Password service calling method and system
By adopting a one-machine-one-cryptographic key management method in the cryptographic machine cluster, and using the first cryptographic machine to decrypt and encrypt the master key, the security problem exposed by the master key of the cryptographic machine cluster in the prior art is solved, and the security of the key is significantly improved.
Patent Information
- Application Number
- CN202211004678.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-22
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2042-08-22
AI Technical Summary
Since all cipher machines need to maintain the same master key in existing cipher machines, if the master key of one cipher machine is cracked, the master key of the entire cluster may be exposed, causing security issues in key management.
By storing the master key cipher text of each working cipher machine in the key storage submodule, and using the first cipher machine to decrypt the master key when needed, the user key is encrypted and sent to the corresponding working cipher machine for decryption, a one-machine-one-secret key management is realized.
The need for all password machines to maintain the same master key improves the security of the working password machine key, thereby enhancing the security of the entire set of password services.
Smart Images

Figure CN115378592B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cryptographic machines, can be used in the financial field, and in particular to a cryptographic service calling method and system. Background Art
[0002] A cipher machine is a cryptographic device used to ensure data security. It can mainly implement cryptographic service functions such as data encryption, trans-encryption, decryption, Media Access Control (MAC) generation and verification, and signature verification.
[0003] At present, the cipher machine stores the master key, which protects the working key, and the working key protects the user key, thus forming a three-layer key system with the cipher machine as the main part. Due to the requirements of the security system, a cipher machine cluster is generally required to consist of multiple models and multiple cipher machines, but due to the requirement that the cipher machine stores the master key, all cipher machines need to maintain the same master key. In this way, if the master key of a model or a key machine is cracked by technology or there are problems in human management, the master key of the cipher machine will be exposed, which will cause the master keys of all cipher machines to be exposed, making the security of key management highly dependent on the security of the cipher machine, causing key security issues for the entire encryption machine cluster. Summary of the invention
[0004] In view of this, the present invention provides a cryptographic service calling method and system to solve at least one of the above-mentioned problems.
[0005] In order to achieve the above object, the present invention adopts the following scheme:
[0006] According to a first aspect of the present invention, a cryptographic service calling method is provided, the method comprising: receiving a cryptographic service calling request issued by a cryptographic service caller, the cryptographic service calling request comprising a user key identifier, a cryptographic service identifier and data to be operated; obtaining a user key plaintext according to the user key identifier; selecting a working cryptographic machine information from the key storage submodule, the working cryptographic machine information comprising a working cryptographic machine identifier and a corresponding master key ciphertext, calling a first cryptographic machine, decrypting the master key ciphertext with a first key of the first cryptographic machine to obtain a master key; encrypting the user key plaintext into a first user key ciphertext with the master key, and sending the first user key ciphertext to a corresponding working cryptographic machine according to the working cryptographic machine identifier, the corresponding working cryptographic machine using its own master key to decrypt the first user ciphertext into a user key, and performing corresponding operations on the data to be operated with the user key according to the cryptographic service identifier.
[0007] According to a second aspect of the present invention, there is provided a cryptographic service calling system, the system comprising: a cryptographic service scheduling module, a key management module and a working cryptographic machine cluster, wherein the key management module further comprises a key storage submodule, the cryptographic service scheduling module is used to receive a cryptographic service calling request issued by a cryptographic service caller, the cryptographic service calling request comprises a user key identifier, a cryptographic service identifier and data to be operated; and is used to receive a first user key ciphertext sent by the key management module, and send the first user key ciphertext to a corresponding working cryptographic machine according to the working cryptographic machine identifier; the key management module is used to obtain a user key plaintext according to the user key identifier; and obtain a user key plaintext from the key storage submodule. A working cipher machine information is selected from the storage submodule, the working cipher machine information includes a working cipher machine identification and a corresponding master key ciphertext, the first cipher machine is called, the master key ciphertext is decrypted with the first key of the first cipher machine to obtain the master key; and the user key plaintext is encrypted into a first user key ciphertext with the master key, and finally the first user key ciphertext is sent to the cryptographic service scheduling module; the working cipher machines in the working cipher machine cluster are used to receive the first user key ciphertext sent by the cryptographic service scheduling module, use their own master key to decrypt the first user ciphertext into a user key, and perform corresponding operations on the data to be operated with the user key according to the cryptographic service identification.
[0008] According to a third aspect of the present invention, there is provided an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.
[0009] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the steps of the above method when executed by a processor.
[0010] According to a fifth aspect of the present invention, there is provided a computer program product, comprising a computer program / instructions, which implement the steps of the above method when executed by a processor.
[0011] It can be seen from the above technical solution that the cryptographic service calling method provided in this application does not need to maintain the same master key, but only needs to store its own master key. It can be done with one machine and one key, which greatly improves the security of the working cryptographic machine key and thus improves the security of the entire set of cryptographic services. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0013] Figure 1 It is a flowchart of a cryptographic service calling method provided in an embodiment of the present application;
[0014] Figure 2 It is a flowchart of a cryptographic service calling method provided by another embodiment of the present application;
[0015] Figure 3 It is a schematic diagram of the storage process of the working cipher machine identification and the master key ciphertext provided in the embodiment of the present application;
[0016] Figure 4 It is a schematic diagram of the storage process of the working key identifier and the working key ciphertext provided in the embodiment of the present application;
[0017] Figure 5 It is a schematic diagram of the storage process of the user key identifier, the second user key ciphertext and the working key identifier provided in the embodiment of the present application;
[0018] Figure 6 It is a structural diagram of a cryptographic service calling system provided in an embodiment of the present application;
[0019] Figure 7 It is a structural diagram of a cryptographic service calling system provided by another embodiment of the present application;
[0020] Figure 8 It is a schematic block diagram of the system structure of the electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0021] The cryptographic service calling method and system provided in the embodiments of the present invention can be used in the financial field and other fields. It should be noted that the cryptographic service calling method and system of the present invention can be used in the financial field, and can also be used in any field except the financial field. The present invention does not limit the application field of the cryptographic service calling method and system.
[0022] To make the purpose, technical solution and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are further described in detail below in conjunction with the accompanying drawings. Here, the exemplary embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.
[0023] like Figure 1The figure is a flow chart of a method for calling a cryptographic service provided in an embodiment of the present application, the method comprising the following steps:
[0024] Step S101: receiving a cryptographic service call request sent by a cryptographic service caller, wherein the cryptographic service call request includes a user key identifier, a cryptographic service identifier and data to be operated.
[0025] Step S102: Obtain the user key plaintext according to the user key identifier.
[0026] Step S103: Select a working cipher machine information from the key storage submodule, the working cipher machine information includes a working cipher machine identification and a corresponding master key ciphertext, call the first cipher machine, use the first key of the first cipher machine to decrypt the master key ciphertext, and obtain the master key.
[0027] In this embodiment, the cipher machine information of each working cipher machine is pre-stored in the key storage submodule. The master key of the working cipher machine is encrypted by the first cipher machine to become a master key ciphertext and stored in the key storage submodule. The master key of each working cipher machine is different, and the master key of each working cipher machine is distinguished by the correspondence between the working cipher machine identification and the master key ciphertext.
[0028] The selection of a working cipher machine can be determined based on the current load of the cipher machine, and a working cipher machine that is currently idle can be selected.
[0029] Step S104: Use the master key to encrypt the user key plaintext into a first user key ciphertext, and send the first user key ciphertext to the corresponding working cipher machine according to the working cipher machine identifier. The corresponding working cipher machine uses its own master key to decrypt the first user ciphertext into a user key, and uses the user key to perform corresponding operations on the operation data according to the cryptographic service identifier.
[0030] After the master key of the selected working cipher machine is decrypted in step S103, the user key plaintext obtained in step S102 is encrypted into a first user key ciphertext using the master key, and the first user ciphertext is sent to the corresponding working cipher machine.
[0031] After receiving the first user's ciphertext, the corresponding working cipher machine will use its own master key to decrypt the first user's ciphertext into a user key, and then use the user key to perform subsequent corresponding operations on the data to be operated.
[0032] From the above, it can be seen that the cryptographic service calling method provided in the embodiment of the present application does not need to maintain the same master key, but only needs to store its own master key. It can use one machine and one key, which greatly improves the security of the working cryptographic machine key and thus improves the security of the entire set of cryptographic services.
[0033] like Figure 2 FIG. 1 is a flow chart of a cryptographic service calling method provided by another embodiment of the present application, the method comprising the following steps:
[0034] Step S201: receiving a cryptographic service call request sent by a cryptographic service caller, wherein the cryptographic service call request includes a user key identifier, a cryptographic service identifier and data to be operated.
[0035] Step S202: Obtain the corresponding second user key ciphertext and working key identifier from the key storage submodule according to the user key identifier.
[0036] In this embodiment, the key storage submodule pre-stores the user key identifier, the second user key ciphertext and the working key identifier, which are stored in the key storage submodule in the associated format of "user key identifier + second user key ciphertext + working key identifier".
[0037] Step S203: Obtain the working key ciphertext from the key storage submodule according to the working key identifier, call the second cryptographic machine, and use the second key of the second cryptographic machine to decrypt the working key ciphertext to obtain the working key plaintext.
[0038] Step S204: Continue to call the second cipher machine, and use the working key plaintext to decrypt the second user key ciphertext to obtain the user key plaintext.
[0039] In this embodiment, the above-mentioned second user key ciphertext is obtained by encrypting the user key plaintext with the working key plaintext, and the working key ciphertext is obtained by encrypting the working key with the second key of the second cipher machine. Therefore, in order to decrypt the second user key ciphertext to obtain the user key plaintext, it is first necessary to obtain the working key plaintext through step S203, and then use the working key plaintext to decrypt the second user key ciphertext to obtain the user key plaintext.
[0040] Step S205: Select a working cipher machine information from the key storage submodule, the working cipher machine information includes a working cipher machine identification and a corresponding master key ciphertext, call the first cipher machine, use the first key of the first cipher machine to decrypt the master key ciphertext, and obtain the master key.
[0041] Step S206: Use the master key to encrypt the user key plaintext into a first user key ciphertext, and send the first user key ciphertext to the corresponding work cipher machine according to the work cipher machine identifier.
[0042] Step S207: The corresponding working cryptographic machine uses its own master key to decrypt the first user ciphertext into a user key, and uses the user key to perform corresponding operations on the data to be operated according to the cryptographic service identifier.
[0043] From the above steps, it can be seen that the key storage submodule in this embodiment pre-stores the following three parts of data:
[0044] 1. The working cipher machine identification and the master key ciphertext and their corresponding relationship;
[0045] 2. Working key identifier and working key ciphertext and their corresponding relationship;
[0046] 3. User key identifier, second user key ciphertext and working key identifier and their corresponding relationship.
[0047] Preferably, Figure 3 As shown, the above-mentioned working cipher machine identification and master key ciphertext can be stored in the key storage submodule in the following manner:
[0048] Step S301: For each working cipher machine, the cipher machine master key protection submodule is called to randomly generate a corresponding master key to ensure that the master key of each working cipher machine is different.
[0049] Step S302: Call the first cryptographic machine and use the first key to encrypt the master key into a master key ciphertext.
[0050] Step S303: The working cipher machine identification and the master key ciphertext of each working cipher machine are formed into a corresponding relationship and stored in the key storage submodule. Specifically, they can be stored in the associated format of "working cipher machine identification + master key ciphertext".
[0051] Preferably, Figure 4 As shown, the above working key identifier and working key ciphertext may be stored in the key storage submodule in the following manner:
[0052] Step S401: Call the key management master key protection submodule to randomly generate a working key.
[0053] Step S402: calling the second cryptographic machine, and using the second key to encrypt the working key into a working key ciphertext.
[0054] Step S403: forming a corresponding relationship between the working key identifier and the working key ciphertext and storing them in the key storage submodule. Specifically, they can be stored in the associated format of "working key identifier+working key ciphertext".
[0055] Preferably, Figure 5 As shown, the user key identifier, the second user key ciphertext and the working key identifier may be stored in the key storage submodule in the following manner:
[0056] Step S501: the key management master key protection submodule obtains the working key ciphertext from the key storage submodule according to the working key identifier.
[0057] Step S502: calling the second cryptographic machine, and using the second key to decrypt the working key ciphertext into working key plaintext.
[0058] Step S503: the key management master key protection submodule randomly generates a user key, and calls the second cryptographic machine to encrypt the user key into a second user key ciphertext using the working key plaintext.
[0059] Step S504: the user key identifier, the second user key ciphertext and the working key identifier are formed into a corresponding relationship and stored in the key storage submodule. Specifically, they can be stored in the associated format of "user key identifier+second user key ciphertext+working key identifier".
[0060] Step S505: Return the user key identifier to the cryptographic service caller.
[0061] From the above, it can be seen that the cryptographic service calling method provided in the embodiment of the present application does not need to maintain the same master key, but only needs to store its own master key. It can use one machine and one key, which greatly improves the security of the working cryptographic machine key and thus improves the security of the entire set of cryptographic services.
[0062] like Figure 6 What is shown is a structural diagram of a cryptographic service calling system provided in an embodiment of the present application, the system comprising: a cryptographic service scheduling module 100, a key management module 200 and a working cryptographic machine cluster 300, the key management module 200 comprising a key storage submodule 201, wherein the cryptographic service scheduling module 100 is respectively connected to the key management module 200 and the working cryptographic machine cluster 300.
[0063] The cryptographic service scheduling module 100 is used to receive a cryptographic service call request issued by a cryptographic service caller, which includes a user key identifier, a cryptographic service identifier and data to be operated. It is also used to receive a first user key ciphertext sent by the key management module 200, and send the first user key ciphertext to the corresponding working cryptographic machine according to the working cryptographic machine identifier.
[0064] The key management module 200 is used to obtain the user key plaintext according to the user key identifier; select a working cipher machine information from the key storage submodule 201, the working cipher machine information includes the working cipher machine identifier and the corresponding master key ciphertext; call the first cipher machine, use the first key of the first cipher machine to decrypt the master key ciphertext, and obtain the master key; and use the master key to encrypt the user key plaintext into the first user key ciphertext, and finally send the first user key ciphertext to the cryptographic service scheduling module 100;
[0065] The working cryptographic machine in the working cryptographic machine cluster 300 is used to receive the first user key ciphertext sent by the cryptographic service scheduling module 100, use its own master key to decrypt the first user ciphertext into a user key, and use the user key to perform corresponding operations on the data to be operated according to the cryptographic service identifier.
[0066] From the above, it can be seen that the cryptographic service calling system provided in the embodiment of the present application does not need to maintain the same master key, but only needs to store its own master key. It can have one machine and one key, which greatly improves the security of the working cryptographic machine key and thus improves the security of the entire set of cryptographic services.
[0067] like Figure 7 As shown is a structural schematic diagram of a cryptographic service calling system provided by another embodiment of the present application, the system includes: a cryptographic service scheduling module 100, a key management module 200 and a working cryptographic machine cluster 300, wherein the cryptographic service scheduling module 100 includes a key scheduling sub-module 101 and a cryptographic service scheduling sub-module 102, and the key management module 200 includes a key storage sub-module 201, a key management master key protection sub-module 202 and a cryptographic machine master key protection sub-module 203.
[0068] In this embodiment, the key storage submodule 201 pre-stores the following three parts of data:
[0069] 1. The working cipher machine identification and the master key ciphertext and their corresponding relationship;
[0070] 2. Working key identifier and working key ciphertext and their corresponding relationship;
[0071] 3. User key identifier, second user key ciphertext and working key identifier and their corresponding relationship.
[0072] For the data in Part 1 above, the generation and storage process is as follows:
[0073] For each working cipher machine, the key scheduling submodule 101 calls the cipher machine master key protection submodule 203 to randomly generate the corresponding master key, and ensures that the master key of each working cipher machine is different. Then the cipher machine master key protection submodule 203 will call the first cipher machine and encrypt the master key into the master key ciphertext with the first key. Then the cipher machine master key protection submodule 203 will form a corresponding relationship between the working cipher machine identification and the master key ciphertext of each working cipher machine and store it in the key storage submodule 201. Specifically, it can be stored in the associated format of "working cipher machine identification + master key ciphertext". At the same time, the cipher machine master key protection submodule 203 will also send the generated master key to the corresponding working cipher machine in the working cipher machine cluster 300.
[0074] For the data in Part 2 above, the generation and storage process is as follows:
[0075] The key scheduling submodule 101 calls the key management master key protection submodule 202 to randomly generate a working key, then calls the second cryptographic machine, encrypts the working key into a working key ciphertext with the second key, and then forms a corresponding relationship between the working key identifier and the working key ciphertext and stores them in the key storage submodule 201. Specifically, they can be stored in the associated format of "working key identifier + working key ciphertext". Finally, the working key identifier is returned to the key scheduling submodule 101.
[0076] For the data in Part 3 above, the generation and storage process is as follows:
[0077] The key scheduling submodule 101 calls the key management master key protection submodule 202, and inputs the working key identifier. The key management master key protection submodule 202 obtains the working key ciphertext from the key storage submodule 201 according to the working key identifier. The key management master key protection submodule 202 calls the second cryptographic machine, and uses the second key to decrypt the above working key ciphertext into the working key plaintext. The key management master key protection submodule 202 randomly generates a user key, and calls the second cryptographic machine, and uses the working key plaintext to encrypt the user key into the second user key ciphertext. Then the key management master key protection submodule 202 forms a corresponding relationship between the user key identifier, the second user key ciphertext and the working key identifier and stores them in the key storage submodule. Specifically, they can be stored in the associated format of "user key identifier + second user key ciphertext + working key identifier". Finally, the key management master key protection submodule 202 returns the user key identifier to the cryptographic service caller through the cryptographic service scheduling module 100.
[0078] The following is a further description of the process of using the system to perform password call services:
[0079] The cryptographic service caller sends a cryptographic service call request to the cryptographic service scheduling module 100, and the cryptographic service call request includes a user key identifier, a cryptographic service identifier and data to be operated. After receiving the cryptographic service call request, the cryptographic service scheduling module 100 immediately calls the key management module 200.
[0080] The key management master key protection submodule 202 obtains the corresponding second user key ciphertext and working key identifier from the key storage submodule 201 according to the user key identifier.
[0081] The key management master key protection submodule 202 obtains the working key ciphertext from the key storage submodule 201 according to the working key identifier, calls the second cryptographic machine, decrypts the working key ciphertext with the second key of the second cryptographic machine, and obtains the working key plaintext.
[0082] The key management master key protection submodule 202 continues to call the second cipher machine, and uses the working key plaintext to decrypt the second user key ciphertext to obtain the user key plaintext.
[0083] The cipher machine master key protection submodule 203 selects a working cipher machine information from the key storage submodule 201, and the working cipher machine information includes the working cipher machine identification and the corresponding master key ciphertext, and then calls the first cipher machine, uses the first key of the first cipher machine to decrypt the master key ciphertext, and obtains the master key.
[0084] The cryptographic machine master key protection submodule 203 uses the master key to encrypt the user key plaintext into a first user key ciphertext, and sends the first user key ciphertext to the cryptographic service scheduling submodule 102. The cryptographic service scheduling submodule 102 sends the first user key ciphertext to the corresponding working cryptographic machine in the working cryptographic machine cluster 300 according to the working cryptographic machine identifier, such as the working cryptographic machine 01.
[0085] The working cryptographic machine 01 uses its own master key to decrypt the first user ciphertext into a user key, and uses the user key to perform corresponding operations on the data to be operated according to the cryptographic service identifier.
[0086] From the above, it can be seen that the cryptographic service calling system provided in the embodiment of the present application does not need to maintain the same master key, but only needs to store its own master key. It can have one machine and one key, which greatly improves the security of the working cryptographic machine key and thus improves the security of the entire set of cryptographic services.
[0087] An embodiment of the present invention further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the above method is implemented when the processor executes the program.
[0088] An embodiment of the present invention further provides a computer program product, including a computer program / instruction, which implements the steps of the above method when the computer program / instruction is executed by a processor.
[0089] An embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program for executing the above method.
[0090] like Figure 8As shown, the electronic device 600 may further include: a communication module 110, an input unit 120, an audio processor 130, a display 160, and a power supply 170. It is worth noting that the electronic device 600 does not necessarily have to include Figure 8 In addition, the electronic device 600 may also include Figure 8 For components not shown, reference may be made to the prior art.
[0091] like Figure 8 As shown, the central processor 100 is sometimes also referred to as a controller or an operation control, and may include a microprocessor or other processor devices and / or logic devices. The central processor 100 receives inputs and controls the operations of various components of the electronic device 600.
[0092] The memory 140 may be, for example, one or more of a cache, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory or other suitable devices. The above-mentioned information related to the failure may be stored, and a program for executing the relevant information may also be stored. The CPU 100 may execute the program stored in the memory 140 to implement information storage or processing.
[0093] The input unit 120 provides input to the CPU 100. The input unit 120 is, for example, a key or a touch input device. The power supply 170 is used to provide power to the electronic device 600. The display 160 is used to display display objects such as images and text. The display may be, for example, an LCD display, but is not limited thereto.
[0094] The memory 140 may be a solid-state memory, such as a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It may also be a memory that saves information even when the power is off, can be selectively erased, and is provided with more data, examples of which are sometimes referred to as EPROMs, etc. The memory 140 may also be some other type of device. The memory 140 includes a buffer memory 141 (sometimes referred to as a buffer). The memory 140 may include an application / function storage unit 142, which is used to store application programs and function programs or processes for executing the operation of the electronic device 600 through the central processor 100.
[0095] The memory 140 may also include a data storage unit 143 for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 144 of the memory 140 may include various drivers for communication functions of the electronic device and / or for executing other functions of the electronic device (such as messaging applications, address book applications, etc.).
[0096] The communication module 110 is a transmitter / receiver 110 that transmits and receives signals via an antenna 111. The communication module (transmitter / receiver) 110 is coupled to the central processor 100 to provide input signals and receive output signals, which may be the same as the case of a conventional mobile communication terminal.
[0097] Based on different communication technologies, multiple communication modules 110 may be provided in the same electronic device, such as a cellular network module, a Bluetooth module and / or a wireless LAN module. The communication module (transmitter / receiver) 110 is also coupled to a speaker 131 and a microphone 132 via an audio processor 130 to provide an audio output via the speaker 131 and receive an audio input from the microphone 132, thereby realizing a common telecommunication function. The audio processor 130 may include any suitable buffer, decoder, amplifier, etc. In addition, the audio processor 130 is also coupled to the central processor 100, so that the sound can be recorded on the local machine through the microphone 132, and the sound stored on the local machine can be played through the speaker 131.
[0098] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0099] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0100] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0101] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0102] The present invention uses specific embodiments to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.
Claims
1. A cryptographic service calling method, characterized in that: The method comprises: Receiving a cryptographic service call request from a cryptographic service caller, wherein the cryptographic service call request includes a user key identifier, a cryptographic service identifier, and data to be operated; Obtaining a user key plaintext according to the user key identifier; Selecting a working cipher machine information from the key storage submodule, the working cipher machine information including the working cipher machine identification and the corresponding master key ciphertext, calling the first cipher machine, and decrypting the master key ciphertext with the first key of the first cipher machine to obtain the master key; The master key is used to encrypt the user key plaintext into a first user key ciphertext, and the first user key ciphertext is sent to the corresponding working cipher machine according to the working cipher machine identifier. The corresponding working cipher machine uses its own master key to decrypt the first user key ciphertext into a user key, and uses the user key to perform corresponding operations on the data to be operated according to the cryptographic service identifier.
2. A cryptographic service calling method as claimed in claim 1, characterized in that: The obtaining of the user key plaintext according to the user key identifier comprises: Obtaining a corresponding second user key ciphertext and a working key identifier from the key storage submodule according to the user key identifier; Obtaining the working key ciphertext from the key storage submodule according to the working key identifier, calling the second cryptographic machine, and decrypting the working key ciphertext with the second key of the second cryptographic machine to obtain the working key plaintext; Continue to call the second cipher machine, and use the working key plaintext to decrypt the second user key ciphertext to obtain the user key plaintext.
3. A cryptographic service calling method as claimed in claim 1, characterized in that: The working cipher machine information is stored in the key storage submodule in the following manner: For each working cipher machine, the cipher machine master key protection submodule is called to randomly generate the corresponding master key to ensure that the master key of each working cipher machine is different; Calling the first cryptographic machine to encrypt the master key with the first key into a master key ciphertext; A corresponding relationship is formed between the working cipher machine identification and the master key ciphertext of each working cipher machine and the ciphertext is stored in the key storage submodule.
4. A cryptographic service calling method as claimed in claim 2, characterized in that: The working key identifier and the working key ciphertext are stored in the key storage submodule in the following manner: Call the key management master key protection submodule to randomly generate a working key; Calling a second cryptographic machine to encrypt the working key into a working key ciphertext using a second key; A corresponding relationship is formed between the working key identifier and the working key ciphertext and the corresponding relationship is stored in the key storage submodule.
5. A cryptographic service calling method as claimed in claim 4, characterized in that: The user key identifier, the second user key ciphertext and the working key identifier are stored in the key storage submodule in the following manner: The key management master key protection submodule obtains the working key ciphertext from the key storage submodule according to the working key identifier; Calling a second cryptographic machine to decrypt the working key ciphertext into working key plaintext using a second key; The key management master key protection submodule randomly generates a user key, and calls the second cryptographic machine to encrypt the user key into a second user key ciphertext using the working key plaintext; The user key identifier, the second user key ciphertext and the working key identifier are formed into a corresponding relationship and stored in the key storage submodule.
6. A cryptographic service calling method as claimed in claim 5, characterized in that: After forming a corresponding relationship among the user key identifier, the second user key ciphertext and the working key identifier and storing them in the key storage submodule, the method further includes: returning the user key identifier to the cryptographic service caller.
7. A cryptographic service calling system, characterized in that: The system comprises: a cryptographic service scheduling module, a key management module and a working cryptographic machine cluster, wherein the key management module further comprises a key storage submodule. The cryptographic service scheduling module is used to receive a cryptographic service call request from a cryptographic service caller, wherein the cryptographic service call request includes a user key identifier, a cryptographic service identifier, and data to be operated; and is used to receive a first user key ciphertext sent by the key management module, and send the first user key ciphertext to a corresponding working cryptographic machine according to the working cryptographic machine identifier; The key management module is used to obtain a user key plaintext according to the user key identifier; select a working cipher machine information from the key storage submodule, the working cipher machine information includes a working cipher machine identifier and a corresponding master key ciphertext, call a first cipher machine, use a first key of the first cipher machine to decrypt the master key ciphertext, and obtain a master key; and use the master key to encrypt the user key plaintext into a first user key ciphertext, and finally send the first user key ciphertext to the cryptographic service scheduling module; The working cryptographic machine in the working cryptographic machine cluster is used to receive the first user key ciphertext sent by the cryptographic service scheduling module, use its own master key to decrypt the first user key ciphertext into a user key, and use the user key to perform corresponding operations on the operation data according to the cryptographic service identifier.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the cryptographic service calling method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the cryptographic service calling method according to any one of claims 1 to 6 are implemented.
10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the cryptographic service calling method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Cryptographic device virtualization method and equipment
CN108228316A
Distributed password service method and distributed password service system
CN108259175A