A multi-layer deployed password service system and method in a cloud environment

By deploying a multi-layered cryptographic service system in a cloud environment and utilizing the collaborative work of the primary and secondary cryptographic service subsystems, the regulatory challenges and resource waste caused by independent management at various levels of units in the cloud environment are solved, achieving efficient cryptographic service management and resource utilization.

CN117978444BActive Publication Date: 2025-10-21AISINO CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311839949.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-10-21
Estimated Expiration
2043-12-28

AI Technical Summary

Technical Problem

In the cloud environment, units at all levels independently build and manage their own comprehensive cryptographic management service platforms, which leads to problems such as difficulty for superiors to supervise subordinates and waste of cryptographic resources.

Method used

This paper proposes a multi-layered cryptographic service system deployed in a cloud environment, including a first-level cryptographic service subsystem and a second-level cryptographic service subsystem. Data is classified using a unified format classification dataset and a classifier to generate sub-classification datasets. Cryptographic service policies are determined and divided into primary target policies and secondary target policies, which are executed and managed in different network domains respectively.

Benefits of technology

It has achieved the integration of cryptographic services, improved the efficiency of use and management, provided a comprehensive system platform, solved the problem of difficulty in supervision from superiors to subordinates, and optimized the utilization of cryptographic resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117978444B_ABST
    Figure CN117978444B_ABST
Patent Text Reader

Abstract

The application discloses a kind of multi-layer deployment password service system and method under cloud environment, belong to password service application technical field.The system of the application, comprising: primary password service subsystem, for executing primary password service based on main target strategy, and the secondary target strategy is issued to secondary password service subsystem, obtains the primary password service data generated after executing primary password service, receives the secondary password service data uploaded by the secondary password service subsystem, and the primary password service data and the secondary password service data are stored;Secondary password service subsystem is used to receive the secondary target strategy issued by the primary password service subsystem, executes secondary password service based on the secondary target strategy, and obtains the secondary password service data of executing secondary password service.The application can integrate password service to provide a comprehensive system platform, improve the efficiency of use and management for password service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cryptographic service application technology, and more specifically, to a cryptographic service system and method for multi-layer deployment in a cloud environment. Background Art

[0002] As various information systems migrate to the cloud, the security of cryptographic applications in cloud environments has become a hot topic. The use of cryptography in the cloud has become a trend in cryptographic development. Currently, many organizations (such as government departments and large enterprises) have numerous subordinate organizations. Generally speaking, first-level organizations oversee second-level organizations, which in turn oversee third-level organizations, and so on. Regarding cryptographic application, if each level independently develops and manages its own comprehensive cryptographic management service platform, this can lead to problems such as difficulty for superiors to supervise subordinates and waste of cryptographic resources. Summary of the Invention

[0003] To address the above issues, the present invention proposes a multi-layer deployed cryptographic service system in a cloud environment, comprising:

[0004] A primary cryptographic service subsystem is configured to obtain informationized data associated with a cryptographic service, preprocess the informationized data to obtain classified cryptographic data in a unified format, construct a classified data set based on the classified cryptographic data, classify each type of data in the classified data set based on a classifier to generate a sub-classified data set for each type of data set, determine a corresponding cryptographic service policy based on the sub-classified data set, determine the adaptability of the cryptographic service policy to current cryptographic service requirements, select a cryptographic service policy whose adaptability meets the requirements as a target policy for the current cryptographic service, determine the importance of the target policy, divide the target policy into a primary target policy and a secondary target policy based on the importance level of the target policy, divide the cryptographic service into a primary cryptographic service and a secondary cryptographic service based on the primary target policy and the secondary target policy, execute the primary cryptographic service based on the primary target policy, and send the secondary target policy to the secondary cryptographic service subsystem, obtain the primary cryptographic service data generated after executing the primary cryptographic service, receive the secondary cryptographic service data uploaded by the secondary cryptographic service subsystem, and store the primary cryptographic service data and the secondary cryptographic service data;

[0005] The first-level cryptographic service subsystem is deployed in a primary network domain in a cloud environment;

[0006] The secondary cryptographic service subsystem is configured to receive the secondary target detection policy issued by the primary cryptographic service subsystem, execute the secondary cryptographic service based on the secondary target policy, obtain secondary cryptographic service data for executing the secondary cryptographic service, and upload the secondary cryptographic service data to the primary cryptographic service subsystem;

[0007] The secondary cryptographic service subsystem is deployed in a second-level network domain in a cloud environment.

[0008] Optionally, an interface-level connection is established between the first-level cryptographic service subsystem and the second-level cryptographic service subsystem.

[0009] Optionally, the first-level cryptographic service subsystem is also used to:

[0010] Based on the first-level cryptographic service data, the adaptability of the main target policy is calculated. If the adaptability is less than the target requirement, the main target policy is adjusted to update the main target policy. Based on the second-level cryptographic service data, the adaptability of the secondary target policy is calculated. If the adaptability is less than the target requirement, the secondary target policy is adjusted to update the secondary target policy, and the secondary target policy is sent down to the second-level cryptographic service subsystem.

[0011] Optionally, the first-level cryptographic service subsystem pre-processes the informationized data, including:

[0012] The information data is cleaned and normalized.

[0013] Optionally, the primary target strategy includes at least one of the following:

[0014] Cloud password service policy, business service policy, master password service policy, operation and maintenance policy, master key service policy and main system service policy.

[0015] Optionally, the secondary target strategy includes at least one of the following:

[0016] Sub-cryptographic service policy, sub-key service policy and sub-system service policy.

[0017] Optionally, the first-level cryptographic service subsystem includes at least one of the following modules: a cloud cryptographic service module, a business service module, a master cryptographic service module, an operation and maintenance module, a master key service module, and a main system service module;

[0018] The cloud cryptographic service module is used to execute cloud cryptographic service policies;

[0019] The business service module is used to execute business service strategies;

[0020] The master password service module is used to execute the master password service policy;

[0021] The operation and maintenance module is used to execute the operation and maintenance strategy;

[0022] The master key service module is used to execute the master key service policy;

[0023] The main system service module is used to execute the main system service strategy.

[0024] Optionally, the secondary cryptographic service subsystem includes at least one of the following modules: a master cryptographic service module, a master key service module, and a main system service module;

[0025] The secondary password service module is used to execute the primary password service policy;

[0026] The secondary key service module is used to execute the primary key service strategy;

[0027] The secondary system service module is used to execute the primary system service strategy.

[0028] Optionally, the first-level cryptographic service subsystem is used to connect to multiple external cryptographic service platforms or cryptographic resource pools, and based on the cryptographic resources / services of multiple external cryptographic service platforms or cryptographic resource pools, execute the first-level cryptographic service according to the main target strategy.

[0029] Optionally, the secondary cryptographic service subsystem is used to connect to multiple external cryptographic service platforms or cryptographic resource pools, and based on the cryptographic resources / services of the multiple external cryptographic service platforms or cryptographic resource pools, execute secondary cryptographic services according to secondary target strategies.

[0030] On the other hand, the present invention also proposes a multi-layer deployed cryptographic service method in a cloud environment, comprising:

[0031] Obtaining informationized data associated with a cryptographic service, preprocessing the informationized data to obtain classified cryptographic data in a unified format, constructing a classified data set based on the classified cryptographic data, and classifying each category of data in the classified data set based on a classifier to generate a sub-classified data set of each category of data set;

[0032] Determining a corresponding cryptographic service policy based on the sub-classification data set, determining the adaptability of the cryptographic service policy to the current cryptographic service requirement, selecting the cryptographic service policy whose adaptability meets the requirement as the target policy for the current cryptographic service, determining the importance of the target policy, and classifying the target policy into a primary target policy and a secondary target policy according to the importance level of the target policy;

[0033] According to the primary target policy and the secondary target policy, the cryptographic service is divided into a primary cryptographic service and a secondary cryptographic service. The primary cryptographic service is executed based on the primary target policy, and the secondary cryptographic service is executed based on the secondary target policy.

[0034] Optionally, the password service method also includes:

[0035] Obtain the first-level cryptographic service data for executing the first-level cryptographic service, and obtain the second-level cryptographic service data for executing the second-level cryptographic service. Based on the first-level cryptographic service data, calculate the fitness of the main target policy. If the fitness is less than the target requirement, adjust the main target policy to update the main target policy. Based on the second-level cryptographic service data, calculate the fitness of the secondary target policy. If the fitness is less than the target requirement, adjust the secondary target policy to update the secondary target policy, and send the secondary target policy to the second-level cryptographic service subsystem.

[0036] Optionally, preprocessing the information data includes:

[0037] The information data is cleaned and normalized.

[0038] Optionally, the primary target strategy includes at least one of the following:

[0039] Cloud password service policy, business service policy, master password service policy, operation and maintenance policy, master key service policy and main system service policy.

[0040] Optionally, the secondary target strategy includes at least one of the following:

[0041] Sub-cryptographic service policy, sub-key service policy and sub-system service policy.

[0042] Optionally, the cryptographic service method also includes: connecting to multiple external cryptographic service platforms or cryptographic resource pools, and executing first-level cryptographic services according to the main target strategy based on the cryptographic resources / services of the multiple external cryptographic service platforms or cryptographic resource pools retrieved.

[0043] Optionally, the cryptographic service method also includes: connecting to multiple external cryptographic service platforms or cryptographic resource pools, and executing secondary cryptographic services according to secondary target strategies based on the cryptographic resources / services retrieved from the multiple external cryptographic service platforms or cryptographic resource pools.

[0044] In yet another aspect, the present invention further provides a computing device comprising: one or more processors;

[0045] a processor for executing one or more programs;

[0046] When the one or more programs are executed by the one or more processors, the above-described method is implemented.

[0047] In another aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed, the method described above is implemented.

[0048] Compared with the prior art, the present invention has the following beneficial effects:

[0049] The present invention proposes a cryptographic service system with multi-layer deployment in a cloud environment, including: a first-level cryptographic service subsystem, used to obtain information data associated with cryptographic services, pre-process the information data to obtain classified cryptographic data in a unified format, and construct a classified data set based on the classified cryptographic data, classify each type of data in the classified data set based on a classifier to generate a sub-classified data set for each type of data set, determine the corresponding cryptographic service policy based on the sub-classified data set, determine the adaptability of the cryptographic service policy to the current cryptographic service requirements, select the cryptographic service policy with the adaptability meeting the requirements as the target policy for the current cryptographic service, determine the importance of the target policy, divide the target policy into a primary target policy and a secondary target policy according to the importance level of the target policy, and divide the target policy into the primary target policy and the secondary target policy according to the primary target policy and the secondary target policy. The cryptographic service is divided into a primary cryptographic service and a secondary cryptographic service. The primary cryptographic service is executed based on the primary target policy, and the secondary target policy is sent to the secondary cryptographic service subsystem. The primary cryptographic service data generated after the primary cryptographic service is executed is obtained, the secondary cryptographic service data uploaded by the secondary cryptographic service subsystem is received, and the primary cryptographic service data and the secondary cryptographic service data are stored. The primary cryptographic service subsystem is deployed in a primary network domain in a cloud environment. The secondary cryptographic service subsystem is used to receive the secondary target policy sent by the primary cryptographic service subsystem, execute the secondary cryptographic service based on the secondary target policy, obtain the secondary cryptographic service data for executing the secondary cryptographic service, and upload the secondary cryptographic service data to the primary cryptographic service subsystem. The secondary cryptographic service subsystem is deployed in a second-tier network domain in a cloud environment. The present invention can integrate cryptographic services to provide a comprehensive system platform, thereby improving the efficiency of using and managing cryptographic services. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 It is a structural diagram of the system of the present invention;

[0051] Figure 2 Flowchart of the method of the present invention. DETAILED DESCRIPTION

[0052] Exemplary embodiments of the present invention will now be described with reference to the accompanying drawings. However, the present invention may be embodied in many different forms and is not limited to the embodiments described herein. These embodiments are provided to provide a thorough and complete disclosure of the present invention and to fully convey the scope of the present invention to those skilled in the art. The terminology used in the exemplary embodiments shown in the accompanying drawings is not intended to limit the present invention. In the accompanying drawings, identical elements are denoted by the same reference numerals.

[0053] Unless otherwise specified, the terms used herein (including technical terms) have the meanings commonly understood by those skilled in the art. In addition, it is understood that terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.

[0054] Example 1:

[0055] The present invention proposes a cryptographic service system 100 deployed in a multi-layer cloud environment, such as Figure 1 Shown, including:

[0056] The primary cryptographic service subsystem 101 is configured to obtain informationized data associated with a cryptographic service, preprocess the informationized data to obtain classified cryptographic data in a unified format, construct a classified data set based on the classified cryptographic data, classify each type of data in the classified data set based on a classifier to generate a sub-classified data set for each type of data set, determine a corresponding cryptographic service policy based on the sub-classified data set, determine the adaptability of the cryptographic service policy to the current cryptographic service requirements, select a cryptographic service policy whose adaptability meets the requirements as a target policy for the current cryptographic service, determine the importance of the target policy, divide the target policy into a primary target policy and a secondary target policy based on the importance level of the target policy, divide the cryptographic service into a primary cryptographic service and a secondary cryptographic service based on the primary target policy and the secondary target policy, execute the primary cryptographic service based on the primary target policy, and send the secondary target policy to the secondary cryptographic service subsystem, obtain the primary cryptographic service data generated after executing the primary cryptographic service, receive the secondary cryptographic service data uploaded by the secondary cryptographic service subsystem, and store the primary cryptographic service data and the secondary cryptographic service data.

[0057] The first-level cryptographic service subsystem 101 is deployed in a primary network domain in a cloud environment;

[0058] The secondary cryptographic service subsystem 102 is configured to receive the secondary target detection policy issued by the primary cryptographic service subsystem, execute the secondary cryptographic service based on the secondary target policy, obtain secondary cryptographic service data for executing the secondary cryptographic service, and upload the secondary cryptographic service data to the primary cryptographic service subsystem;

[0059] The secondary cryptographic service subsystem 102 is deployed in a second-level network domain in a cloud environment.

[0060] Among them, a connection at the interface level is established between the first-level cryptographic service subsystem 101 and the second-level cryptographic service subsystem 102.

[0061] The first-level cryptographic service subsystem 101 is also used for:

[0062] Based on the first-level cryptographic service data, the adaptability of the main target policy is calculated. If the adaptability is less than the target requirement, the main target policy is adjusted to update the main target policy. Based on the second-level cryptographic service data, the adaptability of the secondary target policy is calculated. If the adaptability is less than the target requirement, the secondary target policy is adjusted to update the secondary target policy, and the secondary target policy is sent down to the second-level cryptographic service subsystem.

[0063] The first-level cryptographic service subsystem pre-processes the information data, including:

[0064] The information data is cleaned and normalized.

[0065] The primary target strategy includes at least one of the following:

[0066] Cloud password service policy, business service policy, master password service policy, operation and maintenance policy, master key service policy and main system service policy.

[0067] The secondary target strategy includes at least one of the following:

[0068] Sub-cryptographic service policy, sub-key service policy and sub-system service policy.

[0069] Among them, the first-level cryptographic service subsystem includes at least one of the following modules: cloud cryptographic service module, business service module, master cryptographic service module, operation and maintenance module, master key service module and main system service module;

[0070] The cloud cryptographic service module is used to execute cloud cryptographic service policies;

[0071] The business service module is used to execute business service strategies;

[0072] The master password service module is used to execute the master password service policy;

[0073] The operation and maintenance module is used to execute the operation and maintenance strategy;

[0074] The master key service module is used to execute the master key service policy;

[0075] The main system service module is used to execute the main system service strategy.

[0076] Among them, the secondary cryptographic service subsystem includes at least one of the following modules: a master cryptographic service module, a master key service module and a main system service module;

[0077] The secondary password service module is used to execute the primary password service policy;

[0078] The secondary key service module is used to execute the primary key service strategy;

[0079] The secondary system service module is used to execute the primary system service strategy.

[0080] Among them, the first-level cryptographic service subsystem 101 is used to connect to multiple external cryptographic service platforms or cryptographic resource pools, and based on the cryptographic resources / services of multiple external cryptographic service platforms or cryptographic resource pools, execute the first-level cryptographic service according to the main target strategy.

[0081] Among them, the secondary cryptographic service subsystem 102 is used to connect to multiple external cryptographic service platforms or cryptographic resource pools, and based on the cryptographic resources / services of multiple external cryptographic service platforms or cryptographic resource pools, execute secondary cryptographic services according to secondary target strategies.

[0082] The functional modules of the system of the present invention are described below to illustrate the present invention:

[0083] The Level 1 Cryptography Integrated Management Service Platform (subsystem) is managed by the Level 2 Cryptography Integrated Management Service Platform (subsystem). A secure interface-level connection is established between the Level 2 and Level 1 platforms. The Level 1 Cryptography Integrated Management Service Platform issues the Level 2 platform's root key, key management policy, platform management policy, and other information to the Level 2 Cryptography Integrated Management Service Platform. The Level 2 Cryptography Integrated Management Service Platform then uploads data on business applications, operations, and maintenance services to the Level 1 Cryptography Integrated Management Service Platform, enabling the Level 1 platform to securely and effectively oversee, direct, and exchange data with the Level 2 platform.

[0084] If there are multiple network domains on the cloud, the cloud cryptography service platform, unified business service module, cryptography service management module, operation and maintenance module, key management module, and system management module are deployed in the primary network domain. Other network domains only deploy the cloud cryptography service platform, key management module, and system management module. The unified business service module, cryptography service management module, and operation and maintenance module in the primary network domain can manage the cloud cryptography service platforms in other network domains, forming a "1+N" deployment model. This means that a single set of services (unified business service, cryptography service management, and operation and maintenance) can simultaneously connect to N cloud cryptography service platforms.

[0085] Cloud cryptographic service platform: By deploying cryptographic resources such as server cryptographic machines and signature verification servers to form a cryptographic resource pool, it provides standardized independent cryptographic services and interfaces in the form of microservices to various information systems with the support of the cryptographic resource pool.

[0086] Unified business service module: This module provides unified password-related business services to cloud tenants and internal users across the entire platform. Through the unified identity authentication sub-module, it connects various systems to enable one-stop password service application, evaluation, approval, testing, activation, use, change, and termination. The unified business service module primarily provides users with password solution consulting and design service management, password transformation support service management, tenant self-service application, password service resource application management, and solution review management. The password operations team is responsible for the daily operations and business processing of the unified business service module. At the same time, the unified business service module connects to the unified key management module, the password management service module, and the operation and maintenance service module to provide a one-stop solution for user password service order applications, such as automatically generating service bills, password application warnings, and after-sales service.

[0087] Password management service module: The password management service module implements multi-cloud management for cloud password service platforms deployed in multiple network areas, including the management of multi-level password management service modules and the issuance of management policies. It provides users with one-stop password resource service management, including applying for password resources for applications and managing applied password services. The first-level password management service module manages multiple cloud password service platforms in the first-level unit network area. The first-level unit application system applies for password resources in the first-level unified business service module. After the review is passed, the password management service module will issue the order to the corresponding cloud password service platform based on the network area where it is located, and the system will provide the requested password service for the application. The second-level application system applies for password resources in the second-level unified business service platform. After the review is passed, the second-level password management service center will issue a resource allocation policy, and the corresponding cloud password service system will provide it with password services.

[0088] Operation and maintenance service module: The operation and maintenance service module includes functions such as call service hotline, intelligent customer service, work order management, information management, knowledge base management, work order quality inspection and operation and maintenance data analysis.

[0089] Key management module: responsible for providing key generation, storage, backup, update, recovery, query and other functions for the unified identity authentication service system or other cryptographic application services, and providing judicial evidence collection and other services to judicial departments. It can solve the encryption key management problems brought about by the large-scale application of cryptographic technology in distributed application environments.

[0090] Filters: When a lower-level platform sends a request for a key or policy to a higher-level platform, it must first pass through the primary platform's filters. The filters are configured with rule fields, ensuring that only requests that pass the filtering rules (such as IP address filtering or data content filtering) are passed to the corresponding functional modules. For requests that fail the filtering rules, the filters return a "reject" message. This prevents the platform from processing illegal or invalid requests and improves the response rate for compliant requests.

[0091] The Cloud Cryptography Service Platform is a core system that directly provides cryptographic services for applications. Deployed in each network area of ​​organizations at all levels, it provides cryptographic services for business applications within that area. The Cloud Cryptography Service Platform offers multi-dimensional cryptographic services based on a progressive model of cryptographic devices, cryptographic applications, cryptographic services, and cryptographic resources. It addresses differences in cryptographic devices from different vendors, provides unified management, and offers ease of use, achieving consistent management. It rationally allocates cryptographic resources and provides services based on user cryptographic resource requirements, automatically scaling cryptographic resources on demand according to policies. Management functions include device management of the cryptographic resource pool, configuration of reception and billing policies, and system configuration.

[0092] The cloud cryptographic service platform is connected to the cryptographic management service module at the same level and receives cryptographic resource order applications from the cryptographic management service module.

[0093] When each business system needs to use cryptographic services, it will issue a cryptographic service resource application request through the unified business service module. After review and approval, the cryptographic management service module will issue a resource allocation strategy. The cloud cryptographic service platform will allocate appropriate cryptographic service resources to users based on its own load conditions, parameter configuration, etc., and provide cryptographic operation services according to the strategy.

[0094] Through the cryptographic resource management service, cryptographic devices, full life cycle key management, and user application management are realized, container-based resource isolation and dynamic allocation of cryptographic resources are achieved, and more than one million massive key applications are supported.

[0095] The cryptographic resource pool consists of two parts. The first is to support the simultaneous operation of multiple virtualized cryptographic machines on a hardware platform using virtualization technology, managing these virtualized cloud cryptographic machines to reduce overall costs and improve service resource utilization. The second is to be applicable to any scenario using traditional cryptographic devices, supporting unified access and management of all types of cryptographic devices. This is particularly suitable for traditional business scenarios with numerous cryptographic devices and diverse application systems, as well as for applications running in the cloud.

[0096] The cryptographic resource pool manages the underlying resources in a unified manner, and provides cryptographic services upward through the cloud cryptographic service system, providing powerful cryptographic computing power.

[0097] Cloud Password Resource Management:

[0098] Flexible allocation of government cloud cryptographic resources. In a cloud computing environment, cloud cryptographic resources are scheduled based on cloud computing characteristics and actual business needs, enabling flexible scheduling and allocation of cloud cryptographic resources. This allows for the rational allocation of cloud cryptographic resources across different business systems. Cryptographic hardware resources are virtualized and pooled for unified management and monitoring, reducing operation and maintenance costs.

[0099] Management of various password devices:

[0100] This includes various physical cryptographic devices, such as server cryptographic machines, signature verification servers, collaborative signature servers, electronic signature servers, timestamp servers, etc. Using a cryptographic resource pool model, the management system enables remote management and configuration of various cryptographic devices, including adding, deleting, starting and stopping services, and modifying configuration information.

[0101] Unified service interface:

[0102] Supports access to various cryptographic devices. Through unified interface standards, it adapts to similar cryptographic devices from different manufacturers, integrating interface differences between different manufacturers' devices to achieve unified access and access management for cryptographic devices. Centralized management of cryptographic devices, establishing a unified set of policies, application processes, and enforcement mechanisms, streamlines password usage.

[0103] Reuse of old cryptographic equipment:

[0104] If some cryptographic devices already exist on the cloud and cannot be replaced by the cryptographic resources of the cloud cryptographic service platform, the original cryptographic devices can be accepted and managed, and the original cryptographic devices can be included in the cryptographic resource pool for unified management, achieving a smooth transition in performance and function improvements, and integrating their cryptographic functions into a unified cryptographic service.

[0105] Flexible modular configuration:

[0106] Adopting a flexibly configurable hierarchical and modular design, it allows for flexible service configuration based on the specific requirements of the application system. It flexibly allocates required password resources based on business needs and supports application authentication and access policy configuration.

[0107] Password Services:

[0108] Encryption and decryption services:

[0109] Leveraging a cryptographic resource pool and key management infrastructure, combined with data encryption and decryption services, we provide business-specific encryption and decryption services, such as sensitive text encryption, for organizations and individuals renting cryptographic keys. Designed and implemented in accordance with the National Cryptography SM2, SM3, and SM4 algorithms and in compliance with technical specifications such as the "GM / T 0018-2012 Cryptographic Device Application Interface Specification," we offer symmetric and asymmetric encryption and decryption, P1 signature verification, message digests, MAC, and HMAC operations.

[0110] Signature Verification Service:

[0111] Provides digital signature services for users based on cryptographic resources. Designed and implemented in compliance with technical specifications such as the "GM / T_0020-2012 Certificate Application Integrated Service Interface Specification," it offers computational services such as P1 signature verification, P7 signature verification, and digital envelope encryption and decryption. Supporting cryptographic algorithms such as SM2, SM3, and SM4, it provides security protection for various information systems, including digital signatures and verification, digital certificate-based identity authentication, and digital certificate-based encryption and decryption, ensuring the authenticity, integrity, and non-repudiation of critical business information.

[0112] Electronic Signature Service:

[0113] Provide electronic signature services for organizations and individuals based on cryptographic resources. Designed and implemented in accordance with the national cryptographic SM2, SM3, and SM4 algorithms and in compliance with technical specifications such as the "GM / T 0031-2014 Technical Specification for Secure Electronic Signatures," this service offers services such as seal creation, stamping, multi-page stamping, interleaved stamping, and seal verification, enabling electronic signatures for PDF and OFD documents. This transforms traditional physical seals into secure, controllable electronic anti-counterfeiting seals that verify the identity of electronic document signatories, ensuring the integrity, authenticity, validity, and tamper-resistance of documents.

[0114] Timestamp service:

[0115] Based on the national standard time source, in accordance with the national secret SM2, SM3, and SM4 algorithms, and in compliance with technical specifications such as the "GM / T0033-2014 Timestamp Interface Specification", it is designed and implemented to provide accurate, secure, and reliable timestamp generation, verification, and timestamp parsing services for organizations / individuals.

[0116] Collaborative Signature Service:

[0117] Designed and implemented in accordance with the national secret SM2, SM3, and SM4 algorithms, and in compliance with technical specifications such as "GM / T 0003-2012SM2 Elliptic Curve Public Key Cryptography Algorithm," this system provides unified management of user keys and certificates, collaborative signatures, and other services for organizations and individuals. Key splitting technology ensures mobile key security.

[0118] Database transparent encryption service:

[0119] The database transparent encryption service implements encrypted storage of sensitive data, ensuring that sensitive data is not leaked when the physical disk is stolen. The data encryption and decryption process is transparent and imperceptible, without affecting actual business and meeting compliance requirements.

[0120] It provides data storage encryption, encrypting various commonly used data types in the database. The encrypted data is stored in ciphertext on disk, preventing sensitive data leakage caused by physical intrusion. It supports encryption of mainstream databases such as MYSQL, Oracle, MariaDB, PostgreSQL, and SQLServer, as well as domestic databases such as DAMO and Jincang. It supports encryption and decryption of non-relational databases such as MongoDB and Redis. It supports TDE table-level transparent encryption and decryption. It supports multi-granularity encryption of tables and columns, and encryption of data types such as CHAR, VARCHAR2, VARCHAR, BLOB, TXT, and DATETIME. It supports format-preserving encryption of data based on national secret algorithms. It is compatible with the SM series national secret algorithms and international standard algorithms such as DES, 3DES, and AES. It provides data desensitization capabilities and transparent support capabilities, allowing users to transparently access business data without modifying the architecture, logic, or code level of their business programs. It automatically encrypts and decrypts authorized applications, and the encryption and decryption process is transparent and imperceptible. The platform provides a data integrity verification mechanism to verify modifications to sensitive field data. It supports the control of starting and stopping the encryption and decryption process, and also supports automatically stopping or starting unfinished encryption machine processes based on the detected server status and other information, ensuring smooth encryption and decryption without affecting business performance.

[0121] Digital certificate authentication service:

[0122] It complies with standards such as the "Certificate Authentication System Cryptography and Related Security Technical Specifications" promulgated by the National Cryptography Administration, supports cryptographic algorithms such as SM2, SM3, and SM4, and can be used for digital certificate application, review, issuance, cancellation, renewal, query and other services. It provides certificate status management throughout its life cycle, including certificate issuance, user registration management, certificate / CRL publishing, and online certificate status query.

[0123] Password device management:

[0124] It mainly includes cloud server cryptographic machines / server cryptographic machines, signature verification servers, collaborative signature servers, electronic signature servers, timestamp servers, etc. The cryptographic resource pool model is adopted to achieve unified device management and resource scheduling of various cryptographic resources through the management system.

[0125] Resource management scheduling:

[0126] The platform supports unified scheduling and allocation of various cryptographic resources, allowing for flexible configuration based on the needs of individual system applications, ensuring a one-to-one mapping between user applications and cryptographic resources. This ensures that each application can only access its assigned cryptographic device resources. The platform can also dynamically scale cryptographic resources based on the operational pressure of cryptographic service requests, allowing for flexible configuration of multiple scaling strategies.

[0127] Unified access management:

[0128] Supports access and management of various cryptographic devices. Through unified interface standards, it adapts to the same type of cryptographic devices from different manufacturers, integrates interface differences between cryptographic devices from different manufacturers, and achieves unified access and access management of cryptographic devices.

[0129] Equipment operation management:

[0130] Realize remote management and configuration of various cryptographic devices such as adding, deleting, starting and stopping services, and modifying configuration information.

[0131] Reuse old cryptographic equipment to achieve savings:

[0132] If some cryptographic devices already exist in the platform and cannot be replaced by the cryptographic resources of the cloud cryptographic service platform, the original cryptographic devices can be managed and their cryptographic functions can be integrated into a unified cryptographic service.

[0133] Password Resource Order Processing:

[0134] Receive orders from the password management service module, allocate password device resources and key resources for service orders, and automatically / manually feed back the resource allocation results to the password management service module to ensure normal receipt and feedback of service orders.

[0135] Application Management:

[0136] Application management primarily manages the business application systems included in a password service order. Before using password services, application systems must complete the entry of application information into the unified business service module or the password management service module and configure application authentication policies. Application management aims to assist users in system business planning and establishes the platform's password service relationship with applications based on actual application needs.

[0137] When an application system connects to a cryptographic service, it is necessary to authenticate and determine the permissions of the application, precisely control the cryptographic resources that the application can access, and achieve secure isolation of cryptographic resources.

[0138] Unified business service module:

[0139] The unified business service module is a unified platform that provides comprehensive business services to cloud tenants and internal users. Cloud tenants connect various systems through a unified identity authentication service, enabling one-stop cryptographic service application, evaluation, approval, testing, activation, use, change, and termination. The cryptographic business service submodule primarily provides users with cryptographic solution consulting and design service management, cryptographic transformation support service management, tenant self-service application, cryptographic service resource application management, and solution review management. The cryptographic operations team is responsible for the daily operations and business processing of the unified business service platform. The unified business service module also connects to the key management module, the cryptographic management service module, and the operation and maintenance service module, providing a one-stop solution for daily user cryptographic service order applications, such as automated service bill generation, cryptographic application warnings, and after-sales service.

[0140] Users are provided with a unified service application portal. Based on their actual needs, they can select the corresponding service requirements on demand. The system automatically distributes the service process to relevant business systems based on the user's service application requirements and pre-configured process nodes. Throughout the entire process, depending on the actual service ticket type, they can selectively undergo approval, processing, and feedback from relevant departments, ultimately forming a closed-loop service management system. Each node can be set with a processing time limit for different service types, and the system automatically and effectively issues reminders if the time limit is exceeded. This improves the timeliness of service processing. The platform also tracks the approval, processing, and service quality of all service nodes throughout the entire process.

[0141] Unified service process management:

[0142] Based on actual business needs and characteristics, you can customize various service application types, centrally manage application service types, and configure different approval nodes, execution nodes, support nodes, and other processes for related service types. You can also configure work order reminders to ensure the timeliness of each node.

[0143] Unified identity authentication service:

[0144] Unified user management:

[0145] The unified identity authentication service provides unified account management for all systems connected to the password integrated management service platform, supporting functions such as account freezing, recovery, and archiving to achieve secure management of the lifecycle.

[0146] Application control and management:

[0147] The unified identity authentication service supports centralized management and control of existing business systems, and intuitively displays business application information under various categories to users;

[0148] Unified authorization management:

[0149] The unified identity authentication service provides portal-level authorization through permission control granularity, and can achieve rapid batch authorization through role and organizational attributes;

[0150] Unified authentication management:

[0151] The unified identity authentication service supports single sign-on between different applications and supports high-security authentication methods such as biometrics and digital certificates;

[0152] Cryptographic business services:

[0153] Cryptographic solution consulting and design management:

[0154] If a cloud tenant needs to conduct a cryptographic application security assessment on its business system, it is necessary to first design a cryptographic application solution for the business system according to the cryptographic assessment process. Users can initiate a work order through the cryptographic business service module to apply for solution consultation and solution design services. The module then accepts the work order application online and distributes the work order to the cryptographic application support team. After receiving the order, the cryptographic application support team will conduct research and assessment on the current status of the user's business system, and provide the user with preliminary cryptographic application or transformation solution recommendations. They can also formulate cryptographic application solutions, implementation plans, key management systems and security management strategies according to the GB / T 39786 standard based on user needs, to ensure that the password transformation of the user's business system meets the cryptographic assessment standards, tailor the optimal solution to the user's actual situation, and ultimately assist the user in organizing and passing the cryptographic application solution review.

[0155] Password transformation support service management:

[0156] The cryptographic business service module can provide users with full-process cryptographic transformation support services, including the formulation of cryptographic implementation plans, the formulation of key management systems, cryptographic transformation implementation and testing support, technical consulting services during the implementation process, gap analysis, system prediction and evaluation, system secret evaluation support, and assistance in obtaining secret evaluation reports. After completing the preparation of cryptographic application plans and implementation plans through research and design during the consultation phase, tenants submit cryptographic support service work orders in the cryptographic transformation support service sub-module based on the progress of the business, such as implementation plan preparation, cryptographic transformation implementation consulting, gap analysis, prediction and evaluation analysis, system secret evaluation support, etc. The platform assigns tasks based on the work orders to advance the project implementation process. At each stage, we will arrange the corresponding cryptographic technology team to provide technical support services in accordance with the secret evaluation standards throughout the implementation process of the password transformation, ensuring that the user's password transformation project is carried out according to the process and assisting users in successfully passing the secret evaluation.

[0157] Cryptographic service resource application management:

[0158] Tenants apply for password service resources from the platform through the password service resource application function. The specific process is as follows:

[0159] The responsible unit of the business system submits an application for the use of cloud cryptographic resources through the unified business service module.

[0160] Upon receiving the application, the cryptography application operations team will assess whether the Cloud Cryptography Service Platform resources meet the resource requirements requested by the project responsible unit. If so, the application is submitted to the management department for review of the business system cryptography scenario application to determine whether the requested cryptography service resources meet the business system requirements. If not, the Integrated Business Service Platform will notify the tenant of insufficient cryptography resource requests. If the requested resources exceed actual requirements, the actual required resources will be provided, and the responsible unit will be notified to resubmit the cryptography resource application. If the cryptography service resources meet the business requirements, the tenant will be allocated Cloud Cryptography Service Platform resources.

[0161] Tenant self-service password management:

[0162] Service Order Management:

[0163] Tenants can apply for multiple cryptographic services in one place, based on their specific cryptographic service needs. Based on their specific cryptographic service needs, they can apply for corresponding cryptographic device resources / key resources, configure different fee policies, and submit a service order. This order then awaits administrator review, allowing tenants to check progress and status at any time. Once approved, the order is issued as a service ticket to the password management service module, providing the corresponding cryptographic services.

[0164] Self-service application for sandbox service:

[0165] The sandbox environment provides tenants with an auxiliary environment for developing cryptographic service interface functions and debugging key functions, allowing for pre-launch debugging and functional verification. Tenants can apply for the sandbox environment's cryptographic interface services based on their needs, pending administrator review. Upon approval, a sandbox environment will be allocated to the Password Management Service Center via a service ticket, allowing tenants to quickly conduct development, integration, debugging, and pre-launch verification.

[0166] Service Billing Management:

[0167] Tenants can query the password resource usage statement and view the detailed password resource usage records on their own every month, so as to understand the password application status in a timely and dynamic manner, assist tenants in providing decision-making basis for the next step of password services and ensure password security.

[0168] Tenant self-service application management:

[0169] Tenants can build their own applications on the unified business service platform and manage their maintenance and access. Applications can apply for a variety of cryptographic services, such as encryption and decryption, signature verification, electronic signature, and timestamp services.

[0170] Password application management:

[0171] Tenants can view all cryptographic services of each application, such as encryption and decryption services, signature verification services, and timestamp services, and view key details. They can also view necessary verification information for actual client connection.

[0172] After-sales service:

[0173] Tenants can conveniently connect to the product in various ways according to the provided developer guide, FAQ, SDK client, or Restful API connection package. If any problems occur with the product, they can apply for after-sales service online and check the service progress.

[0174] Tenant application management:

[0175] Application management primarily involves viewing and managing the various business application systems within the unified business service module. Before using password services, application systems must complete the entry of application information into the unified business service module or the password management service module. Key functions include adding, modifying, deleting, enabling, disabling, and accessing applications. Obtain application information.

[0176] Cryptographic Scheme Review Management:

[0177] If the responsible unit of the business system has organized and designed a complete cryptographic application plan, it can apply for a cryptographic plan review service through the unified business service platform. The plan review process is as follows:

[0178] The responsible unit shall apply for scheme review through the unified business service module, submit the "Cryptographic Application Scheme Review Application Form", and attach technical specifications and functional parameters of the business information system's related network, communication, data, etc.

[0179] After the platform accepts the application, it organizes the cryptographic application support team to conduct a preliminary review of the plan. The cryptographic application support team conducts a scenario application assessment of the business system in accordance with the GB / T39786 cryptographic application standard. If the team believes that the plan is reasonably designed, compliant, and meets the cryptographic review standards, the user will be notified that the preliminary review has passed and an expert can be organized for a formal review.

[0180] The cryptographic application support team organizes and assists in organizing the review of the cryptographic application plan, and randomly selects 3 experts from the cryptographic expert database to participate in the review of the cryptographic application plan.

[0181] After the review is passed, the experts will issue a "Cryptography Application Plan Review Conclusion" and submit the review conclusion to the Cryptography Bureau for review. After the Cryptography Bureau issues a receipt of the plan review, it will submit the receipt and the plan review results to the relevant management department to apply for project establishment.

[0182] Password operation and maintenance service management:

[0183] Users can submit operation and maintenance service applications through the unified business module and select the corresponding work order type. After the service application is reviewed and approved, the system platform will dispatch it to the operation and maintenance service module for relevant operation and maintenance service support, and automatically generate an operation and maintenance service application form. The entire operation and maintenance service process is supported by the cryptographic service operation and maintenance team, including remote support, online support, on-site support and other service methods. At the same time, it includes multiple support teams including R&D and demand personnel of related products for comprehensive circulation, and the timeliness warning, supervision and management of the operation and maintenance process form a closed-loop management.

[0184] Example 2:

[0185] The present invention also proposes a cryptographic service method for multi-layer deployment in a cloud environment, such as Figure 2 Shown, including:

[0186] Step 1: Obtain information data associated with the cryptographic service, pre-process the information data to obtain classified cryptographic data in a unified format, construct a classified data set based on the classified cryptographic data, and classify each type of data in the classified data set based on a classifier to generate a sub-classified data set for each type of data set;

[0187] Step 2: Determine the corresponding cryptographic service policy based on the sub-classification data set, determine the adaptability of the cryptographic service policy to the current cryptographic service requirement, select the cryptographic service policy whose adaptability meets the requirement as the target policy for the current cryptographic service, determine the importance of the target policy, and classify the target policy into a primary target policy and a secondary target policy according to the importance level of the target policy;

[0188] Step 3: Divide the cryptographic service into primary cryptographic service and secondary cryptographic service according to the primary target policy and the secondary target policy, execute the primary cryptographic service based on the primary target policy, and execute the secondary cryptographic service based on the secondary target policy.

[0189] The password service method further includes:

[0190] Obtain the first-level cryptographic service data for executing the first-level cryptographic service, and obtain the second-level cryptographic service data for executing the second-level cryptographic service. Based on the first-level cryptographic service data, calculate the fitness of the main target policy. If the fitness is less than the target requirement, adjust the main target policy to update the main target policy. Based on the second-level cryptographic service data, calculate the fitness of the secondary target policy. If the fitness is less than the target requirement, adjust the secondary target policy to update the secondary target policy, and send the secondary target policy to the second-level cryptographic service subsystem.

[0191] The pre-processing of the information data includes:

[0192] The information data is cleaned and normalized.

[0193] The primary target strategy includes at least one of the following:

[0194] Cloud password service policy, business service policy, master password service policy, operation and maintenance policy, master key service policy and main system service policy.

[0195] The secondary target strategy includes at least one of the following:

[0196] Sub-cryptographic service policy, sub-key service policy and sub-system service policy.

[0197] Among them, the cryptographic service method also includes: connecting to multiple external cryptographic service platforms or cryptographic resource pools, and executing first-level cryptographic services according to the main target strategy based on the cryptographic resources / services of the multiple external cryptographic service platforms or cryptographic resource pools.

[0198] Among them, the cryptographic service method also includes: connecting to multiple external cryptographic service platforms or cryptographic resource pools, and executing secondary cryptographic services according to secondary target strategies based on the cryptographic resources / services of the multiple external cryptographic service platforms or cryptographic resource pools retrieved.

[0199] The present invention can integrate cryptographic services to provide a comprehensive system platform, thereby improving the efficiency of using and managing cryptographic services.

[0200] Example 3:

[0201] Based on the same inventive concept, the present invention also provides a computer device, which includes a processor and a memory, wherein the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method flow or corresponding function, so as to implement the steps of the method in the above embodiment.

[0202] Example 4:

[0203] Based on the same inventive concept, the present invention also provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device for storing programs and data. It can be understood that the computer-readable storage medium here can include both built-in storage media in the computer device and, of course, extended storage media supported by the computer device. The computer-readable storage medium provides a storage space that stores the operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space. These instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the steps of the method in the above embodiment.

[0204] It will be understood by those skilled in the art that the embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present invention may be implemented in various computer languages, for example, the object-oriented programming language Java and the interpreted scripting language JavaScript.

[0205] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0206] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0207] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0208] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0209] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A multi-layer deployed cryptographic service system in a cloud environment, characterized in that: The password service system includes: A primary cryptographic service subsystem is configured to obtain informationized data associated with a cryptographic service, preprocess the informationized data to obtain classified cryptographic data in a unified format, construct a classified data set based on the classified cryptographic data, classify each type of data in the classified data set based on a classifier to generate a sub-classified data set for each type of data set, determine a corresponding cryptographic service policy based on the sub-classified data set, determine the adaptability of the cryptographic service policy to current cryptographic service requirements, select a cryptographic service policy whose adaptability meets the requirements as a target policy for the current cryptographic service, determine the importance of the target policy, divide the target policy into a primary target policy and a secondary target policy based on the importance level of the target policy, divide the cryptographic service into a primary cryptographic service and a secondary cryptographic service based on the primary target policy and the secondary target policy, execute the primary cryptographic service based on the primary target policy, and send the secondary target policy to the secondary cryptographic service subsystem, obtain the primary cryptographic service data generated after executing the primary cryptographic service, receive the secondary cryptographic service data uploaded by the secondary cryptographic service subsystem, and store the primary cryptographic service data and the secondary cryptographic service data; The first-level cryptographic service subsystem is deployed in a primary network domain in a cloud environment; The secondary cryptographic service subsystem is configured to receive the secondary target policy issued by the primary cryptographic service subsystem, execute the secondary cryptographic service based on the secondary target policy, obtain secondary cryptographic service data for executing the secondary cryptographic service, and upload the secondary cryptographic service data to the primary cryptographic service subsystem; The secondary cryptographic service subsystem is deployed in a second-level network domain in a cloud environment.

2. The cryptographic service system according to claim 1, wherein: An interface-level connection is established between the first-level cryptographic service subsystem and the second-level cryptographic service subsystem.

3. The cryptographic service system according to claim 1, wherein: The first-level cryptographic service subsystem is further used to: Based on the first-level cryptographic service data, the fitness of the main target policy is calculated. If the fitness is less than the target requirement, the main target policy is adjusted to update the main target policy. Based on the second-level cryptographic service data, the fitness of the secondary target policy is calculated. If the fitness is less than the target requirement, the secondary target policy is adjusted to update the secondary target policy, and the secondary target policy is sent to the second-level cryptographic service subsystem.

4. The cryptographic service system according to claim 1, wherein: The first-level cryptographic service subsystem pre-processes the information data, including: The information data is cleaned and normalized.

5. The cryptographic service system according to claim 1, wherein: The primary target strategy includes at least one of the following: Cloud password service policy, business service policy, master password service policy, operation and maintenance policy, master key service policy and main system service policy.

6. The cryptographic service system according to claim 1, wherein: The secondary target strategy includes at least one of the following: Sub-cryptographic service policy, sub-key service policy and sub-system service policy.

7. The cryptographic service system according to claim 1, wherein: The first-level cryptographic service subsystem includes at least one of the following modules: a cloud cryptographic service module, a business service module, a master cryptographic service module, an operation and maintenance module, a master key service module, and a main system service module; The cloud cryptographic service module is used to execute cloud cryptographic service policies; The business service module is used to execute business service strategies; The master password service module is used to execute the master password service policy; The operation and maintenance module is used to execute the operation and maintenance strategy; The master key service module is used to execute the master key service policy; The main system service module is used to execute the main system service policy.

8. A cryptographic service method for multi-layer deployment in a cloud environment, characterized in that: The password service method includes: The primary cryptographic service subsystem obtains informationized data associated with the cryptographic service, preprocesses the informationized data to obtain classified cryptographic data in a unified format, constructs a classified data set based on the classified cryptographic data, classifies each type of data in the classified data set based on a classifier to generate a sub-classified data set for each type of data set, determines a corresponding cryptographic service policy based on the sub-classified data set, determines the adaptability of the cryptographic service policy to current cryptographic service requirements, selects a cryptographic service policy whose adaptability meets the requirements as a target policy for the current cryptographic service, determines an importance of the target policy, divides the target policy into a primary target policy and a secondary target policy based on the importance level of the target policy, divides the cryptographic service into a primary cryptographic service and a secondary cryptographic service based on the primary target policy and the secondary target policy, executes the primary cryptographic service based on the primary target policy, and sends the secondary target policy to the secondary cryptographic service subsystem, obtains the primary cryptographic service data generated after executing the primary cryptographic service, receives the secondary cryptographic service data uploaded by the secondary cryptographic service subsystem, and stores the primary cryptographic service data and the secondary cryptographic service data; The first-level cryptographic service subsystem is deployed in a primary network domain in a cloud environment; The secondary cryptographic service subsystem receives the secondary target policy issued by the primary cryptographic service subsystem, executes the secondary cryptographic service based on the secondary target policy, obtains secondary cryptographic service data for executing the secondary cryptographic service, and uploads the secondary cryptographic service data to the primary cryptographic service subsystem; The secondary cryptographic service subsystem is deployed in a second-level network domain in a cloud environment.

9. A computer device, characterized in that: include: one or more processors; a processor for executing one or more programs; When the one or more programs are executed by the one or more processors, the method according to claim 8 is implemented.

10. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed, the method according to claim 8 is implemented.

Citation Information

Patent Citations

  • Unified management password service support system

    CN111800267A

  • Password service dynamic monitoring system based on multi-level and multi-dimensional model

    CN113408872A