Key update method, device and service system for ensuring business continuity
By employing a multimodal key mechanism and an information interaction verification mechanism during the key update process, the problem of node key inconsistency caused by network fluctuations was solved, ensuring the business continuity of financial transactions.
Patent Information
- Application Number
- CN202411353740.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-26
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-09-26
AI Technical Summary
Existing technologies suffer from the problem of inconsistent keys between different nodes due to network fluctuations or long network delays during key updates, leading to financial transaction failures.
A multimodal key mechanism is adopted, including an active key, a new key, and an old key. The keys of each node are updated sequentially through information exchange between the first and second key management nodes. A verification mechanism is set up to ensure that at least one subkey is consistent in order to guarantee that the transaction verification is successful.
In the event of network fluctuations or delays, the consistency of keys across all nodes is ensured, transaction failures are avoided, and business continuity is guaranteed.
Smart Images

Figure CN119402177B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of key management technology, and more specifically, to a key update method, apparatus, computer-readable storage medium, and business system for ensuring business continuity. Background Technology
[0002] With the gradual development of the financial industry, financial information systems have very high requirements for business continuity. Cryptographic technology is a crucial technology supporting the security of financial information systems. It is a core capability to ensure the confidentiality, integrity, authenticity, and non-repudiation of financial transaction data. Regular updates of key data are a necessary condition for realizing the security capabilities of cryptographic technology. In the key update interaction scenario between the head office and branches, key updates may fail due to network fluctuations or long network delays. As a result, inconsistencies in keys may occur during the synchronization process of key updates at various nodes, leading to transaction failures and affecting the business continuity of financial transactions.
[0003] In summary, existing password update methods suffer from transaction failures due to password inconsistencies when there are network fluctuations or long network delays. Summary of the Invention
[0004] The main objective of this application is to provide a key update method, apparatus, computer-readable storage medium, and business system to ensure business continuity, so as to at least solve the problem in the prior art where network fluctuations during the key update process cause inconsistencies in keys between different nodes, leading to transaction failures.
[0005] To achieve the above objectives, according to one aspect of this application, a key update method for ensuring business continuity is provided. The key update method is used to control a business system to perform key updates. The business system includes a first security management node and a second security management node. The first security management node manages the keys of a service node, and the second security management node manages the keys of the first security management node. The method includes: controlling the first security management node to receive a key update request from the service node and send it to the second security management node. The key update request instructs the periodic updating of keys stored in the business system. The key includes a first subkey, a second subkey, a third subkey, and target identification information. The target identification information indicates whether the second subkey is valid. If any one of the first subkey, the second subkey, and the third subkey satisfies the transaction verification performed by the second security management node on the first security management node, the transaction verification is determined to be successful. Upon receiving the key update request, the second security management node controls the second... The security management node generates and sequentially updates the second subkey and the target identifier information of the key, and generates a password delivery instruction based on the updated key and sends it to the first security management node. Upon receiving the password delivery instruction, the first security management node updates the second subkey, the first subkey, and the third subkey of the key sequentially according to the password delivery instruction, and generates a first key activation instruction based on the updated key and sends it to the second security management node. Upon receiving the first key activation instruction, the second security management node updates the first subkey, the third subkey, and the target identifier information of the key sequentially according to the first key activation instruction, and generates first feedback information and sends it to the first security management node. The first feedback information indicates that the second subkey has been successfully activated. Upon receiving the first feedback information, the first security management node delivers the updated key to the service node, completing the key update.
[0006] Optionally, after controlling the second secure management node to generate and sequentially update the second subkey of the key and the target identification information, the method further includes: controlling the second secure management node to generate a first key synchronization instruction based on the updated key and sending it to other second secure management nodes, wherein the first key synchronization instruction is used to instruct other second secure management nodes to sequentially update the second subkey of the key and the target identification information.
[0007] Optionally, after controlling the second secure management node to generate a first key synchronization instruction based on the updated key and send it to other second secure management nodes, the method further includes: when other second secure management nodes receive the first key synchronization instruction, controlling the other second secure management nodes to sequentially update the second subkey of the key and the target identifier information based on the first key synchronization instruction, and generating second feedback information to send to the second secure management nodes, wherein the second feedback information is used to indicate that the key synchronization of other second secure management nodes is successful.
[0008] Optionally, after controlling the first secure management node to sequentially update the second subkey, the first subkey, and the third subkey of the key according to the password issuance instruction, the method further includes: controlling the first secure management node to generate a second key synchronization instruction according to the updated key and sending it to other first secure management nodes, wherein the second key synchronization instruction is used to instruct other first secure management nodes to sequentially update the second subkey, the first subkey, and the third subkey of the key.
[0009] Optionally, after controlling the first secure management node to generate a second key synchronization instruction based on the updated key and send it to other first secure management nodes, the method further includes: when other first secure management nodes receive the second key synchronization instruction, controlling the other first secure management nodes to sequentially update the second subkey, the first subkey, and the third subkey of the key based on the second key synchronization instruction, and generating third feedback information to send to the first secure management node, wherein the third feedback information is used to indicate that the key synchronization of other first secure management nodes is successful.
[0010] Optionally, after controlling the second secure management node to sequentially update the first subkey, the third subkey, and the target identification information of the key according to the first key activation instruction, the method further includes: controlling the second secure management node to generate a second key activation instruction according to the updated key and sending it to other second secure management nodes, wherein the second key activation instruction is used to instruct other second secure management nodes to sequentially update the first subkey, the third subkey, and the target identification information of the key.
[0011] Optionally, after controlling the second secure pipe node to generate a second key activation instruction based on the updated key and send it to other second secure pipe nodes, the method further includes: when other second secure pipe nodes receive the second key activation instruction, controlling the other second secure pipe nodes to sequentially update the first subkey, the third subkey, and the target identification information of the key based on the second key activation instruction, and generating a fourth feedback instruction to send to the second secure pipe node, wherein the fourth feedback instruction is used to indicate that the gas pressure second secure pipe node key activation is successful.
[0012] According to another aspect of this application, a key update device for ensuring business continuity is provided. The key update device is used to control a business system to perform key updates. The business system includes a first security management node and a second security management node. The first security management node manages the keys of a service node, and the second security management node manages the keys of the first security management node. The device includes: a first control unit, used to control the first security management node to receive a key update request from the service node and send it to the second security management node. The key update request is used to instruct the periodic updating of keys stored in the business system. The key includes a first subkey, a second subkey, a third subkey, and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey, and the third subkey satisfies the transaction verification of the first security management node by the second security management node, the transaction verification is determined to be successful. A second control unit, used to control the second security management node to generate and sequentially update keys when the second security management node receives the key update request. The system comprises: a third control unit, configured to, upon receiving the password issuance instruction, control the first security management node to sequentially update the second subkey, the first subkey, and the third subkey of the key according to the password issuance instruction, and generate a first key activation instruction based on the updated key and send it to the second security management node; a fourth control unit, configured to, upon receiving the first key activation instruction, control the second security management node to sequentially update the first subkey, the third subkey, and the target identifier information of the key according to the first key activation instruction, and generate first feedback information to send to the first security management node, wherein the first feedback information indicates successful activation of the second subkey; and a fifth control unit, configured to, upon receiving the first feedback information, control the first security management node to issue the updated key to the service node, thereby completing the key update.
[0013] According to another aspect of this application, a computer-readable storage medium is provided, the computer-readable storage medium including a stored program, wherein, when the program is executed, it controls the device on which the computer-readable storage medium is located to perform any of the methods described.
[0014] According to another aspect of this application, a business system is provided, comprising: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the one or more programs including methods for performing any one of the methods described.
[0015] Applying the technical solution of this application, in the aforementioned key update method for ensuring business continuity, firstly, the first secure management node is controlled to receive the key update request from the service node and send it to the second secure management node. The key update request is used to instruct the periodic updating of the key stored in the business system. The key includes a first subkey, a second subkey, a third subkey, and target identification information. The target identification information is used to characterize whether the second subkey is effective. If any one of the first subkey, the second subkey, and the third subkey satisfies the transaction verification of the first secure management node by the second secure management node, the transaction verification is determined to be successful. Then, upon receiving the key update request, the second secure management node is controlled to generate and sequentially update the second subkey and the target identification information of the key, and generates a password distribution instruction based on the updated key and sends it to the service node. The first secure management node then, upon receiving the password distribution instruction, sequentially updates the second subkey, the first subkey, and the third subkey of the key according to the password distribution instruction, and generates a first key activation instruction based on the updated key, which is then sent to the second secure management node. Subsequently, upon receiving the first key activation instruction, the second secure management node sequentially updates the first subkey, the third subkey, and the target identifier information of the key according to the first key activation instruction, and generates first feedback information, which is sent to the first secure management node. This first feedback information indicates successful activation of the second subkey. Finally, upon receiving the first feedback information, the first secure management node distributes the updated key to the service node, completing the key update. This application sets up a multimodal key, including an active key, a new key, and an old key, as well as a flag indicating whether the new key is active. During the password update process, based on the information exchange between the first and second secure management nodes, the new key, active key, and old key stored on different nodes are updated sequentially. A verification mechanism is set based on the order of key updates, that is, disclosure is allowed as long as any subkey in the key is verified. This ensures that at least one subkey is the same among the first secure management node, the second secure management node, and the service node during the key update process to complete the verification, thus ensuring the key consistency of business transactions. This method solves the problem in the prior art where network fluctuations during the key update process cause inconsistencies in keys between different nodes, leading to transaction failures. Attached Figure Description
[0016] Figure 1A hardware structure block diagram of a mobile terminal for a key update method to ensure business continuity provided in an embodiment of this application is shown.
[0017] Figure 2 A flowchart illustrating a key update method for ensuring business continuity according to an embodiment of this application is shown.
[0018] Figure 3 A schematic diagram illustrating the interaction flow between nodes of a business system according to an embodiment of this application is shown.
[0019] Figure 4 A structural block diagram of a key update device for ensuring business continuity is shown according to an embodiment of this application.
[0020] The above figures include the following reference numerals:
[0021] 102. Processor; 104. Memory; 106. Transmission device; 108. Input / output device. Detailed Implementation
[0022] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.
[0023] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0024] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this application described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0025] As described in the background section, existing password update methods suffer from transaction failures due to password inconsistencies caused by network fluctuations or long network delays. To address the issue of transaction failures caused by key inconsistencies between different nodes due to network fluctuations during the key update process, embodiments of this application provide a key update method, apparatus, computer-readable storage medium, and business system to ensure business continuity.
[0026] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.
[0027] The methods and embodiments provided in this application can be executed on a mobile terminal, computer terminal, or similar computing device. Taking running on a mobile terminal as an example, Figure 1 This is a hardware structure block diagram of a mobile terminal for a key update method to ensure business continuity according to an embodiment of the present invention. Figure 1 As shown, a mobile terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. The mobile terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the mobile terminal described above. For example, the mobile terminal may also include components that are more... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0028] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the device information display method in this embodiment of the invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the mobile terminal via a network. Examples of the aforementioned networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. The transmission device 106 is used to receive or send data via a network. Specific examples of the aforementioned networks may include wireless networks provided by the mobile terminal's communication provider. In one example, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to communicate with the Internet. In one example, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0029] This embodiment provides a key update method for ensuring business continuity that runs on a mobile terminal, computer terminal, or similar computing device. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0030] Figure 2 This is a flowchart of a key update method for ensuring service continuity according to an embodiment of this application. For example... Figure 2 As shown, the method includes the following steps:
[0031] Step S201: Control the first secure management node to receive the key update request from the service node and send it to the second secure management node. The key update request is used to instruct the key stored in the business system to be updated periodically. The key includes a first subkey, a second subkey, a third subkey and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey and the third subkey satisfies the transaction business verification of the first secure management node by the second secure management node, the transaction business verification is determined to be successful.
[0032] Specifically, this application provides a method for updating keys between the head office's security management system and the branch office's security management system. The tamper-proof verification code (MAC) is generated by the branch office system and verified by the head office system. This is achieved primarily by setting multiple different parts in the key, i.e., a multimodal key, and updating them asynchronously during the update process. This ensures that during the update of each part, at least one part can be used for transaction verification, enabling normal transaction operation.
[0033] In specific implementation, a two-level node system will be used as an example. P is the branch security management node, i.e., the first security management node mentioned above, and C is the head office security management node, i.e., the second security management node mentioned above. The business system includes multiple first security management nodes and multiple second security management nodes mentioned above. The following will be explained using a single P node and a single C node as examples. In addition, the business system also includes a service system, which is the initiator of key update requests, i.e., the service node mentioned above.
[0034] It is understood that this application sets up a multimodal key, including an active key, a new key, and an old key. When performing verification at the head office security management node, a round-robin approach is adopted, using the active key, the new key, and the old key in sequence.
[0035] Before the aforementioned service node initiates the key update request, the nodes and their corresponding multimodal keys are shown in Table 1.
[0036] Table 1
[0037]
[0038] Furthermore, such as Figure 3 As shown in steps 1 and 2, the first secure management node P1 receives the key update request from the service node and sends it to the second secure management node. Before the key update request sent in step 2 is received by node C1, the keys corresponding to each node are consistent with the initial state. P1 receives the key update request initiated by the service node and sends it to C1.
[0039] Step S202: When the second key management node receives the key update request, the second key management node is controlled to generate and update the second subkey and the target identifier information of the key in sequence, and a password distribution instruction is generated and sent to the first key management node according to the updated key.
[0040] Specifically, such as Figure 3As shown in steps 2 and 5, C1 receives the aforementioned key update request, controls the C1 node to generate a new key, and updates the C1 node's new key and flag (i.e., the aforementioned target identifier information) according to the newly generated key. Then, C1 generates the aforementioned password delivery instruction and sends it to the P1 node. After step 2 is executed and before P1 receives the aforementioned key update request, the nodes and their corresponding multimodal keys are shown in Table 2.
[0041] Table 2
[0042]
[0043] As can be seen, the head office's secure management nodes C1 and C2 can verify each other using either the active key or the old key, ensuring the consistency of keys for financial transactions in the event of network communication anomalies.
[0044] Step S203: When the first secure management node receives the password issuance instruction, the first secure management node is controlled to update the second subkey, the first subkey, and the third subkey of the key in sequence according to the password issuance instruction, and generate a first key activation instruction according to the updated key and send it to the second secure management node.
[0045] Specifically, such as Figure 3 As shown in steps 5 and 8, P1 receives the aforementioned password issuance instruction and updates the new key, active key, and old key of node P1 according to the updated new key. After step 5 is executed and before node C1 receives the aforementioned first key activation instruction, the nodes and their corresponding multimodal keys are shown in Table 3.
[0046] Table 3
[0047]
[0048] As can be seen, the head office's secure management node C1 can verify the P1 node using the new key.
[0049] Step S204: When the second secure management node receives the first key activation instruction, the second secure management node is controlled to update the first subkey, the third subkey and the target identifier information of the key in sequence according to the first key activation instruction, and generate first feedback information and send it to the first secure management node. The first feedback information is used to indicate that the second subkey is successfully activated.
[0050] Specifically, such as Figure 3As shown in steps 8 and 10, C1 receives the first key activation instruction and updates the active key, old key, and flag identifier of node C1 sequentially according to the first key activation instruction. After step 8 is executed and before node P1 receives the first feedback information, each node and its corresponding multimodal key are shown in Table 4 (excluding the key synchronization process between C1 and C2; in fact, the keys of C1 and C2 are consistent at this time).
[0051] Table 4
[0052]
[0053] As can be seen, the head office security node C1 can verify node P1 using any one of the active key, new key, and old key.
[0054] Step S205: When the first secure management node receives the first feedback information, it controls the first secure management node to send the updated key to the service node to complete the key update.
[0055] Specifically, such as Figure 3 As shown in step 11, the return message from the grounded P1 after the key update is completed is sent to the above-mentioned service node. From this point onwards, the keys of all nodes in the business system remain consistent. After this step is executed, each node and its corresponding multimodal key are the same as the key updated in step 9.
[0056] In this embodiment, firstly, the first secure management node receives a key update request from the service node and sends it to the second secure management node. The key update request instructs the periodic updating of the key stored in the business system. The key includes a first subkey, a second subkey, a third subkey, and target identification information. The target identification information indicates whether the second subkey is valid. If any one of the first, second, and third subkeys satisfies the transaction verification performed by the second secure management node on the first secure management node, the transaction verification is deemed successful. Then, upon receiving the key update request, the second secure management node generates and sequentially updates the second subkey and the target identification information of the key, and generates a password distribution instruction based on the updated key, sending it to the first secure management node. Afterwards... Upon receiving the password distribution instruction, the first secure management node updates the second subkey, the first subkey, and the third subkey of the key sequentially according to the password distribution instruction, and generates a first key activation instruction based on the updated key, which is then sent to the second secure management node. Subsequently, upon receiving the first key activation instruction, the second secure management node updates the first subkey, the third subkey, and the target identifier information of the key sequentially according to the first key activation instruction, and generates first feedback information, which is sent to the first secure management node. This first feedback information indicates successful activation of the second subkey. Finally, upon receiving the first feedback information, the first secure management node distributes the updated key to the service node, completing the key update. This application sets up a multimodal key, including an active key, a new key, and an old key, as well as a flag indicating whether the new key is active. During the password update process, based on the information exchange between the first and second secure management nodes, the new key, active key, and old key stored on different nodes are updated sequentially. A verification mechanism is set based on the order of key updates, that is, disclosure is allowed as long as any subkey in the key is verified. This ensures that at least one subkey is the same among the first secure management node, the second secure management node, and the service node during the key update process to complete the verification, thus ensuring the key consistency of business transactions. This method solves the problem in the prior art where network fluctuations during the key update process cause inconsistencies in keys between different nodes, leading to transaction failures.
[0057] To ensure that multiple head office security management nodes can verify branch office security management nodes, in an optional implementation, after controlling the second security management node to generate and sequentially update the second subkey of the key and the target identifier information, the method further includes:
[0058] Step S301: Control the second key management node to generate a first key synchronization instruction based on the updated key and send it to the other second key management nodes. The first key synchronization instruction is used to instruct the other second key management nodes to update the second subkey and the target identification information of the key in sequence.
[0059] Specifically, as shown in Table 3, after updating the key of P1 in step 5, the main control node C2 cannot verify P1. Therefore, this application sets up key synchronization between C1 and C2 before updating the key of P1. That is, node C1 sends the aforementioned first key synchronization instruction to node C2, as follows: Figure 3 As shown in step 3.
[0060] To complete key synchronization with other head office security management nodes, in an optional implementation, after controlling the aforementioned second security management node to generate a first key synchronization instruction based on the updated key and send it to the other aforementioned second security management nodes, the method further includes:
[0061] Step S401: When the other second key management nodes receive the first key synchronization instruction, control the other second key management nodes to update the second subkey and the target identifier information of the key in sequence according to the first key synchronization instruction, and generate second feedback information to send to the second key management nodes. The second feedback information is used to indicate that the key synchronization of the other second key management nodes is successful.
[0062] Specifically, such as Figure 3 As shown in steps 3 and 4, C2 receives the first key synchronization instruction and updates the new key and flag according to the instruction, and then provides feedback to node C1 based on the synchronization result. After step 3 is executed, the nodes and their corresponding multimodal keys are shown in Table 5.
[0063] Table 5
[0064]
[0065] As can be seen, since the key of node C2 is consistent with that of node C1, it can be guaranteed that after step 5 is executed, the main control node C2 can verify node P1 using the new key. Both nodes C1 and C2 can verify node P2 using the active key.
[0066] To ensure that all head office security management nodes can verify multiple branch security management nodes, in an optional implementation, after controlling the first security management node to sequentially update the second subkey, the first subkey, and the third subkey of the key according to the cipher issuance instruction, the method further includes:
[0067] Step S501: Control the first key management node to generate a second key synchronization instruction based on the updated key and send it to the other first key management nodes. The second key synchronization instruction is used to instruct the other first key management nodes to update the second subkey, the first subkey and the third subkey of the key in sequence.
[0068] Specifically, as shown in Table 4, after updating the key for C1 in step 8, node C1 cannot verify node P2. Therefore, this application sets up key synchronization between P1 and P2 before updating the key for C1. Figure 3 As shown in step 6.
[0069] In order to complete the key update for other branch security management nodes, in an optional implementation, after controlling the first security management node to generate a second key synchronization instruction based on the updated key and send it to the other first security management nodes, the method further includes:
[0070] Step S601: When the other first key management nodes receive the second key synchronization instruction, control the other first key management nodes to update the second subkey, the first subkey and the third subkey of the key in sequence according to the second key synchronization instruction, and generate third feedback information and send it to the first key management nodes. The third feedback information is used to indicate that the key synchronization of the other first key management nodes is successful.
[0071] Specifically, such as Figure 3 As shown in steps 6 and 7, P2 receives the aforementioned second key synchronization instruction and updates the new key, active key, and old key according to the instruction, and provides feedback to node C1 based on the synchronization result. After step 6 is executed, the nodes and their corresponding multimodal keys are shown in Table 6.
[0072] Table 6
[0073]
[0074] As can be seen, since the key of node P2 is consistent with that of node P1, it can be guaranteed that after step 6 is executed, the main control node C1 can verify nodes P1 and P2 using the new key. Since the key of C2 is consistent with that of C1, C2 can also verify nodes P1 and P2 using the new key.
[0075] To ensure key consistency, in one optional implementation, after controlling the second key management node to sequentially update the first subkey, the third subkey, and the target identifier information of the key according to the first key activation instruction, the method further includes:
[0076] Step S701: Control the second key management node to generate a second key activation instruction based on the updated key and send it to the other second key management nodes. The second key activation is used to instruct the other second key management nodes to update the first subkey, the third subkey and the target identifier information of the key in sequence.
[0077] Specifically, in order to ensure key consistency in the business system, after node C1 updates the key according to the first key activation instruction, it generates a second key activation instruction based on the updated key and sends it to C2 for synchronous activation.
[0078] To ensure key consistency, in one optional implementation, after controlling the second key management node to generate a second key activation command based on the updated key and send it to the other second key management nodes, the method further includes:
[0079] Step S801: When other second-secret pipe nodes receive the second key activation instruction, control the other second-secret pipe nodes to sequentially update the first sub-key, the third sub-key, and the target identification information of the key according to the second key activation instruction, and generate a fourth feedback instruction to send to the second-secret pipe node. The fourth feedback instruction is used to indicate that the gas pressure second-secret pipe node key activation is successful.
[0080] Specifically, such as Figure 3 As shown in step 9, C2 receives the aforementioned second key activation instruction and updates the active key, old key, and flag identifier according to the instruction. After step 9 is executed, the nodes and their corresponding multimodal keys are shown in Table 7.
[0081] Table 7
[0082]
[0083] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0084] This application also provides a key update apparatus for ensuring business continuity. It should be noted that the key update apparatus for ensuring business continuity in this application can be used to execute the key update method for ensuring business continuity provided in this application. This apparatus is used to implement the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the apparatus described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0085] The following describes the key update device for ensuring business continuity provided in the embodiments of this application.
[0086] Figure 4 This is a structural block diagram of a key update device for ensuring business continuity according to an embodiment of this application. Figure 4 As shown, the device includes:
[0087] The first control unit 10 is used to control the first secure management node to receive the key update request from the service node and send it to the second secure management node. The key update request is used to instruct the key stored in the business system to be updated periodically. The key includes a first subkey, a second subkey, a third subkey and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey and the third subkey satisfies the transaction business verification of the first secure management node by the second secure management node, the transaction business verification is determined to be successful.
[0088] Specifically, this application provides a method for updating keys between the head office's security management system and the branch office's security management system. The tamper-proof verification code (MAC) is generated by the branch office system and verified by the head office system. This is achieved primarily by setting multiple different parts in the key, i.e., a multimodal key, and updating them asynchronously during the update process. This ensures that during the update of each part, at least one part can be used for transaction verification, enabling normal transaction operation.
[0089] In specific implementation, a two-level node system will be used as an example. P is the branch security management node, i.e., the first security management node mentioned above, and C is the head office security management node, i.e., the second security management node mentioned above. The business system includes multiple first security management nodes and multiple second security management nodes mentioned above. The following will be explained using a single P node and a single C node as examples. In addition, the business system also includes a service system, which is the initiator of key update requests, i.e., the service node mentioned above.
[0090] It is understood that this application sets up a multimodal key, including an active key, a new key, and an old key. When performing verification at the head office security management node, a round-robin approach is adopted, using the active key, the new key, and the old key in sequence.
[0091] Before the aforementioned service node initiates the key update request, the nodes and their corresponding multimodal keys are shown in Table 1.
[0092] Table 1
[0093]
[0094] Furthermore, such as Figure 3 As shown in steps 1 and 2, the first secure management node receives the key update request from the service node and sends it to the second secure management node. Before the key update request sent in step 2 is received by node C1, the keys corresponding to each node are consistent with the initial state. P1 receives the key update request initiated by the service node and sends it to C1.
[0095] The second control unit 20 is configured to, when the second control node receives the key update request, control the second control node to generate and sequentially update the second subkey and the target identifier information of the key, and generate a password distribution instruction based on the updated key and send it to the first control node.
[0096] Specifically, such as Figure 3 As shown in steps 2 and 5, C1 receives the aforementioned key update request, controls the C1 node to generate a new key, and updates the C1 node's new key and flag (i.e., the aforementioned target identifier information) according to the newly generated key. Then, C1 generates the aforementioned password delivery instruction and sends it to the P1 node. After step 2 is executed and before P1 receives the aforementioned key update request, the nodes and their corresponding multimodal keys are shown in Table 2.
[0097] Table 2
[0098]
[0099] As can be seen, the head office's secure management nodes C1 and C2 can verify each other using either the active key or the old key, ensuring the consistency of keys for financial transactions in the event of network communication anomalies.
[0100] The third control unit 30 is configured to, when the first control node receives the password issuance instruction, control the first control node to sequentially update the second subkey, the first subkey, and the third subkey of the key according to the password issuance instruction, and generate a first key activation instruction based on the updated key and send it to the second control node.
[0101] Specifically, such as Figure 3 As shown in steps 5 and 8, P1 receives the aforementioned password issuance instruction and updates the new key, active key, and old key of node P1 according to the updated new key. After step 5 is executed and before node C1 receives the aforementioned first key activation instruction, the nodes and their corresponding multimodal keys are shown in Table 3.
[0102] Table 3
[0103]
[0104] As can be seen, the head office's secure management node C1 can verify the P1 node using the new key.
[0105] The fourth control unit 40 is configured to, when the second control node receives the first key activation instruction, control the second control node to sequentially update the first subkey, the third subkey, and the target identifier information of the key according to the first key activation instruction, and generate first feedback information to send to the first control node. The first feedback information is used to indicate that the second subkey has been successfully activated.
[0106] Specifically, such as Figure 3 As shown in steps 8 and 10, C1 receives the first key activation instruction and updates the active key, old key, and flag identifier of node C1 sequentially according to the first key activation instruction. After step 8 is executed and before node P1 receives the first feedback information, each node and its corresponding multimodal key are shown in Table 4 (excluding the key synchronization process between C1 and C2; in fact, the keys of C1 and C2 are consistent at this time).
[0107] Table 4
[0108]
[0109] As can be seen, the head office security node C1 can verify node P1 using any one of the active key, new key, and old key.
[0110] The fifth control unit 50 is used to control the first secure management node to send the updated key to the service node when the first secure management node receives the first feedback information, thereby completing the key update.
[0111] Specifically, such as Figure 3As shown in step 11, the return message from the grounded P1 after the key update is completed is sent to the above-mentioned service node. From this point onwards, the keys of all nodes in the business system remain consistent. After this step is executed, each node and its corresponding multimodal key are the same as the key updated in step 9.
[0112] In this embodiment, the first control unit controls the first secure management node to receive the key update request from the service node and send it to the second secure management node. The key update request is used to instruct the periodic updating of the key stored in the business system. The key includes a first subkey, a second subkey, a third subkey, and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey, and the third subkey satisfies the transaction verification of the first secure management node by the second secure management node, the transaction verification is determined to be successful. When the second secure management node receives the key update request, the second control unit controls the second secure management node to generate and sequentially update the second subkey and the target identification information of the key, and generates a password distribution instruction based on the updated key and sends it to the first secure management node. The third control unit... When the first secure management node receives the password distribution instruction, the unit controls the first secure management node to sequentially update the second subkey, the first subkey, and the third subkey of the key according to the password distribution instruction, and generates a first key activation instruction based on the updated key and sends it to the second secure management node; when the second secure management node receives the first key activation instruction, the fourth control unit controls the second secure management node to sequentially update the first subkey, the third subkey, and the target identifier information of the key according to the first key activation instruction, and generates first feedback information and sends it to the first secure management node, the first feedback information being used to indicate that the second subkey has been successfully activated; when the first secure management node receives the first feedback information, the fifth control unit controls the first secure management node to distribute the updated key to the service node, completing the key update. This application sets up a multimodal key, including an active key, a new key, and an old key, as well as a flag indicating whether the new key is active. During the password update process, based on the information exchange between the first and second secure management nodes, the new key, active key, and old key stored on different nodes are updated sequentially. A verification mechanism is set based on the order of key updates, that is, disclosure is allowed as long as any subkey in the key is verified. This ensures that at least one subkey is the same among the first secure management node, the second secure management node, and the service node during the key update process to complete the verification, thus ensuring the key consistency of business transactions. This method solves the problem in the prior art where network fluctuations during the key update process cause inconsistencies in keys between different nodes, leading to transaction failures.
[0113] To ensure that multiple head office security monitoring nodes can verify branch security monitoring nodes, in one optional embodiment, the above-mentioned device further includes:
[0114] The sixth control unit is configured to, after controlling the second secure management node to generate and sequentially update the second subkey and the target identification information of the key, control the second secure management node to generate a first key synchronization instruction based on the updated key and send it to other second secure management nodes. The first key synchronization instruction is used to instruct other second secure management nodes to sequentially update the second subkey and the target identification information of the key.
[0115] Specifically, as shown in Table 3, after updating the key of P1 in step 5, the main control node C2 cannot verify P1. Therefore, this application sets up key synchronization between C1 and C2 before updating the key of P1. That is, node C1 sends the aforementioned first key synchronization instruction to node C2, as follows: Figure 3 As shown in step 3.
[0116] To enable key synchronization with other head office security management nodes, in one optional implementation, the above-mentioned apparatus further includes:
[0117] The seventh control unit is configured to, after controlling the second key management node to generate a first key synchronization instruction based on the updated key and send it to the other second key management nodes, and upon receiving the first key synchronization instruction, control the other second key management nodes to sequentially update the second subkey and the target identifier information of the key according to the first key synchronization instruction, and generate second feedback information to send to the second key management nodes, wherein the second feedback information is used to indicate that the key synchronization of the other second key management nodes is successful.
[0118] Specifically, such as Figure 3 As shown in steps 3 and 4, C2 receives the first key synchronization instruction and updates the new key and flag according to the instruction, and then provides feedback to node C1 based on the synchronization result. After step 3 is executed, the nodes and their corresponding multimodal keys are shown in Table 5.
[0119] Table 5
[0120]
[0121] As can be seen, since the key of node C2 is consistent with that of node C1, it can be guaranteed that after step 5 is executed, the main control node C2 can verify node P1 using the new key. Both nodes C1 and C2 can verify node P2 using the active key.
[0122] To ensure that all head office security monitoring nodes can verify multiple branch security monitoring nodes, in one optional implementation, the above-mentioned device further includes:
[0123] The eighth control unit is configured to, after controlling the first secure management node to sequentially update the second subkey, the first subkey, and the third subkey of the key according to the password, control the first secure management node to generate a second key synchronization instruction based on the updated key and send it to other first secure management nodes. The second key synchronization instruction is used to instruct other first secure management nodes to sequentially update the second subkey, the first subkey, and the third subkey of the key.
[0124] Specifically, as shown in Table 4, after updating the key for C1 in step 8, node C1 cannot verify node P2. Therefore, this application sets up key synchronization between P1 and P2 before updating the key for C1. Figure 3 As shown in step 6.
[0125] In order to complete the key update for other branch security management nodes, in one optional implementation, the above-mentioned apparatus further includes:
[0126] The ninth control unit is configured to, after controlling the first secure management node to generate a second key synchronization instruction based on the updated key and send it to the other first secure management nodes, and upon receiving the second key synchronization instruction, control the other first secure management nodes to sequentially update the second subkey, the first subkey, and the third subkey of the key according to the second key synchronization instruction, and generate third feedback information to send to the first secure management node, wherein the third feedback information is used to indicate that the key synchronization of the other first secure management nodes is successful.
[0127] Specifically, such as Figure 3 As shown in steps 6 and 7, P2 receives the aforementioned second key synchronization instruction and updates the new key, active key, and old key according to the instruction, and provides feedback to node C1 based on the synchronization result. After step 6 is executed, the nodes and their corresponding multimodal keys are shown in Table 6.
[0128] Table 6
[0129]
[0130] As can be seen, since the key of node P2 is consistent with that of node P1, it can be guaranteed that after step 6 is executed, the main control node C1 can verify nodes P1 and P2 using the new key. Since the key of C2 is consistent with that of C1, C2 can also verify nodes P1 and P2 using the new key.
[0131] To ensure key consistency, in one optional implementation, the above apparatus further includes:
[0132] The tenth control unit is configured to, after controlling the second secure management node to sequentially update the first sub-key, the third sub-key, and the target identification information of the key according to the first key activation instruction, control the second secure management node to generate a second key activation instruction according to the updated key and send it to other second secure management nodes. The second key activation execution is used to instruct other second secure management nodes to sequentially update the first sub-key, the third sub-key, and the target identification information of the key.
[0133] Specifically, in order to ensure key consistency in the business system, after node C1 updates the key according to the first key activation instruction, it generates a second key activation instruction based on the updated key and sends it to C2 for synchronous activation.
[0134] To ensure key consistency, in one optional implementation, the above-mentioned apparatus further includes:
[0135] The eleventh control unit is configured to, after controlling the second secure pipe node to generate a second key activation instruction based on the updated key and send it to the other second secure pipe nodes, and upon receiving the second key activation instruction, control the other second secure pipe nodes to sequentially update the first sub-key, the third sub-key, and the target identification information of the key according to the second key activation instruction, and generate a fourth feedback instruction to send to the second secure pipe node. The fourth feedback instruction is used to indicate that the gas pressure second secure pipe node key activation is successful.
[0136] Specifically, such as Figure 3 As shown in step 9, C2 receives the aforementioned second key activation instruction and updates the active key, old key, and flag identifier according to the instruction. After step 9 is executed, the nodes and their corresponding multimodal keys are shown in Table 7.
[0137] Table 7
[0138]
[0139] The aforementioned key update device for ensuring business continuity includes a processor and a memory. The first control unit, second control unit, third control unit, fourth control unit, and fifth control unit are all stored as program units in the memory. The processor executes these program units stored in the memory to implement their respective functions. All of the above modules reside in the same processor; alternatively, the modules may be located in different processors in any combination.
[0140] The processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and password consistency is ensured by adjusting kernel parameters.
[0141] The memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0142] This invention provides a computer-readable storage medium including a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to perform the key update method for ensuring business continuity.
[0143] Specifically, key update methods to ensure business continuity include:
[0144] Step S201: Control the first secure management node to receive the key update request from the service node and send it to the second secure management node. The key update request is used to instruct the key stored in the business system to be updated periodically. The key includes a first subkey, a second subkey, a third subkey and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey and the third subkey satisfies the transaction business verification of the first secure management node by the second secure management node, the transaction business verification is determined to be successful.
[0145] Step S202: When the second key management node receives the key update request, the second key management node is controlled to generate and update the second subkey and the target identifier information of the key in sequence, and a password distribution instruction is generated and sent to the first key management node according to the updated key.
[0146] Step S203: When the first secure management node receives the password issuance instruction, the first secure management node is controlled to update the second subkey, the first subkey, and the third subkey of the key in sequence according to the password issuance instruction, and generate a first key activation instruction according to the updated key and send it to the second secure management node.
[0147] Step S204: When the second secure management node receives the first key activation instruction, the second secure management node is controlled to update the first subkey, the third subkey and the target identifier information of the key in sequence according to the first key activation instruction, and generate first feedback information and send it to the first secure management node. The first feedback information is used to indicate that the second subkey is successfully activated.
[0148] Step S205: When the first secure management node receives the first feedback information, it controls the first secure management node to send the updated key to the service node to complete the key update.
[0149] This invention provides a processor for running a program, wherein the program executes the aforementioned key update method for ensuring business continuity.
[0150] Specifically, key update methods to ensure business continuity include:
[0151] Step S201: Control the first secure management node to receive the key update request from the service node and send it to the second secure management node. The key update request is used to instruct the key stored in the business system to be updated periodically. The key includes a first subkey, a second subkey, a third subkey and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey and the third subkey satisfies the transaction business verification of the first secure management node by the second secure management node, the transaction business verification is determined to be successful.
[0152] Step S202: When the second key management node receives the key update request, the second key management node is controlled to generate and update the second subkey and the target identifier information of the key in sequence, and a password distribution instruction is generated and sent to the first key management node according to the updated key.
[0153] Step S203: When the first secure management node receives the password issuance instruction, the first secure management node is controlled to update the second subkey, the first subkey, and the third subkey of the key in sequence according to the password issuance instruction, and generate a first key activation instruction according to the updated key and send it to the second secure management node.
[0154] Step S204: When the second secure management node receives the first key activation instruction, the second secure management node is controlled to update the first subkey, the third subkey and the target identifier information of the key in sequence according to the first key activation instruction, and generate first feedback information and send it to the first secure management node. The first feedback information is used to indicate that the second subkey is successfully activated.
[0155] Step S205: When the first secure management node receives the first feedback information, it controls the first secure management node to send the updated key to the service node to complete the key update.
[0156] This invention provides a business system, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs at least the following steps:
[0157] Step S201: Control the first secure management node to receive the key update request from the service node and send it to the second secure management node. The key update request is used to instruct the key stored in the business system to be updated periodically. The key includes a first subkey, a second subkey, a third subkey and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey and the third subkey satisfies the transaction business verification of the first secure management node by the second secure management node, the transaction business verification is determined to be successful.
[0158] Step S202: When the second key management node receives the key update request, the second key management node is controlled to generate and update the second subkey and the target identifier information of the key in sequence, and a password distribution instruction is generated and sent to the first key management node according to the updated key.
[0159] Step S203: When the first secure management node receives the password issuance instruction, the first secure management node is controlled to update the second subkey, the first subkey, and the third subkey of the key in sequence according to the password issuance instruction, and generate a first key activation instruction according to the updated key and send it to the second secure management node.
[0160] Step S204: When the second secure management node receives the first key activation instruction, the second secure management node is controlled to update the first subkey, the third subkey and the target identifier information of the key in sequence according to the first key activation instruction, and generate first feedback information and send it to the first secure management node. The first feedback information is used to indicate that the second subkey is successfully activated.
[0161] Step S205: When the first secure management node receives the first feedback information, it controls the first secure management node to send the updated key to the service node to complete the key update.
[0162] This application also provides a computer program product, which, when executed on a data processing device, is suitable for executing an initialization program having at least the following method steps:
[0163] Step S201: Control the first secure management node to receive the key update request from the service node and send it to the second secure management node. The key update request is used to instruct the key stored in the business system to be updated periodically. The key includes a first subkey, a second subkey, a third subkey and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey and the third subkey satisfies the transaction business verification of the first secure management node by the second secure management node, the transaction business verification is determined to be successful.
[0164] Step S202: When the second key management node receives the key update request, the second key management node is controlled to generate and update the second subkey and the target identifier information of the key in sequence, and a password distribution instruction is generated and sent to the first key management node according to the updated key.
[0165] Step S203: When the first secure management node receives the password issuance instruction, the first secure management node is controlled to update the second subkey, the first subkey, and the third subkey of the key in sequence according to the password issuance instruction, and generate a first key activation instruction according to the updated key and send it to the second secure management node.
[0166] Step S204: When the second secure management node receives the first key activation instruction, the second secure management node is controlled to update the first subkey, the third subkey and the target identifier information of the key in sequence according to the first key activation instruction, and generate first feedback information and send it to the first secure management node. The first feedback information is used to indicate that the second subkey is successfully activated.
[0167] Step S205: When the first secure management node receives the first feedback information, it controls the first secure management node to send the updated key to the service node to complete the key update.
[0168] It is obvious to those skilled in the art that the modules or steps of the present invention described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those described herein, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.
[0169] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0170] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0171] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0172] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0173] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0174] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0175] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0176] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0177] As can be seen from the above description, the embodiments of this application achieve the following technical effects:
[0178] 1) The key update method for ensuring business continuity according to this application firstly controls the first secure management node to receive a key update request from the service node and send it to the second secure management node. The key update request is used to instruct the periodic updating of the key stored in the business system. The key includes a first subkey, a second subkey, a third subkey, and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey, and the third subkey satisfies the transaction verification of the first secure management node by the second secure management node, the transaction verification is determined to be successful. Then, when the second secure management node receives the key update request, it generates and sequentially updates the second subkey and the target identification information of the key, and generates a password distribution instruction based on the updated key and sends it to the first secure management node. The first secure management node then receives the password distribution instruction and sequentially updates the second subkey, the first subkey, and the third subkey of the key according to the password distribution instruction. It then generates a first key activation instruction based on the updated key and sends it to the second secure management node. Upon receiving the first key activation instruction, the second secure management node updates the first subkey, the third subkey, and the target identifier information of the key sequentially according to the first key activation instruction. It then generates first feedback information and sends it to the first secure management node. This first feedback information indicates successful activation of the second subkey. Finally, upon receiving the first feedback information, the first secure management node distributes the updated key to the service node, completing the key update. This application sets up a multimodal key, including an active key, a new key, and an old key, as well as a flag indicating whether the new key is active. During the password update process, based on the information exchange between the first and second secure management nodes, the new key, active key, and old key stored on different nodes are updated sequentially. A verification mechanism is set based on the order of key updates, that is, disclosure is allowed as long as any subkey in the key is verified. This ensures that at least one subkey is the same among the first secure management node, the second secure management node, and the service node during the key update process to complete the verification, thus ensuring the key consistency of business transactions. This method solves the problem in the prior art where network fluctuations during the key update process cause inconsistencies in keys between different nodes, leading to transaction failures.
[0179] 2) The key update device for ensuring business continuity according to this application includes a first control unit that controls the first secure management node to receive a key update request from the service node and send it to the second secure management node. The key update request is used to instruct the periodic updating of the key stored in the business system. The key includes a first subkey, a second subkey, a third subkey, and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey, and the third subkey satisfies the transaction verification of the first secure management node by the second secure management node, the transaction verification is determined to be successful. When the second secure management node receives the key update request, the second control unit controls the second secure management node to generate and sequentially update the second subkey and the target identification information of the key, and generates a password distribution instruction based on the updated key and sends it to the first secure management node. The first secure management node, upon receiving the password issuance instruction, controls the first secure management node to sequentially update the second subkey, the first subkey, and the third subkey of the key according to the password issuance instruction, and generates a first key activation instruction based on the updated key and sends it to the second secure management node; the fourth secure management node, upon receiving the first key activation instruction, controls the second secure management node to sequentially update the first subkey, the third subkey, and the target identifier information of the key according to the first key activation instruction, and generates first feedback information and sends it to the first secure management node, the first feedback information indicating that the second subkey has been successfully activated; the fifth secure management node, upon receiving the first feedback information, controls the first secure management node to issue the updated key to the service node, completing the key update. This application sets up a multimodal key, including an active key, a new key, and an old key, as well as a flag indicating whether the new key is active. During the password update process, based on the information exchange between the first and second secure management nodes, the new key, active key, and old key stored on different nodes are updated sequentially. A verification mechanism is set based on the order of key updates, that is, disclosure is allowed as long as any subkey in the key is verified. This ensures that at least one subkey is the same among the first secure management node, the second secure management node, and the service node during the key update process to complete the verification, thus ensuring the key consistency of business transactions. This method solves the problem in the prior art where network fluctuations during the key update process cause inconsistencies in keys between different nodes, leading to transaction failures.
[0180] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A key update method for ensuring business continuity, characterized in that, The key update method is used to control a business system to update keys. The business system includes a first secure management node and a second secure management node. The first secure management node manages the keys of service nodes, and the second secure management node manages the keys of the first secure management node. The method includes: The first secure management node receives the key update request from the service node and sends it to the second secure management node. The key update request is used to instruct the periodic updating of the key stored in the business system. The key includes a first subkey, a second subkey, a third subkey, and target identification information. The target identification information is used to indicate whether the second subkey is effective. If any one of the first subkey, the second subkey, and the third subkey satisfies the transaction verification of the first secure management node by the second secure management node, the transaction verification is determined to be successful. When the second secure management node receives the key update request, it controls the second secure management node to generate and sequentially update the second subkey of the key and the target identifier information, and generates a password delivery instruction based on the updated key and sends it to the first secure management node. When the first secure management node receives the password issuance instruction, it controls the first secure management node to update the second subkey, the first subkey, and the third subkey of the key in sequence according to the password issuance instruction, and generates a first key activation instruction based on the updated key and sends it to the second secure management node. When the second secure management node receives the first key activation instruction, it controls the second secure management node to update the first subkey, the third subkey and the target identifier information of the key in sequence according to the first key activation instruction, and generates first feedback information and sends it to the first secure management node. The first feedback information is used to indicate that the second subkey is successfully activated. Upon receiving the first feedback information, the first secure management node is controlled to send the updated key to the service node, thus completing the key update.
2. The method according to claim 1, characterized in that, After controlling the second secure management node to generate and sequentially update the second subkey of the key and the target identifier information, the method further includes: The control of the second secret management node generates a first key synchronization instruction based on the updated key and sends it to other second secret management nodes. The first key synchronization instruction is used to instruct other second secret management nodes to update the second subkey of the key and the target identification information in sequence.
3. The method according to claim 2, characterized in that, After controlling the second secure management node to generate a first key synchronization command based on the updated key and send it to other second secure management nodes, the method further includes: When other second-secret management nodes receive the first key synchronization instruction, they are controlled to update the second subkey of the key and the target identifier information in sequence according to the first key synchronization instruction, and generate second feedback information to be sent to the second-secret management nodes. The second feedback information is used to indicate that the key synchronization of other second-secret management nodes is successful.
4. The method according to claim 1, characterized in that, After controlling the first secure management node to sequentially update the second subkey, the first subkey, and the third subkey of the key according to the password issuance instruction, the method further includes: The first secure management node is controlled to generate a second key synchronization instruction based on the updated key and send it to other first secure management nodes. The second key synchronization instruction is used to instruct other first secure management nodes to update the second subkey, the first subkey and the third subkey of the key in sequence.
5. The method according to claim 4, characterized in that, After controlling the first secure management node to generate a second key synchronization command based on the updated key and send it to other first secure management nodes, the method further includes: When other first-secret management nodes receive the second key synchronization instruction, the other first-secret management nodes are controlled to update the second subkey, the first subkey, and the third subkey of the key in sequence according to the second key synchronization instruction, and generate third feedback information and send it to the first-secret management node. The third feedback information is used to indicate that the key synchronization of other first-secret management nodes is successful.
6. The method according to claim 1, characterized in that, After controlling the second secure management node to sequentially update the first subkey, the third subkey, and the target identifier information of the key according to the first key activation instruction, the method further includes: The control of the second secret management node generates a second key activation instruction based on the updated key and sends it to other second secret management nodes. The second key activation execution is used to instruct other second secret management nodes to update the first subkey, the third subkey and the target identification information of the key in sequence.
7. The method according to claim 6, characterized in that, After controlling the second secure management node to generate a second key activation command based on the updated key and send it to other second secure management nodes, the method further includes: When other second-secret pipe nodes receive the second key activation instruction, the other second-secret pipe nodes are controlled to update the first sub-key, the third sub-key, and the target identification information of the key in sequence according to the second key activation instruction, and a fourth feedback instruction is generated and sent to the second-secret pipe node. The fourth feedback instruction is used to indicate that the gas pressure second-secret pipe node key activation is successful.
8. A key update device for ensuring business continuity, characterized in that, The key update device is used to control the business system to perform key updates. The business system includes a first secure management node and a second secure management node. The first secure management node is used to manage the keys of the service nodes, and the second secure management node is used to manage the keys of the first secure management node. The device includes: The first control unit is configured to control the first secure management node to receive the key update request from the service node and send it to the second secure management node. The key update request is used to instruct the periodic updating of the key stored in the business system. The key includes a first subkey, a second subkey, a third subkey, and target identification information. The target identification information is used to characterize whether the second subkey is effective. If any one of the first subkey, the second subkey, and the third subkey satisfies the transaction verification of the first secure management node by the second secure management node, the transaction verification is determined to be successful. The second control unit is configured to, when the second security management node receives the key update request, control the second security management node to generate and sequentially update the second subkey of the key and the target identification information, and generate a password delivery instruction based on the updated key and send it to the first security management node. The third control unit is configured to, when the first security management node receives the password issuance instruction, control the first security management node to sequentially update the second subkey, the first subkey, and the third subkey of the key according to the password issuance instruction, and generate a first key activation instruction based on the updated key and send it to the second security management node. The fourth control unit is configured to, when the second key management node receives the first key activation instruction, control the second key management node to sequentially update the first subkey, the third subkey, and the target identifier information of the key according to the first key activation instruction, and generate first feedback information to send to the first key management node, wherein the first feedback information is used to indicate that the second subkey has been successfully activated. The fifth control unit is used to control the first secure management node to send the updated key to the service node when the first secure management node receives the first feedback information, thereby completing the key update.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device on which the computer-readable storage medium is located to perform the method according to any one of claims 1 to 7.
10. A business system, characterized in that, include: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the one or more programs comprising methods for performing any one of claims 1 to 7.
Citation Information
Patent Citations
Key dynamic switching method, system and device for main service system and medium
CN117201021A
Control method for smart home devices and medium and terminal thereof
WO2021121125A1