A password application method, device, equipment and storage medium

CN115766064BActive Publication Date: 2026-09-18CETC CYBERSPACE SECURITY TECH CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211173019.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-26
Publication Date
2026-09-18
Estimated Expiration
2042-09-26

AI Technical Summary

Technical Problem

[0003]然而,随着互联网的不断演进、攻击技术的不断进化,针对密码机、密码服务的攻击已呈现“隐蔽性、协同性、精确性”等特点,网络安全处于“易攻难守”的态势

Benefits of technology

[0036] As can be seen, this application first obtains the target key data to be cryptographically processed, then randomly selects multiple cryptographically redundant execution entities from a pre-created pool of heterogeneous redundant execution entities to obtain a set of cryptographically redundant execution entities. Next, the target key data is distributed to multiple cryptographically redundant execution entities in the set to perform cryptographic operations on the target key data, obtaining multiple cryptographic operation results. Then, an adjudication mechanism adjudicates the multiple cryptographic operation results to obtain an adjudication result, and the cryptographic operation result that is deemed successful is output. This application incorporates the concept of mimicry defense in the cryptographic operation process. By randomly selecting multiple heterogeneous execution entities for cryptographic operations and obtaining a unique and correct cryptographic operation result through an adjudication mechanism, it can improve the security of key data, protect the confidentiality of key data, prevent data tampering, proactively respond to various unknown threats in cyberspace, and has high robustness. Even if a cryptographic machine is attacked, because it has multiple cryptographically redundant execution entities, it can still calculate the correct cryptographic operation result, effectively solving the problem that the cryptographic application results are untrustworthy and undetectable after a cryptographic machine is attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115766064B_ABST
    Figure CN115766064B_ABST
Patent Text Reader

Abstract

The application discloses a password application method and device, equipment and storage medium, and relates to the technical field of information security, and comprises the following steps: obtaining target key data to be subjected to password operation; randomly selecting a plurality of password heterogeneous redundant execution bodies from a pre-created password heterogeneous redundant execution body pool to obtain a password heterogeneous redundant execution body set; distributing the target key data to the plurality of password heterogeneous redundant execution bodies in the password heterogeneous redundant execution body set respectively, so as to perform password operation on the target key data and obtain a plurality of password operation results; and ruling on the plurality of password operation results through a ruling mechanism, and outputting the password operation result with a successful ruling result. The application integrates the idea of quasiparticle defense in the process of password operation, randomly selects a plurality of heterogeneous execution bodies for password operation, and obtains a unique correct password operation result through a ruling mechanism, so that the security of the key data can be improved, and unknown threats in the network space can be actively coped with.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a cryptographic application method, apparatus, device and storage medium. Background Technology

[0002] In recent years, with the increasingly severe cybersecurity situation, threats to various business systems in finance, energy, transportation, and government have been increasing. my country is gradually promoting commercial cryptography technology and its applications. Business systems primarily access cryptographic resources through external cryptographic resources, such as cryptographic machines, to achieve cryptographic applications.

[0003] However, with the continuous evolution of the internet and the advancement of attack techniques, attacks targeting cryptographic machines and services have become increasingly sophisticated, characterized by "concealment, coordination, and precision," leaving network security in a "easy to attack, difficult to defend" situation. Passive, standalone protection against cryptographic machines is no longer sufficient. Since attacks on cryptographic machines can directly prevent business systems from using cryptographic technologies, business systems cannot confidently rely on external cryptographic machines to apply cryptographic technologies.

[0004] In summary, ensuring the security of business systems when applying cryptographic technologies, and addressing the issue of untrustworthy and undetectable cryptographic application results after a cryptographic machine is attacked, remain issues that require further investigation. Summary of the Invention

[0005] In view of this, the purpose of this application is to provide a cryptographic application method, apparatus, device, and storage medium that can improve the security of critical data and proactively respond to various unknown threats in cyberspace. The specific solution is as follows:

[0006] Firstly, this application discloses a cryptographic application method, including:

[0007] Obtain the target key data to be used for cryptographic operations;

[0008] Multiple cryptographic heterogeneous redundant execution entities are randomly selected from a pre-created pool of cryptographic heterogeneous redundant execution entities to obtain a set of cryptographic heterogeneous redundant execution entities;

[0009] The target key data is distributed to multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set to perform cryptographic operations on the target key data and obtain multiple cryptographic operation results;

[0010] The multiple cryptographic operation results are adjudicated by an adjudication mechanism to obtain an adjudication result, and the adjudication result is output as the successful cryptographic operation result.

[0011] Optionally, the step of resolving multiple cryptographic operation results through a resolving mechanism to obtain a resolving result, and outputting the cryptographic operation result that is successful, includes:

[0012] The number of identical results among multiple cryptographic operation results is counted to obtain statistical results, and the maximum value among the statistical results is obtained;

[0013] Determine whether the maximum value is greater than a preset threshold. If so, output the cryptographic operation result corresponding to the maximum value. Otherwise, determine that there is an abnormal or erroneous cryptographic heterogeneous redundant execution entity in the cryptographic heterogeneous redundant execution entity pool.

[0014] Optionally, the cryptographic application method further includes:

[0015] If the decision result is abnormal or incorrect, then the abnormal or incorrect cryptographic heterogeneous redundant execution body is identified.

[0016] Based on the tolerance parameter, determine whether to continue to retain the abnormal or erroneous cryptographic heterogeneous redundant execution entity in the cryptographic heterogeneous redundant execution entity pool. Otherwise, mark the abnormal or erroneous cryptographic heterogeneous redundant execution entity as unavailable and update the status of the cryptographic heterogeneous redundant execution entity pool.

[0017] Optionally, obtaining the target key data to be used for cryptographic operations includes:

[0018] Obtain the target key data to be used for cryptographic operations, and randomly generate a preset number of bytes.

[0019] Optionally, the step of distributing the target key data to multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set to perform cryptographic operations on the target key data and obtain multiple cryptographic operation results includes:

[0020] The target key data and the random number are distributed to multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, so that the random number is used as a key dispersion factor to disperse the master key in the cryptographic heterogeneous redundant execution entity, thereby obtaining the encryption key and the target vector.

[0021] The target key data is padded to an integer multiple of the preset bytes by multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set to obtain padded data. The padded data is then encrypted using the encryption key, the target vector, and the preset encryption algorithm to obtain multiple encryption results.

[0022] The encrypted data is decrypted by multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, resulting in multiple decryption results;

[0023] Multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set perform hash operations on the encryption result and the decryption result respectively to obtain multiple hash values.

[0024] Optionally, the step of resolving multiple cryptographic operation results through a resolving mechanism to obtain a resolving result, and outputting the cryptographic operation result that is successful, includes:

[0025] If the hash values ​​calculated by each of the cryptographically heterogeneous redundant execution entities are all the same, then the encryption result is output;

[0026] If the hash values ​​calculated by the various cryptographic heterogeneous redundant execution entities are not completely the same, then the number of identical values ​​in the hash values ​​is counted to obtain the count, and it is determined whether the maximum value of the count is greater than a preset number.

[0027] If the maximum value of the statistical count is greater than the preset value, then the encryption result corresponding to the maximum value of the statistical count is output.

[0028] Optionally, the heterogeneous redundant cryptographic execution unit includes a server cryptographic machine, an encryption card, and a software cryptographic module, all of which have the functions of key storage, key distribution, encryption / decryption operations, and hash operations.

[0029] Secondly, this application discloses a cryptographic application apparatus, comprising:

[0030] The key data acquisition module is used to acquire the target key data to be used for cryptographic operations;

[0031] The random selection module is used to randomly select multiple cryptographic heterogeneous redundant execution entities from a pre-created pool of cryptographic heterogeneous redundant execution entities to obtain a set of cryptographic heterogeneous redundant execution entities;

[0032] The cryptographic operation module is used to distribute the target key data to multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, so as to perform cryptographic operations on the target key data and obtain multiple cryptographic operation results;

[0033] The adjudication and output module is used to adjudicate multiple cryptographic operation results through an adjudication mechanism to obtain an adjudication result, and output the adjudication result as the successful cryptographic operation result.

[0034] Thirdly, this application discloses an electronic device, including a processor and a memory; wherein, when the processor executes a computer program stored in the memory, it implements the aforementioned cryptographic application method.

[0035] Fourthly, this application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned cryptographic application method.

[0036] As can be seen, this application first obtains the target key data to be cryptographically processed, then randomly selects multiple cryptographically redundant execution entities from a pre-created pool of heterogeneous redundant execution entities to obtain a set of cryptographically redundant execution entities. Next, the target key data is distributed to multiple cryptographically redundant execution entities in the set to perform cryptographic operations on the target key data, obtaining multiple cryptographic operation results. Then, an adjudication mechanism adjudicates the multiple cryptographic operation results to obtain an adjudication result, and the cryptographic operation result that is deemed successful is output. This application incorporates the concept of mimicry defense in the cryptographic operation process. By randomly selecting multiple heterogeneous execution entities for cryptographic operations and obtaining a unique and correct cryptographic operation result through an adjudication mechanism, it can improve the security of key data, protect the confidentiality of key data, prevent data tampering, proactively respond to various unknown threats in cyberspace, and has high robustness. Even if a cryptographic machine is attacked, because it has multiple cryptographically redundant execution entities, it can still calculate the correct cryptographic operation result, effectively solving the problem that the cryptographic application results are untrustworthy and undetectable after a cryptographic machine is attacked. Attached Figure Description

[0037] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0038] Figure 1 This is a flowchart of a cryptographic application method disclosed in this application;

[0039] Figure 2 This application discloses a block diagram of a specific cryptographic application mimicry defense system.

[0040] Figure 3 This is a flowchart of a specific cryptographic application method disclosed in this application;

[0041] Figure 4 This is a schematic diagram of a specific cryptographic application mimicry defense framework disclosed in this application;

[0042] Figure 5 This is a schematic diagram of the structure of a cryptographic application device disclosed in this application;

[0043] Figure 6 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation

[0044] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0045] This application discloses a cryptographic application method. See also Figure 1 As shown, the method includes:

[0046] Step S11: Obtain the target key data to be used for cryptographic operations.

[0047] In this embodiment, the plaintext data to be cryptographically processed is first acquired to obtain target key data, which includes, but is not limited to, commercial cryptography.

[0048] Step S12: Randomly select multiple cryptographic heterogeneous redundant execution entities from the pre-created cryptographic heterogeneous redundant execution entity pool to obtain a set of cryptographic heterogeneous redundant execution entities.

[0049] In this embodiment, after obtaining the target key data to be cryptographically processed, multiple cryptographic heterogeneous redundant execution entities can be randomly and dynamically selected from a pre-created pool of cryptographic heterogeneous redundant execution entities, thereby obtaining a set of cryptographic heterogeneous redundant execution entities. These cryptographic heterogeneous redundant execution entities are constructed based on Dynamic Heterogeneous Redundancy (DHR) and include, but are not limited to, server cryptographic machines, encryption cards, and software cryptographic modules. It should be noted that each of these cryptographic heterogeneous redundant execution entities is functionally equivalent but consists of different software, hardware, and operating systems, and all have functions such as key storage, key distribution, encryption / decryption operations, and hash operations. The encryption / decryption operations specifically include, but are not limited to, symmetric encryption / decryption and asymmetric encryption / decryption.

[0050] Step S13: Distribute the target key data to multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set to perform cryptographic operations on the target key data and obtain multiple cryptographic operation results.

[0051] In this embodiment, after randomly selecting multiple cryptographic heterogeneous redundant execution entities from a pre-created pool of such entities to obtain a set of cryptographic heterogeneous redundant execution entities, the target key data is further distributed to the multiple cryptographic heterogeneous redundant execution entities in the set. Then, each of the cryptographic heterogeneous redundant execution entities performs cryptographic operations on the target key data to obtain multiple corresponding cryptographic operation results. These cryptographic operations include, but are not limited to, encryption operations, decryption operations, and hash operations.

[0052] Step S14: The multiple cryptographic operation results are adjudicated through an adjudication mechanism to obtain an adjudication result, and the adjudication result is the successful cryptographic operation result.

[0053] In this embodiment, after performing cryptographic operations on the target key data to obtain multiple cryptographic operation results, a arbitrator can further arbitrate these multiple cryptographic operation results to obtain corresponding arbitration results. Then, the cryptographic operation result deemed successful by the arbitrator is output. For example, when there are three cryptographic heterogeneous redundant execution entities (a server cryptographic machine, an encryption card, and a software cryptographic module), each of these three entities performs cryptographic operations on the target key data to obtain three corresponding cryptographic operation results. Then, it is determined whether the three cryptographic operation results are consistent. If all three are consistent, it indicates that all three cryptographic heterogeneous redundant execution entities are normal, and the cryptographic operation result of any one of them can be directly output. If two of the three are consistent, it indicates that one of the three cryptographic heterogeneous redundant execution entities is abnormal, and either of the two consistent cryptographic operation results can be directly output. If all three are different, it indicates that all three cryptographic heterogeneous redundant execution entities are incorrect or abnormal, and the cryptographic operation fails.

[0054] Furthermore, after obtaining the adjudication result by adjudicating multiple cryptographic operation results through the adjudication mechanism, the method may further include: if the adjudication result is abnormal or erroneous, identifying the abnormal or erroneous cryptographic heterogeneous redundant execution entity; determining whether to retain the abnormal or erroneous cryptographic heterogeneous redundant execution entity in the cryptographic heterogeneous redundant execution entity pool based on a tolerance parameter; otherwise, marking the status of the abnormal or erroneous cryptographic heterogeneous redundant execution entity as unavailable and updating the status of the cryptographic heterogeneous redundant execution entity pool. In other words, if inconsistent cryptographic operation results exist, the abnormal or erroneous heterogeneous redundant execution units are first identified. For example, if two of the three heterogeneous redundant execution units have the same cryptographic operation result, the other heterogeneous redundant execution unit with a different cryptographic operation result can be identified as an abnormal or erroneous execution unit. After identifying an abnormal or erroneous heterogeneous redundant execution unit, a decision is made based on the pre-configured tolerance parameter to determine whether to retain the heterogeneous redundant execution unit in the heterogeneous execution unit pool. If not retained, the abnormal or erroneous heterogeneous redundant execution unit is further marked as unavailable, and then the status of the heterogeneous redundant execution unit pool is updated, that is, the abnormal or erroneous heterogeneous redundant execution unit is removed from the heterogeneous redundant execution unit pool to ensure that when randomly selecting heterogeneous redundant execution units from the pool next time, all heterogeneous redundant execution units are normal and usable execution units.

[0055] As can be seen, this embodiment first obtains the target key data to be cryptographically processed, then randomly selects multiple cryptographically redundant execution entities from a pre-created pool of heterogeneous redundant execution entities to obtain a set of cryptographically redundant execution entities. Next, the target key data is distributed to multiple cryptographically redundant execution entities in the set to perform cryptographic operations on the target key data, obtaining multiple cryptographic operation results. Then, an adjudication mechanism adjudicates the multiple cryptographic operation results to obtain an adjudication result, and the cryptographic operation result that is deemed successful is output. This embodiment incorporates the concept of mimicry defense in the cryptographic operation process. By randomly selecting multiple heterogeneous execution entities for cryptographic operations and obtaining a unique and correct cryptographic operation result through an adjudication mechanism, it can improve the security of key data, protect the confidentiality of key data, prevent data tampering, proactively respond to various unknown threats in cyberspace, and has high robustness. Even if a cryptographic machine is attacked, because it has multiple cryptographically redundant execution entities, it can still calculate the correct cryptographic operation result, effectively solving the problem that the cryptographic application results are untrustworthy and undetectable after a cryptographic machine is attacked.

[0056] The specific system framework used in the cryptographic application method of this application can be found in [reference needed]. Figure 2As shown, the system framework adopts mimicry defense technology, and logically, from bottom to top, it can include: cryptographic support layer, cryptographic service layer, mimicry service layer, cryptographic interface layer, cryptographic application layer, and cryptographic management layer.

[0057] The cryptographic support layer includes domestically produced cryptographic machines, non-domestic cryptographic machines, software cryptographic modules, and encryption cards, which together form a cryptographic heterogeneous redundant execution entity pool, providing cryptographic support capabilities for upper-layer applications. The cryptographic service layer functions are also provided by the cryptographic heterogeneous redundant execution entity modules. Each cryptographic heterogeneous redundant execution entity has the functions of key storage, key distribution, encryption and decryption operations, and hash operations, providing confidentiality and integrity protection for critical data of the cryptographic application system. Figure 2 The cryptographic application middleware provides a mimicry defense service layer and a cryptographic interface layer, centered on cryptographic operation scheduling, cryptographic operation adjudication, and negative feedback control of heterogeneous redundant cryptographic executors. This provides a simple yet unified cryptographic service interface for the implementation of the upper cryptographic support layer and business systems, effectively reducing the difficulty of key application modification. Furthermore, business systems at the cryptographic application layer use the cryptographic interface to achieve protocol-secure communication, secure data storage, and access control protection. The keys for the cryptographic support layer originate from the cryptographic management layer, and the key management system is responsible for key generation, distribution, and updates. It should be noted that because the cryptographic middleware simplifies business systems, unifies the cryptographic service interfaces of various heterogeneous redundant cryptographic executors, and hides the mimicry defense process, it achieves seamless cryptographic application for business systems.

[0058] Figure 3 This is a flowchart illustrating a specific cryptographic application method disclosed in an embodiment of this application. See also... Figure 3 As shown, the cryptographic application method includes:

[0059] Step S21: Obtain the target key data to be used for cryptographic operations, and randomly generate a preset number of bytes.

[0060] In this embodiment, the plaintext data to be cryptographically processed is first obtained to acquire the target key data, and then a random number of preset bytes is randomly generated. For example, when... Figure 2 When the key operation scheduling module receives the input plaintext data, it generates a set of 16 bytes of random numbers.

[0061] Step S22: Randomly select multiple cryptographic heterogeneous redundant execution entities from the pre-created cryptographic heterogeneous redundant execution entity pool to obtain a cryptographic heterogeneous redundant execution entity set; the cryptographic heterogeneous redundant execution entity includes a server cryptographic machine, an encryption card, and a software cryptographic module, and all of them have the functions of key storage, key distribution, encryption and decryption operations, and hash operations.

[0062] In one specific implementation, after acquiring the target key data to be subjected to cryptographic operations and randomly generating a preset number of bytes, from... Figure 2 Three heterogeneous redundant cryptographic execution entities are randomly selected from domestic cryptographic machines, non-domestic cryptographic machines, software cryptographic modules, and encryption cards. For example, domestic cryptographic machines, software cryptographic modules, and encryption cards are selected, and then the three selected heterogeneous redundant cryptographic execution entities are combined into a set of heterogeneous redundant cryptographic execution entities.

[0063] Step S23: Distribute the target key data and the random number to multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, so as to use the random number as a key dispersion factor to disperse the master key in the cryptographic heterogeneous redundant execution entity, thereby obtaining the encryption key and the target vector.

[0064] In one specific implementation, after randomly selecting multiple cryptographic heterogeneous redundant execution entities from a pre-created pool of cryptographic heterogeneous redundant execution entities to obtain a set of cryptographic heterogeneous redundant execution entities, then... Figure 2 The key operation scheduling module distributes the target key data and the random number to multiple cryptographic heterogeneous redundant execution entities in the aforementioned cryptographic heterogeneous redundant execution entity set. Then, the random number is used as a key dispersion factor to disperse the master key in the aforementioned cryptographic heterogeneous redundant execution entities to obtain the encryption key and the target vector.

[0065] Step S24: The length of the target key data is padded to an integer multiple of the preset bytes by multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set to obtain padded data. The padded data is then encrypted using the encryption key, the target vector, and the preset encryption algorithm to obtain multiple encryption results.

[0066] In this embodiment, the random number is used as a key dispersion factor to disperse the master key in the cryptographic heterogeneous redundant execution body to obtain the encryption key and target vector. Further, multiple cryptographic heterogeneous redundant execution bodies in the aforementioned set padded the length of the target key data to an integer multiple of the preset bytes to obtain padded data. Then, the encryption key, the target vector, and a preset encryption algorithm are used to encrypt the padded data to obtain multiple corresponding encryption results. The encryption algorithm includes, but is not limited to, symmetric encryption algorithms and asymmetric encryption algorithms. For example, after multiple cryptographic heterogeneous redundant execution bodies disperse the master key using the key dispersion factor to obtain the encryption key and vector IV1 for this encryption, the pkcs#7 padded method is used to padded the target key data to an integer multiple of 16 bytes to obtain padded data. Then, the encryption key, the vector IV1, and the SM4 algorithm are used to encrypt the padded data to obtain the corresponding encryption result.

[0067] Step S25: The ciphertext data is decrypted by multiple ciphertext heterogeneous redundant execution entities in the ciphertext heterogeneous redundant execution entity set, resulting in multiple decryption results.

[0068] In one specific implementation, after performing encryption operations on the padded data using the encryption key, the target vector, and a preset encryption algorithm to obtain multiple encryption results, the results are then processed... Figure 2 The cryptographic operation scheduling module randomly assigns the aforementioned key dispersion factor and encryption result to three or more available cryptographic heterogeneous redundancy execution entities for decryption. Specifically, the cryptographic heterogeneous redundancy execution entity first uses the aforementioned key dispersion factor to disperse the aforementioned master key, obtaining the decryption key and vector IV2 for this decryption. Then, it uses the aforementioned decryption key, the aforementioned vector IV2, and the SM4 algorithm to decrypt the aforementioned encryption result, obtaining the corresponding decryption result.

[0069] Step S26: Perform hash operations on the encryption result and the decryption result respectively through multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set to obtain multiple hash values.

[0070] Furthermore, through Figure 2 The cryptographic operation scheduling module randomly assigns the received encryption and decryption results to three or more available cryptographic heterogeneous redundant execution entities. Then, the cryptographic operation adjudication module calculates the hash value of the operation results of each cryptographic heterogeneous redundant execution entity, and performs multi-mode adjudication by comparing the consistency of the hash values.

[0071] Step S27: If the hash values ​​calculated by each of the heterogeneous redundant cryptographic entities are the same, then the encryption result is output.

[0072] Specifically, through Figure 2 If the calculated hash values ​​are all consistent, it indicates that all the heterogeneous redundant cryptographic execution entities are normal, and the cryptographic operation adjudication module outputs the operation result of any one of the heterogeneous redundant cryptographic execution entities.

[0073] Step S28: If the hash values ​​calculated by each of the heterogeneous redundant cryptographic execution entities are not completely the same, then the number of identical values ​​in the hash values ​​is counted to obtain the count, and it is determined whether the maximum value of the count is greater than a preset number.

[0074] In this embodiment, if the hash values ​​calculated by each of the above-mentioned heterogeneous redundant execution entities are partially consistent, it indicates that there is an anomaly in the heterogeneous redundant execution entity. Then, the number of identical values ​​in the above-mentioned hash values ​​is further counted to obtain the corresponding statistical quantity. Then, it is determined whether the maximum value of the above-mentioned statistical quantity is greater than the preset quantity.

[0075] Step S29: If the maximum value of the statistical quantity is greater than the preset quantity, then output the encryption result corresponding to the maximum value of the statistical quantity.

[0076] In this embodiment, if the maximum value of the above statistical quantity is greater than the preset quantity, it indicates that most of the cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set are correct. At this time, the encryption result corresponding to the maximum value of the above statistical quantity can be directly output, that is, the encryption result calculated by the normal cryptographic heterogeneous redundant execution entity is output.

[0077] Furthermore, if the aforementioned hash values ​​are partially identical, it indicates that some heterogeneous and redundant cryptographic execution units are abnormal. In this case, it can be detected through... Figure 2 The cryptographic operation adjudication module submits any abnormal, heterogeneous, redundant ciphers to the negative feedback processor for handling. Furthermore, if all the hash values ​​are different, it indicates that each heterogeneous cipher is abnormal, and the cryptographic operation fails.

[0078] As can be seen, the cryptographic application scheme proposed in this application adopts mimicry defense technology. It randomly and dynamically selects multiple heterogeneous redundant cryptographic executors to perform cryptographic operations and obtains a unique and correct cryptographic operation result through an adjudication mechanism. This ensures that even if a cryptographic machine is attacked, the business system can still calculate the correct cryptographic operation result, thereby solving the problem that the cryptographic application result is untrustworthy and undetectable after the cryptographic machine is attacked. At the same time, it achieves cryptographic application without the business system's awareness.

[0079] In one specific implementation, see Figure 4 As shown, Figure 4 A specific cryptographic application mimicry defense framework is illustrated, which includes: employing various cryptographic heterogeneous redundant execution entities (PCIs) implemented with functionally equivalent but different software, hardware, and operating systems, such as domestically produced server cryptographic machines, non-domestic server cryptographic machines, encryption cards, and software cryptographic modules, to form a pool of cryptographic heterogeneous redundant execution entities; then dynamically and randomly selecting a portion of the cryptographic heterogeneous redundant execution entities from the pool to form a set of cryptographic heterogeneous redundant execution entities; next, an input agent distributes the input plaintext data to each cryptographic heterogeneous redundant execution entity in the set of cryptographic heterogeneous redundant execution entities for execution; finally, a voting device adjudicates the cryptographic operation results calculated by each cryptographic heterogeneous redundant execution entity and outputs the approximately correct encryption result.

[0080] in, Figure 4 Each heterogeneous redundant cryptographic execution entity (RCE) in the system possesses the capabilities of key storage, key distribution, symmetric cryptographic operations, and hash operations. The cryptographic operation scheduling module, deployed on the application system server, has encryption, decryption, and hash operation interfaces. It can generate random numbers as factors for cryptographic operations and is also responsible for randomly selecting a preset number of available RCEs from the pool for cryptographic operations. The cryptographic operation adjudication module is responsible for multi-modal adjudication, voting on the cryptographic operation results of the RCEs and outputting the majority value of the results. It also feeds back RCEs with abnormal or erroneous results to the negative feedback controller module. Based on the adjudication result of the adjudication module, the negative feedback controller module marks the RCEs in the pool as available and synchronizes their status to the cryptographic operation scheduling module. The key management system is responsible for key generation, updating, and destruction, and for distributing the same encryption and decryption keys to all RCEs.

[0081] Accordingly, this application also discloses a cryptographic application device, see [link to relevant documentation]. Figure 5 As shown, the device includes:

[0082] Key data acquisition module 11 is used to acquire target key data to be used for cryptographic operations;

[0083] The random selection module 12 is used to randomly select multiple cryptographic heterogeneous redundant execution entities from a pre-created pool of cryptographic heterogeneous redundant execution entities to obtain a set of cryptographic heterogeneous redundant execution entities.

[0084] The cryptographic operation module 13 is used to distribute the target key data to multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, so as to perform cryptographic operations on the target key data and obtain multiple cryptographic operation results;

[0085] The adjudication and output module 14 is used to adjudicate multiple cryptographic operation results through an adjudication mechanism to obtain an adjudication result, and output the adjudication result as a successful cryptographic operation result.

[0086] The specific workflow of each of the above modules can be found in the relevant content disclosed in the foregoing embodiments, and will not be repeated here.

[0087] As can be seen, in this embodiment, the target key data to be cryptographically processed is first obtained. Then, multiple cryptographically redundant execution entities are randomly selected from a pre-created pool of heterogeneous redundant execution entities to obtain a set of heterogeneous redundant execution entities. Next, the target key data is distributed to multiple heterogeneous redundant execution entities in the set to perform cryptographic operations, resulting in multiple cryptographic operation results. An adjudication mechanism is then used to adjudicate these results, and the cryptographic operation result that is deemed successful is output. This embodiment incorporates the concept of mimicry defense in the cryptographic operation process. By randomly selecting multiple heterogeneous execution entities for cryptographic operations and obtaining a unique and correct result through an adjudication mechanism, the security of key data is improved, confidentiality is protected, data tampering is prevented, and various unknown threats in cyberspace are proactively addressed. Furthermore, it exhibits high robustness; even if a cryptographic machine is attacked, the correct cryptographic operation result can still be calculated due to the presence of multiple heterogeneous redundant execution entities. This effectively solves the problem that cryptographic application results are untrustworthy and undetectable after a cryptographic machine is attacked.

[0088] In some specific embodiments, the adjudication and output module 14 may specifically include:

[0089] The first quantity statistics unit is used to count the number of identical results among multiple cryptographic operation results to obtain statistical results;

[0090] A maximum value acquisition unit is used to acquire the maximum value in the statistical results;

[0091] The first judgment unit is used to determine whether the maximum value is greater than a preset threshold.

[0092] A cryptographic operation result output unit is used to output the cryptographic operation result corresponding to the maximum value if the maximum value is greater than the preset threshold.

[0093] An anomaly determination unit is used to determine that there is an abnormal or erroneous cryptographic heterogeneous redundant execution entity in the cryptographic heterogeneous redundant execution entity pool if the maximum value is not greater than the preset threshold.

[0094] In some specific embodiments, the cryptographic application device may further include:

[0095] An execution body anomaly determination unit is used to determine the abnormal or erroneous cryptographic heterogeneous redundant execution body if the decision result is abnormal or erroneous;

[0096] The second judgment unit is used to determine, based on the tolerance parameter, whether to continue to retain the abnormal or erroneous cryptographic heterogeneous redundant execution body in the cryptographic heterogeneous redundant execution body pool.

[0097] The marking and updating unit is used to mark the state of the abnormal or erroneous cryptographic heterogeneous redundant execution entity as unavailable if otherwise, and to update the state of the cryptographic heterogeneous redundant execution entity pool.

[0098] In some specific embodiments, the key data acquisition module 11 may specifically include:

[0099] The key data acquisition unit is used to acquire the target key data to be used for cryptographic operations.

[0100] The random number generation unit is used to randomly generate a preset number of bytes.

[0101] In some specific embodiments, the cryptographic operation module 13 may specifically include:

[0102] A data distribution unit is used to distribute the target key data and the random number to multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, respectively.

[0103] A dispersion unit is used to disperse the master key in the cryptographic heterogeneous redundant execution body by using the random number as a key dispersion factor to obtain the encryption key and the target vector;

[0104] The padding unit is used to pad the length of the target key data to an integer multiple of the preset bytes by using multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, so as to obtain the padded data;

[0105] The data encryption unit is used to perform encryption operations on the padded data using the encryption key, the target vector, and a preset encryption algorithm to obtain multiple encryption results;

[0106] The data decryption unit is used to perform decryption operations on the ciphertext data through multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, and obtain multiple decryption results;

[0107] The hash operation unit is used to perform hash operations on the encryption result and the decryption result respectively through multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, so as to obtain multiple hash values.

[0108] In some specific embodiments, the adjudication and output module 14 may specifically include:

[0109] The first encryption result output unit is used to output the encryption result if the hash values ​​calculated by each of the cryptographic heterogeneous redundant executors are the same.

[0110] The second quantity counting unit is used to count the number of identical values ​​in the hash values ​​if the hash values ​​calculated by the various cryptographic heterogeneous redundant execution entities are not completely the same, and to obtain the statistical quantity.

[0111] The third judgment unit is used to determine whether the maximum value of the statistical quantity is greater than a preset quantity;

[0112] The second encryption result output unit is used to output the encryption result corresponding to the maximum value of the statistical quantity if the maximum value of the statistical quantity is greater than the preset quantity.

[0113] In some specific embodiments, the cryptographic heterogeneous redundant execution unit includes a server cryptographic machine, an encryption card, and a software cryptographic module, all of which have the functions of key storage, key distribution, encryption / decryption operations, and hash operations.

[0114] Furthermore, embodiments of this application also disclose an electronic device, Figure 6 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0115] Figure 6 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the cryptographic application method disclosed in any of the foregoing embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0116] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0117] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0118] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including computer programs capable of performing the cryptographic application methods executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.

[0119] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned disclosed cryptographic application method. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0120] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0121] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0122] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0123] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0124] The foregoing has provided a detailed description of a cryptographic application method, apparatus, device, and storage medium provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A cryptographic application method, characterized in that, Applied to business systems, including: Obtain the target key data to be used for cryptographic operations; Multiple cryptographic heterogeneous redundant execution entities are randomly selected from a pre-created pool of cryptographic heterogeneous redundant execution entities to obtain a set of cryptographic heterogeneous redundant execution entities; wherein, the cryptographic heterogeneous redundant execution entities in the pool are functionally equivalent cryptographic operation modules composed of different software, hardware or operating systems; the target key data is distributed to multiple cryptographic heterogeneous redundant execution entities in the set of cryptographic heterogeneous redundant execution entities to perform cryptographic operations on the target key data to obtain multiple cryptographic operation results; The multiple cryptographic operation results are adjudicated by an adjudication mechanism to obtain an adjudication result, and the adjudication result is output as the successful cryptographic operation result. The step of obtaining the target key data to be subjected to cryptographic operations includes: obtaining the target key data to be subjected to cryptographic operations, and randomly generating a preset number of random bytes; The step of distributing the target key data to multiple cryptographically redundant execution entities in the cryptographically redundant execution entity set to perform cryptographic operations on the target key data and obtain multiple cryptographic operation results includes: distributing the target key data and the random number to multiple cryptographically redundant execution entities in the cryptographically redundant execution entity set, using the random number as a key dispersion factor to disperse the master key in the cryptographically redundant execution entity to obtain an encryption key and a target vector; filling the length of the target key data to an integer multiple of the preset bytes by multiple cryptographically redundant execution entities in the cryptographically redundant execution entity set to obtain padded data, and performing encryption operations on the padded data using the encryption key, the target vector, and a preset encryption algorithm to obtain multiple encryption results; decrypting the encryption results by multiple cryptographically redundant execution entities in the cryptographically redundant execution entity set to obtain multiple decryption results; and performing hash operations on the encryption results and the decryption results by multiple cryptographically redundant execution entities in the cryptographically redundant execution entity set to obtain multiple hash values. The target key data is padded to an integer multiple of the preset bytes to obtain padded data. The padded data is then encrypted using the encryption key, the target vector, and a preset encryption algorithm to obtain multiple encryption results, including: using pkcs#7 to padded the target key data to an integer multiple of the preset bytes to obtain padded data; and using the encryption key, the target vector, and the SM4 algorithm to encrypt the padded data to obtain the corresponding encryption result. The step of resolving multiple cryptographic operation results through a resolution mechanism and outputting cryptographic operation results that are successful includes: counting the number of identical results among multiple cryptographic operation results, obtaining statistical results, and obtaining the maximum value in the statistical results; determining whether the maximum value is greater than a preset threshold, and if so, outputting the cryptographic operation result corresponding to the maximum value; otherwise, determining that there is an abnormal or erroneous cryptographic heterogeneous redundant execution entity in the cryptographic heterogeneous redundant execution entity pool. The cryptographic application method further includes: if the adjudication result is abnormal or incorrect, then identifying the abnormal or incorrect cryptographic heterogeneous redundant execution entity; determining whether to continue to retain the abnormal or incorrect cryptographic heterogeneous redundant execution entity in the cryptographic heterogeneous redundant execution entity pool based on the tolerance parameter; otherwise, marking the status of the abnormal or incorrect cryptographic heterogeneous redundant execution entity as unavailable, and updating the status of the cryptographic heterogeneous redundant execution entity pool. The step of adjudicating multiple cryptographic operation results through an adjudication mechanism to obtain an adjudication result, and outputting the cryptographic operation result that is successful, includes: if the hash values ​​calculated by each of the heterogeneous redundant cryptographic executors are all the same, then outputting the encryption result; if the hash values ​​calculated by each of the heterogeneous redundant cryptographic executors are not completely the same, then counting the number of identical values ​​in the hash values ​​to obtain a statistical count, and determining whether the maximum value of the statistical count is greater than a preset number; if the maximum value of the statistical count is greater than the preset number, then outputting the encryption result corresponding to the maximum value of the statistical count.

2. The cryptographic application method according to claim 1, characterized in that, The heterogeneous redundant cryptographic execution unit includes a server cryptographic machine, an encryption card, and a software cryptographic module, all of which have the functions of key storage, key distribution, encryption / decryption operations, and hash operations.

3. A cryptographic application device, characterized in that, Applied to business systems, including: The key data acquisition module is used to acquire the target key data to be used for cryptographic operations; The random selection module is used to randomly select multiple cryptographic heterogeneous redundant execution entities from a pre-created cryptographic heterogeneous redundant execution entity pool to obtain a set of cryptographic heterogeneous redundant execution entities; wherein, the cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity pool are cryptographic operation modules that are functionally equivalent but composed of different software, hardware or operating systems; The cryptographic operation module is used to distribute the target key data to multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, so as to perform cryptographic operations on the target key data and obtain multiple cryptographic operation results; The adjudication and output module is used to adjudicate multiple cryptographic operation results through an adjudication mechanism to obtain an adjudication result, and output the adjudication result as a successful cryptographic operation result. The key data acquisition module is specifically used to acquire the target key data to be used for cryptographic operations, and to randomly generate a preset number of bytes. The cryptographic operation module is specifically used to distribute the target key data and the random number to multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set, so as to distribute the master key in the cryptographic heterogeneous redundant execution entity as a key dispersion factor to obtain an encryption key and a target vector; the multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set respectively fill the length of the target key data to an integer multiple of the preset bytes to obtain padded data, and use the encryption key, the target vector and the preset encryption algorithm to perform encryption operation on the padded data to obtain multiple encryption results; the multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set respectively perform decryption operation on the encryption results to obtain multiple decryption results; the multiple cryptographic heterogeneous redundant execution entities in the cryptographic heterogeneous redundant execution entity set respectively perform hash operation on the encryption results and the decryption results to obtain multiple hash values; The cryptographic operation module is further configured to fill the target key data with a length that is an integer multiple of the preset bytes using the pkcs#7 padding method to obtain the padded data; and to encrypt the padded data using the encryption key, the target vector, and the SM4 algorithm to obtain the corresponding encryption result. The adjudication and output module is specifically used to count the number of identical results among multiple cryptographic operation results, obtain statistical results, and obtain the maximum value in the statistical results; determine whether the maximum value is greater than a preset threshold, and if so, output the cryptographic operation result corresponding to the maximum value; otherwise, determine that there is an abnormal or erroneous cryptographic heterogeneous redundant execution body in the cryptographic heterogeneous redundant execution body pool. The cryptographic application device is further configured to, if the adjudication result is abnormal or incorrect, identify the abnormal or incorrect cryptographic heterogeneous redundant execution entity; determine whether to continue to retain the abnormal or incorrect cryptographic heterogeneous redundant execution entity in the cryptographic heterogeneous redundant execution entity pool based on the tolerance parameter; otherwise, mark the status of the abnormal or incorrect cryptographic heterogeneous redundant execution entity as unavailable and update the status of the cryptographic heterogeneous redundant execution entity pool. The adjudication and output module is used to output the encryption result if the hash values ​​calculated by each of the heterogeneous redundant cryptographic executors are the same; if the hash values ​​calculated by each heterogeneous redundant cryptographic executor are not completely the same, the module counts the number of identical hash values ​​to obtain a statistical count, and determines whether the maximum value of the statistical count is greater than a preset number; if the maximum value of the statistical count is greater than the preset number, the module outputs the encryption result corresponding to the maximum value of the statistical count.

4. An electronic device, characterized in that, It includes a processor and a memory; wherein, when the processor executes a computer program stored in the memory, it implements the cryptographic application method as described in any one of claims 1 to 2.

5. A computer-readable storage medium, characterized in that, Used to store computer programs; wherein, when the computer programs are executed by a processor, they implement the cryptographic application method as described in any one of claims 1 to 2.

Citation Information

Patent Citations

  • Data encrypting method and device

    CN104618093A

  • Mimicry defense judgment method and system based on partial homomorphic encryption algorithm

    CN110995409A

  • Computing power sharing method, device and system, electronic equipment and storage medium

    CN114021162A