[0089] If myapiSign is equal to apiSign, the verification passes. If the two values are different, it means that the timestamp or random number may have changed, may have been tampered with or is not unique, the verification fails, and the plaintext data and plaintext identifier are resent back to the application system.

[0090] S400, after the verification passes, the encryption and decryption server obtains the corresponding key from the hardware security module and encrypts the plaintext data with the key to obtain the corresponding ciphertext data.

[0091] As Figure 1 and Figure 2 shown, specifically including:

[0092] S410, the encryption and decryption server obtains the keyID in the encryption and decryption identifier, and obtains the key matching the keyID from the hardware security module.

[0093] The hardware security module can use a hardware security module based on third-party authentication to uniformly store the keys of multiple application programs paired with the encryption and decryption server. The enterprise side can add and delete keys in the hardware security module.

[0094] When the encryption and decryption server obtains the keyID, because the keyID is the unique identifier of the key, the encryption and decryption server can find the key matching this keyID in the hardware security module, and the keyID and the key match one-to-one.

[0095] For multiple application systems, each application system adds a separate key in the hardware security module, and the keyID of each application system itself is different. Find the matching key among the numerous keys according to a certain keyID.

[0096] S420, Encrypt the plaintext data using the key to obtain the corresponding ciphertext. Add the key to the ciphertext, and then add a random vector to the ciphertext to obtain ciphertext data with a multi - element structure. The combined structure of the ciphertext data is encrypt - {keyID} - {iv} - {ciphertext}.

[0097] Among them, encrypt is a fixed prefix, iv is the random vector for this encryption, and the ciphertext is the string obtained by base64 encoding the encrypted data.

[0098] And the keyID therein is the one sent by the above encryption and decryption SDK to the encryption and decryption server. Setting the ciphertext data into an innovative multi - element ciphertext structure facilitates finding the key during the subsequent decryption process. At the same time, this ciphertext data structure can also create a large direct difference between the plaintext data and the ciphertext data, facilitating the encryption and decryption server to identify, thereby improving the enterprise's management and maintenance of sensitive data.

[0099] S500, The encryption and decryption server sends the ciphertext data to the application system to complete the encryption.

[0100] S600, The encryption and decryption server receives the ciphertext data sent by the application system based on the decryption instruction and the decryption identifier corresponding to the ciphertext data. The decryption identifier is pre - stored in the encryption and decryption toolkit integrated in the application system.

[0101] Among them, the decryption identifier includes apiSign. The generation method of apiSign in the decryption identifier is the same as that of apiSign in the encryption identifier, and the specific process is as described in the above S310 - S330.

[0102] S700, The encryption and decryption server verifies the decryption identifier.

[0103] The verification method of the decryption identifier by the encryption and decryption server is the same as the verification method of the encryption identifier by the encryption and decryption server, that is, it is consistent with the steps of the above S340 - S370.

[0104] S800, After the verification passes, the encryption and decryption server obtains the corresponding key from the hardware security module and decrypts the ciphertext data using the key to obtain the corresponding plaintext data.

[0105] Specifically, it includes the following steps:

[0106] S810, The encryption and decryption server obtains the parameter of keyID in the ciphertext data through {keyID} in the ciphertext data, and obtains the key matching keyID from the hardware security module according to the parameter of keyID.

[0107] When decrypting, there is no need to send the key ID corresponding to the application system together with the ciphertext data to the encryption and decryption server. Instead, the ciphertext data can be directly decrypted. The key ID value can be directly obtained from the multi-structured ciphertext data, and the corresponding key can be directly found according to the key ID, eliminating the process of the encryption and decryption toolkit sending the key ID to the encryption and decryption server and the encryption and decryption server parsing the key ID, reducing the computational workload of the encryption and decryption server. It also reduces the risk of the key ID being intercepted and tampered with during the transmission process.

[0108] S820, the encryption and decryption server obtains the parameters of the random vector in the ciphertext data through {iv} in the ciphertext data.

[0109] The iv is a random vector, that is, the "salt" value. When encrypting the plaintext data, a certain "salt" value will be added to the obtained ciphertext. The "salt" is a random value. Only the encryption and decryption server knows the size of the "salt" value. The purpose of salting is to prevent someone from illegally obtaining the ciphertext data and trying to decrypt it. Since they don't know the "salt" value, the hashing of the ciphertext data is different from the hashing with the known "salt" value, so the ciphertext data cannot be decrypted.

[0110] At the same time, if the plaintext data sent by two application systems happens to be the same 6-digit password, then to avoid conflicts between the two passwords, different "salt" values are placed in each password. So when the two passwords are the same, their hash values are also different.

[0111] S830, the encryption and decryption server encrypts the ciphertext data through the key and the random variable.

[0112] The encryption and decryption server directly obtains the key ID and the random vector from the multi-structured ciphertext data, and obtains the corresponding key according to the key ID for decryption.

[0113] S900, the encryption and decryption server sends the plaintext data to the application system to complete the decryption.

[0114] At the same time, the multi-structured ciphertext data can also enable the server to automatically and quickly identify whether a data is ciphertext data, without repeatedly encrypting the ciphertext data or decrypting the plaintext data, enabling the application system to be smoothly launched and upgraded, eliminating business impacts such as downtime and network jitter.

[0115] Specifically, it includes:

[0116] The encryption and decryption server determines whether the received data is plaintext or ciphertext. If the received data is plaintext, it determines whether the plaintext data is sent by the application system based on an encryption instruction. If not, it cancels the encryption and generates a corresponding error report, and returns the error report and the plaintext data to the application program together.

[0117] If the received data is ciphertext, it determines whether the ciphertext data is sent by the application system based on a decryption instruction. If not, it cancels the decryption and generates a corresponding error report, and returns the error report and the plaintext data to the application program together.

[0118] The encryption and decryption service can quickly determine whether the received data is plaintext or ciphertext according to the structure of the data, and retrieve the instructions in the application system to check whether the data and the instructions are corresponding. If a decryption instruction is issued for plaintext data or an encryption instruction is issued for ciphertext data, there will be duplicate encryption and decryption. The encryption and decryption server can quickly respond to block it and send an error report to the application system to remind the enterprise side to reduce the occurrence of error instructions.

[0119] At the same time, because in this embodiment, in the multi-tenant mode, multiple application systems share an encryption and decryption server, so in this case, the standard ciphertext structure helps enterprises manage and maintain sensitive data. For example, regularly screen whether all sensitive data is stored in this ciphertext structure, and identify which application system requested encryption through the {keyID} part.

[0120] Specifically, it includes:

[0121] After the encryption and decryption server performs encryption or decryption, the encryption and decryption toolkit stores the ciphertext data or plaintext data, and screens the ciphertext data stored in the encryption and decryption toolkit within a preset time to determine whether all ciphertext data is multi-structured data. If there is ciphertext data that is not multi-structured data, it identifies the corresponding application program according to the {keyID} in the ciphertext data, and sends the ciphertext data to the application program for re-encryption.

[0122] Based on the above method, this application provides encryption and decryption HTTP / HTTPS services based on multi-tenant technology. When facing multiple application systems, each application system does not need to develop its own separate encryption and decryption algorithms, nor does it need to care about the storage location and storage status of the keys. Because all application systems perform encryption and decryption operations through the encryption and decryption server, the application system only needs to send the plaintext data or ciphertext data to the encryption and decryption server based on the instructions, and the keys are all stored in the hardware security module based on third-party authentication. The enterprise side does not need to consider the location of the keys, thereby reducing the risk of data leakage in the application system and facilitating enterprise management and maintenance.

[0123] At the same time, the centralized encryption and decryption service can centrally manage keys, facilitating enterprise managers to issue keys and replace keys regularly.

[0124] As Figure 2 and Figure 3 shown, in another embodiment, a multi-tenant data encryption and decryption system is also disclosed, including an application system, an encryption and decryption toolkit, an encryption and decryption server, and a hardware security module.

[0125] The encryption and decryption toolkit is integrated into the application system, used to receive plaintext data and ciphertext data sent by the application system, store the encryption identifier corresponding to the plaintext data sent by the application program or the decryption identifier corresponding to the ciphertext data. When the application system receives an encryption instruction, it sends the plaintext data and the encryption identifier to the encryption and decryption server. When the application system receives a decryption instruction, it sends the ciphertext data and the decryption identifier to the encryption and decryption server.

[0126] The encryption and decryption server is used to receive a service start instruction and receive plaintext data and an encryption identifier. The encryption and decryption server verifies the encryption identifier. After verification, the encryption and decryption server obtains the corresponding key from the hardware security module and encrypts the plaintext data with the key to obtain the corresponding ciphertext data; the encryption and decryption server sends the ciphertext data to the application system to complete the encryption.

[0127] The encryption and decryption server is used to receive a service start instruction and is also used to receive ciphertext data and a decryption identifier. The encryption and decryption server verifies the decryption identifier. After verification, the encryption and decryption server obtains the corresponding key from the hardware security module and decrypts the ciphertext data with the key to obtain the corresponding plaintext data; the encryption and decryption server sends the plaintext data to the application program to complete the decryption.

[0128] The hardware security module is used to add, delete keys according to user configuration and store the keys for the encryption and decryption server to obtain the keys.

[0129] The ciphertext data is multi-structured data, and the combined structure of the multi-structured data is encrypt-{keyID}-{iv}-{ciphertext}, where encrypt is a fixed prefix, iv is the random vector for this encryption, and the ciphertext is the string after the encrypted data is base64 encoded.

[0130] In another embodiment, a computer storage medium is also disclosed, on which a computer program is stored. The computer program, when executed by a processor, implements any one of the above

[0131] The implementation principle is as follows:

[0132] As Figure 1 and Figure 3As shown in the figure, based on the above method, this application provides encrypted and decrypted HTTP / HTTPS services through multi-tenant technology. When facing multiple application systems, each application system does not need to develop its own encryption and decryption algorithms, nor does it need to care about the storage location and storage status of the keys. Because when all application systems perform encryption and decryption operations, they are all carried out through the encryption and decryption server. The application system only needs to send the plaintext data or ciphertext data to the encryption and decryption server based on the instruction, and the keys are stored in the hardware security module based on third-party authentication. The enterprise side does not need to consider the location of the keys, thereby reducing the risk of data leakage in the application system and facilitating enterprise management and maintenance.

[0133] At the same time, the centralized encryption and decryption service can centrally manage the keys, which is convenient for enterprise managers to issue keys and replace keys regularly.

[0134] The above are all the preferred embodiments of this application, and the protection scope of this application is not limited accordingly. Therefore, all equivalent changes made according to the structure, shape, and principle of this application should be covered within the protection scope of this application.

Claims

1. A data encryption and decryption method for a multi-tenant model, characterized in that, it includes: The encryption and decryption server receives a service start instruction; The encryption and decryption server receives the plaintext data sent by the application system based on an encryption instruction and an encryption identifier corresponding to the plaintext data, and the encryption identifier is pre-stored in the encryption and decryption toolkit integrated in the application system; The encryption and decryption server verifies the encryption identifier; After the verification passes, the encryption and decryption server obtains the corresponding key from the hardware security module and encrypts the plaintext data with the key to obtain the corresponding ciphertext data; The encryption and decryption server sends the ciphertext data to the application system to complete the encryption; The encryption and decryption server receives the ciphertext data sent by the application system based on a decryption instruction and a decryption identifier corresponding to the ciphertext data, and the decryption identifier is pre-stored in the encryption and decryption toolkit integrated in the application system; The encryption and decryption server verifies the decryption identifier; After the verification passes, the encryption and decryption server obtains the corresponding key from the hardware security module and decrypts the ciphertext data with the key to obtain the corresponding plaintext data; The encryption and decryption server sends the plaintext data to the application system to complete the decryption; Among them, both the encryption identifier and the decryption identifier include apiSign, the apiSign is a signature, and the generation process of the apiSign specifically includes the following steps: The application system obtains the apiSignKey issued by the enterprise side and sends the apiSignKey to the encryption and decryption toolkit, and the apiSignKey is pre-sent to the enterprise side by the encryption and decryption server through a private channel; The encryption and decryption toolkit obtains the apiSignKey and adds the corresponding timestamp and random number to obtain a signature factor set; Use a signature encryption method to encrypt the signature factor set to generate the corresponding apiSign; The encryption and decryption server verifies the encryption identifier or decryption identifier, including the following steps: The encryption and decryption server calls the myapiSignKey corresponding to the apiSignKey in the application system; The encryption and decryption server decodes the apiSign to obtain a signature factor set, obtains the timestamp and random number in the signature factor set, and adds the timestamp and random number to the myapiSignKey to obtain a verification signature factor set; Use a signature encryption method to encrypt the verification signature factor set to generate the corresponding myapiSign, and compare the myapiSign with the apiSign; If the myapiSign is equal to the apiSign, the verification passes.

2. The method according to claim 1, characterized in that: The encrypted identifier further includes a keyID, which is the unique identifier of the key. The encryption and decryption server obtains the corresponding key from the hardware security module and encrypts the plaintext data with the key to obtain the corresponding ciphertext data, including the following steps: The encryption and decryption server obtains the keyID in the encrypted identifier and obtains the key matching the keyID from the hardware security module; Use the key to encrypt the plaintext data to obtain the corresponding ciphertext, add the keyID to the ciphertext, and then add a random vector to the ciphertext to obtain ciphertext data with a multi-element structure. The combined structure of the ciphertext data is encrypt-{keyID}-{iv}-{ciphertext}, where encrypt is a fixed prefix, iv is the random vector for this encryption, and the ciphertext is the string after base64 encoding of the encrypted data.

3. The method according to claim 2, characterized in that: The encryption and decryption server obtains the corresponding key from the hardware security module and decrypts the ciphertext data with the key, including the following steps: The encryption and decryption server obtains the parameter of the keyID in the ciphertext data through the {keyID} in the ciphertext data, and obtains the key matching the keyID from the hardware security module according to the parameter of the keyID; The encryption and decryption server obtains the parameter of the random vector in the ciphertext data through the {iv} in the ciphertext data; The encryption and decryption server decrypts the ciphertext data with the key and the parameter of the random vector.

4. The method according to claim 2, characterized in that: The encryption and decryption server determines whether the received data is plaintext data or ciphertext data. If the received data is plaintext data, it determines whether the plaintext data is sent by the application system based on the encryption instruction. If not, the encryption is cancelled and a corresponding error report is generated, and the error report and the plaintext data are returned to the application system together; If the received data is ciphertext data, it determines whether the ciphertext data is sent by the application system based on the decryption instruction. If not, the decryption is cancelled and a corresponding error report is generated, and the error report and the ciphertext data are returned to the application system together.

5. The method according to claim 2, characterized in that: After the encryption and decryption server performs encryption or decryption, the encryption and decryption toolkit stores the ciphertext data or plaintext data, and screens the ciphertext data stored in the encryption and decryption toolkit within a preset time to determine whether all the ciphertext data is multi-element structure data. If there is ciphertext data that is not multi-element structure data, it identifies the corresponding application system according to the {keyID} in the ciphertext data, and sends the ciphertext data to the application system for re-encryption.

6. A data encryption and decryption system for a multi-tenant model, characterized in that: It includes an application system, an encryption and decryption toolkit, an encryption and decryption server, and a hardware security module, where, The application system is used to receive an encryption instruction and issue plaintext data based on the encryption instruction; the application system is also used to receive a decryption instruction and issue ciphertext data based on the decryption instruction; The encryption / decryption toolkit is integrated within the application system and is used to receive the plaintext data and ciphertext data issued by the application system, store the encryption identifier corresponding to the plaintext data issued by the application system or the decryption identifier corresponding to the ciphertext data. When the application system receives an encryption instruction, it sends the plaintext data and the encryption identifier to the encryption / decryption server. When the application system receives a decryption instruction, it sends the ciphertext data and the decryption identifier to the encryption / decryption server; The encryption / decryption server is used to receive a service start instruction and receive the plaintext data and the encryption identifier. The encryption / decryption server verifies the encryption identifier. After the verification passes, the encryption / decryption server obtains the corresponding key from the hardware security module and encrypts the plaintext data with the key to obtain the corresponding ciphertext data; the encryption / decryption server sends the ciphertext data to the application system to complete the encryption; The encryption / decryption server is used to receive a service start instruction and is also used to receive the ciphertext data and the decryption identifier. The encryption / decryption server verifies the decryption identifier. After the verification passes, the encryption / decryption server obtains the corresponding key from the hardware security module and decrypts the ciphertext data with the key to obtain the corresponding plaintext data; the encryption / decryption server sends the plaintext data to the application system to complete the decryption; The hardware security module is used to add, delete keys according to user configuration and store the keys for the encryption / decryption server to obtain the keys; Among them, both the encryption identifier and the decryption identifier include apiSign, and the apiSign is a signature. The generation process of the apiSign specifically includes the following steps: The application system obtains the apiSignKey issued by the enterprise side and sends the apiSignKey into the encryption / decryption toolkit. The apiSignKey is pre-sent by the encryption / decryption server to the enterprise side through a private channel; The encryption / decryption toolkit obtains the apiSignKey and adds the corresponding timestamp and random number to obtain a signature factor set; Use a signature encryption method to encrypt the signature factor set to generate the corresponding apiSign; The encryption / decryption server verifies the encryption identifier or decryption identifier, including the following steps: The encryption / decryption server calls the myapiSignKey corresponding to the apiSignKey in the application system; The encryption / decryption server decodes the apiSign to obtain a signature factor set, obtains the timestamp and random number in the signature factor set, and adds the timestamp and random number to the myapiSignKey to obtain a verification signature factor set; Encrypt the verification signature factor set using a signature encryption method to generate a corresponding myapiSign, and compare the myapiSign with the apiSign; If the myapiSign is equal to the apiSign, the verification passes.

7. A computer storage medium, on which a computer program is stored, characterized in that, when the computer program is executed by a processor, it implements the data encryption and decryption method of the multi-tenant model according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Identity-based closed key management method and system

    CN107948156A

  • Method and system for provision of cryptographic services

    US20120131354A1