Cryptographic service method, apparatus, device, medium, and product
By setting up secure nodes in the cryptographic machine and cryptographic service platform, trust assessment and dynamic cryptographic policy generation are carried out, solving the problem of cryptographic information leakage, realizing secure data transmission and access control, and improving the security of cryptographic services and the flexibility of the system.
Patent Information
- Application Number
- CN202410722913.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-05
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2044-06-05
AI Technical Summary
Existing cryptographic service platforms pose a high security risk of password information leakage when multiple applications share a cryptographic machine resource pool, making it difficult to achieve effective access control and secure data transmission.
By setting up secure nodes in the cryptographic machine and cryptographic service platform, trust assessment and dynamic cryptographic policy generation are performed to ensure that only authorized platforms can access and manipulate cryptographic information. Secure nodes are used for data transmission to achieve one-to-one data transmission and access control.
It improves the security of the cryptographic service process, prevents the leakage of cryptographic information, ensures that only authorized platforms can access and operate cryptographic information, realizes differentiated cryptographic services, and enhances the security of data transmission and the flexibility of the system.
Smart Images

Figure CN118631512B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the network security technical field, in particular to a password service method and device, equipment, medium and product. BACKGROUND
[0002] With the continuous development and application of information technology, more and more application systems require password machines. In order to support the security requirements of many application systems on password machines and fully play the important role of password machines in guaranteeing identity authentication, confidentiality, integrity and anti-repudiation of each link of the application system, it is necessary to provide unified password machine resource pooling capabilities.
[0003] There are many password service platforms that can call password machine resource pool service capabilities to a certain extent, realize multi-application sharing of password machine resource pool, and provide security key management capabilities and password operation capabilities based on password machines for applications. When the password service platform receives a password service request sent by different applications, it needs to send the password service request to the password machine, so that the password machine responds. In this process, the password information between different applications is easy to be leaked, and there is a high security risk. SUMMARY
[0004] The password service method, device, equipment, medium and product provided by the present application can improve the security of password information in the password service process.
[0005] In a first aspect, an embodiment of the present application provides a password service method applied to a first password machine, wherein the first password machine is provided with a first security node, and the method comprises:
[0006] receiving, by the first security node, an operation request sent by a second security node of a first password service platform, wherein the operation request comprises first data to be operated and password information required for operating the first data;
[0007] obtaining a sensitive level of the first data, a request type of the operation request, at least one security node having an access right of the password information, and risk data of the second security node;
[0008] performing trust evaluation on the second security node according to the risk data to obtain a trust degree of the second security node;
[0009] generating a dynamic password strategy corresponding to the trust degree, the sensitive level and the request type;
[0010] in a case where the at least one security node comprises the second security node, operating the first data by using the password information according to the dynamic password strategy to obtain second data operated.
[0011] sending the second data to the third security node through the second security node.
[0012] In a second aspect, the embodiments of the present application provide a cryptographic service method, applied to a first cryptographic service platform, the first cryptographic service platform being provided with a second security node, and the method comprises:
[0013] receiving, by the second security node, an operation request sent by a third security node of an application, wherein the operation request comprises first data to be operated and cryptographic information required for operating the first data;
[0014] sending, by the second security node, the operation request to a first security node of a first cryptographic machine;
[0015] receiving, by the second security node, second data sent by the first security node, the second data being obtained by operating the first data by the first cryptographic machine using the cryptographic information;
[0016] sending, by the second security node, the second data to the third security node.
[0017] In a third aspect, the embodiments of the present application provide a cryptographic service device, applied to a first cryptographic machine, the first cryptographic machine being provided with a first security node, and the device comprises:
[0018] a first receiving module, configured to receive, by the first security node, an operation request sent by a second security node of a first cryptographic service platform, wherein the operation request comprises first data to be operated and cryptographic information required for operating the first data;
[0019] an obtaining module, configured to obtain a sensitive level of the first data, a request type of the operation request, and risk data of at least one security node having an access right of the cryptographic information and the second security node;
[0020] an evaluating module, configured to perform trust evaluation on the second security node according to the risk data, to obtain a trust degree of the second security node;
[0021] a generating module, configured to generate a dynamic cryptographic policy corresponding to the trust degree, the sensitive level, and the request type;
[0022] an operating module, configured to, in a case where the at least one security node comprises the second security node, perform operation on the first data using the cryptographic information according to the dynamic cryptographic policy, to obtain second data of the operation;
[0023] The first sending module is configured to send the second data to the second security node through the first security node.
[0024] In a fourth aspect, an embodiment of the present application provides a cryptographic service device, applied to a first cryptographic service platform, wherein the first cryptographic service platform is provided with a second security node, and the device comprises:
[0025] The second sending module is configured to receive an operation request sent by a third security node of an application through the second security node, wherein the operation request comprises first data to be operated and cryptographic information required for operating the first data;
[0026] The third sending module is configured to send the operation request to a first security node of the first cryptographic machine through the second security node.
[0027] The second receiving module is configured to receive second data sent by the first security node through the second security node, wherein the second data is obtained by operating the first data by the first cryptographic machine using the cryptographic information.
[0028] The fourth sending module is configured to send the second data to the third security node through the second security node.
[0029] In a fifth aspect, an embodiment of the present application provides an electronic device, comprising a processor and a memory storing computer program instructions.
[0030] The processor executes the computer program instructions to implement the cryptographic service method in any one of the embodiments of the first aspect and the second aspect.
[0031] In a sixth aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores computer program instructions, and the computer program instructions are executed by a processor to implement the cryptographic service method in any one of the embodiments of the first aspect and the second aspect.
[0032] In a seventh aspect, an embodiment of the present application provides a computer program product, wherein instructions in the computer program product are executed by a processor of an electronic device to enable the electronic device to implement the cryptographic service method in any one of the embodiments of the first aspect and the second aspect.
[0033] In the cryptographic service method, device, equipment, medium and product provided by the embodiment of the present application, the security node is arranged in the cryptographic machine and the cryptographic service platform, and the security node is used for data transmission, so that the cryptographic machine and the cryptographic service platform can realize one-to-one data transmission. The sensitive level of the first data, the request type of the operation request, and the risk data of at least one security node and the second security node having the access authority of the cryptographic information are obtained, and the dynamic cryptographic policy corresponding to the trust degree of the second security node, the sensitive level and the request type is generated, so that the differential cryptographic service of the first data can be realized, and the security of the first data is improved. The access authority corresponding to the second security node of the cryptographic service platform is obtained by the cryptographic machine, and only when the second security node has the access authority of the cryptographic information stored in the cryptographic machine, the cryptographic information is used to execute the operation required by the cryptographic service platform, so that the access control of the cryptographic service platform to the cryptographic information in the cryptographic machine is realized, the problem that the cryptographic information in the cryptographic machine is obtained by the platform without the access authority is prevented, the cryptographic information is prevented from being leaked, it is ensured that only the authorized cryptographic service platform can access and operate the cryptographic information, and the security in the cryptographic service process is improved. BRIEF DESCRIPTION OF DRAWINGS
[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced. Other drawings can also be obtained by those of ordinary skill in the art without creative labor on the premise that they do not conflict with these drawings.
[0035] Figure 1 is an interaction flow diagram of a cryptographic service method provided by an embodiment of the present application;
[0036] Figure 2 is a structural schematic diagram of a cryptographic service device applied to a first cryptographic machine provided by an embodiment of the present application;
[0037] Figure 3 is a structural schematic diagram of a cryptographic service device applied to a first cryptographic service platform provided by an embodiment of the present application;
[0038] Figure 4 is a structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0039] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced. Other drawings can also be obtained by those of ordinary skill in the art without creative labor on the premise that they do not conflict with these drawings.
[0040] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. However, the present disclosure can be practiced without the specific details. In other instances, well-known methods, procedures, components, and circuits have not been described in detail since not to unnecessarily obscure aspects of the present disclosure.
[0041] It should be noted that, in this document, relational terms such as "first" and "second", and the like, are used solely to distinguish one entity or action from another entity or action, without necessarily requiring or implying any actual such relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", "includes", "including", or any other variation thereof, are intended to cover a non-exclusive inclusion such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises a", "comprising", "includes", "including", or "has", does not, without more constraints, preclude the existence of additional identical elements in the process, method, article, or apparatus that comprises, includes, or has that element.
[0042] It should be noted that the acquisition, storage, use and processing of data in the embodiments of the present application comply with the relevant provisions of national laws and regulations.
[0043] It should be noted that in the embodiments of the present application, some existing industry solutions may be mentioned, such as software, components, models, etc., which should be considered as exemplary, and the purpose is only to illustrate the feasibility of the implementation of the technical solutions of the present application, but it does not mean that the applicant has or will necessarily use the solution.
[0044] To solve the problems in the prior art, the embodiments of the present application provide a password service method, device, equipment, medium and product. First, the password service method provided by the embodiments of the present application is introduced.
[0045] Figure 1 The flowchart of the password service method provided by an embodiment of the present application is shown. As shown in Figure 1 The method can specifically include the following steps:
[0046] Step 101, the password service platform receives the operation request sent by the third security node of the application through the second security node;
[0047] Step 102, the password service platform sends the operation request to the first security node of the first cryptographic machine through the second security node;
[0048] In step 103, the first cryptographic machine receives an operation request sent by the second security node of the first cryptographic service platform through the first security node, wherein the operation request includes first data to be operated and cryptographic information required for operation of the first data;
[0049] The application scenario of the present application can be a cryptographic service scenario between an application, a cryptographic service platform and a cryptographic machine. For example, when the application needs cryptographic service, an operation request corresponding to the cryptographic service is sent to the cryptographic service platform, and the cryptographic service platform sends the operation request to the cryptographic machine, so that the cryptographic machine responds to the operation request to complete the cryptographic service. The cryptographic service platform is deployed with applications, and provides a running environment for the applications. The number of applications can be multiple.
[0050] The cryptographic service scenario described above can be a data encryption and decryption scenario, a signature authentication scenario and an identity authentication scenario, etc. Correspondingly, the operation request described above can include an encryption request, a decryption request, a signature verification request and an identity authentication request, etc. The corresponding first data can be to-be-encrypted data, to-be-decrypted data and to-be-verified data, etc. The cryptographic information can include a key for data encryption and decryption and a function instruction for controlling the cryptographic machine to perform a specific cryptographic operation. The function instruction can include a data encryption and decryption instruction, a signature verification instruction and the like.
[0051] In step 104, the first cryptographic machine obtains a sensitive level of the first data, a request type of the operation request, at least one security node having an access right of the cryptographic information and risk data of the second security node.
[0052] The cryptographic machine stores the cryptographic information and the security nodes having the access right of the cryptographic information. Each cryptographic information is provided with a corresponding access control right. Only when the security node has the access control right corresponding to the cryptographic information, the security node can call the cryptographic information to perform the cryptographic service operation. It should be noted that the above-mentioned corresponding relationship can be stored by setting a mapping table between the access right and the security node in the cryptographic machine. The risk data can be a request source, a request type, a sensitive level of operation data and the like of the operation request sent by the second security node.
[0053] The sensitive level described above can represent the importance of the first data. The higher the sensitive level, the higher the importance. The request type can include encryption, decryption or identity verification and the like.
[0054] In step 105, the first cryptographic machine performs trust evaluation on the second security node according to the risk data to obtain a trust degree of the second security node.
[0055] In the embodiment, the collected data can be input into a risk assessment model to calculate the trust degree of the operation request. The trust degree of the second security node is assessed based on multiple dimensions such as request source, request type, and sensitive level of operation data. When the trust degree is lower than a certain threshold, additional security measures such as limiting access rights and enhancing data encryption level can be taken when generating a dynamic password policy.
[0056] In step 106, the first password machine generates a dynamic password policy corresponding to the trust degree, the sensitive level, and the request type.
[0057] In the embodiment, the dynamic password encryption policy can include operation mode, combination mode, type, and length of the key corresponding to the sensitive level and the request type. Different dynamic password policies can be formulated for different sensitive levels and request types, thereby realizing differentiated password services for different first data.
[0058] In step 107, the first password machine performs the operation on the first data using the password information according to the dynamic password policy when the at least one security node includes the second security node.
[0059] When the at least one security node includes the second security node, it indicates that the second security node has access to the password information, and the corresponding data operation can be directly performed using the password information. For example, when the operation request is an encryption request, the first data is the data to be encrypted, and the corresponding password information can be an encryption instruction for calling the password machine to perform the encryption operation and a key used for encryption. Or when the operation request is a decryption request, the first data is the data to be decrypted, and the corresponding password information can be a decryption instruction for calling the password machine to perform the decryption operation and a key needed for decryption. The second data obtained by operating the first data is, for example, encrypted data or decrypted data.
[0060] In an embodiment, the operation on the first data using the password information according to the dynamic password policy to obtain the second data includes:
[0061] According to the dynamic password policy, the combination mode, key length, and key type corresponding to the operation on the first data are obtained.
[0062] According to the combination mode, key length, and key type, the key is modified to obtain a target key.
[0063] The target key is used to perform the operation corresponding to the operation instruction on the first data to obtain the second data.
[0064] In the embodiment, the password information includes a key and an operation instruction. Since the dynamic password policy includes the combination mode, the key length and the key type of the key corresponding to the first data and the request type, when the operation is performed on the first data, the key in the password machine can be reformed according to the combination mode, the key length and the key type in the dynamic password policy, so as to obtain the reformed target key. And the operation instruction in the password information is called to perform the operation corresponding to the request type, so as to obtain the second data. The operation can be an encryption operation, a decryption operation and the like.
[0065] In the embodiment, the dynamic password policy is used to perform the operation corresponding to the first data, so as to realize the differentiated password service for the first data, ensure that the first data with different sensitive levels is operated by different dynamic password policies, and improve the security of the first data.
[0066] In step 108, the first password machine sends the second data to the second security node through the first security node.
[0067] In step 109, the password service platform receives the second data sent by the first security node through the second security node.
[0068] In step 110, the password service platform sends the second data to the third security node through the second security node.
[0069] After the first password machine completes the operation corresponding to the operation request, the obtained second data needs to be returned to the application which initiates the request. Specifically, the transmission of the second data can be performed through the first security node arranged in the first password service platform, the first security node arranged in the first password machine and the third security node arranged in the application. A secure channel can be constructed among the three nodes, so as to complete the security of the data transmission among the three nodes.
[0070] In the embodiment, the security nodes are arranged in the password machine and the password service platform, and the security nodes are used for data transmission, so as to ensure that the password machine and the password service platform can realize one-to-one data transmission. The access permission corresponding to the second security node of the password service platform is obtained through the password machine. Only when the second security node has the access permission to the password information stored in the password machine, the password information is used to perform the operation required by the password service platform, so as to realize the access control of the password service platform to the encrypted information in the password machine, prevent the problem that the password information in the password machine is obtained by the platform without the access permission, prevent the password information from being leaked, ensure that only the authorized password service platform can access and operate the password information, and improve the security in the password service process.
[0071] In an embodiment of the present application, the operating the first data according to the dynamic password policy and using the password information to obtain second data after the operation comprises:
[0072] In the case that the first digital certificate and the second digital certificate are verified successfully, the first data is operated according to the dynamic password policy and using the password information to obtain second data after the operation.
[0073] In the embodiment, the first security node is bound with a first digital certificate, and the second security node is bound with a second digital certificate, wherein the first digital certificate is carried in the operation request; and a security channel is established between the first security node and the second security node, wherein the operation request and the second data are transmitted through the security channel.
[0074] It should be noted that the security channel between the first security node and the second security node is established by verifying the second digital certificate sent by the second security node. Specifically, after the first security node receives the second digital certificate, it can verify whether the second digital certificate is authentic by checking whether the certificate authority is authentic, whether the certificate is expired, and whether the public key in the certificate matches the information in the certificate. Similarly, the second security node also verifies whether the first digital certificate of the first security node is authentic. After the first digital certificate and the second digital certificate are both verified, the security channel between the first security node and the second security node can be established. After the establishment of the security channel is completed, it is indicated that the first security node and the second security node can transmit data. Then, according to the combination mode, the key length, and the key type in the dynamic password policy, the key in the password machine is reformed in the mode specified by the dynamic password policy, so as to obtain the target key after the reform, and the operation instruction in the password information is called to execute the operation corresponding to the request type, so as to obtain the second data.
[0075] In the embodiment, by setting the security node in the password service platform and the first password machine respectively, and binding the digital certificate in the security node, the security of data transmission between the password service platform and the first password machine can be ensured, and data leakage can be prevented.
[0076] In an embodiment of the present application, the operating the first data according to the dynamic password policy and using the password information to obtain second data after the operation comprises:
[0077] In the case that the white list includes the address information of the first password service platform, the first data is operated according to the dynamic password policy and using the password information to obtain second data after the operation.
[0078] In the embodiment, the first cryptographic machine is provided with a white list, and the white list includes address information of the cryptographic service platform allowed to call the first cryptographic machine. The address information can be a network IP address.
[0079] When the cryptographic service platform initiates access to the first cryptographic machine, the first cryptographic machine also needs to verify the IP address of the first cryptographic service platform. In the case of successful verification, the first cryptographic service platform is allowed to access the first cryptographic machine. By setting the IP white list, only the cryptographic service platform with correct IP address is allowed to access the cryptographic machine, thereby realizing secure access of the cryptographic machine at the network access control level, preventing platforms other than the white list from accessing, avoiding malicious attacks on the cryptographic machine, and improving the security of the cryptographic service.
[0080] In another embodiment, in the process of establishing the secure channel, the network IP address of the second security node can also be added in the second digital certificate. When the first cryptographic machine verifies the second digital certificate, it can verify whether the network IP address of the second security node is in the white list. If the IP address of the second security node is in the white list, the secure channel between the first security node and the second security node is established; if not, it is not established. Thus, while establishing the secure channel, the management of network access control is realized, and the efficiency of the cryptographic service is improved.
[0081] In an embodiment of the present application, the first data is operated according to the dynamic password strategy and the password information to obtain second data of the operation, comprising:
[0082] In the case that the first cryptographic service platform is located in the first local area network, the first data is operated according to the dynamic password strategy and the password information to obtain second data of the operation.
[0083] In the embodiment, the first cryptographic machine is a cryptographic machine in the first local area network. Only when the first cryptographic service platform and the first cryptographic machine belong to the same local area network, the cryptographic service operation is performed, further realizing secure access of the cryptographic machine at the network access control level. In addition, a local area network white list can also be set in the cryptographic machine, and the first data is operated according to the password information to obtain second data in the case that the first cryptographic service platform is located in the local area network white list. By setting the local area network and the local area network white list as described above, the access of the cryptographic service platform is controlled, the network isolation of the cryptographic machine is realized, the security between the cryptographic machine and the cryptographic service platform is improved, and malicious attacks from external platforms are prevented.
[0084] In the embodiment, after the first security node receives the operation request sent by the second security node of the first cryptographic service platform, the method further comprises:
[0085] In the case that the first cryptomachine resource pool fails, the operation request is sent to a second cryptomachine in a second cryptomachine resource pool, so that the second cryptomachine responds to the operation request.
[0086] In the embodiment, the first cryptomachine is a cryptomachine in a first cryptomachine resource pool, and the first cryptomachine resource pool includes a plurality of cryptomachines, each of which has the same function. The second cryptomachine resource pool is the same as the first cryptomachine resource pool, and the first cryptomachine resource pool and the second cryptomachine resource pool can be deployed in different locations. In the case that one of the resource pools fails, the operation request can be quickly switched to a second cryptomachine in the other resource pool. The secure and stable cryptoservice is provided.
[0087] In an embodiment of the present application, the second data sent by the first security node is received by the second security node, comprising:
[0088] In the case that the first digital certificate and the second digital certificate are verified successfully, the second data sent by the first security node is received by the second security node.
[0089] In the embodiment, the second security node is bound with a second digital certificate, and the first security node is bound with a first digital certificate, wherein the first digital certificate is carried in the operation request; a secure channel is established between the first security node and the second security node, and the operation request and the second data are transmitted through the secure channel.
[0090] It should be noted that the secure channel between the first security node and the second security node is established by verifying the second digital certificate sent by the second security node. Specifically, after the first security node receives the second digital certificate, it can verify whether the second digital certificate is authentic by checking whether the certificate authority is authentic, whether the certificate is expired, and whether the public key in the certificate matches the information in the certificate. Similarly, the second security node also verifies whether the first digital certificate of the first security node is authentic. After the first digital certificate and the second digital certificate are verified, the secure channel between the first security node and the second security node is established. After the establishment of the secure channel is completed, it is indicated that the first security node and the second security node can transmit data, and then the second data sent by the first security node can be received by the second security node.
[0091] In the embodiment, by setting a security node in the cryptoservice platform and the first cryptomachine respectively, and binding a digital certificate in the security node, when the second security node receives the second data returned by the first security node, the security of data transmission between the cryptoservice platform and the first cryptomachine can be ensured, and data leakage can be prevented.
[0092] In an embodiment of the present application, after receiving the operation request sent by the third security node of the second security node, the method further comprises:
[0093] determining the first cryptographic machine from a first cryptographic machine resource pool, wherein the first cryptographic machine resource pool comprises at least two cryptographic machines produced by at least two manufacturers.
[0094] The first cryptographic machine is determined from the first cryptographic machine resource pool, specifically by the working state of the cryptographic machines in the first resource pool, and specifically, the cryptographic machine with a non-working state is determined as the first cryptographic machine. In addition, when all the cryptographic machines in the first cryptographic machine resource pool are in a working state, the cryptographic machine with the least pending tasks can be determined as the first cryptographic machine.
[0095] In the embodiment, the first cryptographic machine resource pool includes at least two cryptographic machines produced by at least two manufacturers, which means that the system does not rely on a single manufacturer or a single model of cryptographic machine. This design increases the flexibility and scalability of the system, because when the cryptographic machine of a certain manufacturer has problems or cannot meet the performance requirements, it can be easily switched to the cryptographic machine of another manufacturer, thereby avoiding dependence on a specific manufacturer. By maintaining a cryptographic machine resource pool, the system can ensure that there are enough cryptographic machine resources to handle requests during peak periods or when facing a large number of requests. This helps to improve the throughput and response time of the system, ensuring high availability of services.
[0096] Figure 2 A structural schematic diagram of a cryptographic service device applied to a first cryptographic machine is shown, and only parts related to the embodiments of the present application are shown for ease of illustration.
[0097] Referring to Figure 2 The cryptographic service device 200 can include:
[0098] The first receiving module 201 is configured to receive an operation request sent by a second security node of a first cryptographic service platform through the first security node, wherein the operation request includes first data to be operated and cryptographic information required for operating the first data;
[0099] The obtaining module 202 is configured to obtain a sensitive level of the first data, a request type of the operation request, at least one security node having an access authority of the cryptographic information, and risk data of the second security node;
[0100] The evaluation module 203 is configured to perform trust evaluation on the second security node according to the risk data, to obtain a trust degree of the second security node;
[0101] The generating module 204 is configured to generate a dynamic password policy corresponding to the trust degree, the sensitive level, and the request type.
[0102] The operating module 205 is configured to, in a case where the at least one security node includes the second security node, operate the first data according to the dynamic password policy by using the password information, to obtain second data after operation.
[0103] The first sending module 206 is configured to send the second data to the second security node through the first security node.
[0104] Optionally, the first sending module 206 is specifically configured to:
[0105] In a case where the first digital certificate and the second digital certificate are verified successfully, operate the first data according to the dynamic password policy by using the password information, to obtain second data after operation.
[0106] Optionally, the operating module 205 is specifically configured to:
[0107] In a case where the white list includes address information of the first password service platform, operate the first data according to the dynamic password policy by using the password information, to obtain second data after operation.
[0108] Optionally, the operating module 205 is specifically configured to:
[0109] In a case where the first password service platform is located in the first local area network, operate the first data according to the dynamic password policy by using the password information, to obtain second data after operation.
[0110] Optionally, the operating module 205 includes:
[0111] The first obtaining sub-module is configured to obtain a combination mode, a key length, and a key type of the key corresponding to the operation according to the dynamic password policy.
[0112] The second obtaining sub-module is configured to transform the key according to the combination mode, the key length, and the key type, to obtain a target key.
[0113] The executing sub-module is configured to execute the operation corresponding to the operation instruction on the first data by using the target key, to obtain second data.
[0114] Optionally, the password service apparatus 200 is specifically configured to:
[0115] In a case where the first cryptomachine resource pool fails, the operation request is sent to a second cryptomachine in a second cryptomachine resource pool, so that the second cryptomachine responds to the operation request.
[0116] The cryptoservice device 200 provided by the embodiments of the present application can implement the various processes implemented by the foregoing method embodiments, and thus details are not repeated here.
[0117] Figure 3 A structure diagram of a cryptoservice device applied to a first cryptoservice platform is shown, and only parts related to the embodiments of the present application are shown for ease of illustration.
[0118] With reference to Figure 3 The cryptoservice device 300 can include:
[0119] The second sending module 301 is configured to receive, through the second security node, an operation request sent by a third security node to which the application is applied, wherein the operation request includes first data to be operated and cryptograph information required for operating the first data;
[0120] The third sending module 302 is configured to send, through the second security node, the operation request to a first security node of a first cryptomachine;
[0121] The second receiving module 303 is configured to receive, through the second security node, second data sent by the first security node, wherein the second data is obtained by operating the first data by the first cryptomachine using the cryptograph information.
[0122] The fourth sending module 304 is configured to send, through the second security node, the second data to the third security node.
[0123] Optionally, the second receiving module 303 is specifically configured to:
[0124] In a case where the first digital certificate and the second digital certificate are verified successfully, the second receiving module 303 is configured to receive, through the second security node, second data sent by the first security node.
[0125] Optionally, the cryptoservice device 300 is specifically configured to:
[0126] The first cryptomachine is determined from a first cryptomachine resource pool, wherein the first cryptomachine resource pool includes at least two cryptomachines produced by at least two manufacturers.
[0127] The cryptoservice device 300 provided by the embodiments of the present application can implement the various processes implemented by the foregoing method embodiments, and thus details are not repeated here.
[0128] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional units and modules is taken as an example, and in actual application, the above functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the above described functions. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit. In addition, the specific names of each functional unit and module are only for convenient distinction, and do not limit the protection scope of the present application. The specific working process of the units and modules in the system can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.
[0129] Figure 4 A hardware structure schematic diagram of an electronic device provided by an embodiment of the present application is shown.
[0130] The device can include a processor 401 and a memory 402 storing program instructions.
[0131] The processor 401 executes the program to implement the steps in any of the above method embodiments.
[0132] For example, the program can be divided into one or more modules / units, one or more modules / units are stored in the memory 402 and executed by the processor 401 to complete the present application. One or more modules / units can be a series of program instruction segments that can complete a specific function, which is used to describe the execution process of the program in the device.
[0133] Specifically, the above processor 401 can include a central processing unit (CPU), or a specific integrated circuit (ASIC), or can be configured to implement one or more integrated circuits of the present application.
[0134] The memory 402 can include mass storage for data or instructions. As an example and not by way of limitation, the memory 402 can include a hard disk drive (HDD), a floppy disk drive, flash memory, an optical disc (e.g., a compact disc (CD) or a digital versatile disc (DVD)), a solid-state drive (SSD), a USB drive, or a combination of two or more of these. Where appropriate, the memory 402 can include removable or non-removable (or fixed) media. Where appropriate, the memory 402 can be internal or external to the integrated gateway disaster recovery appliance. In particular embodiments, the memory 402 is non-volatile, solid-state memory.
[0135] The memory can include read-only memory (ROM), random-access memory (RAM), magnetic disk storage mediums, optical storage mediums, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, in general, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software that, when executed (by one or more processors), is operable to access the data and / or instructions as described with reference to the methods according to the aspects of the present disclosure.
[0136] The processor 401 implements any of the above-described methods by reading and executing program instructions stored in the memory 402.
[0137] In one example, the electronic device further includes a communication interface 403 and a bus 410. The processor 401, the memory 402, and the communication interface 403 are connected through the bus 410 and accomplish communication therebetween.
[0138] The communication interface 403 is mainly used to realize the communication between various modules, devices, units, and / or equipment in the embodiments of the present application.
[0139] Bus 410 includes hardware, software, or both, to couple components of the online data traffic metering device to each other and to couple components to other systems. For example, but not limited to, the bus can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand (IB) interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association local (VLB) bus, or another suitable bus or a combination of two or more of these. Where suitable, bus 410 can include one or more buses. Although a particular bus is described and illustrated in this embodiment, the application contemplates any suitable bus or interconnect.
[0140] In addition, in combination with the method in the above-mentioned embodiments, the embodiments of the present application can provide a storage medium for implementation. The storage medium has program instructions stored thereon; the program instructions are executed by a processor to implement any of the methods in the above-mentioned embodiments.
[0141] The embodiments of the present application further provide a chip, which includes a processor and a communication interface, the communication interface is coupled to the processor, the processor is configured to execute programs or instructions, to implement various processes of the above-mentioned method embodiments and achieve the same technical effects. To avoid repetition, details are not described here.
[0142] It should be understood that the chip mentioned in the embodiments of the present application can also be referred to as a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
[0143] The embodiments of the present application provide a computer program product, which is stored in a storage medium, and the program product is executed by at least one processor to implement various processes of the above-mentioned method embodiments and achieve the same technical effects. To avoid repetition, details are not described here.
[0144] It should be understood that the present application is not limited to the specific configurations and processes described above and shown in the drawings. For the sake of brevity, detailed descriptions of well-known methods are omitted here. In the above-mentioned embodiments, several specific steps are described and shown as examples. However, the method processes of the present application are not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between steps, after understanding the spirit of the present application.
[0145] The functional modules shown in the structural block diagram above can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, and the like. When implemented in software, the elements of the present application are program or code segments that are used to perform the required tasks. The program or code segments can be stored in a machine-readable medium or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. The "machine-readable medium" can include any medium that can store or transfer information. Examples of the machine-readable medium include an electronic circuit, a semiconductor memory device, a ROM, a flash memory, an erasable ROM (EROM), a floppy diskette, a CD-ROM, an optical disk, a hard disk, a fiber optic medium, a radio frequency (RF) link, and the like. The code segments can be downloaded via a computer network, such as the Internet, an intranet, and the like.
[0146] It should also be noted that the example embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiments, or in an order different from the embodiments, or several steps can be performed simultaneously.
[0147] The above describes aspects of the present disclosure with reference to flowcharts and / or block diagrams of methods, apparatus (systems) and program products according to embodiments of the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams and combinations of blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus enable the implementation of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. The processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It should also be understood that each block of the block diagrams and / or flowcharts and combinations of blocks in the block diagrams and / or flowcharts can also be implemented by special-purpose hardware to perform the specified functions or acts, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0148] The above is only a specific embodiment of the present application, and those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described system, module and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here. It should be understood that the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be covered within the protection scope of the present application.
Claims
1. A cryptographic service method characterized by, The application is applied to a first cryptographic machine provided with a first security node, and the method comprises: receiving, by the first security node, an operation request sent by a second security node of a first cryptographic service platform, wherein the operation request comprises first data to be operated and cryptographic information required for operating the first data; obtaining a sensitive level of the first data, a request type of the operation request, at least one security node having an access right of the cryptographic information, and risk data of the second security node; performing trust evaluation on the second security node according to the risk data to obtain a trust degree of the second security node; generating a dynamic cryptographic policy corresponding to the trust degree, the sensitive level, and the request type; in a case where the at least one security node comprises the second security node, operating the first data by using the cryptographic information according to the dynamic cryptographic policy to obtain second data after operation; sending, by the first security node, the second data to the second security node.
2. The password service method of claim 1, wherein, The first security node is bound with a first digital certificate, and the second security node is bound with a second digital certificate, wherein the first digital certificate is carried in the operation request; a secure channel is established between the first security node and the second security node, wherein the operation request and the second data are transmitted through the secure channel; the operating the first data by using the cryptographic information according to the dynamic cryptographic policy to obtain second data after operation comprises: in a case where the first digital certificate and the second digital certificate are verified successfully, operating the first data by using the cryptographic information according to the dynamic cryptographic policy to obtain second data after operation.
3. The password service method of claim 1, wherein, The first cryptographic machine is provided with a white list, and the white list comprises address information of a cryptographic service platform allowed to call the first cryptographic machine; the operating the first data by using the cryptographic information according to the dynamic cryptographic policy to obtain second data after operation comprises: in a case where the white list comprises the address information of the first cryptographic service platform, operating the first data by using the cryptographic information according to the dynamic cryptographic policy to obtain second data after operation.
4. The password service method of claim 1, wherein, The first cryptographic machine is a cryptographic machine in a first local area network; the operating the first data by using the cryptographic information according to the dynamic cryptographic policy to obtain second data after operation comprises: in a case where the first cryptographic service platform is located in the first local area network, operating the first data by using the cryptographic information according to the dynamic cryptographic policy to obtain second data after operation.
5. The password service method according to any one of claims 1 to 4, wherein, The cryptographic information comprises a key and an operation instruction; the operating the first data by using the cryptographic information according to the dynamic cryptographic policy to obtain second data after operation comprises: obtaining, according to the dynamic cryptographic policy, a combination mode, a key length, and a key type of the key corresponding to operation; reforming the key according to the combination mode, the key length, and the key type to obtain a target key; Perform an operation corresponding to the operation instruction on the first data by using the target key to obtain second data.
6. The password service method of claim 1, wherein, The first cryptographic machine is a cryptographic machine in a first cryptographic machine resource pool, and the first cryptographic machine resource pool includes a plurality of cryptographic machines. After receiving the operation request sent by the second security node of the first cryptographic service platform through the first security node, the method further includes: In the case where the first cryptographic machine resource pool fails, the operation request is sent to a second cryptographic machine in a second cryptographic machine resource pool, so that the second cryptographic machine responds to the operation request.
7. A cryptographic service method characterized by, The method is applied to a first cryptographic service platform, and the first cryptographic service platform is provided with a second security node, and the method includes: Receiving, by the second security node, an operation request sent by a third security node of an application, wherein the operation request includes first data to be operated and cryptographic information required for operating the first data; Sending, by the second security node, the operation request to a first security node of a first cryptographic machine; Receiving, by the second security node, second data sent by the first security node, wherein the second data is obtained by operating the first data by the first cryptographic machine according to a dynamic cryptographic policy in the case where at least one security node having access authority of the cryptographic information includes the second security node, the dynamic cryptographic policy corresponds to a trust degree of the second security node, a sensitive level of the first data, and a request type of the operation request, and the trust degree is obtained by the first cryptographic machine by performing trust evaluation on the second security node according to risk data of the second security node; Sending, by the second security node, the second data to the third security node.
8. The password service method according to claim 7, wherein, The second security node is bound with a second digital certificate, and the first security node is bound with a first digital certificate, wherein the first digital certificate is carried in the operation request; A secure channel is established between the first security node and the second security node, wherein the operation request and the second data are transmitted through the secure channel; The second data sent by the first security node is received by the second security node in the case where the first digital certificate and the second digital certificate are verified successfully. After receiving the operation request sent by the third security node of the application through the second security node, the method further includes:
9. The password service method of claim 7, wherein, Determining the first cryptographic machine from a first cryptographic machine resource pool, wherein the first cryptographic machine resource pool includes at least two cryptographic machines produced by at least two manufacturers. The device is applied to a first cryptographic machine, and the first cryptographic machine has only a first security node, and the device includes:
10. A cryptographic service device, characterized by A first receiving module is configured to receive, by the first security node, an operation request sent by a second security node of a first cryptographic service platform, wherein the operation request includes first data to be operated and cryptographic information required for operating the first data; The acquisition module is configured to acquire a risk data of at least one security node having an access right to the password information and the second security node, a sensitive level of the first data, a request type of the operation request, and the second security node; The evaluation module is configured to perform trust evaluation on the second security node according to the risk data, to obtain a trust degree of the second security node; The generation module is configured to generate a dynamic password policy corresponding to the trust degree, the sensitive level, and the request type; The operation module is configured to, in a case where the at least one security node includes the second security node, perform the operation on the first data by using the password information according to the dynamic password policy, to obtain second data of the operation; The first sending module is configured to send the second data to the second security node through the first security node.
11. A cryptographic service device, characterized by The application is applied to a first password service platform, and the first password service platform is provided with a second security node. The device comprises: The second sending module is configured to receive an operation request sent by a third security node of an application through the second security node, wherein the operation request comprises first data to be operated and password information required for operating the first data; The third sending module is configured to send the operation request to a first security node of a first password machine through the second security node; The second receiving module is configured to receive second data sent by the first security node through the second security node, wherein the second data is obtained by the first password machine in a case where at least one security node having an access right to the password information includes the second security node, by performing the operation on the first data by using the password information according to a dynamic password policy, the dynamic password policy corresponds to a trust degree of the second security node, a sensitive level of the first data, and a request type of the operation request, and the trust degree is obtained by the first password machine by performing trust evaluation on the second security node according to risk data of the second security node; The fourth sending module is configured to send the second data to the third security node through the second security node.
12. An electronic device, comprising: The device comprises a processor and a memory storing computer program instructions; The processor executes the computer program instructions to implement the password service method in any one of claims 1-9.
13. A computer-readable storage medium, characterized in that, The computer program instructions are stored on the computer readable storage medium, and the computer program instructions are executed by the processor to implement the password service method in any one of claims 1-9.
14. A computer program product, characterised in that, The instructions in the computer program product are executed by the processor of the electronic device, so that the electronic device performs the password service method in any one of claims 1-9.
Citation Information
Patent Citations
Big data system password service method and system
CN116108474A
Multi-category data encryption system and method based on cloud password unified service platform
CN117728937A