Mimic server cryptographic machine model and secure communication method

Through the heterogeneous design of the mimicry server cipher machine model, the vulnerabilities and backdoor problems of the server cipher machine are solved, its security is improved, and the security of password service data transmission is ensured.

CN115694824BActive Publication Date: 2025-05-23HENAN XINDA WANGYU TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211093186.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-08
Publication Date
2025-05-23
Estimated Expiration
2042-09-08

AI Technical Summary

Technical Problem

There is a risk of illegal calls from the server password machine and the risk of illegal tampering with the processing results, resulting in vulnerabilities and backdoor problems, affecting its security.

Method used

The verbright server cipher machine model is adopted to ensure the security of data transmission through the heterogeneous design of business left brackets, management left brackets, and execution of body pools and closing brackets.

Benefits of technology

It effectively solves vulnerabilities and backdoor problems in the server password machine operation environment, improves its security, ensures the security of password service data transmission, and is suitable for public key infrastructure systems and large-scale host systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115694824B_ABST
    Figure CN115694824B_ABST
Patent Text Reader

Abstract

The present invention provides a mimetic server cryptographic machine model and a secure communication method, wherein the mimetic server cryptographic machine model includes a business left bracket, which is used to receive business request data, add a label I to the received business request data, etc.; a management left bracket, which is used to receive password management service request data, add a label II to the received password management service request data, etc.; an execution body pool, which is configured with N business execution bodies and M management execution bodies; a right bracket, which is used to adjudicate business request data with the same label I and the corresponding inspection results, and if the adjudication fails, the business request is blocked, and if the adjudication passes, the business request data is sent to the password card mounted on the right bracket, etc. The present invention is heterogeneous at the two levels of management service and business service, and the management service and the business service are equipped with independent left bracket modules, which effectively solves the loopholes and backdoor problems existing in the server cryptographic machine operating environment and improves its own security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of mimicry defense technology, and in particular to a mimicry server cryptographic machine model and a secure communication method. Background Art

[0002] The server cryptographic machine (cryptographic server), also known as the host encryption server, can independently or concurrently provide cryptographic services and key management for multiple application entities, and supports a variety of cryptographic algorithms. Symmetric algorithms mainly include SM1, SM4, 3DES, AES, etc., and asymmetric algorithms mainly include RSA, SM2, etc. The server cryptographic machine can realize functions such as data encryption and decryption, digital signature verification, key generation, key storage, and key management. It is widely used in e-commerce, e-government, CA certification, online banking and other server-sides, and can provide basic, efficient, and stable cryptographic services for various security application systems such as e-government, CA certification, cloud storage, and the Internet of Things.

[0003] As a cryptographic service provider, the server cryptographic machine adopts the B / S (full name: Browser / Server) mode to provide cryptographic related services to the outside world. The caller sends a command request to the cryptographic machine, and the server cryptographic machine analyzes and processes the command request, and returns the processing result to the caller in the form of a command response. Since B / S is built on a wide area network and usually communicates through the network, there is a risk of illegal calls to the server cryptographic machine, and the processing results returned by the server cryptographic machine are also at risk of being illegally tampered with.

[0004] From the above analysis, it can be seen that the security of server cryptographic machines is of vital importance. The security of server cryptographic machines mainly depends on the security of keys and the security of service operation carriers. Therefore, the inherent security issues of server cryptographic machines can be attributed to the vulnerabilities and backdoors of software and hardware. On the one hand, the static, deterministic and single architecture of traditional cryptographic devices have inherent "genetic defects". On the other hand, the basic software and hardware environments that traditional cryptographic devices, cyberspace and communication networks rely on are similar, making the "genetic defects" of various basic software and hardware environments similar; therefore, these factors lead to vulnerabilities and backdoors. Once they are exploited, it is very likely to cause large-scale and continuous security threats and losses.

[0005] Therefore, how to improve the security of the server cryptographic machine operating environment has become an urgent problem to be solved.

[0006] In order to solve the above problems, people have been seeking an ideal technical solution. Summary of the invention

[0007] The purpose of the present invention is to provide a virtual server cryptographic machine model and a secure communication method in view of the deficiencies in the prior art.

[0008] In order to achieve the above object, the technical solution adopted by the present invention is:

[0009] The first aspect of the present invention provides a pseudo server cryptographic machine model, which includes:

[0010] The business left bracket is used to receive business request data, add label I to the received business request data and distribute it to each business executor in the executor pool; it is also used to receive the response result I returned by each business executor and make a decision on the response result I;

[0011] The management left bracket is used to receive the password management service request data, add the label Ⅱ to the received password management service request data and distribute it to each management executor in the executor pool; it is also used to receive the response result Ⅱ returned by each management executor and make a decision on the response result Ⅱ;

[0012] The executor pool is configured with N business executors and M management executors;

[0013] N service execution bodies are respectively connected to the service left bracket for communication, and are used to receive service request data from the service left bracket, perform rule check on the received service request data, generate corresponding check results, and encapsulate the check results and label I, and send them together with the service request data to the right bracket; and are also used to receive the response result I returned by the right bracket, and forward it to the service left bracket;

[0014] M management execution bodies are respectively connected to the management left bracket for communication, and are used to receive the password management service request data from the management left bracket, parse the received password management service request data, and send the label II and the parsing result to the right bracket; and are also used to receive the response result II returned by the right bracket, and forward it to the management left bracket;

[0015] and a right bracket, which are respectively connected to the business executor and the management executor for communication, and are used to make a decision on the business request data and the corresponding inspection results with the same label I. If the decision is not passed, the business request is blocked. If the decision is passed, the business request data passed is sent to the password card mounted on the right bracket; it is also used to receive the response result I generated by the password card and transmit it to N business executors respectively; it is also used to make a decision on the parsing result with the same label II. If the decision is not passed, the password management service request is blocked. If the decision is passed, the password management service request corresponding to the parsing result is responded to.

[0016] A second aspect of the present invention provides a secure communication method, the method comprising a business request data transmission phase and a password management service request data transmission phase, wherein:

[0017] During the business request data transmission phase, the following steps are performed:

[0018] Step A1, the business left bracket receives the business request data, adds label I to the received business request data, and distributes it to each business executor in the executor pool;

[0019] Step A2, after receiving the service request data from the service left bracket, the service execution body performs a rule check on the received service request data, generates a corresponding check result, and encapsulates the check result and label I, and sends them together with the service request data to the right bracket;

[0020] Step A3, the right bracket makes decisions on the service request data with the same tag I and the corresponding inspection results respectively. If the decision is not passed, the service request is blocked. If the decision is passed, the passed service request data is sent to the password card mounted on the right bracket;

[0021] Step A4, the password card generates a response result I based on the service request data, and transmits it to N service execution bodies respectively through the right bracket;

[0022] Step A5, the business execution body receives the response result I returned by the right bracket, and forwards it to the business left bracket;

[0023] Step A6, the business left bracket receives the response result I returned by each business execution body, makes a decision on the response result I, and outputs the response result I after the decision is passed;

[0024] During the password management service request data transmission phase, the following steps are performed:

[0025] Step B1, the management left bracket receives the password management service request data, adds the label II to the received password management service request data and distributes it to each management executive in the executive pool;

[0026] Step B2, after receiving the password management service request data from the management left bracket, the management execution body parses the received password management service request data and sends the tag II and the parsing result to the right bracket;

[0027] Step B3, the right bracket makes a decision on the parsing result with the same label II, blocks the password management service request if the decision fails, and responds to the password management service request corresponding to the parsing result if the decision passes;

[0028] Step B4, the right bracket obtains the response result II, and returns to the management left bracket through each management execution body;

[0029] Step B5, the management left bracket receives the response result II returned by each management execution body, and makes a decision on the response result II; if the decision is passed, the response result II is output, and if the decision is not passed, abnormal decision information is output.

[0030] The beneficial effects of the present invention are:

[0031] 1) The present invention provides a mimetic server cryptographic machine model and a secure communication method. The mimetic server cryptographic machine model includes a business left bracket, a management left bracket, an execution body pool and a right bracket. It is heterogeneous at the management service and business service levels. The management service and the business service are equipped with independent left bracket modules, which effectively solves the vulnerabilities and backdoor problems in the server cryptographic machine operating environment and improves its own security.

[0032] 2) Existing password cards and password chips are implemented through hardware logic based on mature password algorithms, with low security risks. The use of this mimic server password machine model can solve the vulnerability and backdoor problems of the password machine host environment, improve the security of password service data transmission, and integrate mimicry technology with cryptographic technology to further ensure the security of user data;

[0033] 3) The present invention can be applied to the construction of public key infrastructure systems and application systems based on public key infrastructure, and is particularly suitable for large host systems such as digital certificate authentication centers and authorization management centers to improve the security of cryptographic service data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 It is a structural schematic diagram of the pseudo server cryptographic machine model of the present invention;

[0035] Figure 2 is the timing of the service request data transmission phase of the present invention Figure 1 ;

[0036] Figure 3 is the timing of the service request data transmission phase of the present invention Figure 2 ;

[0037] Figure 4 The timing of the password management service request data transmission phase of the present invention is Figure 1 ;

[0038] Figure 5 The timing of the password management service request data transmission phase of the present invention is Figure 2 . DETAILED DESCRIPTION

[0039] The technical solution of the present invention is further described in detail below through specific implementation methods.

[0040] Example 1

[0041] As attached Figure 1 As shown, a pseudo server cipher machine model includes a business left bracket, a management left bracket, an execution body pool and a right bracket; wherein,

[0042] The business left bracket is used to receive business request data, add label I to the received business request data and distribute it to each business executor in the executor pool; it is also used to receive response result I returned by each business executor and make a decision on the response result I; wherein the business request data is cryptographic service request data, specifically including data to be encrypted, data to be decrypted, data to be authenticated and key index number, etc., the label I adopts a random number with a length of X (such as X=20) bytes, and the response result I is the response data corresponding to the business request data, specifically including ciphertext data (response data corresponding to the data to be encrypted), plaintext data (response data corresponding to the data to be decrypted), etc.;

[0043] The management left bracket is used to receive password management service request data, add label II to the received password management service request data and distribute it to each management executor in the executor pool; it is also used to receive response result II returned by each management executor and make a decision on the response result II; wherein the password management service request data includes key management type request and system configuration type request, etc., so as to manage the key, manage and configure the administrator, operator and auditor of the cipher machine, or manage and configure the network card, time and log of the cipher machine, the label II adopts a random number with a length of Y (such as Y=20) bytes, and the response result II includes a configuration success message or a configuration failure message;

[0044] The executor pool is configured with N business executors and M management executors;

[0045] N service execution bodies are respectively connected to the service left bracket for communication, and are used to receive service request data from the service left bracket, perform rule check on the received service request data, generate corresponding check results, and encapsulate the check results and label I, and send them together with the service request data to the right bracket; and are also used to receive the response result I returned by the right bracket, and forward it to the service left bracket;

[0046] M management execution bodies are respectively connected to the management left bracket for communication, and are used to receive the password management service request data from the management left bracket, parse the received password management service request data, and send the label II and the parsing result to the right bracket; and are also used to receive the response result II returned by the right bracket, and forward it to the management left bracket;

[0047] The right bracket is respectively connected to the business executor and the management executor for communication, and is used to make a decision on the business request data and the corresponding inspection results with the same label I. If the decision is not passed, the business request is blocked. If the decision is passed, the business request data that passes the decision is sent to the password card mounted on the right bracket; it is also used to receive the response result I generated by the password card and transmit it to N business executors respectively; it is also used to make a decision on the parsing result with the same label II. If the decision is not passed, the password management service request is blocked. If the decision is passed, the password management service request corresponding to the parsing result is responded to.

[0048] It should be noted that the right bracket blocks the current business request by not sending the business request data to the password card; correspondingly, the right bracket also blocks the current password management service request by not responding to the parsing result.

[0049] The inspection result corresponding to the service request data refers to the rule inspection result, which is generated according to the "GMT 0018-2012 Cryptographic Device Application Interface Specification" and is used to prevent interface data other than the standard from operating the back-end cryptographic card; the tag I and the inspection result are encapsulated in a preset encapsulation format and transmitted together with the service request data (cryptographic service request data); the right bracket selects data packets belonging to the same group according to the tag I, and makes decisions on the inspection results and service request data in the same group of data packets according to the preset policies;

[0050] Specifically, the preset encapsulation format of the inspection result and label I is: length (4 bytes in big endian) + label I (20 bytes) + online business executor information (24 bytes) + interface type (1 byte) + status code (1 byte) + client IP (4 bytes), and the status code in the preset encapsulation format is used to indicate the inspection result; for example, if the online business executor determines that the data type corresponding to the received business request data matches the preset business data type, and the data format corresponding to the business request data matches the preset business data format, a preset status code (such as 11111111) is generated to indicate the inspection result.

[0051] Furthermore, the mimic server cryptographic machine model further includes a scheduling module, which is respectively connected to the execution body pool and the right bracket for:

[0052] receiving first abnormality decision information from the right bracket, and performing cleaning and offline processing on abnormal business execution bodies in the execution body pool according to the first abnormality decision information; wherein the first abnormality decision information is a decision result of business request data with the same label I or a decision result of an inspection result;

[0053] Receive the second abnormality decision information from the right bracket, and perform cleaning and offline processing on the abnormal management executor in the executor pool according to the second abnormality decision information; wherein the second abnormality decision information is the decision result of the parsing result with the same label II.

[0054] It can be understood that the business left bracket, the management left bracket, the right bracket and the scheduling module constitute a mimetic component, and the mimetic component and the executor pool hardware platform (the hardware platform refers to the physical device that carries the software) constitute a mimetic server cryptographic machine model. The business left bracket and the business executor correspond to the implementation of business services, and the management left bracket and the management executor correspond to the implementation of management services. In this embodiment, management services and business services are equipped with independent left brackets respectively. Through the independent setting of the left bracket and the shared setting of the right bracket, combined with the heterogeneous executors that configure the business services and management services at the same time, heterogeneity is performed at the two levels of management services and business services, thereby ensuring the security and reliability of the management configuration process and the business execution process.

[0055] The execution body pool is configured with N business execution bodies and M management execution bodies, providing management services and business services to the outside. Management services refer to the management of keys, etc., the management and configuration of cipher machine administrators, operators, auditors, etc., and the management and configuration of cipher machine network cards, time, logs, etc. The cryptographic business services refer to encryption and decryption services, signature verification services, etc.;

[0056] It should be noted that the business executor and the management executor in the executor pool are independent of each other, N and M are integers greater than or equal to 4, and considering cost and efficiency, the number of online executors is 3, and the other executor is used for standby rotation.

[0057] Further, the scheduling module is also respectively connected to the service left bracket and the management left bracket for: sending first configuration information to the service left bracket, the first configuration information including online service execution body information for agreeing on the service execution body information for receiving service request data;

[0058] Sending second configuration information to the management left bracket, wherein the second configuration information includes online management executive information for agreeing on the management executive information for receiving password management service request data.

[0059] It should be noted that when the client generates service request data, the service request data is transmitted to the service left bracket via the TCP (Transmission Control Protocol) communication channel; when the client generates password management service request data, the password management service request data is transmitted to the management left bracket via the Https communication channel;

[0060] As shown in Figure 1, the service left bracket is also used to establish a TCP communication channel with the client to receive service request data from the client; it should be noted that the password management service provides web services (WebService) to the outside, so the management left bracket is also used to establish an Https (full name: Hyper Text Transfer Protocol over Secure Socket Layer) communication channel with the client to receive password management service request data from the client;

[0061] A TCP communication channel is established between the service left bracket and the service execution body, and an Http communication channel is established between the management left bracket and the management execution body.

[0062] It can be understood that the TCP communication channel established between the service left bracket and the client, and the TCP communication channel established between the service left bracket and the service execution body, are dedicated service data transmission channels;

[0063] The Https communication channel established between the management left bracket and the client, and the Http communication channel established between the management left bracket and the management execution body, are dedicated management service data transmission channels;

[0064] The dedicated business data transmission channel and the dedicated management service data transmission channel are independent of each other, so that the business service and management service are independent of each other and can run in parallel. It should be noted that the mimetic server cryptographic machine model needs to be initialized before using the mimetic server cryptographic machine model. After the initialization is completed, the mimetic server cryptographic machine model can also be managed and configured during normal business request processes.

[0065] It should be noted that the service left bracket proxies (copies and distributes) the service request data, adds a label to the service request data and distributes it to the service execution body, the service execution body performs a rule check on the service request data, adds the check result to the front of the service request data, and forwards it to the right bracket, the right bracket makes a decision on the service request data and the check result respectively, and blocks the service request in time when the decision is not passed, thereby preventing the password card from being illegally called;

[0066] The business execution body also forwards the response result I (such as encrypted / decrypted data) returned by the right bracket to the business left bracket. The business left bracket adjudicates the response result returned by the business execution body and returns the response result I after the adjudication to the client, thereby avoiding the response result I from being illegally tampered with and improving the security of the application system encryption request data.

[0067] The management left bracket provides password management services to the outside, proxies (copies and distributes) password management service request data, adds tags to the password management service request data and distributes it to the management execution body. The management execution body provides key management and device management services to the outside, parses the parsing results (key management request and device management request data), and sends the parsing results to the right bracket. The right bracket makes a decision on the parsing results, and blocks the password management service request in time when the decision fails, thereby preventing the pseudo server cryptographic machine model from being illegally configured;

[0068] The management execution body also transmits the response result II returned by the right bracket to the management left bracket, and the management left bracket judges the response result II returned by each management execution body, thereby preventing the response result II from being illegally tampered with and improving the security of the management system password management request data.

[0069] Example 2

[0070] Based on Example 1, this example provides another specific implementation of the pseudo server cryptographic machine model;

[0071] Specifically, the right bracket also mounts a USBKey, and the USBKey is used to perform identity authentication and authority authentication on the user who sends the password management service request data;

[0072] The right bracket also mounts a file system, which is used to store configuration information.

[0073] As attached Figure 1 As shown, the right bracket is mounted with a password card, USBKey and file system. The password management service request data (key management data) and business request data need to be implemented by operating the password card. Therefore, the password card should be mounted on the right bracket at the end of the mimicry protection to ensure the operation security of the password card. The USBKey is used to authenticate and manage the user who sends the password management service request data to ensure the security and reliability of the password management service.

[0074] Among them, the USBkey is used for identity authentication of administrators / operators / auditors. Only by inserting the corresponding USBkey can the corresponding permissions be obtained. Key-related operations require USBkey access to be used (similar to bank U-shield); the file system is used to store configuration information, which includes information such as the cipher machine network card, time, log, etc.

[0075] It should be noted that when the management execution body receives the password management service request data, it will first determine whether the operation corresponding to the password management service request data requires authentication; if it does, it will initiate an authentication request to the right bracket, and if it has been authenticated, it will return the web request data; if it has not been authenticated, it will prompt the user that it has not been authenticated;

[0076] Specifically, the management execution body determines whether the parsing result matches the preset password management service type, and if so, sends an authentication request to the right bracket; wherein the parsing result includes key management service, device management service and device configuration service, and the preset password management service type includes key management service, device management service and device configuration service;

[0077] After receiving the authentication request, the right bracket calls the USBKey mounted on the right bracket to perform identity authentication and authority authentication on the user who sent the password management service request data;

[0078] When the identity authentication and authority authentication are not passed, the right bracket sends an unauthenticated prompt message to the management left bracket through the management execution body; when the identity authentication and authority authentication are passed, the right bracket receives the label II and the parsing result from the right bracket.

[0079] Specifically, the business left bracket provides a business service SDK to the outside world, and the business service SDK is an API for facilitating the client to call the interface of the pseudo-server cryptographic machine model.

[0080] Example 3

[0081] Based on the above embodiments, this embodiment provides a secure communication method. Figures 2 to 5 As shown;

[0082] The secure communication method includes a business request data transmission phase and a password management service request data transmission phase, wherein:

[0083] During the business request data transmission phase, the following steps are performed:

[0084] Step A1, the business left bracket receives the business request data, adds label I to the received business request data, and distributes it to each business executor in the executor pool;

[0085] Step A2, after receiving the service request data from the service left bracket, the service execution body performs a rule check on the received service request data, generates a corresponding check result, and encapsulates the check result and label I, and sends them together with the service request data to the right bracket;

[0086] Step A3, the right bracket makes decisions on the service request data with the same tag I and the corresponding inspection results respectively. If the decision is not passed, the service request is blocked. If the decision is passed, the passed service request data is sent to the password card mounted on the right bracket;

[0087] Step A4, the password card generates a response result I based on the service request data, and transmits it to N service execution bodies respectively through the right bracket;

[0088] Step A5, the business execution body receives the response result I returned by the right bracket, and forwards it to the business left bracket;

[0089] Step A6, the business left bracket receives the response result I returned by each business execution body, makes a decision on the response result I, and outputs the response result I after the decision is passed;

[0090] During the password management service request data transmission phase, the following steps are performed:

[0091] Step B1, the management left bracket receives the password management service request data, adds the label II to the received password management service request data and distributes it to each management executive in the executive pool;

[0092] Step B2, after receiving the password management service request data from the management left bracket, the management execution body parses the received password management service request data and sends the tag II and the parsing result to the right bracket; the parsing result includes key management service, device management service and device configuration service, etc.;

[0093] Step B3, the right bracket makes a decision on the parsing result with the same label II, blocks the password management service request if the decision fails, and responds to the password management service request corresponding to the parsing result if the decision passes;

[0094] Step B4, the right bracket obtains the response result II, and returns to the management left bracket through each management execution body;

[0095] Step B5, the management left bracket receives the response result II returned by each management execution body, and makes a decision on the response result II; if the decision is passed, the response result II is output, and if the decision is not passed, the abnormal decision information is output (to the scheduling module).

[0096] Among them, the right parenthesis receives the request data of the management execution entity and the service execution entity, adjudicates the data with the same label, and forwards the abnormal adjudication result to the scheduling module; after filtering out the secure request data, it requests password services from the password card and returns the response result to the service execution entity or the management execution entity;

[0097] It can be understood that when the right parenthesis in step A3 adjudicates the service request data with the same label I and the corresponding inspection results, when the service left parenthesis in step A6 adjudicates the response results I returned by each service execution entity, when the right parenthesis in step B3 adjudicates the parsing results with the same label II, and when the management left parenthesis in step B5 adjudicates the response results II returned by each management execution entity, the adjudication strategy adopted is the majority adjudication strategy or the consistency adjudication strategy.

[0098] Furthermore, during the adjudication process, the right parenthesis, the service left parenthesis, or the management left parenthesis respectively sets the data reception time. If the data reception time is exceeded (such as 2 minutes), the corresponding execution entity is determined to be an abnormal execution entity.

[0099] It should be noted that there is no sequence between the service request data transmission stage and the password management service request data transmission stage, and they are two sets of parallel services (except for initialization).

[0100] It can be understood that the response result I in step A4 is transmitted to the service left parenthesis through the right parenthesis and the service execution entity. During this process, the service execution entity directly forwards the response result I to the service left parenthesis; the service left parenthesis adjudicates the received response result I to prevent the response result I output by the encryption card from being tampered with by hackers using operating system or code vulnerabilities.

[0101] In step B3, the right parenthesis adjudicates the parsing results with the same label II. If the adjudication passes, the password management service request data is sent to the rear database or the password card. If the adjudication fails, the current password management service request is blocked, and the problem (abnormal) execution entity is rotated and cleaned.

[0102] Furthermore, in step A2, when the service execution entity performs rule checks on the received service request data and generates corresponding inspection results, it executes:

[0103] Parse the received service request data to obtain the data type and data format of the service request data, and perform rule checks on the data type and data format of the service request data respectively;

[0104] Determine whether the data type of the business request data matches the preset business data type. If so, determine whether the data format of the business request data matches the preset business data format. If so, determine that the rule check of the business request data has passed; otherwise, determine that the rule check of the business request data has failed.

[0105] Among them, the preset business data type refers to the data type defined in the interface function in the "GMT 0018-2012 Cryptographic Equipment Application Interface Specification", and the preset business data format refers to the data format defined in the interface function in the "GMT 0018-2012 Cryptographic Equipment Application Interface Specification".

[0106] Furthermore, the step B2 further comprises the following steps:

[0107] The management execution body determines whether the parsing result matches the preset password management service type, and if so, sends an authentication request to the right bracket. After receiving the authentication request, the right bracket calls the USBKey mounted on the right bracket to perform identity authentication and authority authentication on the user who sent the password management service request data;

[0108] The parsing result includes key management service, device management service and device configuration service, and the preset password management service type includes key management service, device management service and device configuration service;

[0109] When it is confirmed that the user who sent the password management service request data has not passed the identity authentication and authority authentication, the right bracket sends an unauthenticated prompt message to the management left bracket via the management execution body;

[0110] When it is confirmed that the user who sent the password management service request data has passed the identity authentication and authority authentication, the right bracket receives the label II and the parsing result from the right bracket.

[0111] Furthermore, in step A3, after the right bracket respectively determines the service request data and the corresponding inspection results with the same label I, the following steps are further performed: transmitting the abnormal determination information to the scheduling module, and the scheduling module performs cleaning and offline processing on the service execution bodies in the execution body pool according to the abnormal determination information;

[0112] Step B3, after the right bracket makes a decision on the parsing results with the same label II, the following steps are further performed: the abnormal decision information is transmitted to the scheduling module, and the scheduling module performs a cleaning and offline processing on the management execution body in the execution body pool according to the abnormal decision information.

[0113] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or some technical features can be replaced by equivalents without departing from the spirit of the technical solution of the present invention, which should be included in the scope of the technical solution for protection of the present invention.

Claims

1. A pseudo-server cipher machine model, It is characterized in that include: The business left bracket is used to receive business request data, add label I to the received business request data, and distribute it to each business executor in the executor pool; It is also used to receive the response result I returned by each business execution body and make a decision on the response result I; The management left bracket is used to receive the password management service request data, add the label Ⅱ to the received password management service request data and distribute it to each management executor in the executor pool; it is also used to receive the response result Ⅱ returned by each management executor and make a decision on the response result Ⅱ; The executor pool is configured with N business executors and M management executors; N service execution bodies are respectively connected to the service left bracket for communication, and are used to receive service request data from the service left bracket, perform rule check on the received service request data, generate corresponding check results, and encapsulate the check results and label I, and send them together with the service request data to the right bracket; and are also used to receive the response result I returned by the right bracket, and forward it to the service left bracket; M management execution bodies are respectively connected to the management left bracket for communication, and are used to receive the password management service request data from the management left bracket, parse the received password management service request data, and send the label II and the parsing result to the right bracket; and are also used to receive the response result II returned by the right bracket, and forward it to the management left bracket; and a right bracket, which are respectively connected to the business executor and the management executor for communication, and are used to make a decision on the business request data and the corresponding inspection results with the same label I. If the decision is not passed, the business request is blocked. If the decision is passed, the business request data passed is sent to the password card mounted on the right bracket; it is also used to receive the response result I generated by the password card and transmit it to N business executors respectively; it is also used to make a decision on the parsing result with the same label II. If the decision is not passed, the password management service request is blocked. If the decision is passed, the password management service request corresponding to the parsing result is responded to.

2. The pseudo server cryptographic machine model according to claim 1, It is characterized in that The system further includes a scheduling module, which is respectively connected to the execution body pool and the right bracket for: receiving first abnormality decision information from the right bracket, and performing cleaning and offline processing on abnormal business execution bodies in the execution body pool according to the first abnormality decision information; The second abnormality decision information from the right bracket is received, and the abnormal management execution body in the execution body pool is cleaned and offline processed according to the second abnormality decision information.

3. The pseudo server cryptographic machine model according to claim 1, It is characterized in that The service left bracket is also used to establish a TCP communication channel with the client to receive service request data from the client; The management left bracket is also used to establish an Https communication channel with the client to receive password management service request data from the client.

4. The pseudo server cryptographic machine model according to claim 1, It is characterized in that A TCP communication channel is established between the service left bracket and the service execution body, and an Http communication channel is established between the management left bracket and the management execution body.

5. The pseudo server cryptographic machine model according to claim 1, It is characterized in that The right bracket also mounts a USBKey, and the USBKey is used to perform identity authentication and authority authentication on the user who sends the password management service request data.

6. The pseudo server cryptographic machine model according to claim 1, It is characterized in that The right bracket also mounts a file system, which is used to store configuration information.

7. A secure communication method, It is characterized in that It includes the business request data transmission phase and the password management service request data transmission phase, in which: During the business request data transmission phase, the following steps are performed: Step A1, the business left bracket receives the business request data, adds label I to the received business request data, and distributes it to each business executor in the executor pool; Step A2, after receiving the service request data from the service left bracket, the service execution body performs a rule check on the received service request data, generates a corresponding check result, and encapsulates the check result and label I, and sends them together with the service request data to the right bracket; Step A3, the right bracket makes decisions on the service request data with the same tag I and the corresponding inspection results respectively. If the decision is not passed, the service request is blocked. If the decision is passed, the passed service request data is sent to the password card mounted on the right bracket; Step A4, the password card generates a response result I based on the service request data, and transmits it to N service execution bodies respectively through the right bracket; Step A5, the business execution body receives the response result I returned by the right bracket, and forwards it to the business left bracket; Step A6, the business left bracket receives the response result I returned by each business execution body, makes a decision on the response result I, and outputs the response result I after the decision is passed; During the password management service request data transmission phase, the following steps are performed: Step B1, the management left bracket receives the password management service request data, adds the label II to the received password management service request data and distributes it to each management executive in the executive pool; Step B2, after receiving the password management service request data from the management left bracket, the management execution body parses the received password management service request data and sends the tag II and the parsing result to the right bracket; Step B3, the right bracket makes a decision on the parsing result with the same label II, blocks the password management service request if the decision fails, and responds to the password management service request corresponding to the parsing result if the decision passes; Step B4, the right bracket obtains the response result II, and returns to the management left bracket through each management execution body; Step B5, the management left bracket receives the response result II returned by each management execution body, and makes a decision on the response result II; if the decision is passed, the response result II is output, and if the decision is not passed, abnormal decision information is output.

8. The secure communication method according to claim 7, Features: The step B2 further comprises the following steps: The management execution body determines whether the parsing result matches the preset password management service type, and if so, sends an authentication request to the right bracket. After receiving the authentication request, the right bracket calls the USBKey mounted on the right bracket to perform identity authentication and authority authentication on the user who sent the password management service request data; wherein the parsing result includes key management service, device management service and device configuration service, and the preset password management service type includes key management service, device management service and device configuration service; When it is confirmed that the user who sent the password management service request data has not passed the identity authentication and authority authentication, the right bracket sends an unauthenticated prompt message to the management left bracket via the management execution body; When it is confirmed that the user who sent the password management service request data has passed the identity authentication and authority authentication, the right bracket receives the label II and the parsing result from the right bracket.

9. The secure communication method according to claim 8, It is characterized in that In step A2, the service execution body performs a rule check on the received service request data, and when a corresponding check result is generated, executes: Parsing the received service request data, obtaining the data type and data format of the service request data, and performing rule checks on the data type and data format of the service request data respectively; Determine whether the data type of the business request data matches the preset business data type. If so, determine whether the data format of the business request data matches the preset business data format. If so, determine that the rule check of the business request data has passed; otherwise, determine that the rule check of the business request data has failed.

10. The secure communication method according to claim 7, It is characterized in that In step A3, after the right bracket respectively determines the service request data with the same label I and the corresponding inspection results, the following steps are further performed: The abnormality decision information is transmitted to the scheduling module, and the scheduling module performs cleaning and offline processing on the business execution bodies in the execution body pool according to the abnormality decision information.

Citation Information

Patent Citations

  • Mimicry bracket device with master-slave switching function, mimicry defense method and architecture

    CN111885014A

  • Input distribution method, input agent and mimicry distributed storage system

    CN112511317A