A time window based cipher key smooth transition system
By using a time-window-based cryptographic key smooth transition system, the problems of unsmooth and unstable key transitions in existing technologies are solved, achieving smoothness and stability in key transitions and improving the security and reliability of cryptographic machines.
Patent Information
- Application Number
- CN202411452161.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-17
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2044-10-17
AI Technical Summary
In existing cryptographic key transition technologies, fixed-time replacement schemes result in an uneven key transition and are prone to packet loss. Negotiated replacement schemes are not suitable for scenarios with high data interaction latency and high packet loss rates, which affects the stability and reliability of cryptographic machines.
A time-window-based cryptographic key smooth transition system is adopted. The system collects operational data through a data analysis module, analyzes key transition index values and time window parameters, adjusts the time window parameters for key smooth transition, and updates the key based on the key smooth update results. The key time window is designed to achieve a smooth transition.
It improves the smoothness and stability of the key transition process, reduces key transition errors, enhances the security and reliability of the cryptographic machine, reduces repeated adjustments and security risks caused by poor key transition, and improves the security protection capabilities of the cryptographic machine.
Smart Images

Figure CN119449287B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of key distribution, in particular to a password machine key smooth transition system based on a time window. BACKGROUND
[0002] In the field of password machine key transition technology, real-time processing technology can be used to monitor and process password machine data, and timely password machine key transition. The unreasonable password machine key transition method directly affects the use of the password machine, which may cause high data interaction delay and high packet loss rate in the key transition process, thereby affecting the stability and reliability of the password machine and affecting the performance of the password machine.
[0003] The prior art, such as the invention patent CN109802827B, discloses a key update method and a key update system, which comprises the following steps: when the first terminal device receives the key update command, it sends the key update command to the second terminal device; the second terminal device acquires the key flag bit of the first terminal device after receiving the key update command, and judges whether the key flag bit of the first terminal device is the same as the key flag bit of the second terminal device, if the same, then update the key of the second terminal device and the key flag bit of the second terminal device, and send the update success information to the first terminal device; the first terminal device updates the key of the first terminal device and the key flag bit of the first terminal device after receiving the update success information.
[0004] The prior art, such as the invention patent CN101562521B, discloses a key update method, which comprises the following steps: a, reading the even key as the initialization vector; inputting the initialization vector into the password system; b, intercepting a predetermined length of key stream output by the password system to update the odd key; c, using the even key to encrypt and decrypt data; d, when the predetermined key update time arrives, reading the odd key as the initialization vector; inputting the initialization vector into the password system; e, intercepting a predetermined length of key stream output by the password system to update the even key; f, using the odd key to encrypt and decrypt data; g, when the predetermined key update time arrives, returning to step a.
[0005] In combination with the above scheme, it is found that in the field of password machine key transition technology, there are usually two key update schemes, namely fixed time replacement scheme and negotiation replacement scheme. The fixed time replacement scheme has the problems of not smooth key transition, long replacement data and dependence on accurate time calibration of both password machines, while the negotiation replacement scheme depends on data interaction between both password machines, which is not suitable for scenes with high data interaction delay and high packet loss rate. SUMMARY
[0006] In view of the deficiencies of the prior art, the present application provides a time window-based cryptographic machine key smooth transition system, which can effectively solve the problems involved in the background art.
[0007] To achieve the above object, the present application is implemented by the following technical solutions: a time window-based cryptographic machine key smooth transition system, comprising a data analysis module, which is used to collect relevant operation data of the cryptographic machine, analyze the key transition indicator value of the cryptographic machine, and further analyze the adjustment result of the cryptographic machine time window parameter.
[0008] A key transition module is used to obtain the time window parameter of the key smooth transition of the cryptographic machine according to the adjustment result of the cryptographic machine time window parameter, and perform the key transition of the cryptographic machine in combination with the time window parameter of the key smooth transition of the cryptographic machine.
[0009] A key transition flow analysis module is used to analyze the key transition flow of the cryptographic machine, obtain the key security indicator value of the cryptographic machine, further analyze the key smooth update result of the cryptographic machine, and perform the key update according to the key smooth update result of the cryptographic machine, analyze the key in the key update time period, and prompt adjustment.
[0010] Further, the relevant operation data of the cryptographic machine includes the data flow of the cryptographic machine, the data processing amount of the cryptographic machine, and the total number of key calls of the cryptographic machine.
[0011] The time window parameter of the key smooth transition of the cryptographic machine includes the maximum clock error of the cryptographic machine, the maximum network delay of the cryptographic machine, the key enable time of the cryptographic machine, the key disable time of the cryptographic machine, the key pre-enable time of the cryptographic machine, and the key invalidation time of the cryptographic machine.
[0012] Further, the analysis of the key transition indicator value of the cryptographic machine includes the following specific analysis process: setting a plurality of supervision periods, taking the ratio of the total number of key calls of the cryptographic machine in each supervision period to the duration of the supervision period as the key call frequency of the cryptographic machine in each supervision period.
[0013] The data flow of the cryptographic machine and the data processing amount of the cryptographic machine in each supervision period are counted, and the key transition indicator value of the cryptographic machine is comprehensively analyzed in combination with the key call frequency of the cryptographic machine in each supervision period, which is used to comprehensively quantify the influence degree of the data flow and data processing amount of the cryptographic machine on the key transition quality of the cryptographic machine.
[0014] Further, the analysis of the adjustment result of the cryptographic machine time window parameter includes the following specific analysis process: comparing the key transition indicator value of the cryptographic machine with the set key transition indicator threshold value of the cryptographic machine to obtain the adjustment result of the cryptographic machine time window parameter.
[0015] The adjustment result of the cryptographic machine time window parameter includes needing adjustment and not needing adjustment, wherein if the cryptographic machine key transition index value is higher than or equal to the set cryptographic machine key transition index threshold value, the adjustment result of the cryptographic machine time window parameter is needing adjustment, and if the cryptographic machine key transition index value is lower than the set cryptographic machine key transition index threshold value, the adjustment result of the cryptographic machine time window parameter is not needing adjustment.
[0016] Further, the cryptographic machine time window parameter is adjusted according to the adjustment result of the cryptographic machine time window parameter, and the time window parameter for smooth transition of the cryptographic machine key is obtained. The specific analysis process is as follows: if the adjustment result of the cryptographic machine time window parameter is needing adjustment, the time window correction parameter for smooth transition of the cryptographic machine key is obtained according to the cryptographic machine key transition index value matching, and the time window correction parameter for smooth transition of the cryptographic machine key is added to the corresponding time window parameter for smooth transition of the cryptographic machine key stored in the cryptographic machine key transition database, serving as the time window parameter for smooth transition of the cryptographic machine key.
[0017] If the adjustment result of the cryptographic machine time window parameter is not needing adjustment, the time window parameter for smooth transition of the cryptographic machine key stored in the cryptographic machine key transition database is taken as the time window parameter for smooth transition of the cryptographic machine key.
[0018] Further, the cryptographic machine key transition is performed in combination with the time window parameter for smooth transition of the cryptographic machine key. The specific process is as follows: the time window of the key is designed according to the time window parameter for smooth transition of the cryptographic machine key.
[0019] The specific process of designing the time window of the key is as follows: the adjusted time window parameter for smooth transition of the cryptographic machine key is arranged in time sequence as pre-activation time, activation time, deactivation time and invalidation time, and the time window of the key is obtained by dividing the unactivated state, the to-be-activated state, the activated state, the to-be-invalidated state and the invalidated state of the cryptographic machine key.
[0020] The cryptographic machine key transition is performed in combination with the time window of the key. The specific process is as follows: the key information on the current cryptographic machine is obtained, including the pre-activation time, the activation time, the deactivation time and the invalidation time of the key of the current cryptographic machine, the time window of the new key of the cryptographic machine is designed, the pre-activation time, the activation time, the deactivation time and the invalidation time of the new key of the cryptographic machine are determined, and the deactivation time of the key of the current cryptographic machine is set as the activation time of the new key of the cryptographic machine.
[0021] Further, the cryptographic machine key transition process is analyzed. The specific analysis process is as follows: the analysis of the cryptographic machine key transition process includes the analysis of the response duration of the decryption operation of the cryptographic machine, the total number of decryption failures of the cryptographic machine and the key calling frequency of the cryptographic machine.
[0022] The response time of the decryption operation of the cryptographic machine in each supervision period and the total number of decryption failures of the cryptographic machine are monitored, the key calling frequency of the cryptographic machine in each supervision period is combined, and a weighted analysis is performed to obtain a key security index value of the cryptographic machine in each supervision period, which is used to comprehensively quantify the influence degree of the response time of the decryption operation and the total number of decryption failures of the cryptographic machine on the key security quality of the cryptographic machine.
[0023] Further, the analysis obtains a key smooth update result of the cryptographic machine, and the specific analysis process is that the key smooth update result of the cryptographic machine includes a need for update and a no need for update.
[0024] The key security index value of the cryptographic machine in each supervision period is compared with a set key security index threshold value of the cryptographic machine to obtain a key smooth update result of the cryptographic machine. If the key security index value of the cryptographic machine in a certain supervision period is higher than or equal to the set key security index threshold value of the cryptographic machine, the key smooth update result of the cryptographic machine in the supervision period is set to no need for update.
[0025] If the key security index value of the cryptographic machine in a certain supervision period is lower than the set key security index threshold value of the cryptographic machine, the key smooth update result of the cryptographic machine in the supervision period is set to need for update, and then the key is updated according to the key smooth update result and in combination with the adjusted time window parameter of the key smooth transition of the cryptographic machine.
[0026] Further, the key is updated according to the key smooth update result and in combination with the adjusted time window parameter of the key smooth transition of the cryptographic machine, and the specific analysis process is that if the key smooth update result of the cryptographic machine is need for update, the key setting is updated, and the time window of the updated key is designed in combination with the adjusted time window parameter of the key smooth transition of the cryptographic machine, the original key is updated to the updated key, the updated key enabling time is set to the original key disabling time, the original key original disabling time is set to the updated key disabling time, and the original key original invalidation time is set to the updated key invalidation time.
[0027] Further, the key transition index value of the cryptographic machine, and the specific analysis condition is that:
[0028] In the formula, α represents the key transition index value of the cryptographic machine, A 1→i represents the data flow of the cryptographic machine in the i th supervision period, represents the weight factor corresponding to the set data flow, A 2→i represents the data processing amount of the cryptographic machine in the i th supervision period, represents the weight factor corresponding to the set data processing amount, A3→i represents the key calling frequency of the cryptographic machine in the i-th supervision cycle, represents the weight factor corresponding to the set key calling frequency, i represents the number of each supervision cycle, i = 1, 2, 3, … n, n represents the total number of supervision cycles.
[0029] The present application has the following beneficial effects:
[0030] (1) The present application provides a cryptographic machine key smooth transition system based on a time window. First, the adjustment result of the cryptographic machine time window parameter is analyzed to accurately evaluate whether the cryptographic machine time window parameter needs to be adjusted. Then, the time window parameter of the cryptographic machine key smooth transition is analyzed to improve the smoothness and stability of the key transition process. Finally, the key update result of the cryptographic machine key smooth update is analyzed to improve the security of the key.
[0031] (2) The present application can reduce key transition errors caused by parameter mismatch by analyzing the adjustment result of the cryptographic machine time window parameter, improve the accuracy of key transition operation, reduce the possible interruption or instability in the key transition process, improve the stability and reliability of the cryptographic machine, reduce the risk of security vulnerabilities or operation interruption that may occur during the key transition of the cryptographic machine, and enhance the security of the cryptographic machine.
[0032] (3) The present application can reduce the error rate in the key transition of the cryptographic machine by combining the key transition of the cryptographic machine with the time window parameter of the cryptographic machine key smooth transition, accurately setting the time window parameter, thereby improving the accuracy of the key replacement operation, reducing repeated adjustments caused by poor key transition of the cryptographic machine, improving the efficiency of the key transition operation, saving time and resources, and enhancing the reliability of the cryptographic machine.
[0033] (4) The present application can help reduce the service interruption of the cryptographic machine due to key leakage by analyzing the key smooth update result of the cryptographic machine and updating the key according to the key smooth update result of the cryptographic machine, timely and accurately updating the key to reduce the security risk caused by key leakage or suspected leakage, improve the security protection capability of the cryptographic machine, and quickly and accurately complete the key update, thereby improving the response capability of the cryptographic machine.
[0034] Of course, implementing any product of the present application does not necessarily require all the advantages described above. BRIEF DESCRIPTION OF DRAWINGS
[0035] Figure 1 The present application has the following beneficial effects:
[0036] Figure 2An example diagram of a key security indicator value for a cryptographic machine.
[0037] Figure 3 An example diagram of a time window for a key of a cryptographic machine.
[0038] Figure 4 An example diagram of a process for key transition for a single cryptographic machine.
[0039] Figure 5 An example diagram of a process for key transition for two cryptographic machines.
[0040] Figure 6 An example diagram of a process for key update for a cryptographic machine. DETAILED DESCRIPTION
[0041] The technical solutions in the embodiments of the present application will be apparently and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0042] Please refer to Figure 1 the technical solutions provided by the embodiments of the present application: a time window-based cryptographic machine key smooth transition system, comprising a data analysis module, configured to collect relevant operation data of a cryptographic machine, analyze to obtain a key transition indicator value of the cryptographic machine, and further analyze to obtain an adjustment result of a time window parameter of the cryptographic machine.
[0043] A key transition module, configured to obtain a time window parameter of key smooth transition of the cryptographic machine according to the adjustment result of the time window parameter of the cryptographic machine, and perform key transition of the cryptographic machine in combination with the time window parameter of key smooth transition of the cryptographic machine.
[0044] It should be noted that the key transition of the cryptographic machine means replacement of the key of the cryptographic machine.
[0045] A key transition flow analysis module, configured to analyze a key transition flow of the cryptographic machine, obtain a key security indicator value of the cryptographic machine, further analyze to obtain a key smooth update result of the cryptographic machine, and perform key update according to the key smooth update result of the cryptographic machine, analyze the key in a key update time period, and provide a prompt for adjustment.
[0046] It should be noted that, as Figure 6 shown, the key update time period refers to a length of a time period in which the key 1 and the updated key overlap between an update key setting time and an update key invalidation time.
[0047] It needs to be added that the keys in the key update time period are analyzed and prompted to adjust, and the specific process is that the updated key is used to decrypt the cryptomachine in the time period between the update key setting time and the enable time, if the cryptomachine cannot perform decryption operation, it indicates that the update key setting fails, the staff needs to be prompted, and the key of the cryptomachine needs to be updated again, if the decryption operation can be performed, it indicates that the update key setting is successful, and the second judgment needs to be made.
[0048] It needs to be added that the second judgment is made, and the specific process is that the key 1 is used to encrypt the cryptomachine in the time period between the update key enable time and the key 1 invalidation time, if the cryptomachine can perform encryption operation, it indicates that the key 1 disable time setting is wrong, the staff needs to be prompted, and the key time window of the key 1 needs to be reset, if the cryptomachine cannot perform encryption operation, it indicates that the key 1 disable time setting is successful, then the updated key is used to encrypt the cryptomachine, if the cryptomachine cannot perform encryption operation, it indicates that the updated key fails to be successfully enabled, it needs to be updated again, if the cryptomachine can perform encryption operation, it indicates that the updated key is successfully enabled, the third judgment needs to be made.
[0049] It needs to be added that the third judgment is made, and the specific process is that the key 1 is used to decrypt the cryptomachine and the updated key is used to encrypt the cryptomachine in the time period between the update key disable time and the invalidation time, if the key 1 can decrypt the cryptomachine, it indicates that the key 1 fails to successfully enter the invalid state, if the updated key can encrypt the cryptomachine, it indicates that the update disable time setting is wrong, it needs to be prompted and the key time window needs to be reset, if both cannot be operated, it indicates that the key 1 and the updated key are successfully operated, then the key 2 is used to encrypt and decrypt the cryptomachine, if it is successful, it indicates that the cryptomachine key update is successful, if it is not successful, it indicates that the key 2 fails to operate successfully, the staff needs to be prompted, and the key of the cryptomachine needs to be updated again.
[0050] It needs to be added that through the three times of analysis and judgment of the keys in the key update time period in the key update process, the key update process can be fully understood, which helps to confirm whether the key is successfully updated, thereby improving the security and reliability of the cryptomachine, and at the same time, potential security vulnerabilities can be found in time, and the confidentiality and integrity of data transmission are improved.
[0051] Specifically, the related operation data of the cryptomachine includes the data flow of the cryptomachine, the data processing amount of the cryptomachine and the total number of key calls of the cryptomachine.
[0052] It should be noted that the data flow of the cryptographic machine refers to the amount of data processed by the cryptographic machine in each supervision period, which is usually calculated by using device logs to obtain the total number of bytes passing through the cryptographic machine, the data processing amount of the cryptographic machine refers to the total amount of data processed by the cryptographic machine, including encryption and decryption operations, which can be obtained by analyzing the operation logs of the cryptographic machine, and the total number of key calls of the cryptographic machine refers to the total number of key calls of the cryptographic machine in each supervision period, which can be obtained by using a special monitoring tool.
[0053] The time window parameter of the key smooth transition of the cryptographic machine includes a maximum clock error of the cryptographic machine, a maximum network delay of the cryptographic machine, a key enable time of the cryptographic machine, a key disable time of the cryptographic machine, a key pre-enable time of the cryptographic machine, and a key invalidation time of the cryptographic machine.
[0054] It should be noted that the maximum clock error of the cryptographic machine refers to the deviation value of the internal clock of the cryptographic machine from the standard time, which is measured by synchronizing the clock of the cryptographic machine with the standard time source (such as a network time protocol server), and the maximum network delay of the cryptographic machine refers to the longest time required for the data packet of the cryptographic machine to be sent and received in network communication, which is usually measured by a network delay test tool (such as Internet Packet Explorer).
[0055] Specifically, the key transition index value of the cryptographic machine is analyzed, and the specific analysis process is as follows: a plurality of supervision periods are set, and the ratio of the total number of key calls of the cryptographic machine in each supervision period to the length of the supervision period is taken as the key call frequency of the cryptographic machine in each supervision period.
[0056] The data flow of the cryptographic machine and the data processing amount of the cryptographic machine in each supervision period are counted, and the key call frequency of the cryptographic machine in each supervision period is combined to comprehensively analyze the key transition index value of the cryptographic machine, which is used to comprehensively quantify the influence degree of the data flow and the data processing amount of the cryptographic machine on the key transition quality of the cryptographic machine.
[0057] It should be noted that the key transition index value of the cryptographic machine represents the quantitative result of the key transition quality of the cryptographic machine in the supervision period obtained by analyzing the relevant running data of the cryptographic machine.
[0058] Specifically, the adjustment result of the time window parameter of the cryptographic machine is analyzed, and the specific analysis process is as follows: the key transition index value of the cryptographic machine is compared with the set key transition index threshold value of the cryptographic machine to obtain the adjustment result of the time window parameter of the cryptographic machine.
[0059] The adjustment result of the cryptographic machine time window parameter includes needing adjustment and not needing adjustment, wherein if the cryptographic machine key transition index value is higher than or equal to the set cryptographic machine key transition index threshold value, the adjustment result of the cryptographic machine time window parameter is needing adjustment, and if the cryptographic machine key transition index value is lower than the set cryptographic machine key transition index threshold value, the adjustment result of the cryptographic machine time window parameter is not needing adjustment.
[0060] Specifically, according to the adjustment result of the cryptographic machine time window parameter, the time window parameter of the cryptographic machine key smooth transition is obtained, and the specific analysis process is as follows: if the adjustment result of the cryptographic machine time window parameter is needing adjustment, the time window correction parameter of the cryptographic machine key smooth transition is obtained according to the cryptographic machine key transition index value matching, and the time window correction parameter of the cryptographic machine key smooth transition is added to the corresponding time window parameter of the cryptographic machine key smooth transition stored in the cryptographic machine key transition database, as the time window parameter of the cryptographic machine key smooth transition.
[0061] It should be noted that the time window correction parameter of the cryptographic machine key smooth transition is obtained according to the cryptographic machine key transition index value matching, and the specific process is as follows: a mapping set between the cryptographic machine key transition index value interval and the corresponding time window correction parameter of the cryptographic machine key smooth transition is constructed, the real-time cryptographic machine key transition index value is input, the interval in which the cryptographic machine key transition index value is located is matched, and the time window correction parameter of the cryptographic machine key smooth transition corresponding to the cryptographic machine key transition index value is obtained through the mapping set.
[0062] It should be noted that the time window correction parameter of the key smooth transition includes the maximum clock error correction value of the cryptographic machine and the maximum network delay correction value of the cryptographic machine.
[0063] It should be noted that the time window of the key can be adjusted by adjusting the time window correction parameter of the key smooth transition, thereby improving the reliability and security of the key replacement.
[0064] If the adjustment result of the cryptographic machine time window parameter is not needing adjustment, the time window parameter of the cryptographic machine key smooth transition stored in the cryptographic machine key transition database is used as the time window parameter of the cryptographic machine key smooth transition.
[0065] It should be noted that the time window parameter of the cryptographic machine key smooth transition stored in the cryptographic machine key transition database is used for the historical cryptographic machine transition process, and the adjustment result of the cryptographic machine time window parameter is not needing adjustment, which means that the stored time window parameter of the cryptographic machine key smooth transition does not need to be adjusted and can be directly applied to the next key transition process.
[0066] Specifically, the key transition of the cryptographic machine is performed in combination with the time window parameter of the key smooth transition of the cryptographic machine, and the specific process is that the time window of the key is designed according to the time window parameter of the key smooth transition of the cryptographic machine.
[0067] The specific process of designing the time window of the key is that the adjusted time window parameter of the key smooth transition of the cryptographic machine is sequentially arranged in time sequence as a pre-activation time, an activation time, a deactivation time and an invalidation time, and the time window of the key is obtained by dividing the unactivated state, the activated state, the activated state, the deactivated state and the deactivated state of the key of the cryptographic machine.
[0068] It should be noted that the unactivated state of the key represents the state of the key before the pre-activation time of the key of the cryptographic machine, the activated state represents the state of the key between the pre-activation time and the activation time of the key of the cryptographic machine, the activated state represents the state of the key between the activation time and the deactivation time of the key of the cryptographic machine, the deactivated state represents the state of the key between the deactivation time and the invalidation time of the key of the cryptographic machine, and the deactivated state represents the state of the key after the invalidation time of the key of the cryptographic machine.
[0069] It should be noted that, Figure 3 The image of the time window of the key of the cryptographic machine is shown in the figure, in which the pre-activation time is the time point of the activation time forward by a fixed length window n, and the invalidation time is the time point of the deactivation time backward by a fixed length window m, the values of n and m directly affect the reliability and security of the key replacement, when the values of n and m are set too small, the business data packets will be lost, and when the values of n and m are set too large, the key will be used excessively, which will cause certain security risks, and the double time window before and after the activation and deactivation time of the key is set to solve the smooth key replacement problem in the key transition process.
[0070] It should be noted that the key in the activated state can be used for encryption and decryption operations on the business data, the key in the activated state can only be used for decryption operations on the business data, the key in the deactivated state can also only be used for decryption operations on the business data, the key in the unactivated state cannot be used for encryption and decryption operations on the business data, and the key in the deactivated state cannot be used for encryption and decryption operations on the business data, and in order to release the key storage space, the key in this state should be deleted from the device.
[0071] The key transition of the cryptographic machine in combination with the time window of the key is specifically as follows: key information on the current cryptographic machine is acquired, including the pre-activation time, activation time, deactivation time and invalidation time of the key of the current cryptographic machine, a time window of a new key of the cryptographic machine is designed, the pre-activation time, activation time, deactivation time and invalidation time of the new key of the cryptographic machine are determined, and the deactivation time of the key of the current cryptographic machine is set as the activation time of the new key of the cryptographic machine.
[0072] It should be noted that the key transition of the cryptographic machine in combination with the time window of the key is a process of key transition of a single cryptographic machine, Figure 4 For a process image of key transition of a single cryptographic machine, the key 1 represents the key of the current cryptographic machine, and the key 2 represents the new key of the cryptographic machine. The two keys should be kept continuous on the time axis, that is, the deactivation time of the key 1 coincides with the activation time of the key 2.
[0073] It should be noted that, Figure 5 For a process image of key transition of two cryptographic machines, the key transition of the two cryptographic machines is specifically as follows: the deactivation time of the key 1 of the cryptographic machine 1 is set as the activation time of the key 2 of the cryptographic machine 1, and the deactivation time of the key 1 of the cryptographic machine 2 is set as the activation time of the key 2 of the cryptographic machine 2. The dashed box area is a time period during which the key 1 and the key 2 can be decrypted on the two cryptographic machines. C represents the maximum clock error of the cryptographic machine. When c plus the maximum network delay of the cryptographic machine is less than n and m, the encryption switching time points of the two cryptographic machines are in the box, and at this time, the key replacement of the two cryptographic machines will not cause packet loss. The time window parameters for smooth key transition can be adjusted to determine the values of m and n. The values of m and n are twice the maximum clock error of the cryptographic machine and the sum of the maximum network delay of the cryptographic machine.
[0074] In the embodiment, the key replacement process does not depend on data interaction of the cryptographic machines, and can be applied to scenarios such as satellite communication which is inconvenient for data interaction. On the basis of the method of fixed-time key replacement, the time window management design is added, which retains the advantages of the method of fixed-time key replacement, such as simplicity, easy implementation and independence from data interaction between cryptographic machines, and solves the disadvantages of the method of fixed-time key replacement, such as insufficient smoothness of switching, easy packet loss and dependence on accurate time calibration.
[0075] Specifically, the key transition process of the cryptographic machine is analyzed, and the specific analysis process is as follows: the analysis of the key transition process of the cryptographic machine includes analysis of the response duration of the decryption operation of the cryptographic machine, the total number of decryption failures of the cryptographic machine and the key calling frequency of the cryptographic machine.
[0076] The response time of the decryption operation of the cryptographic machine in each supervision period and the total number of decryption failures of the cryptographic machine are monitored, and the key security index value of the cryptographic machine in each supervision period is obtained by weighted analysis combined with the key calling frequency of the cryptographic machine in each supervision period, and the key security index value of the cryptographic machine in each supervision period is used to comprehensively quantify the influence degree of the response time of the decryption operation of the cryptographic machine and the total number of decryption failures on the key security quality of the cryptographic machine.
[0077] It should be noted that the response time of the decryption operation of the cryptographic machine refers to the time interval from receiving the decryption request to completing the decryption and returning the result, which is usually obtained by checking the operation log of the cryptographic machine, obtaining the time stamps of the decryption request and response, and calculating the difference between the time stamps of the decryption request and response to obtain the response time of the decryption operation, and the total number of decryption failures of the cryptographic machine refers to the total number of failures of the cryptographic machine in the decryption process in the supervision period, which is obtained by analyzing the operation log of the cryptographic machine and counting the total number of decryption failure events.
[0078] It should be noted that the key security index value of the cryptographic machine represents the numerical quantification result of the key security index value obtained by analyzing the key transition process of the cryptographic machine, which can be obtained by the following analysis method, and the specific analysis conditions are as follows:
[0079]
[0080] In the formula, β i represents the key security index value of the cryptographic machine in the i-th supervision period, B 1→i represents the response time of the decryption operation of the cryptographic machine in the i-th supervision period, μ1 represents the correction factor corresponding to the set response time, B 2→i represents the total number of decryption failures of the cryptographic machine in the i-th supervision period, μ2 represents the correction factor corresponding to the set number of decryption failures, A 3→i represents the key calling frequency of the cryptographic machine in the i-th supervision period, μ3 represents the correction factor corresponding to the set key calling frequency, i represents the number of each supervision period, i = 1, 2, 3, … n, n represents the total number of supervision periods, and e represents the natural constant.
[0081] In a specific embodiment, Table 1 is the response time of the decryption operation of the cryptographic machine, the total number of decryption failures and the key calling frequency of the cryptographic machine in different supervision periods and the key security index value, in this embodiment, the correction factor corresponding to the response time is 0.3, the correction factor corresponding to the number of decryption failures is 0.3, and the correction factor corresponding to the key calling frequency is 0.4.
[0082] Table 1 is the response time of the decryption operation of the cryptographic machine, the total number of decryption failures and the key calling frequency of the cryptographic machine in different supervision periods and the key security index value
[0083]
[0084]
[0085] It needs to be explained that, with the total number of decryption failures of the cryptographic machine and the key call frequency increasing, the key security index value decreases, and with the response time of the decryption operation of the cryptographic machine, the key security index value increases, the response time of the decryption operation of the cryptographic machine, the total number of decryption failures and the key call frequency in four different supervision periods are listed in Table 1, and the corresponding key security index value is obtained by formula, these key security index values provide the influence degree of the key call frequency of the cryptographic machine in different supervision periods on the key security index value, the key security index value considers the response time of the decryption operation of the cryptographic machine, the total number of decryption failures and the key call frequency, provides data support for the key smooth update of the cryptographic machine, and improves the accuracy of the key security index value evaluation of the cryptographic machine.
[0086] It needs to be explained that, Figure 2 The key security index value of the cryptographic machine is shown in the example graph, as Figure 2 The x-axis represents the response time of the decryption operation of the cryptographic machine, and the y-axis represents the key security index value of the cryptographic machine, in this embodiment, the key call frequency of the cryptographic machine is 2 times per second, three different example parameters are defined in the graph, corresponding to three different curves, represented by solid line, dotted line and dot-dashed line, and the corresponding curve labels are a, b and c.
[0087] It needs to be explained that, when the total number of decryption failures of the cryptographic machine is 3, the functional relationship between the response time of the decryption operation of the cryptographic machine and the key security index value of the cryptographic machine is shown in curve a, when the total number of decryption failures of the cryptographic machine is 4, the functional relationship between the response time of the decryption operation of the cryptographic machine and the key security index value of the cryptographic machine is shown in curve b, when the total number of decryption failures of the cryptographic machine is 5, the functional relationship between the response time of the decryption operation of the cryptographic machine and the key security index value of the cryptographic machine is shown in curve c, the key security index value of the cryptographic machine increases with the increase of the response time of the decryption operation of the cryptographic machine, when the total number of decryption failures of the cryptographic machine increases, the key security index value of the cryptographic machine decreases, the key security index value of the cryptographic machine can be quickly and accurately obtained through the curve, solving the problem that the key security index value of the cryptographic machine cannot be accurately analyzed due to insufficient analysis process in the prior art, and further realizing the accurate analysis of the key security index value of the cryptographic machine.
[0088] It should be noted that in the present embodiment, the preset response time corresponding correction factor, the decryption failure number corresponding correction factor and the key calling frequency corresponding correction factor are obtained from the cryptographic key transition database, and the preset response time corresponding correction factor, the decryption failure number corresponding correction factor and the key calling frequency corresponding correction factor obtained from the cryptographic key transition database are all numbers between 0 and 1.
[0089] It should be noted that the response time corresponding correction factor represents the influence degree of the response time on the key security index value of the cryptographic machine, the decryption failure number corresponding correction factor represents the influence degree of the decryption failure number on the key security index value of the cryptographic machine, and the key calling frequency corresponding correction factor represents the influence degree of the decryption failure number on the key security index value of the cryptographic machine. These corresponding relationships are pre-set mapping relationships, for example, the response time of the real-time decryption operation of the cryptographic machine is input into the mapping set to obtain the response time corresponding correction factor of the decryption operation of the cryptographic machine.
[0090] It should be noted that in the present formula, the response time of the decryption operation of the cryptographic machine, the total number of decryption failures and the key calling frequency in each regulatory period are associated, and are not independent, for example, a longer response time may mean that the cryptographic machine is under higher load, which may result in more failure numbers. With the increase of the key calling frequency, the load of the cryptographic machine will increase, which may lead to the increase of the response time.
[0091] It should be noted that the longer the response time of the decryption operation is, the more secure the key is. By analyzing the response time, it can be determined early whether the key needs to be updated in advance to maintain the performance and security of the cryptographic machine. The increase of the total number of decryption failures may indicate that the key has a problem in actual use. By monitoring these failure numbers, it can be determined in time whether the key needs to be updated in advance to prevent the intensification of the security risk of the cryptographic machine. High key calling frequency indicates that the use intensity of the key is large, which can reveal the stress level of the key. By monitoring the calling frequency, it can be more accurately evaluated whether the key needs to be updated in advance due to overuse to reduce the security risks caused by the performance decline of the cryptographic machine.
[0092] In the present embodiment, the response time of the decryption operation of the cryptographic machine, the total number of decryption failures and the key calling frequency are comprehensively analyzed to obtain the key security index value of the cryptographic machine, which can evaluate the risk index of the cryptographic key transition, and then determine whether the key needs to be updated.
[0093] Specifically, the key smooth update result of the cryptographic machine is analyzed, and the specific analysis process is as follows: the key smooth update result of the cryptographic machine includes the need to update and the need not to update.
[0094] The key security indicator value of the cryptographic machine in each supervision period is compared with the set key security indicator threshold value of the cryptographic machine to obtain a key smoothing update result of the cryptographic machine. If the key security indicator value of the cryptographic machine in a certain supervision period is higher than or equal to the set key security indicator threshold value of the cryptographic machine, the key smoothing update result of the cryptographic machine in the supervision period is set to no need to update.
[0095] It should be noted that the key smoothing update result of the cryptographic machine can be analyzed to evaluate the risk value of the cryptographic machine key leakage or suspected leakage, and then determine whether the key needs to be updated.
[0096] If the key security indicator value of the cryptographic machine in a certain supervision period is lower than the set key security indicator threshold value of the cryptographic machine, the key smoothing update result of the cryptographic machine in the supervision period is set to need to update, and then the key is updated according to the key smoothing update result in combination with the adjusted key smoothing transition time window parameter of the cryptographic machine.
[0097] Specifically, the key is updated according to the key smoothing update result in combination with the adjusted key smoothing transition time window parameter of the cryptographic machine, and the specific analysis process is as follows: if the key smoothing update result of the cryptographic machine is to update, the key setting is updated, and the time window of the updated key is designed in combination with the adjusted key smoothing transition time window parameter of the cryptographic machine. The original key is updated to the updated key, the enable time of the updated key is set to the disable time of the original key, the original disable time of the original key is set to the disable time of the updated key, and the original invalid time of the original key is set to the invalid time of the updated key.
[0098] It should be noted that, Figure 6 For the process image of the key update of the cryptographic machine, key 1 in the figure represents the original key of the cryptographic machine, and update key represents the updated key of the cryptographic machine. When the update key is set, the invalid time point of the key 1 is set to a time window m after the disable time of the updated key, the enable time of the update key is the same as the enable time of other keys, which is a specific time point, and the delay time d between the setting time of the update key and the enable time of the update key. The delay time d is used to ensure that all devices have been completed before the update key is enabled. In order to ensure that there is no packet loss in the key update process, the delay time d reserved when the enable time of the new key is set is the sum of the new key synchronization setting time difference, twice the maximum clock error of the cryptographic machine, and the maximum network delay of the cryptographic machine.
[0099] Specifically, the key transition indicator value of the cryptographic machine, and the specific analysis condition is:
[0100]
[0101] In the formula, a represents the key transition index value of the cryptographic machine, A 1→i represents the data flow of the cryptographic machine in the i-th supervision period, represents the weight factor corresponding to the set data flow, A 2→i represents the data processing amount of the cryptographic machine in the i-th supervision period, represents the weight factor corresponding to the set data processing amount, A 3→i represents the key invocation frequency of the cryptographic machine in the i-th supervision period, represents the weight factor corresponding to the set key invocation frequency, i represents the number of each supervision period, i = 1, 2, 3, … n, and n represents the total number of supervision periods.
[0102] It should be noted that in the present embodiment, the preset weight factor corresponding to the data flow, the weight factor corresponding to the data processing amount, and the weight factor corresponding to the key invocation frequency are obtained from the cryptographic machine key transition database. The preset weight factor corresponding to the data flow, the weight factor corresponding to the data processing amount, and the weight factor corresponding to the key invocation frequency obtained from the cryptographic machine key transition database are all numbers between 0 and 1.
[0103] It should be noted that the weight factor corresponding to the data flow represents the numerical value of the influence degree of the data flow on the key transition index value of the cryptographic machine, the weight factor corresponding to the data processing amount represents the numerical value of the influence degree of the data processing amount on the key transition index value of the cryptographic machine, and the weight factor corresponding to the key invocation frequency represents the numerical value of the influence degree of the key invocation frequency on the key transition index value of the cryptographic machine. These corresponding relationships are pre-set mapping relationships, for example, the data flow and the preset weight factor corresponding to the data flow obtained from the cryptographic machine key transition database form a mapping set, and the real-time data flow of the cryptographic machine is input into the mapping set to obtain the weight factor corresponding to the data flow of the cryptographic machine.
[0104] It should be noted that in the present formula, the data flow, data processing amount, and key invocation frequency of the cryptographic machine in each supervision period are related, and are not independent, for example, the data flow and the data processing amount are usually positively correlated, and greater data flow usually means that the cryptographic machine needs to process more data, thereby increasing the data processing amount of the cryptographic machine.
[0105] It should be noted that by analyzing the key transition index value of the cryptographic machine under different data flow conditions, it can be determined whether more frequent key transition is needed in the case of high data flow to ensure the security and effectiveness of data encryption analysis, analyzing the data processing amount of the cryptographic machine can more accurately measure the key transition demand, and analyzing the key invocation frequency of the cryptographic machine can more accurately evaluate the performance of the key in actual operation, thereby determining whether the time window parameter of the key smooth transition of the cryptographic machine needs to be adjusted.
[0106] It should be noted that, in the analysis process of the key transition indicator value of the cryptographic machine, analyzing the key call frequency of the cryptographic machine helps to identify whether the key usage is frequent, thereby optimizing the time window parameter of the key smooth transition of the cryptographic machine, and in the analysis process of the key security indicator value of the cryptographic machine, analyzing the key call frequency of the cryptographic machine can identify abnormal patterns early, discover potential key leakage risks in time, and then judge whether the key needs to be updated in advance.
[0107] In the embodiment, the data flow, data processing amount and key call frequency of the cryptographic machine are comprehensively analyzed to obtain the key transition indicator value of the cryptographic machine, the use efficiency and security of the key can be analyzed, and then the time window parameter of the key smooth transition of the cryptographic machine is adjusted.
[0108] It should be noted that the cryptographic machine key smooth transition system based on the time window further includes a cryptographic machine key transition database for storing the key transition indicator threshold of the cryptographic machine, the correction factor corresponding to the response time, the correction factor corresponding to the decryption failure times, the correction factor corresponding to the key call frequency, the key security indicator threshold of the cryptographic machine, the time window parameter of the key smooth transition of the cryptographic machine, the weight factor corresponding to the data flow, the weight factor corresponding to the data processing amount and the weight factor corresponding to the key call frequency obtained by analyzing the historical data.
[0109] It should be noted that, in this document, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or equipment.
[0110] The preferred embodiments of the application disclosed above are only used to help explain the application. The preferred embodiments do not describe all the details, nor limit the application to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of the present application. The present application selects and describes these embodiments in order to better explain the principles and practical applications of the application, so that those skilled in the art can well understand and utilize the application.
Claims
1. A time window-based cipher machine key smooth transition system, characterized in that, comprising: a data analysis module for collecting relevant operation data of a cipher machine, analyzing to obtain a cipher machine key transition index value, and further analyzing to obtain a cipher machine time window parameter adjustment result; a key transition module for obtaining a cipher machine key smooth transition time window parameter according to the cipher machine time window parameter adjustment result, and combining the cipher machine key smooth transition time window parameter to perform a cipher machine key transition; a key transition flow analysis module for analyzing a cipher machine key transition flow to obtain a cipher machine key security index value, and further analyzing to obtain a cipher machine key smooth update result, and performing a key update according to the cipher machine key smooth update result, analyzing and prompting adjustment of a key in a key update time period; the analysis to obtain the cipher machine time window parameter adjustment result comprises: comparing the cipher machine key transition index value with a set cipher machine key transition index threshold value to obtain the cipher machine time window parameter adjustment result; the cipher machine time window parameter adjustment result comprises a need to adjust and a no need to adjust, wherein if the cipher machine key transition index value is higher than or equal to the set cipher machine key transition index threshold value, the cipher machine time window parameter adjustment result is the need to adjust, and if the cipher machine key transition index value is lower than the set cipher machine key transition index threshold value, the cipher machine time window parameter adjustment result is the no need to adjust; the combining the cipher machine key smooth transition time window parameter to perform the cipher machine key transition comprises: designing a key time window according to the cipher machine key smooth transition time window parameter; the designing the key time window comprises: arranging the adjusted cipher machine key smooth transition time window parameter in a time sequence as a pre-activation time, an activation time, a deactivation time and an invalidation time in turn, dividing cipher machine keys into an unactivated state, a standby activated state, an activated state, a standby invalidation state and an invalidated state to obtain the key time window; the combining the key time window to perform the cipher machine key transition comprises: obtaining key information on a current cipher machine, including a key pre-activation time, an activation time, a deactivation time and an invalidation time of the current cipher machine, designing a new key time window for a new key of the cipher machine, determining a new key pre-activation time, an activation time, a deactivation time and an invalidation time of the cipher machine, and setting the deactivation time of the current cipher machine as the activation time of the new key of the cipher machine; the analysis to obtain the cipher machine key smooth update result comprises: the cipher machine key smooth update result comprises a need to update and a no need to update; comparing cipher machine key security index values in each supervision period with a set cipher machine key security index threshold value to obtain the cipher machine key smooth update result, wherein if a cipher machine key security index value in a certain supervision period is higher than or equal to a set cipher machine key security index threshold value, the cipher machine key smooth update result in the supervision period is set as the no need to update. If the key security index value of the cryptographic machine in a supervision period is lower than the set key security index threshold value of the cryptographic machine, the key smooth update result of the cryptographic machine in the supervision period is set as needing to be updated, and then the key is updated according to the key smooth update result and in combination with the adjusted time window parameter of the key smooth transition of the cryptographic machine.
2. The time window-based cryptographic machine key smooth transition system according to claim 1, characterized in that: the relevant operation data of the cryptographic machine comprises data traffic of the cryptographic machine, data processing amount of the cryptographic machine, and total number of key calls of the cryptographic machine; the time window parameter of the key smooth transition of the cryptographic machine comprises maximum clock error of the cryptographic machine, maximum network delay of the cryptographic machine, key enabling time of the cryptographic machine, key disabling time of the cryptographic machine, key pre-enabling time of the cryptographic machine, and key invalidation time of the cryptographic machine.
3. The time window-based cryptographic machine key smooth transition system according to claim 2, characterized in that: the analysis obtains a key transition index value of the cryptographic machine, and the specific analysis process is as follows: a plurality of supervision periods are set, and the ratio of the total number of key calls of the cryptographic machine in each supervision period to the length of the supervision period is taken as the key call frequency of the cryptographic machine in each supervision period; the data traffic of the cryptographic machine and the data processing amount of the cryptographic machine in each supervision period are counted, and the key transition index value of the cryptographic machine is obtained by comprehensive analysis in combination with the key call frequency of the cryptographic machine in each supervision period, wherein the key transition index value of the cryptographic machine is used to quantitatively analyze the influence of the data traffic and the data processing amount of the cryptographic machine on the key transition quality of the cryptographic machine.
4. The time window-based cryptographic machine key smooth transition system according to claim 3, characterized in that: the time window parameter of the key smooth transition of the cryptographic machine is obtained according to the adjustment result of the time window parameter of the cryptographic machine, and the specific analysis process is as follows: if the adjustment result of the time window parameter of the cryptographic machine is that adjustment is needed, the time window correction parameter of the key smooth transition of the cryptographic machine is matched and obtained according to the key transition index value of the cryptographic machine, the time window correction parameter of the key smooth transition of the cryptographic machine is added to the corresponding time window parameter of the key smooth transition of the cryptographic machine stored in the key transition database of the cryptographic machine, and the result is taken as the time window parameter of the key smooth transition of the cryptographic machine; if the adjustment result of the time window parameter of the cryptographic machine is that adjustment is not needed, the time window parameter of the key smooth transition of the cryptographic machine stored in the key transition database of the cryptographic machine is taken as the time window parameter of the key smooth transition of the cryptographic machine.
5. The time window-based cryptographic machine key smooth transition system according to claim 1, characterized in that: the analysis of the key transition process of the cryptographic machine is performed, and the specific analysis process is as follows: the analysis of the key transition process of the cryptographic machine comprises analysis of the response time of the decryption operation of the cryptographic machine, the total number of decryption failures of the cryptographic machine, and the key call frequency of the cryptographic machine. The response time of the decryption operation of the cryptographic machine in each supervision period and the total number of decryption failures of the cryptographic machine are monitored, the key calling frequency of the cryptographic machine in each supervision period is combined, and weighted analysis is performed to obtain a key security index value of the cryptographic machine in each supervision period, which is used to comprehensively quantify the influence degree of the response time of the decryption operation and the total number of decryption failures of the cryptographic machine on the key security quality of the cryptographic machine.
6. The time window-based cryptographic machine key smooth transition system according to claim 1, characterized in that: the key update is performed according to the key smooth update result and in combination with the adjusted time window parameter of the key smooth transition of the cryptographic machine, and the specific analysis process is as follows: if the key smooth update result of the cryptographic machine is that the update is needed, the key setting is updated, the time window of the updated key is designed in combination with the adjusted time window parameter of the key smooth transition of the cryptographic machine, the original key is updated to the updated key, the enabling time of the updated key is set as the disabling time of the original key, the original disabling time of the original key is set as the disabling time of the updated key, and the original invalidation time of the original key is set as the invalidation time of the updated key.
7. The time window based cipher key smoothing transition system of claim 3, wherein: the key transition index value of the cryptographic machine, and the specific analysis condition is that: wherein α represents a key transition index value of the cryptographic machine, A 1→i represents the data flow of the cryptographic machine in the i-th supervision period, represents a weight factor corresponding to the set data flow, A 2→i represents the data processing amount of the cryptographic machine in the i-th supervision period, represents a weight factor corresponding to the set data processing amount, A 3→i represents the key invocation frequency of the cryptographic machine in the i-th supervision period, represents a weight factor corresponding to the set key invocation frequency, i represents the number of each supervision period, i = 1, 2, 3, … n, and n represents the total number of supervision periods.
Citation Information
Patent Citations
Key updating method
CN101562521B
Key update method and key update system
CN109802827B
An adaptation control system and method for enhancing password device on-demand service capacity
CN104506304A
New key switching method and device
CN116388976A