A method for key replacement, a cluster system, a device, a medium, and a product

By unpacking and encapsulating the key encryption key, the replacement of the master key is realized, solving the problem of long and high cost of key replacement, and improving the efficiency and security of key replacement.

CN119402192BActive Publication Date: 2025-05-27INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411996511.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-27
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

In the prior art, the key replacement process is longer and costly, especially in the replacement of the master key and data encryption key.

Method used

By obtaining the master key to be replaced and the current master key, the encryption key is encrypted using the current master key, and the unsealed key encryption key is encapsulated using the master key to be replaced to complete the key replacement.

Benefits of technology

Reduces the cost of key replacement, improves the efficiency of key replacement, avoids the re-encapsulation of large amounts of data encryption keys, and reduces the impact on system availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119402192B_ABST
    Figure CN119402192B_ABST
Patent Text Reader

Abstract

The present invention discloses a key replacement method, a cluster system, a device, a medium, and a product, relating to the technical field of data security management. In a key management mechanism, a key encryption key is used to encrypt a data encryption key, eliminating the need for conventional key replacement for the data encryption key, thereby reducing the replacement cost. It also avoids the situation where the key replacement process is relatively long due to the need to re-encapsulate all data encryption keys with a new master key when conventionally replacing the master key. The key replacement mainly corresponds to the update of the master key. To complete the key replacement process, only the key encryption key needs to be encapsulated with the new master key (the master key to be replaced), without the need to re-encrypt and encapsulate all data encryption keys. This improves the key update efficiency and reduces the impact of key updates on system availability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security management, and in particular to a key replacement method, cluster system, device, medium and product. Background Art

[0002] In order to avoid the reduction of key security due to long-term exposure of keys, the key replacement link corresponding to the key lifecycle management is crucial.

[0003] Key replacement: The keys of each layer can be replaced. If the master key is replaced, it is necessary to regenerate the master key and re-encapsulate all data encryption keys with the new master key, which results in a longer key replacement process. If the data encryption key is replaced, all new data encryption keys need to be used to re-encrypt the data, which increases the replacement cost.

[0004] Therefore, how to reduce the key replacement cost and improve the key replacement efficiency is an urgent problem that those skilled in the art need to solve. Summary of the invention

[0005] The purpose of the present invention is to provide a key replacement method, cluster system, device, medium and product to solve the problem of long replacement process and high replacement cost caused by replacing keys at each layer in the conventional key replacement process.

[0006] In order to solve the above technical problems, the present invention provides a key replacement method, comprising:

[0007] Acquire a master key to be replaced and a current master key based on a key replacement instruction; wherein the key management mechanism to which the key replacement instruction belongs includes a key encryption key;

[0008] Decrypting the key encryption key using the current master key;

[0009] The unsealed key encryption key is encapsulated using the master key to be replaced to complete the key replacement.

[0010] On the one hand, the key management mechanism determination process includes:

[0011] Get the data encryption key corresponding to the current key storage mechanism;

[0012] Using the current master key to encapsulate the key encryption key;

[0013] The data encryption key is encapsulated using the encapsulated key encryption key to ensure that the key encryption key is introduced into the key management mechanism.

[0014] On the other hand, before the unsealed key encryption key is encapsulated by using the master key to be replaced, the method further includes:

[0015] Get the authentication mechanism;

[0016] Performing verification processing on the master key to be replaced according to the verification mechanism to determine a verification result;

[0017] If the verification result is passed, the process proceeds to the step of encapsulating the unsealed key encryption key using the master key to be replaced.

[0018] On the other hand, performing verification processing on the master key to be replaced according to the verification mechanism to determine a verification result includes:

[0019] Using the current master key as the first master key and using the master key to be replaced as the second master key;

[0020] Obtaining the key length of each of the first master key and the second master key;

[0021] If the key lengths of the first master key and the second master key are the same, entering the step of encapsulating the unsealed key encryption key using the master key to be replaced;

[0022] If the key lengths of the first master key and the second master key are different, and the key length of the first master key is greater than that of the second master key, the key length of the second master key is padded according to the key length of the first master key so that the key length of the padded second master key is the same as that of the first master key, and the process proceeds to the step of encapsulating the unsealed key encryption key using the master key to be replaced.

[0023] On the other hand, padding the key length of the second master key according to the key length of the first master key so that the key length of the padded second master key is the same as the key length of the first master key, including:

[0024] Performing difference processing on the key length of the first master key and the key length of the second master key to obtain the key length to be padded;

[0025] Generate a random code according to the length of the key to be padded;

[0026] The random code and the second master key are concatenated to obtain a padded second master key, so that a key length of the padded second master key is the same as a key length of the first master key.

[0027] On the other hand, performing verification processing on the master key to be replaced according to the verification mechanism to determine a verification result includes:

[0028] Get the target randomness detection mode;

[0029] Select each target detection item according to the target randomness detection mode;

[0030] Configure corresponding detection parameters according to each of the target detection items;

[0031] Based on each of the target detection items and the corresponding detection parameters, the key file of the master key to be replaced is tested to obtain the test results corresponding to each of the target detection items;

[0032] The test results corresponding to each of the target detection items are evaluated to determine the verification result of the master key to be replaced.

[0033] On the other hand, after the unsealed key encryption key is encapsulated by using the master key to be replaced, the method further includes:

[0034] Encapsulating the unsealed key encryption key with the master key to be replaced to obtain a first key encryption key;

[0035] comparing the first key encryption key with the key encryption key;

[0036] If the first key encryption key is the same as the key encryption key, it is determined that the master key to be replaced is successfully verified.

[0037] On the other hand, after the unsealed key encryption key is encapsulated by using the master key to be replaced, the method further includes:

[0038] Encapsulating the unsealed key encryption key with the master key to be replaced to obtain a first key encryption key;

[0039] Using the master key to be replaced to decrypt the first key encryption key to obtain a second key encryption key;

[0040] Decrypting the key encryption key using the current master key to obtain a third key encryption key;

[0041] comparing the second key encryption key with the third key encryption key;

[0042] If the second key encryption key is the same as the third key encryption key, it is determined that the verification of the master key to be replaced is successful.

[0043] On the other hand, when the key replacement instruction is triggered, if there is a current key storage mechanism to which the current master key belongs that satisfies the switching condition of the key storage mechanism, after obtaining the master key to be replaced and the current master key based on the key replacement instruction, it also includes:

[0044] Get the key encryption key corresponding to the current key storage mechanism;

[0045] Using the current master key to decrypt the key encryption key corresponding to the current key storage mechanism to obtain a fourth key encryption key;

[0046] Obtain the first master key corresponding to the target key storage mechanism;

[0047] The fourth key encryption key is encapsulated by using the first master key to complete the switching process from the current key storage mechanism to the target key storage mechanism.

[0048] On the other hand, the triggering process of the key replacement instruction includes:

[0049] Receiving a key request instruction triggered by a user;

[0050] According to the key request instruction, an application is made to the current key storage mechanism for key replacement to trigger the key replacement instruction.

[0051] On the other hand, the triggering process of the key replacement instruction includes:

[0052] Get the time interval between the preset time interval, the previous time and the current time;

[0053] If the time interval reaches the preset time interval, the key replacement instruction is triggered for the current key storage mechanism.

[0054] In order to solve the above technical problem, the present invention further provides a cluster system, which includes a plurality of nodes; the cluster system is used to execute the steps of the above key replacement method to perform key management.

[0055] In order to solve the above technical problems, the present invention further provides a key replacement device, comprising:

[0056] Memory for storing computer programs;

[0057] A processor is used to implement the steps of the key replacement method when executing the computer program.

[0058] In order to solve the above technical problem, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the key replacement method are implemented.

[0059] In order to solve the above technical problem, the present invention also provides a computer program product, including a computer program / instruction, which implements the steps of the key replacement method when executed by a processor.

[0060] The beneficial effects of the present invention are that, on the one hand, in the key management mechanism, the key encryption key is used to encrypt the data encryption key, and there is no need for conventional key replacement for the replacement of the data encryption key, thereby reducing the replacement cost. There is also no need to use the new master key to re-encapsulate all the data encryption keys when the master key is replaced, which results in a longer key replacement process. On the other hand, the present invention corresponds to the key replacement, which mainly corresponds to the update of the master key. The new master key (the master key to be replaced) only needs to encapsulate the key encryption key to complete the key replacement process, and there is no need to re-encrypt and encapsulate all the data encryption keys. The present invention only needs to update one master key, use the original master key (the current master key) to decapsulate the key encryption key to obtain the key encryption key in plain text, and use the new master key (the master key to be replaced) to re-encapsulate the key decryption key in plain text, without re-encapsulating a large number of data encryption keys, thereby improving the efficiency of key updates and reducing the impact of key updates on system availability.

[0061] Secondly, the triggering of the key replacement instruction is based on the user's automatic triggering, which improves the optional flexibility of the key replacement triggering. The triggering of the key replacement instruction is based on the arrival of the update cycle, which enriches the triggering diversity and flexibility of the key replacement. The configuration process of the master key, key encryption key and data encryption key is to determine the introduction of the key encryption key in the key management mechanism, which improves the security compared with the conventional two-layer key system. The verification mechanism verifies the master key to be replaced to obtain the verification result. Only when the verification result passes, the unsealed plaintext key encryption key is encapsulated based on the master key to be replaced to improve the security of the key replacement of the master key to be replaced. Before the unsealed key encryption key is encapsulated with the second master key, the second master key is verified, and the key lengths of the first master key and the second master key are compared and verified to improve the accuracy of the second master key (the master key to be replaced). The filling process of the key completion processing is to facilitate the subsequent second master key to encapsulate the unsealed first key, ensure that the encapsulation processing of the second master key is successfully completed, so as to realize the key replacement processing. The corresponding quality results are obtained based on the randomness test of the master key to be replaced, which reduces security vulnerabilities and improves the quantitative standards, test flexibility and applicability. After the unsealed key encryption key is encapsulated by the master key to be replaced, the accuracy of the master key to be replaced is indirectly verified by comparing the first key encryption key. If the first key encryption key is the same as the key encryption key, it is determined that the verification of the master key to be replaced is successful, and the key replacement process of the master key is successfully completed. Before the unsealed key encryption key is encapsulated by the master key to be replaced, the accuracy of the master key to be replaced is indirectly verified by comparing the second key encryption key. If the unsealed second key encryption key is the same as the third key encryption key, it is determined that the verification of the master key to be replaced is successful. The master key to be replaced is verified by the unsealed second key encryption key, which improves the fairness and authority of the verification and ensures the accuracy of the encapsulation of the key encryption key.

[0062] In addition, the present invention also provides a cluster system, a key replacement device, a medium and a product, which have the same beneficial effects as the above-mentioned key replacement method. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] In order to more clearly illustrate the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0064] Figure 1 A flowchart of a key replacement method provided by an embodiment of the present invention;

[0065] Figure 2 A schematic diagram of a multiple key storage mechanism in a storage system provided by an embodiment of the present invention;

[0066] Figure 3 A schematic diagram of a key update scenario when using a key management service system provided by an embodiment of the present invention;

[0067] Figure 4 A schematic diagram of a key update scenario when using dedicated encryption hardware provided by an embodiment of the present invention;

[0068] Figure 5 A structural diagram of a key replacement device provided by an embodiment of the present invention;

[0069] Figure 6 A structural diagram of a key replacement device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0070] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0071] The core of the present invention is to provide a key replacement method, cluster system, device, medium and product to solve the problem of long replacement process and high replacement cost caused by replacing keys at each layer in the conventional key replacement process.

[0072] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0073] With the rapid development of information technology, data security and privacy protection have become crucial issues. In the field of data storage, static data encryption, as an effective security measure, is gradually gaining widespread attention and application. Static data encryption refers to the encryption of data stored on physical media (such as hard disks, solid-state drives, tapes, etc.) to ensure that the data cannot be read or understood without authorization. By adopting advanced encryption algorithms and key management mechanisms, static data encryption can provide strong security protection for the storage of sensitive data and effectively prevent data leakage and illegal access. In the current context of frequent data leakage incidents, the application of static data encryption technology is particularly important. It can not only protect personal privacy and corporate trade secrets, but also meet the strict requirements of laws and regulations on data security.

[0074] In the current digital age, enterprise-level storage systems carry massive amounts of critical business data, the security and integrity of which are directly related to the stability of business operations, customer trust, and legal compliance. As a cutting-edge data protection technology, static data encryption has far-reaching value in enterprise-level storage.

[0075] First, static data encryption can significantly improve the confidentiality of data. By encrypting data stored on physical media such as hard disks and solid-state drives (SSDs), even if the storage device is stolen or lost, attackers cannot directly access and understand the data, thereby effectively preventing the leakage of sensitive information, which is crucial for protecting corporate trade secrets and customer privacy.

[0076] Secondly, static data encryption helps to enhance data integrity. The encryption process is usually accompanied by data integrity verification to ensure that the data has not been tampered with during storage and transmission. This is of great significance for maintaining the authenticity and credibility of enterprise data and meeting industry regulatory requirements.

[0077] In addition, static data encryption can also provide flexible data access control for enterprise-level storage systems. With the cooperation of the key management system, enterprises can implement fine-grained control over data access rights of different users or applications, ensuring that only authorized users can access specific data. This helps prevent internal leaks and misoperations, and improves the company's data security management level.

[0078] In summary, implementing static data encryption in enterprise-level storage can not only significantly improve data confidentiality and integrity protection, but also provide enterprises with more flexible data access control methods. This plays an irreplaceable role in maintaining enterprise data security, ensuring stable business operations, and meeting legal and regulatory requirements.

[0079] Key management plays a vital role in implementing static data encryption in enterprise-level storage systems. The key is the core of encrypting and decrypting data, and its security is directly related to the reliability of the entire encryption system. An effective key management strategy can not only ensure the confidentiality of data, but also improve the flexibility and scalability of the system.

[0080] Key management involves multiple links such as key generation, storage, distribution, update, revocation and destruction. First, the generation of keys should follow the principles of security and randomness to ensure that each key is unique and difficult to predict or crack. Second, the storage of keys needs to be secure, such as hardware security modules (HSM) or key management services (KMS) to prevent unauthorized access or disclosure of keys.

[0081] In terms of key distribution, it should be ensured that only authorized users or systems can obtain the corresponding keys. This is usually achieved through secure communication channels and strict access control mechanisms. At the same time, key update and revocation are also important links in key management. Over time, keys may need to be updated or revoked for various reasons (such as key leakage, algorithm obsolescence, etc.). At this time, there needs to be an efficient and secure way to update or revoke keys and ensure the smooth distribution of new keys.

[0082] Finally, the destruction of keys is also an important part. When keys are no longer needed, they should be destroyed securely to prevent them from being misused or leaked. This usually involves multiple steps such as key deletion and physical destruction.

[0083] When implementing static data encryption in enterprise-level storage, the principle of separating keys from storage systems is adopted for security reasons. Keys should be generated and managed by a dedicated key management system (KMS) or dedicated encryption hardware on the storage system. Keys should be stored in encrypted form and should not appear in plain text in the storage system. Keys can be stored in hardware security modules (HSMs) or cryptographic devices, which have physical protection and tamper-proof functions. Key storage should follow the principle of least privilege, that is, only authorized personnel or systems can access the keys.

[0084] When implementing static data encryption in enterprise-level storage systems, a multi-level key management mechanism is usually adopted, the core of which is the hierarchical design of the master key (MK) and the data encryption key (DEK). This mechanism is designed to provide a more stringent and flexible data protection strategy to ensure the integrity and confidentiality of stored data.

[0085] As the foundation of the entire encryption system, the master key (MK) has a very high security level and is usually stored in a highly secure hardware security module (HSM) or a dedicated security processor. Its role is to generate, manage and protect the data encryption key (DEK) without directly participating in the data encryption process. This design reduces the risk of master key exposure and can protect data from damage to the greatest extent possible by limiting the access and use of the master key even in the most extreme security incidents.

[0086] The data encryption key (DEK) is directly used for data encryption and decryption operations. Compared with the master key, the number of DEKs may be larger, because each data set or file block may require a separate DEK to enhance the granularity and security of encryption. The DEK generated by the master key not only implements data encryption protection, but also allows key rotation when necessary to adapt to different security needs and compliance requirements.

[0087] This dual-layer mechanism combining the master key and the data encryption key not only improves the flexibility and scalability of the encryption system, but also significantly enhances data security through hierarchical management and independent protection of keys. It enables enterprise-level storage systems to meet the growing demand for data security and privacy protection while ensuring efficient data access, providing solid support for the company's data security strategy. Therefore, this dual-layer key management mechanism has become one of the indispensable key technologies in implementing enterprise-level storage static data encryption.

[0088] When the corresponding key is replaced regularly, the master key will be regenerated to re-encapsulate the data encryption key using the regenerated master key. Since each encryption object (such as storage pool, volume, etc.) in enterprise-level storage generally uses an independent data encryption key, when there are a large number of encryption objects, it will take a long time to re-update all data encryption keys, and the corresponding data encryption key needs to be re-encrypted when it is replaced regularly, resulting in a high corresponding replacement cost in the overall data encryption process. In order to solve the above technical problems, the key replacement method provided by the present invention can solve the above technical problems.

[0089] Figure 1 A flowchart of a key replacement method provided by an embodiment of the present invention is shown in FIG. Figure 1 As shown, the method includes:

[0090] S11: obtaining a master key to be replaced and a current master key based on a key replacement instruction; wherein the key management mechanism to which the key replacement instruction belongs includes a key encryption key;

[0091] S12: Decrypting the key encryption key using the current master key;

[0092] S13: The unsealed key encryption key is encapsulated using the master key to be replaced to complete the key replacement.

[0093] Specifically, the key replacement instruction is a key replacement trigger instruction triggered during the key replacement process, which can be actively triggered by the user, inputting the corresponding replacement operation, or selecting the corresponding replacement option on the interface; it can also be automatically set to achieve the scheduled time of replacement, automatically trigger the key replacement instruction, or it can be triggered by other methods, such as the security of the key is reduced and the master key needs to be upgraded. The triggering method is not limited and can be set according to the actual situation.

[0094] In some embodiments, the triggering process of the key replacement instruction includes:

[0095] Receiving a key request instruction triggered by a user;

[0096] According to the key request instruction, apply to the current key storage mechanism for key replacement to trigger the key replacement instruction.

[0097] Specifically, a key request instruction triggered by a user is received. Here, the key request instruction may be an instruction in a certain format input by the user, or a key request instruction is triggered by selecting a corresponding option in an interface, etc., which is not limited here. According to the key request instruction, an application is made to the current key storage mechanism for key replacement. Here, the application process is to apply for a new key as the master key to be replaced, so as to trigger the key replacement instruction.

[0098] The triggering of the key replacement instruction provided in this embodiment is based on automatic triggering by the user, thereby improving the optional flexibility of triggering the key replacement.

[0099] In some other embodiments, the triggering process of the key replacement instruction includes:

[0100] Get the time interval between the preset time interval, the previous time and the current time;

[0101] If the time interval reaches the preset time interval, a key replacement instruction is triggered for the current key storage mechanism.

[0102] Specifically, a preset time interval is set, where the preset time interval is the corresponding key update period. The time interval between the previous time and the current time corresponds to the current actual time interval. When the time interval reaches the preset time interval, a key replacement instruction for the current key storage mechanism is triggered.

[0103] The triggering of the key replacement instruction provided in this embodiment is based on the arrival of the update period, thereby enriching the triggering diversity and flexibility of the key replacement.

[0104] The master key to be replaced and the current master key are obtained. The specific acquisition process is to trigger the key replacement instruction, initiate the key update process, and the storage controller applies for a new key from the key management mechanism in the current key storage mechanism. The key management mechanism in the current key storage mechanism returns the key to the storage controller, which is the master key to be replaced. The current key storage mechanism here can be KMS or dedicated encryption hardware, which is not limited here.

[0105] It should be noted that the key management mechanism within the current key preservation mechanism in this embodiment is a multi-layer key system, which is different from the conventional multi-layer key system that only includes a master key and a data encryption key. The multi-layer key system of the key management mechanism in this embodiment includes a master key, a key encryption key, and a data encryption key. For the master key, the updated data encryption key (also called a working key or session key) is usually encrypted by the master key. In the hierarchy of key management, the master key is the highest-level key, which is used to encrypt the next level of key, namely the key encryption key, and the key encryption key is used to encrypt the data encryption key (session key). In this process, the master key remains unchanged, while the data encryption key is changed regularly to maintain the security of the system.

[0106] The master key is usually used as a seed for generating a key encryption key and a data encryption key. The key encryption key is used to encrypt the data encryption key to increase security. Even if the data encryption key is intercepted, the data encryption key cannot be decrypted without the key encryption key.

[0107] In the three-layer key system, when the current key storage mechanism is the key management service system, corresponding to the data encryption scenario, the host writes plaintext data to the storage controller; the storage controller queries the configuration library for the encapsulated data encryption key that the host should use for this write; the storage controller uses the key encryption key to decrypt the encapsulated data encryption key and obtains the data encryption key; the storage controller uses the key encryption key to complete the data encryption operation; the storage controller writes the encrypted ciphertext to the hard disk. Corresponding to the data decryption scenario, when the key management service system is used, the host sends a read data instruction to the storage controller; the storage controller queries the configuration library for the encapsulated data encryption key that the host should use for this read; the storage controller uses the key encryption key to decrypt the encapsulated data encryption key and obtains the data encryption key; the storage controller reads the encrypted data from the hard disk and uses the data encryption key obtained in the previous step to complete the data decryption operation; the storage controller sends the decrypted plaintext to the host. In the key update scenario, the user initiates the key update process; the storage controller applies for a new key from the key management service system; the key management service system returns the key to the storage controller, that is, the new master key; the storage controller uses the original master key to decrypt the key encryption key, obtains the plaintext key encryption key, and uses the new master key to re-encapsulate the plaintext key encryption key; the storage controller responds to the user that the key update has been completed.

[0108] In step S12, the key encryption key is unsealed using the current master key. The unsealing process here takes into account that during the key replacement process, the key encryption key is unsealed using the original master key (current master key) to obtain the unsealed plaintext key encryption key.

[0109] In step S13, the master key to be replaced is used to encapsulate the unsealed key encryption key to complete the key replacement. The encapsulation process here is the same as the conventional data encryption key encapsulation process, or it can be different. It is not limited here and can be set according to actual conditions. At this point, the key replacement has been completed. The key replacement in this embodiment is mainly the master key replacement, and there is no need to replace the data encryption key.

[0110] A key replacement method provided by an embodiment of the present invention obtains a master key to be replaced and a current master key based on a key replacement instruction; wherein the key management mechanism to which the key replacement instruction belongs includes a key encryption key; the key encryption key is unsealed using the current master key; the unsealed key encryption key is encapsulated using the master key to be replaced to complete the key replacement. On the one hand, in the key management mechanism, the key encryption key is used to encrypt the data encryption key, and there is no need for conventional key replacement for the replacement of the data encryption key, thereby reducing the replacement cost. There is also no need to conventionally use a new master key to re-encapsulate all data encryption keys when replacing the master key, resulting in a longer key replacement process. On the other hand, the present invention corresponds to the key replacement mainly corresponding to the update of the master key. Using the new master key (the master key to be replaced) only requires encapsulating the key encryption key to complete the key replacement process, and there is no need to re-encrypt and encapsulate all data encryption keys. The present invention only needs to update one master key, use the original master key (current master key) to decrypt the key encryption key to obtain the key encryption key in plain text, and use the new master key (the master key to be replaced) to re-encapsulate the key decryption key in plain text. There is no need to re-encapsulate a large number of data encryption keys, thereby improving the key update efficiency and reducing the impact of key update on system availability.

[0111] In some embodiments, the process of determining the key management mechanism includes:

[0112] Get the data encryption key corresponding to the current key storage mechanism;

[0113] Encapsulate the key encryption key using the current master key;

[0114] The data encryption key is encapsulated using the encapsulated key encryption key to determine the key encryption key introduced into the key management mechanism.

[0115] Specifically, the current key storage mechanism can be dedicated encryption hardware or KMS. The data encryption key corresponding to the current key storage mechanism is obtained, and the key encryption key is encapsulated using the current master key. The master key is the first key of the encryption system and needs to be generated first. The user initiates an MK generation request and sends the request to the storage controller; the storage controller requests a new key from the current key storage mechanism; the key management service system generates a key and returns the key to the storage controller; the storage controller caches the key returned by the current key storage mechanism, namely MK, in the secure memory.

[0116] In the scenario of generating a key encryption key, since the security requirement of the key encryption key is lower than that of the master key and the number of keys stored by the key storage mechanism is limited, the key encryption key is generally generated by the hardware random generator on the storage controller and then encapsulated with the master key.

[0117] The generation steps include: a user initiates a key encryption key generation scenario; a storage controller uses a hardware random number generator to generate a random number of a length that meets security requirements as a key encryption key; the storage controller uses a master key to encapsulate the key encryption key and saves the encapsulated key encryption key in a configuration library.

[0118] Similarly, corresponding to the data encryption key generation scenario, it is generally generated by the hardware random number generator on the storage controller, and then encapsulated with the key encryption key. The generation steps include: the user initiates the data encryption key generation scenario; the storage controller uses the hardware random number generator to generate a random number that meets the security requirements as the data encryption key; the storage controller uses the master key to encapsulate the data encryption key and saves the encapsulated data encryption key in the configuration library.

[0119] The configuration process of the master key, key encryption key and data encryption key provided in this embodiment is to determine the introduction of the key encryption key into the key management mechanism, which improves security compared with the conventional two-layer key system.

[0120] In some embodiments, before the unsealed key encryption key is encapsulated using the master key to be replaced, the method further includes:

[0121] Get the authentication mechanism;

[0122] Performing verification processing on the master key to be replaced according to the verification mechanism to determine the verification result;

[0123] If the verification result is passed, the process proceeds to the step of encapsulating the decrypted key encryption key using the master key to be replaced.

[0124] Specifically, based on the verification mechanism of the current key replacement, the master key to be replaced is verified based on the verification mechanism. The verification here can be to perform randomness detection on the master key to be replaced separately to correspond to the quality block of the master key, or to compare and verify the current master key and the master key to be replaced. It can also be indirectly compared and verified by comparing each master key with the key encryption key after unsealing, and it can also be indirectly compared and verified by comparing each master key with the key encryption key after encapsulation, etc. There is no limitation here, and the processing can be set according to the actual situation.

[0125] The verification mechanism provided in this embodiment verifies the master key to be replaced to obtain a verification result. Only when the verification result passes, the unsealed plaintext key encryption key is encapsulated based on the master key to be replaced, thereby improving the security of key replacement of the master key to be replaced.

[0126] In some embodiments, the master key to be replaced is verified according to the verification mechanism to determine the verification result, including:

[0127] The current master key is used as the first master key, and the master key to be replaced is used as the second master key;

[0128] Obtaining the key lengths of the first master key and the second master key;

[0129] If the key lengths of the first master key and the second master key are the same, entering the step of encapsulating the unsealed key encryption key using the master key to be replaced;

[0130] If the key lengths of the first master key and the second master key are different, and the key length of the first master key is greater than that of the second master key, the key length of the second master key is padded according to the key length of the first master key so that the padded key length of the second master key is the same as that of the first master key, and the step of encapsulating the unsealed key encryption key using the master key to be replaced is entered.

[0131] Specifically, the verification process based on the second master key is compared with the first master key. The comparison method here uses the key length of each master key. Randomness can also be used to evaluate the quality of the second master key, which is not limited here. For example, if the key lengths of the respective master keys are the same, the second master key (the master key to be replaced) is directly used to encapsulate the unsealed key encryption key. If they are different, and the key length of the first master key is greater than the key length of the second master key, it is necessary to pad the key length of the second master key based on the key length of the first master key so that the key lengths of the two master keys are the same.

[0132] If the key length of the first master key is smaller than the key length of the second master key, it is necessary to re-acquire a new second master key based on the target key storage mechanism for determination.

[0133] This embodiment provides that before using the second master key to encapsulate the unsealed key encryption key, the second master key is verified, and the key lengths of the first master key and the second master key are compared and verified to improve the accuracy of the second master key (the master key to be replaced).

[0134] In some embodiments, padding the key length of the second master key according to the key length of the first master key so that the key length of the padded second master key is the same as the key length of the first master key includes:

[0135] Performing difference processing on the key length of the first master key and the key length of the second master key to obtain the key length to be padded;

[0136] Generate a random code according to the length of the key to be completed;

[0137] The random code and the second master key are concatenated to obtain a padded second master key, so that the key length of the padded second master key is the same as the key length of the first master key.

[0138] Specifically, the key completion process generates a random code based on the length of the key to be completed, and the random code is pieced together with the second master key. The pieced together process can add a random code at the end, or fill the random code with 0 bytes, or set a specific random code corresponding to other algorithms, and the PKCS#5 Padding algorithm can be used for filling, etc.

[0139] After the completed second master key is obtained, the key length of the second master key is the same as the key length of the first master key.

[0140] The filling process of the key completion processing provided in this embodiment facilitates the subsequent second master key to encapsulate the unsealed first key, ensuring that the encapsulation processing of the second master key is successfully completed to realize the key replacement processing.

[0141] In some embodiments, the master key to be replaced is verified according to the verification mechanism to determine the verification result, including:

[0142] Get the target randomness detection mode;

[0143] Select each target detection item according to the target randomness detection mode;

[0144] Configure corresponding detection parameters according to each target detection item;

[0145] Based on each target detection item and the corresponding detection parameter, the key file of the master key to be replaced is tested to obtain the test result corresponding to each target detection item;

[0146] The test results corresponding to each target detection item are evaluated to determine the verification result of the master key to be replaced.

[0147] Specifically, the user can determine the randomness detection mode according to at least one algorithm, and can be targeted at randomness detection modes such as national secrets of national standards. The user can select the key file to be detected (the key file of the master key to be replaced) according to the needs, and import it into the randomness detection module to execute the randomness detection scheme. The randomness detection scheme here corresponds to each target detection item under the target randomness detection mode, and the corresponding detection parameters are configured according to each target detection item. Based on each target detection item and the corresponding detection parameter, the key file of the master key to be replaced is tested and processed to obtain the test results corresponding to each target detection item. The target detection items here can be single-bit frequency detection, intra-block frequency detection, run detection, longest run detection in the block, matrix rank detection, discrete Fourier transform detection, general statistical detection, linear complexity detection, cumulative sum detection, random walk detection, etc. According to the standard parameter recommendations, configure the parameters of each detection item. For example, block size M, number of blocks N, etc. Corresponding to the test result, if the test result of a test item is greater than 0.01, it is considered that the test has passed. The test results corresponding to each target detection item are evaluated and counted, and the passing ratio of the corresponding test results is compared with the preset ratio. If it is greater than the preset ratio, it is determined that the verification result of the master key to be replaced is successful.

[0148] The randomness test based on the master key to be replaced provided in this embodiment obtains corresponding quality results, reduces security vulnerabilities, and improves quantitative standards, test flexibility and applicability.

[0149] In some embodiments, after the unsealed key encryption key is encapsulated using the master key to be replaced, the method further includes:

[0150] Encapsulating the unsealed key encryption key with the master key to be replaced to obtain a first key encryption key;

[0151] comparing the first key encryption key to the key encryption key;

[0152] If the first key encryption key is the same as the key encryption key, it is determined that the master key to be replaced has been successfully verified.

[0153] Specifically, considering the verification of the master key to be replaced after encapsulation, the accuracy of the master key to be replaced is indirectly verified by comparing the first key encryption key obtained by encapsulating the unsealed key encryption key with the current master key of the current key storage mechanism.

[0154] The key data of the key encryption key (key encryption key in plain text) after the master key to be replaced is encapsulated is used as the first key encryption key, and the first key encryption key is compared with the key encryption key. The comparison process here can be a comparison between key lengths, or a comparison based on special bytes of the key encryption key, etc., which is not limited here.

[0155] The present embodiment provides that after the unsealed key encryption key is encapsulated with the master key to be replaced, the accuracy of the master key to be replaced is indirectly verified by comparing the first key encryption key. If the first key encryption key is the same as the key encryption key, it is determined that the verification of the master key to be replaced is successful, and the key replacement process of the master key is successfully completed.

[0156] In some embodiments, after the unsealed key encryption key is encapsulated using the master key to be replaced, the method further includes:

[0157] Encapsulating the unsealed key encryption key with the master key to be replaced to obtain a first key encryption key;

[0158] Using the master key to be replaced to decrypt the first key encryption key to obtain a second key encryption key;

[0159] Decrypting the key encryption key using the current master key to obtain a third key encryption key;

[0160] comparing the second key encryption key to the third key encryption key;

[0161] If the second key encryption key is the same as the third key encryption key, it is determined that the master key to be replaced is successfully verified.

[0162] In this embodiment, the accuracy of the master key to be replaced is indirectly verified based on the comparison method of the key encryption key after the unsealing process. The first key encryption key is unsealed using the master key to be replaced to obtain the second key encryption key in plain text. The second key encryption key here corresponds to the initial experimental stage and is not actually unsealed. The current master key is used to unseal the key encryption key to obtain a third key encryption key and compare it with the second key encryption key. The comparison process here can be a comparison between key lengths, or a comparison based on special bytes of the key encryption key, etc., which is not limited here. If the second key encryption key is the same as the third key encryption key, it is determined that the verification of the master key to be replaced is successful, and the master key to be replaced can be used to encapsulate the unsealed first key encryption key.

[0163] The present embodiment provides that before the unsealed key encryption key is encapsulated with the master key to be replaced, the accuracy of the master key to be replaced is indirectly verified by comparing the second key encryption key. If the unsealed second key encryption key is the same as the third key encryption key, it is determined that the verification of the master key to be replaced is successful. The master key to be replaced is verified by the unsealed second key encryption key, thereby improving the fairness and authority of the verification and ensuring the accuracy of the encapsulation of the key encryption key.

[0164] In some embodiments, when the key replacement instruction is triggered, if the current key storage mechanism to which the current master key belongs satisfies the switching condition of the key storage mechanism, after obtaining the master key to be replaced and the current master key based on the key replacement instruction, the method further includes:

[0165] Get the key encryption key corresponding to the current key storage mechanism;

[0166] Using the current master key to decrypt the key encryption key corresponding to the current key storage mechanism to obtain a fourth key encryption key;

[0167] Obtain the first master key corresponding to the target key storage mechanism;

[0168] The fourth key encryption key is encapsulated using the first master key to complete the switching process from the current key storage mechanism to the target key storage mechanism.

[0169] Considering that enterprise-level storage uses a proprietary key storage mechanism for static data encryption, and there are multiple key storage mechanisms to ensure data security. Currently, key storage mechanism A is used for key management. If key storage mechanism A fails during the key management process and needs to be switched to key storage mechanism B, the existing data, master key and data encryption key encrypted by key storage mechanism A need to be deleted. That is, after the entire key storage mechanism A is completed and deleted, it is switched to the new key management mechanism of key storage mechanism B for reconfiguration, obtaining a new master key and a new data encryption key to re-encrypt the data. This repetitive operation affects the original encryption business, which in turn reduces storage availability.

[0170] In this embodiment, the current key preservation mechanism satisfies the switching conditions of the key preservation mechanism, which may be a switching instruction corresponding to the switching conditions issued to trigger the key preservation mechanism. The specific time of the trigger may be based on different application scenarios, such as the failure or attack scenario of the current key preservation mechanism, or the storage device corresponding to the current key preservation mechanism is in a relocation state and needs to be temporarily switched. It may also be an experimental state corresponding to multiple key preservation mechanisms to compare and determine which key preservation mechanism to select.

[0171] When the current key storage mechanism meets the switching conditions of the key storage mechanism, the current master key is used to unseal the key encryption key corresponding to the current key storage mechanism. The unseal processing here takes into account the switching process, and uses the master key (current master key) to unseal the key encryption key corresponding to the current key storage mechanism to obtain the fourth key encryption key in plain text after unsealing.

[0172] Obtain the first master key corresponding to the target key storage mechanism. The generation process of the first master key here is the same as the generation process of the current master key corresponding to the current key storage mechanism, that is, the user initiates a master key generation request and sends the request to the storage controller. The storage controller requests a new key from the respective key storage mechanism. The respective key storage mechanisms generate a key and return this key as their respective master key to the storage controller. The storage controller caches the returned master key in the secure memory. The acquisition step here and the above-mentioned step of obtaining the key encryption key corresponding to the current key storage mechanism can be executed sequentially or simultaneously with obtaining the key encryption key corresponding to the current key storage mechanism. This is not limited here. Considering the configuration information of the current key storage mechanism and the target key storage mechanism, it can be the configuration work completed before switching the key storage mechanism, or it can be the configuration of the target key storage mechanism when the switching conditions are met. The two methods are not limited.

[0173] In some embodiments, the process of obtaining the target key storage mechanism includes:

[0174] Obtain the configuration information of the target key storage mechanism in advance;

[0175] Synchronize with the process of obtaining the configuration information of the current key storage mechanism to obtain the target key storage mechanism;

[0176] Alternatively, when the current key storage mechanism meets the switching condition of the key storage mechanism, the configuration information of the target key storage mechanism is obtained so as to obtain the target key storage mechanism.

[0177] Specifically, the configuration information of the target key storage mechanism may be obtained in advance, and synchronized with the key encryption key acquisition process corresponding to the current key storage mechanism in the above embodiment to obtain the target key storage mechanism. Alternatively, when the switching condition is met and the target key switching mechanism needs to be switched, the configuration information of the target key storage mechanism is obtained to complete the acquisition process of the target key storage mechanism.

[0178] This embodiment provides a configuration sequence of corresponding configuration information during the acquisition process of the target key storage mechanism to enrich the flexibility of configuration of the configuration information of the target key storage mechanism.

[0179] In some embodiments, the process of determining whether the current key storage mechanism satisfies the switching condition of the key storage mechanism includes:

[0180] Receiving a key storage mechanism switching instruction issued by a host; wherein the parameters corresponding to the switching instruction at least include a current key storage mechanism, a current master key, and a target key storage mechanism;

[0181] If the switching instruction of the key storage mechanism is a valid switching instruction, it is determined that the current key storage mechanism meets the switching condition of the key storage mechanism.

[0182] Specifically, a switching instruction of the key storage mechanism sent by the host is received. It can be understood that the host refers to the user-side host, the data read and written by the host is plain text data, and the host cannot perceive the encryption and decryption operations of the data. Figure 2 A schematic diagram of a plurality of key storage mechanisms in a storage system provided by an embodiment of the present invention, such as Figure 2 As shown, key management supports both a dedicated key management service system and dedicated encryption hardware on the storage system, allowing enterprise-level storage to switch key preservation mechanisms without affecting existing encryption services. The storage system, that is, the storage array, is responsible for completing encryption and decryption operations on user data. The dedicated encryption hardware is built into the storage system and is responsible for key management, that is, key generation, destruction, and preservation, etc., when the key management service system is not in use. Similarly, the key management service system is responsible for key generation, destruction, and preservation, etc., when the dedicated encryption hardware built into the storage system is not in use.

[0183] The switching instruction at least includes the current key storage mechanism, the current master key currently in use, and the target key storage mechanism. The processing of the switching instruction requires that the switching instruction of the corresponding key storage mechanism is a valid switching instruction, which can be triggered by setting the valid flag bit, that is, determining that the current key storage mechanism meets the switching conditions of the key storage mechanism.

[0184] In addition, the processing process of its instructions, for example, the key storage mechanism currently in use is A, the new key storage mechanism is B, the master key in use is Master_Key_A, the data encryption key Data_Encryption_Key in use, there are multiple Data Encryption Keys in the system, one for each storage pool or each volume according to the configuration. These data encryption keys have been wrapped by Master_Key_A and recorded as Data_Encryption_Key_Wrapped_by_Master_Key_A. The storage system receives the issued command and obtains the above parameters, including A, B, and Master_Key_A. The storage system checks whether Master_key_A is the same as the master key in use in the system. If they are not the same, an error message is prompted and the process ends. The storage system applies to B for a new master key, Master_key_B. If the application fails, an error message is prompted and the process ends. The storage system uses Master_Key_A to unseal all Data_Encryption_Key_Wrapped_by_Master_Key_A in the system to obtain Data_Encryption_Key. The storage system uses Master_Key_B to encrypt and wrap Data_Encryption_Key to obtain Data_Encryption_Key_Wrapped_by_Master_Key_B. The storage system destroys Master_Key_A. Command feedback: After the storage system completes the key management mode switch, it will feedback the execution result to the user. The feedback result carries the following parameters: Execution result: success or failure; error message (optional), when the execution result is failure, the error message is filled; the key management mode currently used, A or B.

[0185] Therefore, the setting of its effective flag bit can be switched based on a certain scenario trigger, which is not limited here.

[0186] The setting of the valid flag bit of the valid switching instruction provided in this embodiment improves the simplicity and operability of determining whether the current key storage mechanism satisfies the switching condition of the key storage mechanism.

[0187] In some embodiments, determining that the switching instruction of the key storage mechanism is a valid switching instruction includes:

[0188] When the storage device to which the current key storage mechanism belongs is in a waiting-for-relocation state, the switching instruction of the key storage mechanism is converted from an invalid switching instruction to a valid switching instruction.

[0189] Specifically, when the storage device to which the current key storage mechanism belongs is in a state to be relocated, the current key storage mechanism needs to be temporarily disabled. Corresponding to the key storage during the relocation process, it needs to be switched to the target key storage mechanism, so the switching instruction of the key storage mechanism needs to be switched from an invalid switching instruction to a valid switching instruction. When the storage device relocation is completed, the target key storage mechanism needs to be switched to the current key storage mechanism.

[0190] In the migration state provided in this embodiment, if the key storage mechanism of the corresponding storage device needs to be switched, the flag bit of the invalid switching instruction is converted into a valid switching instruction to complete the subsequent key storage mechanism switching process.

[0191] In some embodiments, determining that the switching instruction of the key storage mechanism is a valid switching instruction includes:

[0192] Get the working status of the current key storage mechanism;

[0193] If the working state is a fault state or an attack state, the switching instruction of the key storage mechanism is converted into a valid switching instruction.

[0194] Specifically, if the working state of the current key storage mechanism is a fault state or an attack state, it means that the current key storage mechanism is abnormal and needs to be switched to other key storage mechanisms for key management, so the switching instruction is converted into a valid switching instruction.

[0195] If the key preservation mechanism in the fault state or attack state provided in this embodiment needs to be switched, the invalid switching instruction is converted into a flag setting of a valid switching instruction to facilitate the subsequent switching processing of the key preservation mechanism and improve the data security under the key preservation mechanism.

[0196] In some embodiments, after the key storage mechanism in the above-mentioned fault state or attack state is replaced, after the fourth key encryption key is encapsulated by using the first master key, it also includes:

[0197] Delete and destroy the current master key of the current key storage mechanism;

[0198] Release the storage space of the current key storage mechanism.

[0199] Specifically, the current master key of the current key storage mechanism is deleted and destroyed to release storage space, thereby saving storage space and releasing resources.

[0200] Taking the switching scenario from using the key management service system to using dedicated encryption hardware as an example, the user initiates the key management mode switching process and specifies the new key management mode as using dedicated encryption hardware to manage keys; the storage controller applies for a new master key from the dedicated encryption hardware; the storage controller uses the original master key to unseal the data encryption key and obtains the unseal data encryption key; the storage controller uses the newly applied master key to re-encapsulate the data encryption key; the storage controller deletes the original master key stored on the key management service system; the storage controller responds to the user that the key management mode switching is completed. Similarly, the switching scenario of switching from using dedicated encryption hardware to the key management service system is the same as the above switching scenario, which will not be repeated here.

[0201] In some embodiments, determining that the switching instruction of the key storage mechanism is a valid switching instruction includes:

[0202] Pre-acquire the current number of experiments and the preset number of experiments of the current key preservation mechanism;

[0203] When the current number of experiments reaches the preset number of experiments, the switching instruction of the key preservation mechanism is converted into a valid switching instruction.

[0204] Specifically, in the actual application process of the key preservation mechanism, experiments can be carried out corresponding to multiple key preservation mechanisms. The experimental process here is not limited, and it mainly corresponds to the quality inspection of key management of different key preservation mechanisms, or corresponds to the performance inspection of the storage system, etc., to obtain the current number of experiments and the preset number of experiments of the current key preservation mechanism. If the current number of experiments reaches the preset number of experiments, the switching instruction will be converted into a valid switching instruction.

[0205] When the current number of experiments of the current key preservation mechanism provided in this embodiment reaches the preset number of experiments, the mechanism is switched, and its invalid switching instruction is converted into a flag setting of a valid switching instruction, so as to complete the subsequent switching processing of the key preservation mechanism, that is, complete the experiment of the target key preservation mechanism, improve the experimental processing efficiency under multiple key preservation mechanisms, and make the switching process connected without delay.

[0206] In some embodiments, considering the experimental process of the target key storage mechanism, after completing the switching process from the current key storage mechanism to the target key storage mechanism, the method further includes:

[0207] Running the key life cycle under the target key preservation mechanism according to a preset number of experiments;

[0208] When the current number of experiments of the target key storage mechanism reaches the preset number of experiments, the key operation effects corresponding to the current key storage mechanism and the target key storage mechanism are obtained;

[0209] The key operation effects corresponding to the current key preservation mechanism and the target key preservation mechanism are compared to determine the comparison result of the current key preservation mechanism and the target key preservation mechanism, and determine the final key preservation mechanism.

[0210] Specifically, after the experiments of the current key preservation mechanism and the target key preservation mechanism are completed, it is necessary to obtain the key operation effect corresponding to each key preservation mechanism, that is, the quality detection effect, and compare them. If the key operation effect of the current key preservation mechanism and the target key preservation mechanism are the same, you can choose any one, or select the final key preservation mechanism based on other factors. If the key operation effect of the current key preservation mechanism is better than the key operation effect of the target key preservation mechanism, the current key preservation mechanism is selected as the final key preservation mechanism. If the key operation effect of the target key preservation mechanism is better than the key operation effect of the current key preservation mechanism, the target key preservation mechanism is selected as the final key preservation mechanism.

[0211] This embodiment provides an experimental comparison based on the current key storage mechanism and the target key storage mechanism to determine the comparison results of the respective key operation effects and improve the accuracy of the selection under the final key storage mechanism.

[0212] It should be noted that in this embodiment, the switching process between the current key storage mechanism and the target key storage mechanism is involved. The master key of the target key storage mechanism may be the same as or different from the verification process corresponding to the master key to be replaced in the key replacement process in the above embodiment, and is not limited here.

[0213] When the current key storage mechanism meets the switching condition of the key storage mechanism, the switching mechanism of the key storage mechanism is triggered, and the key encryption key is unsealed using the current master key corresponding to the current key storage mechanism to obtain the plain text form of the unsealed key encryption key. There is no need to use the unsealed key encryption key to decrypt the data under the current key storage mechanism itself, and the first master key of the target key storage mechanism is directly used to encapsulate the plain text data of the unsealed key encryption key to switch to the target key storage mechanism. There is no need to encrypt the data itself, and the online switching of the key storage mechanism is realized by unsealing and encapsulating the master key and key encryption key under each key storage mechanism. On the other hand, through the unsealing and encapsulation of the keys (the master key and key encryption key of each key storage mechanism), there is no need to reconfigure the encryption of the data based on the new key management mechanism, that is, there is no need to perform repetitive operations of decrypting and encrypting the data itself, saving switching efficiency. At the same time, the data of the current encryption business itself is not affected in any way, improving the storage availability and the flexibility of online switching of different key storage mechanisms.

[0214] Figure 3 A schematic diagram of a key update scenario when using a key management service system provided by an embodiment of the present invention, such as Figure 3 As shown, the user initiates the key update process; the storage controller applies for a new key from the key management service system; the key management service system returns the key to the storage controller, that is, the new MK; the storage controller uses the original master key to decapsulate the KEK, obtains the plaintext KEK, and re-encapsulates the plaintext KEK with the new master key; the storage controller responds to the user that the key update has been completed. Figure 4 A schematic diagram of a key update scenario when using dedicated encryption hardware is provided in an embodiment of the present invention, such as Figure 4 As shown, the user initiates the key update process; the storage controller applies for a new key from the dedicated encryption hardware; the dedicated encryption hardware returns the key to the storage controller, that is, the new MK; the storage controller uses the original master key to decapsulate the KEK, obtains the plaintext KEK, and re-capsulates the plaintext KEK with the new master key; the storage controller responds to the user that the key update has been completed. Furthermore, the present invention also provides a cluster system, the cluster system includes multiple nodes; the cluster system is used to perform the above-mentioned key replacement steps to perform key management.

[0215] For an introduction to a cluster system provided by the present invention, please refer to the above method embodiment, which will not be described in detail herein. The present invention has the same beneficial effects as the above key replacement method.

[0216] The above describes in detail various embodiments corresponding to the key replacement method. On this basis, the present invention also discloses a key replacement device corresponding to the above method. Figure 5 This is a structural diagram of a key replacement device provided by an embodiment of the present invention. Figure 5 As shown, the key replacement device includes:

[0217] An acquisition module 11 is used to acquire a master key to be replaced and a current master key based on a key replacement instruction; wherein the key management mechanism to which the key replacement instruction belongs includes a key encryption key;

[0218] The decryption processing module 12 is used to decrypt the key encryption key using the current master key;

[0219] The encapsulation processing module 13 is used to encapsulate the unsealed key encryption key using the master key to be replaced to complete the key replacement.

[0220] Since the embodiments of the device part correspond to the above embodiments, please refer to the description of the embodiments of the method part for the embodiments of the device part, and will not be repeated here.

[0221] For an introduction to a key replacement device provided by the present invention, please refer to the above method embodiment, and the present invention will not be repeated here. It has the same beneficial effects as the above key replacement method.

[0222] Figure 6 A structural diagram of a key replacement device provided by an embodiment of the present invention, such as Figure 6 As shown, the device comprises:

[0223] A memory 21, used for storing computer programs;

[0224] The processor 22 is used to implement the steps of the key replacement method when executing the computer program.

[0225] The key replacement device provided in this embodiment may include but is not limited to a tablet computer, a laptop computer, or a desktop computer.

[0226] Among them, the processor 22 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 22 may be implemented in at least one hardware form of a digital signal processor (DSP), a field-programmable gate array (FPGA), and a programmable logic array. The processor 22 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 22 may be integrated with a graphics processing unit (GPU), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 22 may also include an artificial intelligence (AI) processor, which is used to process computing operations related to machine learning.

[0227] The memory 21 may include one or more computer-readable storage media, which may be non-transitory. The memory 21 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory 21 is at least used to store the following computer program 211, wherein, after the computer program is loaded and executed by the processor 22, it can implement the relevant steps of the key replacement method disclosed in any of the aforementioned embodiments. In addition, the resources stored in the memory 21 may also include an operating system 212 and data 213, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 212 may include Windows, Unix, Linux, etc. The data 213 may include, but is not limited to, data involved in the key replacement method, etc.

[0228] In some embodiments, the key replacement device may further include a display screen 23 , an input / output interface 24 , a communication interface 25 , a power supply 26 , and a communication bus 27 .

[0229] Those skilled in the art can understand that Figure 6 The structure shown in the figure does not constitute a limitation on the key replacement device, and may include more or less components than those shown in the figure.

[0230] The processor 22 implements the key replacement method provided by any of the above embodiments by calling the instructions stored in the memory 21 .

[0231] For an introduction to a key replacement device provided by the present invention, please refer to the above method embodiment, and the present invention will not be repeated here. It has the same beneficial effects as the above key replacement method.

[0232] Furthermore, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by the processor 22, the steps of the key replacement method as described above are implemented.

[0233] It is understandable that if the method in the above embodiment is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium to execute all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program codes.

[0234] For an introduction to a computer-readable storage medium provided by the present invention, please refer to the above method embodiment, which will not be described in detail herein. It has the same beneficial effects as the above key replacement method.

[0235] Furthermore, the present invention also provides a computer program product, including a computer program / instruction, which implements the steps of the key replacement method when executed by a processor.

[0236] For an introduction to a computer program product provided by the present invention, please refer to the above method embodiment, which will not be described in detail herein. It has the same beneficial effects as the above key replacement method.

[0237] The key replacement method, cluster system, device, medium and product provided by the present invention are introduced in detail above. The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same and similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description. It should be pointed out that for ordinary technicians in this technical field, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the scope of protection of the present invention.

[0238] It should also be noted that, in this specification, relational terms such as first and second, etc. are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises", "comprising" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprising a ..." does not exclude the presence of other identical elements in the process, method, article or device including the element.

Claims

1. A key replacement method, characterized in that: include: Based on the key replacement instruction, a master key to be replaced and a current master key are obtained; wherein the key management mechanism to which the key replacement instruction belongs includes a key encryption key; the key encryption key is used to encrypt a data encryption key; Decrypting the key encryption key using the current master key; The unsealed key encryption key is encapsulated using the master key to be replaced to complete the key replacement.

2. The key replacement method according to claim 1, characterized in that: The process of determining the key management mechanism includes: Get the data encryption key corresponding to the current key storage mechanism; Using the current master key to encapsulate the key encryption key; The data encryption key is encapsulated by using the encapsulated key encryption key to ensure that the key encryption key is introduced into the key management mechanism.

3. The key replacement method according to claim 1, characterized in that: Before the unsealed key encryption key is encapsulated by using the master key to be replaced, the method further includes: Get the authentication mechanism; Performing verification processing on the master key to be replaced according to the verification mechanism to determine a verification result; If the verification result is passed, the process proceeds to the step of encapsulating the unsealed key encryption key using the master key to be replaced.

4. The key replacement method according to claim 3, characterized in that: Performing verification processing on the master key to be replaced according to the verification mechanism to determine a verification result includes: Using the current master key as the first master key and using the master key to be replaced as the second master key; Obtaining the key length of each of the first master key and the second master key; If the key lengths of the first master key and the second master key are the same, entering the step of encapsulating the unsealed key encryption key using the master key to be replaced; If the key lengths of the first master key and the second master key are different, and the key length of the first master key is greater than that of the second master key, the key length of the second master key is padded according to the key length of the first master key so that the key length of the padded second master key is the same as that of the first master key, and the process proceeds to the step of encapsulating the unsealed key encryption key using the master key to be replaced.

5. The key replacement method according to claim 4, characterized in that: The key length of the second master key is padded according to the key length of the first master key so that the key length of the padded second master key is the same as the key length of the first master key, including: Performing difference processing on the key length of the first master key and the key length of the second master key to obtain the key length to be padded; Generate a random code according to the length of the key to be padded; The random code and the second master key are concatenated to obtain a padded second master key, so that a key length of the padded second master key is the same as a key length of the first master key.

6. The key replacement method according to claim 3, characterized in that: Performing verification processing on the master key to be replaced according to the verification mechanism to determine a verification result includes: Get the target randomness detection mode; Select each target detection item according to the target randomness detection mode; Configure corresponding detection parameters according to each of the target detection items; Based on each of the target detection items and the corresponding detection parameters, the key file of the master key to be replaced is tested to obtain the test results corresponding to each of the target detection items; The test results corresponding to each of the target detection items are evaluated to determine the verification result of the master key to be replaced.

7. The key replacement method according to claim 1, characterized in that: After the unsealed key encryption key is encapsulated by using the master key to be replaced, the method further includes: Encapsulating the unsealed key encryption key with the master key to be replaced to obtain a first key encryption key; comparing the first key encryption key with the key encryption key; If the first key encryption key is the same as the key encryption key, it is determined that the master key to be replaced is successfully verified.

8. The key replacement method according to claim 1, characterized in that: After the unsealed key encryption key is encapsulated by using the master key to be replaced, the method further includes: Encapsulating the unsealed key encryption key with the master key to be replaced to obtain a first key encryption key; Using the master key to be replaced to decrypt the first key encryption key to obtain a second key encryption key; Decrypting the key encryption key using the current master key to obtain a third key encryption key; comparing the second key encryption key with the third key encryption key; If the second key encryption key is the same as the third key encryption key, it is determined that the verification of the master key to be replaced is successful.

9. The key replacement method according to claim 1, characterized in that: When the key replacement instruction is triggered, if the current key storage mechanism to which the current master key belongs satisfies the switching condition of the key storage mechanism, after obtaining the master key to be replaced and the current master key based on the key replacement instruction, the method further includes: Get the key encryption key corresponding to the current key storage mechanism; Using the current master key to decrypt the key encryption key corresponding to the current key storage mechanism to obtain a fourth key encryption key; Obtain the first master key corresponding to the target key storage mechanism; The fourth key encryption key is encapsulated by using the first master key to complete the switching process from the current key storage mechanism to the target key storage mechanism.

10. The key replacement method according to claim 1, characterized in that: The triggering process of the key replacement instruction includes: Receiving a key request instruction triggered by a user; According to the key request instruction, an application is made to the current key storage mechanism for key replacement to trigger the key replacement instruction.

11. The key replacement method according to claim 1, characterized in that: The triggering process of the key replacement instruction includes: Get the time interval between the preset time interval, the previous time and the current time; If the time interval reaches the preset time interval, the key replacement instruction is triggered for the current key storage mechanism.

12. A cluster system, characterized in that: The cluster system includes a plurality of nodes; the cluster system is used to execute the steps of the key replacement method described in any one of claims 1 to 11 to perform key management.

13. A key replacement device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the key replacement method according to any one of claims 1 to 11 when executing the computer program.

14. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the key replacement method according to any one of claims 1 to 11 are implemented.

15. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the steps of the key replacement method according to any one of claims 1 to 11 are implemented.

Citation Information

Patent Citations

  • Data protection method, data protection device, computer equipment and storage medium

    CN118536140A