A key management method and device, electronic equipment and storage medium
By constructing a multi-level cascaded key management architecture, and using the upper-level key management system to generate and encrypt interoperability keys, the control and management problem of the central key management system over the lower-level system is solved, and secure cross-domain transmission and management of encrypted data is realized.
Patent Information
- Application Number
- CN202211157003.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-22
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2042-09-22
AI Technical Summary
In existing technologies, the central key management system cannot uniformly manage the various subordinate key management systems, resulting in chaotic encrypted data circulation management. It lacks interoperability means for centralized management of subordinate key management systems and cannot meet the needs of data circulation management.
A multi-level cascaded key management architecture is constructed, in which the upper-level key management system generates interoperable master keys and interoperable keys for the lower-level key management system, thereby realizing data encryption protection between the upper and lower levels. The public key is encrypted and distributed offline to build a cascaded relationship, enabling cross-domain management and encrypted data exchange.
It enables the upper-level key management system to control and manage the lower-level system, ensures the secure transmission and management of encrypted data between all levels, solves the problem of cross-domain interoperability of encrypted data, and meets the needs of cross-domain management and encrypted data exchange.
Smart Images

Figure CN115499227B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and more particularly to a key management method and device, an electronic device and a computer readable storage medium. BACKGROUND
[0002] With the development of information industry technology and the cloudization of information systems, commercial cryptography applications have shown the characteristics of diversification, integration and ubiquity. Commercial cryptography has also begun to explore in various important industries. Under the premise of compliance, commercial cryptography technology is fully deployed to provide unified cryptographic services for information systems, meet the application development trend of ubiquitous cryptography, and meet the security requirements of system "compliance, correctness and effectiveness" in using cryptography.
[0003] In the fields of surveying and mapping, transportation and power, there is a clear management hierarchy in the process of informatization, such as central management of information in each province, provincial management of information in cities and companies, and a tree-like feature of "single center, multiple subordinates and layer-by-layer management". For the cryptographic transformation of such industry applications, it is required to independently construct a key management system at each subordinate to uniformly manage the key resources in the subordinate area, but there is no unified requirement for the key cascade management and encrypted information interconnection management between the superiors and subordinates and between the brothers of the same level. Generally, the key management is isolated from each other, the information cross-domain continues to use plaintext transmission, and the problem of information cross-domain access is solved by re-encrypting after reaching the target subordinate, or by using offline synchronization plaintext key to synchronize data encryption key in advance, or by using VPN equipment to build a virtual private network for transmission.
[0004] In the related art, the key management systems of the center and each local end are independent of each other, and are independent in construction, use and management. The center cannot uniformly manage the key management systems of each subordinate, and the subordinate key management systems do not perceive the existence of the superior or center key management systems, resulting in invalidation of the business management relationship in the key management system. The superior key management system cannot perceive and control the interconnection relationship of the subordinate key management system, which will cause confusion in the circulation management of encrypted data, lack of centralized management of the interconnectivity of the subordinates, and inability to meet the regular data circulation management requirements.
[0005] Therefore, how to realize the control and management of the superior key management system over the subordinate key management system is a technical problem to be solved by those skilled in the art. SUMMARY
[0006] The purpose of the present application is to provide a key management method and device, an electronic device and a computer readable storage medium, which realize the control and management of the superior key management system over the subordinate key management system.
[0007] To achieve the above object, the application provides a key management method applied to a key management architecture, wherein the key management architecture comprises a plurality of key management systems in a multi-level cascade, each upper key management system corresponding to a plurality of lower key management systems; the method comprises:
[0008] The upper key management system generates a corresponding interworking master key for each lower key management system and issues the interworking master key to the corresponding lower key management system.
[0009] The upper key management system generates a corresponding interworking key for each lower key management system and issues the interworking key to the corresponding lower key management system after encryption protection by the corresponding interworking master key; wherein the interworking key is used for transmission protection of a data encryption key between the upper key management system and the corresponding lower key management system, and the data encryption key is used for transmission protection of service data between the upper key management system and the corresponding lower key management system.
[0010] The upper key management system generates a corresponding interworking master key for each lower key management system and issues the interworking master key to the corresponding lower key management system, comprising:
[0011] When the upper key management system receives a request for applying an interworking master key sent by a lower key management system, the upper key management system generates a corresponding interworking master key for the lower key management system.
[0012] The interworking master key is encrypted by using the public key of the lower key management system and then issued to the lower key management system in an offline manner.
[0013] The first key management system and the second key management system at the same level perform transmission protection of a data encryption key between the first key management system and the second key management system by using the same interworking key, and the data encryption key is used for transmission protection of service data between the first key management system and the second key management system.
[0014] The method further comprises:
[0015] Receiving a registration request of a lower key management system; wherein the registration request at least comprises node information of the lower key management system.
[0016] Registering the lower key management system based on the node information of the lower key management system to construct a cascade relationship between the upper key management system and the lower key management system.
[0017] The method further comprises:
[0018] querying and / or modifying the node information of the lower-level key management system.
[0019] wherein further comprising:
[0020] suspending or resuming the key management service of the lower-level key management system.
[0021] wherein further comprising:
[0022] deleting the node information of the lower-level key management system and deleting the cascading relationship between the lower-level key management system.
[0023] To achieve the above object, the application provides a key management device applied to a key management architecture, the key management architecture comprising a plurality of key management systems in a multi-level cascade, each upper-level key management system corresponding to a plurality of lower-level key management systems; the device comprises:
[0024] a first generation module for generating, by the upper-level key management system, a corresponding interworking master key for each corresponding lower-level key management system and issuing the corresponding interworking master key to the corresponding lower-level key management system;
[0025] a second generation module for generating, by the upper-level key management system, a corresponding interworking key for each corresponding lower-level key management system and issuing the corresponding interworking key to the corresponding lower-level key management system after encryption protection by the corresponding interworking master key; wherein the interworking key is used for transmission protection of a data encryption key between the upper-level key management system and the corresponding lower-level key management system, and the data encryption key is used for transmission protection of service data between the upper-level key management system and the corresponding lower-level key management system.
[0026] To achieve the above object, the application provides an electronic device comprising:
[0027] a memory for storing a computer program;
[0028] a processor for executing the computer program to realize the steps of the above key management method.
[0029] To achieve the above object, the application provides a computer readable storage medium, the computer readable storage medium storing a computer program, the computer program being executed by a processor to realize the steps of the above key management method.
[0030] It can be known from the above scheme that the key management method provided in the application is applied to a key management architecture, the key management architecture includes a plurality of key management systems in a multi-level cascade, each upper key management system corresponds to a plurality of lower key management systems; the method includes: the upper key management system generates a corresponding interworking master key for each corresponding lower key management system and distributes the interworking master key to the corresponding lower key management system; the upper key management system generates a corresponding interworking key for each corresponding lower key management system and distributes the interworking key to the corresponding lower key management system after the interworking key is encrypted and protected by the corresponding interworking master key; wherein the interworking key is used for transmission protection of a data encryption key between the upper key management system and the corresponding lower key management system, and the data encryption key is used for transmission protection of service data between the upper key management system and the corresponding lower key management system.
[0031] In the application, a key management architecture in which a plurality of key management systems are in a multi-level cascade is constructed, the upper key management system generates a corresponding interworking master key for each corresponding lower key management system, which is used for encryption protection of an interworking key between the upper key management system and the lower key management system, and the upper key management system generates a corresponding interworking key for each corresponding lower key management system, which is used for encryption protection of a data encryption key between the upper key management system and the lower key management system. It can be seen that the key management method provided in the application realizes the construction of a cascade relationship with the lower key management system through the key domain management of the lower system by the upper key management system, realizes the key interworking of all devices and systems in the entire cascade system, and meets the cross-domain management and encrypted data exchange requirements between the upper key management system and the lower key management system. The application also discloses a key management device, an electronic device and a computer readable storage medium, which can also achieve the above technical effects.
[0032] It should be understood that the foregoing general description and the following detailed description are only exemplary and cannot limit the application. BRIEF DESCRIPTION OF DRAWINGS
[0033] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description only some embodiments of the application, and for those skilled in the art, without creative labor, other drawings can also be obtained from these drawings. The drawings are used to provide further understanding of the present disclosure and constitute a part of the specification, and together with the following specific embodiments, they are used to explain the present disclosure, but do not constitute a limitation on the present disclosure. In the drawings:
[0034] Figure 1A structure diagram of a key management architecture according to an exemplary embodiment;
[0035] Figure 2 A structure diagram of a cascade key system according to an exemplary embodiment;
[0036] Figure 3 A flow chart of a key management method according to an exemplary embodiment;
[0037] Figure 4 A schematic diagram of vertical cascade management according to an exemplary embodiment;
[0038] Figure 5 A schematic diagram of horizontal cascade management according to an exemplary embodiment;
[0039] Figure 6 A structure diagram of a key management device according to an exemplary embodiment;
[0040] Figure 7 A structure diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION
[0041] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by a person of ordinary skill in the art without any creative work fall within the protection scope of the present application. In addition, in the embodiments of the present application, “first”, “second” and the like are used to distinguish similar objects, rather than necessarily used to describe a specific order or sequence.
[0042] In order to understand the key management method provided by the present application, first, the key management architecture applied by the key management method is introduced, which includes multiple key management systems in multiple cascades, and each upper key management system corresponds to multiple lower key management systems.
[0043] Referring to Figure 1 , Figure 1 A structure diagram of a key management architecture according to an exemplary embodiment. As shown in Figure 1 , the key management architecture is divided into multiple levels, the uppermost layer is a key management system deployed at a center end, and the second layer and lower layers are key management systems deployed at local lower levels.
[0044] Among them, the center end key management system (referred to as the center key tube) as the center of the cascade key tube system, uniformly manages the key tube in the whole domain, and other intermediate key tubes (not the lowest level key tube) each manages the subordinate lower level key tube. Through the sub-domain management of the key, the intercommunication management of the key tube system and the cross-domain exchange of encrypted data based on the intercommunication of the key are realized. At the same time, each key management sub-domain provides key management services for the password application in each sub-domain, and realizes the whole life cycle management of the data encryption key from generation to destruction.
[0045] The key system includes a system local master key, an intercommunication master key, a key encryption key, a user master key, an intercommunication key, and a data encryption key.
[0046] Among them, the local master key is used to protect the key encryption key and the intercommunication master key, and will also be used to protect other key import and export password devices. The key encryption key is used to store and protect the user master key, and the intercommunication master key is used to distribute and protect the intercommunication key. The user master key is used to protect and distribute the service key, and the intercommunication key is used to protect and distribute the data encryption key. The data encryption key is used for business data encryption.
[0047] The cascade key system is as shown in Figure 2 The upper level key management system manages the vertical intercommunication master key and the vertical intercommunication key of all lower level key management systems, which is used to build the vertical intercommunication relationship between the upper and lower levels. The lower level key management system manages the vertical intercommunication master key of the upper level key management, which is used for the intercommunication of the upper and lower levels. The same level key management system manages the horizontal intercommunication master key and the horizontal intercommunication key. If the same level contains N key management systems, each key management system needs to save N-1 groups of intercommunication master keys and horizontal intercommunication keys. The vertical key and the horizontal key are destroyed when the intercommunication relationship is cancelled, and the destroyed intercommunication key cannot be used continuously.
[0048] This embodiment constructs the key management system of each region by level, registers and records all key management systems through the key tube intercommunication management process, and the lower level key management system registers and records in the directly subordinate upper level key management system in the cascade relationship. The upper level key management system manages the directly subordinate lower level key management system. The key tube intercommunication relationship is built, that is, the key intercommunication in the key management system is realized. The two ends of data transmission directly transmit the cross-domain transmission of the ciphertext through the key tube system with the existing intercommunication relationship, solves the problem of encrypted data intercommunication from the root on the premise of guaranteeing the key independence of each lower level key management system. In the key management architecture with cascade relationship built, the center key management system manages the intercommunication relationship of the second level key management system, the second level key management system manages the intercommunication relationship of the third level key management system, and so on, finally forming a tree-shaped cascade intercommunication management system.
[0049] The embodiment of the application discloses a key management method, which realizes the control and management of a superior key management system on a subordinate key management system.
[0050] Referring to Figure 3 , a flowchart of a key management method according to an exemplary embodiment is shown, as Figure 3 shown, comprising:
[0051] S101: The superior key management system generates a corresponding interworking master key for each corresponding subordinate key management system, and distributes the interworking master key to the corresponding subordinate key management system.
[0052] The vertical cascade management is as shown in Figure 4 In this step, the superior key management system generates different interworking master keys for each subordinate key management system, which is used to ensure the security of the vertical transmission of the interworking key distributed between the superior key management system and the subordinate key management system. Preferably, the interworking master key is encrypted by the public key provided by each subordinate key management system, and is securely distributed to each subordinate key management system in an offline manner.
[0053] As a feasible implementation manner, this step can include: when the superior key management system receives a request for applying for an interworking master key sent by a subordinate key management system, generating a corresponding interworking master key for the subordinate key management system; encrypting the interworking master key by using the public key of the subordinate key management system, and then distributing the interworking master key to the subordinate key management system in an offline manner.
[0054] In a specific implementation, the subordinate key management system generates a request for applying for an interworking master key, and the request data structure includes: a unique identifier of the subordinate key management system (not containing the unique identifier of the subordinate key management system when applying for the interworking master key for the first time, and containing the unique identifier of the subordinate key management system when applying for the interworking master key subsequently), a unique identifier of a business system or a device, a protection key algorithm type, an interworking master key protection public key, a request signature public key and a signature value. The interworking master key application file can be represented in a JSON text format, and is returned after being encoded by Base64. Except the signature value field, all fields need to be added to the signature calculation.
[0055] The superior key management system imports the request for applying for an interworking master key generated by the subordinate key management system, parses the request and waits for the administrator to review, generates the interworking master key after the review is passed, and the superior key management system also needs to generate a unique identifier of the subordinate key management system for the subordinate key management system when the subordinate key management system applies for the interworking master key for the first time.
[0056] It should be noted that each lower-level key management system can correspond to multiple business systems or devices, and the upper-level key management system can generate multiple different interworking master keys for different business systems or devices.
[0057] The upper-level key management system exports the interworking master key generated for the lower-level key management system, and the response data structure includes: a unique identifier of the lower-level key management system, interworking master key ciphertext data encrypted by a public key, a signature public key, and a signature value. The response data can also be represented in JSON text format and output after Base64 encoding.
[0058] The lower-level key management system imports the interworking master key response data exported by the upper-level key management system, parses the interworking master key ciphertext and injects it into the managed device or system.
[0059] S102: The upper-level key management system generates a corresponding interworking key for each corresponding lower-level key management system, and distributes it to the corresponding lower-level key management system after encryption protection by the corresponding interworking master key; wherein the interworking key is used to transmit and protect the data encryption key between the upper-level key management system and the corresponding lower-level key management system, and the data encryption key is used to transmit and protect the business data between the upper-level key management system and the corresponding lower-level key management system.
[0060] In this step, the upper-level key management system generates a vertical interworking key for each lower-level key management system to protect the transmission of data encryption keys between the upper and lower levels, ensuring the security of vertical business data between the upper-level business system and each lower-level business system.
[0061] In specific implementation, after the lower-level key management system completes the interworking master key application and import, it applies for an interworking key online, generates an application interworking key request, uploads the request to the upper-level key management system through an online way, waits for the system administrator to review, and obtains the interworking key online and injects it into the managed device or system. The interworking key is returned after encryption protection by the interworking master key.
[0062] The upper-level key management system receives the interworking key application uploaded by the lower-level key management system, parses the request and waits for the administrator to review, generates an interworking key after the review is passed, generates a unique request ID and returns it to the lower-level key management system, and the lower-level key management system can obtain the interworking key online through the request ID.
[0063] The lower-level key management system obtains the interoperability key online from the higher-level key management system. The response data structure includes: a unique identifier for the lower-level key management system, a unique identifier for the business system or device, a unique identifier for the peer key management system, a unique identifier for the peer business system or device, the encrypted interoperability key data protected by the interoperability master key, and the signature value. This can also be represented in JSON text format and output after Base64 encoding.
[0064] In this embodiment, a multi-level cascaded key management architecture is constructed, comprising multiple key management systems. Each higher-level key management system generates a corresponding interoperability master key for its lower-level key management system, used to encrypt and protect the interoperability keys between the two systems. Similarly, each higher-level key management system generates a corresponding interoperability key for its lower-level key management system, used to encrypt and protect the data encryption keys between them. Therefore, the key management method provided in this embodiment achieves cascading relationships with lower-level key management systems through domain-based key management by the higher-level key management system. This enables key interoperability among all devices and systems within the entire cascaded system, satisfying the cross-domain management and encrypted data exchange requirements between the higher-level and lower-level key management systems.
[0065] Based on the above embodiments, as a preferred implementation, the first key management system and the second key management system at the same level use the same interoperability key to protect the transmission of the data encryption key between the first key management system and the second key management system. The data encryption key is used to protect the transmission of business data between the first key management system and the second key management system.
[0066] Horizontal cascading management, such as Figure 5 As shown, in practical implementation, the two horizontal key management systems achieve interconnection and interoperability of cross-domain business data through a shared interoperability key. The interoperability key is generated by the upper-level key management system for information exchange between the two lower-level key management systems, and is distributed to the corresponding key management systems after being protected by their respective interoperability master keys. The two lower-level business systems protect their data encryption keys with a consistent interoperability key, thus achieving secure transmission of cross-domain business data.
[0067] Therefore, based on the password technology and the key synchronization technology, the elastic and scalable key cascade management is completed through the vertical and horizontal cascade system construction of the key management system, and the cross-domain intercommunication of the business system data based on the key management system can be completed. That is, the cascade management problem of the key management is solved, and in the industry application of the cascade management, a consistent management strategy can be adopted for the key management system dependent on the business based on the hierarchical relationship of the business. In addition, based on the original key intercommunication technology of the key management system, the problem of cross-domain intercommunication of encrypted data between business systems can be solved without introducing other components or products, which has low cost, small influence and transparent process.
[0068] On the basis of the above-mentioned embodiments, as a preferred embodiment, the method further comprises: receiving a registration request of a lower-level key management system; wherein the registration request at least includes node information of the lower-level key management system; and registering the lower-level key management system based on the node information of the lower-level key management system, to construct a cascade relationship between the upper-level key management system and the lower-level key management system.
[0069] It can be cracked that the lower-level key management system reports the node information to the upper-level key management system, and the upper-level key management system completes the registration of the node after auditing. In specific implementation, after the lower-level key management system is constructed, the necessary node information is reported to the upper-level key management system, which can include node name, node internal identifier, contact information, IP and port, registration time, etc. After the upper-level key management system verifies the identity and legality of the request, the registration of the node corresponding to the lower-level key management system is completed, and the node is included in the node management system to realize the management of the node. After the lower-level key management system completes the registration, the intercommunication key can be applied online to complete the cross-domain intercommunication with other key management systems.
[0070] On the basis of the above-mentioned embodiments, as a preferred embodiment, the method further comprises: querying and / or modifying the node information of the lower-level key management system.
[0071] In specific implementation, the upper-level key management system can query and modify the node information of each lower-level key management system.
[0072] On the basis of the above-mentioned embodiments, as a preferred embodiment, the method further comprises: suspending or resuming the key management service of the lower-level key management system.
[0073] In specific implementation, the upper-level key management system can suspend the service and management of a certain lower-level key management system by suspending the use function. The upper-level key management system can resume the service and management of a certain lower-level key management system by resuming the use function.
[0074] On the basis of the above-mentioned embodiments, as a preferred embodiment, the method further comprises: deleting the node information of the subordinate key management system, and deleting the cascading relationship between the subordinate key management system.
[0075] In a specific implementation, when the subordinate key management system needs to be revoked or separated from the management and control of the superior key management system, the superior key management system can delete the node corresponding to the subordinate key management system in the node management, and no longer serve and supervise the node.
[0076] Next, a key management device provided by an embodiment of the present application is described, and the key management device described below can be referred to in conjunction with the key management method described above.
[0077] Referring to Figure 6 , a structural diagram of a key management device according to an example embodiment is shown, as Figure 6 shown, comprising:
[0078] The first generation module 100 is configured to generate, by the superior key management system, a corresponding intercommunication master key for each corresponding subordinate key management system, and deliver the intercommunication master key to the corresponding subordinate key management system.
[0079] The second generation module 200 is configured to generate, by the superior key management system, a corresponding intercommunication key for each corresponding subordinate key management system, and deliver the intercommunication key to the corresponding subordinate key management system after encryption protection by the corresponding intercommunication master key; wherein the intercommunication key is used for transmission protection of a data encryption key between the superior key management system and the corresponding subordinate key management system, and the data encryption key is used for transmission protection of service data between the superior key management system and the corresponding subordinate key management system.
[0080] In the embodiment of the present application, a multi-level cascading key management architecture of multiple key management systems is constructed, the superior key management system generates a corresponding intercommunication master key for each corresponding subordinate key management system, which is used for encryption protection of an intercommunication key between the superior key management system and the subordinate key management system, and the superior key management system generates a corresponding intercommunication key for each corresponding subordinate key management system, which is used for encryption protection of a data encryption key between the superior key management system and the subordinate key management system. As can be seen, the key management device provided by the embodiment of the present application realizes the construction of a cascading relationship with the subordinate key management system through the key domain management of the subordinate system by the superior key management system, realizes the key intercommunication of all devices and systems within the entire cascading system, and meets the cross-domain management and encrypted data exchange requirements between the superior key management system and the subordinate key management system.
[0081] On the basis of the above-mentioned embodiments, as a preferred implementation, the first generation module 100 is specifically configured to: when the upper key management system receives a request for intercommunication master key sent by the lower key management system, generate a corresponding intercommunication master key for the lower key management system; and after encrypting the intercommunication master key by using the public key of the lower key management system, issue the intercommunication master key to the lower key management system in an offline manner.
[0082] On the basis of the above-mentioned embodiments, as a preferred implementation, the first key management system and the second key management system at the same level transmit and protect the data encryption key between the first key management system and the second key management system by using the same intercommunication key, and the data encryption key is used for transmitting and protecting the service data between the first key management system and the second key management system.
[0083] On the basis of the above-mentioned embodiments, as a preferred implementation, the method further comprises:
[0084] The receiving module is configured to receive a registration request of a lower key management system, and the registration request at least comprises node information of the lower key management system.
[0085] The registration module is configured to register the lower key management system based on the node information of the lower key management system, so as to construct a cascading relationship between the upper key management system and the lower key management system.
[0086] On the basis of the above-mentioned embodiments, as a preferred implementation, the method further comprises:
[0087] The first management module is configured to query and / or modify the node information of the lower key management system.
[0088] On the basis of the above-mentioned embodiments, as a preferred implementation, the method further comprises:
[0089] The second management module is configured to suspend or restore the key management service of the lower key management system.
[0090] On the basis of the above-mentioned embodiments, as a preferred implementation, the method further comprises:
[0091] The deleting module is configured to delete the node information of the lower key management system and delete the cascading relationship between the lower key management system.
[0092] As to the apparatus in the above-mentioned embodiments, the specific manners in which various modules perform operations have been described in details in the embodiments of the method, and will not be described in details here.
[0093] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of the present application, the embodiments of the present application also provide an electronic device, Figure 7 A structural diagram of an electronic device according to an exemplary embodiment is shown in FIG. 1. As shown in FIG. 1, the electronic device includes: Figure 7
[0094] A communication interface 1 capable of information interaction with other devices such as network devices and the like;
[0095] A processor 2 connected with the communication interface 1 to implement information interaction with other devices, for running a computer program, and executing the key management method provided by one or more of the above technical solutions. The computer program is stored on a memory 3.
[0096] Of course, in actual application, various components in the electronic device are coupled together through a bus system 4. It can be understood that the bus system 4 is used to realize the connection and communication between the components. The bus system 4 includes not only a data bus, but also a power bus, a control bus and a status signal bus. However, in order to clearly illustrate, all kinds of buses are marked as the bus system 4 in the Figure 7
[0097] The memory 3 in the embodiments of the present application is used to store various types of data to support the operation of the electronic device. Examples of these data include: any computer program for operating on the electronic device.
[0098] It can be understood that the memory 3 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM can be used, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), sync link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory 3 described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.
[0099] The method disclosed in the embodiments of the present application can be applied to the processor 2 or implemented by the processor 2. The processor 2 can be an integrated circuit chip with processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware in the processor 2 or the instruction in the form of software. The processor 2 described above can be a general processor, a DSP, or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The processor 2 can implement or execute the disclosed methods, steps and logic block diagrams in the embodiments of the present application. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the execution can be directly embodied as hardware decoding processor or executed by the combination of hardware and software modules in the decoding processor. The software module can be located in the storage medium, which is located in the memory 3. The processor 2 reads the program in the memory 3 and combines the hardware to complete the steps of the above method.
[0100] The processor 2 implements the corresponding flow in each method of the embodiments of the present application when executing the program. For brevity, it will not be repeated here.
[0101] In the exemplary embodiments, the embodiments of the present application also provide a storage medium, i.e. a computer storage medium, specifically a computer readable storage medium, for example, including the memory 3 storing the computer program, the above computer program can be executed by the processor 2 to complete the steps of the above method. The computer readable storage medium can be FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.
[0102] Those skilled in the art can understand that all or part of the steps of the above method embodiments can be completed by program instruction related hardware, and the above program can be stored in a computer readable storage medium. The program is executed to perform the steps of the above method embodiments, and the above storage medium includes mobile storage device, ROM, RAM, magnetic disc or optical disc, etc. Various media that can store program codes.
[0103] Alternatively, the above-mentioned integrated units of the present application, if realized in the form of software function modules and sold or used as independent products, can also be stored in a computer-readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions for causing an electronic device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the embodiments of the present application. The aforementioned storage medium includes: mobile storage devices, ROM, RAM, magnetic disks or optical disks, and various media that can store program codes.
[0104] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A key management method characterized by comprising: The method is applied to a key management architecture, the key management architecture comprises a plurality of key management systems in a multi-level cascade, each upper key management system corresponds to a plurality of lower key management systems; the method comprises: The upper key management system generates a corresponding different interworking master key for each corresponding lower key management system and issues it to the corresponding lower key management system; each lower key management system corresponds to a plurality of business systems or devices, and the upper key management system generates a plurality of different interworking master keys for different business systems or devices; The upper key management system generates a corresponding interworking key for each corresponding lower key management system and issues it to the corresponding lower key management system after encryption protection by the corresponding interworking master key; wherein the interworking key is used for transmission protection of a data encryption key between the upper key management system and the corresponding lower key management system, and the data encryption key is used for transmission protection of business data between the upper key management system and the corresponding lower key management system; Wherein, the first key management system and the second key management system at the same level protect the data encryption key between the first key management system and the second key management system by the same interworking key, and the data encryption key is used for transmission protection of business data between the first key management system and the second key management system.
2. The key management method of claim 1, wherein, The upper key management system generates a corresponding interworking master key for each corresponding lower key management system and issues it to the corresponding lower key management system, comprising: When the upper key management system receives a request for applying an interworking master key sent by a lower key management system, the corresponding interworking master key is generated for the lower key management system; After encrypting the interworking master key by using the public key of the lower key management system, it is issued to the lower key management system in an offline manner.
3. The key management method of claim 1, wherein, Further comprising: Receiving a registration request of a lower key management system; wherein the registration request at least comprises node information of the lower key management system; Registering the lower key management system based on the node information of the lower key management system to construct a cascade relationship between the upper key management system and the lower key management system.
4. The key management method of claim 3, wherein, Further comprising: Querying and / or modifying the node information of the lower key management system.
5. The key management method of claim 3, wherein, Further comprising: Suspending or resuming the key management service of the lower key management system.
6. The key management method of claim 3, wherein, Further comprising: Deleting the node information of the lower key management system and deleting the cascade relationship with the lower key management system.
7. A key management apparatus characterized by comprising: The device is applied to a key management architecture, the key management architecture comprises a plurality of key management systems in a multi-level cascade, each upper key management system corresponds to a plurality of lower key management systems; the device comprises: The first generation module is configured to generate different intercommunication master keys corresponding to different subordinate key management systems respectively by the superior key management system, and distribute the intercommunication master keys to the subordinate key management systems; each subordinate key management system corresponds to a plurality of business systems or devices, and the superior key management system generates a plurality of different intercommunication master keys for different business systems or devices respectively; The second generation module is configured to generate an intercommunication key corresponding to a subordinate key management system by the superior key management system, encrypt the intercommunication key by using the corresponding intercommunication master key, and then distribute the intercommunication key to the subordinate key management system; the intercommunication key is used for transmission protection of a data encryption key between the superior key management system and the subordinate key management system, and the data encryption key is used for transmission protection of business data between the superior key management system and the subordinate key management system; The first key management system and the second key management system at the same level are protected by the same intercommunication key, and the data encryption key between the first key management system and the second key management system is protected by the intercommunication key; the data encryption key is used for transmission protection of business data between the first key management system and the second key management system.
8. An electronic device, comprising: The memory is configured to store a computer program; The processor is configured to execute the computer program to implement the steps of the key management method according to any one of claims 1 to 6. The computer program is stored on the computer readable storage medium, and the computer program is executed by the processor to implement the steps of the key management method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that,
Citation Information
Patent Citations
Encrypted storage key management system and method of high-speed network
CN106330868A