Key processing methods, apparatus, devices and readable storage media
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-02
- Publication Date
- 2026-08-14
AI Technical Summary
[0003]本申请实施例在于提供一种密钥处理方法、装置、设备及可读存储介质,解决制约“一终端一卡多应用”目标实现过程中终端侧密钥如何安全存储、如何高效共用的问题
[0063]在本申请中,在终端存储的一个或多个密钥中,为所述终端上的第一应用分配第一密钥;其中,所述存储的一个或多个密钥是所述终端与第一设备之间共享的密钥。终端侧通过公共密钥池的方法实现密钥的“集中存储、按需分配、共享使用”,能够有效提高SIM卡等安全介质的存储空间利用率。与网络侧的第一设备相配合,可以在不改变现有实现机制的基础上,以较低成本实现不同终端应用与第一设备安全交互,达到“一部终端、一张卡”支持多种不同保密通信应用的目标,解决了制约“一终端一卡多应用”目标实现过程中终端侧密钥如何安全存储、如何高效共用的瓶颈问题。
Smart Images

Figure CN118802142B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, specifically to a key processing method, apparatus, device, and readable storage medium. Background Technology
[0002] Currently, to achieve the goal of "one terminal, one card, multiple applications," the security medium on the terminal typically allocates a dedicated storage area for each secure communication application to store the corresponding quantum symmetric key pre-configured by the secure management platform, which is then available for use by upper-layer applications, such as... Figure 1 As shown. For example, multiple containers or security domains can be divided within a secure medium. In each container or security domain, a certain number of keys are stored for use by a specific secure communication application. When a terminal supports a wide variety of secure communication applications, the storage space allocated to each application becomes more limited. Users need to frequently recharge keys offline, thus limiting the realization of the "one terminal, one card, multiple applications" goal. Summary of the Invention
[0003] This application provides a key processing method, apparatus, device, and readable storage medium to solve the problem of how to securely store and efficiently share terminal-side keys during the process of achieving the goal of "one terminal, one card, multiple applications".
[0004] Firstly, a key processing method is provided for use in a terminal, including:
[0005] From one or more keys stored in the terminal, a first key is assigned to a first application on the terminal;
[0006] The stored one or more keys are keys shared between the terminal and the first device.
[0007] Optionally, the method further includes:
[0008] A second key is generated based on the first key; wherein the second key is a key shared between the terminal and the first device.
[0009] Optionally, the method further includes:
[0010] The first module obtains the first request from the first application and allocates the first key to the first application;
[0011] Send the result of the first key allocation to the first application.
[0012] Optionally, the first module obtains the first request from the first application and assigns a first key to the first application, including:
[0013] The first module obtains the first request from the first application and allocates the first key and the corresponding first key identifier to the first application;
[0014] Return the first key identifier to the first application.
[0015] Optionally, the first request may further include first indication information;
[0016] A second key is generated based on the first key according to the first instruction information.
[0017] Optionally, when the first module includes middleware and an applet, the middleware obtains the first request of the first application, determines a first key identifier for the first application, and the applet determines a first key based on the first key identifier;
[0018] Alternatively, when the first module includes middleware and an applet, the middleware obtains the first request of the first application and forwards the first request to the applet, and the applet assigns a first key and a corresponding first key identifier to the first application;
[0019] Alternatively, when the first module includes middleware, the middleware obtains the first request from the first application, and the software cryptography module allocates a first key and a corresponding first key identifier to the first application.
[0020] Alternatively, when the first module includes middleware, the middleware obtains the first request of the first application, determines a first key identifier for the first application, and the software cryptography module determines the first key based on the first key identifier;
[0021] Alternatively, when the first module includes an Applet, the Applet obtains a first request from the first application, and the Applet assigns the first key and a corresponding first key identifier to the first application.
[0022] Optionally, the applet includes a first applet and a second applet;
[0023] The first applet receives a first key acquisition request, the first applet sends a second key acquisition request to the second applet, the second applet provides the first applet with the first key, and the first applet generates the second key based on the first key;
[0024] Alternatively, the first applet receives a first key retrieval request, the first applet sends a second key retrieval request to the second applet, the second applet retrieves the first key, generates a second key based on the first key, and provides the second key to the first applet.
[0025] Optionally, the first Applet obtains the first key identifier based on the first key acquisition request, or the first Applet assigns the first key identifier.
[0026] Optionally, the second key acquisition request includes the first key identifier.
[0027] Optionally, the first applet returns the first key identifier to the middleware or the first application.
[0028] Optionally, the first applet obtains the first instruction information based on the first key acquisition request, or the first applet determines the first instruction information.
[0029] Optionally, the second key acquisition request may also include first indication information.
[0030] Optionally, the one or more keys are stored in one or more key pools of the terminal.
[0031] Optionally, a first message is sent to the first device, the first message including the first key identifier.
[0032] Optionally, the first message may also include the first indication information.
[0033] Secondly, a key processing method is provided, applied to a first device, comprising:
[0034] From one or more keys stored in the first device, a first key is assigned to a first application supported by the first device;
[0035] The one or more keys are keys shared between the first device and the terminal.
[0036] Optionally, the method further includes:
[0037] A second key is generated based on the first key; wherein the second key is a key shared between the first device and the terminal.
[0038] Optionally, from one or more keys stored in the first device, a first key is assigned to a first application supported by the first device, including:
[0039] The receiving terminal sends a first message, the first message including a first key identifier corresponding to the first key;
[0040] Obtain the first key based on the first key identifier.
[0041] Optionally, the first message may further include first indication information, which is used to indicate the generation of a second key based on the first key.
[0042] Optionally, when the first device includes a first platform and a second platform,
[0043] The second platform acquires a first message sent by the terminal; the first message includes a first key identifier corresponding to the first key;
[0044] The second platform sends a second message to the first platform, the second message including the first key identifier;
[0045] The first platform obtains the first key based on the first key identifier;
[0046] The first platform sends the first key or a second key generated based on the first key to the second platform.
[0047] Optionally, the first message may further include first indication information, and the second message may also include the first indication information;
[0048] The first platform generates a second key based on the first key according to the first instruction information.
[0049] Optionally, the method further includes:
[0050] The second platform generates a second key based on the first key sent by the first platform.
[0051] Optionally, the first message may further include first indication information, and the method may further include:
[0052] The second platform generates a second key based on the first key according to the first instruction information.
[0053] Optionally, the one or more keys are stored in one or more key pools of the first device.
[0054] Optionally, when the first device includes a first platform and a second platform, one or more keys are stored in one or more key pools of the first platform.
[0055] Thirdly, a key processing device is provided for use in a terminal, comprising: a first transceiver unit and a first processing unit;
[0056] The first processing unit is used to allocate a first key for a first application on the terminal from one or more keys stored in the terminal;
[0057] The stored one or more keys are keys shared between the terminal and the first device.
[0058] Fourthly, a key processing apparatus is provided for use in a first device, comprising: a second transceiver unit and a second processing unit;
[0059] The second processing unit is configured to allocate a first key for a first application supported by the first device from one or more keys stored in the first device;
[0060] The one or more keys are keys shared between the first device and the terminal.
[0061] Fifthly, a communication device is provided, including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the method described in the first or second aspect.
[0062] A sixth aspect provides a readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first or second aspect.
[0063] In this application, a first key is assigned to a first application on the terminal from one or more keys stored in the terminal; wherein the stored one or more keys are keys shared between the terminal and a first device. The terminal side achieves "centralized storage, on-demand allocation, and shared use" of keys through a public key pool, effectively improving the storage space utilization of secure media such as SIM cards. In conjunction with the first device on the network side, secure interaction between different terminal applications and the first device can be achieved at a lower cost without changing the existing implementation mechanism, achieving the goal of "one terminal, one card" supporting multiple different secure communication applications. This solves the bottleneck problem of how to securely store and efficiently share terminal-side keys during the realization of the "one terminal, one card, multiple applications" goal. Attached Figure Description
[0064] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:
[0065] Figure 1This is a schematic diagram of existing quantum secure communication key management mechanisms;
[0066] Figure 2 This is one of the flowcharts of the key processing method provided in the embodiments of this application;
[0067] Figure 3 This is a second flowchart of the key processing method provided in the embodiments of this application;
[0068] Figure 4 This is a schematic diagram of the key management system architecture provided in an embodiment of this application;
[0069] Figure 5 This is a schematic diagram of a single Applet card application implementation scheme provided in an embodiment of this application;
[0070] Figure 6 This is a flowchart illustrating the business processing in a single Applet card application scenario provided by an embodiment of this application;
[0071] Figure 7 This is a schematic diagram of a dual-Applet card application implementation scheme provided in an embodiment of this application;
[0072] Figure 8 This is the business processing flow provided in the dual Applet card application scenario according to the embodiments of this application;
[0073] Figure 9 This is one of the schematic diagrams of a communication processing apparatus provided in an embodiment of this application;
[0074] Figure 10 This is a second schematic diagram of the communication processing device provided in the embodiments of this application;
[0075] Figure 11 This is a schematic diagram of a communication device provided in an embodiment of this application. Detailed Implementation
[0076] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0077] The term "comprising," and any variations thereof, used in the specification and claims of this application, is intended to cover a non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those explicitly listed, but may include other steps or units not explicitly listed or inherent to such process, method, product, or apparatus. Furthermore, the use of "and / or" in the specification and claims indicates at least one of the connected objects, such as A and / or B, indicating the inclusion of A alone, B alone, or both A and B.
[0078] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0079] like Figure 1 As shown, in a quantum secure communication system, to ensure that secure communication applications on the terminal can securely access the quantum key management platform (hereinafter referred to as the quantum key platform) to obtain services, the secure communication application first needs to use the quantum key pre-provided by the quantum key platform for identity authentication and establish a secure channel. Then, it transmits various types of information through the secure channel to complete business processing. The pre-provided quantum key is usually generated by the quantum key platform based on random numbers from a quantum random number generator (QRNG) and pre-configured offline in the secure medium of the terminal before being distributed to the terminal user. The pre-configured quantum key is shared between the quantum key platform and the terminal device, and is a symmetric key. The quantum key platform is responsible for the full lifecycle management of the pre-configured quantum key. The secure medium can take various forms, such as a Subscriber Identity Module (SIM) card, a USB key, a Trans-flash card, a chip card, or a security chip. Hardware cryptographic modules can be formed based on hardware secure media. In addition, there are software cryptographic modules.
[0080] Figure 1The quantum key management platform in China can also be called a key management platform, quantum key service platform, quantum key platform, quantum key center, quantum service platform, quantum service center, quantum communication platform, quantum communication center, quantum communication service platform, quantum communication security service platform, etc. It is a device name composed of words such as quantum, cryptography, key, communication, security, service, management, center, platform, system, equipment, business, and application. It is used to provide key or cryptographic services required for secure communication for user terminals, network equipment, or application service equipment, and can also be used for full lifecycle management of the required keys.
[0081] A single terminal needs to support multiple secure communication applications simultaneously, such as quantum high-definition encrypted calls (based on fourth-generation (4G) / fifth-generation (5G) network standards), quantum encrypted calls via Voice over Internet Protocol (VoIP), quantum encrypted messages / information, quantum encrypted data, quantum encrypted email, quantum encrypted intercom, quantum encrypted cloud storage, quantum encrypted cloud phones, etc., to meet users' diverse secure communication needs. Since the quantum cryptographic platforms providing cryptographic services for each application may be different, each secure communication application on the terminal needs to be able to access the corresponding quantum cryptographic platform using the appropriate quantum symmetric key to obtain services. However, the secure media hardware supported by the terminal (e.g., the SIM card in a mobile phone) is limited. This requires the terminal to be able to implement multiple quantum secure communication services based on a single secure medium, i.e., to have the capability of "one terminal, one card, multiple applications".
[0082] Currently, to achieve the goal of "one terminal, one card, multiple applications," the security medium on the terminal typically allocates a dedicated storage area for each secure communication application to store the corresponding quantum symmetric key pre-configured by the quantum key distribution platform, for use by upper-layer applications, such as... Figure 1 As shown. For example, multiple containers or multiple security domains can be divided into a secure medium as storage space, and a certain number of quantum keys can be stored in each container or security domain for use in a specific secure communication application.
[0083] Mobile terminals in the form of mobile phones are communication devices used by users every day. SIM cards are a must-have security medium for such devices. High-capacity storage media such as USB keys, TF cards, and independent security chips are no longer supported by mobile terminals.
[0084] SIM cards are inexpensive (3-4 yuan / card), but their storage space is very limited (hundreds to thousands of KB). Dividing this limited storage space into multiple fixed storage areas to store pre-configured keys for different secure communication applications would result in a significant waste of storage resources. Infrequently used secure communication applications occupy fixed storage areas for extended periods, rarely using the stored quantum keys, leading to ineffective storage space usage. Frequently used secure communication applications, with smaller fixed storage areas and fewer stored quantum keys, quickly deplete their storage, requiring frequent offline or online key replenishment, resulting in a poor user experience. When a terminal supports many types of secure communication applications, the storage space allocated to each application becomes even more limited, requiring users to frequently replenish keys, which is unacceptable and fundamentally limits the realization of the "one terminal, one card, multiple applications" goal.
[0085] Therefore, an effective key management scheme is needed to improve the utilization rate of key storage space on security media such as SIM cards and meet the business development requirements of "one terminal, one card, multiple applications" for mobile terminals.
[0086] See Figure 2 The embodiments of this application provide a key processing method applied to a terminal, the specific steps of which include: step 21.
[0087] Step 21: Assign a first key to a first application on the terminal from one or more keys stored in the terminal; wherein the one or more stored keys are keys shared between the terminal and the first device.
[0088] It is understandable that the first application on the terminal can be: the first application that the terminal includes, supports, loads, executes, runs, loads, or installs; of course, there can be other similar interpretations as well.
[0089] Optionally, one or more applications can be installed on the terminal. The first application is one of these applications. For example, the application can be various types of encrypted communication applications that occur between terminals, devices, platforms, and terminals, such as encrypted calls, encrypted messages, encrypted emails, encrypted data, and encrypted cloud storage.
[0090] An application can be understood as an application, or it can also be called a service, business function, or feature.
[0091] Optionally, assigning a first key to the first application on the terminal can be: determining, assigning, configuring, distributing, or obtaining a first key for the first application on the terminal; other similar interpretations are also possible.
[0092] In this embodiment, the terminal may store one or more keys to form a first key pool (e.g., Figure 4 (a shared key resource pool in the first key pool), where the first key is one or more keys in the first key pool.
[0093] Optionally, the terminal may assign one first key to the first application at a time, or assign multiple first keys. That is, in this embodiment, the number of first keys is not limited.
[0094] Optionally, the first device can be a quantum key management platform, or it can be called a key management platform, cryptographic service platform, quantum key platform, quantum key center, quantum service platform, quantum service center, quantum communication platform, quantum communication center, quantum communication service platform, quantum communication security service platform, etc., which are device names composed of words such as quantum, cryptography, key, communication, security, service, management, center, platform, system, device, business, and application.
[0095] Optionally, the first device can be used to provide the keys required for secure communication for terminals, network devices, or application service devices, or the first device can also be used to manage the required keys throughout their entire lifecycle.
[0096] Optionally, the first device can be a single-platform device or a multi-platform device, for example, the first device includes a first platform and a second platform.
[0097] In this embodiment, the first platform can also be called a primary platform or a general key management platform, and the second platform can also be called a secondary platform or a business key management platform. The secondary platform may include multiple key management platforms, with different key management platforms corresponding to different services. See also... Figure 4 Secondary platforms may include, but are not limited to, key management platforms (business A), key management platforms (business B), and key management platforms (business C).
[0098] In one embodiment of this application, the method further includes:
[0099] A second key is generated based on the first key; wherein the second key is a key shared between the terminal and the first device.
[0100] It should be noted that the first key is a shared key between the terminal and the first device, which can be pre-configured by the first device onto the terminal. The second key is a working key generated between the terminal and the first device for secure communication and business operations.
[0101] Optionally, the second key is derived from the first key. The second key is generated according to different security needs; for example, multiple second keys can be generated based on the first key. Using the second key as the working key for secure communication between the terminal and the first device is to achieve different security purposes or functions. Different users or operations with different functions should use different keys for protection to avoid the multiple uses of the same key, thereby improving the security of the communication system.
[0102] Optionally, the types of the second key include: a second key for integrity protection, a second key for encryption, a second key for uplink communication, a second key for downlink communication, a second key for communicating with the key management platform (service A) in the secondary platform, a second key for communicating with the key management platform (service B) in the secondary platform, a second key for communicating with the key management platform (service C) in the secondary platform, and so on.
[0103] Optionally, during the second key generation process, multiple different second keys can be generated based on the first key by adding parameters such as function (encryption, integrity protection), direction (uplink, downlink), secondary platform identifier, timestamp, random number, and classic key (e.g., a key obtained through classic cryptography).
[0104] In one embodiment of this application, allocating a first key for a first application on the terminal includes:
[0105] The first module obtains the first request from the first application and allocates the first key to the first application;
[0106] Send the result of the first key allocation to the first application.
[0107] Optionally, the first module can be a cryptographic module, used to implement cryptographic operations such as secure key storage and encryption / decryption. The cryptographic module can be a software cryptographic module, a hardware cryptographic module, or a combination of both. The software cryptographic module can be included in middleware; the hardware cryptographic module typically includes middleware and a physical security medium (e.g., middleware software and a SIM card). A corresponding software program (i.e., the card application) is needed on the security medium to implement cryptographic operations. The card application (Applet) is the software program that implements cryptographic operations on hardware security media such as SIM cards and TF cards, and is an essential component of the hardware cryptographic module.
[0108] In one embodiment of this application, the first module obtains a first request from the first application and allocates a first key to the first application, including:
[0109] The first module obtains the first request from the first application and allocates the first key and the corresponding first key identifier to the first application;
[0110] Return the first key identifier to the first application.
[0111] For example, if the first application is a secure communication application A, the first key identifier can be QKID. A .
[0112] In one embodiment of this application, the first request further includes first indication information; the first module generates a second key based on the first key according to the first indication information. That is, the first request can indicate the method of key generation.
[0113] The first module mentioned in this embodiment of the invention generates a second key based on a first key in the following ways:
[0114] (1) When the first module includes middleware and an applet (i.e., a password management applet), such as Figure 5 As shown, the middleware receives the first request from secure communication application A and determines the QKID for secure communication application A. A The Applet (i.e., the password management Applet) is based on the QKID. A Determine QK A .
[0115] (2) When the first module includes middleware and an applet (i.e., a password management applet), such as Figure 5 As shown, the middleware receives the first request from secure communication application A, forwards the first request to the Applet (i.e., the password management Applet), and the Applet allocates QK to secure communication application A. A and QKID A .
[0116] (3) When the first module includes middleware, the middleware obtains the first request from secure communication application A, and the middleware's software cryptography module allocates QK to secure communication application A. A and QKID A .
[0117] (4) When the first module includes middleware, the middleware obtains the first request from secure communication application A and determines the QKID for secure communication application A. A The middleware's software cryptography module is based on QKID. A Assign QK to secure communication application A A .
[0118] (5) When the first module includes an Applet, such as Figure 5As shown (excluding middleware at this time), Figure 5 The middleware (optional) in the applet receives the first request from secure communication application A, and the applet assigns a QKID to secure communication application A. A and QK A .
[0119] It should be noted that, in embodiments of the present invention, the terminal may include one or more applets. Figure 5 This illustrates a case involving an applet. Figure 7 The example shown includes two applets.
[0120] In one embodiment of this application, such as Figure 7 As shown, an applet includes a first applet and a second applet;
[0121] The first applet receives a first key retrieval request (in this case, the applet may or may not include middleware. For example, if middleware is present, this request could be...). Figure 8 Step 4A (i.e., key distribution), without middleware, this request can be... Figure 8 In step 2A (i.e., key acquisition instruction), the first Applet sends a second key acquisition request to the second Applet, and the second Applet provides the first Applet with the first key QK. A The first Applet is based on the first key QK A Generate a second key Qkey A ;
[0122] Alternatively, the first applet receives a first key retrieval request, the first applet sends a second key retrieval request to the second applet, the second applet retrieves the first key, generates a second key based on the first key, and provides the second key to the first applet.
[0123] The first applet mentioned above can also be called a password service applet, and the second applet can also be called a key storage applet. For example... Figure 7 As shown, the cryptographic service applet may include, but is not limited to, cryptographic application A, cryptographic application B, and cryptographic application C. The key storage applet includes functional modules such as a key pool and cryptographic computation capabilities. There is a service interface between the cryptographic service applet and the key storage applet.
[0124] In one embodiment of this application, the first applet obtains a first key identifier based on the first key acquisition request, or the first applet assigns a first key identifier. That is, the first key identifier may be assigned by the terminal and sent to the first applet through the first key acquisition request; or it may not be assigned by the terminal, but directly assigned by the first applet.
[0125] In one embodiment of this application, the second key acquisition request includes the first key identifier. That is, regardless of whether the first key identifier is assigned by the terminal or the first applet, it needs to be sent to the second applet through the second key acquisition request so that the second applet can assign the first key based on the first key identifier.
[0126] In one embodiment of this application, the first applet returns a first key identifier to the middleware or the first application. That is, when the first module includes middleware, the first applet returns the first key identifier to the middleware; when the first module does not include middleware, the first applet returns the first key identifier to the first application.
[0127] In one embodiment of this application, the first applet obtains the first instruction information based on the first key acquisition request, or the first applet determines the first instruction information. That is, the first instruction information may be determined by the terminal and sent to the first applet through the first key acquisition request; or it may be determined by the first applet itself.
[0128] In one embodiment of this application, the second key acquisition request further includes first indication information. That is, regardless of whether the first indication information is determined by the terminal or the first applet, it needs to be provided to the second applet through the second key acquisition request so that the second applet can generate a second key based on the first key according to the first indication information.
[0129] In one embodiment of this application, the one or more keys are stored in one or more key pools of the terminal.
[0130] In one embodiment of this application, the method further includes: sending a first message to the first device, the first message including the first key identifier. Here, the first message may be sent by a first application on the terminal.
[0131] Optionally, the first message may also include the first indication information, used to indicate to the network-side first device the generation method of generating the second key based on the first key.
[0132] Optionally, the first message can be an authentication request message, which contains authentication information encrypted and / or protected for integrity using a first key or a second key. In this case, the second platform uses the first key or the second key obtained from the first platform to process the authentication information in the received authentication request message. The first message can also be a secure channel establishment request, a (quantum) session key distribution request, a (quantum) key update request, a (quantum) key destruction request, etc.
[0133] In this application, a first key is assigned to a first application on the terminal from one or more keys stored in the terminal; wherein the stored one or more keys are keys shared between the terminal and a first device. The terminal side achieves "centralized storage, on-demand allocation, and shared use" of keys through a public key pool, effectively improving the storage space utilization of secure media such as SIM cards. In conjunction with the first device on the network side, secure interaction between different terminal applications and the first device can be achieved at a lower cost without changing the existing implementation mechanism, achieving the goal of "one terminal, one card" supporting multiple different secure communication applications. This solves the bottleneck problem of how to securely store and efficiently share terminal-side keys during the realization of the "one terminal, one card, multiple applications" goal.
[0134] See Figure 3 The embodiments of this application provide a key processing method applied to a first device, the specific steps of which include: step 31.
[0135] Step 31: Assign a first key to a first application supported by the first device from one or more keys stored in the first device;
[0136] The one or more keys are keys shared between the first device and the terminal.
[0137] See Figure 4The first application on the terminal (e.g., secure communication application A) and the first application supported by the first device (e.g., key management system) (service A) are respectively client and server software or hardware that implement a certain secure communication service function. For example, in an encrypted call application, encrypted call client software is installed on the terminal, which is the first application on the terminal. Correspondingly, on the key management platform side, the first device is equipped with a first application that provides services to support the terminal in implementing the encrypted call function. The first application on the terminal and the first application supported by the first device use an assigned first key or a second key generated based on the assigned first key to conduct secure communication or secure interaction to complete the processing of business information. In addition to encrypted calls, the first application can also be various types of encrypted communication applications that occur between terminals, between devices, between platforms, or between terminals and devices or platforms, such as encrypted messages, encrypted data, encrypted emails, encrypted cloud storage, etc.
[0138] An application can be understood as an application, or it can also be called a service, business function, or feature.
[0139] In one embodiment of this application, the method further includes:
[0140] A second key is generated based on the first key; wherein the second key is a key shared between the first device and the terminal.
[0141] In one embodiment of this application, allocating a first key for a first application supported by the first device from one or more keys stored in the first device includes:
[0142] The receiving terminal sends a first message, the first message including a first key identifier corresponding to the first key;
[0143] Obtain the first key based on the first key identifier.
[0144] In one embodiment of this application, the first message further includes first indication information, which is used to indicate the generation of a second key based on the first key.
[0145] Optionally, the first message can be called a business request.
[0146] In the above embodiments, the first device is a unified device.
[0147] In one embodiment of this application, when the first device includes a first platform and a second platform,
[0148] The second platform acquires a first message sent by the terminal; the first message includes a first key identifier corresponding to the first key;
[0149] The second platform sends a second message to the first platform, the second message including the first key identifier;
[0150] The first platform obtains the first key based on the first key identifier;
[0151] The first platform sends the first key or a second key generated based on the first key to the second platform.
[0152] There are three possible implementation methods:
[0153] (1) The first platform sends the first key to the second platform so that the second platform can use the first key for secure processing;
[0154] (2) The first platform sends the first key to the second platform. At this time, the second platform further derives the second key based on the first key and uses the second key for security processing.
[0155] (3) After obtaining the first key, the first platform uses the first key to generate the second key, and then sends the second key to the second platform so that the second platform can use the second key for secure processing.
[0156] When corresponding to the above-mentioned case (1), the first message may or may not carry the first instruction information.
[0157] When corresponding to the second scenario described above, if the first message includes the first instruction information, the second platform generates the second key based on the first key according to the first instruction information. If the first message does not include the first instruction information, the second platform generates the second key based on the first key according to the default method.
[0158] When corresponding to the above-mentioned situation (3), if both the first message and the second message include the first instruction information (the first instruction information originates from the terminal), the first platform generates the second key based on the first key according to the first instruction information. If the first message does not include the first instruction information, but the second message does include the first instruction information (the first instruction information originates from the second platform), the first platform generates the second key based on the first key according to the first instruction information. If the second message does not include the first instruction information, the first platform generates the second key based on the first key according to the default method.
[0159] Optionally, the first message can be called a business request, and the second message can be called a key request.
[0160] It should be noted that the first platform can also be called a primary platform or a general key management platform, and the second platform can also be called a secondary platform or a business key management platform. A secondary platform can include multiple key management platforms, and different key management platforms can correspond to one or more different services. It is understood that the specific names of the first and second platforms are not limited in this embodiment.
[0161] exist Figure 4 In the architecture shown, the secondary platform obtains the first message sent by the secure communication application A on the terminal. The first message includes QK. A Corresponding QKID A The secondary platform sends a second message to the primary platform, the second message including the QKID. A The primary platform is based on QKID. A Get QK A The primary platform will include QK. A Or based on QK A Generated QKey A The key is sent to the secondary platform's key management platform (Business A), and the secondary platform directly uses the QK. A Perform security processing (e.g., secure processing of the first message), or use QK on a secondary platform. A Generate QKey A And using QKey A To perform security processing (e.g., security processing of the first message), or the secondary platform receives the QKey sent by the primary platform. A And using QKey A To perform security processing (e.g., to perform security processing on the first message).
[0162] Optionally, the first message can be an authentication request message, which contains authentication information encrypted and / or protected for integrity using a first key or a second key. In this case, the second platform uses the first key or the second key obtained from the first platform to process the authentication information in the received authentication request message. The first message can also be a secure channel establishment request, a (quantum) session key distribution request, a (quantum) key update request, a (quantum) key destruction request, etc.
[0163] In one embodiment of this application, the one or more keys are stored in one or more key pools of the first device.
[0164] In one embodiment of this application, when the first device includes a first platform and a second platform, one or more keys are stored in one or more key pools of the first platform.
[0165] In this application, a first key is assigned to a first application supported by the first device from one or more keys stored in the first device; wherein, the one or more keys are keys shared between the first device and the terminal. The terminal side achieves "centralized storage, on-demand allocation, and shared use" of keys through a public key pool, effectively improving the storage space utilization of secure media such as SIM cards. In conjunction with the first device on the network side, secure interaction between different terminal applications and the first device can be achieved at a lower cost without changing the existing implementation mechanism, achieving the goal of "one terminal, one card" supporting multiple different secure communication applications. This solves the bottleneck problem of how to securely store and efficiently share terminal-side keys during the realization of the "one terminal, one card, multiple applications" goal.
[0166] In the following embodiments, the first application is a secure communication application A, secure communication application B, or secure communication application C; the first module includes middleware and an applet; the applet includes cryptographic application A, cryptographic application B, cryptographic application C, a key pool, and cryptographic computing capabilities; the first platform is a primary platform; and the second platform is a secondary platform.
[0167] like Figure 4 As shown, storage space is allocated in the secure medium of the terminal to store the keys filled by the key management system. For example, the secure medium is used to store keys generated by the key management system based on QRNG, forming a shared key pool within the secure medium. The keys in the key pool have no application or business attributes; they are key resources shared by multiple applications on the terminal (e.g., secure communication application A, secure communication application B, and secure communication application C), and are allocated to upper-layer applications as needed. Before allocation and use, the keys in the shared key pool have no application or business attributes and do not belong solely to any one secure communication application.
[0168] In order to enable the management of shared keys in secure media, a key management platform ( Figure 4 The quantum key management system is also divided into a general-purpose key management platform (Level 1 platform) and a business-oriented key management platform (Level 2 platform), thus forming a quantum key management system. The Level 1 platform can be understood as... Figure 1It integrates common components from multiple existing key management platforms, implementing general cryptographic operations and key management functions. For example, it supports symmetric encryption algorithms, asymmetric encryption algorithms, postquantum cryptography algorithms, hash algorithms, etc., completing message encryption and decryption processing, Message Authentication Code (MAC) / Hash-based Message Authentication Code (HMAC) calculation, Key Derivation Function (KDF) operations, and implementing full lifecycle management of keys, including generation, distribution, use, update, destruction, recovery, and archiving.
[0169] The primary platform is responsible for offline charging of pre-configured keys to the secure medium. These pre-configured keys are stored and maintained on both the primary platform and the secure medium, and are symmetric keys shared by the key management system and the user terminal. Before being allocated to specific secure communication applications, the shared keys in the public resource pools on both sides have no application or business attributes. They are allocated to different secondary platforms as needed as business transactions occur. The primary platform manages the keys charged to the terminal throughout their entire lifecycle online. The primary platform supports integration with multiple secondary platforms, providing key services to different secondary platforms.
[0170] based on Figure 4 The system architecture shown below will be followed by two schemes for implementing a key pool in the terminal's super SIM card.
[0171] The Super SIM card is an evolution of the traditional SIM card (which stores a user's unique identification code and network key for mobile communication network access authentication). It expands storage space, adds security algorithms, supports dynamic application loading, and enables Near Field Communication (NFC) card swiping capabilities, making it a highly secure carrier for various sensitive digital assets. It can serve a wider range of industry applications such as digital identity, access control, payment, and transportation. An Applet is a small application (also known as a card application) written in the Java programming language that can be downloaded and installed on the Super SIM card to implement specific application functions.
[0172] Option 1: Single-card application solution
[0173] like Figure 5As shown, a password management card application is downloaded and installed on the Super SIM card security medium. This application includes a key resource pool, cryptographic computation capabilities, and several smart password key applications (referred to as password applications). The password management card application provides services such as password resource storage and cryptographic computation for secure communication applications on the terminal. The key pool is responsible for storing a certain number of keys and allocating them to secure communication applications as needed. Keys are filled in by the primary platform through the filling interface. The cryptographic computation capabilities are responsible for calling the Super SIM card cryptographic engine to complete symmetric encryption / decryption, asymmetric encryption / decryption, signature verification, hashing, and other operations, realizing key derivation, information encryption / decryption, integrity protection, and other processing. Each smart password key application corresponds to a secure communication application on the terminal. For example, the smart password key application is implemented in accordance with GM / T 0016 "Smart Password Key Cryptographic Application Interface Specification". Each password application includes a PIN (Personal Identification Number), several files, and several containers. The containers store the asymmetric keys, symmetric keys, digital certificates, etc., required by the secure communication application and can be accessed by the corresponding secure communication application on the terminal. Multiple secure communication applications on the terminal access the card application in the Super SIM card through middleware software. The middleware is responsible for managing and maintaining the keys in the key pool, including assigning keys to users, deleting used keys, maintaining the key count, and the next usable key (implemented by maintaining pointer variables or key IDs), etc. The key status information maintained by the middleware is stored in a file within the Super SIM card's password management card application. When multiple secure communication applications simultaneously access the card application, the middleware needs to manage conflicts between concurrent access requests to prevent the same key in the resource pool from being assigned to different applications, thus preventing the leakage of protected information. The middleware is an optional software module. Without middleware, multiple secure communication applications on the terminal directly access the card application in the Super SIM card through an interface; in this case, conflict management is handled by the card application.
[0174] Figure 6 Under this scheme, multiple secure communication applications obtain keys on demand by accessing a shared key pool and interact with the corresponding key management platform to complete business processing.
[0175] Step 1A: Secure communication application A on the terminal initiates a certain service. This service requires the use of a pre-charged quantum key in the super SIM card to securely communicate with the corresponding secondary platform (service A) to complete the service processing.
[0176] For example, this service could be a login service, where terminal application A logs into a secondary platform, uses a pre-filled key to complete identity authentication, and establishes a secure channel with the secondary platform; or it could be an encrypted call or quantum-encrypted message transmission service, where terminal application A accesses the secondary platform to apply for a session key, and the terminal and the secondary platform use the pre-filled key to securely protect the distributed session key.
[0177] Step 2A: Secure communication application A on the terminal calls the software interface to send an instruction to the middleware, requesting the allocation of one or more pre-filled keys (QK) for this service. A ).
[0178] Optionally, communication application A on the terminal can carry the Qkey when invoking the interface. A Generation method indication information, used to describe the QKey A The generation method.
[0179] Step 3A: The middleware queries the status information of the shared key resource pool within the Super SIM card (e.g., the next usable key), and allocates one or more keys from the resource pool for the secure communication application A, identified by QKID. A These keys, once assigned to secure communication application A, will be marked and will not be assigned to other applications to avoid the security risk of the same key being used multiple times.
[0180] Step 4A: The middleware calls the Super SIM Card Key Management Card application interface, instructing it to transfer the QKID. A The corresponding key is assigned to secure communication application A.
[0181] Optionally, the middleware can also specify the Qkey to the password management card application. A The generation method. For example, if the secure communication application A on the terminal specifies it in step 2A, the middleware specifies the Qkey according to the instruction of the secure communication application A on the terminal. A The generation method; if not specified, the middleware uses the default business logic instruction QKey from the secure communication application A on the terminal. A The generation method.
[0182] Step 5A: The password management card application obtains the QKID from the key pool. A The corresponding key QK A , and assign it to the password application A.
[0183] Step 6A: Based on the business processing logic of the secure communication application A, the cryptographic application A in the cryptographic management card application can further be based on QK. A Generate QKey ATo meet business needs.
[0184] Optional, QKey A There are many ways to live, for example,
[0185] Method 1: Qkey A That is, QK A itself.
[0186] Method 2: Qkey A Based on QK A This is derived from and generated using a Key Derivation Function (KDF). In step 4A, the middleware specifies the Qkey. A In the case of generation mode, password application A operates according to the instructions of the middleware; if the middleware does not specify, password application A generates a QKey according to the default business logic of secure communication application A on the terminal. A .
[0187] Step 7A: The password management card application returns the key allocation processing result.
[0188] Step 8A: The middleware returns the key allocation result to the secure communication application A on the terminal. This result includes the QKID. A Identification information.
[0189] Step 9A: Secure communication application A sends a service request message (i.e., the first message) to the secondary platform (service A) that provides services to it, which carries the QKID. A Identification information, optionally including Qkey A Generation method indication information.
[0190] It's understandable that the aforementioned business request is a higher-level concept, representing various business processing requests sent by application A to its secondary service platform. Mapped to a specific business processing mechanism, this request could be a secure channel establishment request, a session key request, etc. Qkey A The generation method indication information is used to describe the QKey. A The generation method.
[0191] Step 10A: Since the key resources corresponding to the key pool in the terminal's super SIM card are maintained by the primary platform, the secondary platform sends a key request message (i.e., the second message) to the primary platform to obtain the quantum key required for interaction with the secure communication application A on the terminal. The message carries the QKID. A Identification information, optionally including Qkey A Generation method indication information. If the business request message received by the secondary platform carries a Qkey... AThe generation method indication information should be filled in according to the information in the business request message. If the business request message does not carry a Qkey... A The generation method indication information, then the Qkey in the key request message A The generation method instruction information is filled in by the secondary platform according to the agreed default method, so as to obtain the key that meets the requirements of application A.
[0192] Step 11A: According to QKID A The identification information allows the primary platform to obtain the quantum symmetric key QK from the key pool corresponding to the terminal's secure medium. A .
[0193] Step 12A: Based on Qkey A Generation method indication information, the primary platform is based on QK A Generate QKey A This is to meet business needs. If the received key request message does not contain a Qkey... A If the generation method is specified, the primary platform will generate the Qkey according to the agreed-upon default method. A QKey A There are multiple ways to produce it; some examples can be found in step 6A.
[0194] Step 13A: The Level 1 platform returns a key response message, which carries the QKey. A .
[0195] Step 14A: Using QKey on the secondary platform A Process business request messages.
[0196] Step 15A: After processing is complete, the secondary platform returns a response message to the secure communication application A on the terminal.
[0197] Steps 1B to 15B: These are the basic processes by which the secure communication application B on the terminal requests the quantum key from the Super SIM card's public resource pool to complete service processing with the secondary platform (Service B). This process is similar to steps 1A to 15A and will not be described in detail here.
[0198] As can be seen, by using the public key pre-filled in the key management applet, the terminal can achieve "one terminal, one card, multiple applications".
[0199] Option 2: Dual-SIM application solution.
[0200] The single-SIM application solution requires fewer applets, saving space. However, when applets need to be upgraded online, the quantum keys stored in the resource pool will be lost, requiring offline recharging through the primary platform, resulting in a poor user experience.
[0201] Therefore, further proposals are put forward, such as Figure 7 The dual-SIM application scheme is shown. The password service card application and the key storage card application are downloaded and installed on the Super SIM card security medium.
[0202] See Figure 7 The key storage card application provides cryptographic resource storage and cryptographic operations services for secure communication applications on the terminal. The cryptographic service card application can contain several smart cryptographic key cryptographic applications (referred to as cryptographic applications). Each cryptographic application corresponds to a secure communication application on the terminal device and is implemented in accordance with GM / T 0016 "Smart Cryptographic Key Cryptographic Application Interface Specification". Each cryptographic application contains a Personal Identification Number (PIN), several files, and several containers. The containers store the asymmetric keys, symmetric keys, digital certificates, etc., required by the secure communication application and can be accessed by the corresponding secure communication application. The key storage card application includes a key pool and cryptographic operation capabilities, responsible for storing a certain number of keys and performing cryptographic operations. The key storage card application supports a refill interface, where pre-stored keys are refilled by the primary platform through the refill interface. Furthermore, it supports a service interface, allowing keys allocated to secure communication applications on demand to be provided to the corresponding cryptographic applications, providing key support for secure communication applications on the terminal.
[0203] Figure 8 Taking secure communication application A as an example, the system working mechanism under this scheme is explained.
[0204] Steps 1A to 4A, steps 9A to 16A and Figure 6 In the case of a single Applet card application, the processing of the secure communication application A, middleware, primary platform, and secondary platform on the terminal is the same and will not be repeated here. The difference lies in the interaction and processing between the two card applications within the Super SIM card after the cryptographic service Applet receives the key allocation instruction issued by the middleware in step 4A, as described below:
[0205] Step 5A: The password service applet sends a key retrieval instruction to the key storage applet through the Super SIM card's internal interface, requesting to obtain the QKID. A The corresponding key QK A .
[0206] Step 6A: The key storage applet returns the requested key QK. A .
[0207] Step 7A: Password application A in the password service applet is based on QK A Generate QKeyA .
[0208] Step 8A: Return a response indicating that the required key has been successfully prepared to the middleware.
[0209] It should be noted that steps 5A to 7A are based on QK. A Generate QKey A The operation can also be performed by the key storage applet. In this case, the cryptographic service applet in step 5A needs to specify the Qkey to the key storage applet. A The generation method. Then, the QKey is generated by the key storage applet. A And the generated QKey A Returned to the password service applet. Without specifying a Qkey. A In the case of the generation method, the key storage applet can generate a QKey according to the default method. A .
[0210] The above embodiments illustrate a scenario where an application on a terminal and a secondary platform securely interact using keys from a shared key pool to complete business processing. In addition, the shared key pool scheme proposed in this embodiment is also applicable to scenarios where a terminal application communicates securely with a primary platform. In this case, middleware or secure communication applications will obtain keys from the key pool as needed to communicate directly with the primary platform. The specific process will not be elaborated here.
[0211] It should be noted that, in addition to SIM cards, U-shields (USB Keys), TF cards, chip cards, security chips, software password modules, etc., although they have larger storage space and can store more keys, they also need to improve the utilization of storage space. This embodiment is also applicable to other types of security media.
[0212] Existing technologies use dedicated storage space to store pre-configured keys for each secure communication application, resulting in a significant waste of storage resources as each application occupies a fixed portion of the SIM card's limited storage space. The limited storage space is divided into small blocks, with each secure communication application allocated only a small area to store a limited number of keys, insufficient to meet application needs. Dedicated, high-capacity SIM cards can meet application requirements, but they are expensive (approximately 50 RMB per card), requiring substantial investment from operators for business development.
[0213] This application employs a public key pool method to achieve "centralized storage, on-demand allocation, and shared use" of terminal-side keys, effectively improving the storage space utilization of secure media such as SIM cards. In conjunction with the first device on the network side, it enables secure interaction between different terminal applications and the first device at a lower cost without altering the existing implementation mechanism, achieving the goal of "one terminal, one card" supporting multiple different secure communication applications. This solves the bottleneck problem of how to securely store and efficiently share terminal-side keys during the realization of the "one terminal, one card, multiple applications" goal. This embodiment is also applicable to other forms of secure media, with a wide range of applications.
[0214] See Figure 9 The embodiments of this application provide a key processing device applied to a terminal. The device 900 includes: a first transceiver unit 901 and a first processing unit 902.
[0215] The first processing unit 902 is used to allocate a first key for a first application on the terminal from one or more keys stored in the terminal;
[0216] The stored one or more keys are keys shared between the terminal and the first device.
[0217] In one embodiment of this application, the first processing unit 902 is further configured to: generate a second key based on the first key; wherein the second key is a key shared between the terminal and the first device.
[0218] In one embodiment of this application, the first processing unit 902 is further configured to: obtain a first request from the first application and allocate the first key to the first application;
[0219] Send the result of the first key allocation to the first application.
[0220] In one embodiment of this application, the first processing unit 902 is further configured to: obtain a first request from the first application, allocate the first key and a corresponding first key identifier to the first application, and return the first key identifier to the first application.
[0221] In one embodiment of this application, the first request further includes first indication information; the first processing unit 902 is further configured to generate a second key based on the first key according to the first indication information.
[0222] In one embodiment of this application, when the first module includes middleware and a card application Applet, the middleware obtains a first request from the first application, determines a first key identifier for the first application, and the Applet determines a first key based on the first key identifier;
[0223] Alternatively, when the first module includes middleware and an applet, the middleware obtains the first request of the first application and forwards the first request to the applet, and the applet assigns a first key and a corresponding first key identifier to the first application;
[0224] Alternatively, when the first module includes middleware, the middleware obtains the first request from the first application, and the software cryptography module of the middleware allocates a first key and a corresponding first key identifier to the first application.
[0225] Alternatively, when the first module includes middleware, the middleware obtains the first request of the first application, determines a first key identifier for the first application, and the software cryptography module of the middleware determines the first key based on the first key identifier;
[0226] Alternatively, when the first module includes an Applet, the Applet obtains a first request from the first application, and the Applet assigns the first key and a corresponding first key identifier to the first application.
[0227] In one embodiment of this application, the applet includes a first applet and a second applet;
[0228] The first applet receives a first key acquisition request, the first applet sends a second key acquisition request to the second applet, the second applet provides the first applet with the first key, and the first applet generates the second key based on the first key;
[0229] Alternatively, the first applet receives a first key retrieval request, the first applet sends a second key retrieval request to the second applet, the second applet retrieves the first key, generates a second key based on the first key, and provides the second key to the first applet.
[0230] In one embodiment of this application, the first Applet obtains a first key identifier according to the first key acquisition request or the first Applet is assigned a first key identifier.
[0231] In one embodiment of this application, the second key acquisition request includes the first key identifier.
[0232] In one embodiment of this application, the first applet returns the first key identifier to the middleware or the first application.
[0233] In one embodiment of this application, the first Applet obtains first indication information based on the first key acquisition request or the first Applet determines the first indication information.
[0234] In one embodiment of this application, the second key acquisition request further includes first indication information.
[0235] In one embodiment of this application, the one or more keys are stored in one or more key pools of the terminal.
[0236] In one embodiment of this application, a first message is sent to the first device, the first message including the first key identifier.
[0237] In one embodiment of this application, the first message further includes the first indication information.
[0238] The apparatus provided in this application embodiment can achieve... Figure 2 The various processes implemented in the method embodiments shown achieve the same technical effects, and will not be described again here to avoid repetition.
[0239] See Figure 10 The embodiments of this application provide a key processing device, applied to a first device, the device 1000 including: a second transceiver unit 1001 and a second processing unit 1002;
[0240] The second processing unit 1002 is configured to allocate a first key for a first application supported by the first device from one or more keys stored in the first device.
[0241] The one or more keys are keys shared between the first device and the terminal.
[0242] In one embodiment of this application, the second processing unit 1002 is further configured to: generate a second key based on the first key; wherein the second key is a key shared between the first device and the terminal.
[0243] In one embodiment of this application, the second processing unit 1002 is further configured to: receive a first message sent by a terminal, the first message including a first key identifier corresponding to a first key; and obtain the first key according to the first key identifier.
[0244] In one embodiment of this application, the first message further includes first indication information, which is used to indicate the generation of a second key based on the first key.
[0245] In one embodiment of this application, when the first device includes a first platform and a second platform,
[0246] The second platform acquires a first message sent by the terminal; the first message includes a first key identifier corresponding to the first key;
[0247] The second platform sends a second message to the first platform, the second message including the first key identifier;
[0248] The first platform obtains the first key based on the first key identifier;
[0249] The first platform module sends the first key or a second key generated based on the first key to the second platform.
[0250] In one embodiment of this application, the first message further includes first indication information, and the second message includes the first indication information;
[0251] The first platform generates a second key based on the first key according to the first instruction information.
[0252] In one embodiment of this application, the one or more keys are stored in one or more key pools of the first device.
[0253] In one embodiment of this application, when the first device includes a first platform and a second platform, one or more keys are stored in one or more key pools of the first platform.
[0254] The apparatus provided in this application embodiment can achieve... Figure 3 The various processes implemented in the method embodiments shown achieve the same technical effects, and will not be described again here to avoid repetition.
[0255] like Figure 11 As shown, this application embodiment also provides a communication device 1100, including a processor 1101, a memory 1102, and a program or instructions stored in the memory 1102 and executable on the processor 1101. When the program or instructions are executed by the processor 1101, they implement the above-mentioned... Figure 2 or Figure 3 The various processes in the method embodiments can achieve the same technical effect. To avoid repetition, they will not be described again here.
[0256] This application embodiment also provides a readable storage medium storing a program or instructions that, when executed by a processor, implement the above-described functionality. Figure 2 or Figure 3 The various processes of the method embodiments shown can achieve the same technical effect, and will not be described again here to avoid repetition.
[0257] The processor mentioned above is the processor in the terminal described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0258] The steps of the methods or algorithms described in this application can be implemented in hardware or by executing software instructions on a processor. The software instructions can consist of corresponding software modules, which can be stored in RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disk, portable hard disk, read-only optical disk, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can be housed in an ASIC. Alternatively, the ASIC can be housed in a core network interface device. Of course, the processor and storage medium can also exist as discrete components in the core network interface device.
[0259] Those skilled in the art will recognize that, in one or more of the examples above, the functions described in this application can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transfer of a computer program from one place to another. Storage media can be any available medium accessible to a general-purpose or special-purpose computer.
[0260] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above description is only a specific embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of this application should be included within the scope of protection of this application.
[0261] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, embodiments of this application can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of this application can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0262] This application describes embodiments of methods, apparatus (systems), and computer program products according to embodiments of this application with reference to flowchart illustrations and / or block diagrams. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0263] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0264] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0265] Obviously, those skilled in the art can make various modifications and variations to the embodiments of this application without departing from the spirit and scope of this application. Therefore, if these modifications and variations to the embodiments of this application fall within the scope of the claims of this application and their equivalents, this application also intends to include these modifications and variations.
Claims
1. A key processing method, applied to a terminal, characterized in that, include: Among the multiple keys stored in the terminal, a first key is assigned to a first application on the terminal; wherein the multiple stored keys are keys shared between the terminal and the first device; The first module obtains the first request from the first application, allocates the first key and the corresponding first key identifier to the first application, returns the first key identifier to the first application, and multiple applications are installed on the terminal. Send the first key identifier to the first device; The first device is configured to allocate the first key for the first application supported by the first device from the plurality of keys stored in the first device according to the first key identifier; The first device includes a first platform and multiple second platforms, with different second platforms corresponding to different applications. The second platform is used to obtain the first key identifier sent by the terminal. The second platform is also used to send the first key identifier to the first platform. The second platform is also used to perform secure communication with the first application on the terminal through the first key or a second key generated based on the first key. The first platform is used to obtain the first key according to the first key identifier. The first platform is also used to send the first key or a second key generated based on the first key to the second platform.
2. The method according to claim 1, characterized in that, The method further includes: A second key is generated based on the first key; wherein the second key is a key shared between the terminal and the first device.
3. The method according to claim 1 or 2, characterized in that, The method further includes: The first module obtains the first request from the first application and allocates the first key to the first application; Send the result of the first key allocation to the first application.
4. The method according to claim 1 or 2, characterized in that, The first request also includes first indication information; The first module generates a second key based on the first key according to the first instruction information.
5. The method according to claim 1 or 2, characterized in that, When the first module includes middleware and applet, the middleware obtains the first request of the first application, determines the first key identifier for the first application, and the applet determines the first key based on the first key identifier; Alternatively, when the first module includes middleware and an applet, the middleware obtains the first request of the first application and forwards the first request to the applet, and the applet assigns a first key and a corresponding first key identifier to the first application; Alternatively, when the first module includes middleware, the middleware obtains the first request from the first application, and the software cryptography module allocates a first key and a corresponding first key identifier to the first application. Alternatively, when the first module includes middleware, the middleware obtains the first request of the first application, determines a first key identifier for the first application, and the software cryptography module determines the first key based on the first key identifier; Alternatively, when the first module includes an Applet, the Applet obtains a first request from the first application, and the Applet assigns the first key and a corresponding first key identifier to the first application.
6. The method according to claim 5, characterized in that, The applet includes a first applet and a second applet; The first applet receives a first key acquisition request, the first applet sends a second key acquisition request to the second applet, the second applet provides the first applet with the first key, and the first applet generates the second key based on the first key; Alternatively, the first applet receives a first key retrieval request, the first applet sends a second key retrieval request to the second applet, the second applet retrieves the first key, generates a second key based on the first key, and provides the second key to the first applet.
7. The method according to claim 6, characterized in that, The first Applet obtains the first key identifier based on the first key acquisition request, or the first Applet assigns the first key identifier.
8. The method according to claim 6 or 7, characterized in that, The second key acquisition request includes the first key identifier.
9. The method according to claim 6 or 7, characterized in that, The first applet returns the first key identifier to the middleware or the first application.
10. The method according to claim 6, characterized in that, The first applet obtains the first instruction information based on the first key acquisition request, or the first applet determines the first instruction information.
11. The method according to claim 9, characterized in that, The second key acquisition request also includes first indication information.
12. The method according to claim 1 or 2, characterized in that, The multiple keys are stored in multiple key pools of the terminal.
13. The method according to claim 1, characterized in that, The first key identifier is carried in a first message, which also includes first indication information.
14. A key processing method, characterized in that, Applied to a first device, characterized in that it comprises: Among the multiple keys stored in the first device, a first key is assigned to a first application supported by the first device; wherein, the multiple keys are keys shared between the first device and the terminal; Among the multiple keys stored in the first device, a first key is assigned to a first application supported by the first device, including: The first key identifier sent by the receiving terminal; Obtain the first key based on the first key identifier; The first device includes a first platform and multiple second platforms, with different second platforms corresponding to different applications; The second platform acquires a first message sent by the terminal; the first message includes a first key identifier corresponding to the first key; The second platform sends a second message to the first platform, the second message including the first key identifier; The second platform communicates securely with the first application on the terminal using the first key or a second key generated based on the first key; The first platform obtains the first key based on the first key identifier; The first platform sends the first key or a second key generated based on the first key to the second platform.
15. The method according to claim 14, characterized in that, The method further includes: A second key is generated based on the first key; wherein the second key is a key shared between the first device and the terminal.
16. The method according to claim 14, characterized in that, The first message also includes first indication information, which is used to indicate the generation of a second key based on the first key.
17. The method according to claim 14, characterized in that, The first message also includes first indication information, and the second message also includes first indication information; The first platform generates a second key based on the first key according to the first instruction information.
18. The method according to claim 14, characterized in that, The method further includes: The second platform generates a second key based on the first key sent by the first platform.
19. The method according to claim 18, characterized in that, The first message also includes first indication information, and the method further includes: The second platform generates a second key based on the first key according to the first instruction information.
20. The method according to any one of claims 14-19, characterized in that, The multiple keys are stored in one or more key pools of the first device.
21. The method according to claim 20, characterized in that, Multiple keys are stored in one or more key pools on the first platform.
22. A key processing device, applied to a terminal, characterized in that, include: First transceiver unit and first processing unit; The first processing unit is configured to assign a first key to a first application on the terminal from among a plurality of keys stored in the terminal; wherein the plurality of stored keys are keys shared between the terminal and the first device; The first processing unit is further configured to obtain a first request from the first application, allocate the first key and a corresponding first key identifier to the first application, return the first key identifier to the first application, and install multiple applications on the terminal; The first transceiver unit is used to send the first key identifier to the first device; The first device is configured to allocate the first key for the first application supported by the first device from the plurality of keys stored in the first device according to the first key identifier; The first device includes a first platform and multiple second platforms, with different second platforms corresponding to different applications. The second platform is used to obtain the first key identifier sent by the terminal. The second platform is also used to send the first key identifier to the first platform. The second platform is also used to perform secure communication with the first application on the terminal through the first key or a second key generated based on the first key. The first platform is used to obtain the first key according to the first key identifier. The first platform is also used to send the first key or a second key generated based on the first key to the second platform.
23. A key processing device, applied to a first device, characterized in that, include: Second transceiver unit and second processing unit; The second processing unit is configured to allocate a first key for a first application supported by the first device from among a plurality of keys stored in the first device; wherein the plurality of keys are keys shared between the first device and the terminal; The second transceiver unit is used to receive the first key identifier sent by the terminal; The second processing unit is further configured to obtain the first key based on the first key identifier; The first device includes a first platform and multiple second platforms, with different second platforms corresponding to different applications; The second platform is used to obtain a first message sent by the terminal; the first message includes a first key identifier corresponding to the first key; The second platform is also used to send a second message to the first platform, the second message including the first key identifier; The second platform is also used to securely communicate with the first application on the terminal using the first key or a second key generated based on the first key; The first platform is used to obtain the first key based on the first key identifier; The first platform is also used to send the first key or a second key generated based on the first key to the second platform.
24. A communication device, characterized in that, It includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the method as described in any one of claims 1 to 21.
25. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the method as described in any one of claims 1 to 21.
26. A computer program product, characterized in that, Includes computer instructions that, when executed by a processor, implement the steps of the method as described in any one of claims 1 to 21.
Citation Information
Patent Citations
Key management method and device, equipment and storage medium
CN117439734A
Communication network encryption method and system, electronic equipment and storage medium
CN117858081A