A key management system, method, device, storage medium and equipment
By injecting a sectional program into each data storage server of the data storage service cluster and managing keys, the problem of the encryption protection of the data storage service cluster in the prior art requires transformation and introduction of an independent key management system, and efficient and stable key management is achieved.
Patent Information
- Application Number
- CN202411757741.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-02
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-12-02
AI Technical Summary
When the prior art realizes encryption protection of data storage service clusters, it is necessary to upgrade and transform the entire cluster, affect business stability, and introduce an independent key management system to lead to online access performance bottlenecks.
By injecting a sectional program into each data storage server of the data storage service cluster, and using the sectional program engine to manage the keys, the data is encrypted and decrypted, avoiding the transformation of the entire cluster and the introduction of an independent key management system.
It realizes that key management can be managed without the need to transform the data storage service cluster, avoids performance bottlenecks, and improves data security and system stability.
Smart Images

Figure CN119232507B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a key management system, method, apparatus, storage medium and device. Background Art
[0002] Currently, more and more companies are using data storage service clusters consisting of multiple data storage servers to manage the growing amount of data. As companies pay more and more attention to data security, a large number of data storage servers need to encrypt and protect the stored data to prevent the leakage of important data of users and companies, which brings huge security and compliance risks to companies.
[0003] In the existing technology, to realize the encryption protection capability of the data storage service cluster, the entire data storage service cluster needs to be upgraded and reconstructed, which will affect the existing business and have a great stability risk. In addition, it is generally necessary to introduce a key management system independent of the data storage service cluster to provide key management and encryption and decryption calculations, which also brings about the performance bottleneck problem of online access to the key management system. Summary of the invention
[0004] The embodiments of this specification provide a key management system, method, device, storage medium and electronic device to partially solve the problems existing in the above-mentioned prior art.
[0005] The embodiments of this specification adopt the following technical solutions:
[0006] This specification provides a key management system, the system comprising: a slice server, a data storage service cluster; the data storage service cluster comprises a plurality of data storage servers;
[0007] The data storage server is used to run a main program, and the main program is used to manage data;
[0008] The aspect server is used to store the aspect points set in the main program of each data storage server through the aspect program engine, and inject the aspect program into the main program of the data storage server according to the aspect points. The aspect program is used to manage the key for the data storage server when the data storage server runs the main program, and the key is used to encrypt and decrypt the data managed by the data storage server.
[0009] Optionally, the aspect program is used to manage keys for the data storage server according to the key management configuration carried in the aspect program;
[0010] The aspect program engine is also used to send the updated key management configuration to the aspect program injected into the data storage server, so that the aspect program manages the key of the data storage server according to the updated key management configuration.
[0011] This specification provides a key management method, which is applied to each data storage server in a data storage service cluster; the aspect program engine pre-injects the aspect program into the main program of the data storage server; the method includes:
[0012] The data storage server runs a main program for managing data;
[0013] When the execution reaches the cutting point in the main program for injecting the cutting program, the cutting program is executed;
[0014] The key is managed by the running slice program, and the key is used to encrypt and decrypt the data managed by the data storage server.
[0015] Optionally, the cut point includes a first cut point located at a server initialization function in the main program; the aspect program injected at the first cut point is a first aspect program;
[0016] When the main program is run to the cut point for injecting the cut program, the cut program is run, specifically including:
[0017] When the server initialization function is run to initialize the data storage server, the first slice program is run;
[0018] Managing keys by running the aspect program includes:
[0019] Generate a software trusted execution environment STEE by running the first aspect program;
[0020] Keys are managed based on the STEE.
[0021] Optionally, managing the key based on the STEE specifically includes:
[0022] Acquire device information of the data storage server;
[0023] According to the device information, a machine key corresponding to the data storage server is generated in the STEE and stored in an area corresponding to the STEE in the volatile storage medium of the data storage server.
[0024] Optionally, the cut point includes a second cut point located at a data write function in the main program; the section program injected at the second cut point is a second section program;
[0025] When the main program is run to the cut point for injecting the cut program, the cut program is run, specifically including:
[0026] When the data write function is executed to make the data storage server write the data to be written into the non-volatile storage medium, the second section program is executed;
[0027] Managing keys by running the aspect program includes:
[0028] Obtaining the machine key by running the second aspect program;
[0029] Based on the machine key, a data key corresponding to the data to be written is generated.
[0030] Optionally, the method further comprises:
[0031] Using the data key corresponding to the data to be written, encrypting the data to be written to obtain ciphertext data, and using the machine key to encrypt the data key corresponding to the data to be written to obtain a ciphertext key;
[0032] The ciphertext data and the ciphertext key are stored correspondingly in a non-volatile storage medium of the data storage server.
[0033] Optionally, the cut point includes a third cut point located at a data read function in the main program; the section program injected at the third cut point is a third section program;
[0034] When the main program is run to the cut point for injecting the cut program, the cut program is run, specifically including:
[0035] When the data read function is executed to enable the data storage server to read the data to be read from the non-volatile storage medium, the third section program is executed;
[0036] Managing keys by running the aspect program includes:
[0037] Obtaining the machine key by running the third aspect program, and reading the ciphertext key corresponding to the data to be read from the non-volatile storage medium;
[0038] Based on the machine key, the ciphertext key corresponding to the data to be read is decrypted to obtain the data key corresponding to the data to be read.
[0039] Optionally, the method further comprises:
[0040] Reading the to-be-read data from the non-volatile storage medium;
[0041] The data to be read is decrypted using a data key corresponding to the data to be read.
[0042] Optionally, the method further comprises:
[0043] When the data key needs to be replaced, the data corresponding to the data key and the ciphertext key corresponding to the data key are read from the non-volatile storage medium;
[0044] Decrypting the ciphertext key using the machine key to obtain the data key;
[0045] Decrypting the data corresponding to the read data key using the data key to obtain plaintext data;
[0046] Regenerate a data key corresponding to the plaintext data based on the machine key as an update key;
[0047] Encrypting the plaintext data using the update key to obtain update ciphertext data, and encrypting the update key using the machine key to obtain an update ciphertext key;
[0048] The updated ciphertext data and the updated ciphertext key are correspondingly stored in a non-volatile storage medium of the data storage server.
[0049] Optionally, the method further comprises:
[0050] When the machine key needs to be replaced, all ciphertext keys are read from the non-volatile storage medium, and the machine key is regenerated to obtain an updated machine key;
[0051] For each ciphertext key, the machine key before the update is used to decrypt the ciphertext key to obtain the data key corresponding to the ciphertext key, and the data key corresponding to the ciphertext key is encrypted using the updated machine key to obtain the updated ciphertext key, a correspondence is established between the updated ciphertext key and the ciphertext data corresponding to the ciphertext key before the update, and the updated ciphertext key is stored in the non-volatile storage medium of the data storage server.
[0052] Optionally, the method further comprises:
[0053] When the machine key needs to be replaced, all ciphertext keys and ciphertext data corresponding to all ciphertext keys are read from the non-volatile storage medium, and the machine key is regenerated to obtain an updated machine key;
[0054] For each ciphertext key, the machine key before the update is used to decrypt the ciphertext key to obtain the data key corresponding to the ciphertext key; the data key corresponding to the ciphertext key is used to decrypt the ciphertext data corresponding to the ciphertext key to obtain the plaintext data; the data key is regenerated based on the updated machine key as the update key; the plaintext data is encrypted using the update key to obtain updated ciphertext data, and the update key is encrypted using the updated machine key to obtain an updated ciphertext key; the updated ciphertext data and the updated ciphertext key are stored correspondingly in the non-volatile storage medium of the data storage server.
[0055] This specification provides a key management device, which is applied to each data storage server in a data storage service cluster; a slice program engine pre-injects a slice program into a main program of the device; the device includes:
[0056] The main program running module runs the main program for managing data;
[0057] A section running module, when the main program running module runs to a section point in the main program for injecting the section program, runs the section program;
[0058] A management module is used to manage keys through the running aspect program, and the keys are used to encrypt and decrypt data managed by the data storage server.
[0059] This specification provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned medical information management method is implemented.
[0060] The present specification provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned key management method when executing the program.
[0061] At least one of the above technical solutions adopted in the embodiments of this specification can achieve the following beneficial effects:
[0062] An embodiment of the present specification discloses a key management method. This method injects an aspect program into each data storage server in a data storage service cluster, and uses the injected aspect program to manage respective keys for each data storage server. There is no need to modify the entire data storage service cluster. Moreover, the aspect program injected into a data storage server can manage keys for the data storage server. Therefore, there is no need to introduce an independent key management system to provide key management services for the entire data storage service cluster, which will not cause performance bottleneck problems caused by a large number of online accesses to the key management system. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] The drawings described herein are used to provide a further understanding of this specification and constitute a part of this specification. The illustrative embodiments and descriptions of this specification are used to explain this specification and do not constitute an improper limitation on this specification. In the drawings:
[0064] Figure 1 A schematic diagram of a key management system provided in an embodiment of this specification;
[0065] Figure 2 A schematic diagram of a key management process provided in an embodiment of this specification;
[0066] Figure 3 A schematic diagram of a key management device provided in an embodiment of this specification;
[0067] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this specification. DETAILED DESCRIPTION
[0068] In order to make the purpose, technical solutions and advantages of this specification more clear, the technical solutions of this specification will be clearly and completely described below in combination with the specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this specification.
[0069] The technical solutions provided by the embodiments of this specification are described in detail below in conjunction with the accompanying drawings.
[0070] The embodiment of this specification provides a key management system, such as Figure 1 As shown, it includes an aspect server and a data storage service cluster. The data storage service cluster includes multiple data storage servers. The aspect server stores the preset cut points in the main program of each data storage server through the aspect program engine installed therein, and injects the aspect program into the main program of each data storage server according to the cut point. When the data storage server runs the main program for managing data, if it runs to the cut point of the main program, it runs the aspect program injected at the cut point, and manages the key of the data storage server itself through the running aspect program, and the key is used to encrypt and decrypt the data managed by the data storage server.
[0071] Based on the above system, the embodiment of this specification provides a key management method, such as Figure 2 shown.
[0072] Figure 2A schematic diagram of a key management process provided in this specification may include the following steps:
[0073] S200: The data storage server runs a main program for managing data.
[0074] In an embodiment of the present specification, each data storage server in the data storage service cluster is used to manage data, and the management data includes both read data and write data, that is, when a data acquisition request is received, data is read from its own non-volatile storage medium, and when a data write request is received, data is written to its own non-volatile storage medium. Each data storage server manages data through its own main program. The main program includes: a server initialization function, a write data function, and a read data function. Among them, the server initialization function is used to initialize the data storage server, the write data function is used to write data to its own non-volatile storage medium in response to a data write request, and the read data function is used to read data from its own non-volatile storage medium in response to a data acquisition request.
[0075] In actual application scenarios, in order to ensure the security of data managed by the data storage server, the data storage server is often required to encrypt and decrypt the data when reading and writing data. Moreover, the keys used for encryption and decryption must be kept secure. Therefore, it is necessary to generate a Software Trusted Execution Environment (STEE) when the data storage server is initialized, and at least some keys are managed in the STEE.
[0076] Thus, the cut points can be set in the server initialization function, data writing function and data reading function of each data storage server, and the cut points can be stored in the form of a list such as Figure 1 In the aspect server shown, the aspect server can inject the aspect program into the main program of each data storage server according to the saved aspect points through its aspect program engine.
[0077] S202: When the main program reaches the cutting point for injecting the cutting program, the cutting program is run.
[0078] S204: managing a key through the running aspect program, wherein the key is used to encrypt and decrypt data managed by the data storage server.
[0079] For any data storage server, when it runs the main program to the cutting point position, it switches to running the cutting program, and manages the key of the data storage server through the running cutting program, including but not limited to generating STEE, generating keys in STEE, and using keys for encryption and decryption when reading and writing data.
[0080] Through the above method, there is no need to transform the entire data storage service cluster. You only need to inject enhanced code (i.e., aspect program) into each data storage server through the aspect program engine to achieve the upgrade of data management of the entire data storage service cluster. Moreover, the aspect program injected into a data storage server can manage the key for the data storage server, so there is no need to introduce an independent key management system to provide key management services for the entire data storage service cluster, which will not bring about the performance bottleneck problem of a large number of online accesses to the key management system.
[0081] The following describes in detail the method of using aspect programs to manage keys in the data storage server in the three scenarios of server initialization, writing data, and reading data to assist in data management.
[0082] 1. Server initialization.
[0083] As mentioned above, in order to ensure the security of the key, the data storage server needs to generate a STEE when the data storage server is initialized. At least part of the key is managed in the STEE. Therefore, a pointcut can be set in advance at the server initialization function in the main program, which is recorded as the first pointcut. The aspect program injected by the aspect program engine at the first pointcut is called the first aspect program.
[0084] When the data storage server runs the server initialization function to initialize the data storage server itself, the injected first aspect program is run, and the STEE is generated by the running first aspect program, that is, the STEE is pulled up by the first aspect program. At least part of the key can be managed in the STEE later.
[0085] Furthermore, when managing keys in STEE, the data storage server can still generate a machine key corresponding to the data storage server by running the first aspect program. Specifically, the device information of the data storage server can be obtained through the first aspect program, including one or a combination of various device information that can uniquely identify the data storage server, such as the serial number, MAC address, and IP address of the data storage server. Then, based on the acquired device information, the machine key corresponding to the data storage server is generated in STEE and stored in the area corresponding to the STEE in the volatile storage medium (such as memory) of the data storage server.
[0086] It should be noted that since the STEE in this specification is a software trusted execution environment pulled up by the first aspect program, the STEE needs to be allocated an area in the data storage server's own memory specifically for STEE use, and this area is prohibited from being accessed by any hardware or software except for the injected aspect programs. The machine key is generated based on the device information of the data storage server, that is, the machine keys corresponding to different data storage servers are not the same and are unique. Therefore, storing the machine key in a volatile storage medium so that it has the characteristic of being destroyed when power is off can enhance the security of the machine key.
[0087] 2. Write data.
[0088] When the data storage server receives a data write request, it can run the write data function in its main program to write the data to be written into the non-volatile storage medium of the data storage server. Therefore, a cut point can be set in advance at the write data function in the main program, which is recorded as the second cut point. The cut program injected by the cut program engine at the second cut point is called the second cut program.
[0089] When the data storage server runs the write function, it runs the second aspect program, and obtains the machine key in the memory area corresponding to the STEE through the second aspect program, and generates a data key corresponding to the data to be written based on the machine key. Specifically, the second aspect program can generate a random number, and generate a data key corresponding to the data to be written based on the random number and the machine key.
[0090] Therefore, when writing data, the data key corresponding to the data to be written is used to encrypt the data to be written to obtain ciphertext data, and the data key corresponding to the data to be written is encrypted using the machine key to obtain the ciphertext key. Finally, the ciphertext data and the ciphertext key are stored correspondingly in the non-volatile storage medium (such as a hard disk) of the data storage server.
[0091] It should be noted that each time the data storage server in this application receives a data write request, that is, each time data needs to be written, it will call the write data function, and each time the write data function is called and run, the second aspect program will be run. It can be seen that although the machine key of a data storage server in this application is unchanged, the data key used each time it writes data (regardless of whether the data written each time is one or a batch) is different, which can achieve the effect of "one number and one secret", further improving the security of the data.
[0092] 3. Read data.
[0093] When the data storage server receives a data acquisition request, it can run the data read function in its main program to read the data to be read from the non-volatile storage medium of the data storage server. Therefore, a cut point can be set in advance at the data read function in the main program, which is recorded as the third cut point. The cut program injected by the cut program engine at the third cut point is called the third cut program.
[0094] When the data storage server runs the data reading function, the third aspect program is run, the machine key is obtained through the running third aspect program, and the ciphertext key corresponding to the data to be read is read from the non-volatile storage medium, and then the ciphertext key corresponding to the data to be read is decrypted based on the machine key to obtain the data key corresponding to the data to be read. Then, the data to be read can be read from the non-volatile storage medium, and the data key corresponding to the data to be read is used to decrypt the data to be read to obtain the plaintext data.
[0095] Through the above method, in the scenarios of data storage server initialization, data writing and data reading, the key can be managed for the data storage server through a section program such as , and the data storage server can be assisted to use the key management data. As for the key, it may be necessary to replace the key in some cases. For example, in order to improve the security of the key, at least one of the machine key and the data key can be replaced according to a set period, or when at least one of the machine key and the data key is leaked, the leaked key can be replaced urgently. The following are explained separately.
[0096] Since the data key has encrypted certain data, and the data key itself is encrypted by the machine key and stored in the non-volatile storage medium corresponding to these data, when replacing the data key, it is necessary to read the data corresponding to the data key and the ciphertext key corresponding to the data key (encrypted by the machine key) from the non-volatile storage medium, and then use the machine key to decrypt the ciphertext key to obtain the plaintext data key, use the plaintext data key to decrypt the data corresponding to the read data key to obtain the plaintext data, and then regenerate the data key corresponding to the plaintext data based on the machine key as the update key. Finally, the plaintext data is re-encrypted and stored using the update key, that is, the plaintext data is encrypted using the update key to obtain the updated ciphertext data, and the update key is encrypted using the machine key to obtain the updated ciphertext key, and the updated ciphertext data and the updated ciphertext key are stored in the non-volatile storage medium of the data storage server. In this way, the replacement of the data key is completed, not only the data key is replaced, but also the original plaintext data is re-encrypted using the new data key. This method is not only applicable to the periodic replacement of data keys, but also to the emergency replacement of data keys when data keys are leaked.
[0097] As for the machine key, if the machine key is only replaced regularly and the machine key itself has not been leaked, all ciphertext keys can be read from the non-volatile storage medium, and the machine key can be regenerated to obtain the updated machine key. Then, for each ciphertext key, the machine key before the update is used to decrypt the ciphertext key to obtain the data key corresponding to the ciphertext key, and the data key corresponding to the ciphertext key is encrypted using the updated machine key to obtain the updated ciphertext key, and the corresponding relationship between the updated ciphertext key and the ciphertext data corresponding to the ciphertext key before the update is established, and the updated ciphertext key is stored in the non-volatile storage medium of the data storage server. In other words, when the machine key has not been leaked and is only replaced regularly, only the machine key needs to be replaced, and no data key needs to be replaced. All the original data keys are re-encrypted using the replaced machine key, and then the re-encrypted data key is stored back in the non-volatile storage medium while maintaining the original corresponding relationship with the ciphertext data, and there is no need to re-encrypt the stored ciphertext data.
[0098] When the machine key itself is leaked and needs to be replaced urgently, in order to ensure data security, after replacing the machine key, all data keys must also be replaced and the original ciphertext data must be re-encrypted using the replaced data key.
[0099] Specifically, all ciphertext keys and ciphertext data corresponding to all ciphertext keys are read from the non-volatile storage medium, and the machine key is regenerated to obtain the updated machine key. Then, for each ciphertext key, the machine key before the update is used to decrypt the ciphertext key to obtain the data key corresponding to the ciphertext key, and then the data key corresponding to the ciphertext key is used to decrypt the ciphertext data corresponding to the ciphertext key to obtain the plaintext data. At this point, the original data key and the original ciphertext data have been decrypted into plaintext form.
[0100] Thus, the data key is regenerated based on the updated machine key as the updated key, the plaintext data is encrypted with the updated key to obtain updated ciphertext data, and the updated key is encrypted with the updated machine key to obtain an updated ciphertext key, and finally the updated ciphertext data and the updated ciphertext key are correspondingly stored in the non-volatile storage medium of the data storage server. At this point, the machine key and the data key have been replaced, the stored ciphertext key is encrypted by the replaced machine key, and the stored ciphertext data is also encrypted by the replaced data key, which can ensure data security.
[0101] In addition, since in the above method, the aspect program manages the key for the data storage server where it is located according to the default key management configuration it carries (the default key management configuration is carried in the aspect program by the aspect program engine when the aspect program is injected), therefore, in order to facilitate the rapid change of the key management configuration of the aspect programs of all data storage servers in the data storage service cluster, the aspect program engine in the aspect server can also send the updated key management configuration to the aspect programs injected into each data storage server at any time, so that the aspect program manages the key for the data storage server according to the updated key management configuration, so as to achieve the effect of hot configuration modification without restarting the data storage server when changing the configuration.
[0102] The above is a key management method and system provided in the embodiments of this specification. Based on the same idea, this specification also provides corresponding devices, storage media and electronic devices.
[0103] Figure 3 A schematic diagram of a key management device provided in an embodiment of the present specification, the key management device is applied to each data storage server in a data storage service cluster; the aspect program engine pre-injects the aspect program into the main program of the device; the device includes:
[0104] A main program running module 301 runs a main program for managing data;
[0105] A section running module 302 runs the section program when the main program running module 301 runs to a section point in the main program for injecting the section program;
[0106] The management module 303 is used to manage the key through the running aspect program, and the key is used to encrypt and decrypt the data managed by the data storage server.
[0107] Optionally, the cut point includes a first cut point located at a server initialization function in the main program; the aspect program injected at the first cut point is a first aspect program;
[0108] The aspect running module 302 is specifically used to run the first aspect program when running the server initialization function to initialize the data storage server;
[0109] The management module 303 is specifically configured to generate a software trusted execution environment (STEE) by running the first aspect program; and manage keys based on the STEE.
[0110] Optionally, the management module 303 is specifically used to obtain device information of the data storage server; based on the device information, generate a machine key corresponding to the data storage server in the STEE, and store it in an area corresponding to the STEE in the volatile storage medium of the data storage server.
[0111] Optionally, the cut point includes a second cut point located at a data write function in the main program; the section program injected at the second cut point is a second section program;
[0112] The aspect running module 302 is specifically used to run the second aspect program when running the write data function to enable the data storage server to write the data to be written into the non-volatile storage medium;
[0113] The management module 303 is specifically configured to obtain the machine key by running the second slice program; and generate a data key corresponding to the data to be written based on the machine key.
[0114] Optionally, the management module 303 is also used to encrypt the data to be written using the data key corresponding to the data to be written to obtain ciphertext data, and to encrypt the data key corresponding to the data to be written using a machine key to obtain a ciphertext key; and store the ciphertext data and the ciphertext key correspondingly in the non-volatile storage medium of the data storage server.
[0115] Optionally, the cut point includes a third cut point located at a data read function in the main program; the section program injected at the third cut point is a third section program;
[0116] The aspect running module 302 is specifically configured to run the third aspect program when running the data reading function to enable the data storage server to read the data to be read from the non-volatile storage medium;
[0117] The management module 303 is specifically used to obtain the machine key by running the third aspect program, and read the ciphertext key corresponding to the data to be read from the non-volatile storage medium; based on the machine key, the ciphertext key corresponding to the data to be read is decrypted to obtain the data key corresponding to the data to be read.
[0118] Optionally, the management module 303 is further configured to read the data to be read from the non-volatile storage medium; and decrypt the data to be read using a data key corresponding to the data to be read.
[0119] Optionally, the management module 303 is also used to, when the data key needs to be replaced, read the data corresponding to the data key and the ciphertext key corresponding to the data key from the non-volatile storage medium; use the machine key to decrypt the ciphertext key to obtain the data key; use the data key to decrypt the data corresponding to the read data key to obtain plaintext data; regenerate the data key corresponding to the plaintext data based on the machine key as an update key; use the update key to encrypt the plaintext data to obtain updated ciphertext data, and use the machine key to encrypt the update key to obtain an updated ciphertext key; store the updated ciphertext data and the updated ciphertext key correspondingly in the non-volatile storage medium of the data storage server.
[0120] Optionally, the management module 303 is also used to, when the machine key needs to be replaced, read all ciphertext keys from the non-volatile storage medium and regenerate the machine key to obtain an updated machine key; for each ciphertext key, use the machine key before the update to decrypt the ciphertext key to obtain a data key corresponding to the ciphertext key, use the updated machine key to encrypt the data key corresponding to the ciphertext key to obtain an updated ciphertext key, establish a correspondence between the updated ciphertext key and the ciphertext data corresponding to the ciphertext key before the update, and store the updated ciphertext key in the non-volatile storage medium of the data storage server.
[0121] Optionally, the management module 303 is also used to, when the machine key needs to be replaced, read all ciphertext keys and the ciphertext data corresponding to all ciphertext keys from the non-volatile storage medium, and regenerate the machine key to obtain an updated machine key; for each ciphertext key, use the machine key before the update to decrypt the ciphertext key to obtain the data key corresponding to the ciphertext key; use the data key corresponding to the ciphertext key to decrypt the ciphertext data corresponding to the ciphertext key to obtain plaintext data; regenerate the data key based on the updated machine key as an updated key; use the updated key to encrypt the plaintext data to obtain updated ciphertext data, and use the updated machine key to encrypt the updated key to obtain an updated ciphertext key; store the updated ciphertext data and the updated ciphertext key correspondingly in the non-volatile storage medium of the data storage server.
[0122] This specification also provides a computer-readable storage medium, wherein the storage medium stores a computer program, and when the computer program is executed by a processor, it can be used to perform the above Figure 1 Provides key management methods.
[0123] based on Figure 1Based on the Figure 1 The key management method shown in the present specification also provides Figure 4 The structural diagram of the electronic device shown in FIG. Figure 4 At the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may also include other hardware required for the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to achieve the above Figure 1 The key management method described.
[0124] Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc., that is to say, the executor of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0125] In the 1990s, it was very clear whether the improvement of a technology was hardware improvement (for example, improvement of the circuit structure of diodes, transistors, switches, etc.) or software improvement (improvement of the method flow). However, with the development of technology, many improvements of the method flow today can be regarded as direct improvements of the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that the improvement of a method flow cannot be implemented with hardware entity modules. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to ask chip manufacturers to design and make dedicated integrated circuit chips. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.
[0126] The controller may be implemented in any suitable manner, for example, the controller may take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (e.g., software or firmware) executable by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320, and the memory controller may also be implemented as part of the control logic of the memory. It is also known to those skilled in the art that, in addition to implementing the controller in a purely computer-readable program code manner, the controller may be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, such a controller may be considered as a hardware component, and the devices for implementing various functions included therein may also be considered as structures within the hardware component. Or even, the devices for implementing various functions may be considered as both software modules for implementing the method and structures within the hardware component.
[0127] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0128] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0129] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0130] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0131] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0132] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0133] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0134] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0135] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0136] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0137] It should be understood by those skilled in the art that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0138] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0139] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0140] The above description is only an embodiment of the present specification and is not intended to limit the present specification. For those skilled in the art, the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of the claims of the present specification.
Claims
1. A key management system, the system comprising: Aspect servers and data storage service clusters; The data storage service cluster includes multiple data storage servers; The data storage server is used to run a main program, and the main program is used to manage data; The aspect server is used to store the aspect points set in the main program of each data storage server through the aspect program engine, and inject the aspect program into the main program of the data storage server according to the aspect point. The aspect program is used to manage the key for the data storage server when the data storage server runs the main program. The key includes a machine key and a data key for encrypting and decrypting the data managed by the data storage server. The machine keys corresponding to different data storage servers are different, and the data keys used each time data is written to the data storage server are different. Among them, the data storage server is used to store the ciphertext key and the ciphertext data corresponding to the ciphertext key, the ciphertext key is obtained by encrypting the data key using the machine key, and the ciphertext data is obtained by encrypting the data to be written corresponding to the data key using the data key.
2. The system of claim 1, wherein the aspect program is used to manage keys for the data storage server according to the key management configuration carried in the aspect program; The aspect server is also used to send the updated key management configuration to the aspect program injected into the data storage server through the aspect program engine, so that the aspect program manages the key for the data storage server according to the updated key management configuration.
3. A key management method, the method being applied to each data storage server in a data storage service cluster; The aspect program engine injects the aspect program into the main program of the data storage server in advance; the method comprises: The data storage server runs a main program for managing data; When the execution reaches the cutting point in the main program for injecting the cutting program, the cutting program is executed; The key is managed by the running aspect program, and the key includes a machine key and a data key for encrypting and decrypting data managed by the data storage server. The machine keys corresponding to different data storage servers are different, and the data keys used each time data is written to the data storage server are different; Among them, the data storage server is used to store the ciphertext key and the ciphertext data corresponding to the ciphertext key, the ciphertext key is obtained by encrypting the data key using the machine key, and the ciphertext data is obtained by encrypting the data to be written corresponding to the data key using the data key.
4. The method according to claim 3, wherein the cut point comprises a first cut point located at a server initialization function in the main program; the aspect program injected at the first cut point is a first aspect program; When the main program is run to the cut point for injecting the cut program, the cut program is run, specifically including: When the server initialization function is run to initialize the data storage server, the first slice program is run; Managing keys by running the aspect program includes: Generate a software trusted execution environment STEE by running the first aspect program; Keys are managed based on the STEE.
5. The method according to claim 4, managing keys based on the STEE, specifically comprising: Acquire device information of the data storage server; According to the device information, a machine key corresponding to the data storage server is generated in the STEE and stored in an area corresponding to the STEE in a volatile storage medium of the data storage server.
6. The method according to claim 5, wherein the cut point comprises a second cut point located at a data write function in the main program; the section program injected at the second cut point is a second section program; When the main program is run to the cut point for injecting the cut program, the cut program is run, specifically including: When the data write function is executed to make the data storage server write the data to be written into the non-volatile storage medium, the second section program is executed; Managing keys by running the aspect program includes: Obtaining the machine key by running the second aspect program; Based on the machine key, a data key corresponding to the data to be written is generated.
7. The method of claim 6, further comprising: Using the data key corresponding to the data to be written, encrypting the data to be written to obtain ciphertext data, and using the machine key to encrypt the data key corresponding to the data to be written to obtain a ciphertext key; The ciphertext data and the ciphertext key are stored correspondingly in a non-volatile storage medium of the data storage server.
8. The method according to claim 5, wherein the cut point comprises a third cut point located at a data read function in the main program; the section program injected at the third cut point is a third section program; When the main program is run to the cut point for injecting the cut program, the cut program is run, specifically including: When the data read function is executed to enable the data storage server to read the data to be read from the non-volatile storage medium, the third section program is executed; Managing keys by running the aspect program includes: Obtaining the machine key by running the third aspect program, and reading the ciphertext key corresponding to the data to be read from the non-volatile storage medium; Based on the machine key, the ciphertext key corresponding to the data to be read is decrypted to obtain the data key corresponding to the data to be read.
9. The method of claim 8, further comprising: Reading the to-be-read data from the non-volatile storage medium; The data to be read is decrypted using a data key corresponding to the data to be read.
10. The method of claim 7, further comprising: When the data key needs to be replaced, the data corresponding to the data key and the ciphertext key corresponding to the data key are read from the non-volatile storage medium; Decrypting the ciphertext key using the machine key to obtain the data key; Decrypting the data corresponding to the read data key using the data key to obtain plaintext data; Regenerate a data key corresponding to the plaintext data based on the machine key as an update key; Encrypting the plaintext data using the update key to obtain update ciphertext data, and encrypting the update key using the machine key to obtain an update ciphertext key; The updated ciphertext data and the updated ciphertext key are correspondingly stored in a non-volatile storage medium of the data storage server.
11. The method of claim 7, further comprising: When the machine key needs to be replaced, all ciphertext keys are read from the non-volatile storage medium, and the machine key is regenerated to obtain an updated machine key; For each ciphertext key, the machine key before the update is used to decrypt the ciphertext key to obtain the data key corresponding to the ciphertext key, and the data key corresponding to the ciphertext key is encrypted using the updated machine key to obtain the updated ciphertext key, a correspondence is established between the updated ciphertext key and the ciphertext data corresponding to the ciphertext key before the update, and the updated ciphertext key is stored in the non-volatile storage medium of the data storage server.
12. The method of claim 7, further comprising: When the machine key needs to be replaced, all ciphertext keys and ciphertext data corresponding to all ciphertext keys are read from the non-volatile storage medium, and the machine key is regenerated to obtain an updated machine key; For each ciphertext key, use the machine key before the update to decrypt the ciphertext key to obtain the data key corresponding to the ciphertext key; use the data key corresponding to the ciphertext key to decrypt the ciphertext data corresponding to the ciphertext key to obtain the plaintext data; regenerate a data key based on the updated machine key as an updated key; Encrypting the plaintext data using the updated key to obtain updated ciphertext data, and encrypting the updated key using the updated machine key to obtain an updated ciphertext key; The updated ciphertext data and the updated ciphertext key are correspondingly stored in a non-volatile storage medium of the data storage server.
13. A key management device, the device being applied to each data storage server in a data storage service cluster; The aspect program engine injects the aspect program into the main program of the device in advance; the device comprises: The main program running module runs the main program for managing data; A section running module, when the main program running module runs to a section point in the main program for injecting the section program, runs the section program; A management module, used to manage keys through the running aspect program, wherein the keys include a machine key and a data key used to encrypt and decrypt data managed by the data storage server, wherein different machine keys correspond to different data storage servers, and different data keys are used each time data is written to the data storage server; Among them, the data storage server is used to store the ciphertext key and the ciphertext data corresponding to the ciphertext key, the ciphertext key is obtained by encrypting the data key using the machine key, and the ciphertext data is obtained by encrypting the data to be written corresponding to the data key using the data key.
14. A computer-readable storage medium storing a computer program, wherein the computer program implements the method according to any one of claims 3 to 12 when executed by a processor.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 3 to 12 when executing the program.
Citation Information
Patent Citations
Cloud storage data encryption and decryption methods and apparatus, medium and device
WO2024164742A1