Data encryption and decryption method, device, equipment, system and storage medium

By using centralized and distributed encryption and decryption services, the working key ciphertext is decrypted using the master key, which solves the problem of the working key being exposed in plaintext, thereby improving data security and maintaining decryption capabilities.

CN116707789BActive Publication Date: 2026-05-19CHINA UNIONPAY
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA UNIONPAY
Filing Date
2023-06-16
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In existing technologies, the working key is exposed in plaintext during encryption and decryption, which poses a risk of leakage and results in insufficient data security.

Method used

It adopts a combination of centralized and distributed encryption and decryption services and key management mechanisms. It calls the encryption machine through key mapping relationship and uses the master key to decrypt the working key ciphertext, avoiding the transmission of the working key plaintext across systems or platforms, and only transmitting the instruction working key ciphertext.

Benefits of technology

It effectively prevents the leakage of plaintext working keys, improves data security, and maintains data decryption capabilities when transferring data between different platforms and devices, thereby enhancing data security and applicability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116707789B_ABST
    Figure CN116707789B_ABST
Patent Text Reader

Abstract

The application discloses a data encryption and decryption method, device, equipment, system and storage medium, and belongs to the field of data processing. The method comprises the following steps: a key mapping relationship is called based on an encryption and decryption execution platform; an encryption and decryption request sent by the encryption and decryption execution platform is received; the key mapping relationship is maintained by a key management platform and comprises a mapping relationship of a master key unique identifier, an encryption machine cluster identifier and a master key physical index; the encryption and decryption request comprises to-be-processed data and target working key indication data; the to-be-processed data comprises to-be-encrypted data or to-be-decrypted data; the target working key indication data is used for indicating target working key ciphertext; the target working key ciphertext is decrypted by using a first target master key to obtain a target working key; the to-be-processed data is encrypted or decrypted by using the target working key to obtain result data; and the result data is fed back to the encryption and decryption execution platform. According to the embodiment of the application, the working key can be prevented from being leaked, and the security of data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of data processing, and in particular relates to a data encryption / decryption method, apparatus, device, system, and storage medium. Background Technology

[0002] With the development of information network technology, more and more businesses need to collect and process user data to complete their tasks. However, some of this data is sensitive to privacy, making data security a key concern.

[0003] To enhance data security, a working key can be used to encrypt data. When data sharing is required, the encrypted data and the key are transmitted. When decryption is needed, the working key is used to decrypt the encrypted data, yielding the plaintext. However, the working keys used for encryption and decryption are exposed in plaintext, posing a risk of leakage. If the working key is leaked, it will also bring significant security risks to the data. Summary of the Invention

[0004] This application provides a data encryption / decryption method, apparatus, device, system, and storage medium that can prevent working key leakage and improve data security.

[0005] In a first aspect, embodiments of this application provide a data encryption / decryption method applied to an encryption machine, which has a first target master key. The method includes: an encryption / decryption execution platform invoking and receiving an encryption / decryption request sent by the encryption / decryption execution platform based on a key mapping relationship. The key mapping relationship is maintained by a key management platform and includes a mapping relationship between a unique master key identifier, an encryption machine cluster identifier, and a master key physical index. The encryption / decryption request includes data to be processed and target working key indication data. The data to be processed includes data to be encrypted or data to be decrypted, and the target working key indication data is used to indicate target working key ciphertext. The target working key ciphertext is decrypted using the first target master key to obtain the target working key. The data to be processed is encrypted or decrypted using the target working key to obtain result data. The result data is then fed back to the encryption / decryption execution platform.

[0006] Secondly, embodiments of this application provide a data encryption / decryption method applied to an encryption / decryption execution platform. The method includes: invoking an encryption machine with a first target master key based on a key mapping relationship maintained by a key management platform; the key mapping relationship including a mapping relationship between a unique master key identifier, an encryption machine cluster identifier, and a master key physical index; sending an encryption / decryption request to the encryption machine, the request including data to be processed and target working key indication data; the data to be processed including data to be encrypted or data to be decrypted; the target working key indication data indicating target working key ciphertext; the encryption / decryption request causing the encryption machine to decrypt the target working key ciphertext using the first target master key to obtain the target working key; and using the target working key to encrypt or decrypt the data to be processed to obtain result data; and receiving result data fed back by the encryption machine.

[0007] Thirdly, embodiments of this application provide a data encryption / decryption method applied to a key management platform. The method includes: interacting with an encryption / decryption execution platform, so that the encryption / decryption execution platform, based on the key mapping relationship maintained by the key management platform, calls an encryption machine with a first target master key. The encryption machine uses the first target master key to decrypt the ciphertext of the target working key indicated by the target working key indication data in the encryption / decryption request to obtain the target working key. Then, the target working key is used to encrypt or decrypt the data to be processed in the encryption / decryption request, and the result data is fed back to the encryption / decryption execution platform. The key mapping relationship includes a mapping relationship between the unique identifier of the master key, the encryption machine cluster identifier, and the physical index of the master key. The encryption / decryption request is sent by the encryption / decryption execution platform to the encryption machine. The data to be processed includes data to be encrypted or data to be decrypted.

[0008] Fourthly, embodiments of this application provide an encryption machine having a first target master key. The encryption machine includes: a receiving module, used by an encryption / decryption execution platform to receive encryption / decryption requests sent by the platform based on a key mapping relationship. The key mapping relationship is maintained by a key management platform and includes a mapping relationship between a unique master key identifier, an encryption machine cluster identifier, and a master key physical index. The encryption / decryption request includes data to be processed and target working key indication data. The data to be processed includes data to be encrypted or data to be decrypted, and the target working key indication data indicates the target working key ciphertext. An encryption / decryption module is used to decrypt the target working key ciphertext using the first target master key to obtain the target working key; and to encrypt or decrypt the data to be processed using the target working key to obtain result data. A sending module is used to send the result data back to the encryption / decryption execution platform.

[0009] Fifthly, embodiments of this application provide a data encryption / decryption apparatus applied to an encryption / decryption execution platform. The apparatus includes: a sending module, configured to, based on a key mapping relationship maintained by a key management platform, invoke an encryption machine with a first target master key and send an encryption / decryption request to the encryption machine. The key mapping relationship includes a mapping relationship between a unique master key identifier, an encryption machine cluster identifier, and a master key physical index. The encryption / decryption request includes data to be processed and target working key indication data. The data to be processed includes data to be encrypted or data to be decrypted. The target working key indication data indicates the target working key ciphertext. The encryption / decryption request enables the encryption machine to decrypt the target working key ciphertext using the first target master key to obtain the target working key, and to encrypt or decrypt the data to be processed using the target working key to obtain result data. A receiving module is configured to receive the result data fed back by the encryption machine.

[0010] In a sixth aspect, embodiments of this application provide a data encryption / decryption device applied to a key management platform. The device includes: a communication module for interacting with an encryption / decryption execution platform, enabling the encryption / decryption execution platform to invoke an encryption machine with a first target master key based on a key mapping relationship maintained by the key management platform. The encryption machine uses the first target master key to decrypt the ciphertext of the target working key indicated by the target working key indication data in the encryption / decryption request, obtaining the target working key. Then, the target working key is used to encrypt or decrypt the data to be processed in the encryption / decryption request, and the result data is fed back to the encryption / decryption execution platform. The key mapping relationship includes a mapping relationship between the unique identifier of the master key, the encryption machine cluster identifier, and the physical index of the master key. The encryption / decryption request is sent by the encryption / decryption execution platform to the encryption machine, and the data to be processed includes data to be encrypted or data to be decrypted.

[0011] In a seventh aspect, embodiments of this application provide an electronic device, including: a processor and a memory storing computer program instructions; the processor, when executing the computer program instructions, implements a data encryption / decryption method of the first aspect, a data encryption / decryption method of the second aspect, or a data encryption / decryption method of the third aspect.

[0012] Eighthly, embodiments of this application provide a data encryption / decryption system, comprising: an encryption machine for executing the data encryption / decryption method as described in the first aspect; an encryption / decryption execution platform communicatively connected to the encryption machine for executing the data encryption / decryption method as described in the second aspect; and a key management platform communicatively connected to the encryption machine and the encryption / decryption execution platform for executing the data encryption / decryption method as described in the third aspect.

[0013] Ninthly, embodiments of this application provide a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement a data encryption / decryption method of the first aspect, a data encryption / decryption method of the second aspect, or a data encryption / decryption method of the third aspect.

[0014] This application provides a data encryption / decryption method, apparatus, device, system, and storage medium. An encryption / decryption execution platform, based on a key mapping relationship maintained by a key management platform, invokes an encryption machine with a first target master key. The platform sends an encryption / decryption request to the encryption machine, which includes the data to be processed and target working key indication data that indicates the ciphertext of the target working key. The encryption machine uses the first target master key to decrypt the ciphertext of the target working key indicated by the target working key indication data to obtain the target working key. It then uses the target working key to encrypt or decrypt the data to be processed, obtaining the result data. The encryption / decryption execution platform receives the result data fed back by the encryption machine. In this encryption / decryption process, the plaintext of the working key is only obtained by the encryption machine when decrypting the ciphertext of the working key using the master key during the encryption or decryption of the data to be processed. Different platforms and devices do not transmit the plaintext of the working key; instead, they transmit the working key indication data that indicates the ciphertext of the working key. This prevents the working key from being exposed in plaintext form, thereby avoiding working key leakage and improving data security. Attached Figure Description

[0015] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0016] Figure 1 A schematic diagram of an example application architecture for the data encryption / decryption method provided in the embodiments of this application;

[0017] Figure 2 A flowchart illustrating a data encryption / decryption method provided in an embodiment of the first aspect of this application;

[0018] Figure 3 A schematic diagram illustrating an example of the result data storage format provided in the embodiments of this application;

[0019] Figure 4 A flowchart illustrating a data encryption / decryption method provided in another embodiment of the first aspect of this application;

[0020] Figure 5 A flowchart illustrating a data encryption / decryption method provided in an embodiment of the second aspect of this application;

[0021] Figure 6 A flowchart illustrating a data encryption / decryption method provided in an embodiment of the third aspect of this application;

[0022] Figure 7 A flowchart illustrating a data encryption / decryption method provided in another embodiment of the third aspect of this application;

[0023] Figure 8 A schematic diagram illustrating an example of a data encryption / decryption process provided in an embodiment of this application;

[0024] Figure 9 A schematic diagram illustrating another example of the data encryption / decryption process provided in the embodiments of this application;

[0025] Figure 10 This is a schematic diagram of the structure of an encryption machine provided in an embodiment of the fourth aspect of this application;

[0026] Figure 11 A schematic diagram of the structure of a data encryption / decryption device provided in an embodiment of the fifth aspect of this application;

[0027] Figure 12 A schematic diagram of the structure of a data encryption / decryption apparatus provided in an embodiment of the sixth aspect of this application;

[0028] Figure 13 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the seventh aspect of this application. Detailed Implementation

[0029] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.

[0030] With the development of information network technology, more and more businesses need to collect and process user data to complete their tasks. However, some data is sensitive to privacy, making its security a key concern. To improve data security, working keys can be used to encrypt data. The encrypted data is transmitted during data transfer, and when decryption is needed, the working key is used to decrypt the data to obtain the plaintext. However, the working keys used for encryption and decryption are exposed in plaintext, posing a risk of leakage. If the working key is leaked, it will also bring significant security risks to the data.

[0031] This application provides a data encryption / decryption method, apparatus, device, system, and storage medium. It establishes a centralized and distributed encryption / decryption service and key management mechanism, enabling the transmission of working key indication data (which indicates the ciphertext of the working key) across systems or platforms. The working key ciphertext is obtained by encrypting the working key with a master key. When encrypting or decrypting data, the encryption machine obtains the working key ciphertext based on the working key indication data, decrypts it using its own master key, and then uses the decrypted working key to encrypt or decrypt the data. Throughout the entire encryption / decryption process, the plaintext of the working key only appears during the encryption process and is not transmitted across systems or platforms, preventing the working key from being exposed in plaintext form and thus avoiding working key leakage, thereby improving data security.

[0032] To facilitate understanding, the application architecture of the data encryption and decryption methods in the embodiments of this application will be explained first. Figure 1 A schematic diagram of an application architecture for an example of the data encryption / decryption method provided in the embodiments of this application, as shown below. Figure 1 As shown, the data encryption and decryption methods may involve a key management platform 11, an encryption and decryption execution platform 12, and an encryption machine 13.

[0033] The key management platform 11 has a Key Management Service (KMS) function. The key management platform 11 can maintain the master key (MK), and can maintain the sharing, circulation, and use of the unique identifier of the master key. The master key can serve as a primary key to protect the working key, and can be used to encrypt the working key to obtain the working key ciphertext. The working key is a secondary key used to protect data security, and can be used to encrypt data to obtain the encrypted data ciphertext. The key management platform 11 can also maintain key mapping relationships related to the master key, such as maintaining the master key unique identifier, encryption machine cluster identifier, and master key physical index. The master key unique identifier is used to identify the master key; each master key has only one unique identifier, and the master key unique identifier is unique. The encryption machines in the system can be divided into multiple encryption machine clusters. The encryption machine cluster identifier is used to identify the encryption machine cluster; different encryption machine clusters have different encryption machine cluster identifiers. The master key physical index indicates the physical location of the master key within the encryption machine cluster; the corresponding master key can be obtained through the master key physical index. The key management platform 11 can interact with the encryption / decryption execution platform 12, enabling the execution platform to obtain relevant information from the key mapping relationships required during the encryption / decryption process. The key management platform 11 can also manage the lifecycle of the master key and working keys. When the master key or working key needs to be changed, the encryption machine 13 can be invoked to perform the re-encryption of both the master key and the working key. The key management platform 11 can be implemented by modules, devices, equipment, etc., and the type and number of modules, devices, equipment, etc., used to implement the key management platform 11 are not limited herein.

[0034] The encryption / decryption execution platform 12 has encryption and / or decryption service functions. The platform can belong to an independent encryption / decryption service provider or to a user with encryption and / or decryption needs for the data to be processed; this is not limited here. The encryption / decryption execution platform 12 can determine the encryption machine 13 containing the master key corresponding to the working key ciphertext required for encryption or decryption based on the key mapping relationship maintained by the key management platform 11, and then call the encryption machine 13 to perform encryption or decryption. The encryption / decryption execution platform 12 can be implemented by modules, devices, equipment, etc.; the type and number of modules, devices, equipment, etc., implementing the encryption / decryption execution platform 12 are not limited here.

[0035] Encryption device 13 has encryption and / or decryption functions, and can encrypt or decrypt data to be processed. Encryption device 13 stores a master key. When encryption or decryption of data to be processed is required, the corresponding working key ciphertext can be obtained, and the working key can be decrypted using the master key to obtain the working key. The working key is then used to encrypt or decrypt the data to be processed. The plaintext of the working key only appears in encryption device 13 after the working key ciphertext is decrypted using the master key; the plaintext of the working key is not transmitted outside of encryption device 13. Encryption device 13 can belong to the same entity as encryption / decryption execution platform 12, or to the same entity as key management platform 11, or it can be independent of both encryption / decryption execution platform 12 and key management platform 11; this is not limited here.

[0036] The encryption and decryption methods, devices, equipment, systems, and storage media of the data provided in this application are described below.

[0037] The first aspect of this application provides a data encryption / decryption method applied to an encryption machine, that is, the data encryption / decryption method can be executed by the encryption machine. Figure 2 A flowchart of a data encryption / decryption method provided in an embodiment of the first aspect of this application is shown below. Figure 2 As shown, the encryption and decryption method for this data may include steps S201 to S204.

[0038] In step S201, the encryption / decryption execution platform is invoked based on the key mapping relationship to receive the encryption / decryption request sent by the encryption / decryption execution platform.

[0039] The encryption / decryption execution platform can determine the encryption machine containing the master key required for encrypting or decrypting the data to be processed based on the key mapping relationship, and then invoke that encryption machine. In this embodiment, the master key required for encrypting or decrypting the data to be processed is a first target master key, and the encryption machine possesses the first target master key.

[0040] The key mapping relationship is maintained by the key management platform and includes the mapping relationship between the master key unique identifier, the encryption machine cluster identifier, and the master key physical index. Based on the key mapping relationship, the encryption / decryption execution platform can determine the master key physical index of the master key required for this encryption or decryption, thereby determining the proxy encryption machine. In some examples, the encryption machine is invoked by the encryption / decryption execution platform based on the obtained target master key unique identifier, target encryption machine cluster identifier, and key mapping relationship. In the key mapping relationship, the target master key physical index corresponds to the target master key unique identifier and the target encryption machine cluster identifier; the target master key physical index is the master key physical index of the first target master key. For example, the key mapping relationship is shown in Table 1 below:

[0041] Table 1

[0042]

[0043]

[0044] Table 1 illustrates the key mapping relationship, including the mapping between the master key unique identifier, the encryption machine cluster identifier, and the master key physical index. The same master key can exist in different encryption machine clusters. The master key unique identifier for master key MK1 is gIndex1. Master key MK1 exists in two encryption machine clusters, and the master key physical index of master key MK1 is also different in the two encryption machine clusters. The encryption machine cluster identifiers for the two encryption machine clusters are hsmClusterId1 and hsmClusterId2, respectively. Correspondingly, the master key physical index for encryption machine cluster identifier hsmClusterId1 is hsmIndex1, and the master key physical index for encryption machine cluster identifier hsmClusterId2 is hsmIndex2. If the target master key unique identifier is gIndex1 and the target encryption machine cluster identifier is hsmClusterId1, then the target master key physical index is hsmIndex1, and the corresponding master key MK1 can be obtained based on the target master key physical index hsmIndex1.

[0045] In some examples, the key mapping relationship can be pre-synchronized from the key management platform to the encryption / decryption execution platform. The encryption / decryption execution platform can determine the physical index of the target master key in the pre-synchronized key mapping relationship based on the unique identifier of the target master key and the identifier of the target encryption machine cluster, and then determine the encryption machine to be invoked based on the physical index of the target master key.

[0046] In some examples, the physical index of the target master key is obtained by the encryption / decryption execution platform querying the key management platform for a key mapping relationship. The encryption / decryption execution platform can provide the obtained unique identifier of the target master key and the target encryption machine cluster identifier to the key management platform. Based on the unique identifier of the target master key and the target encryption machine cluster identifier, the key management platform determines the physical index of the target master key in the key mapping relationship and feeds back the physical index of the target master key to the encryption / decryption execution platform, so that the encryption / decryption execution platform can determine the encryption machine to be invoked based on the physical index of the target master key.

[0047] An encryption / decryption request may include data to be processed and target working key indication data. The data to be processed may include data to be encrypted or data to be decrypted. Specifically, the encryption / decryption request may be implemented as an encryption request or a decryption request. If the data to be processed includes data to be encrypted, the encryption / decryption request is implemented as an encryption request, and the encryption machine subsequently encrypts the data to be encrypted; if the data to be processed includes data to be decrypted, the encryption / decryption request is implemented as a decryption request, and the encryption machine subsequently decrypts the data to be decrypted. The working key indication data may indicate the working key ciphertext; that is, the corresponding working key ciphertext can be obtained from the working key indication data, and different working key ciphertexts correspond to different working key indication data. The target working key indication data is the working key indication data in the encryption / decryption request, used to indicate the target working key ciphertext. In some examples, the working key indication data may include a working key ciphertext index or the working key ciphertext; correspondingly, the target working key indication data may include a target working key ciphertext index or the target working key ciphertext. The target working key ciphertext index points to the target working key ciphertext, and the target working key ciphertext can be obtained from the target working key ciphertext index.

[0048] In step S202, the target working key ciphertext is decrypted using the first target master key to obtain the target working key.

[0049] The working key ciphertext is obtained by encrypting the working key with the master key. Correspondingly, the target working key ciphertext is obtained by encrypting the target working key with the first target master key. The encryption machine can obtain the target working key ciphertext according to the target working key instruction data, and decrypt the target working key using the first target master key to obtain the target working key. The encryption machine can obtain the working key ciphertext according to the working key instruction data. The working key ciphertext does not need to be stored in the encryption machine. The amount of working keys, or the amount of working key ciphertext, is not limited by the capacity of the encryption machine, making the management of working keys, or working key ciphertext, more flexible.

[0050] In step S203, the target working key is used to encrypt or decrypt the data to be processed to obtain the result data.

[0051] The resulting data may include data obtained by encrypting or decrypting the data to be processed using the target working key, and may also include data related to the encryption process or the decryption process. When the data to be processed is data to be encrypted, encrypting it using the target working key yields resulting data that may include the encrypted ciphertext of the data to be encrypted and target working key indication data. When the data to be processed is data to be decrypted, decrypting it using the target working key yields resulting data that may include the decrypted plaintext of the data to be decrypted; in some cases, the resulting data may also include target working key indication data.

[0052] In some examples, when the data to be processed includes data to be encrypted, the resulting data also includes fuzzy data of the data to be encrypted and digest data of the data to be encrypted. The data to be encrypted is plaintext. The fuzzy data is obtained by fuzzifying the data to be encrypted. The fuzzy data has some characteristics of the data to be encrypted and can be used for fuzzy queries. The fuzzy data may include a mask field; that is, it fuzzifies part of the content of the data to be encrypted. The data to be encrypted cannot be directly determined based on the mask field. For example, if the data to be encrypted includes a mobile phone number, assuming the plaintext mobile phone number is 12345678910, then the fuzzy data 123****8910 can be generated. This fuzzy data 123****8910 can be used for fuzzy queries. The digest data can be obtained by processing the data to be encrypted using a digest algorithm. Here, a suitable digest algorithm can be selected based on the scenario, requirements, experience, etc. For example, if the data to be encrypted includes a mobile phone number, the SM3 algorithm can be used to process the mobile phone number to obtain the SM3 digest data of the mobile phone number.

[0053] In step S204, the result data is fed back to the encryption / decryption execution platform.

[0054] The encryption / decryption execution platform receives the result data and can store it or transmit it to other devices, equipment, or platforms for storage. For example, if the encryption / decryption execution platform belongs to the user, it can directly store the result data; if it is independent of the user, it can send the result data to the user for storage on the user's device, equipment, or platform. The encryption / decryption execution platform, other devices, equipment, or platforms can be configured with an application database to store the result data in the format required by the application database. For example, the data to be processed includes data to be encrypted. Figure 3 A schematic diagram illustrating an example of the result data storage format provided in the embodiments of this application, such as... Figure 3 As shown, the encrypted ciphertext, target working key ciphertext index, fuzzy data, and digest data in the result data can be stored as four fields in the format required by the application database. The encryption / decryption execution platform can also transmit the result data to downstream systems, enabling downstream systems to also have the ability to decrypt and use the data.

[0055] In this embodiment, the encryption machine with the first target master key can be invoked by the encryption / decryption execution platform based on the key mapping relationship maintained by the key management platform. Using the first target master key, it decrypts the ciphertext of the target working key indicated by the target working key indication data in the encryption / decryption request sent by the encryption / decryption execution platform, obtaining the target working key. The target working key is then used to encrypt or decrypt the data to be processed in the encryption / decryption request, obtaining the result data, which is then fed back to the encryption / decryption execution platform. During this encryption / decryption process, the plaintext of the working key is only obtained by the encryption machine when decrypting the ciphertext of the working key using the master key during the encryption or decryption of the data to be processed. Different platforms and devices do not transmit the plaintext of the working key; instead, they transmit the working key indication data that indicates the ciphertext of the working key. This prevents the working key from being exposed in plaintext, thereby avoiding working key leakage and improving data security. Furthermore, the flow of the working key indication data between different platforms and devices ensures that, while maintaining data security, all platforms and devices that obtain the working key indication data have the ability to decrypt the data, improving the applicability of the data encryption / decryption method.

[0056] In some embodiments, it is necessary to change the master key. Since the working key ciphertext is obtained by encrypting the working key with the master key, when the master key is changed, it is necessary to re-encrypt the working key with the new master key to obtain the new working key ciphertext, that is, to realize the trans-encryption of the working key. Figure 4 A flowchart illustrating a data encryption / decryption method provided in another embodiment of the first aspect of this application. Figure 4 and Figure 2 The difference is that, Figure 4 The data encryption and decryption method shown also includes steps S205 to S208.

[0057] In step S205, if the first target master key is invalid or about to be invalid, it is invoked by the key management platform to decrypt the working key ciphertext encrypted with the first target master key line by line to obtain the working key.

[0058] The expiration of the primary target master key can be due to expiration of its validity period or expiration in response to a corresponding request; this is not limited to either. The expiration of the master key can be determined by the key management platform or the encryption / decryption execution platform through an online interface. The working key ciphertext before encryption is still the working key encrypted using the primary target master key. The encryption machine is invoked by the key management platform to decrypt each working key using the primary target master key, obtaining the working key corresponding to each working key ciphertext.

[0059] In step S206, the working key is encrypted one by one using the second target master key to obtain a new working key ciphertext.

[0060] The second target master key is used to replace the first target master key and can be obtained in response to user input. The key management platform can configure a corresponding unique master key identifier for the second target master key and add a mapping relationship to the key mapping relationship that includes the unique master key identifier of the second target master key, the encryption machine cluster identifier, and the master key index. The working key is not deleted during the encryption process to ensure security.

[0061] In some examples, before encrypting the working key using the second target master key, the key management platform can first add a working key ciphertext record and a unique identifier for the master key of the second target master key. However, at this time, the content of the working key ciphertext in the newly added working key ciphertext record is empty. After encrypting the working key using the second target master key, the newly added working key ciphertext record is updated using the obtained new working key ciphertext. That is, the new working key ciphertext is written into the content of the working key ciphertext in the newly added working key ciphertext record.

[0062] In step S207, the working key obtained based on the working key ciphertext is used to encrypt the randomly generated plaintext data to be verified, thus obtaining the ciphertext data to be verified.

[0063] Since master key replacement is a low-frequency and highly rigorous process, after obtaining the new working key ciphertext encrypted using the second target master key, it is necessary to verify the new working key ciphertext. In this embodiment, the verification of the new working key ciphertext can be achieved by using randomly generated plaintext data to be verified, combined with the working key obtained from the original working key ciphertext and the second target master key.

[0064] In step S208, the new working key ciphertext is verified based on the plaintext data to be verified, the ciphertext data to be verified, the new working key ciphertext, and the second target master key.

[0065] The encrypted data to be verified is the ciphertext encrypted using a working key derived from the original working key. The working key itself remains unchanged before and after the encryption process; what changes is the ciphertext of the working key. That is, the original working key is different from the new working key. If the encryption is successful, for the same data, the ciphertext obtained by encrypting with the working key corresponding to the original working key should be identical to the ciphertext obtained by encrypting with the new working key. Similarly, the plaintext obtained by decrypting with the new working key should also be identical to the plaintext obtained by decrypting with the new working key. This principle can be used to verify the new working key. Based on the plaintext of the data to be verified, the new working key ciphertext, and the second target master key, the ciphertext obtained by encrypting the new working key ciphertext with the corresponding working key can be obtained; based on the ciphertext of the data to be verified, the new working key ciphertext, and the second target master key, the plaintext obtained by decrypting the new working key ciphertext with the corresponding working key can be obtained; by comparing the ciphertexts obtained before and after the same data is re-encrypted, and / or by comparing the plaintexts obtained before and after the same data is re-encrypted, the verification of the new working key ciphertext can be achieved.

[0066] Specifically, the encryption machine can use the second target master key to decrypt the new working key ciphertext to obtain the working key; use the decrypted working key to decrypt the data to be verified ciphertext to obtain the first data; compare the first data with the data to be verified plaintext, and / or use the decrypted working key to encrypt the data to be verified to obtain the second data; compare the second data with the data to be verified ciphertext; if the first data matches the data to be verified plaintext, and / or the second data matches the data to be verified ciphertext, the new working key ciphertext is confirmed to have been successfully verified.

[0067] The first data is the plaintext obtained using the encrypted working key. If the first data matches the plaintext data to be verified, it means the encrypted working key ciphertext can be used normally. The second data is the ciphertext obtained using the encrypted working key, and the ciphertext data to be verified is the ciphertext obtained using the unencrypted working key. If the second data matches the ciphertext data to be verified, it means the encrypted working key ciphertext can be used normally. The comparison between the first data and the plaintext data to be verified, and the comparison between the second data and the ciphertext data to be verified, can be performed once or both times.

[0068] Correspondingly, if the first data does not match the plaintext of the data to be verified, or if the second data does not match the ciphertext of the data to be verified, the verification of the new working key ciphertext fails. The failure to verify the new working key ciphertext may be caused by a failed encryption process, the presence of invisible special characters in the randomly generated plaintext of the data to be verified, or uncontrollable factors during the operation of the encryption machine, such as a power outage during the encryption process. The plaintext of the data to be verified can be verified, and corresponding actions can be taken based on the verification result.

[0069] Specifically, if the verification of the new working key ciphertext fails, the encryption machine can verify the plaintext data to be verified based on the plaintext data to be verified, the ciphertext data to be verified, the working key ciphertext, and the first target master key; if the verification of the plaintext data to be verified fails, it can obtain a randomly generated new plaintext data to be verified, encrypt the new plaintext data to be verified using the working key obtained based on the working key ciphertext, and obtain a new ciphertext data to be verified; and verify the new working key ciphertext based on the new plaintext data to be verified, the new ciphertext data to be verified, the new working key ciphertext, and the second target master key.

[0070] The step of verifying the plaintext data to be verified based on the plaintext data to be verified, the ciphertext data to be verified, the ciphertext working key, and the first target master key is similar to the step of verifying the new ciphertext working key based on the plaintext data to be verified, the ciphertext data to be verified, the new ciphertext working key, and the second target master key in the above embodiment. The encryption machine can decrypt the ciphertext working key (i.e., the ciphertext working key before encryption) using the first target master key to obtain the working key. It then uses the decrypted working key to decrypt the ciphertext data to be verified to obtain third data. The third data is compared with the plaintext data to be verified, and / or the decrypted working key is used to encrypt the plaintext data to be verified to obtain fourth data. The fourth data is then compared with the ciphertext data to be verified. If the third data matches the plaintext data to be verified, and / or the fourth data matches the ciphertext data to be verified, the plaintext data to be verified is determined to have been successfully verified. If the third data does not match the plaintext data to be verified, or the fourth data does not match the ciphertext data to be verified, the plaintext data to be verified is determined to have failed to be verified. The third data is the plaintext obtained by decrypting using the working key before encryption, and the fourth data is the ciphertext obtained by encrypting using the working key before encryption. If the third data matches the plaintext to be verified, it indicates that the randomly generated plaintext to be verified is correct, meaning the verification of the plaintext to be verified is successful. If the fourth data matches the ciphertext to be verified, it also indicates that the randomly generated plaintext to be verified is correct, meaning the verification of the plaintext to be verified is successful. In comparing the third data with the plaintext to be verified and the fourth data with the ciphertext to be verified, one comparison can be performed, or both comparisons can be performed. If the plaintext to be verified is correct, the failure to verify the new working key ciphertext may be due to factors other than the plaintext to be verified. In this case, the new working key ciphertext can be re-verified using the plaintext to be verified. Specific steps can be found in the relevant descriptions in the above embodiments, and will not be repeated here. If the third data is inconsistent with the plaintext of the data to be verified, or if the fourth data is inconsistent with the ciphertext of the data to be verified, it indicates that the randomly generated plaintext of the data to be verified may have a problem. A new plaintext of the data to be verified can be randomly generated, and a new ciphertext of the data to be verified corresponding to the new plaintext of the data to be verified is obtained. The new ciphertext of the data to be verified is encrypted using the working key corresponding to the working key ciphertext before encryption. The step of verifying the new working key ciphertext based on the new plaintext of the data to be verified, the new ciphertext of the data to be verified, the new working key ciphertext, and the second target master key is similar to the step of verifying the new working key ciphertext based on the plaintext of the data to be verified, the new ciphertext of the data to be verified, and the second target master key in the above embodiments. Please refer to the relevant descriptions in the above embodiments, which will not be repeated here.

[0071] In the above embodiments, the transcryption of the working key is performed line by line, and records must be made before and after transcryption to ensure that the new working key ciphertext is verified line by line, and to avoid missing the transcryption of the working key and the verification of the new working key ciphertext.

[0072] In some embodiments, the working key has an expiration date. Upon expiration, the working key needs to be replaced, and the data to be processed under working protection needs to be re-encrypted. The lifecycle of the working key can be sequentially divided into the working key validity period, the working key replacement period, and the working key expiration period. For example, 0 to 2.5 years is the working key validity period, 2.5 to 3 years is the working key replacement period, and after 3 years is the working key expiration period. When the working key is currently valid, the original working key is effective, and the encryption machine uses the original working key to encrypt and decrypt the data to be encrypted. When the working key is currently in the replacement period, the original working key is gradually replaced with a new working key. The encryption machine can use the original working key to decrypt the data to be decrypted and the new working key to encrypt the data to be encrypted, and feed back the working key indication data indicating the corresponding working key ciphertext to the encryption / decryption execution platform, thus achieving implicit re-encryption of the data to be processed. If the current time point is within the working key expiration period (i.e., after the working key replacement period), the new working key has completely replaced the original working key. The encryption machine can use the new working key to decrypt data and encrypt data to be encrypted. In some examples, if the current time point is within the working key expiration period, the encryption / decryption execution platform can provide the encryption machine with unencrypted data from the working key replacement period, based on the actual need for data activity. The encryption machine then uses the new working key to encrypt or decrypt the data, completing the data encryption / decryption process. For example, the encryption machine can use the new working key to encrypt or decrypt data whose generation time is within a preset time period from the current time and which was not encrypted during the working key replacement period; the encryption machine does not encrypt data whose generation time exceeds a preset time period.

[0073] The embodiments of this application can achieve seamless encryption of working keys and data to be processed. When the amount of working keys and data to be processed is large, encryption can be performed one by one in a centralized manner, thereby improving the efficiency of encryption.

[0074] In some embodiments, a root encryption machine may also be configured. The root encryption machine maintains all master keys and can input master keys based on user input. In the case where the encryption machine in the above embodiments is a root encryption machine, this machine can store master keys and can also determine the physical index of the master key in the root encryption machine as the unique identifier of the master key, synchronizing it to the key management platform.

[0075] The second aspect of this application provides a data encryption / decryption method applied to an encryption / decryption execution platform, that is, the data encryption / decryption method can be executed by the encryption / decryption execution platform. Figure 5 A flowchart of a data encryption / decryption method provided in an embodiment of the second aspect of this application is shown below. Figure 5 As shown, the encryption and decryption method for this data may include steps S301 to S303.

[0076] In step S301, based on the key mapping relationship maintained by the key management platform, the encryption machine with the first target master key is invoked.

[0077] The key mapping relationship can include the mapping relationship between the master key unique identifier, the encryption machine cluster identifier, and the master key physical index.

[0078] Specifically, the encryption / decryption execution platform can determine the physical index of the target master key based on the unique identifier of the target master key, the cluster identifier of the target encryption machine, and the key mapping relationship; and determine and invoke the encryption machine with the first target master key according to the physical index of the target master key.

[0079] In some examples, the encryption / decryption execution platform can query the physical index of the master key corresponding to the unique identifier of the target master key and the identifier of the target encryption machine cluster from the key mapping relationship synchronized in advance from the key management platform to determine the physical index of the target master key.

[0080] In other examples, the encryption / decryption execution platform can query the key management platform for the physical index of the master key corresponding to the unique identifier of the target master key and the identifier of the target encryption machine cluster based on the unique identifier of the target master key and the identifier of the target encryption machine cluster in the key mapping relationship, and determine it as the physical index of the target master key.

[0081] In step S302, an encryption / decryption request is sent to the encryption machine.

[0082] The encryption / decryption request includes the data to be processed and the target working key indication data. The data to be processed includes data to be encrypted or data to be decrypted. The target working key indication data is used to indicate the target working key ciphertext. The encryption / decryption request is used to enable the encryption machine to decrypt the target working key ciphertext using the first target master key to obtain the target working key, and then use the target working key to encrypt or decrypt the data to be processed to obtain the result data.

[0083] In some examples, the target working key indicator data includes either a target working key ciphertext index or the target working key ciphertext. The target working key ciphertext index points to the target working key ciphertext, which is obtained by encrypting the target working key using the first target master key.

[0084] In step S303, the result data fed back by the encryption machine is received.

[0085] In some examples, where the data to be processed includes data to be encrypted, the resulting data includes the encrypted ciphertext of the data to be encrypted and the target working key indication data. Where the data to be processed includes data to be decrypted, the resulting data includes the decrypted plaintext of the data to be decrypted.

[0086] In some examples, where the data to be processed includes data to be encrypted, the resulting data also includes obfuscated data of the data to be encrypted and digest data of the data to be encrypted.

[0087] The specific details of steps S301 to S303 can be found in the relevant descriptions in the above embodiments, and will not be repeated here.

[0088] In this embodiment, the encryption / decryption execution platform invokes an encryption machine with a first target master key based on the key mapping relationship maintained by the key management platform. The platform sends an encryption / decryption request to the encryption machine, which includes the data to be processed and target working key indication data that indicates the ciphertext of the target working key. The encryption machine uses the first target master key to decrypt the ciphertext of the target working key indicated by the target working key indication data to obtain the target working key. It then uses the target working key to encrypt or decrypt the data to be processed to obtain the result data. The encryption / decryption execution platform receives the result data fed back by the encryption machine. During this encryption / decryption process, the plaintext of the working key is only obtained by the encryption machine when decrypting the ciphertext of the working key using the master key during the encryption or decryption of the data to be processed. Different platforms and devices do not transmit the plaintext of the working key; instead, they transmit the working key indication data that indicates the ciphertext of the working key. This prevents the working key from being exposed in plaintext, thereby avoiding working key leakage and improving data security. Furthermore, the flow of the working key indication data between different platforms and devices ensures that, while maintaining data security, all platforms and devices that obtain the working key indication data have the ability to decrypt the data, improving the applicability of the data encryption / decryption method.

[0089] In some embodiments, if the current point in time is during the working key replacement period, the encryption / decryption execution platform can invoke the encryption machine to decrypt the data to be decrypted using the original working key and to encrypt the data to be encrypted using the new working key. If the current point in time is after the working key replacement period, the encryption / decryption execution platform can invoke the encryption machine to decrypt the data to be decrypted using the new working key and to encrypt the data to be encrypted using the new working key.

[0090] The specific details of the encryption and decryption methods executed by the encryption and decryption execution platform can be found in the relevant content of the encryption and decryption methods executed by the encryption machine in the above embodiments, and will not be repeated here.

[0091] The third aspect of this application provides a data encryption / decryption method applied to a key management platform, wherein the data encryption / decryption method is executed by the key management platform. Figure 6 A flowchart of a data encryption / decryption method provided in an embodiment of the third aspect of this application is shown below. Figure 6 As shown, the encryption and decryption method for this data may include step S401.

[0092] In step S401, the encryption and decryption execution platform is interacted with so that the encryption and decryption execution platform calls the encryption machine with the first target master key based on the key mapping relationship maintained by the key management platform. The encryption machine uses the first target master key to decrypt the target working key ciphertext indicated by the target working key indication data in the encryption and decryption request to obtain the target working key. Then, the target working key is used to encrypt or decrypt the data to be processed in the encryption and decryption request, and the result data is fed back to the encryption and decryption execution platform.

[0093] The key mapping relationship includes the mapping between the master key's unique identifier, the encryption machine cluster identifier, and the master key's physical index. Encryption / decryption requests are sent from the encryption / decryption execution platform to the encryption machine. Data to be processed includes data to be encrypted or data to be decrypted.

[0094] In some examples, the target working key indicator data includes either a target working key ciphertext index or the target working key ciphertext. The target working key ciphertext index points to the target working key ciphertext. The target working key ciphertext is obtained by encrypting the target working key using the first target master key.

[0095] In some examples, the physical index of the target master key is the physical index of the master key of the first target master key, and in the key mapping relationship, the physical index of the target master key corresponds to the unique identifier of the target master key and the identifier of the target encryption machine cluster.

[0096] The steps for the interaction between the key management platform and the encryption / decryption execution platform can be specifically implemented as follows: synchronizing the key mapping relationship to the encryption / decryption execution platform; or, based on the unique identifier of the target master key and the identifier of the target encryption machine cluster sent by the encryption / decryption execution platform, querying the physical index of the target master key in the key mapping relationship, and feeding it back to the encryption / decryption execution platform.

[0097] In some examples, where the data to be processed includes data to be encrypted, the resulting data includes the encrypted ciphertext of the data to be encrypted and the target working key indication data. Where the data to be processed includes data to be decrypted, the resulting data includes the decrypted plaintext of the data to be decrypted.

[0098] In some examples, where the data to be processed includes data to be encrypted, the resulting data also includes obfuscated data of the data to be encrypted and digest data of the data to be encrypted.

[0099] In this embodiment, the key management platform interacts with the encryption / decryption execution platform. Based on the key mapping relationship maintained by the key management platform, the encryption / decryption execution platform invokes an encryption machine with a first target master key. The platform sends an encryption / decryption request to the encryption machine, which includes the data to be processed and target working key indication data that indicates the ciphertext of the target working key. The encryption machine uses the first target master key to decrypt the ciphertext of the target working key indicated by the target working key indication data to obtain the target working key. It then uses the target working key to encrypt or decrypt the data to be processed, obtaining the result data. The encryption / decryption execution platform receives the result data fed back by the encryption machine. During this encryption / decryption process, the plaintext of the working key is only obtained by the encryption machine when decrypting the ciphertext of the working key using the master key during the encryption or decryption of the data to be processed. Different platforms and devices do not transmit the plaintext of the working key; instead, they transmit the working key indication data that indicates the ciphertext of the working key. This prevents the working key from being exposed in plaintext form, thereby avoiding working key leakage and improving data security. Moreover, the working key indicator data can be transferred between different platforms and devices, which, on the basis of data security, enables all platforms and devices that obtain the working key indicator data to have the ability to decrypt the data, thus improving the applicability of the data encryption and decryption methods.

[0100] In some embodiments, the key management platform can establish a key mapping relationship. In response to a user's first input, the key management platform can input the unique identifier of the master key, which is generated by the encryption machine; obtain the physical index of the master key indicated by the input unique identifier and the encryption machine cluster identifier of the encryption machine cluster where the master key resides; and establish a key mapping relationship based on the unique identifier, the physical index of the master key indicated by the unique identifier, and the encryption machine cluster identifier of the encryption machine cluster where the master key resides.

[0101] When it is necessary to replace, add, or delete the master key, the key management platform can perform corresponding replacement, addition, or deletion operations on the information associated with the master key that needs to be replaced, added, or deleted in the key mapping relationship.

[0102] In some embodiments, the master key needs to be changed. Figure 7 A flowchart illustrating a data encryption / decryption method provided in another embodiment of a third aspect of this application. Figure 7 and Figure 6 The difference is that, Figure 7 The data encryption and decryption method shown also includes steps S402 to S404.

[0103] In step S402, if the first target master key is invalid or about to be invalid, the second target master key is entered.

[0104] The second target master key is generated by the encryption machine. That is, if the first target master key expires or is about to expire, the encryption machine can generate a second target master key.

[0105] In step S403, the encryption machine is invoked to decrypt the working key ciphertext encrypted with the first target master key line by line using the first target master key to obtain the working key, and then the working key is encrypted line by line using the second target master key to obtain a new working key ciphertext.

[0106] In step S404, the encryption machine is invoked to encrypt the randomly generated plaintext data to be verified using the working key obtained based on the working key ciphertext, to obtain the ciphertext data to be verified. The new working key ciphertext is then verified based on the plaintext data to be verified, the ciphertext data to be verified, the new working key ciphertext, and the second target master key.

[0107] The specific details of steps S402 to S404 can be found in the relevant descriptions in the above embodiments, and will not be repeated here.

[0108] In some embodiments, the encryption machine includes a root encryption machine, which stores the master key. Correspondingly, the key management platform can receive the master key physical index of the master key sent by the root encryption machine and determine the master key physical index of the master key as the unique identifier of the master key. For details, please refer to the relevant descriptions in the above embodiments, which will not be repeated here.

[0109] To facilitate understanding, the encryption and decryption process of data will be explained below using two examples. This data encryption and decryption process involves a key management platform, an encryptor, an encryption / decryption execution platform, an encryption machine, and a decryptor. The encryptor can be considered as the user party that needs to encrypt the data, and the decryptor can be considered as the user party that needs to decrypt the data. The encryption / decryption execution platform interacting with the encryptor and the decryptor can be the same or different. Similarly, the encryption machine called by the encryption / decryption execution platform during the encryption and decryption processes can be the same or different. In this example, for ease of description, we will use the example where the encryption / decryption execution platform interacting with the encryptor and the decryptor are the same, and the encryption machine called by the encryption / decryption execution platform during the encryption and decryption processes is the same.

[0110] Figure 8 A schematic diagram illustrating an example of a data encryption / decryption process provided in an embodiment of this application, such as... Figure 8 As shown, the data encryption process may include steps a1 to a15.

[0111] In step a1, the key management platform maintains the key mapping relationship.

[0112] In step a2, the encryption direction sends a data encryption request to the encryption / decryption execution platform. The data encryption request includes the data to be encrypted, the target working key ciphertext, the target master key unique identifier, and the target encryption machine cluster identifier.

[0113] In step a3, the encryption / decryption execution platform sends a first query request to the key management platform. The first query request includes the unique identifier of the target master key and the identifier of the target encryption machine cluster.

[0114] In step a4, the key management platform determines the physical index of the target master key in the key mapping relationship based on the unique identifier of the target master key and the identifier of the target encryption machine cluster, and feeds back the physical index of the target master key to the encryption and decryption execution platform.

[0115] In step a5, the encryption / decryption execution platform calls the corresponding encryption machine based on the physical index of the target master key and sends an encryption request to the encryption machine. The encryption request includes the data to be encrypted and the ciphertext of the target working key.

[0116] In step a6, the encryption machine uses the master key indicated by the physical index of the target master key to decrypt the target working key ciphertext, obtains the target working key, and then uses the target working key to encrypt the data to be encrypted, to obtain the encrypted ciphertext.

[0117] In step a7, the encryption machine generates first result data based on the encrypted ciphertext, the target working key ciphertext, and the unique identifier of the target master key, and then feeds the first result data back to the encryption / decryption execution platform.

[0118] In step a8, the encryption / decryption execution platform sends the first result data back to the encrypting party.

[0119] In step a9, the decryption party sends a data decryption request to the encryption / decryption execution platform. The data decryption request includes the data to be decrypted, the target working key ciphertext, the target master key unique identifier, and the target encryption machine cluster identifier.

[0120] In step a10, the encryption / decryption execution platform sends a second query request to the key management platform. The second query request includes the unique identifier of the target master key and the identifier of the target encryption machine cluster.

[0121] In step a11, the key management platform determines the physical index of the target master key in the key mapping relationship based on the unique identifier of the target master key and the identifier of the target encryption machine cluster, and feeds back the physical index of the target master key to the encryption and decryption execution platform.

[0122] In step a12, the encryption / decryption execution platform calls the corresponding encryption machine based on the physical index of the target master key and sends a decryption request to the encryption machine. The decryption request includes the data to be decrypted and the target working key ciphertext.

[0123] In step a13, the encryption machine uses the master key indicated by the physical index of the target master key to decrypt the ciphertext of the target working key, obtains the target working key, and then uses the target working key to decrypt the data to be decrypted, obtains the decrypted plaintext.

[0124] In step a14, the encryption machine generates second result data based on the decrypted plaintext, the target working key ciphertext, and the unique identifier of the target master key, and then feeds the second result data back to the encryption / decryption execution platform.

[0125] In step a15, the encryption / decryption execution platform sends the second result data back to the decryption party.

[0126] Figure 9 A schematic diagram illustrating another example of the data encryption / decryption process provided in the embodiments of this application, such as... Figure 9 As shown, the data encryption process may include steps b1 to b17.

[0127] In step b1, the key management platform maintains the key mapping relationship.

[0128] In step b2, the encryption direction sends a data encryption request to the encryption / decryption execution platform. The data encryption request includes the data to be encrypted, the target working key ciphertext index, the target master key unique identifier, and the target encryption machine cluster identifier.

[0129] In step b3, the encryption / decryption execution platform obtains the target working key ciphertext based on the target working key ciphertext index.

[0130] In step b4, the encryption / decryption execution platform sends a third query request to the key management platform. The third query request includes the unique identifier of the target master key and the identifier of the target encryption machine cluster.

[0131] In step b5, the key management platform determines the physical index of the target master key in the key mapping relationship based on the unique identifier of the target master key and the identifier of the target encryption machine cluster, and feeds back the physical index of the target master key to the encryption and decryption execution platform.

[0132] In step b6, the encryption / decryption execution platform calls the corresponding encryption machine based on the physical index of the target master key and sends an encryption request to the encryption machine. The encryption request includes the data to be encrypted and the ciphertext of the target working key.

[0133] In step b7, the encryption machine uses the master key indicated by the physical index of the target master key to decrypt the target working key ciphertext, obtains the target working key, and then uses the target working key to encrypt the data to be encrypted, to obtain the encrypted ciphertext.

[0134] In step b8, the encryption machine generates third result data based on the encrypted ciphertext and sends the third result data back to the encryption / decryption execution platform.

[0135] In step b9, the encryption / decryption execution platform sends the fourth result data back to the encryptor. The fourth result data includes the encrypted ciphertext and the ciphertext index of the target working key.

[0136] In step b10, the decryption party sends a data decryption request to the encryption / decryption execution platform. The data decryption request includes the data to be decrypted, the target working key ciphertext index, the target master key unique identifier, and the target encryption machine cluster identifier.

[0137] In step b11, the encryption / decryption execution platform obtains the target working key ciphertext based on the target working key ciphertext index.

[0138] In step b12, the encryption / decryption execution platform sends a fourth query request to the key management platform. The fourth query request includes the unique identifier of the target master key and the identifier of the target encryption machine cluster.

[0139] In step b13, the key management platform determines the physical index of the target master key in the key mapping relationship based on the unique identifier of the target master key and the identifier of the target encryption machine cluster, and feeds back the physical index of the target master key to the encryption and decryption execution platform.

[0140] In step b14, the encryption / decryption execution platform calls the corresponding encryption machine based on the physical index of the target master key and sends a decryption request to the encryption machine. The decryption request includes the data to be decrypted and the target working key ciphertext.

[0141] In step b15, the encryption machine uses the master key indicated by the physical index of the target master key to decrypt the ciphertext of the target working key, obtains the target working key, and then uses the target working key to decrypt the data to be decrypted, obtains the decrypted plaintext.

[0142] In step b16, the encryption machine generates the fifth result data based on the decrypted plaintext and sends the fifth result data back to the encryption / decryption execution platform.

[0143] In step b17, the encryption / decryption execution platform sends the sixth result data back to the decryption party. The sixth result data includes the encrypted ciphertext and the target working key ciphertext index.

[0144] A fourth aspect of this application provides an encryption machine having a first target master key. Figure 10 This is a schematic diagram of the structure of an encryption machine provided in an embodiment of the fourth aspect of this application, as shown below. Figure 10 As shown, the encryption device 500 may include a receiving module 501, an encryption / decryption module 502, and a sending module 503.

[0145] The receiving module 501 can be invoked by the encryption / decryption execution platform based on the key mapping relationship to receive encryption / decryption requests sent by the encryption / decryption execution platform.

[0146] The key mapping relationship is maintained by the key management platform, including the mapping relationship between the master key unique identifier, the encryption machine cluster identifier, and the master key physical index. Encryption / decryption requests include data to be processed and target working key indication data. The data to be processed includes data to be encrypted or data to be decrypted, and the target working key indication data indicates the target working key ciphertext.

[0147] In some examples, the target working key indicator data includes either a target working key ciphertext index or the target working key ciphertext. The target working key ciphertext index points to the target working key ciphertext, which is obtained by encrypting the target working key using the first target master key.

[0148] In some examples, the receiving module 501 can be specifically used to: receive encryption / decryption requests sent by the encryption / decryption execution platform based on the obtained target master key unique identifier, target encryption machine cluster identifier, and key mapping relationship. Specifically, in the key mapping relationship, the target master key physical index corresponds to the target master key unique identifier and the target encryption machine cluster identifier, and the target master key physical index is the master key physical index of the first target master key.

[0149] In some examples, the key mapping relationship is pre-synchronized from the key management platform to the encryption / decryption execution platform.

[0150] In some examples, the physical index of the target master key is obtained by the encryption / decryption execution platform querying the key management platform for the key mapping relationship.

[0151] The encryption / decryption module 502 can be used to decrypt the target working key ciphertext using the first target master key to obtain the target working key; and to encrypt or decrypt the data to be processed using the target working key to obtain the result data.

[0152] In some examples, where the data to be processed includes data to be encrypted, the resulting data includes the encrypted ciphertext of the data to be encrypted and the target working key indication data. Where the data to be processed includes data to be decrypted, the resulting data includes the decrypted plaintext of the data to be decrypted.

[0153] In some examples, where the data to be processed includes data to be encrypted, the resulting data also includes obfuscated data of the data to be encrypted and digest data of the data to be encrypted.

[0154] The sending module 503 can be used to send result data back to the encryption / decryption execution platform.

[0155] In this embodiment, the encryption machine with the first target master key can be invoked by the encryption / decryption execution platform based on the key mapping relationship maintained by the key management platform. Using the first target master key, it decrypts the ciphertext of the target working key indicated by the target working key indication data in the encryption / decryption request sent by the encryption / decryption execution platform, obtaining the target working key. The target working key is then used to encrypt or decrypt the data to be processed in the encryption / decryption request, obtaining the result data, which is then fed back to the encryption / decryption execution platform. During this encryption / decryption process, the plaintext of the working key is only obtained by the encryption machine when decrypting the ciphertext of the working key using the master key during the encryption or decryption of the data to be processed. Different platforms and devices do not transmit the plaintext of the working key; instead, they transmit the working key indication data that indicates the ciphertext of the working key. This prevents the working key from being exposed in plaintext, thereby avoiding working key leakage and improving data security. Furthermore, the flow of the working key indication data between different platforms and devices ensures that, while maintaining data security, all platforms and devices that obtain the working key indication data have the ability to decrypt the data, improving the applicability of the data encryption / decryption method.

[0156] In some embodiments, the encryption / decryption module 502 can also be invoked by the key management platform when the first target master key expires or is about to expire, to decrypt the working key ciphertext encrypted with the first target master key line by line to obtain the working key; and to encrypt the working key line by line with the second target master key to obtain a new working key ciphertext.

[0157] In some embodiments, the encryption / decryption module 502 may also be used to: encrypt randomly generated plaintext data to be verified using a working key obtained based on the working key ciphertext, to obtain ciphertext data to be verified; and verify the new working key ciphertext based on the plaintext data to be verified, the ciphertext data to be verified, the new working key ciphertext, and the second target master key.

[0158] In some examples, the encryption / decryption module 502 described above can be specifically used to: decrypt the new working key ciphertext using the second target master key to obtain the working key; decrypt the data to be verified ciphertext using the decrypted working key to obtain the first data; compare the first data with the data to be verified plaintext; and / or encrypt the data to be verified plaintext using the decrypted working key to obtain the second data; compare the second data with the data to be verified ciphertext; if the first data matches the data to be verified plaintext, and / or the second data matches the data to be verified ciphertext, determine that the new working key ciphertext has been successfully verified.

[0159] In some examples, the encryption / decryption module 502 can also be used to: determine that the verification of the new working key ciphertext fails if the first data is inconsistent with the plaintext to be verified, or if the second data is inconsistent with the ciphertext to be verified; verify the plaintext to be verified based on the plaintext to be verified, the ciphertext to be verified, the working key ciphertext, and the first target master key if the verification of the new working key ciphertext fails; obtain a randomly generated new plaintext to be verified if the verification of the plaintext to be verified fails, encrypt the new plaintext to be verified using the working key obtained based on the working key ciphertext, and obtain a new ciphertext to be verified; and verify the new working key ciphertext based on the new plaintext to be verified, the new ciphertext to be verified, the new working key ciphertext, and the second target master key.

[0160] In some embodiments, the encryption / decryption module 502 can also be used to: decrypt the data to be decrypted using the original working key and encrypt the data to be encrypted using the new working key when the current time point is in the working key replacement period; and decrypt the data to be decrypted using the new working key and encrypt the data to be encrypted using the new working key when the current time point is after the working key replacement period.

[0161] In some embodiments, when the encryption machine is a root encryption machine, the encryption machine 500 may further include a storage module and a synchronization module.

[0162] The storage module can be used to store the master key.

[0163] The synchronization module can be used to determine the physical index of the master key in the root encryption machine as the unique identifier of the master key and synchronize it to the key management platform.

[0164] The fifth aspect of this application provides a data encryption / decryption device that can be applied to an encryption / decryption execution platform, that is, the encryption / decryption execution platform can be implemented by the data encryption / decryption device. Figure 11 A schematic diagram of the structure of a data encryption / decryption device provided in an embodiment of the fifth aspect of this application is shown below. Figure 11 As shown, the data encryption / decryption device 600 may include a sending module 601 and a receiving module 602.

[0165] The sending module 601 can be used to call the encryption machine with the first target master key based on the key mapping relationship maintained by the key management platform, and send encryption / decryption requests to the encryption machine.

[0166] The key mapping relationship includes the mapping relationship between the master key unique identifier, the encryption machine cluster identifier, and the master key physical index. The encryption / decryption request includes the data to be processed and the target working key indication data. The data to be processed includes data to be encrypted or data to be decrypted. The target working key indication data indicates the target working key ciphertext. The encryption / decryption request enables the encryption machine to decrypt the target working key ciphertext using the first target master key to obtain the target working key, and then uses the target working key to encrypt or decrypt the data to be processed to obtain the result data.

[0167] In some examples, the target working key indicator data includes either a target working key ciphertext index or the target working key ciphertext. The target working key ciphertext index points to the target working key ciphertext, which is obtained by encrypting the target working key using the first target master key.

[0168] In some examples, where the data to be processed includes data to be encrypted, the resulting data includes the encrypted ciphertext of the data to be encrypted and the target working key indication data. Where the data to be processed includes data to be decrypted, the resulting data includes the decrypted plaintext of the data to be decrypted.

[0169] In some examples, where the data to be processed includes data to be encrypted, the resulting data also includes obfuscated data of the data to be encrypted and digest data of the data to be encrypted.

[0170] The receiving module 602 can be used to receive the result data fed back by the encryption machine.

[0171] In this embodiment, the encryption / decryption execution platform invokes an encryption machine with a first target master key based on the key mapping relationship maintained by the key management platform. The platform sends an encryption / decryption request to the encryption machine, which includes the data to be processed and target working key indication data that indicates the ciphertext of the target working key. The encryption machine uses the first target master key to decrypt the ciphertext of the target working key indicated by the target working key indication data to obtain the target working key. It then uses the target working key to encrypt or decrypt the data to be processed to obtain the result data. The encryption / decryption execution platform receives the result data fed back by the encryption machine. During this encryption / decryption process, the plaintext of the working key is only obtained by the encryption machine when decrypting the ciphertext of the working key using the master key during the encryption or decryption of the data to be processed. Different platforms and devices do not transmit the plaintext of the working key; instead, they transmit the working key indication data that indicates the ciphertext of the working key. This prevents the working key from being exposed in plaintext, thereby avoiding working key leakage and improving data security. Furthermore, the flow of the working key indication data between different platforms and devices ensures that, while maintaining data security, all platforms and devices that obtain the working key indication data have the ability to decrypt the data, improving the applicability of the data encryption / decryption method.

[0172] In some embodiments, the data encryption / decryption device 600 may further include a calling module, which may be used to: determine the physical index of the target master key based on the obtained unique identifier of the target master key, the cluster identifier of the target encryption machine, and the key mapping relationship; and determine and call the encryption machine with the first target master key according to the physical index of the target master key.

[0173] In some examples, the calling module can be specifically used to: query the physical index of the master key corresponding to the unique identifier of the target master key and the identifier of the target encryption machine cluster in the key mapping relationship synchronized in advance from the key management platform, and determine it as the physical index of the target master key.

[0174] In some examples, the sending module 601 and the receiving module 602 can be used to: query the key management platform for the physical index of the master key corresponding to the unique identifier of the target master key and the identifier of the target encryption machine cluster based on the unique identifier of the target master key and the identifier of the target encryption machine cluster, and determine it as the physical index of the target master key.

[0175] In some examples, the calling module can be used to: decrypt data to be decrypted using the original working key and encrypt data to be encrypted using the new working key when the current point in time is in the working key replacement period; and decrypt data to be decrypted using the new working key and encrypt data to be encrypted using the new working key after the current point in time is in the working key replacement period.

[0176] The sixth aspect of this application provides a data encryption / decryption device that can be applied to a key management platform, i.e., the key management platform can be implemented by the data encryption / decryption device. Figure 12 A schematic diagram of the structure of a data encryption / decryption apparatus provided in an embodiment of the sixth aspect of this application is shown below. Figure 12 As shown, the encryption / decryption device 700 may include a communication module 701.

[0177] The communication module 701 can be used to interact with the encryption / decryption execution platform, so that the encryption / decryption execution platform can call the encryption machine with the first target master key based on the key mapping relationship maintained by the key management platform. The encryption machine uses the first target master key to decrypt the target working key ciphertext indicated by the target working key indication data in the encryption / decryption request to obtain the target working key. Then, the target working key is used to encrypt or decrypt the data to be processed in the encryption / decryption request, and the result data is fed back to the encryption / decryption execution platform.

[0178] The key mapping relationship includes the mapping between the master key's unique identifier, the encryption machine cluster identifier, and the master key's physical index. Encryption / decryption requests are sent from the encryption / decryption execution platform to the encryption machine. Data to be processed includes data to be encrypted or data to be decrypted.

[0179] The communication module 701 may include a sending unit and a receiving unit, which together can implement the steps of interacting with the encryption / decryption execution platform.

[0180] In some examples, the target working key indicator data includes either a target working key ciphertext index or the target working key ciphertext. The target working key ciphertext index points to the target working key ciphertext, which is obtained by encrypting the target working key using the first target master key.

[0181] In some examples, the physical index of the target master key is the physical index of the master key of the first target master key, and in the key mapping relationship, the physical index of the target master key corresponds to the unique identifier of the target master key and the identifier of the target encryption machine cluster.

[0182] In some examples, where the data to be processed includes data to be encrypted, the resulting data includes the encrypted ciphertext of the data to be encrypted and the target working key indication data. Where the data to be processed includes data to be decrypted, the resulting data includes the decrypted plaintext of the data to be decrypted.

[0183] In some examples, where the data to be processed includes data to be encrypted, the resulting data also includes obfuscated data of the data to be encrypted and digest data of the data to be encrypted.

[0184] In this embodiment, the key management platform interacts with the encryption / decryption execution platform. Based on the key mapping relationship maintained by the key management platform, the encryption / decryption execution platform invokes an encryption machine with a first target master key. The platform sends an encryption / decryption request to the encryption machine, which includes the data to be processed and target working key indication data that indicates the ciphertext of the target working key. The encryption machine uses the first target master key to decrypt the ciphertext of the target working key indicated by the target working key indication data to obtain the target working key. It then uses the target working key to encrypt or decrypt the data to be processed, obtaining the result data. The encryption / decryption execution platform receives the result data fed back by the encryption machine. During this encryption / decryption process, the plaintext of the working key is only obtained by the encryption machine when decrypting the ciphertext of the working key using the master key during the encryption or decryption of the data to be processed. Different platforms and devices do not transmit the plaintext of the working key; instead, they transmit the working key indication data that indicates the ciphertext of the working key. This prevents the working key from being exposed in plaintext form, thereby avoiding working key leakage and improving data security. Moreover, the working key indicator data can be transferred between different platforms and devices, which, on the basis of data security, enables all platforms and devices that obtain the working key indicator data to have the ability to decrypt the data, thus improving the applicability of the data encryption and decryption methods.

[0185] In some examples, the communication module 701 described above can be used to: synchronize the key mapping relationship to the encryption / decryption execution platform; or, based on the unique identifier of the target master key and the identifier of the target encryption machine cluster sent by the encryption / decryption execution platform, query the physical index of the target master key in the key mapping relationship and report it back to the encryption / decryption execution platform.

[0186] In some embodiments, the data encryption / decryption device 700 may further include a key maintenance module and a calling module.

[0187] The key maintenance module can be used to: respond to the user's first input, enter the master key unique identifier of the master key, which is generated by the encryption machine; obtain the master key physical index of the master key indicated by the entered master key unique identifier and the encryption machine cluster identifier of the encryption machine cluster where the master key is located; and establish a key mapping relationship based on the master key unique identifier, the master key physical index of the master key indicated by the master key unique identifier, and the encryption machine cluster identifier of the encryption machine cluster where the master key is located.

[0188] The key maintenance module can be used to enter a second target master key if the first target master key expires or is about to expire. The second target master key is generated by the encryption machine.

[0189] The calling module can be used to: call the encryption machine to decrypt the working key ciphertext encrypted with the first target master key line by line to obtain the working key, and then use the second target master key to encrypt the working key line by line to obtain the new working key ciphertext.

[0190] In some examples, the calling module can be used to: invoke the encryption machine to encrypt randomly generated plaintext data to be verified using a working key obtained based on the working key ciphertext, to obtain ciphertext data to be verified, and verify the new working key ciphertext based on the plaintext data to be verified, the ciphertext data to be verified, the new working key ciphertext, and the second target master key.

[0191] In some embodiments, the encryption machine may include a root encryption machine that stores the master key. The communication module 701 may also be configured to receive the master key physical index of the master key sent by the root encryption machine. The key maintenance module may further be configured to determine the master key physical index of the master key as the master key unique identifier of the master key.

[0192] The seventh aspect of this application also provides an electronic device that can implement the encryption machine, encryption / decryption execution platform, and key management platform in the above embodiments. Figure 13 This is a schematic diagram of the structure of an electronic device provided according to an embodiment of the seventh aspect of this application. For example... Figure 13 As shown, the electronic device 800 includes a memory 801, a processor 802, and a computer program stored in the memory 801 and executable on the processor 802.

[0193] In some examples, the processor 802 described above may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or one or more integrated circuits that may be configured to implement the embodiments of this application.

[0194] Memory 801 may include read-only memory (ROM), random access memory (RAM), disk storage media device, optical storage media device, flash memory device, electrical, optical, or other physical / tangible memory storage device. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described in the encryption / decryption method for data according to the first aspect, the second aspect, or the third aspect of the embodiments of this application. When electronic device 800 implements the encryption machine in the above embodiments, when the software in memory 801 is executed, it is operable to perform the encryption / decryption method for data according to the first aspect of the embodiments of this application. When electronic device 800 implements the encryption / decryption execution platform in the above embodiments, when the software in memory 801 is executed, it is operable to perform the encryption / decryption method for data according to the second aspect of the embodiments of this application. When the electronic device 800 implements the key management platform of the above embodiments, when the software in the memory 801 is executed, it is operable to execute the encryption and decryption method for data according to the third aspect of the embodiments of this application.

[0195] The processor 802 runs a computer program corresponding to the executable program code stored in the memory 801 to implement the data encryption / decryption method of the first aspect, the data encryption / decryption method of the second aspect, or the data encryption / decryption method of the third aspect in the above embodiments. When the electronic device 800 implements the encryption machine in the above embodiments, the processor 802 runs a computer program corresponding to the executable program code stored in the memory 801 to implement the data encryption / decryption method of the first aspect in the above embodiments. When the electronic device 800 implements the encryption / decryption execution platform in the above embodiments, the processor 802 runs a computer program corresponding to the executable program code stored in the memory 801 to implement the data encryption / decryption method of the second aspect in the above embodiments. When the electronic device 800 implements the key management platform in the above embodiments, the processor 802 runs a computer program corresponding to the executable program code stored in the memory 801 to implement the data encryption / decryption method of the third aspect in the above embodiments.

[0196] In some examples, the electronic device 800 may also include a communication interface 803 and a bus 804. For example, Figure 13 As shown, the memory 801, processor 802, and communication interface 803 are connected through bus 804 and complete communication with each other.

[0197] The communication interface 803 is mainly used to enable communication between various modules, devices, units, and / or equipment in the embodiments of this application. Input devices and / or output devices can also be connected through the communication interface 803.

[0198] Bus 804 includes hardware, software, or both, that couples components of electronic device 800 together. For example, and not limitingly, bus 804 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-E) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 804 may include one or more buses. Although specific buses are described and illustrated in the embodiments of this application, this application considers any suitable bus or interconnection.

[0199] The eighth aspect of this application provides a data encryption and decryption system, which may include an encryption machine, an encryption and decryption execution platform, and a key management platform.

[0200] The encryption machine is used to execute the data encryption and decryption method of the first aspect in the above embodiments.

[0201] The encryption / decryption execution platform is connected to the encryption machine and is used to execute the data encryption / decryption method of the second aspect in the above embodiments.

[0202] The key management platform communicates with the encryption machine and the encryption / decryption execution platform to execute the data encryption / decryption method of the third aspect in the above embodiments.

[0203] The specific details of the encryption machine, encryption / decryption execution platform, key management platform, and data encryption / decryption methods in the data encryption / decryption system can be found in the relevant descriptions in the above embodiments, and they can achieve the same technical effect. To avoid repetition, they will not be described again here.

[0204] The ninth aspect of this application also provides a computer-readable storage medium storing computer program instructions. When executed by a processor, these computer program instructions can implement the data encryption / decryption methods of the first aspect, the second aspect, or the third aspect described in the above embodiments, and achieve the same technical effect. To avoid repetition, these methods will not be described again here. The aforementioned computer-readable storage medium may include non-transitory computer-readable storage media, such as read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks, etc., and is not limited thereto.

[0205] This application provides a computer program product. When the instructions in the computer program product are executed by the processor of an electronic device, the electronic device executes the data encryption and decryption method of the first aspect, the data encryption and decryption method of the second aspect, or the data encryption and decryption method of the third aspect described in the above embodiments, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0206] It should be clarified that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. For the embodiments of encryption machines, devices, electronic devices, systems, computer-readable storage media, and computer program products, the relevant parts can be referred to the description section of the method embodiments. This application is not limited to the specific steps and structures described above and shown in the figures. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application. Furthermore, for the sake of brevity, detailed descriptions of known methods and techniques are omitted here.

[0207] The aspects of this application have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by dedicated hardware performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0208] Those skilled in the art will understand that the above embodiments are exemplary and not restrictive. Different technical features appearing in different embodiments can be combined to achieve beneficial effects. Based on a study of the drawings, specification, and claims, those skilled in the art should be able to understand and implement other variations of the disclosed embodiments. In the claims, the term "comprising" does not exclude other means or steps; the quantifier "a" does not exclude a plurality; the terms "first" and "second" are used to identify names and not to indicate any particular order. No reference numerals in the claims should be construed as limiting the scope of protection. The functionality of multiple parts appearing in the claims can be implemented by a single hardware or software module. The appearance of certain technical features in different dependent claims does not mean that these technical features cannot be combined to achieve beneficial effects.

Claims

1. A data encryption / decryption method, characterized in that, Applied to an encryption machine having a first target master key, the method includes: The encryption / decryption execution platform is invoked based on the key mapping relationship. The encryption / decryption request is received from the encryption / decryption execution platform. The key mapping relationship is maintained by the key management platform and includes the mapping relationship between the master key unique identifier, the encryption machine cluster identifier and the master key physical index. The encryption / decryption request includes data to be processed and target working key indication data. The data to be processed includes data to be encrypted or data to be decrypted. The target working key indication data is used to indicate the target working key ciphertext. The target working key is obtained by decrypting the ciphertext of the target working key using the first target master key; The target working key is used to encrypt or decrypt the data to be processed to obtain the result data. The result data is fed back to the encryption / decryption execution platform.

2. The method according to claim 1, characterized in that, The target working key indication data includes either a target working key ciphertext index or the target working key ciphertext. The target working key ciphertext index points to the target working key ciphertext, which is obtained by encrypting the target working key using the first target master key.

3. The method according to claim 1, characterized in that, The encryption / decryption execution platform is invoked based on the key mapping relationship, including: The encryption / decryption execution platform invokes the key based on the unique identifier of the target master key, the identifier of the target encryption machine cluster, and the key mapping relationship. In the key mapping relationship, the physical index of the target master key corresponds to the unique identifier of the target master key and the identifier of the target encryption machine cluster, and the physical index of the target master key is the physical index of the master key of the first target master key.

4. The method according to claim 3, characterized in that, The key mapping relationship is pre-synchronized from the key management platform to the encryption / decryption execution platform; or, The physical index of the target master key is obtained by the encryption / decryption execution platform querying the key management platform for the key mapping relationship.

5. The method according to claim 1, characterized in that, When the data to be processed includes data to be encrypted, the result data includes the encrypted ciphertext of the data to be encrypted and the target working key indication data; If the data to be processed includes data to be decrypted, the result data includes the plaintext of the data to be decrypted.

6. The method according to claim 5, characterized in that, In the case where the data to be processed includes data to be encrypted, the result data also includes fuzzy data of the data to be encrypted and digest data of the data to be encrypted.

7. The method according to claim 1, characterized in that, Also includes: In the event that the first target master key has expired or is about to expire, it is invoked by the key management platform to decrypt the working key ciphertext encrypted with the first target master key one by one to obtain the working key. The working key is encrypted one by one using the second target master key to obtain the new working key ciphertext.

8. The method according to claim 7, characterized in that, Also includes: The random plaintext of the data to be verified is encrypted using the working key obtained based on the ciphertext of the working key to obtain the ciphertext of the data to be verified. The new working key ciphertext is verified based on the plaintext data to be verified, the ciphertext data to be verified, the new working key ciphertext, and the second target master key.

9. The method according to claim 8, characterized in that, The step of verifying the new working key ciphertext based on the plaintext data to be verified, the ciphertext data to be verified, the new working key ciphertext, and the second target master key includes: The new working key is decrypted using the second target master key to obtain the working key; The working key obtained from decryption is used to decrypt the ciphertext of the data to be verified to obtain first data. The first data is compared with the plaintext of the data to be verified. And / or, the working key obtained from decryption is used to encrypt the plaintext of the data to be verified to obtain second data. The second data is compared with the ciphertext of the data to be verified. If the first data matches the plaintext of the data to be verified, and / or the second data matches the ciphertext of the data to be verified, then the new working key ciphertext is determined to have been successfully verified.

10. The method according to claim 9, characterized in that, Also includes: If the first data is inconsistent with the plaintext of the data to be verified, the verification of the new working key ciphertext is determined to have failed; or, if the second data is inconsistent with the ciphertext of the data to be verified, the verification of the new working key ciphertext is determined to have failed. If the verification of the new working key ciphertext fails, the plaintext data to be verified is verified based on the plaintext data to be verified, the ciphertext data to be verified, the working key ciphertext, and the first target master key. If the verification of the plaintext data to be verified fails, a new plaintext data to be verified is obtained by random generation, and the new plaintext data to be verified is encrypted using the working key obtained based on the working key ciphertext to obtain a new ciphertext data to be verified. The new working key ciphertext is verified based on the new plaintext data to be verified, the new ciphertext data to be verified, the new working key ciphertext, and the second target master key.

11. The method according to claim 1, characterized in that, Also includes: If the current working key is in the process of changing, the original working key is used to decrypt the data to be decrypted, and the new working key is used to encrypt the data to be encrypted. If the current time point is after the working key replacement period, the new working key is used to decrypt the data to be decrypted, and the new working key is used to encrypt the data to be encrypted.

12. The method according to claim 1, characterized in that, Also includes: When the encryption machine is the root encryption machine, the master key is stored; The master key physical index in the root encryption machine is used to determine the master key's unique identifier and synchronized to the key management platform.

13. A data encryption / decryption method, characterized in that, The method, applied to an encryption / decryption execution platform, includes: Based on the key mapping relationship maintained by the key management platform, the encryption machine with the first target master key is invoked. The key mapping relationship includes the mapping relationship between the master key unique identifier, the encryption machine cluster identifier and the master key physical index. An encryption / decryption request is sent to the encryption machine. The encryption / decryption request includes data to be processed and target working key indication data. The data to be processed includes data to be encrypted or data to be decrypted. The target working key indication data is used to indicate the target working key ciphertext. The encryption / decryption request is used to enable the encryption machine to decrypt the target working key ciphertext using the first target master key to obtain the target working key, and to encrypt or decrypt the data to be processed using the target working key to obtain the result data. Receive the result data fed back by the encryption machine.

14. The method according to claim 13, characterized in that, The target working key indication data includes either a target working key ciphertext index or the target working key ciphertext. The target working key ciphertext index points to the target working key ciphertext, which is obtained by encrypting the target working key using the first target master key.

15. The method according to claim 13, characterized in that, The step of invoking the encryption machine with the first target master key based on the key mapping relationship includes: Based on the obtained unique identifier of the target master key, the identifier of the target encryption machine cluster, and the key mapping relationship, the physical index of the target master key is determined; Based on the physical index of the target master key, the encryption machine with the first target master key is identified and invoked.

16. The method according to claim 15, characterized in that, The step of determining the physical index of the target master key based on the obtained unique identifier of the target master key, the identifier of the target encryption machine cluster, and the key mapping relationship includes: In the key mapping relationship synchronized from the key management platform in advance, the physical index of the master key corresponding to the unique identifier of the target master key and the identifier of the target encryption machine cluster is determined as the physical index of the target master key; or, Based on the unique identifier of the target master key and the identifier of the target encryption machine cluster, the physical index of the master key corresponding to the unique identifier of the target master key and the identifier of the target encryption machine cluster in the key mapping relationship is queried from the key management platform and determined as the physical index of the target master key.

17. The method according to claim 13, characterized in that, When the data to be processed includes data to be encrypted, the result data includes the encrypted ciphertext of the data to be encrypted and the target working key indication data; If the data to be processed includes data to be decrypted, the result data includes the plaintext of the data to be decrypted.

18. The method according to claim 17, characterized in that, In the case where the data to be processed includes data to be encrypted, the result data also includes fuzzy data of the data to be encrypted and digest data of the data to be encrypted.

19. The method according to claim 13, characterized in that, Also includes: If the current time is during the working key replacement period, the encryption machine is invoked to decrypt the data to be decrypted using the original working key, and to encrypt the data to be encrypted using the new working key. If the current time point is after the working key replacement period, the encryption machine is invoked to decrypt the data to be decrypted using the new working key, and to encrypt the data to be encrypted using the new working key.

20. A method for encrypting and decrypting data, characterized in that, The method, applied to a key management platform, includes: The system interacts with an encryption / decryption execution platform, which, based on the key mapping relationship maintained by the key management platform, invokes an encryption machine with a first target master key. The encryption machine then uses the first target master key to decrypt the ciphertext of the target working key indicated by the target working key indication data in the encryption / decryption request, obtaining the target working key. The target working key is then used to encrypt or decrypt the data to be processed in the encryption / decryption request, and the resulting data is fed back to the encryption / decryption execution platform. The key mapping relationship includes the mapping relationship between the master key unique identifier, the encryption machine cluster identifier and the master key physical index. The encryption / decryption request is sent by the encryption / decryption execution platform to the encryption machine. The data to be processed includes data to be encrypted or data to be decrypted.

21. The method according to claim 20, characterized in that, The target working key indication data includes either a target working key ciphertext index or the target working key ciphertext. The target working key ciphertext index points to the target working key ciphertext, which is obtained by encrypting the target working key using the first target master key.

22. The method according to claim 20, characterized in that, Also includes: In response to the user's first input, the unique identifier of the master key is entered, which is generated by the encryption machine; Obtain the physical index of the master key, which is indicated by the unique identifier of the entered master key, and the encryption machine cluster identifier of the encryption machine cluster where the master key is located; The key mapping relationship is established based on the master key unique identifier, the master key physical index of the master key indicated by the master key unique identifier, and the encryption machine cluster identifier of the encryption machine cluster where the master key is located.

23. The method according to claim 20, characterized in that, The physical index of the target master key is the physical index of the master key of the first target master key. In the key mapping relationship, the physical index of the target master key corresponds to the unique identifier of the target master key and the identifier of the target encryption machine cluster.

24. The method according to claim 23, characterized in that, The interaction with the encryption / decryption execution platform includes: Synchronize the key mapping relationship to the encryption / decryption execution platform; or, Based on the unique identifier of the target master key and the identifier of the target encryption machine cluster sent by the encryption / decryption execution platform, the physical index of the target master key is queried in the key mapping relationship and fed back to the encryption / decryption execution platform.

25. The method according to claim 20, characterized in that, When the data to be processed includes data to be encrypted, the result data includes the encrypted ciphertext of the data to be encrypted and the target working key indication data; If the data to be processed includes data to be decrypted, the result data includes the plaintext of the data to be decrypted.

26. The method according to claim 20, characterized in that, In the case where the data to be processed includes data to be encrypted, the result data also includes fuzzy data of the data to be encrypted and digest data of the data to be encrypted.

27. The method according to claim 20, characterized in that, Also includes: If the first target master key expires or is about to expire, a second target master key is entered, which is generated by the encryption machine; The encryption machine is invoked to decrypt the working key ciphertext encrypted with the first target master key line by line using the first target master key to obtain the working key. Then, the working key is encrypted line by line using the second target master key to obtain a new working key ciphertext.

28. The method according to claim 27, characterized in that, Also includes: The encryption machine is invoked to encrypt the randomly generated plaintext data to be verified using the working key obtained based on the working key ciphertext, resulting in ciphertext data to be verified. The new working key ciphertext is then verified based on the plaintext data to be verified, the ciphertext data to be verified, the new working key ciphertext, and the second target master key.

29. The method according to claim 20, characterized in that, The encryption machine includes a root encryption machine, which stores the master key. The method further includes: Receive the master key physical index of the master key sent by the root encryption machine, and determine the master key physical index of the master key as the master key unique identifier of the master key.

30. An encryption machine, characterized in that, The encryption machine contains a first target master key, and the encryption machine includes: The receiving module is used to receive encryption / decryption requests sent by the encryption / decryption execution platform based on the key mapping relationship. The key mapping relationship is maintained by the key management platform and includes the mapping relationship between the master key unique identifier, the encryption machine cluster identifier and the master key physical index. The encryption / decryption request includes data to be processed and target working key indication data. The data to be processed includes data to be encrypted or data to be decrypted. The target working key indication data is used to indicate the target working key ciphertext. The encryption / decryption module is used to decrypt the target working key ciphertext using the first target master key to obtain the target working key; and to encrypt or decrypt the data to be processed using the target working key to obtain the result data. The sending module is used to send the result data back to the encryption / decryption execution platform.

31. A data encryption / decryption device, characterized in that, The device, used in an encryption / decryption execution platform, includes: The sending module is used to invoke an encryption machine with a first target master key based on the key mapping relationship maintained by the key management platform, and send an encryption / decryption request to the encryption machine. The key mapping relationship includes a mapping relationship between the master key unique identifier, the encryption machine cluster identifier, and the master key physical index. The encryption / decryption request includes data to be processed and target working key indication data. The data to be processed includes data to be encrypted or data to be decrypted. The target working key indication data is used to indicate the target working key ciphertext. The encryption / decryption request is used to enable the encryption machine to decrypt the target working key ciphertext using the first target master key to obtain the target working key, and to encrypt or decrypt the data to be processed using the target working key to obtain the result data. A receiving module is used to receive the result data fed back by the encryption machine.

32. A data encryption / decryption device, characterized in that, The device, used in a key management platform, includes: The communication module interacts with the encryption / decryption execution platform, enabling the platform to invoke an encryption machine with a first target master key based on the key mapping relationship maintained by the key management platform. The encryption machine then uses the first target master key to decrypt the ciphertext of the target working key indicated by the target working key indication data in the encryption / decryption request, obtaining the target working key. The target working key is then used to encrypt or decrypt the data to be processed in the encryption / decryption request, and the resulting data is fed back to the encryption / decryption execution platform. The key mapping relationship includes the mapping relationship between the master key unique identifier, the encryption machine cluster identifier and the master key physical index. The encryption / decryption request is sent by the encryption / decryption execution platform to the encryption machine. The data to be processed includes data to be encrypted or data to be decrypted.

33. An electronic device, characterized in that, include: Processor and memory storing computer program instructions; When the processor executes the computer program instructions, it implements the data encryption and decryption method as described in any one of claims 1 to 29.

34. A data encryption / decryption system, characterized in that, include: An encryption machine for performing the data encryption and decryption method as described in any one of claims 1 to 12; An encryption / decryption execution platform, communicatively connected to the encryption machine, is used to execute the data encryption / decryption method as described in any one of claims 13 to 19; A key management platform, which is communicatively connected to the encryption machine and the encryption / decryption execution platform, is used to execute the data encryption / decryption method as described in any one of claims 20 to 29.

35. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processor, implement the data encryption / decryption method as described in any one of claims 1 to 29.