A method for key management and cryptographic calculation, an encryption method and device

By introducing a hierarchical structure of master key and controlled key in the key management system, the shortcomings of existing systems in independent key control and flexible authorization are solved, and more efficient and secure key management is achieved.

CN115412236BActive Publication Date: 2025-06-10BEIJING CERTIFICATE AUTHORITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211033030.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-26
Publication Date
2025-06-10
Estimated Expiration
2042-08-26

AI Technical Summary

Technical Problem

Existing key management systems have shortcomings in independent control and flexible authorization of keys, especially in the challenge of defending against internal attacks and simplifying the authorization process.

Method used

By layering the key into a master key and a controlled key, and the password holder independently controls the master key, the controlled key is authorized to other users through master key manipulation.

Benefits of technology

It realizes independent control of the keys stored in the key management system by password holders, and simplifies the flexible authorization of controlled keys, significantly improving the performance and security of the key management system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115412236B_ABST
    Figure CN115412236B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a method for key management and password calculation, a data encryption method, and an apparatus. Among them, the method for generating key data includes: generating a master key; encrypting at least the master key to obtain master key attribute data; establishing an association relationship between the master key and at least one controlled key, where the association relationship is used to record the control relationship of the master key over the controlled key, and the controlled key can be authorized for use by at least one object through the master key; storing at least the master key attribute data and the association relationship, so that the password holder can perform an encryption operation according to the master key or authorize the controlled key to other objects according to the association relationship. The technical solutions of some embodiments of the present application can ensure that the key holder independently controls the key and can further flexibly authorize the key (i.e., the controlled key) to other users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information technology security. Specifically, embodiments of this application relate to a method for key management and cryptographic calculation, a data encryption method, and an apparatus. Background Art

[0002] With the increasing popularity of cryptographic applications, the demand for key management systems has gradually increased. As the key data for identity authentication and information encryption, it is usually protected as the core asset of an enterprise or individual, and its security requirements are relatively high.

[0003] At present, there are mainly the following two centralized management methods for keys:

[0004] First, the full custody method of the management center. In this method, a key management system is established in the key management center. The management center centrally generates, stores, and authorizes the use of keys, and the key owner uses the keys through network calls. In this method, the application keys are stored in plaintext on the center side or encrypted using the encryption keys provided by the center side. In either case, if the internal personnel in the management center successfully exceed their authority or collude with each other in multiple links, they can use the entrusted keys for cryptographic operations without the explicit authorization of the key owner. Therefore, this method is difficult to resist internal attacks from the management center.

[0005] Second, the collaborative signature method. The signature key components are stored separately on the client side and the server side, and neither end can obtain the complete signature private key data, thus preventing the server from forging user signatures, and the application is relatively flexible. However, in this method, if the key needs to be authorized for others to use, the security parameters of both the server side and the client side need to be updated simultaneously. Therefore, all the server side and all relevant client sides (the authorizing party and the authorized party) need to participate in the operation, and the interaction process is relatively complex.

[0006] Therefore, there are many problems in the key management systems of related technologies. How to improve the performance of the key management system has become an urgent technical problem to be solved. Summary of the Invention

[0007] The purpose of the embodiments of this application is to provide a method for key management and cryptographic calculation, an encryption method, and an apparatus. On the one hand, through the technical solutions of some embodiments of this application, it can be ensured that the key holder independently controls the key (for example, the master key, or a certain controlled key controlled by the master key). On the other hand, through some embodiments of this application, the key (i.e., the controlled key) can be further flexibly authorized to other users, significantly improving the performance of the key management side system.

[0008] In a first aspect, some embodiments of the present application provide a method for key management and cryptographic calculation, which is applied to a key management system. The method includes: generating a master key, where the master key is independently controlled by a password holder through control information; at least encrypting the master key to obtain master key attribute data, where the master key attribute data at least includes a master key ciphertext and master key index information for finding the master key, and the master key ciphertext is obtained by encrypting the master key; establishing an association relationship between the master key and at least one controlled key, where the association relationship is used to record the control relationship of the master key over the controlled key, and the controlled key can be authorized for use by at least one object through the master key; at least storing the master key attribute data and the association relationship, so that the password holder can perform an encryption operation according to the master key or authorize the controlled key to other objects according to the association relationship.

[0009] In some embodiments of the present application, the key is hierarchically divided into a master key and a controlled key, and the master key is independently controlled by the password holder, and the corresponding controlled key is authorized for use by at least one user through the control of the master key. On the one hand, this realizes the independent control of the password holder over the keys stored in the key management system, and on the other hand, it can also flexibly authorize the controlled key to other users.

[0010] In some embodiments, before establishing the association relationship between the master key and at least one controlled key, the method further includes: generating the controlled key; at least encrypting the controlled key to obtain controlled key attribute data, where the controlled key attribute data includes a controlled key ciphertext and controlled key index information for finding the controlled key, and the controlled key ciphertext is obtained by encrypting the controlled key; the at least storing the master key attribute data and the association relationship includes: storing the master key attribute data, the controlled key attribute data, and multiple association relationships.

[0011] In some embodiments of the present application, by generating a controlled key in the key management system, storing the controlled key in ciphertext, and storing the control relationship between the controlled key and the master key, the key holder can flexibly authorize the controlled key.

[0012] In some embodiments, generating the master key includes: generating a first public-private key pair represented in plaintext to obtain the master key, where the first public-private key pair includes a master public key and a master private key; encrypting at least the master key to obtain master key attribute data, including: encrypting the master private key with a first encryption data provided by the key management system to obtain an encrypted master private key; at least re-encrypting the encrypted master private key according to the control information to obtain the master key ciphertext, where the control information at least includes communication unit information that can communicate with the key holder and a control code known to the key holder; using the master key ciphertext and the master public key as at least part of the content of the master key attribute data.

[0013] Some embodiments of the present application encrypt the master key generated by the key management system using control information held by the key holder, effectively overcoming the problem in related technologies that only using the encryption key provided by the key management system for encryption may be difficult to resist internal attacks from the key management system.

[0014] In some embodiments, at least re-encrypting the encrypted master private key according to the control information to obtain the master key ciphertext includes: assigning a master identifier keyId to the master key, where the master identifier keyId serves as the unique identifier of the master key, and the master identifier serves as the master key index information; obtaining a protection key according to the master identifier and the control information; re-encrypting the encrypted master private key based on the protection key to obtain the master key ciphertext; where the master key attribute data further includes the master identifier.

[0015] Some embodiments of the present application use the control information held and input by the key holder and the master identifier assigned to the master key to obtain a protection key, and then use the protection key to encrypt the master private key, improving the security of the master key ciphertext (i.e., the master private key ciphertext) while also enabling the master key to be searched.

[0016] In some embodiments, the control code is a string or a multi-bit binary number, and the communication unit information includes: a mobile phone number or an email address.

[0017] Some embodiments of the present application provide multiple types of control codes and communication information units.

[0018] In some embodiments, the control information is two-factor control information, and the two-factor control information includes: a PIN code and a mobile phone number, or a PIN code and an email address.

[0019] The control information in some embodiments of this application uses a PIN code (as an example of a control code) and a mobile phone number (as an example of communication unit information), or uses two-factor control information of a PIN code and an email address.

[0020] In some embodiments, the method further includes: calculating a check code of the control information to obtain a control check code macPin, where the control check code is used to verify the legality of the control information before performing a password operation using the master key; and taking the control check code as a part of the master key attribute data.

[0021] To improve the security of encryption operations using a master key or a controlled key, some embodiments of this application also provide a technical solution for generating a check code based on control information uniquely held by a key holder.

[0022] In some embodiments, generating the controlled key includes: generating a second public-private key pair represented in plaintext to obtain the controlled key, where the second public-private key pair includes a controlled public key and a controlled private key; and encrypting at least the controlled key to obtain encrypted controlled key attribute data, including: encrypting the controlled private key using a private key protection key plaintext provided by the key management system to obtain the controlled key ciphertext; and taking the controlled key ciphertext and the controlled public key as at least part of the content of the controlled key attribute data.

[0023] Some embodiments of this application encrypt the controlled private key using a private key protection key plaintext provided by the key management system to obtain the controlled key ciphertext and save the controlled key ciphertext, so as to facilitate decrypting the controlled key ciphertext later and then using the controlled private key for encryption processing.

[0024] In some embodiments, the method further includes: assigning a controlled key identifier slaveId to the controlled key, where the controlled key identifier slaveId serves as the unique identifier of the controlled key, and the controlled key identifier slaveId serves as the controlled key index information; and the controlled key attribute data includes the controlled key identifier slaveId.

[0025] Some embodiments of this application establish a controlled key identifier for each established controlled key to facilitate finding the controlled key, so that the key holder can authorize the corresponding controlled key to other users (for example, using the controlled private key to complete signature authentication) based on providing the controlled key identifier.

[0026] In some embodiments, establishing the association relationship between the master key and at least one controlled key includes: encrypting the plaintext of the private key protection key with a key encryption key (KEK) provided by the key management system to obtain the ciphertext of the private key protection key, ePek; encrypting the ciphertext of the private key protection key with the master public key to obtain the associated ciphertext of the private key protection key, pubEncEPek; and using the controlled key identifier, the master key, and the associated ciphertext of the private key protection key as the association information.

[0027] Some embodiments of the present application perform a double encryption operation on the plaintext of the private key protection key that encrypts the controlled private key, and then store the associated ciphertext of the private key protection key obtained after the double encryption, improving the security of the controlled private key so that only authorized key holders can control the corresponding controlled private key.

[0028] In some embodiments, there are multiple master keys, and the multiple master keys are stored in a master key identifier list. The master key identifier list is used to store multiple master keys and the master key identifier list numbers respectively corresponding to the multiple master keys. Among them, establishing the association relationship between the master key and at least one controlled key includes: encrypting the ciphertext of the private key protection key, ePek, with all the master keys in the master key identifier list respectively to obtain multiple associated ciphertexts of the private key protection key, forming an association relationship set, where the association relationship is an element in the association relationship set.

[0029] Some embodiments of the present application, after generating a controlled key on the key management side, also establish the association relationship between this controlled key and multiple master public keys, so that one controlled key can be controlled by the key holders of multiple master keys (i.e., authorizing other users to use the controlled key).

[0030] In some embodiments, after at least storing the master key attribute data and the association relationship, the method further includes: performing a backup operation on the master key and the controlled key.

[0031] To improve the security of the key data stored in the key management system, the master key and the controlled key can also be backed up.

[0032] In some embodiments, after at least storing the master key attribute data and the association relationship, the method further includes: the key holder performing an update operation on the master key and / or the controlled key by providing control information.

[0033] Some embodiments of the present application also provide a technical solution for updating the key data (i.e., the master key and the controlled key) stored in the key management system.

[0034] In some embodiments, after storing at least the master key attribute data and the association relationship, the method further includes: the key holder destroys the master key and / or the controlled key by providing control information.

[0035] To efficiently utilize the storage space of the key management center, some embodiments of the present application also need to destroy the master key and the controlled key that are no longer in use.

[0036] In a second aspect, some embodiments of the present application provide a method for encrypting data using a master key, which is applied to a key management system. The method includes: receiving master key index information, control information, and data to be encrypted provided by a key holder, where the control information is independently held by the password holder; finding master key attribute data according to the master key index information; decrypting at least the master key ciphertext included in the master key attribute data according to the control information to obtain a master key; and performing an encryption process on the data to be encrypted according to the master key.

[0037] In some embodiments, before decrypting at least the master key ciphertext included in the master key attribute data according to the control information to obtain a master key, the method further includes: obtaining a control check code from the master key attribute data; calculating a control check code to be verified according to the control information; and confirming that the control check code is consistent with the control check code to be verified.

[0038] In some embodiments, decrypting at least the master key ciphertext included in the master key attribute data according to the control information to obtain a master key includes: obtaining a protection key according to the master key index information and the control information; decrypting the master key ciphertext with the protection key to obtain an initial decrypted master ciphertext; and decrypting the initial decrypted master ciphertext with the first encrypted data provided by the key management system to obtain a master private key, where the master key includes the master private key and the master public key.

[0039] In a third aspect, some embodiments of the present application provide a method for encrypting data using a controlled key. The method includes: receiving control information provided by a key holder, a master key identification list number masterId, a controlled key identification slaveId, and data to be encrypted, where the control information is independently held by a password holder; obtaining association information corresponding to the master key identification list number masterId according to the control information and the master key identification list number masterId, where the association information includes an associated private key protection key ciphertext pubEncEPek; decrypting the associated private key protection key ciphertext pubEncEPek to obtain a private key protection key ciphertext ePek; decrypting the controlled key ciphertext according to the private key protection key ciphertext ePek to obtain a controlled key; and encrypting the data to be encrypted based on the controlled key.

[0040] In some embodiments, the decrypting the associated private key protection key ciphertext pubEncEPek to obtain a private key protection key ciphertext ePek includes: obtaining a master key according to the master key identification list number; obtaining a master private key from the master key, and decrypting the associated private key protection key ciphertext pubEncEPek based on the master private key to obtain the private key protection key ciphertext ePek.

[0041] In some embodiments, the decrypting the controlled key ciphertext according to the private key protection key ciphertext ePek to obtain a controlled key includes: querying and obtaining controlled key attribute data according to the controlled key identification slaveId to obtain a controlled key ciphertext pekEncSlavePri; decrypting the private key protection key ciphertext ePek with a key encryption key KEK to obtain a private key protection key plaintext pek; and decrypting the controlled key ciphertext pekEncSlavePri with the private key protection key plaintext pek to obtain the controlled private key slavePri, where the controlled key includes the controlled private key.

[0042] Fourth aspect, some embodiments of the present application provide a key management system, the system comprising: a master key generation module configured to generate a master key, wherein the master key is independently controlled by a password holder through control information; a master key attribute data generation module configured to at least encrypt the master key to obtain master key attribute data, wherein the master key attribute data at least includes a master key ciphertext and master key index information for searching the master key, and the master key ciphertext is obtained after encrypting the master key; an association relationship establishment module configured to establish an association relationship between the master key and at least one controlled key, wherein the association relationship is used to record the control relationship of the master key over the controlled key, and the controlled key can be authorized for use by at least one object through the master key; a storage module configured to at least store the master key attribute data and the association relationship, so that the password holder can perform an encryption operation according to the master key or authorize the controlled key to other objects according to the association relationship.

[0043] Fifth aspect, some embodiments of the present application provide a key management system, the system comprising: a first control information receiving module configured to receive master key index information and control information provided by a key holder, wherein the control information is independently held by a password holder; a master key attribute data obtaining module configured to obtain master key attribute data according to the master key index information; a decryption module configured to decrypt the master key ciphertext included in the master key attribute data to obtain the master key; a first encryption module configured to complete the encryption process of the data to be encrypted according to the master key.

[0044] Sixth aspect, some embodiments of the present application provide a key management system, the system comprising: a second control information receiving module configured to receive control information, a master key identification list number masterId, a controlled key identification slaveId and data to be encrypted provided by a key holder, wherein the control information is independently held by a password holder; an authorization information obtaining module configured to obtain authorization information corresponding to the master key identification list number masterId according to the control information and the master key identification list number masterId, wherein the authorization information includes an associated private key protection key ciphertext pubEncEPek; a second decryption template configured to decrypt the associated private key protection key ciphertext pubEncEPek to obtain a private key protection key ciphertext ePek; a third decryption module configured to decrypt the controlled key ciphertext according to the private key protection key ciphertext ePek to obtain the controlled key; a second encryption module configured to encrypt the data to be encrypted based on the controlled key.

[0045] In a seventh aspect, some embodiments of the present application provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method described in any of the embodiments included in the first aspect, the second aspect, or the third aspect can be implemented.

[0046] In an eighth aspect, some embodiments of the present application provide an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the method described in any of the embodiments included in the first aspect, the second aspect, or the third aspect can be implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0048] Figure 1 Schematic diagram of the key system provided by the embodiment of the present application;

[0049] Figure 2 Flowchart of the method for key management and password calculation provided by the embodiment of the present application;

[0050] Figure 3 Schematic diagram of hierarchical key generation provided by the embodiment of the present application;

[0051] Figure 4 Schematic diagram of the use of the key management system provided by the embodiment of the present application;

[0052] Figure 5 Flowchart of the method for encrypting data using the master key provided by the embodiment of the present application;

[0053] Figure 6 Flowchart of the method for encrypting data using the controlled key provided by the embodiment of the present application;

[0054] Figure 7 Block diagram of the composition of the device for generating key data provided by the embodiment of the present application;

[0055] Figure 8 Block diagram of the composition of the device for encrypting data using the master key provided by the embodiment of the present application;

[0056] Figure 9 Block diagram of the composition of the device for encrypting data using the controlled key provided by the embodiment of the present application;

[0057] Figure 10 Schematic diagram of the composition of the electronic device provided by the embodiment of the present application. Detailed implementation manners

[0058] The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings in the embodiments of the present application.

[0059] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0060] Combined with the description in the background art section, it can be seen that the full trusteeship method of the management center using related technologies can provide a flexible management and authorization mechanism. However, most systems do not solve the need for the key holder to "independently control" the key. The security of the key is mainly the responsibility of the center, and it is difficult for the center side to defend against unauthorized or collusive attacks from the inside, and it is difficult to resist attacks from "insiders". When using the collaborative signature method for key authorization, both the server and the client need to participate in the operation. Therefore, the authorized person must participate in the authorization process, and the interaction process is relatively complex.

[0061] In some embodiments of the present application, the keys entrusted by the key management system are divided into two types: "master key" and "controlled key". The master key indirectly manages the controlled key (for example, Figure 2 the PEK shown) through the "private key protected key (PEK)". Figure 2 The controlled key (for example, Figure 2 the controlled key composed of the enterprise private key and the enterprise public key). It should be noted that the master key (Master Key) in some embodiments of the present application represents the identity of the key holding entity. The key holding entity can be a natural person or other entity. The master key includes a master private key and a master public key (for example, Figure 2The control information is the multi-factor control information of a natural person), and it can only be generated and used by the key holder through the control information (for example, multi-factor control information or two-factor control information). This type of key can only be controlled by one person (i.e., the corresponding key holder) at the same time and cannot be authorized for others to use. For example, the control information of the key is multi-factor control information, which includes two-factor control based on the mobile phone number and the control code, two-factor control based on the email and the control code, and other control methods can also be adopted. The controlled key (Slave Key) in some embodiments of the present application generally represents a logical entity or business role, including a controlled private key and a controlled public key. This key is created using the master key and indirectly protected using the master public key, and can be authorized for multiple people to control simultaneously. The private key encryption key (PEK) in some embodiments of the present application is created when the controlled key is generated and is used to encrypt and protect the controlled private key. The PEK can be encrypted and stored using multiple master public keys respectively, so that multiple master keys can use the same controlled key for cryptographic operations.

[0062] It can be understood that Figure 2 The "natural person" is only an example of the password "holder" because the holder may be a natural person or other entity. Figure 2 The "multi-factor control information of User A" is an example of the multi-factor control information of the password "holder",

[0063] because the multi-factor control information can include two-factor control information, three-factor control information, etc.

[0064] Please refer to Figure 1 , Figure 1 is a key system provided by some embodiments of the present application. In this key system, it includes a key management system 100 and a key holder or an authorized object that uses the keys stored on the key management system 100. The authorized object can use the controlled key held by the corresponding password holder on the password management device with the assistance of the password holder. It should be noted that the keys stored on the key management device provided by some embodiments of the present application include a master key and a controlled key. Among them, the master key is independently controlled by a certain password holder. For example, a certain password holder decrypts the master key by providing the secret information known to himself (for example, the secret information includes the control code in the control information), and then encrypts the data to be encrypted according to the master private key obtained by decrypting the master key. The controlled key can be authorized for one or more objects to use under the control of one or more master keys.

[0065] Such as Figure 1As shown, the password holders may include a first password holder 210, a second password holder 220, etc. A password calculation module 101 and a storage module 102 are provided in the password management system 100. Among them, the password calculation module can generate a master key and a controlled key, and can also encrypt the data to be encrypted using the master private key included in the master key in response to the encryption request of the password holder, or encrypt the data to be encrypted using the controlled private key included in the controlled key in response to the data encryption request of the authorized object or the password holder. The storage module 102 is configured to store the master key, the controlled key, and the association relationship between the master key and the controlled key. Figure 1 The first password holder 210 of Figure 1 sends control information to the password management system and receives the first master key or the controlled key associated with the first master key fed back by the password management system 100. Figure 1 The second password holder 220 of Figure 1 sends control information to the password management system and receives the second master key fed back by the password management system or receives the controlled key associated with the second master key. In Figure 1 Among them, the controlled key is a key controlled by the first master key, that is, the controlled key has an association relationship with the first master key, and the controlled key ciphertext can be decrypted with the assistance of the master key to obtain the controlled key. Figure 1 The first authorized object 211 of Figure 1 can receive the controlled key associated with the first master key fed back by the password management system. Figure 1 The second authorized object 212 of Figure 1 can also receive the controlled key associated with the first master key, so that the first authorized object or the second authorized object can complete the encryption process of the data to be encrypted according to the received controlled key.

[0066] Figure 1 Only two password holders and two authorized objects are shown. It can be understood that in some embodiments of the present application, there may also be more than two password holders or more than two authorized objects, and one controlled key may be associated with multiple master keys. In some embodiments of the present application, the key management system 100 further includes other modules in addition to the password calculation module 101 and the storage module 102, which will be exemplarily described below.

[0067] Next, in combination with Figure 3 Exemplarily describe the method for generating key data executed by the Figure 1 password management system of Figure 1 .

[0068] As Figure 3 shown, some embodiments of the present application provide a method for key management and password calculation, which is applied to a key management system. The method includes the following S101-S104:

[0069] S101, generating a master key, wherein the master key is independently controlled by a password holder through control information.

[0070] S102, at least encrypt the master key to obtain master key attribute data, wherein the master key attribute data at least includes a master key ciphertext and master key index information for searching the master key, and the master key ciphertext is obtained after encrypting the master key.

[0071] S103, establishing an association relationship between the master key and at least one controlled key, wherein the association relationship is used to record the control relationship of the master key over the controlled key, and the controlled key can be authorized to at least one object for use through the master key.

[0072] S104, at least storing the master key attribute data and the association relationship, so that the password holder can perform encryption operations according to the master key or authorize other objects to use the controlled key according to the association relationship.

[0073] It should be noted that the control information is information independently controlled by the password holder, including secret information known to the controller, biometric information (for example, fingerprint, face recognition), or a dedicated control device held by the controller (for example, USBKey).

[0074] Some embodiments of the present application hierarchically divide the keys into master keys and controlled keys, and the password holder independently controls the master key through control information (for example, control information), and authorizes the corresponding controlled key to at least one user for use through the master key. In this way, on the one hand, the password holder can independently control the keys stored in the key management system, and on the other hand, the controlled keys can be flexibly authorized to other users.

[0075] It should be noted that, in some embodiments of the present application, before S103, the method for generating key data further includes: generating the controlled key; at least encrypting the controlled key to obtain controlled key attribute data, wherein the controlled key attribute data includes a controlled key ciphertext and controlled key index information for searching the controlled key, and the controlled key ciphertext is obtained after encrypting the controlled key. The corresponding S104 at least storing the master key attribute data and the association relationship exemplarily includes: storing the master key attribute data, the controlled key attribute data, and multiple association relationships.

[0076] Some embodiments of the present application generate a controlled key in a key management system, store the controlled key in ciphertext, and store the manipulation relationship between the controlled key and the master key, enabling the key holder to flexibly authorize the controlled key.

[0077] The following exemplarily elaborates on the implementation process of obtaining the master key attribute data.

[0078] In some embodiments of the present application, the process of generating the master key in S101 exemplarily includes: generating the master key by generating a first public-private key pair represented in plaintext, where the first public-private key pair includes a master public key and a master private key. Correspondingly, S102 exemplarily includes:

[0079] First step, encrypt the master private key with the first encrypted data provided by the key management system to obtain an encrypted master private key.

[0080] Second step, at least re-encrypt the encrypted master private key according to the control information to obtain the master key ciphertext, where the control information at least includes communication unit information that can communicate with the key holder and a control code known to the key holder. It should be noted that the communication unit exemplarily includes: mobile phone number, email, or other communication units that can receive control information.

[0081] For example, this second step exemplarily includes: assigning a master identifier keyId to the master key, where the master identifier keyId serves as the unique identifier of the master key, and the master identifier serves as the master key index information; obtaining a protection key according to the master identifier and the control information; re-encrypting the encrypted master private key based on the protection key to obtain the master key ciphertext; where the master key attribute data further includes the master identifier. Some embodiments of the present application use the control information held and input by the key holder and the master identifier assigned to the master key to obtain a protection key, and then encrypt the master private key with the protection key, improving the security of the master key ciphertext (i.e., the master private key ciphertext) while also enabling the master key to be searched.

[0082] It should be noted that the protection key includes a symmetric key or an asymmetric key, that is to say, the protection of the master private key can use a "symmetric key" or may also use an asymmetric key.

[0083] For example, in some embodiments of the present application, the control code is a string or a multi-bit binary number, and the communication unit information includes: mobile phone number or email. Some embodiments of the present application provide multiple types of control codes and communication information units.

[0084] For example, in some embodiments of the present application, the control information is two-factor control information, and the two-factor control information includes: a PIN code (Personal Identification Number) and a mobile phone number, or a PIN code and an email address. The control information of some embodiments of the present application is two-factor control information using a PIN code and a mobile phone number, or a PIN code and an email address.

[0085] In the third step, the master key ciphertext and the master public key are used as at least part of the master key attribute data. Some embodiments of the present application use control information held by the key holder to encrypt the master key generated by the key management system, effectively overcoming the problem that the related art only uses the encryption key provided by the key management system for encryption, which may cause difficulty in resisting internal attacks from the key management system.

[0086] It should be noted that, in some embodiments of the present application, the method for generating key data further includes: calculating the check code of the control information to obtain a control check code macPin, wherein the control check code is used to verify the legitimacy of the control information before using the master key for cryptographic operations; and using the control check code as part of the attribute data of the master key. In other words, in order to improve the security of encryption operations using the master key or the controlled key, some embodiments of the present application also provide a technical solution for generating a check code based on control information held solely by the key holder.

[0087] The following is an example of the process of maintaining controlled key attributes.

[0088] In some embodiments of the present application, the above-mentioned process of generating a controlled key exemplarily includes: generating a second public-private key pair represented by plain text to obtain the controlled key, wherein the second public-private key pair includes a controlled public key and a controlled private key. Correspondingly, the above-mentioned process of encrypting at least the controlled key to obtain encrypted controlled key attribute data exemplarily includes: encrypting the controlled private key using the private key protection key plain text provided by the key management system to obtain the controlled key ciphertext; using the controlled key ciphertext and the controlled public key as at least part of the controlled key attribute data. Some embodiments of the present application encrypt the controlled private key using the private key protection key plain text provided by the key management system to obtain the controlled private key ciphertext and save the controlled private key ciphertext to facilitate the subsequent decryption of the controlled private key ciphertext and then encrypting it using the controlled private key.

[0089] To facilitate the search for the controlled key, in some embodiments of the present application, the method for generating key data further includes: assigning a controlled key identifier slaveId to the controlled key, where the controlled key identifier slaveId serves as the unique identifier of the controlled key, and the controlled key identifier slaveId serves as the controlled key index information; wherein, the controlled key attribute data includes the controlled key identifier slaveId. In some embodiments of the present application, in order to facilitate the search for the controlled key, a controlled key identifier is also established for each established controlled key, so that the key holder can authorize the corresponding controlled key to other users on the basis of providing the controlled key identifier (for example, using the controlled private key to complete signature authentication).

[0090] The following exemplarily elaborates on the implementation process of obtaining the association information.

[0091] In some embodiments of the present application, the process of establishing the association relationship between the master key and at least one controlled key in S103 exemplarily includes: encrypting the private key protection key plaintext with the key encryption key KEK provided by the key management system to obtain the private key protection key ciphertext ePek; encrypting the private key protection key ciphertext with the master public key to obtain the associated private key protection key ciphertext pubEncEPek; using the controlled key identifier, the master key, and the associated private key protection key ciphertext as the association information. That is to say, in some embodiments of the present application, the plaintext of the private key protection key used to encrypt the controlled private key is encrypted twice, and then the associated private key protection key ciphertext obtained after the double encryption is stored, improving the security of the controlled private key so that only authorized key holders can control the corresponding controlled private key.

[0092] In some embodiments of the present application, there are multiple master keys, and the multiple master keys are stored in the master key identifier list, and the master key identifier list is used to store multiple master keys and the master key identifier list numbers corresponding to each of the multiple master keys respectively. Among them, the process of establishing the association relationship between the master key and at least one controlled key in S103 exemplarily includes: encrypting the private key protection key ciphertext ePek with all the master keys in the master key identifier list to obtain multiple associated private key protection key ciphertexts, obtaining an association relationship set, where the association relationship belongs to one element in the association relationship set. In some embodiments of the present application, after generating a controlled key on the key management side, an association relationship between this controlled key and multiple master public keys will also be established, so that one controlled key can be controlled by the key holders of multiple master keys (that is, authorizing other users to use the controlled key).

[0093] To enhance the security of the key data stored in the key management system, in some embodiments of the present application, after S104, the method for generating key data further includes: performing a backup operation on the master key and the controlled key. That is to say, to enhance the security of the key data stored in the key management system, backup processing can also be performed on the master key and the controlled key.

[0094] To enhance the effectiveness of the key data, in some embodiments of the present application, after S104, the method for generating key data further includes: the key holder performs an operation of updating the master key and / or the controlled key by providing control information. That is to say, some embodiments of the present application also provide a technical solution for updating the key data (i.e., the master key and the controlled key) stored in the key management system.

[0095] To enhance the usage efficiency of the storage module on the key management system, in some embodiments of the present application, after S104, the method for generating key data further includes: the key holder destroys the master key and / or the controlled key by providing control information. That is to say, to efficiently utilize the storage space of the key management center, some embodiments of the present application also need to destroy the master key and the controlled key that are no longer in use.

[0096] The following Figure 4 exemplarily elaborates on the key management system of some embodiments of the present application.

[0097] The key management system constructed in some embodiments of the present application includes: a key service encapsulation module, a cryptographic module (corresponding to Figure 1 the cryptographic calculation module 101), a key storage module (corresponding to Figure 1 the storage module 102), and an out-of-band communication module. Each functional module within the boundary of the key management system should be deployed in a tamper-proof physical environment, and the tamper-proof physical environment can be a hardware server or other physical boundary, or a strictly controlled computer room.

[0098] Figure 4 The key service module of

[0099] Figure 4 is configured to encapsulate the key management protocol based on the cryptographic module (or cryptographic machine) and provide a key service interface for the application.

[0100] Figure 4The out-of-band communication module is configured to send an OTP (One Time Password) code directly to the user through the out-of-band device, and verify the user's ownership of the key based on a multi-factor (e.g., OTP and key authorization code) method.

[0101] Figure 4 The key storage module is configured to store the managed key ciphertext and its authorization information (or called association information). That is to say, in the embodiments of the present application, the key data stored in the key management system mainly includes three types: managed master key ciphertext, managed controlled key ciphertext and authorization relationship data (or called association relationship data). For example, in some embodiments of the present application, the master key ciphertext is protected by double encryption, first encrypted with the internal key of the password module to form a ciphertext, and then the key based on the multi-factor structure is used to encrypt the ciphertext again to form a double ciphertext. For example, in some embodiments of the present application, the managed controlled key ciphertext is protected by double encryption, first encrypted with the internal key of the password module to form a ciphertext, and then the private key protection key is used to encrypt the ciphertext again to form a double ciphertext. For example, in some embodiments of the present application, the authorization relationship data is used to record the association relationship between the master key and the controlled key, and the private key protection key ciphertext is stored in the authorization relationship (or called association relationship).

[0102] The following is an exemplary description of a method for encrypting data to be encrypted using a master key.

[0103] like Figure 5 As shown, some embodiments of the present application provide a method for encrypting data using a master key, which is applied in a key management system, and the method includes: S201, receiving master key index information, control information and data to be encrypted provided by a key holder; S202, searching and obtaining master key attribute data according to the master key index information; S203, decrypting the master key ciphertext included in the master key attribute data at least according to the control information to obtain the master key; S204, completing encryption processing of the data to be encrypted according to the master key.

[0104] In some embodiments of the present application, before decrypting the master key ciphertext included in the master key attribute data at least based on the control information to obtain the master key, the method also includes: obtaining a control verification code from the master key attribute data; calculating the control verification code to be verified based on the control information; and confirming that the control verification code is consistent with the verification code to be verified.

[0105] In some embodiments of the present application, decrypting the master key ciphertext included in the master key attribute data according to at least the control information to obtain the master key includes: obtaining a protection key according to the master key index information and the control information; decrypting the master key ciphertext with the protection key to obtain an initial decrypted master ciphertext; decrypting the initial decrypted master ciphertext with the first encrypted data provided by the key management system to obtain the master private key, where the master key includes the master private key and the master public key.

[0106] The following exemplarily elaborates on the method for encrypting data to be encrypted according to the controlled key.

[0107] As Figure 6 shown, some embodiments of the present application provide a method for encrypting data using a controlled key. The method includes: S301, receiving control information, a master key identification list number masterId, a controlled key identification slaveId, and data to be encrypted provided by a key holder; S302, obtaining associated information corresponding to the master key identification list number masterId according to the control information and the master key identification list number masterId, where the associated information includes an associated private key protection key ciphertext pubEncEPek; S303, decrypting the associated private key protection key ciphertext pubEncEPek to obtain a private key protection key ciphertext ePek; S304, decrypting the controlled key ciphertext with the private key protection key ciphertext ePek to obtain the controlled key; S305, encrypting the data to be encrypted based on the controlled key.

[0108] In some embodiments of the present application, decrypting the associated private key protection key ciphertext pubEncEPek to obtain the private key protection key ciphertext ePek includes: obtaining the master key according to the master key identification list number; obtaining the master private key from the master key, and decrypting the associated private key protection key ciphertext pubEncEPek with the master private key to obtain the private key protection key ciphertext ePek.

[0109] In some embodiments of the present application, decrypting the controlled key ciphertext with the private key protection key ciphertext ePek to obtain the controlled key includes: querying and obtaining controlled key attribute data according to the controlled key identification slaveId to obtain a controlled key ciphertext pekEncSlavePri; decrypting the private key protection key ciphertext ePek with a key protection key KEK to obtain a private key protection key plaintext pek; decrypting the controlled key ciphertext pekEncSlavePri with the private key protection key plaintext pek to obtain the controlled private key slavePri, where the controlled key includes the controlled private key.

[0110] The following is an exemplary description Figure 4 of the method for generating key data, the method for encrypting data, and the methods for updating and destroying password data executed by the password management system described below. In the following examples, the above control information is multi-factor control information, or two-factor control information included in the multi-factor control information.

[0111] The main working processes of the key management system provided by some embodiments of this application include: system initialization, creating a master key (i.e., generating master key attribute data), performing password operations using the master key (i.e., performing an encryption operation on the data to be encrypted using the master key), creating a controlled key (i.e., generating controlled key attribute data), authorizing the controlled key (i.e., obtaining the association relationship), and performing password operations using the controlled key (i.e., performing an encryption operation on the data to be encrypted using the controlled key).

[0112] The first step is system initialization

[0113] Before officially providing services externally, the system should initialize the necessary password resources, mainly including:

[0114] ① Generate an identity key pair (SAM_Pri, SAM_Pub) of the key management system within the password module, and this key pair is used to prove the identity of the management system externally.

[0115] ② Generate a key encryption key KEK within the password module, and this key is used to encrypt and protect the private keys of the master key and the controlled key to prevent the private keys from being exposed outside the password module.

[0116] ③ Generate an anti-tampering key SAM_SymKey within the password module, and this key is used to protect information such as OTP from being tampered with.

[0117] The second step is to create a master key

[0118] The key holder provides the two-factor control information of the key and calls the key service module to create a master key. The two-factor control information can be in the following forms:

[0119] ① PIN code + mobile phone number;

[0120] ② PIN code + email;

[0121] ③ Other multi-factor control forms.

[0122] The input, output, and execution process when the password management system creates a master key are as follows:

[0123] Input: Holder's two-factor information

[0124] Output: Master key keyId

[0125] Execution process:

[0126] ① Generate the first public-private key pair (pri, pub) of the plaintext within the password module to obtain the master public key pub and the master private key pri.

[0127] ② Use KEK (as an example of the first encrypted data) to encrypt the master private key pri included in the master key within the password module to obtain kekEncPri (as an example of the encrypted master private key), and the password module outputs (kekEncPri, pub) externally.

[0128] ③ The key management system assigns a unique keyId (i.e., the master identifier) to the master key, and jointly disperses (keyId, multi-factor control information) to obtain a symmetric key (as an example of the protection key) pinDivKey, and uses pinDivKey to encrypt kekEncPri to obtain the master key ciphertext pinEncPri. The master key ciphertext and the master public key (pinEncPri, pub) are used as the data included in the master key attribute data.

[0129] ④ The key management system calculates the check code of the multi-factor control information to obtain the control check code macPin.

[0130] ⑤ The key management system stores the master key attribute data (keyId, macPin, pinEncPri, pub), and keyId serves as the unique identifier of the master key.

[0131] In specific implementation, the key management system can also store other relevant information together with the key, such as the validity period of the key, the usage times limit, the mobile phone number and email of the holder, etc.

[0132] Step 3, perform cryptographic operations using the private key of the master key

[0133] After the master key is created, the private key ciphertext is stored in the key management system. When using the master key, the key holder should provide two-factor control information. The input, output, and execution process when using the master key are as follows:

[0134] Input: Two-factor information of the master key holder;

[0135] Output: The result of cryptographic calculation using the private key of the master key

[0136] Execution process:

[0137] ① The key holder provides keyId and two-factor control information.

[0138] ②The secure tube system uses the keyId index to obtain (keyId, macPin, pinEncPri, pub).

[0139] ③The secure tube system calculates the verification code of the multi-factor control information, compares it with macPin, and verifies the legality of the two-factor control information.

[0140] ④The secure tube system uses (keyId, multi-factor control information) to jointly disperse to obtain the protection key pinDivKey, and uses pinDivKey to decrypt pinEncPri to obtain kekEncPri.

[0141] ⑤The secure tube system uses kekEncPri and calls the cryptographic module for calculation (the cryptographic module supports calculations based on private key ciphertext).

[0142] ⑥Inside the cryptographic module, KEK is used to decrypt kekEncPri to obtain pri.

[0143] ⑦At this point, the plaintext of the private key of the master key is already in the cryptographic module, and the master key holder can use this private key for cryptographic calculations.

[0144] Step 4: Create a controlled key

[0145] The secure tube system can create a controlled key according to application requirements and associate the newly created controlled key with one or more master keys. The master key holder does not need to participate in the process of creating the controlled key, and the created controlled key can be used by any associated master key. The input, output, and execution process of the secure tube system when creating a controlled key are as follows:

[0146] Input: masterIds (list of master key identifiers, the created controlled key is associated with all master keys in the list)

[0147] Output: slaveId (controlled key identifier), slavePub (controlled key public key)

[0148] Execution process:

[0149] ①Generate a plaintext second public-private key pair (slavePri, slavePub) and the plaintext of the private key protection key pek inside the cryptographic module, use pek to encrypt slavePri to obtain the ciphertext of the controlled key pekEncSlavePri, use KEK to encrypt pek to obtain the ciphertext of the private key protection key ePek, and the cryptographic module outputs pekEncSlavePri, slavePub, ePek externally;

[0150] ②The secure tube service assigns a unique controlled key identifier slaveId, and stores slaveId, pekEncSlavePri, and slavePub as controlled key attribute data. It should be noted that ePek is not stored as controlled key data to prevent internal personnel from using ePek and the cryptographic module to obtain information related to the controlled key.

[0151] ③The secure tube service retrieves a master key materId from masterIds, queries the corresponding master key public key using masterId, and encrypts ePek using the public key of the master key to obtain pubEncEPek. (slaveId, masterId, pubEncEPek) is persistently stored as authorization information (or called the association relationship), that is, the controlled key identifier, the master key, and the ciphertext of the associated private key protection key are used as the association information.

[0152] ④Repeat step 3 in sequence, encrypt the same ePek using all the master keys in masterIds, and persistently store it.

[0153] That is to say, there are multiple master keys in some embodiments of the present application, and the multiple master keys are stored in the master key identifier list. The master key identifier list is used to store multiple master keys and the master key identifier list numbers corresponding to each of the multiple master keys. Among them, multiple ciphertexts of associated private key protection keys are obtained by encrypting the ciphertext ePek of the private key protection key respectively according to all the master keys in the master key identifier list, and an association relationship set is obtained. Among them, the association relationship belongs to an element in the association relationship set.

[0154] ⑤The secure tube module outputs slaveId and slavePub externally.

[0155] 5) Perform cryptographic operations using the private key of the controlled key

[0156] The private key of the controlled key can only be used by the holder of the master key that manages it. When the holder of the master key wants to use the private key of the controlled key for cryptographic calculations, the operation process is as follows:

[0157] Input: Two-factor information of the master key holder, master key identifier masterId, controlled key identifier slaveId, and private key operation data;

[0158] Output: The result of cryptographic calculation using the private key of the controlled key

[0159] Execution process:

[0160] ① The secure key management system uses two-factor information to authenticate the identity of the holder of the master key. The authentication methods include, but are not limited to, sending OTP information to the mobile phone or email of the key holder and authenticating the identity of the key holder based on the OTP.

[0161] ② The secure key management system uses the two-factor information of the master key holder and the master key identifier masterId to obtain the right to use the private key of the master key, and uses the private key of the master key to decrypt pubEncEPek to obtain ePek. The operation process is shown in "Performing cryptographic operations using the private key of the master key".

[0162] ③ The secure key management system queries and obtains the controlled key data using the controlled key identifier slaveId to get pekEncSlavePri.

[0163] ④ The secure key management system passes ePek, pekEncSlavePri, and operation data to the cryptographic module. Inside the cryptographic module, the KEK is used to decrypt ePek to obtain the plaintext of the private key protection key pek, pek is used to decrypt pekEncSlavePri to obtain the plaintext of the controlled private key slavePri, and then slavePri is used to perform operations on the private key operation data to obtain the operation result.

[0164] ⑤ The secure key management system returns the operation result.

[0165] 6) Backup operation of keys

[0166] The secure key management system can perform backup operations on the master key and the controlled key. During backup, there is no need to change the key data, and only the key ciphertext needs to be backed up. The authorization relationship between the master key and the controlled key should remain unchanged during the backup process.

[0167] 7) Update operation of the master key

[0168] When updating the master key, the master key holder should provide two-factor control information. The input, output, and execution process during key update are as follows:

[0169] Input: keyId, two-factor information of the master key holder;

[0170] Output: Update result (success or failure)

[0171] Execution process:

[0172] ① The master key holder provides keyId and two-factor control information.

[0173] ② The secure key management system uses keyId to index to get (keyId, macPin, pinEncPri, pub);

[0174] ③The cipher management system calculates the verification code of the multi-factor control information, compares it with macPin to verify the legality of the two-factor control information. If the verification fails, the key update fails; otherwise, the following steps are continued.

[0175] ④Generate a plaintext public-private key pair (newPri, newPub) within the cryptographic module, and encrypt newPri with KEK within the cryptographic module to obtain kekEncNewPri. The cryptographic module outputs (kekEncNewPri, newPub).

[0176] ⑤The cipher management system uses (keyId, multi-factor control information) to jointly generate a protection key pinDivKey through dispersion.

[0177] ⑥The cipher management system encrypts kekEncNewPri with pinDivKey to obtain (pinEncNewPri, newPub).

[0178] ⑦The cipher management system updates the original key record, updating (keyId, macPin, pinEncPri, pub) to (keyId, macPin, pinEncNewPri, newPub).

[0179] ⑧When the cipher management system updates the key record, it can also update other attributes, such as the validity period of the key, etc.

[0180] 8) Destruction operation of the master key

[0181] When the master key holder destroys the master key, the two-factor control information should be provided. The input, output, and execution process during key update are as follows:

[0182] Input: keyId, the two-factor information of the master key holder;

[0183] Output: Destruction result (success or failure)

[0184] Execution process:

[0185] ①The key holder provides keyId and two-factor control information.

[0186] ②The cipher management system uses keyId to index and obtain (keyId, macPin, pinEncPri, pub).

[0187] ③The cipher management system calculates the verification code of the multi-factor control information, compares it with macPin to verify the legality of the two-factor control information. If the verification fails, the key destruction fails; otherwise, the key data corresponding to keyId is deleted from the cipher management to complete the destruction operation.

[0188] 9) Update operation of controlled keys

[0189] The controlled key is updated by the master key holder. When the master key holder wants to update the controlled key, the operation process is as follows:

[0190] Input: two-factor information of the master key holder, master key identifier masterId, and slave key identifier slaveId;

[0191] Output: Update result (success or failure)

[0192] Execution process:

[0193] ① The key management system uses two-factor information to verify the identity of the master key holder. The verification method includes but is not limited to sending OTP information to the key holder's mobile phone or email address, and verifying the key holder's identity based on OTP. If the verification fails, the controlled key update fails, otherwise proceed to the following steps.

[0194] ② Generate a plaintext public-private key pair (newSlavePri, newSlavePub) and a private key protection key plaintext newPek in the cryptographic module, use newPek to encrypt newSlavePri to obtain pekEncNewSlavePri, use KEK to encrypt newPek to obtain eNewPek, and the cryptographic module outputs pekEncNewSlavePri, newSlavePub, and eNewPek.

[0195] ③ The key management service uses the input controlled key identifier slaveId to find the existing controlled key record, updates pekEncSlavePri to pekEncNewSlavePri, and updates slavePub to newSlavePub.

[0196] ④ The key management service uses masterId to query the corresponding master key public key, and uses the master key public key to encrypt eNewPek to obtain pubEncENewPek, and stores (slaveId, masterId, pubEncENewPek) as authorization information persistently; at this point, the controlled key operation is completed.

[0197] 10) Destruction of controlled keys

[0198] The controlled key is destroyed by the master key holder. When the master key holder wants to destroy the controlled key, the operation process is as follows:

[0199] Input: two-factor information of the master key holder, master key identifier masterId, and slave key identifier slaveId;

[0200] Output: Destruction result (success or failure)

[0201] Execution process:

[0202] ① The cipher tube system uses two-factor information to verify the identity of the holder of the master key. The verification methods include, but are not limited to, sending OTP information to the mobile phone or email of the key holder, and verifying the identity of the key holder based on the OTP. If the verification fails, the controlled key destruction fails; otherwise, the following steps are carried out.

[0203] ② The cipher tube system queries the key authorization table using masterId and slaveId to ensure that masterId has control authority over slaveId.

[0204] ③ The cipher tube system deletes the key record corresponding to slaveId and simultaneously deletes the control relationship between masterId and slaveId in the authorization table.

[0205] In summary, some embodiments of the present application achieve the key escrow ability where the key is independently controlled by the user (i.e., the key holder) and "visible but unusable" by the central side (i.e., the key management system). Its technical features include: 1) Key independent control ability. The key holder can perform "independent control" over the key based on two factors. By constructing a cryptographic protocol, the separation of key ownership (life cycle management) and governance rights (centralized storage, data backup, etc.) is achieved. It can effectively resist attacks such as database theft attacks by external attackers, as well as attacks such as identity impersonation, signature forgery, and protocol replay by internal attackers. 2) Terminal adaptation ability. There is no specific limitation on the terminal. Terminal users can use a general browser or a general client without the need to connect to additional hardware media. 3) Flexible authorization ability. The holder can authorize others to use the key, and the authorized person does not need to participate in the authorization process (the authorized person can also participate, but it is not necessary), thus simplifying the authorization operation.

[0206] It should be noted that in the above technical solution, a two-factor method is used to authenticate the master key holder, and in actual operation, it can be replaced with other methods according to the actual scenario, including but not limited to authenticating the master key holder through collaborative signature technology, authenticating the master key holder through a dedicated medium, authenticating the master key holder through a preset secret information, authenticating through further dispersion of a preset same seed key, etc. In the above technical solution, KEK is used to perform the first encryption on the private key plaintext. For the convenience of narration, it is not clearly stated whether the KEK in various scenarios is the same one. In the actual scenario, on the premise of ensuring the password strength, a unique KEK can be selected according to the application requirements, or several different KEKs can be selected according to the operation type, or even a KEK can be randomly selected each time of calculation, as long as the identifier corresponding to the KEK can be recorded in the persistently stored data and the KEK can be indexed in the subsequent operation.

[0207] Please refer to Figure 7 , Figure 7 which shows the key management system provided by the embodiment of the present application. It should be understood that this system corresponds to the above Figure 3 method embodiment and can execute each step involved in the above method embodiment. The specific functions of this system can be seen in the above description. To avoid repetition, the detailed description is appropriately omitted here. The system includes at least one software function module that can be stored in the memory in the form of software or firmware or solidified in the operating system of the key management system. This key management system includes: a master key generation module 111, a master key attribute data generation module 112, an association relationship establishment module 113, and a storage module 114.

[0208] The master key generation module 111 is configured to generate a master key, where the master key is controlled by a password holder through control information, and the control information is independently held by the password holder.

[0209] The master key attribute data generation module 112 is configured to at least perform encryption processing on the master key to obtain master key attribute data, where the master key attribute data at least includes a master key ciphertext and master key index information for finding the master key, and the master key ciphertext is obtained by performing encryption processing on the master key.

[0210] The association relationship establishment module 113 is configured to establish an association relationship between the master key and at least one controlled key, where the association relationship is used to record the control relationship of the master key to the controlled key, and the controlled key can be authorized to at least one object for use through the master key.

[0211] A storage module 114, configured to store at least the master key attribute data and the association relationship, so that the password holder can perform encryption operations according to the master key or authorize other objects to use the controlled key according to the association relationship.

[0212] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process of the above-described device can refer to the corresponding process in the foregoing method, and will not be elaborated here.

[0213] As Figure 8 shown, some embodiments of the present application provide a key management system, which includes: a first control information receiving module 121, a master key attribute data obtaining module 122, a decryption module 123, and a first encryption module 124.

[0214] The first control information receiving module 121 is configured to receive the master key index information and control information provided by the key holder, and the control information is independently held by the password holder.

[0215] The master key attribute data obtaining module 122 is configured to find the master key attribute data according to the master key index information.

[0216] The decryption module 123 is configured to decrypt the master key ciphertext included in the master key attribute data to obtain the master key.

[0217] The first encryption module 124 is configured to complete the encryption process of the data to be encrypted according to the master key.

[0218] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process of the above-described device can refer to the corresponding process in the foregoing method, and will not be elaborated here.

[0219] As Figure 9 shown, some embodiments of the present application provide a key management system, which includes: a second control information receiving module 131, an authorization information obtaining module 132, a second decryption template 133, a third decryption module 134, and a second encryption module 135.

[0220] The second control information receiving module 131 is configured to receive the control information, the master key identification list number masterId, the controlled key identification slaveId, and the data to be encrypted provided by the key holder.

[0221] The authorization information acquisition module 132 is configured to obtain authorization information corresponding to the master key identification list number masterId according to the control information and the master key identification list number masterId, where the authorization information includes the associated private key protection key ciphertext pubEncEPek.

[0222] The second decryption template 133 is configured to decrypt the associated private key protection key ciphertext pubEncEPek to obtain the private key protection key ciphertext ePek.

[0223] The third decryption module 134 is configured to decrypt the controlled key ciphertext according to the private key protection key ciphertext ePek to obtain the controlled key.

[0224] The second encryption module 135 is configured to perform an encryption process on the data to be encrypted based on the controlled key.

[0225] Some embodiments of the present application provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it can implement as Figure 3 、 Figure 5 or Figure 6 any of the methods described in the included embodiments.

[0226] As Figure 10 shown, some embodiments of the present application provide an electronic device 500, including a memory 510, a processor 520, and a computer program stored on the memory 510 and executable on the processor 520. Wherein, when the processor 520 reads the program from the memory 510 through the bus 530 and executes the program, it can implement as described above Figure 3 、 Figure 5 or Figure 6 any of the methods described in the method embodiments.

[0227] The processor 520 can process digital signals and can include various computing architectures. For example, a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, the processor 520 can be a microprocessor.

[0228] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of the instructions. These instructions and / or data can include code for implementing some or all of the functions of one or more modules described in the embodiments of the present application. The processor 520 of the embodiments of the present disclosure can be used to execute the instructions in the memory 510 to implement Figure 3The method shown in [description]. Memory 510 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.

[0229] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0230] In addition, in each embodiment of this application, the various functional modules can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part.

[0231] If the described functions are implemented in the form of software functional modules and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this application. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs, etc., which can store program codes.

[0232] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various modifications and changes can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0233] As described above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, and all of them should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0234] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

Claims

1. A method for key management and cryptographic calculation, applied to a key management system, characterized in that, the method includes: generating a master key, wherein the master key is independently controlled by a password holder through control information; at least encrypting the master key to obtain master key attribute data, wherein the master key attribute data at least includes a master key ciphertext and master key index information for searching for the master key, and the master key ciphertext is obtained by encrypting the master key; establishing an association relationship between the master key and at least one controlled key, wherein the association relationship is used to record the control relationship of the master key to the controlled key, and the controlled key can be authorized for use by at least one object through the master key; storing at least the master key attribute data and the association relationship, so that the password holder can perform an encryption operation according to the master key or authorize the controlled key to other objects according to the association relationship; the generating of the master key includes: generating a first public-private key pair represented in plaintext to obtain the master key, wherein the first public-private key pair includes a master public key and a master private key; the establishing of the association relationship between the master key and at least one controlled key includes: encrypting the private key protection key plaintext with a key encryption key KEK provided by the key management system to obtain a private key protection key ciphertext ePek; encrypting the private key protection key ciphertext with the master public key to obtain an associated private key protection key ciphertext pubEncEPek; using the controlled key identifier, the master key, and the associated private key protection key ciphertext as the association information.

2. The method according to claim 1, characterized in that, before the establishing of the association relationship between the master key and at least one controlled key, the method further includes: generating the controlled key; at least encrypting the controlled key to obtain controlled key attribute data, wherein the controlled key attribute data includes a controlled key ciphertext and controlled key index information for searching for the controlled key, and the controlled key ciphertext is obtained by encrypting the controlled key; the storing of at least the master key attribute data and the association relationship includes: storing the master key attribute data, the controlled key attribute data, and multiple association relationships.

3. The method according to claim 1, characterized in that, the at least encrypting the master key to obtain master key attribute data includes: encrypting the master private key with a first encryption data provided by the key management system to obtain an encrypted master private key; at least re-encrypting the encrypted master private key according to the control information to obtain the master key ciphertext, wherein the control information at least includes communication unit information that can communicate with the key holder and a control code known to the key holder; using the master key ciphertext and the master public key as at least part of the master key attribute data.

4. The method according to claim 3, wherein, the step of further encrypting the encrypted master private key according to the control information to obtain the master key ciphertext includes: assigning a master identifier keyId to the master key, where the master identifier keyId serves as the unique identifier of the master key, and the master identifier serves as the master key index information; obtaining a protection key according to the master identifier and the control information; performing a further encryption process on the encrypted master private key based on the protection key to obtain the master key ciphertext; wherein, the master key attribute data further includes the master identifier.

5. The method according to claim 3, wherein, the control code is a string or a multi-bit binary number, and the communication unit information includes: a mobile phone number or an email address.

6. The method according to claim 3, wherein, the control information is two-factor control information, and the two-factor control information includes: a PIN code and a mobile phone number, or a PIN code and an email address.

7. The method according to claim 4, wherein, the method further includes: calculating a check code of the control information to obtain a control check code, where the control check code is used to verify the legality of the control information before performing a cryptographic operation using the master key; taking the control check code as a part of the master key attribute data.

8. The method according to claim 2, wherein, the step of generating the controlled key includes: generating a second public-private key pair represented in plaintext to obtain the controlled key, where the second public-private key pair includes a controlled public key and a controlled private key; the step of at least encrypting the controlled key to obtain encrypted controlled key attribute data includes: encrypting the controlled private key using the private key protection key plaintext provided by the key management system to obtain the controlled key ciphertext; taking the controlled key ciphertext and the controlled public key as at least part of the content of the controlled key attribute data.

9. The method according to claim 8, wherein, the method further includes: assigning a controlled key identifier slaveId to the controlled key, where the controlled key identifier slaveId serves as the unique identifier of the controlled key, and the controlled key identifier slaveId serves as the controlled key index information; wherein, the controlled key attribute data includes the controlled key identifier slaveId.

10. The method according to claim 9, wherein, there are multiple master keys, and the multiple master keys are stored in a master key identifier list, and the master key identifier list is used to store multiple master keys and the master key identifier list numbers respectively corresponding to the multiple master keys, where the step of establishing an association relationship between the master key and at least one controlled key includes: Encrypt the private key protection key ciphertext ePek respectively according to all the master keys in the master key identification list to obtain a plurality of associated private key protection key ciphertexts, and obtain an association relationship set, wherein the association relationship belongs to an element in the association relationship set.

11. The method according to claim 1, characterized in that, after storing at least the master key attribute data and the association relationship, the method further includes: performing a backup operation on the master key and the controlled key.

12. The method according to claim 1, characterized in that, after storing at least the master key attribute data and the association relationship, the method further includes: the key holder performs an operation of updating the master key and / or the controlled key by providing control information.

13. The method according to claim 1, characterized in that, after storing at least the master key attribute data and the association relationship, the method further includes: the key holder destroys the master key and / or the controlled key by providing control information.

14. A method for encrypting data using a master key, applied in a key management system, characterized in that, the method includes: receiving master key index information, control information and data to be encrypted provided by a key holder, wherein the control information is independently held by the password holder; finding master key attribute data according to the master key index information; decrypting at least the master key ciphertext included in the master key attribute data according to the control information to obtain a master key; completing the encryption process of the data to be encrypted according to the master key; before decrypting at least the master key ciphertext included in the master key attribute data according to the control information, the method further includes: obtaining a control check code from the master key attribute data; calculating a control check code to be verified according to the control information; confirming that the control check code is consistent with the control check code to be verified; the decrypting at least the master key ciphertext included in the master key attribute data according to the control information to obtain a master key includes: obtaining a protection key according to the master key index information and the control information; decrypting the master key ciphertext according to the protection key to obtain an initial decrypted master ciphertext; decrypting the initial decrypted master ciphertext using the first encrypted data provided by the key management system to obtain a master private key, wherein the master key includes the master private key and a master public key.

15. A method for encrypting data using a controlled key, characterized in that, the method includes: receiving control information, a master key identification list number masterId, a controlled key identification slaveId and data to be encrypted provided by a key holder, wherein the control information is independently held by the password holder; Obtain the associated information corresponding to the master key identification list number masterId according to the control information and the master key identification list number masterId, where the associated information includes the associated private key protected key ciphertext pubEncEPek; Decrypt the associated private key protected key ciphertext pubEncEPek to obtain the private key protected key ciphertext ePek; Decrypt the controlled key ciphertext according to the private key protected key ciphertext ePek to obtain the controlled key; Encrypt the data to be encrypted based on the controlled key.

16. The method according to claim 15, wherein, The decrypting the associated private key protected key ciphertext pubEncEPek to obtain the private key protected key ciphertext ePek includes: Obtain the master key according to the master key identification list number; Obtain the master private key from the master key, and decrypt the associated private key protected key ciphertext pubEncEPek based on the master private key to obtain the private key protected key ciphertext ePek.

17. The method according to any one of claims 15-16, wherein, The decrypting the controlled key ciphertext according to the private key protected key ciphertext ePek to obtain the controlled key includes: Query and obtain the controlled key attribute data according to the controlled key identification slaveId to obtain the controlled key ciphertext pekEncSlavePri; Decrypt the private key protected key ciphertext ePek with the key encryption key KEK to obtain the private key protected key plaintext pek; Decrypt the controlled key ciphertext pekEncSlavePri with the private key protected key plaintext pek to obtain the controlled private key slavePri, where the controlled key includes the controlled private key.

18. A key management system, wherein, It is implemented by using the method described in claim 1, and the system includes: A master key generation module, configured to generate a master key, where the master key is controlled by a password holder through control information, and the control information is independently held by the password holder; A master key attribute data generation module, configured to at least encrypt the master key to obtain master key attribute data, where the master key attribute data at least includes a master key ciphertext and master key index information for finding the master key, and the master key ciphertext is obtained after encrypting the master key; An association relationship establishment module, configured to establish an association relationship between the master key and at least one controlled key, where the association relationship is used to record the control relationship of the master key over the controlled key, and the controlled key can be authorized for use by at least one object through the master key; A storage module, configured to at least store the master key attribute data and the association relationship, so that the password holder can perform an encryption operation according to the master key or authorize the controlled key to other objects according to the association relationship.

19. A key management system, wherein, Implemented by the method described in claim 15, the system includes: A first control information receiving module, configured to receive master key index information and control information provided by a key holder, wherein the control information is independently held by a password holder; A master key attribute data obtaining module, configured to find master key attribute data according to the master key index information; A decryption module, configured to decrypt the master key ciphertext included in the master key attribute data to obtain the master key; A first encryption module, configured to complete the encryption process of data to be encrypted according to the master key.

20. A key management system Characterized in that The system includes: A second control information receiving module, configured to receive control information, a master key identification list number masterId, a controlled key identification slaveId, and data to be encrypted provided by a key holder, wherein the control information is independently held by a password holder; An authorization information obtaining module, configured to obtain authorization information corresponding to the master key identification list number masterId according to the control information and the master key identification list number masterId, wherein the authorization information includes an associated private key protection key ciphertext pubEncEPek; A second decryption template, configured to decrypt the associated private key protection key ciphertext pubEncEPek to obtain a private key protection key ciphertext ePek; A third decryption module, configured to decrypt the controlled key ciphertext according to the private key protection key ciphertext ePek to obtain a controlled key; A second encryption module, configured to encrypt the data to be encrypted based on the controlled key.

21. A computer-readable storage medium, on which a computer program is stored Characterized in that When the program is executed by a processor, it can implement the method described in any one of claims 1-17.

22. An information processing device, including a memory, a processor, and a computer program stored on the memory and executable on the processor Wherein When the processor executes the program, it can implement the method described in any one of claims 1-17.

Citation Information

Patent Citations

  • Authorization signature method, device and system based on trusteeship key and storage medium

    CN112765626A

  • Unlocking authentication method and device, security chip and electronic key management system

    CN114267100A