A key supplement method for high-traffic data centers

Through the key supplement method for large-traffic data centers, scrambling processing and independent physical storage media are used to solve the problem of insufficient supplement speed and security in the existing methods, and the reliability of fast and secure key supplementation and large-data volume keys are achieved.

CN119135345BActive Publication Date: 2025-05-23MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411266228.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-11
Publication Date
2025-05-23
Estimated Expiration
2044-09-11

AI Technical Summary

Technical Problem

When facing large-traffic data centers, the existing key supplementation method is insufficient in supplement speed and security, which cannot meet the needs of large-scale and high-frequency key updates, and poses network security threats and physical transmission risks.

Method used

A key supplement method for large-traffic data centers is adopted, by generating paired key files and scrambling each key file, using scrambling code S, scrambling key K and key guide G as scrambling parameters, stored in an independent physical storage medium, and descrambling and recovery of the original key file through the key center network of the data center.

Benefits of technology

It realizes the quick and secure key replenishment between large-traffic data centers, ensuring the security and reliability of keys, meeting the rapid replenishment of large-data keys, reducing operating costs and improving security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119135345B_ABST
    Figure CN119135345B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of information security technology, and specifically to a key supplement method for a large-traffic data center. The solution of the present application can safely and reliably complete the key supplement between large-traffic data centers. This supplement method can quickly supplement large-volume keys. The keys are scrambled in plain text for transportation, which ensures the security of the keys and the feasibility of calculating large amounts of data. The secure access method ensures that the key pool is reliably accessed to the key center, and the entire distribution process is reliable and trustworthy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a key supplement method for a high-traffic data center. Background Art

[0002] With the advent of the big data era, data centers, as core facilities for information processing and storage, are receiving increasing attention for their security. Key management plays a vital role in the security architecture of data centers. Especially for high-traffic data centers, efficient and secure key supplementation methods have become a technical problem that needs to be solved urgently.

[0003] At present, there are two main methods of using quantum-secure true random numbers as key supplements: online supplementation and offline supplementation.

[0004] Online replenishment: This method can usually achieve Mbps-level traffic replenishment. Although keys can be provided in real time, the replenishment speed is far from meeting the needs of large-traffic data centers. In addition, online replenishment also faces network security threats and may be attacked during transmission.

[0005] Offline supplementation: This method usually relies on mobile storage devices (such as USB flash drives, hard drives, etc.) as media for key supplementation. Although this method has certain advantages in terms of security, it is extremely inefficient and difficult to meet the needs of large-scale key updates. For servers or terminals with small traffic, this method is barely feasible, but for data centers with large traffic levels, it is completely unable to meet the needs.

[0006] These two traditional methods have obvious limitations when facing the key supplement needs of high-traffic data centers:

[0007] Insufficient replenishment speed: cannot meet large-scale, high-frequency key update needs.

[0008] Insufficient security: Online methods are subject to cybersecurity threats, and offline methods have risks during physical transmission.

[0009] In recent years, with the development of quantum cryptography, some schemes based on quantum key distribution (QKD) have been proposed. Although these schemes can provide unconditionally secure key distribution in theory, they still face many challenges in practical applications, such as quantum communication distance limitations, expensive equipment, and poor compatibility with existing infrastructure. More importantly, even the most advanced QKD system has a key generation rate that is far from meeting the needs of high-traffic data centers.

[0010] Therefore, a new key supplement method is urgently needed to meet the special needs of high-traffic data centers. Summary of the invention

[0011] Purpose of the invention: To solve the above problems, the present application discloses a key supplement method for a high-traffic data center.

[0012] Technical solution: This application discloses a key supplement method for a high-traffic data center, comprising the following steps:

[0013] Generate a pair of key files, and perform scrambling processing on each key file; the scrambling parameters used for the scrambling processing include multiple key parameters, and after the multiple key parameters are reconstructed, the scrambling parameters for restoring the original key file are obtained by calculation;

[0014] The encrypted key files and corresponding key parameters are stored in independent physical storage media, and then the physical storage media are transported to the corresponding data center and connected to the key center network of the data center;

[0015] After one data center obtains the descrambling information sent by the other data center, it uses the descrambling information to descramble and restore the original key file.

[0016] The scrambling parameters include a scrambling code S, a scrambling key K and a key guide G, wherein the scrambling code S is used to perform an XOR operation on the original key file, and the scrambling key K and the key guide G are used to reconstruct the scrambling code S.

[0017] The reconstruction process of the key parameters includes:

[0018] Obtain the scrambling key K, the intermediate parameter M and the key guide G respectively;

[0019] Using the obtained parameters, calculate the scrambling code S = scrambling key K ⊕ intermediate parameter M ⊕ key guide G.

[0020] The scrambling process includes:

[0021] Generate a random scrambling code S, whose length is less than the length of the key file F to be scrambled;

[0022] Perform XOR operation on the scramble code S and the corresponding bit of the key file F bit by bit;

[0023] The scrambling code S is used cyclically until the entire key file F is processed; the result after the XOR operation is used as the scrambled key file F';

[0024] Generate a random scrambling key K and key guide G respectively, and calculate the intermediate parameter M = scrambling key K ⊕ scrambling code S ⊕ key guide G.

[0025] In a specific solution, the independent physical storage medium includes an independent physical storage medium storing the first key pool and the second key pool respectively, and a key boot disk, wherein:

[0026] The first key pool stores the encrypted key file F', and one of the scrambling key K and the intermediate parameter M; the second key pool stores the encrypted key file F', and the other of the scrambling key K and the intermediate parameter M; the key boot disk stores the key boot G.

[0027] The lengths of the scrambling code S, the scrambling key K and the key guide G are all no greater than a preset number of bits, and the lengths of the scrambling code S, the scrambling key K and the key guide G are consistent.

[0028] The scrambling code S, scrambling key K and key guide G are all quantum true random numbers.

[0029] Beneficial effects: The solution of this application can safely and reliably complete the key supplement between data centers with large traffic volumes. This supplement method can quickly supplement large data volume keys. The key is scrambled in plain text for transportation, which ensures the security of the key and the feasibility of calculating large data volumes. The secure access method ensures that the key pool is reliably connected to the key center, and the entire distribution process is reliable and trustworthy. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 This is a flow chart of a key supplement method according to an embodiment of the present application;

[0031] Figure 2 This is a flow chart of a method for scrambling a key file F in an embodiment of the present application;

[0032] Figure 3 A flowchart of a method for reconstructing key parameters in an embodiment of the present application;

[0033] Figure 4 This is a flow chart of a method for enabling a key file in a data center in an embodiment of the present application. DETAILED DESCRIPTION

[0034] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present application.

[0035] Example 1: Figure 1 As shown, a key supplement method for a large traffic data center includes the following steps:

[0036] S101: Generate paired key files and perform scrambling processing on each key file; the scrambling parameters used for the scrambling processing include multiple key parameters, and after the multiple key parameters are reconstructed, the scrambling parameters for restoring the original key file are obtained by calculation;

[0037] In a possible implementation manner, the key file generated above is a quantum random number key file, which is generated by a random number generator (QRNG) or a quantum true random number array server including a random number generator (QRNG). Two corresponding key files are generated during the generation process, and scrambling parameters for scrambling the key files are generated corresponding to each key file. The scrambling parameters include a scrambling code S, a scrambling key K, and a key guide G, wherein the scrambling code S is used to perform an XOR operation on the original key file, and the scrambling key K and the key guide G are used to reconstruct the scrambling code S;

[0038] XOR operation can effectively obfuscate the original key data, making it difficult to directly identify or understand. Even if the attacker obtains the XORed file, the original data cannot be restored without the correct XOR key. XOR is a very simple and fast bit operation that can reduce the performance overhead of the system.

[0039] Among them, the scrambling code S, the scrambling key K and the key guide G are all quantum true random numbers, and the length of the scrambling code S is less than the length of the key file to be scrambled; using quantum true random numbers to generate the scrambling code S, the scrambling key K and the key guide G can significantly improve the security of the system. Quantum true random numbers have true randomness and unpredictability, making the scrambling process based on these parameters more difficult to crack. The length of the scrambling code S is less than the length of the key file to be scrambled, and there is no need to generate a corresponding scrambling code for each key. This can greatly reduce the space and bandwidth required to store and transmit the scrambling code, especially when processing large key files. The effect is more significant. Since the scrambling code S is short, it can be used cyclically to process the entire key file, and the scrambling and descrambling process can be accelerated, improving the overall efficiency of the system.

[0040] like Figure 2 As shown, assuming that two key files F are generated, the scrambling process of the key file F includes:

[0041] S111: performing an XOR operation on the scrambling code S and the corresponding bit of the key file F bit by bit;

[0042] S112: cyclically use the scrambling code S until the entire key file F is processed; the result after the XOR operation is used as the scrambled key file F';

[0043] S113: Generate a random scrambling key K and a key guide G respectively, and calculate an intermediate parameter M=scrambling key K⊕scrambling code S⊕key guide G.

[0044] The intermediate parameter M serves as an additional transformation layer between the scrambling key K and the actual scrambling operation. It provides an adjustable and unpredictable additional protection layer for the encryption process by increasing system complexity, improving flexibility and enhancing security without changing the basic key structure.

[0045] S102: storing the encrypted key files and corresponding key parameters in independent physical storage media respectively;

[0046] The independent physical storage medium includes an independent physical storage medium storing a first key pool and a second key pool, respectively, and a key boot disk configured corresponding to the first key pool and the second key pool, respectively, wherein:

[0047] The first key pool stores the encrypted key file F', and one of the scrambling key K and the intermediate parameter M; the second key pool stores the encrypted key file F', and the other of the scrambling key K and the intermediate parameter M; the key boot disk stores the key boot G.

[0048] The physical storage medium is then transported to the corresponding data center and connected to the key center network of the data center; the key boot disk G is stored separately from other key data, reducing the risk of all key information being leaked at the same time, and stricter access control measures can be implemented on the key boot disk to limit the personnel who can access G. Independent storage facilitates the implementation of special monitoring measures to quickly discover potential security threats.

[0049] In a possible implementation, the first key pool and the second key pool are stored in two storage devices, respectively, and the key boot disk is stored in a separate key boot disk. Then, the two storage devices and the key boot disk are transported to the corresponding data center by freight, and an iSCSI service is configured in the key center network of each data center. The IP address and port of the iSCSI (full name: Internet Small Computer System Interface) target are set, and the storage device is connected to the corresponding key center network through the iSCSI interface: compared with traditional direct-attached storage (DAS) and Fibre Channel (FC) storage, iSCSI has lower cost and simpler management.

[0050] S103: After obtaining the descrambling information sent by the other data center, one data center uses the descrambling information to descramble and restore the original key file.

[0051] Specifically include:

[0052] In the data center where the key file needs to be enabled, connect the key boot disk to the key center server.

[0053] Afterwards, the initiator data center carries its own key parameters (scrambling key K and one of the intermediate parameters M) in the descrambling request and sends it to the receiver data center; the receiver data center reconstructs the key parameters obtained with its own stored key parameters and calculates the scrambling parameters, specifically including: calculating the scrambling code S = scrambling key K ⊕ intermediate parameter M ⊕ key guide G; using the scrambling parameters to decrypt the key file F' to restore the original key file F, and calculating the file hash HF;

[0054] The receiving data center constructs a descrambling response, carries the scrambling parameters and the file hash HF, and sends the descrambling response message to the initiating data center in an encrypted form;

[0055] The sender data center descrambles its own key file F according to the scrambling parameters received, obtains the corresponding original key file, calculates the file hash H'F, and compares it with the received HF; the initiator data center notifies the receiver of the comparison result to complete the key file descrambling and consistency verification.

[0056] like Figure 3 As shown, the reconstruction process of the key parameters includes:

[0057] S121: Obtain the scrambling key K, the intermediate parameter M and the key guide G respectively;

[0058] S122: Using the acquired parameters, calculate the scrambling code S = scrambling code key K ⊕ intermediate parameter M ⊕ key guide G.

[0059] To save storage space, the lengths of the scrambling code S, scrambling key K and key boot G are not greater than the preset number of bits, and the lengths of the scrambling code S, scrambling key K and key boot G are consistent. The preset number of bits can be much smaller than the size of the key file F; if a 1GB key file is calculated with a 256-bit scrambling code S, 160PB of key scrambling boot storage requires 5GB of capacity, which is sufficient for a mobile storage.

[0060] Let's take a specific data center scenario as an example for analysis:

[0061] Storage capacity calculation:

[0062] One 42U cabinet unit can accommodate 20 storage array servers

[0063] Assume that the average storage capacity of each storage array server is 400TB

[0064] Total storage capacity of a single cabinet unit = 20*400TB = 8PB

[0065] Single transport capacity:

[0066] Assume that a transport vehicle can load 20 cabinets

[0067] Total key storage volume for a single transport = 20*8PB = 160PB

[0068] Key usage time estimate:

[0069] Assume that the data exchange capacity of the data center is 100Gbps

[0070] The usable time of the key transported by a single vehicle = 160PB / (100Gbps*60*60*24)≈155 days (about 5 months)

[0071] Annual transportation demand:

[0072] Less than 3 truckloads per year are needed to meet the key needs of the data center

[0073] Compared with traditional methods:

[0074] Offline manual supplement:

[0075] Assume that 10 TB is replenished manually each time

[0076] Requires approximately 16,000 round trips (160PB / 10TB)

[0077] Each copy takes a long time, the operation is cumbersome, and the risk is high

[0078] Online supplement:

[0079] Assuming 10Gbps dedicated fiber for online supplementation

[0080] Time required to transfer 160PB: 160PB / (10Gbps*60*60*24)≈1553 days (about 4.25 years)

[0081] It is far from enough to meet the key consumption speed of the data center.

[0082] Key generation efficiency:

[0083] Assume that the random number generation rate of a random number array server is 100Gbps

[0084] Total generation rate of 20 storage array servers = 20*100Gbps = 2Tbps

[0085] Time required to generate 160PB keys = 160PB / (2Tbps*60*60*24)≈7.75 days

[0086] Through this example, we can see that a single transport can meet the key needs of a high-traffic data center for nearly 5 months, greatly reducing the frequency of replenishment.

[0087] Compared with traditional methods, this method can provide a large number of keys at one time, fully meeting the needs of high-traffic data centers. The key generation and transportation process is fast, and the generation and transportation of 160PB keys can be completed in about a week. It reduces frequent manual operations and long-term network resource occupation, reducing operating costs. It avoids the risk of long-term online transmission, and improves security through physical isolation.

[0088] In a possible implementation, after the data centers of both parties obtain the encrypted key file, the process of the data center activating the key file includes:

[0089] When one data center needs to enable one or more files, it first initiates a descrambling request to the other data center. After descrambling, the other data center returns the scrambling code and the hash value of the descrambled file. After receiving the descrambling response, it descrambles the file with the scrambling code, calculates the file hash, and compares it with the hash in the response. If a match is found, the key file is successfully descrambled and the consistency check is successful. Then, a descrambling confirmation message is returned to the other end to complete the entire descrambling.

[0090] The specific steps include:

[0091] S201: Detect whether the corresponding key boot disk is enabled. If no key boot disk is enabled, initiate a descrambling request to the other end as the initiator, carry the file index corresponding to the first scrambling key file to be descrambled and the first key parameter held by itself, and send the descrambling request in an encrypted form;

[0092] The initiator may use the symmetric quantum key paired between it and the receiver to encrypt the descrambling request; the symmetric quantum key may be an initially preset key, or a remaining key after previous supplementation;

[0093] S202: After receiving the descrambling request, the receiver detects whether the corresponding key boot disk is enabled, and if so, obtains the third key parameter of the corresponding file from the key boot disk;

[0094] Ensure that the recipient also has the necessary security credentials (key boot disk) to establish a foundation for both parties to meet security conditions;

[0095] S203: The receiver reconstructs the scrambling parameters according to the first key parameter in the request, the second key parameter stored in the receiver, and the third key parameter; uses the reconstructed scrambling parameters to descramble its second scrambling key file to obtain the corresponding second original key file, and calculates the file hash HF; reconstructs the descrambling response, carries the scrambling parameters and the file hash HF, and sends the descrambling response message to the initiator in an encrypted form;

[0096] By reconstructing the scrambling parameters using parameters from multiple sources (the initiator, the receiver itself, and the key boot disk), security is greatly improved; even if one parameter is leaked, the entire system will not be compromised; the descrambling process and hash calculation prepare for subsequent consistency verification;

[0097] The reconstructed scrambling parameters are securely transmitted in encrypted form, so that the initiator can descramble its own key file; at the same time, the hash value is transmitted in preparation for subsequent consistency checks;

[0098] S204: After receiving the descrambling response, the initiator uses the received scrambling parameters to descramble its own first scrambling key file, obtains the corresponding first original key file, calculates the file hash H'F, and compares it with the received HF;

[0099] The initiator uses the received parameters to descramble its own file, realizing the secure activation of the key file. By calculating and comparing the hash values, it can verify whether the descrambled key files of both parties are consistent, ensuring the correctness and integrity of the key.

[0100] S205: The initiator notifies the receiver of the comparison result to complete the key file descrambling and consistency verification;

[0101] By notifying the receiving party of the comparison result, both parties can confirm that the key file has been correctly descrambled and remains consistent.

[0102] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. A key supplement method for a high-traffic data center, characterized by: The following steps are involved: Generate a pair of key files, and perform scrambling processing on each key file; the scrambling parameters used for the scrambling processing include multiple key parameters, after the multiple key parameters are reconstructed, the scrambling parameters for restoring the original key file are obtained by calculation, the multiple key parameters include a first key parameter, a second key parameter, and a third key parameter, and the scrambling parameters include a scrambling code S, a scrambling code key K, and a key guide G; The encrypted key files and corresponding key parameters are stored in independent physical storage media, and then the physical storage media are transported to the corresponding data center and connected to the key center network of the data center; After one data center obtains the descrambling information sent by the other data center, it uses the descrambling information to descramble and restore the original key file, including: In the data center where the key file needs to be enabled, connect the key boot disk to the key center server; Then, the initiator data center carries the first key parameter held by itself in the descrambling request and sends it to the receiver data center, where the first key parameter is one of the scrambling key K and the intermediate parameter M; After receiving the descrambling request, the receiving data center detects whether the corresponding key boot disk is enabled, and if so, obtains the third key parameter of the corresponding file from the key boot disk, where the third key parameter is the key boot G; The receiving data center reconstructs the scrambling parameter according to the first key parameter in the descrambling request, the second key parameter stored in the receiving data center, and the third key parameter, where the second key parameter is the other of the scrambling key K and the intermediate parameter M; The key file is decrypted using the scrambling parameters to restore the original key file.

2. The method according to claim 1, characterized in that: The scrambling parameters include a scrambling code S, a scrambling key K and a key guide G, wherein the scrambling code S is used to perform an XOR operation on the original key file, and the scrambling key K and the key guide G are used to reconstruct the scrambling code S.

3. The method according to claim 2, characterized in that: The reconstruction process of the key parameters includes: Obtain the scrambling key K, the intermediate parameter M and the key guide G respectively; Using the obtained parameters, calculate the scrambling code S = scrambling key K ⊕ intermediate parameter M ⊕ key guide G.

4. The method according to claim 3, characterized in that The scrambling process includes: Generate a random scrambling code S, whose length is less than the length of the key file F to be scrambled; Perform XOR operation on the scramble code S and the corresponding bit of the key file F bit by bit; The scrambling code S is used cyclically until the entire key file F is processed; the result after the XOR operation is used as the scrambled key file F'; Generate a random scrambling key K and key guide G respectively, and calculate the intermediate parameter M = scrambling key K ⊕ scrambling code S ⊕ key guide G.

5. The method according to claim 1, characterized in that: The independent physical storage medium comprises an independent physical storage medium storing a first key pool and a second key pool respectively, and a key boot disk, wherein: The first key pool stores the encrypted key file F', and one of the scrambling key K and the intermediate parameter M; the second key pool stores the encrypted key file F', and the other of the scrambling key K and the intermediate parameter M; the key boot disk stores the key boot G.

6. The method according to claim 2, characterized in that: The lengths of the scrambling code S, the scrambling key K and the key guide G are all no greater than a preset number of bits, and the lengths of the scrambling code S, the scrambling key K and the key guide G are consistent.

7. The method according to claim 2 or 6, characterized in that: The scrambling code S, scrambling key K and key guide G are all quantum true random numbers.

Citation Information

Patent Citations

  • Key management method, device, equipment, system and medium

    CN115085920A

  • Key supplement triggering method for quantum security communication system

    CN117714050A