Key backup method, key recovery method, and system

By obtaining key backup requests from the key management service, identifying and backing up key resources and their metadata information, the problem of key data loss caused by user misoperation is solved, ensuring data security and a reliable key recovery process.

CN115292088BActive Publication Date: 2026-05-19ALIBABA CLOUD COMPUTING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ALIBABA CLOUD COMPUTING CO LTD
Filing Date
2022-07-25
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In key management services, high-risk user actions can lead to the deletion of key data, rendering data encryption and decryption operations unusable. Furthermore, existing technologies struggle to accurately recover the correct key version, posing a data security risk.

Method used

By obtaining the key backup request corresponding to the dedicated KMS instance, the current key resources are determined, backup operations are performed, and storage metadata information is associated to ensure that the key version can be accurately selected during recovery.

Benefits of technology

This effectively avoids data security issues caused by incorrect recovery key versions, ensuring the security, reliability, and usability of data access operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115292088B_ABST
    Figure CN115292088B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a key backup method, a key recovery method and a system, which are applied to a key management service (KMS) console, the KMS console is in communication connection with a special KMS, the special KMS comprises a special KMS instance; the key backup method comprises the following steps: obtaining a key backup request corresponding to the special KMS instance; determining current key resources corresponding to the special KMS instance based on the key backup request; performing a backup operation on the current key resources to obtain backup key resources and metadata information corresponding to the backup key resources; and storing the backup key resources and the metadata information in association. The technical scheme provided by the embodiment realizes the backup operation of the key in combination with the metadata information, and then the user can determine the key resources to be recovered through the metadata information, so that the problem of unsafe data processing caused by the error recovery of the key resources can be avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, and in particular to a key backup method, a key recovery method, and a system. Background Technology

[0002] Key Management Service (KMS) is a one-stop platform for key management and data encryption. Because it provides simple, reliable, secure, and compliant data encryption protection capabilities, KMS can significantly reduce users' costs in purchasing, maintaining, and developing cryptographic infrastructure and data encryption / decryption products, allowing users to focus solely on data processing. However, during the use and management of keys through KMS, human error may occur, leading to accidental key deletion. This can easily render encrypted data online or encrypted data from cloud products unusable.

[0003] To address the issue of data encryption and decryption being impossible due to key data deletion caused by high-risk user actions, a solution for key backup and recovery has been proposed. This solution involves directly displaying multiple key backup versions, from which the user can then select one for recovery. However, the large number of key versions can make it difficult for users to accurately identify the correct backup version to recover. Incorrectly selecting a backup version could lead to greater risks to online data security. Summary of the Invention

[0004] This invention provides a key backup method, a key recovery method, and a system that can effectively avoid data security problems caused by incorrect key resource version recovery.

[0005] In a first aspect, embodiments of the present invention provide a key backup method applied to a Key Management Service (KMS) control console, wherein the KMS control console is communicatively connected to a dedicated KMS, and the dedicated KMS includes a dedicated KMS instance; the method includes:

[0006] Obtain the key backup request corresponding to the dedicated KMS instance;

[0007] Based on the key backup request, determine the current key resources corresponding to the dedicated KMS instance;

[0008] Perform a backup operation on the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource;

[0009] The backup key resources are associated with and stored with the metadata information.

[0010] Secondly, embodiments of the present invention provide a key backup device applied to a Key Management Service (KMS) control console, wherein the KMS control console is communicatively connected to a dedicated KMS, and the dedicated KMS includes a dedicated KMS instance; the device includes:

[0011] The first acquisition module is used to acquire a key backup request corresponding to the dedicated KMS instance;

[0012] The first determining module is used to determine the current key resource corresponding to the dedicated KMS instance based on the key backup request;

[0013] The first processing module is used to perform a backup operation on the current key resource to obtain the backup key resource and metadata information corresponding to the backup key resource.

[0014] The first sending module is used to associate and store the backup key resources with the metadata information.

[0015] Thirdly, embodiments of the present invention provide an electronic device, including: a memory and a processor; wherein the memory is used to store one or more computer instructions, wherein the one or more computer instructions, when executed by the processor, implement the key backup method in the first aspect described above.

[0016] Fourthly, embodiments of the present invention provide a computer storage medium for storing a computer program, which, when executed by a computer, implements the key backup method described in the first aspect above.

[0017] Fifthly, embodiments of the present invention provide a computer program product, comprising: a computer program that, when executed by a processor of an electronic device, causes the processor to perform the steps of the key backup method described in the first aspect.

[0018] Sixthly, embodiments of the present invention provide a key recovery method applied to a Key Management Service (KMS) control console, wherein the KMS control console is communicatively connected to a dedicated KMS, and the dedicated KMS includes a dedicated KMS instance; the method includes:

[0019] Obtain the backup metadata corresponding to the dedicated KMS instance;

[0020] Based on the target backup metadata in the backup metadata, determine the backup resources to be restored corresponding to the dedicated KMS instance;

[0021] The dedicated KMS instance is updated based on the backup resources to be restored to obtain the restored key resources;

[0022] The key corresponding to the dedicated KMS instance is recovered based on the recovered key resources.

[0023] In a seventh aspect, embodiments of the present invention provide a key recovery device applied to a Key Management Service (KMS) control console, wherein the KMS control console is communicatively connected to a dedicated KMS, and the dedicated KMS includes a dedicated KMS instance; the device includes:

[0024] The second acquisition module is used to acquire backup metadata corresponding to the dedicated KMS instance.

[0025] The second determination module is used to determine the backup resources to be restored corresponding to the dedicated KMS instance based on the target backup metadata in the backup metadata.

[0026] The second update module is used to update the dedicated KMS instance based on the backup resources to be restored, and obtain the restored key resources;

[0027] The second processing module is used to recover the key corresponding to the dedicated KMS instance based on the recovered key resources.

[0028] Eighthly, embodiments of the present invention provide an electronic device, including: a memory and a processor; wherein the memory is used to store one or more computer instructions, wherein the one or more computer instructions, when executed by the processor, implement the key recovery method in the sixth aspect above.

[0029] Ninthly, embodiments of the present invention provide a computer storage medium for storing a computer program that, when executed by a computer, implements the key recovery method described in the sixth aspect above.

[0030] In a tenth aspect, embodiments of the present invention provide a computer program product, comprising: a computer program that, when executed by a processor of an electronic device, causes the processor to perform the steps of the key recovery method described in the sixth aspect.

[0031] Eleventhly, embodiments of the present invention provide a key backup system, including: a Key Management Service (KMS) control console and a dedicated KMS, wherein the KMS control console is communicatively connected to the dedicated KMS, and the dedicated KMS includes a dedicated KMS instance;

[0032] The KMS management console is used to obtain a key backup request corresponding to the dedicated KMS instance; determine the current key resource corresponding to the dedicated KMS instance based on the key backup request; perform a backup operation on the current key resource to obtain the backup key resource and metadata information corresponding to the backup key resource; and send the backup key resource and the metadata information to the dedicated KMS.

[0033] The dedicated KMS is used to associate and store the backup key resources with the metadata information.

[0034] The technical solution provided in this embodiment obtains a key backup request corresponding to a dedicated KMS instance, then determines the current key resource corresponding to the dedicated KMS instance based on the key backup request, performs a backup operation on the current key resource, obtains the backup key resource and the metadata information corresponding to the backup key resource, and then stores the backup key resource and metadata information together. This effectively realizes the backup operation of the key resource by combining metadata information. Since the metadata information corresponding to different versions of the key resource being backed up is different, when a key recovery operation is required, the user can determine the detailed information of the key resource through the metadata information. This can reduce or even completely avoid the situation where the user mistakenly selects the key version to be recovered, thereby avoiding data security problems caused by incorrect key resource version recovery. This effectively ensures the security and reliability of data access operations and further improves the practicality of the method. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 A schematic diagram illustrating a key backup method provided in an embodiment of the present invention;

[0037] Figure 2 A flowchart illustrating a key backup method provided in an embodiment of the present invention;

[0038] Figure 3 A flowchart illustrating another key backup method provided in an embodiment of the present invention;

[0039] Figure 4 A flowchart illustrating another key backup method provided in an embodiment of the present invention;

[0040] Figure 5 This is a flowchart illustrating a key recovery method provided in an embodiment of the present invention;

[0041] Figure 6 A flowchart illustrating another key recovery method provided in an embodiment of the present invention;

[0042] Figure 7 Signaling diagram of a key backup method provided for an application embodiment of the present invention;

[0043] Figure 8 Signaling diagram of a key recovery method provided in an application embodiment of the present invention;

[0044] Figure 9 This is a schematic diagram of the structure of a key backup device provided in an embodiment of the present invention;

[0045] Figure 10 To and Figure 9 A schematic diagram of the electronic device corresponding to the key backup device provided in the illustrated embodiment;

[0046] Figure 11 This is a schematic diagram of a key recovery device provided in an embodiment of the present invention;

[0047] Figure 12 To and Figure 11 A schematic diagram of the electronic device corresponding to the key recovery device provided in the illustrated embodiment;

[0048] Figure 13 This is a schematic diagram of a key backup system provided in an embodiment of the present invention. Detailed Implementation

[0049] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0050] The terminology used in the embodiments of this invention is for the purpose of describing particular embodiments only and is not intended to limit the invention. The singular forms “a,” “the,” and “the” used in the embodiments of this invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. “Multiple” generally includes at least two, but does not exclude the inclusion of at least one.

[0051] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0052] Depending on the context, the words “if” or “suppose” as used here can be interpreted as “when” or “in response to determination” or “in response to detection.” Similarly, depending on the context, the phrases “if determination” or “if detection (of the stated condition or event)” can be interpreted as “when determination” or “in response to determination” or “when detection (of the stated condition or event)” or “in response to detection (of the stated condition or event).”

[0053] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a product or system comprising a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a product or system. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the product or system that includes said element.

[0054] Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.

[0055] Terminology definition:

[0056] Dedicated KMS: A cloud-based private key management service exclusively for the user. Users have complete control over their own dedicated KMS, enabling data encryption and cloud product integration. The key processing and storage resources of the dedicated KMS are exclusively available to each user, and network communication is also a dedicated network link for the user.

[0057] Shared KMS: A one-stop key management and data encryption service platform for users, providing simple, reliable, secure, and compliant data encryption protection capabilities. Shared KMS uses a multi-user shared mode for key processing and storage resources, and also shares network links for network communication.

[0058] CloudHSM encryption service uses hardware cryptographic machines certified by the State Cryptography Administration as the underlying service layer. Through virtualization technology, it helps users meet regulatory compliance requirements for data security and protect the security of data on the cloud. With this encryption service, users can securely and reliably manage keys and use various encryption algorithms to reliably encrypt and decrypt data.

[0059] To facilitate understanding of the specific implementation process of the technical solution in this embodiment, the relevant technologies are explained below: Key Management Service (KMS) is a one-stop key management and data encryption service platform. Because it provides simple, reliable, secure, and compliant data encryption protection capabilities, KMS can significantly reduce the procurement, maintenance, and R&D costs of cryptographic infrastructure and data encryption / decryption products, allowing users to focus solely on the data processing operation itself. During the use and management of keys through the Key Management Service, human error may occur, leading to accidental key deletion. This can easily render encrypted data online or cloud product encrypted data unusable. Furthermore, during key recovery based on encryption machine instance backups, the encryption machine instance cannot provide external services, which significantly impacts its availability.

[0060] To address the aforementioned technical issues, this embodiment provides a key backup method, a key recovery method, and a system. The execution entity of the key backup method can be a key backup device, which can be implemented as a KMS control console or a server. The server or KMS control console can be communicatively connected to a client or a requesting end to perform the key backup operation.

[0061] For details, please refer to the appendix. Figure 1 As shown, the client can be any computing device with a certain data transmission capability. Specifically, the basic structure of the client can include at least one processor. The number of processors depends on the client's configuration and type. The client can also include memory, which can be volatile, such as RAM, or non-volatile, such as read-only memory (ROM), flash memory, etc., or both types can be included simultaneously. The memory typically stores the operating system (OS), one or more applications, and may also store program data. In addition to the processing unit and memory, the client also includes some basic configurations, such as a network interface card (NIC) chip, I / O bus, display components, and some peripheral devices. Optionally, some peripheral devices may include, for example, a keyboard, mouse, pen, printer, etc. Other peripheral devices are well known in the art and will not be described in detail here.

[0062] A server is a device that provides key management services in a network virtual environment, typically referring to a device that uses a network for information planning and key backup operations. Physically, a server can be any device capable of providing computing services, responding to service requests, and processing them; examples include cluster servers, regular servers, cloud servers, cloud hosts, and virtual data centers. The main components of a server include a processor, hard drive, memory, and system bus, similar to a general computer architecture.

[0063] In the above embodiment, the server can establish a network connection with the client, which can be a wireless or wired network connection. If the server and client are connected via a communication network, the mobile network standard can be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+ (LTE+), WiMax, 5G, 6G, etc.

[0064] Specifically, when a user needs key backup, the user can generate a key backup request through the client and send it to the key backup device. The key backup device then obtains the key backup request corresponding to the dedicated KMS instance. Since the key backup request is used to perform a backup operation on the current key resource corresponding to the dedicated KMS instance, the current key resource corresponding to the dedicated KMS instance can be determined based on the key backup request, and a backup operation can be performed on the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource. Then, the backup key resource and the metadata information can be associated and stored, thus realizing the key backup operation.

[0065] The technical solution provided in this embodiment obtains a key backup request corresponding to a dedicated KMS instance, then determines the current key resource corresponding to the dedicated KMS instance based on the key backup request, and backs up the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource. The backup key resource and the metadata information are then stored together, effectively realizing the backup operation of the key resource by combining the metadata information. Since the metadata information corresponding to different versions of the key resource being backed up is different, when a key recovery operation is needed, the user can determine the detailed information of the key resource through the metadata information. Therefore, it avoids the problem of incorrect key resource version recovery due to the user's incorrect selection of the key version to be recovered, which could lead to data security issues, thus ensuring the security and reliability of data processing.

[0066] The following detailed description of some embodiments of the present invention is provided in conjunction with the accompanying drawings. Where there is no conflict between the embodiments, the following embodiments and features can be combined with each other. Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.

[0067] Figure 2 This is a flowchart illustrating a key backup method provided in an embodiment of the present invention; see attached diagram. Figure 2 As shown, this embodiment provides a key backup method. The execution subject of this method can be a key backup device. It is understood that the key backup device can be implemented as software, or a combination of software and hardware. Specifically, the key backup device can be implemented as a Key Management Service (KMS) control console, that is, this method can be applied to the Key Management Service (KMS) control console. The KMS control console has a communication connection to a dedicated KMS, which includes one or more dedicated KMS instances. In this case, the key backup method can include the following steps:

[0068] Step S201: Obtain the key backup request corresponding to the dedicated KMS instance.

[0069] Step S202: Based on the key backup request, determine the current key resources corresponding to the dedicated KMS instance.

[0070] Step S203: Perform a backup operation on the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource.

[0071] Step S204: Associate and store the backup key resources with metadata information.

[0072] The following is a detailed explanation of each of the above steps:

[0073] Step S201: Obtain the key backup request corresponding to the dedicated KMS instance.

[0074] In the process of data encryption and decryption using a dedicated KMS instance, to ensure the security and reliability of data encryption and decryption, the dedicated KMS often generates multiple versions of key information. That is, different key information is generated for different data encryption and decryption operations. Therefore, the dedicated KMS contains multiple versions of key information. To ensure the stable operation of data encryption and decryption, key administrators periodically clean up the key information in the dedicated KMS. Since deleted key information may require key recovery later, key backups should be performed before cleaning up the key information.

[0075] Specifically, key backup operations can be automatic or user-controlled. For example, if a dedicated KMS is configured to perform automatic key cleanup at a fixed period (e.g., weekly, monthly, 2-monthly, or 3-monthly), then a key backup operation needs to be performed automatically before key cleanup. Alternatively, when a user manually cleans up the key information in the dedicated KMS, the user must first perform a manual key backup operation. As can be seen, key backup requests can be obtained in two ways: one is automatically generated by the key backup device. In this case, obtaining a key backup request corresponding to the dedicated KMS instance can include: automatically generating a key backup request in response to a preset key backup period. The other is obtained through user-inputted operations. In this case, obtaining a key backup request corresponding to the dedicated KMS instance can include: displaying an interactive interface corresponding to the dedicated KMS instance, obtaining the user's input operations in the interactive interface, and generating a key backup request based on the operations to perform a key backup operation on the dedicated KMS instance.

[0076] Step S202: Based on the key backup request, determine the current key resources corresponding to the dedicated KMS instance.

[0077] For a key backup device, a single key backup device may include multiple dedicated KMS instances. To accurately perform key backup operations, after receiving a key backup request, the current key resource corresponding to the dedicated KMS instance can be determined based on the key backup request. Specifically, this embodiment does not limit the specific implementation method for determining the current key resource. In some instances, the key backup request includes the identification information of the dedicated KMS instance. Based on the identification information of the dedicated KMS instance, the dedicated KMS instance corresponding to the key backup request is determined. Since there is an association between the dedicated KMS instance and the corresponding current key resource, the current key resource corresponding to the dedicated KMS instance can be searched in the database, thereby effectively achieving accurate and reliable determination of the current key resource.

[0078] In other instances, a dedicated KMS may include dedicated KMS instances of different specifications, and different specifications of dedicated KMS instances may correspond to different types of key resources. Therefore, the current key resources can be determined based on the specifications corresponding to the dedicated KMS instance. In this case, determining the current key resources corresponding to the dedicated KMS instance based on the key backup request may include: determining the specification information corresponding to the dedicated KMS instance based on the key backup request; and determining the current key resources corresponding to the dedicated KMS instance based on the specification information.

[0079] After receiving a key backup request, the request can be analyzed to determine the specification information corresponding to the dedicated KMS instance. In some instances, the specification information of the dedicated KMS instance may be related to its attributes. In this case, determining the specification information of the dedicated KMS instance based on the key backup request may include: obtaining the attribute information corresponding to the dedicated KMS instance based on the key backup request; and determining the specification information of the dedicated KMS instance based on the attribute information. For example, the attribute information may include a preset first attribute and a second attribute. In this case, determining the specification information of the dedicated KMS instance based on the attribute information may include: when the attribute information is the first attribute, where the first attribute can be an identifier or specification information corresponding to a standard-specification dedicated KMS instance, then the dedicated KMS instance is determined to be of standard specification; when the attribute information is the second attribute, where the second attribute can be an identifier or specification information corresponding to a basic-specification dedicated KMS instance, then the dedicated KMS instance is determined to be of basic specification.

[0080] It should be noted that the type of current key resource corresponds to different specifications of dedicated KMS instances. For example, for a standard-specification dedicated KMS instance, its corresponding key resource can be an encryption service cluster resource, while for a basic-specification dedicated KMS instance, its corresponding key resource can be a database instance resource. Therefore, determining the current key resource corresponding to a dedicated KMS instance based on the specification information can include: when the dedicated KMS instance is of standard specification, the corresponding current key resource is determined to be an encryption service cluster; when the dedicated KMS instance is of basic specification, the corresponding current key resource is determined to be a database instance.

[0081] Step S203: Perform a backup operation on the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource.

[0082] After determining the current key resource, a backup operation can be performed on the current key resource, thereby obtaining the backup key resource and the corresponding metadata information. This metadata information can include information related to the backup key resource, such as: the type of the backup key resource, the time information of the backup key resource, the specification information of the backup key resource, etc. The existence of metadata information allows users to filter and view the corresponding backup key resources.

[0083] Furthermore, this embodiment does not limit the method of obtaining metadata information. In some instances, when performing a backup operation on the current key resource, the backup key resource can be obtained first, and then metadata information can be automatically generated based on the backup key resource. In other instances, when performing a backup operation on the current key resource, the backup key resource and metadata information can be obtained simultaneously. In this case, the metadata information corresponds to the current key resource, and there is an association between the backup key resource and the current key resource. Therefore, the obtained metadata information also corresponds to the backup key resource.

[0084] In some other instances, metadata information can be obtained based on a dedicated KMS instance. In this case, performing a backup operation on the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource may include: performing a backup operation on the current key resource to obtain the backup key resource; generating the current key metadata corresponding to the dedicated KMS instance; and generating the metadata information corresponding to the backup key resource based on the current key metadata and the backup key resource.

[0085] During the backup operation of the current key resource, the key backup device can generate current key metadata corresponding to the dedicated KMS instance. This current key metadata corresponds to the current key resource. Then, based on the current key metadata and the backup key resource, metadata information corresponding to the backup key resource can be generated. In some instances, a machine learning model for generating metadata information is pre-trained. After obtaining the current key metadata and the backup key resource, these can be input into the machine learning model to obtain the metadata information output by the machine learning model, which corresponds to the backup key resource.

[0086] In other instances, since the current key metadata is generated based on the current key resource, and the backup key resource is obtained by backing up the current key resource, theoretically, the backup key resource is identical to the current key resource. Therefore, the current key metadata should also correspond to the backup key resource. In this case, the key metadata can be directly identified as the metadata information corresponding to the backup key resource. However, due to the complexity of the network environment, various factors may arise during backup operations or data processing, leading to errors in the results. This could result in a mismatch between the current key metadata and the backup key resource. To avoid this, after obtaining the current key metadata and the backup key resource, they can be analyzed and processed to determine more accurate metadata information based on the analysis results. Specifically, generating metadata information corresponding to the backup key resource based on the current key metadata and the backup key resource may include: detecting whether the current key metadata corresponds to the backup key resource; if the current key metadata corresponds to the backup key resource, then determining the current key metadata as the metadata information corresponding to the backup key resource; if the current key metadata does not correspond to the backup key resource, then performing a backup operation on the current key resource again until the current key metadata corresponds to the backup key resource, and then determining the current key metadata as the metadata information corresponding to the backup key resource.

[0087] After obtaining the current key metadata and backup key resources, it's possible to first check if the current key metadata corresponds to the backup key resources. In some instances, this check might include: obtaining the theoretical key resources corresponding to the current key metadata; checking if the theoretical key resources are the same as the backup key resources; if they are the same, then the current key metadata corresponds to the backup key resources; if they are different, then they do not correspond. In other instances, this check might include: obtaining the theoretical metadata corresponding to the backup key resources; checking if the current key metadata is the same as the theoretical metadata; if they are the same, then the current key metadata corresponds to the backup key resources; if they are different, then they do not correspond.

[0088] If the current key metadata corresponds to the backup key resource, the backup operation is normal, and the current key metadata can be directly identified as the metadata information corresponding to the backup key resource. If the current key metadata does not correspond to the backup key resource, it indicates that an anomaly occurred during the key backup process. In this case, to ensure the quality and effectiveness of the key backup, the current key resource can be backed up again to obtain a new backup key resource. Then, the above operation is repeated, that is, checking whether the new backup key resource corresponds to the current key metadata, until the current key metadata corresponds to the backup key resource. This effectively realizes the acquisition of metadata information and corresponding backup key resources. Furthermore, since the metadata information at this time is generated by combining the backup key resource and the current key metadata corresponding to the current key resource before the backup operation, the obtained metadata information is more accurate and reliable.

[0089] Step S204: Associate and store the backup key resources with metadata information.

[0090] After obtaining the backup key resources and metadata information, in order to ensure the security and reliability of the backup key resources, the backup key resources and metadata information can be sent to the database in the dedicated KMS for associated storage, thus realizing the entire process of backup key operation.

[0091] In addition, in order to enable users to understand the progress of the key backup operation in a timely manner, after associating and storing the backup key resources and metadata information, the method in this embodiment may further include: generating a prompt message to indicate that the key backup operation has been completed, and displaying the prompt message through a display module, so that users can quickly and timely understand the status or progress of the key backup operation through the prompt message, further improving the user experience.

[0092] The key backup method provided in this embodiment obtains a key backup request corresponding to a dedicated KMS instance, then determines the current key resource corresponding to the dedicated KMS instance based on the key backup request, performs a backup operation on the current key resource, obtains the backup key resource and the metadata information corresponding to the backup key resource, and then stores the backup key resource and metadata information together. This effectively realizes the key resource backup operation combined with metadata information. Since the metadata information corresponding to different versions of key resources are different, when a key recovery operation is required, the user can determine the detailed information of the key resource through the metadata information. This can reduce or even completely avoid the situation where the user mistakenly selects the key version to be recovered, thereby avoiding data security problems caused by incorrect key resource version recovery. This effectively ensures the security and reliability of data access operations and further improves the practicality of the method.

[0093] Figure 3 This is a flowchart illustrating another key backup method provided by an embodiment of the present invention; based on the above embodiments, refer to the appendix. Figure 3 As shown, during the key resource backup process, all management operations on all key information in the dedicated KMS can be disabled to prevent key resources under management from failing to perform normal backup operations, thereby ensuring the consistency between the key resources and the current resources corresponding to the dedicated KMS instance. Specifically, before determining the current key resources corresponding to the dedicated KMS instance based on the key backup request, the method in this embodiment may further include:

[0094] Step S301: Determine all key information corresponding to the dedicated KMS instance.

[0095] Step S302: Adjust the key management mode corresponding to all key information to the disabled state. The key management mode is used to implement the management and control operation of key information.

[0096] In the process of key management services through a dedicated KMS instance, users can perform two types of management operations on the keys corresponding to the dedicated KMS instance: one is key control operations, such as generating, updating, modifying, and deleting keys—operations related to the key's lifecycle; the other is data computation or storage operations based on the key, such as encryption / decryption operations or key storage. Since key-based data computation or storage operations do not change the key information, these operations do not need to be stopped during key backup. However, key control operations will change the key information; to ensure key backup consistency, control operations on key information must be stopped during the key backup process.

[0097] Based on the above statements, to ensure the consistency of key backups, before determining the current key resources corresponding to the dedicated KMS instance based on the key backup request, all key information corresponding to the dedicated KMS instance can be determined first. Specifically, all associated key information can be determined based on the identification information of the dedicated KMS instance. For any key information usage operation, two modes are pre-configured: a controlled mode for managing key information and a non-controlled mode for performing computational and storage operations on key information. Since key information does not change in non-controlled mode but does change in controlled mode, to ensure that the key resources after key backup are consistent with the current key resources corresponding to the dedicated KMS instance, the key control mode corresponding to all key information can be disabled. That is, during key backup, users are prohibited from performing any management operations on the key information corresponding to the dedicated KMS instance, such as modifying, deleting, editing, or generating the key information. This helps ensure the stability and reliability of key backups.

[0098] Corresponding to the above implementation, after associating and storing the backup key resources and metadata information, the method in this embodiment may further include adjusting the key management status corresponding to all key information to the usage status. Specifically, the method may further include:

[0099] Step S301: Determine all key information corresponding to the dedicated KMS instance.

[0100] Step S302: Adjust the key management mode corresponding to all key information to the usage state. The key management mode is used to implement the management and control operations of key information.

[0101] Specifically, when the backup key resources and metadata information are sent to the database in the dedicated KMS for associated storage, it indicates that the key backup operation has been completed. At this time, for the dedicated KMS instance, the management mode of all keys may still be in a disabled state. In order to enable users to manage key information normally, all key information corresponding to the dedicated KMS instance can be identified, and then the key management mode corresponding to all key information can be adjusted to the enabled state. That is, users can normally perform management operations such as generating, changing, and deleting key information. This effectively ensures that users can perform key management service operations in a timely and effective manner, further improving the practicality of the method.

[0102] In this embodiment, before determining the current key resource corresponding to the dedicated KMS instance based on the key backup request, the key management mode corresponding to all key information is adjusted to a disabled state. This effectively ensures that the data of the key backup operation is consistent with the current key resource corresponding to the dedicated KMS instance, further improving the quality and effectiveness of the key backup operation. It should be noted that users can still perform data encryption and decryption operations based on the key information at this time, that is, the key backup operation does not affect the availability of the encryption machine instance. In addition, after associating and storing the backup key resource with the metadata information, the key management mode corresponding to all key information is adjusted to a usable state. This effectively enables users to perform normal key management operations immediately after the key backup operation is completed, further improving the efficiency of key management operations and ensuring the flexibility and reliability of the method.

[0103] Figure 4 This is a flowchart illustrating another key backup method provided by an embodiment of the present invention; based on any of the above embodiments, refer to the appendix. Figure 4 As shown, after associating and storing the backup key resources and metadata information, this embodiment provides a method for performing key recovery operations based on the backup key resources, which may specifically include:

[0104] Step S401: Obtain the backup metadata corresponding to the dedicated KMS instance.

[0105] When a user needs to recover a key for a specific dedicated KMS instance, this instance often corresponds to multiple versions of key information. Different key information corresponds to different backup metadata, which includes relevant information corresponding to the key information. Users can obtain the specific key resource information by viewing the backup metadata. Therefore, backup metadata helps users select the correct key recovery version. To ensure the accuracy and reliability of the key recovery operation, the backup metadata corresponding to the dedicated KMS instance can be obtained first. There can be one or more backup metadata sets, typically multiple sets, each used to identify different key resources.

[0106] Furthermore, this embodiment does not limit the specific implementation method for obtaining backup metadata. In some instances, the backup metadata can be stored in a database or preset area within a dedicated KMS or shared KMS. The backup metadata corresponding to the dedicated KMS instance can be obtained by accessing the database or preset area. In other instances, the backup metadata can be stored in a third device connected to the dedicated KMS communication connection. The backup metadata corresponding to the dedicated KMS instance can be obtained actively or passively through the third device.

[0107] Step S402: Based on the backup metadata, determine the backup resources to be restored corresponding to the dedicated KMS instance.

[0108] Since backup metadata is used to identify information related to key backup resources, after obtaining the backup metadata, analyzing and processing it can determine the backup resources to be restored corresponding to the dedicated KMS instance. In some instances, the backup resources to be restored can be automatically determined. In this case, determining the backup resources to be restored corresponding to the dedicated KMS instance based on the backup metadata can include: determining the time information corresponding to each key backup resource based on one or more backup metadata; and identifying the key backup resource with the closest time information (i.e., the last key resource used for the dedicated KMS instance) as the backup resources to be restored. In other instances, the backup resources to be restored can be manually determined by the user. In this case, determining the backup resources to be restored corresponding to the dedicated KMS instance based on the backup metadata can include: displaying all backup metadata, obtaining the user's input operations on the backup metadata, determining the backup metadata to be restored based on the executed operations, and determining the backup resources to be restored corresponding to the dedicated KMS instance based on the backup metadata to be restored, thereby effectively ensuring that the backup resources to be restored can meet the user's usage needs.

[0109] Step S403: Based on the backup resources to be restored, establish an intermediate key resource in the shared KMS corresponding to the dedicated KMS instance.

[0110] After obtaining the backup resource to be restored, the key resource can be restored based on the backup resource. Since the backup resource to be restored is the resource corresponding to the dedicated KMS instance, and the access security requirements of the dedicated KMS are high, and the key resource restoration operation often takes a period of time, in order to ensure the stability and reliability of the key resource restoration, an intermediate key resource corresponding to the dedicated KMS instance can be established in the shared KMS based on the backup resource to be restored. This intermediate key resource is the same as the backup resource to be restored.

[0111] Step S404: Update the dedicated KMS instance based on the intermediate key resource to obtain the recovered key resource.

[0112] Since the intermediate key resource is stored in the shared KMS, in order to restore the key resource of the dedicated KMS instance in the dedicated KMS, the dedicated KMS instance can be updated based on the intermediate key resource. Specifically, the dedicated KMS instance can be updated using a rolling upgrade method to obtain the restored key resource, which is stored in the dedicated KMS. The rolling upgrade method ensures that the dedicated KMS service on the user side remains available during the recovery process, further improving the practicality of this technical solution.

[0113] Step S405: Recover the key corresponding to the dedicated KMS instance based on the recovered key resources.

[0114] Since the key corresponding to the dedicated KMS instance is related to the recovered key resource, after obtaining the recovered key resource, the key corresponding to the dedicated KMS instance can be restored based on the recovered key resource, thereby effectively realizing stable key restoration based on backup metadata.

[0115] In this embodiment, the backup resource to be restored corresponding to the dedicated KMS instance is determined based on the obtained backup metadata. An intermediate key resource corresponding to the dedicated KMS instance is established in the shared KMS based on the backup resource to be restored. The dedicated KMS instance is then updated based on the intermediate key resource to obtain the restored key resource. Subsequently, the key corresponding to the dedicated KMS instance is restored based on the restored key resource. This effectively realizes a stable key restoration operation based on backup metadata, avoiding the problem that users may incorrectly select the key backup version for restoration due to their inability to accurately locate the key backup version to be restored, which could lead to greater online risks. This further improves the practicality of the method and is conducive to market promotion and application.

[0116] Figure 5 This is a flowchart illustrating a key recovery method provided in an embodiment of the present invention; see attached diagram. Figure 5 As shown, this embodiment provides a key recovery method. The execution subject of this method can be a key recovery device. It is understood that the key recovery device can be implemented as software, or a combination of software and hardware. Specifically, the key recovery device can be implemented as a Key Management Service (KMS) control console, meaning this method can be applied to the KMS control console. The KMS control console has a communication connection to a dedicated KMS, which includes a dedicated KMS instance. In this case, the key recovery method can include the following steps:

[0117] Step S501: Obtain the backup metadata corresponding to the dedicated KMS instance.

[0118] Step S502: Based on the target backup metadata in the backup metadata, determine the backup resources to be restored corresponding to the dedicated KMS instance.

[0119] Step S503: Update the dedicated KMS instance based on the backup resources to be restored to obtain the restored key resources.

[0120] Step S504: Recover the key corresponding to the dedicated KMS instance based on the recovered key resources.

[0121] The following is a detailed explanation of each of the above steps:

[0122] Step S501: Obtain the backup metadata corresponding to the dedicated KMS instance.

[0123] For a dedicated KMS instance, there are multiple versions of backup key resources. Different versions of backup key resources have different time and resource information, and each backup key resource has different backup metadata. This backup metadata is used to identify the relevant information of the backup key resource. When a user needs to recover a key for a specific dedicated KMS instance, since a dedicated KMS instance often corresponds to multiple versions of key information (e.g., different key information for different data processing periods, and different data to be processed may also correspond to different key information), and different key information can correspond to different key resource information, and different key resource information can correspond to different metadata, thus multiple pre-backed-up backup key resources can exist. For these pre-backed-up backup key resources, users can obtain detailed information about the specific backup key resources by viewing the backup metadata. This backup metadata helps users select the correct version of the backup key resource for recovery.

[0124] As described above, since backup metadata helps users select the correct version of the backup key resource for recovery, to ensure the accuracy and reliability of the key recovery operation, the backup metadata corresponding to the dedicated KMS instance can be obtained first. Specifically, this embodiment does not limit the specific implementation method for obtaining backup metadata. In some instances, the backup metadata can be stored in a database or preset area within the dedicated KMS or shared KMS, and the backup metadata corresponding to the dedicated KMS instance can be obtained by accessing the database or preset area. In other instances, the backup metadata can be stored in a third device connected to the dedicated KMS communication connection, and the backup metadata corresponding to the dedicated KMS instance can be obtained actively or passively through the third device.

[0125] In some instances, the number of backup metadata obtained can be one, that is, the obtained backup metadata corresponds to the backup resource to be restored. In this case, the backup metadata can be obtained based on the user's selection operation. Specifically, in this embodiment, obtaining the backup metadata corresponding to the dedicated KMS instance can include: obtaining a key recovery request; displaying multiple backup metadata corresponding to the dedicated KMS instance based on the key recovery request; and selecting one backup metadata for key recovery operation from the multiple backup metadata in response to the user's data selection operation.

[0126] Specifically, since the key recovery device may include multiple backup metadata, in order to accurately perform key recovery operations, after obtaining the key recovery request, multiple backup metadata corresponding to the dedicated KMS instance can be displayed based on the key recovery request. Different backup metadata correspond to different key backup resources. Then, the user can input an operation on any of the displayed backup metadata, such as viewing or selecting. After obtaining the user's input data selection operation, the backup metadata corresponding to the data selection operation can be used as the backup metadata for key recovery operations. This effectively enables the determination of the specification information of the key resource to be recovered based on the user's selection, thereby avoiding the data insecurity problem caused by the user's inability to select the recovery version of the key resource in the current implementation.

[0127] Step S502: Based on the target backup metadata in the backup metadata, determine the backup resources to be restored corresponding to the dedicated KMS instance.

[0128] Since backup metadata is used to identify information related to key backup resources, after obtaining the backup metadata, the target backup metadata is determined through analysis and processing. Then, based on the target backup metadata, the backup resource to be restored corresponding to the dedicated KMS instance can be determined. In some instances, the backup resource to be restored can be automatically determined. In this case, determining the backup resource to be restored corresponding to the dedicated KMS instance based on the target backup metadata can include: determining the time information corresponding to each key backup resource based on the target backup metadata; and identifying the key backup resource with the closest time information (i.e., the key resource version used for the dedicated KMS instance) as the backup resource to be restored. In other instances, the backup resource to be restored can be manually determined by the user. In this case, determining the backup resource to be restored corresponding to the dedicated KMS instance based on the target backup metadata can include: displaying all backup metadata, obtaining the user's input operations on the backup metadata, determining the target backup metadata based on the executed operations, and determining the backup resource to be restored corresponding to the dedicated KMS instance based on the target backup metadata, thereby effectively ensuring that the backup resource to be restored meets the user's needs.

[0129] In some instances, dedicated KMS instances can correspond to different specification information, such as standard specification type or basic specification type. Since dedicated KMS instances with different specification information can correspond to different types of backup resources to be restored, the specific type of backup resource to be restored can be determined based on the specification information of the dedicated KMS instance. Specifically, determining the backup resource to be restored corresponding to the dedicated KMS instance based on backup metadata can include: determining the specification information corresponding to the dedicated KMS instance; and determining the backup resource to be restored corresponding to the dedicated KMS instance based on the specification information and backup metadata.

[0130] Specifically, during the key recovery process, the specification information corresponding to the dedicated KMS instance can be determined first. In some instances, the specification information of the dedicated KMS instance may be related to its attributes. In this case, determining the specification information of the dedicated KMS instance may include: obtaining the attribute information corresponding to the dedicated KMS instance; and determining the specification information of the dedicated KMS instance based on the attribute information. For example, the attribute information may include a preset first attribute or a second attribute. In this case, determining the specification information of the dedicated KMS instance based on the attribute information may include: if the attribute information is the first attribute, then the dedicated KMS instance is determined to be of standard specification; if the attribute information is the second attribute, then the dedicated KMS instance is determined to be of basic specification.

[0131] It should be noted that the types of key resources corresponding to dedicated KMS instances of different specifications are different. For example, for a standard-specification dedicated KMS instance, its corresponding key resource can be an encryption service cluster resource, while for a basic-specification dedicated KMS instance, its corresponding key resource can be a database instance resource. In this case, determining the backup resource to be restored corresponding to the dedicated KMS instance based on the specification information and backup metadata can include: when the specification information is standard, the backup resource to be restored corresponding to the dedicated KMS instance is an encryption service cluster; when the specification information is basic, the backup resource to be restored corresponding to the dedicated KMS instance is a database instance.

[0132] Step S503: Update the dedicated KMS instance based on the backup resources to be restored to obtain the restored key resources.

[0133] After obtaining the backup resources to be restored, the key resources can be restored based on the backup resources. Specifically, the dedicated KMS instance can be updated based on the backup resources to be restored, that is, the current resources corresponding to the dedicated KMS instance are updated to the backup resources to be restored, thereby obtaining the restored key resources.

[0134] Furthermore, during the key resource recovery process, since the backup resource to be recovered is a key resource corresponding to a dedicated KMS instance, and dedicated KMS has high access security requirements, and key resource recovery often takes time, in order to ensure the stability and reliability of key resource recovery, an intermediate key resource corresponding to the dedicated KMS instance can be first established in the shared KMS based on the backup resource to be recovered. This intermediate key resource is identical to the backup resource to be recovered. Then, updating the dedicated KMS instance based on the backup resource to be recovered to obtain the recovered key resource can include: establishing an intermediate key resource corresponding to the dedicated KMS instance in the shared KMS based on the backup resource to be recovered; and updating the dedicated KMS instance based on the intermediate key resource to obtain the recovered key resource.

[0135] Specifically, since the intermediate key resource is stored in the shared KMS, in order to restore the key resource of the dedicated KMS instance in the dedicated KMS, the dedicated KMS instance can be updated based on the intermediate key resource. Specifically, the dedicated KMS instance can be updated using a rolling upgrade method to obtain the restored key resource, which is stored in the dedicated KMS. The rolling upgrade method for updating the dedicated KMS instance ensures that the dedicated KMS service on the user side remains available during the recovery process, further improving the practicality of this technical solution.

[0136] Furthermore, since the backup resources to be restored may correspond to a standard-specification dedicated KMS instance or a basic-specification dedicated KMS instance, and different specifications of dedicated KMS correspond to different types of resource information, the obtained intermediate key resources may also correspond to different types. Specifically, based on the backup resources to be restored, establishing intermediate key resources corresponding to the dedicated KMS instance in the shared KMS may include: when the dedicated KMS instance is of standard specification, establishing an intermediate encryption service cluster corresponding to the dedicated KMS instance in the shared KMS based on the image of the backup encryption service cluster; when the dedicated KMS instance is of basic specification, establishing an intermediate database instance corresponding to the dedicated KMS instance in the shared KMS based on the backup database.

[0137] In some instances, after establishing an intermediate key resource corresponding to a dedicated KMS instance in a shared KMS based on the backup resource to be restored, the method in this embodiment may further include storing the intermediate encryption resource in a database in the shared KMS to facilitate user management of the intermediate key resource.

[0138] Step S504: Recover the key corresponding to the dedicated KMS instance based on the recovered key resources.

[0139] Since the key corresponding to the dedicated KMS instance is related to the recovered key resource, after obtaining the recovered key resource, the key corresponding to the dedicated KMS instance can be restored based on the recovered key resource, thereby effectively realizing stable key restoration based on backup metadata.

[0140] In some other instances, after recovering the key corresponding to the dedicated KMS instance based on the recovered key resources, in order to enable users to promptly understand the key recovery status information, the method in this embodiment may further include: generating prompt information corresponding to the key recovery operation to indicate whether the key recovery operation was successful or completed, and displaying the prompt information. For example, if the key recovery operation fails, a first prompt information may be generated and displayed; if the key recovery operation succeeds, a second prompt information may be generated and displayed.

[0141] It should be noted that, in order to further ensure the stable operation of the key recovery method, before determining the backup resources to be recovered corresponding to the dedicated KMS instance based on the backup metadata, the method in this embodiment may further include: determining all key information corresponding to the dedicated KMS instance; adjusting the key management mode corresponding to all key information to a disabled state, wherein the key management mode is used to implement management operations on key information.

[0142] Similarly, after recovering the key corresponding to the dedicated KMS instance based on the recovered key resources, in order to enable users to perform key-related operations in a timely and fast manner, the method in this embodiment may further include: determining all key information corresponding to the dedicated KMS instance; adjusting the key management mode corresponding to all key information to the usage state, wherein the key management mode is used to implement management operations on key information.

[0143] Specifically, in this embodiment, the implementation processes of "adjusting the key management mode corresponding to all key information to a disabled state" and "adjusting the key management mode corresponding to all key information to a enabled state" are the same as those described above. Figure 3 The specific implementation methods of the corresponding embodiments are similar, and you can refer to the above description for details, which will not be repeated here.

[0144] The key recovery method provided in this embodiment determines the backup resource to be recovered corresponding to the dedicated KMS instance based on the obtained backup metadata, updates the dedicated KMS instance based on the backup resource to be recovered to obtain the recovered key resource, and recovers the key corresponding to the dedicated KMS instance based on the recovered key resource. This effectively realizes a stable key recovery operation based on backup metadata, avoiding the problem that users may incorrectly select the key backup version for recovery due to their inability to accurately locate the key backup version to be recovered, which may lead to greater online risks. This further improves the practicality of the method and is conducive to market promotion and application.

[0145] Figure 6 This is a flowchart illustrating another key recovery method provided in an embodiment of the present invention; based on the above embodiments, refer to the appendix. Figure 6 As shown, during the process of updating a dedicated KMS instance based on intermediate key resources, data update anomalies may occur. In this case, the recovered key resource obtained may differ from the intermediate key resource. If the key recovery operation is performed directly based on the recovered key resource, incorrect recovery may occur. Therefore, to avoid the above situation, after updating the dedicated KMS instance based on intermediate key resources and obtaining the recovered key resource, the method in this embodiment further includes:

[0146] Step S601: Obtain the current key metadata corresponding to the dedicated KMS instance.

[0147] Step S602: If the current key metadata does not correspond to the recovered key resource, then the key recovery operation is prohibited.

[0148] Step S603: If the current key metadata corresponds to the recovered key resource, then the key recovery operation is allowed.

[0149] In the process of updating a dedicated KMS instance based on intermediate key resources, since the metadata corresponding to the intermediate key resources is known, the metadata update operation can be performed synchronously or asynchronously. Thus, for the dedicated KMS instance, the key metadata update process and the key resource update process are two independent processes. To avoid key recovery errors due to anomalies during the intermediate key resource update process, after obtaining the recovered key resources, it is possible to check for anomalies in the resource update operation based on the intermediate key resources. In this case, the current key metadata corresponding to the dedicated KMS instance can be obtained first. The obtained current key metadata can be based on the metadata of the intermediate key resources. Theoretically, when the key resource update operation is normal, the obtained current key metadata will correspond to the recovered key resources obtained after the update operation; however, when the key resource update operation is abnormal, the obtained recovered key may be a part of the intermediate key resources, meaning the current key metadata does not correspond to the recovered key resources. Therefore, the anomaly of the key resource update process can be detected by checking whether the current key metadata corresponds to the recovered key resource. Specifically, if the current key metadata does not correspond to the recovered key resource, it indicates an anomaly in the key resource update process. In this case, to ensure the normal operation of key recovery, the key recovery operation is prohibited. If the current key metadata corresponds to the recovered key resource, it indicates that the key resource update process is not abnormal, and a normal key recovery operation can be performed, thus allowing the key recovery operation to proceed.

[0150] In some other instances, after updating the dedicated KMS instance based on the intermediate key resource and obtaining the recovered key resource, in order to avoid interference from the historical key resource on the key recovery operation and to reduce the data footprint, the historical key resource can be deleted after obtaining the new recovered key resource. Specifically, the method in this embodiment may also include:

[0151] Step S701: Obtain the historical key resources corresponding to the dedicated KMS instance before performing the recovery operation.

[0152] Step S702: Delete the historical key resources.

[0153] Specifically, after obtaining the recovered key resources, it means that the key resource update operation has been completed. At this time, for the dedicated KMS instance, it includes the historical key resources before the recovery operation and the recovered key resources after the recovery operation. Since the historical key resources cannot perform any service operations, in order to reduce the space occupied by data resources and avoid the historical key resources interfering with the key information recovery operation, the historical key resources can be deleted, which further improves the stability and reliability of the method.

[0154] In this embodiment, by obtaining the current key metadata corresponding to the dedicated KMS instance, if the current key metadata does not correspond to the recovered key resource, the key recovery operation is prohibited; if the current key metadata corresponds to the recovered key resource, the key recovery operation is allowed, thereby effectively ensuring the normal operation of the key recovery operation and further improving the stability and reliability of the method.

[0155] In specific applications, this application embodiment provides a method for key backup and key recovery based on a key service management system. The execution subject of this method can be a key service management system (KMS). This KMS system can effectively solve the following problems: (1) Since user keys are the basic resources for users to encrypt data in the cloud, and the current key data backup is based on the backup capability of the HSM image layer, users cannot know the specific key metadata information in the key backup and choose a more effective backup time point, which leads to users being unable to accurately locate the key backup version that needs to be restored. Incorrectly selecting the backup version for recovery may lead to greater risks online. In addition, due to user misoperation and other reasons, key resources may be irreversibly deleted. Therefore, it is necessary to provide a method to perform a full backup of user key resources before high-risk operations, and to use the backup image to restore keys after problems occur, so as to ensure that user encrypted data will not be unable to be decrypted due to high-risk operations. (2) There is a risk of data leakage of user key data backup information. Once user key data backup information is leaked, it may lead to the risk of leakage of user online encrypted data.

[0156] Based on the above considerations, the key backup and key recovery methods provided in this application embodiment enable users to view key metadata information in the key backup during the key recovery process. This allows users to quickly determine the version of the backup to restore, avoiding the restoration of incorrect backup versions and preventing more serious online problems. Furthermore, during the user key recovery process, the user-side key service should be kept as uninterrupted as possible or have minimal downtime. This ensures that even if issues such as accidental key deletion occur, the original key data can be promptly restored through key data backup, guaranteeing normal online key usage for users. Specifically, the execution entity of the key backup and key recovery methods in this embodiment can be the KMS management console in the KMS system. This KMS management console has communication connections with a dedicated KMS and a shared KMS, and the dedicated KMS includes a dedicated KMS instance. (See attached document.) Figure 7 As shown, the key backup method in this application embodiment may include the following steps:

[0157] Step 1: The user initiates a key backup request to the designated dedicated KMS instance through the KMS management console.

[0158] Users can proactively initiate a key backup request for a specified dedicated KMS instance through the KMS console. This key backup request can include the identification information of the dedicated KMS instance.

[0159] Step 2: Disable all key management operations under the user's dedicated KMS instance in the KMS management console.

[0160] All key management operations can include at least one of the following: key generation, key update, key deletion, key modification, etc. It is important to note that key management operations do not include data encryption / decryption based on the key, key storage, or other operations unrelated to the key's lifecycle.

[0161] Step 3: The KMS management console returns a backup task to the user, accepting the specified dedicated KMS instance.

[0162] Because key backup operations involve a large amount of data, the backup process may take 10 to 30 minutes. This could result in the KMS management console receiving another key backup task for the dedicated KMS instance after the KMS backup operation has already been performed. In this case, the KMS management console will not accept the backup task for the specified dedicated KMS instance again and can generate a prompt message to inform the user that a key backup operation is already in progress and therefore the backup task cannot be accepted.

[0163] Step 4: The KMS management console begins executing the backup task for the specified dedicated KMS instance.

[0164] Step 5: The KMS management console calls the preset OpenAPI to create a backup for the specified dedicated KMS instance and records the relevant backup information. If the dedicated KMS instance is the standard version, it calls the encryption service management OpenAPI to create a backup of the current encryption machine instance (i.e., the encryption service cluster); if the dedicated KMS instance is the basic version, it calls the database management OpenAPI to create a backup of the current database instance.

[0165] After receiving a key backup request from the KMS management console, the system can obtain attribute information corresponding to the dedicated KMS instance based on the request. This attribute information allows the system to identify whether the dedicated KMS instance is a basic or standard version. For a standard version dedicated KMS instance, key management services are implemented through an encryption machine cluster. For a basic version dedicated KMS instance, there is no encryption machine cluster; instead, key management services are implemented through software (i.e., a database instance). Compared to the basic version, the standard version of dedicated KMS instance meets compliance and national cryptographic requirements. Furthermore, the initialization process for the basic version of dedicated KMS instance is simpler and more convenient than that for the standard version. In practice, users can freely choose the specifications of their dedicated KMS instance according to their needs.

[0166] Step 6: Query the key metadata information of the currently specified dedicated KMS instance in the KMS management console.

[0167] Since a dedicated KMS instance contains multiple key information entries, and different key information entries can correspond to different metadata information, a dedicated KMS instance will contain multiple metadata entries. To accurately perform key backup operations, the key metadata information in the current dedicated KMS instance can be queried. Specifically, the KMS control console can display all key metadata information, and users can then view all the key metadata information and select the key metadata information they want to back up.

[0168] It is important to note that after querying the key metadata information, you can match the key metadata information with the key resources backed up in step 5. If the key metadata information does not correspond to the key resources, the backup operation should be performed again until they match. If the key metadata information corresponds to the key resources, you can proceed to the next step.

[0169] Step 7: The KMS management console saves the instance backup information and key metadata information as backup information to the dedicated KMS database.

[0170] Step 8: Enable the use of management APIs for the key of the specified dedicated KMS instance in the KMS management console.

[0171] Step 9: The KMS management console notifies the user that the backup task for the designated dedicated KMS instance has been completed.

[0172] Additionally, please refer to the appendix. Figure 8 As shown, the key recovery method may include the following steps:

[0173] Step 11: Users can view the backup metadata information (including key metadata information in each backup) of a specified dedicated KMS instance through the KMS management console, and select a specified backup version to perform backup and recovery.

[0174] After receiving a user's key backup request from the KMS management console, the user's identity can be authenticated first. Only after confirming that the user is a legitimate user will the user be allowed to view and select operations on the backup metadata information of the dedicated KMS instance.

[0175] Step 12: The KMS control console disables all key management operations performed by the user under this dedicated KMS instance.

[0176] Step 13: The KMS management console returns a backup and recovery task to the user for the specified dedicated KMS instance.

[0177] Step 14: The KMS management console begins executing the backup and recovery task for the specified dedicated KMS instance.

[0178] Step 15: The KMS management console calls the preset OpenAPI to back up and restore the specified dedicated KMS instance, recording relevant backup information. If the dedicated KMS instance is the standard version, it calls the Encryption Service Management OpenAPI to create a brand new encryption service cluster, and restores the specified backup through Encryption Service Management, recording relevant information; if the dedicated KMS instance is the base version, it calls the Database Management OpenAPI to create a brand new database instance using the specified backup, and records relevant information.

[0179] When the dedicated KMS instance is the standard version, the backup is of the encrypted service cluster. At this time, a backup image of the encrypted service cluster can be obtained. When restoring, a brand new encrypted service cluster can be created based on the backup image of the encrypted service cluster. The newly created encrypted service cluster is the same as the backup image, thus realizing the image restoration operation.

[0180] Step 16: The KMS control console saves the information of the new and innovative instances (including a brand new encrypted service cluster or a brand new database instance) to the database in the shared KMS.

[0181] Step 17: The KMS management console calls the key operation node management service to upgrade the user's dedicated KMS instance located in the dedicated KMS through a rolling upgrade method. The upgraded dedicated KMS instance will load the key metadata information from the backup.

[0182] In addition, when users query relevant information through the database in the dedicated KMS, the aforementioned relevant information will also be loaded into the cache. Therefore, after updating the instance information in the dedicated KMS using the instance information in the database in the shared KMS, the backed-up data can also be loaded into the cache to facilitate data querying for users.

[0183] Step 18: The KMS management console queries the key metadata information backed up by the specified dedicated KMS instance to ensure that the key metadata information is consistent with the instance information restored by the dedicated KMS instance.

[0184] Step 19: Once the key metadata matches the instance information in the dedicated KMS, the KMS control console will restore the instance backup information to the database in the dedicated KMS.

[0185] Step 20: Enable the use of management APIs for keys of the specified dedicated KMS instance in the dedicated KMS management console of the Key Service.

[0186] Step 21: The KMS management console notifies the user that the backup and recovery task for the designated dedicated KMS instance has been completed.

[0187] Step 22: The KMS management console deletes the encryption service cluster or database instance that the dedicated KMS instance depended on before the recovery, and then uses it to perform key recovery operations based on the recovered encryption service cluster or database instance.

[0188] The technical solution provided in this application embodiment enables dedicated KMS backup and recovery to view key metadata information, ensuring that users can clearly understand the backup key data information and select the most suitable key backup for recovery. This avoids users restoring to an incorrect key backup due to opaque key information in the key backup, thus preventing online issues for users. Furthermore, it implements a dedicated KMS backup and recovery technical solution based on the system's OpenAPI, effectively avoiding the problem of user key encryption data being undecryptable due to user error. Specifically, the dedicated KMS standard version performs mirror backup and recovery of the encryption machine associated with the dedicated KMS instance through the OpenAPI on the encryption service management side, thereby achieving dedicated KMS key backup and recovery; the dedicated KMS basic version performs database instance backup and recovery of the database instance associated with the dedicated KMS instance through the OpenAPI on the database management side, thereby achieving dedicated KMS key backup and recovery. In addition, a backup and recovery process was implemented that ensures the user-specific KMS service remains available throughout the key backup and recovery process. This solves the problem of the key management service being unavailable during key backup and recovery. Specifically, during the key backup and recovery process, rolling upgrades are used to perform key recovery operations on the dedicated KMS. This ensures that the user-side dedicated KMS service remains available throughout the recovery process, further improving the practicality of the technical solution and facilitating its promotion and application in the market.

[0189] Figure 9 This is a schematic diagram of a key backup device provided in an embodiment of the present invention; see attached diagram. Figure 9 As shown, this embodiment provides a key backup device that can perform the above-described... Figure 2 The key backup method shown can be implemented in a way that the key backup device can be applied to a Key Management Service (KMS) control console. The KMS control console has a communication connection to a dedicated KMS, which includes a dedicated KMS instance. Specifically, the key backup device may include:

[0190] The first acquisition module 11 is used to acquire the key backup request corresponding to the dedicated KMS instance;

[0191] The first determining module 12 is used to determine the current key resource corresponding to the dedicated KMS instance based on the key backup request;

[0192] The first processing module 13 is used to perform a backup operation on the current key resource and obtain the backup key resource and the metadata information corresponding to the backup key resource.

[0193] The first sending module 14 is used to associate and store backup key resources with metadata information.

[0194] In some instances, when the first determining module 12 determines the current key resources corresponding to the dedicated KMS instance based on the key backup request, the first determining module 12 is used to perform: determining the specification information corresponding to the dedicated KMS instance based on the key backup request; and determining the current key resources corresponding to the dedicated KMS instance based on the specification information.

[0195] In some instances, when the first determining module 12 determines the current key resource corresponding to the dedicated KMS instance based on the specification information, the first determining module 12 is used to perform the following: when the dedicated KMS instance is of standard specification, the current key resource corresponding to the dedicated KMS instance is determined to be an encryption service cluster; when the dedicated KMS instance is of basic specification, the current key resource corresponding to the dedicated KMS instance is determined to be a database instance.

[0196] In some instances, before determining the current key resource corresponding to the dedicated KMS instance based on the key backup request, the first determining module 12 and the first processing module 13 are respectively used to perform the following steps:

[0197] The first determining module 12 is used to determine all key information corresponding to the dedicated KMS instance;

[0198] The first processing module 13 is used to adjust the key management mode corresponding to all key information to a disabled state. The key management mode is used to implement the management and control operation of key information.

[0199] In some instances, when the first processing module 13 performs a backup operation on the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource, the first processing module 13 is used to perform: perform a backup operation on the current key resource to obtain the backup key resource; generate the current key metadata corresponding to the dedicated KMS instance; and generate the metadata information corresponding to the backup key resource based on the current key metadata and the backup key resource.

[0200] In some instances, when the first processing module 13 generates metadata information corresponding to the backup key resource based on the current key metadata and the backup key resource, the first processing module 13 is used to perform the following: detect whether the current key metadata corresponds to the backup key resource; if the current key metadata corresponds to the backup key resource, then determine the current key metadata as the metadata information corresponding to the backup key resource; if the current key metadata does not correspond to the backup key resource, then perform a backup operation on the current key resource again until the current key metadata corresponds to the backup key resource, and then determine the current key metadata as the metadata information corresponding to the backup key resource.

[0201] In some instances, after associating and storing the backup key resources with metadata information, the first determining module 12 and the first processing module 13 in this embodiment are respectively used to perform the following steps:

[0202] The first determining module 12 is used to determine all key information corresponding to the dedicated KMS instance;

[0203] The first processing module 13 is used to adjust the key management mode corresponding to all key information to the usage state. The key management mode is used to implement the management and control operation of key information.

[0204] In some instances, after the backup key resources and metadata information are associated and stored, the first acquisition module 11, the first determination module 12, and the first processing module 13 in this embodiment are respectively used to perform the following steps:

[0205] The first acquisition module 11 is used to acquire backup metadata corresponding to the dedicated KMS instance;

[0206] The first determination module 12 is used to determine the backup resources to be restored corresponding to the dedicated KMS instance based on the backup metadata;

[0207] The first processing module 13 is used to establish an intermediate key resource corresponding to the dedicated KMS instance in the shared KMS based on the backup resource to be restored; update the dedicated KMS instance based on the intermediate key resource to obtain the restored key resource; and restore the key corresponding to the dedicated KMS instance based on the restored key resource.

[0208] Figure 9 The device shown can perform Figures 1-4 , Figure 7 For the methods shown in the embodiments, the parts not described in detail in this embodiment can be referred to the following: Figures 1-4 , Figure 7 The illustrated embodiment is described below. For the execution process and technical effects of this technical solution, please refer to [link / reference]. Figures 1-4 , Figure 7 The descriptions in the illustrated embodiments will not be repeated here.

[0209] In one possible design, Figure 9 The key backup device shown can be implemented as an electronic device, which can be a server, a key management service (KMS) control console, or other devices. When the electronic device is a KMS control console, the KMS control console has a dedicated KMS communication connection, which includes a dedicated KMS instance, such as... Figure 10 As shown, the electronic device may include a first processor 21 and a first memory 22. The first memory 22 is used to store data executed by the corresponding electronic device. Figures 1-4 , Figure 7 In the illustrated embodiment, the key backup method program is configured to execute a program stored in the first memory 22.

[0210] The program includes one or more computer instructions, wherein when the one or more computer instructions are executed by the first processor 21, they can perform the following steps: obtain a key backup request corresponding to the dedicated KMS instance; determine the current key resource corresponding to the dedicated KMS instance based on the key backup request; perform a backup operation on the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource; and associate and store the backup key resource and the metadata information.

[0211] Furthermore, the first processor 21 is also used to perform the aforementioned Figures 1-4 , Figure 7 All or part of the steps in the illustrated embodiments. The electronic device may also include a first communication interface 23 for communication between the electronic device and other devices or communication networks.

[0212] In addition, embodiments of the present invention provide a computer storage medium for storing computer software instructions used by an electronic device, which includes instructions for executing the above-described... Figures 1-4 , Figure 7 The procedure involved in the key backup method in the illustrated embodiment.

[0213] Furthermore, embodiments of the present invention provide a computer program product, comprising: a computer program, which, when executed by a processor of an electronic device, causes the processor to perform... Figures 1-4 , Figure 7 The key backup method in the illustrated embodiment.

[0214] Figure 11 This is a schematic diagram of a key recovery device provided in an embodiment of the present invention; see attached diagram. Figure 11 As shown, this embodiment provides a key recovery device that can perform the above-described... Figure 5 The key recovery method shown can be implemented using a Key Management Service (KMS) control console. The KMS control console has a dedicated KMS connection, which includes a dedicated KMS instance. Specifically, the key recovery device may include:

[0215] The second acquisition module 31 is used to acquire backup metadata corresponding to the dedicated KMS instance.

[0216] The second determination module 32 is used to determine the backup resources to be restored corresponding to the dedicated KMS instance based on the target backup metadata in the backup metadata.

[0217] The second update module 33 is used to update the dedicated KMS instance based on the backup resources to be restored, and obtain the restored key resources;

[0218] The second processing module 34 is used to recover the key corresponding to the dedicated KMS instance based on the recovered key resources.

[0219] In some instances, when the second update module 33 updates the dedicated KMS instance based on the backup resources to be restored and obtains the restored key resources, the second update module 33 performs the following: based on the backup resources to be restored, establishes an intermediate key resource corresponding to the dedicated KMS instance in the shared KMS; and updates the dedicated KMS instance based on the intermediate key resource to obtain the restored key resources.

[0220] In some instances, when the second acquisition module 31 acquires backup metadata corresponding to the dedicated KMS instance, the second acquisition module 31 is used to perform: acquire a key recovery request; display multiple backup metadata corresponding to the dedicated KMS instance based on the key recovery request; and select one backup metadata for key recovery operation from the multiple backup metadata in response to the user's data selection operation.

[0221] In some instances, when the second determining module 32 determines the backup resources to be restored corresponding to the dedicated KMS instance based on the backup metadata, the second determining module 32 is used to perform: determining the specification information corresponding to the dedicated KMS instance; and determining the backup resources to be restored corresponding to the dedicated KMS instance based on the specification information and the backup metadata.

[0222] In some instances, when the second determining module 32 determines the backup resource to be restored corresponding to the dedicated KMS instance based on the specification information and backup metadata, the second determining module 32 is used to perform the following: when the specification information is standard specification, the backup resource to be restored corresponding to the dedicated KMS instance is determined to be an encrypted service cluster based on the backup metadata; when the specification information is basic specification, the backup resource to be restored corresponding to the dedicated KMS instance is determined to be a database instance based on the backup metadata.

[0223] In some instances, when the second update module 33 establishes an intermediate key resource corresponding to the dedicated KMS instance in the shared KMS based on the backup resource to be restored, the second update module 33 is used to perform the following: when the dedicated KMS instance is of standard specification, an intermediate encryption service cluster corresponding to the dedicated KMS instance is established in the shared KMS based on the image of the backup encryption service cluster; when the dedicated KMS instance is of basic specification, an intermediate database instance corresponding to the dedicated KMS instance is established in the shared KMS based on the backup database.

[0224] In some instances, after updating the dedicated KMS instance based on the intermediate key resource and obtaining the recovered key resource, the second acquisition module 31 and the second processing module 34 perform the following steps:

[0225] The second acquisition module 31 is used to acquire the current key metadata corresponding to the dedicated KMS instance;

[0226] The second processing module 34 is used to prohibit key recovery operations if the current key metadata does not correspond to the recovered key resources, and to allow key recovery operations if the current key metadata corresponds to the recovered key resources.

[0227] In some instances, after updating the dedicated KMS instance based on the intermediate key resource and obtaining the recovered key resource, the second acquisition module 31 and the second processing module 34 perform the following steps:

[0228] The second acquisition module 31 is used to acquire historical key resources corresponding to the dedicated KMS instance before the recovery operation is performed;

[0229] The second processing module 34 is used to delete historical key resources.

[0230] Figure 11 The device shown can perform Figures 5-6 , Figure 8 For the methods shown in the embodiments, the parts not described in detail in this embodiment can be referred to the following: Figures 5-6 , Figure 8 The illustrated embodiment is described below. For the execution process and technical effects of this technical solution, please refer to [link / reference]. Figures 5-6 , Figure 8 The descriptions in the illustrated embodiments will not be repeated here.

[0231] In one possible design, Figure 11 The key recovery device shown can be implemented as an electronic device, which can be various devices such as a server key management service (KMS) control console. When the electronic device is a KMS control console, the KMS control console has a dedicated KMS communication connection, and the dedicated KMS includes a dedicated KMS instance. Figure 12 As shown, the electronic device may include a second processor 41 and a second memory 42. The second memory 42 is used to store data executed by the corresponding electronic device. Figures 5-6 , Figure 8 In the illustrated embodiment, the key recovery method program includes a second processor 41 configured to execute a program stored in a second memory 42.

[0232] The program includes one or more computer instructions, wherein when the one or more computer instructions are executed by the second processor 41, they can perform the following steps: obtain backup metadata corresponding to the dedicated KMS instance; determine the backup resource to be restored corresponding to the dedicated KMS instance based on the target backup metadata in the backup metadata; update the dedicated KMS instance based on the backup resource to be restored to obtain the restored key resource; and restore the key corresponding to the dedicated KMS instance based on the restored key resource.

[0233] Furthermore, the second processor 41 is also used to perform the aforementioned Figures 5-6 , Figure 8 All or part of the steps in the illustrated embodiments. The electronic device may also include a second communication interface 43 for communication between the electronic device and other devices or communication networks.

[0234] In addition, embodiments of the present invention provide a computer storage medium for storing computer software instructions used by an electronic device, which includes instructions for executing the above-described... Figures 5-6 , Figure 8 The procedure involved in the key recovery method in the illustrated embodiment.

[0235] Furthermore, embodiments of the present invention provide a computer program product, comprising: a computer program, which, when executed by a processor of an electronic device, causes the processor to perform... Figures 5-6 , Figure 8 The key recovery method in the illustrated embodiment.

[0236] Figure 13 This is a schematic diagram of a key backup system provided in an embodiment of the present invention, with reference to the appendix. Figure 13 As shown, this embodiment provides a key backup system that can achieve the above-mentioned... Figures 1-4 The key backup operation shown can be specifically described as follows: the key backup system may include a key management service KMS control console 51 and a dedicated KMS 52. The KMS control console 51 and the dedicated KMS 52 are connected in communication. The dedicated KMS 52 includes a dedicated KMS instance.

[0237] KMS control console 51 is used to obtain key backup requests corresponding to the dedicated KMS instance; based on the key backup requests, determine the current key resources corresponding to the dedicated KMS instance; perform backup operations on the current key resources to obtain the backup key resources and the metadata information corresponding to the backup key resources; and send the backup key resources and metadata information to the dedicated KMS 52.

[0238] Dedicated KMS 52 is used to associate and store backup key resources with metadata information.

[0239] Figure 13 The specific implementation principle, implementation method, and implementation effect of the KMS control console 51 in the system shown are the same as those described above. Figures 1-4 The specific implementation principles, methods, and effects of the steps in the corresponding embodiments are similar, and can be found in the above descriptions, which will not be repeated here. Additionally, the system in this embodiment can also execute... Figures 1-4 , Figure 7 For the methods shown in the embodiments, the parts not described in detail in this embodiment can be referred to the following: Figures 1-4 , Figure 7 The illustrated embodiment is described below. For the execution process and technical effects of this technical solution, please refer to [link / reference]. Figures 1-4 , Figure 7 The descriptions in the illustrated embodiments will not be repeated here.

[0240] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0241] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of a necessary general-purpose hardware platform, or by a combination of hardware and software. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a computer product. The present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0242] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1The computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The functions specified in one or more boxes. These computer program instructions may also be loaded onto a computer or other programmable device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0243] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory. Memory may include non-persistent storage in computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media. Computer-readable media includes both permanent and non-persistent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information that can be accessed by the computing device. As defined in this article, computer-readable media do not include transient media, such as modulated data signals and carrier waves.

[0244] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A key backup method, characterized in that, The method is applied to a Key Management Service (KMS) control console, wherein the KMS control console has a communication connection to a dedicated KMS, and the dedicated KMS includes a dedicated KMS instance; the method includes: Obtain the key backup request corresponding to the dedicated KMS instance; Determine all key information corresponding to the dedicated KMS instance; Adjust the key management mode corresponding to all key information to the disabled state. The key management mode is used to implement the management operation of key information. Based on the key backup request, determine the current key resources corresponding to the dedicated KMS instance; Perform a backup operation on the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource; The backup key resources are associated with and stored with the metadata information.

2. The method according to claim 1, characterized in that, Based on the key backup request, determine the current key resources corresponding to the dedicated KMS instance, including: Based on the key backup request, determine the specification information corresponding to the dedicated KMS instance; Based on the specification information, the current key resources corresponding to the dedicated KMS instance are determined.

3. The method according to claim 2, characterized in that, Based on the specification information, the current key resources corresponding to the dedicated KMS instance are determined, including: When the dedicated KMS instance is of standard specification, the current key resource corresponding to the dedicated KMS instance is determined to be an encryption service cluster; When the dedicated KMS instance is the basic specification, the current key resource corresponding to the dedicated KMS instance is determined to be the database instance.

4. The method according to any one of claims 1-3, characterized in that, Perform a backup operation on the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource, including: Perform a backup operation on the current key resource to obtain a backup key resource; Generate the current key metadata corresponding to the dedicated KMS instance; Based on the current key metadata and the backup key resource, generate metadata information corresponding to the backup key resource.

5. The method according to claim 4, characterized in that, Based on the current key metadata and the backup key resource, generate metadata information corresponding to the backup key resource, including: Detect whether the current key metadata corresponds to the backup key resource; When the current key metadata corresponds to the backup key resource, the current key metadata is determined to be the metadata information corresponding to the backup key resource; If the current key metadata does not correspond to the backup key resource, the current key resource is backed up again until the current key metadata corresponds to the backup key resource, and the current key metadata is determined as the metadata information corresponding to the backup key resource.

6. A key recovery method, characterized in that, The method is applied to a Key Management Service (KMS) control console, wherein the KMS control console has a communication connection to a dedicated KMS, and the dedicated KMS includes a dedicated KMS instance; the method includes: Obtain the backup metadata corresponding to the dedicated KMS instance; Determine all key information corresponding to the dedicated KMS instance; Set all key management modes corresponding to key information to disabled state. Key management mode is used to implement management operations on key information. Based on the target backup metadata in the backup metadata, determine the backup resources to be restored corresponding to the dedicated KMS instance; The dedicated KMS instance is updated based on the backup resources to be restored to obtain the restored key resources; The key corresponding to the dedicated KMS instance is recovered based on the recovered key resources.

7. The method according to claim 6, characterized in that, The dedicated KMS instance is updated based on the backup resources to be restored to obtain the restored key resources, including: Based on the backup resources to be restored, an intermediate key resource corresponding to the dedicated KMS instance is established in the shared KMS; The dedicated KMS instance is updated based on the intermediate key resource to obtain the recovered key resource.

8. The method according to claim 6, characterized in that, Based on the backup metadata, determine the backup resources to be restored corresponding to the dedicated KMS instance, including: Determine the specification information corresponding to the dedicated KMS instance; Based on the specification information and the backup metadata, the backup resources to be restored corresponding to the dedicated KMS instance are determined.

9. The method according to claim 8, characterized in that, Based on the specification information and the backup metadata, determine the backup resources to be restored corresponding to the dedicated KMS instance, including: When the specification information is a standard specification, the backup resource to be restored corresponding to the dedicated KMS instance is determined to be an encrypted service cluster based on the backup metadata. When the specification information is the basic specification, the backup resource to be restored corresponding to the dedicated KMS instance is determined to be a database instance based on the backup metadata.

10. The method according to claim 7, characterized in that, After updating the dedicated KMS instance based on the intermediate key resource to obtain the recovered key resource, the method further includes: Obtain the current key metadata corresponding to the dedicated KMS instance; If the current key metadata does not correspond to the recovered key resource, then key recovery operations are prohibited. If the current key metadata corresponds to the recovered key resource, then the key recovery operation is permitted.

11. A key backup system, characterized in that, include: The Key Management Service (KMS) console and the dedicated KMS are connected in communication. The dedicated KMS includes a dedicated KMS instance. The KMS control console is used to obtain key backup requests corresponding to the dedicated KMS instance; Determine all key information corresponding to the dedicated KMS instance; Adjust the key management mode corresponding to all key information to the disabled state. The key management mode is used to implement the management operation of key information. Based on the key backup request, determine the current key resources corresponding to the dedicated KMS instance. Perform a backup operation on the current key resource to obtain the backup key resource and the metadata information corresponding to the backup key resource; Send the backup key resources and the metadata information to the dedicated KMS; The dedicated KMS is used to associate and store the backup key resources with the metadata information.