A gatekeeper type password application method and apparatus

By employing a gatekeeper-style cryptographic approach to provide fine-grained protection for business data, this technology addresses the inability of existing technologies to achieve fine-grained protection of business data. It enables seamless application-level data transmission security and is suitable for existing legacy business systems and industrial control systems.

CN119598526BActive Publication Date: 2026-03-27CHINA YANGTZE POWER
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-25
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing technologies cannot achieve fine-grained protection of business data. VPN gateway devices can only protect specified addresses, protocols, and ports, but cannot protect a specific field of business data.

Method used

The gatekeeper-style cryptography application method is adopted. By acquiring the sub-content protection strategy of business data, the data to be protected is encrypted using a preset encryption algorithm to generate ciphertext payload and extended payload, thus generating secure business data, and fine-grained protection is performed during transmission.

Benefits of technology

It provides fine-grained protection for business data, preventing data from being stolen or tampered with during transmission, reducing the difficulty of business system transformation, and is suitable for seamless application-level data transmission protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119598526B_ABST
    Figure CN119598526B_ABST
Patent Text Reader

Abstract

The application discloses a gatekeeper type password application method and device. A first gatekeeper type application password machine acquires original service data containing original application load of a first service, determines to-be-protected data according to each sub-content protection strategy, and generates security control parameters, encrypts ciphertext load and extension load, and further generates security service data and sends the security service data to a second gatekeeper type application password machine. The second gatekeeper type application password machine acquires the security control parameters from the sub-extension load, and then decrypts the ciphertext load by using a preset decryption algorithm according to the protection mode, the security control parameters and the key index, obtains the to-be-protected data, and finally determines the original service data by combining the ciphertext load and sends the original service data to a second service. The application contains multiple sub-content protection strategies through the protection strategy, can realize fine differentiated protection for different parts of data in the original application load, and better adapts to complex and various data protection requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of information security, specifically relating to a gatekeeper-style cryptographic application method and apparatus. Background Technology

[0002] With the rapid development of information technology, the risks of data leakage and illegal interception are increasing. To enhance the secure and reliable operation of important systems such as government, power, and banking, it is necessary to use cryptographic technology to encrypt information, achieve information concealment, and effectively protect the security of data during transmission, storage, and use, ensuring that data is not illegally intercepted or tampered with, and protecting the integrity and authenticity of the data.

[0003] Currently, some data protection solutions deploy VPN gateway devices at the boundary of business systems. Through a key negotiation mechanism, VPN gateways maintain the same business protection key. When plaintext data between business systems is transmitted over the network, it is encrypted and signed for protection by the VPN gateway. Sensitive data is securely transmitted in the network between the two VPN gateways, preventing it from being stolen or tampered with, thus achieving network-level security protection for business data.

[0004] However, this type of VPN gateway is a device designed to protect business data and cannot provide fine-grained protection for the data. It can only protect data at specified addresses, protocols, and ports, and cannot protect a specific field of the business data. Summary of the Invention

[0005] The technical objective of this application is to address the limitations of current data protection methods, which fail to provide fine-grained data protection. It offers a gatekeeper-style cryptographic application method and system that provides fine-grained data protection without affecting business systems, preventing business data from being stolen or tampered with during transmission.

[0006] To achieve the above technical objectives, this application adopts the following technical solution.

[0007] In a first aspect, embodiments of this application provide a gatekeeper-style cryptographic application method, applied to a first gatekeeper-style cryptographic application machine, the method comprising:

[0008] Obtain the original business data of the first service, wherein the original business data includes the original application payload;

[0009] Each sub-content protection strategy is obtained according to the preset data protection strategy. Each sub-content protection strategy includes the data to be protected limitation parameters, protection method and protection key index. The data protection strategy includes at least one sub-content protection strategy.

[0010] determining the to-be-protected data corresponding to each of the sub content protection strategies in the original application load according to the to-be-protected data definition parameters respectively; determining the security control parameters according to the protection modes respectively, and encrypting each of the to-be-protected data according to the protection mode, the security control parameter and the protection key index by using a preset encryption algorithm to obtain a ciphertext load;

[0011] generating a sub extension load according to each of the sub content protection strategies and the corresponding security control parameters, and generating an extension load according to each of the sub extension loads;

[0012] generating a new application load according to the ciphertext load and the extension load, and generating a secure service data according to the new application load;

[0013] sending the secure service data to the second gatekeeper application cipher machine, so that the second gatekeeper application cipher machine obtains the original application load according to the secure service data, generates an original service data according to the original application load, and sends the original service data to a second service.

[0014] As an improvement of the above scheme, the method further comprises:

[0015] Each of the sub content protection strategies comprises a protection condition, and the to-be-protected data definition parameter comprises a protection start point and a protection length;

[0016] determining the to-be-protected data corresponding to each of the sub content protection strategies in the original application load according to the to-be-protected data definition parameters respectively comprises:

[0017] determining whether the data corresponding to the sub content protection strategy in the original application load needs protection according to each of the protection conditions respectively; if the data needs protection, the data with the protection length starting from the protection start point is taken as the to-be-protected data corresponding to the sub content protection strategy.

[0018] As an improvement of the above scheme, the protection condition comprises an operation mode, an operation value and a preset result; determining whether the data corresponding to the sub content protection strategy in the original application load needs protection according to each of the protection conditions respectively comprises:

[0019] performing operation on the operation value by using the operation mode, comparing the obtained operation result with the preset result, and if the operation result is consistent with the preset result, the data corresponding to the sub content protection strategy in the original application load needs protection.

[0020] As an improvement of the above scheme, the original service data further comprises a protocol header;

[0021] Before obtaining each of the sub content protection strategies according to the preset data protection strategy, the method further comprises:

[0022] obtaining a network protocol, a source port and a destination port from the protocol header; if the network protocol, the source port and the destination port satisfy the requirements of the data protection policy on protocol and port, obtaining each sub-content protection policy according to the data protection policy.

[0023] As an improvement of the above solution, the protection mode comprises any one of a confidentiality protection mode, an integrity protection mode or an integrity and confidentiality protection mode.

[0024] If the protection mode comprises the confidentiality protection mode, the corresponding security control parameter comprises an encryption protection vector.

[0025] If the protection mode comprises the integrity protection mode, the corresponding security control parameter comprises an integrity check value.

[0026] In a second aspect, the embodiments of the present application further provide a gatekeeper type password application method, applied to a second gatekeeper type password machine, the method comprising:

[0027] obtaining security service data, wherein the security service data comprises a new application load, the new application load comprises a ciphertext load and an extension load corresponding to all sub-content protection policies in a preset data protection policy, and the data protection policy comprises at least one sub-content protection policy;

[0028] obtaining each sub-extension load according to the extension load, wherein each sub-extension load is determined according to a security control parameter corresponding to the sub-content protection policy and the protection mode, and each sub-content protection policy comprises a to-be-protected data limiting parameter, the protection mode and a protection key index;

[0029] decrypting the ciphertext load according to each protection mode, security control parameter and protection key index respectively by using a preset decryption algorithm to obtain to-be-protected data corresponding to each sub-content protection policy;

[0030] determining an original application load according to each to-be-protected data and the ciphertext load, generating original service data according to the original application load, and sending the original service data to a second service.

[0031] As an improvement of the above solution, the protection mode comprises any one of a confidentiality protection mode, an integrity protection mode or an integrity and confidentiality protection mode.

[0032] If the protection mode comprises the confidentiality protection mode, the corresponding security control parameter comprises an encryption protection vector.

[0033] If the protection mode includes an integrity protection mode, the corresponding security control parameter includes an integrity check value, and after the cipher text payload is decrypted, the obtained integrity check result is compared with the received integrity check value; if they are consistent, it means that the data remains intact during transmission and has not been tampered with; if they are inconsistent, the decrypted obtained data is not adopted.

[0034] In a third aspect, the embodiments of the present application further provide a gatekeeper type password application method, applied to a gatekeeper type password application system, the gatekeeper type password application system including a first gatekeeper type application password machine and a second gatekeeper type application password machine;

[0035] The method includes:

[0036] After the first gatekeeper type application password machine and the second gatekeeper type application password machine establish a communication connection, the first gatekeeper type application password machine obtains original service data of a first service, and the original service data includes original application payload;

[0037] The first gatekeeper type application password machine obtains each sub-content protection strategy according to a preset data protection strategy, each sub-content protection strategy includes data protection parameters, a protection mode, and a protection key index, and the data protection strategy includes at least one sub-content protection strategy;

[0038] The first gatekeeper type application password machine determines the data to be protected corresponding to each sub-content protection strategy in the original application payload according to each data to be protected parameter; determines the corresponding security control parameter according to each protection mode, and encrypts each data to be protected according to the corresponding protection mode, security control parameter, and protection key index by using a preset encryption algorithm to obtain a cipher text payload; generates a corresponding sub-extension payload according to each sub-content protection strategy and the corresponding security control parameter, generates an extension payload according to each sub-extension payload, generates a new application payload according to the cipher text payload and the extension payload, and generates security service data according to the new application payload;

[0039] The first gatekeeper type application password machine sends the security service data to the second gatekeeper type application password machine;

[0040] The second gatekeeper type application password machine obtains the security service data, the security service data includes a new application payload, the new application payload includes a cipher text payload and an extension payload corresponding to all sub-content protection strategies in a preset data protection strategy, and the data protection strategy includes at least one sub-content protection strategy;

[0041] The second gatekeeper-type application cryptographic machine obtains each sub-extension load according to the extension load, each of the sub-extension loads being determined according to a security control parameter corresponding to the sub-content protection policy and the protection mode, each of the sub-content protection policies including a to-be-protected data limiting parameter, the protection mode and a protection key index;

[0042] The second gatekeeper-type application cryptographic machine respectively decrypts the ciphertext load according to each of the protection modes, the security control parameter and the protection key index, using a preset decryption algorithm, to obtain to-be-protected data corresponding to each of the sub-content protection policies; determines an original application load according to each of the to-be-protected data and the ciphertext load; generates original service data according to the original application load, and sends the original service data to a second service.

[0043] In a fourth aspect, the embodiments of the present application further provide a gatekeeper-type cryptographic application device, applied to a first gatekeeper-type application cryptographic machine, the device comprising:

[0044] A first data receiving module, configured to acquire original service data of a first service, the original service data including an original application load;

[0045] A first protection policy acquiring module, configured to acquire each sub-content protection policy according to a preset data protection policy, each of the sub-content protection policies including a to-be-protected data limiting parameter, a protection mode and a protection key index, the data protection policy including at least one sub-content protection policy;

[0046] A data encryption module, configured to determine to-be-protected data corresponding to each of the sub-content protection policies in the original application load according to each of the to-be-protected data limiting parameters respectively; determine a corresponding security control parameter according to each of the protection modes respectively, encrypt each of the to-be-protected data according to the corresponding protection mode, the security control parameter and the protection key index, using a preset encryption algorithm, to obtain a ciphertext load; generate a corresponding sub-extension load according to each of the sub-content protection policies and the corresponding security control parameter, generate an extension load according to each of the sub-extension loads; generate a new application load according to the ciphertext load and the extension load, and generate secure service data according to the new application load;

[0047] A first data sending module, configured to send the secure service data to the second gatekeeper-type application cryptographic machine, so that the second gatekeeper-type application cryptographic machine acquires the original application load according to the secure service data, generates original service data according to the original application load, and sends the original service data to a second service.

[0048] In a fifth aspect, the embodiments of the present application further provide a gatekeeper-type cryptographic application device, applied to a second gatekeeper-type application cryptographic machine, the device comprising:

[0049] The second data receiving module is configured to acquire security service data, wherein the security service data comprises a new application load, and the new application load comprises a cipher text load and an extension load corresponding to all sub-content protection policies in a preset data protection policy, and the data protection policy comprises at least one sub-content protection policy;

[0050] The second protection policy acquiring module is configured to obtain each sub-extension load according to the extension load, wherein each sub-extension load is determined according to a security control parameter corresponding to the sub-content protection policy and a protection mode, and each sub-content protection policy comprises a to-be-protected data limiting parameter, the protection mode and a protection key index;

[0051] The data decrypting module is configured to decrypt the cipher text load by using a preset decryption algorithm according to each protection mode, security control parameter and protection key index, to obtain to-be-protected data corresponding to each sub-content protection policy, to determine an original application load according to each to-be-protected data and the cipher text load, and to generate original service data according to the original application load.

[0052] The second data sending module is configured to send the original service data to a second service.

[0053] Compared with the prior art, the door guard type password application method and device provided by the embodiment of the application can realize fine-grained application data protection for a service system without sensing, prevent business data from being stolen and tampered with in the transmission process, and enable the service system to realize application level data transmission protection without modification. BRIEF DESCRIPTION OF DRAWINGS

[0054] The drawings described herein are only for the purpose of explanation, and are not intended to limit the scope of the present application in any way. In addition, the shapes and scale sizes of the components in the drawings are only illustrative, and are used to help understand the present application, and are not specific limitations on the shapes and scale sizes of the components of the present application. Those skilled in the art can select various possible shapes and scale sizes to implement the present application according to specific circumstances under the teaching of the present application. In the drawings:

[0055] Figure 1 It is a schematic diagram of the principle of the first scheme for realizing data protection at present;

[0056] Figure 2 It is a schematic diagram of the principle of the second scheme for realizing data protection at present;

[0057] Figure 3 It is a schematic diagram of the principle of the third scheme for realizing data protection at present;

[0058] Figure 4 It is a schematic diagram of the principle of the third scheme for realizing data protection at present;

[0059] Figure 5 A comparison diagram of the data before protection and the data after protection in the gatekeeper type password application method provided by an embodiment of the present application is shown in the following figure;

[0060] Figure 6 A flowchart of the gatekeeper type password application method provided by another embodiment of the present application is shown in the following figure;

[0061] Figure 7 A structure diagram of the gatekeeper type password application system provided by an embodiment of the present application is shown in the following figure;

[0062] Figure 8 A structure diagram of the gatekeeper type password application device provided by an embodiment of the present application is shown in the following figure;

[0063] Figure 9 A structure diagram of the gatekeeper type password application device provided by another embodiment of the present application is shown in the following figure. DETAILED DESCRIPTION

[0064] In order to make the personnel in the technical field better understand the technical solutions in the present application, the technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all the other embodiments obtained by the personnel in the field without making creative efforts should belong to the protection scope of the present application.

[0065] In the description of the present application, the terms “first” and “second” are only used for description purpose, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with “first” and “second” can explicitly or implicitly include one or more features.

[0066] Currently, there are usually three methods to realize data protection of different ranges and different levels.

[0067] Scheme one, a server cryptomachine is deployed in a business system to provide key management, symmetric encryption machine, asymmetric encryption and decryption, signature and signature verification and other password service capabilities. After the business system generates data (such as power 104 protocol data), the password operation interface of the server cryptomachine is called through socket communication to encrypt, sign and protect the data.

[0068] If sensitive data needs to be interacted between multiple systems, the initiator sends the data in the protection state to the receiver through the network. The receiver also restores and verifies the authenticity of the data in the protection state by calling the password operation interface of the server cryptomachine through socket communication. Since the server cryptomachines (such as the first business and the second business in the following figure) at both ends of the initiator and the receiver are the same, the data in the protection state can be restored and verified.Figure 1 The first server cryptomachine and the second server cryptomachine in the network have the same key, so the sensitive data of the initiator and the receiver can be circulated with each other.

[0069] In this way, the sensitive data is securely transmitted on the network and cannot be stolen or tampered with. Only the first service and the second service can see the plaintext sensitive data, and the application-level security protection of service data is realized.

[0070] Scheme two, deploy VPN gateway devices at the boundary of the service system, and maintain the same service protection key between VPN gateways through a key agreement mechanism. As shown in Figure 2 When the plaintext data of the first service and the second service is transmitted on the network, it will be encrypted and signed by the VPN gateway for protection. The sensitive data is securely transmitted in the network between the two VPN gateways and cannot be stolen or tampered with, realizing network-level security protection of service data.

[0071] Scheme three, sometimes for more security, as shown in Figure 3 Both server cryptomachines and VPN gateways are deployed to protect service data transmission in multiple layers. The service system first calls the password operation interface of the server cryptomachine to realize application-level data protection. And through the VPN gateway, network-level data protection is realized.

[0072] Now more and more inventory systems need to be evaluated and improved, and the method of deploying server cryptomachines is not simply purchasing a server cryptomachine for the business system. More complex is the need for business system modification. Although the server cryptomachine provides multiple password operation API interfaces, the interface covers symmetric password operation, asymmetric password operation, etc. However, due to the high professionalism of password technology, business system developers need to understand password technology and the meaning of password operation API interfaces, and need to know how the length of the protected data changes when a certain data is protected by a certain password algorithm, in order to specify the protection of the business system data.

[0073] Especially in industrial control systems such as power generation systems, foreign business systems account for the majority. Foreign business systems cannot be modified. Domestic business systems need high learning costs and modification fees to call the password operation interface of the server cryptomachine. Therefore, in practical applications, it can be seen that in the security evaluation of many business systems, the "application and data security" project scores lower.

[0074] In order to guarantee the data security transmission of the business system and avoid the difficulty of business system transformation, the second scheme can be used to protect the entire network security at the boundary. However, in the second scheme, the VPN gateway is a device for protecting the original business data, and cannot realize fine-grained protection of the data, but only can protect the data of the specified address, protocol and port, and cannot protect a certain field of the business data. For example, only the IEC 104 protocol data of the power system can be protected, but the remote control and remote adjustment instruction protection and the fine-grained protection control of the telemetry and telecommunication instruction plaintext transmission cannot be realized.

[0075] To solve the above technical problems, the embodiment of the application provides a gatekeeper type password application method, which is applied to a first gatekeeper type application password machine, and the method comprises the following steps:

[0076] In step S101, original business data of a first business is acquired, and the original business data comprises original application load.

[0077] In step S102, each sub-content protection strategy is acquired according to a preset data protection strategy, each sub-content protection strategy comprises to-be-protected data limiting parameters, a protection mode and a protection key index, and the data protection strategy comprises at least one sub-content protection strategy.

[0078] In step S103, to-be-protected data corresponding to each sub-content protection strategy in the original application load is determined according to each to-be-protected data limiting parameter respectively, corresponding security control parameters are determined according to each protection mode, each to-be-protected data is encrypted by using a preset encryption algorithm according to the corresponding protection mode, the security control parameters and the protection key index, ciphertext load is obtained, corresponding sub-extended load is generated according to each sub-content protection strategy and the corresponding security control parameters, extended load is generated according to each sub-extended load, new application load is generated according to the ciphertext load and the extended load, and secure business data is generated according to the new application load.

[0079] In step S104, the secure business data is sent to a second gatekeeper type application password machine, so that the second gatekeeper type application password machine acquires the original application load according to the secure business data, generates original business data according to the original application load, and sends the original business data to a second business.

[0080] It should be noted that the embodiment of the application is suitable for the data security transmission process between the first gatekeeper type application password machine and the second gatekeeper type application password machine, and the first gatekeeper type application password machine and the second gatekeeper type application password machine are the main bodies of the data security communication.

[0081] In network communication, application payload refers to the part of content actually carrying application layer related data, which is encapsulated after the protocol header of each layer of network protocol stack and is the data part to be really delivered to the application program for processing.

[0082] In some embodiments, the method further comprises: each sub content protection strategy comprises a protection condition, the to-be-protected data definition parameter comprises a protection start point and a protection length; and the to-be-protected data corresponding to each sub content protection strategy in the original application payload is determined according to the to-be-protected data definition parameter respectively, comprising: determining whether the data corresponding to the sub content protection strategy in the original application payload needs to be protected according to the protection condition respectively; and if it needs to be protected, the data with the protection length starting from the protection start point is taken as the to-be-protected data corresponding to the sub content protection strategy.

[0083] In some embodiments, the format of each sub content protection strategy can be as shown in Table 1.

[0084] Table 1: Format example of sub content protection strategy

[0085]

[0086] In some embodiments, the protection condition comprises an operation mode, an operation value and a preset result; and determining whether the data corresponding to the sub content protection strategy in the original application payload needs to be protected according to the protection condition respectively, comprising:

[0087] The operation value is operated by using the operation mode, and the obtained operation result is compared with the preset result, and if they are consistent, the data corresponding to the sub content protection strategy in the original application payload needs to be protected.

[0088] As an example, the protection condition further comprises a protection start point and a protection length, which are the same as the to-be-protected data definition parameter and are used to determine the data corresponding to the sub content protection strategy.

[0089] As an example, the protection condition field supports multiple sub condition fields, and the format of each sub condition field can be as shown in Table 2.

[0090] Table 2: Format example of sub condition field

[0091]

[0092]

[0093] In some embodiments, the original service data further comprises a protocol header; please refer to Figure 4According to the preset data protection policy, each sub-content protection policy is obtained, and the obtaining of each sub-content protection policy before the obtaining of each sub-content protection policy according to the preset data protection policy includes: obtaining a network protocol, a source port and a destination port from a protocol header; and if the network protocol, the source port and the destination port meet the requirements of the protection policy on the protocol and the port, each sub-content protection policy is obtained according to the preset protection policy.

[0094] As an example, the format of the data protection policy can be as shown in Table 3, and Table 3 shows that data of a specified protocol and port is protected according to protection content requirements.

[0095] Table 3 shows an example of the format of the data protection policy

[0096]

[0097] In an embodiment, a comparison diagram of the data before protection and the data after protection is as shown in Figure 5 The new application payload after protection includes the ciphertext payload and the sub-extension payload corresponding to each sub-content protection policy.

[0098] The gatekeeper type password application method provided in the application protects the application payload (application data) part in the business data (network data message), and the ciphertext payload includes a plurality of small encrypted ciphertext fields in the original application payload.

[0099] As can be seen from Table 1 above, the protection mode includes any one of a confidentiality protection mode, an integrity protection mode or an integrity and confidentiality protection mode. If the protection mode includes the confidentiality protection mode, the corresponding security control parameter includes an encryption protection vector; if the protection mode includes the integrity protection mode, the corresponding security control parameter includes an integrity check value.

[0100] As an example, the SM4-GCM encryption algorithm can be used to encrypt the data. The SM4-GCM is an encryption algorithm combining the SM4 symmetric encryption algorithm and the GCM (Galois / Counter Mode) encryption mode. When the SM4-GCM algorithm is used for confidentiality protection in an embodiment, padding is not required, and the encrypted data covers the original application payload (i.e., the plaintext data region) to be encrypted.

[0101] As an example, an example of the extension payload structure is shown in Table 4.

[0102] Table 4 shows an example of the extension payload format

[0103] As shown in Table 4, in an embodiment, the extension payload can include an extension header, a plurality of sub-extension payloads and an extension tail.

[0104] As an example, the structure of each sub-extension payload can be as shown in Table 5.

[0105] Table 5 Sub-extended payload format example

[0106]

[0107]

[0108] As shown in Table 5, in some embodiments, the first security control parameter (confidentiality protection vector IV), the confidentiality protection key index, the integrity protection key index and the second security control parameter (integrity check value) are saved in the sub-extended payload.

[0109] As the first gatekeeper application cryptographic machine on the sending side, the extended payload can be modified when protecting the application data in terms of confidentiality, integrity, etc. The second gatekeeper application cryptographic machine on the receiving side can use the key and IV information in each sub-extended payload to decrypt and verify the ciphertext payload.

[0110] In some embodiments, the content of the extension header field can be as shown in Table 6.

[0111] Table 6 Example of extension header field format

[0112]

[0113] In embodiments, the key identification such as the header identification of the extended payload and the metadata information can be contained by the setting of the extension header pair, which helps the receiving side to quickly identify and understand the basic attributes and purposes of the extended payload. The design of multiple sub-extended payloads has strong flexibility and scalability. Different sub-content protection strategies can correspond to different sub-extended payloads, which can more finely manage and distinguish various protection-related information. In this way, complex business needs and diversified protection strategies can be adapted to, so that the system can more targetedly handle different types of data protection situations.

[0114] In some embodiments, the content of the extension tail can be as shown in Table 7.

[0115] Table 7 Example of content format of extension tail

[0116]

[0117]

[0118] The presence of the extension tail can be used for integrity checking or adding some end identifier, etc., which helps to ensure the integrity of the extended payload during transmission and processing, and prevents data loss or tampering.

[0119] In specific embodiments, before the gatekeeper application cryptographic machine protects the data, the key preloading and data protection strategy configuration can be completed in advance.

[0120] The key management of the door guard type application cryptographic machine (including the first door guard type application cryptographic machine and the second door guard type application cryptographic machine) is consistent with that of a conventional server cryptographic machine, and the key information includes a key index and a key, and the key information is distributed and maintained by a key management system. The first door guard type application cryptographic machine and the second door guard type application cryptographic machine for the same service encryption and decryption processing adopt the same key information.

[0121] The data protection policy is the basis for protecting service data and needs to be configured in the door guard type application cryptographic machine in advance. In an embodiment, the corresponding protection of the IEC 104 protocol data of the power system needs to be implemented. For the data related to the IEC 104 protocol in the power system, the original service data of the first service is obtained, and the original application payload is separated therefrom. The original service data covers various related data contents transmitted in the power system communication process in accordance with the IEC 104 protocol, such as telemetry, remote signaling, remote control, remote adjustment, and the like. The data protection policy is preset according to the safety requirements of the power system and the characteristics of the IEC 104 protocol data, and multiple sub-content protection policies are set in the policy. For example, a remote control and remote adjustment instruction related sub-content protection policy and a telemetry and remote signaling instruction related sub-content protection policy, each of which sets corresponding to-be-protected data limiting parameters, a protection mode, and a protection key index. After obtaining the secure service data according to the above embodiment, the secure service data is sent to the second door guard type application cryptographic machine, the second door guard type application cryptographic machine restores the original service data, and accurately sends the original service data to the second service, such as a control center, a monitoring terminal, and the like in the power system, to implement fine-grained protection and correct transmission of different instructions of the IEC 104 protocol data.

[0122] Another flowchart of a door guard type cryptographic application method provided by the embodiment of the application is provided, the door guard type cryptographic application method is applied to a second door guard type application cryptographic machine, and the door guard type cryptographic application method includes the following steps.

[0123] In step S201, secure service data is obtained, the secure service data includes a new application payload, the new application payload includes ciphertext payloads corresponding to all sub-content protection policies in a preset data protection policy and an extension payload, and the data protection policy includes at least one sub-content protection policy.

[0124] In step S202, each sub-extension payload is obtained according to the extension payload, each sub-extension payload is determined according to a security control parameter corresponding to a sub-content protection policy and a protection mode, and each sub-content protection policy includes to-be-protected data limiting parameters, a protection mode, and a protection key index.

[0125] Step S203, according to each protection mode, security control parameter and protection key index, the ciphertext payload is decrypted by using a preset decryption algorithm to obtain the to-be-protected data corresponding to each sub-content protection strategy; the original application payload is determined according to each to-be-protected data and the ciphertext payload; and the original service data is generated according to the original application payload;

[0126] Step S204, the original service data is sent to the second service.

[0127] In some embodiments, the protection mode (the setting format can refer to Table 1 above) includes any one of a confidentiality protection mode, an integrity protection mode or an integrity and confidentiality protection mode; if the protection mode includes the confidentiality protection mode, the corresponding security control parameter includes an encryption protection vector; if the protection mode includes the integrity protection mode, as shown in Table 2, the corresponding security control parameter includes an integrity check value, and after the ciphertext payload is decrypted, the calculated integrity check result is compared with the received integrity check value; if the two are consistent, it means that the data remains intact during transmission and has not been tampered with; if the two are inconsistent, the to-be-protected data obtained by decryption is not adopted. Figure 6

[0128] In the embodiment, the extension payload includes an extension header, at least one sub-extension field and an extension tail, and after the second gatekeeper application cryptographic machine obtains the secure service data in step S201, the method further includes: determining the range of the extension field according to the header identifier in the extension payload, the tail identifier of the extension tail field and the length of the extension tail field; calculating the CRC32 value of the extension field and comparing it with the check value in the extension tail field; if the check values are consistent, it is considered that the secure service data needs to be subjected to the data verification processing flow in the entry direction.

[0129] It should be noted that the gatekeeper cryptographic application method applied to the second gatekeeper application cryptographic machine provided in the embodiments of the present application corresponds to all the flow steps of the gatekeeper cryptographic application method applied to the first gatekeeper application cryptographic machine in the above embodiments, and the working principles and beneficial effects of the two are the same, and thus will not be described again.

[0130] The embodiments of the present application also provide another gatekeeper cryptographic application method, which is applied to a gatekeeper cryptographic application system, as shown in FIG. 8, the system includes a first gatekeeper application cryptographic machine and a second gatekeeper application cryptographic machine; the method includes: Figure 7

[0131] Step 301, after the first gatekeeper application cryptographic machine and the second gatekeeper application cryptographic machine establish a communication connection, the first gatekeeper application cryptographic machine obtains the original service data of the first service, and the original service data includes an original application payload;

[0132] ​​Step 302, the first door guard type application cryptographic machine acquires each sub-content protection policy according to a preset data protection policy, each sub-content protection policy including a to-be-protected data definition parameter, a protection mode, and a protection key index, and the data protection policy including at least one sub-content protection policy;

[0133] Step 303, the first door guard type application cryptographic machine respectively determines to-be-protected data corresponding to each sub-content protection policy in the original application load according to each to-be-protected data definition parameter, respectively determines a corresponding security control parameter according to each protection mode, encrypts each to-be-protected data according to the corresponding protection mode, security control parameter, and protection key index by using a preset encryption algorithm to obtain a ciphertext load, generates a corresponding sub-extension load according to each sub-content protection policy and the corresponding security control parameter, generates an extension load according to each sub-extension load, generates a new application load according to the ciphertext load and the extension load, and generates a secure service data according to the new application load;

[0134] Step 304, the first door guard type application cryptographic machine sends the secure service data to the second door guard type application cryptographic machine;

[0135] Step 305, the second door guard type application cryptographic machine acquires the secure service data, the secure service data including a new application load, and the new application load including ciphertext loads and extension loads corresponding to all sub-content protection policies in a preset data protection policy, and the protection policy including at least one sub-content protection policy;

[0136] Step 306, the second door guard type application cryptographic machine acquires each sub-extension load according to the extension load, each sub-extension load being determined according to a sub-content protection policy and a security control parameter corresponding to a protection mode, and each sub-content protection policy including a to-be-protected data definition parameter, a protection mode, and a protection key index;

[0137] Step 307, the second door guard type application cryptographic machine respectively decrypts the ciphertext load according to each protection mode, security control parameter, and protection key index by using a preset decryption algorithm to obtain to-be-protected data corresponding to each sub-content protection policy, determines an original application load according to each to-be-protected data and the ciphertext load, and generates an original service data according to the original application load;

[0138] Step 308, the original service data is sent to a second service.

[0139] In the embodiment, the first gatekeeper application cryptographic machine intercepts network message data (i.e., original service data) sent by the first service to the second service, and performs confidentiality protection and / or integrity protection on some fields of the original application payload of the network message data to obtain a secure network message containing a new application payload, and then forwards the network message to the second service. The second gatekeeper application cryptographic machine intercepts the network message sent to the second service, and performs verification, decryption, or in some embodiments, integrity verification on the new application payload. The second gatekeeper application cryptographic machine forwards the restored original data message with verified data to the second service. The application payload between the gatekeeper application cryptographic machines uses a cryptographic algorithm message and cannot be stolen, intercepted, or tampered with during network transmission. The service system sees only plaintext service application payload, which can be stored, processed, etc.

[0140] In the embodiment of the application, the gatekeeper application cryptographic machine is connected in series between the service system and the border router. When the data of the service system passes through the gatekeeper application cryptographic machine, the gatekeeper application cryptographic machine identifies the application payload part in the service network data, and performs confidentiality and integrity protection on the application payload that meets the security policy.

[0141] Referring to Figure 7 In some embodiments, the specific process of data protection in the out direction of the first gatekeeper application cryptographic machine includes:

[0142] The first gatekeeper application cryptographic machine checks the passing service data packet according to the data protection policy. The first gatekeeper application cryptographic machine only processes the service data packet that meets the data protection policy in terms of protocol and port.

[0143] The first gatekeeper application cryptographic machine compares each sub-content protection policy in the protection policy one by one, and compares all protection conditions in each sub-content protection policy. The first gatekeeper application cryptographic machine only processes the service data message that matches all protection conditions.

[0144] The first gatekeeper application cryptographic machine determines the protection range of the application payload according to the protection start point and the protection length in the sub-content protection policy. If the protection mode is integrity protection or integrity confidentiality protection (corresponding to protection mode 2 and protection mode 3 in Table 1 above), the first gatekeeper application cryptographic machine uses the key of the integrity protection key index to calculate the integrity check value of the payload data in the protection range according to the protection mode using the SM4-GCM algorithm. The integrity check value is stored in the sub-extension field.

[0145] If the protection method is confidentiality protection or integrity confidentiality protection (corresponding to protection method 1 and protection method 3 in Table 1), the first gatekeeper-type application cryptographic machine generates an encryption protection vector IV, uses the key indexed by the confidentiality protection key, and protects the payload data within the protection range using the SM4-GCM algorithm according to the protection method. The encrypted data is stored in the "payload data starting from the protection start point and protection length" location.

[0146] Based on the protection method, sub-extended payloads are constructed using the encryption protection vector IV, protection start point, protection length and protection method, and protection key index or integrity check value. Multiple sub-extended payloads are combined to form an extended payload. The extended payload check value is calculated and filled into the end of the original data packet to obtain a secure message.

[0147] In some embodiments, the specific process of data verification in the inbound direction of the second gatekeeper-type application cryptographic machine includes: the second gatekeeper-type application cryptographic machine performs type determination on the passing business data packets, and the determination is based on:

[0148] The header identifier in the extended header field, the tail representation in the extended tail field, and the length of the extended tail field determine the range of the extended payload field. The CRC32 value of the extended field is calculated and compared with the checksum in the extended tail field. If the checksums match, the data packet is considered to require inbound data verification processing.

[0149] like Figure 6 In the embodiment shown, the second gatekeeper-style application cryptographic machine processes each sub-extended payload one by one, and parses out the protection start point and protection length in each sub-extended payload to determine the protection range.

[0150] If the protection method is confidentiality protection or integrity confidentiality protection, the second gatekeeper-style application cryptographic machine uses the vector IV in the sub-extended payload and the key indexed by the confidentiality protection key, and employs the SM4-GCM algorithm for protection. The decrypted data is stored in the "payload data starting from the protection start point and extending to the protection length" location.

[0151] If the protection method is integrity protection or integrity confidentiality protection, the second gatekeeper-style application cryptographic machine uses the key indexed by the integrity protection key and calculates its integrity check value using the SM4-GCM algorithm to measure the protection range. This integrity check value is then compared with the integrity check value in the sub-extended payload; if they do not match, the application payload is considered to have been tampered with.

[0152] The second gatekeeper-type application cryptographic machine constructs a sub-extension payload according to the protection mode, the vector IV, the protection start point, the protection length, the protection mode, the protection key index, and the integrity check value. After processing all the sub-extension payloads, the second gatekeeper-type application cryptographic machine strips the extension payload, restores the service data application payload, and obtains the original service data message. The second gatekeeper-type application cryptographic machine forwards the restored original service data message to the second service.

[0153] The application provides a fine-grained gatekeeper-type cryptographic application method, which can support fine protection on a certain field in an application payload. For a service system, the service system does not participate in the process of protecting the application data. The application reduces the difficulty of learning cryptographic algorithms and server cryptographic machine interfaces for the R&D personnel of the service system, reduces the cost of applying cryptography for the service system, is more helpful for old service systems and industrial control systems, and can quickly apply cryptography.

[0154] An embodiment of the application further provides a gatekeeper-type cryptographic application device, which is applied to a first gatekeeper-type application cryptographic machine, as shown in Figure 8 The device comprises:

[0155] A first data receiving module is configured to obtain original service data of a first service, wherein the original service data comprises original application payload.

[0156] A first protection policy obtaining module is configured to obtain each sub-content protection policy according to a preset data protection policy, wherein each sub-content protection policy comprises data to be protected limiting parameters, a protection mode, and a protection key index, and the data protection policy comprises at least one sub-content protection policy.

[0157] A data encryption module is configured to determine data to be protected corresponding to each sub-content protection policy in the original application payload according to each data to be protected limiting parameter; determine a corresponding security control parameter according to each protection mode; encrypt each data to be protected by using a preset encryption algorithm according to the corresponding protection mode, the security control parameter, and the protection key index, to obtain a ciphertext payload; generate a corresponding sub-extension payload according to each sub-content protection policy and the corresponding security control parameter; generate an extension payload according to each sub-extension payload; generate a new application payload according to the ciphertext payload and the extension payload; and generate secure service data according to the new application payload.

[0158] A first data sending module is configured to send the secure service data to a second gatekeeper-type application cryptographic machine, so that the second gatekeeper-type application cryptographic machine obtains the original application payload according to the secure service data, generates original service data according to the original application payload, and sends the original service data to a second service.

[0159] Another embodiment of the application further provides a gatekeeper-type cryptographic application device, which is applied to a second gatekeeper-type application cryptographic machine, as shown in Figure 9 The device comprises:

[0160] The second data receiving module is configured to acquire the secure service data, the secure service data including a new application payload, the new application payload including a ciphertext payload and an extension payload corresponding to all sub-content protection policies in a preset data protection policy, and the data protection policy including at least one sub-content protection policy;

[0161] The second protection policy obtaining module is configured to obtain each sub-extension payload according to the extension payload, each sub-extension payload being determined according to a security control parameter corresponding to a sub-content protection policy and a protection mode, and each sub-content protection policy including a to-be-protected data limiting parameter, a protection mode and a protection key index;

[0162] The data decryption module is configured to decrypt the ciphertext payload by using a preset decryption algorithm according to each protection mode, the security control parameter and the protection key index, to obtain to-be-protected data corresponding to each sub-content protection policy, to determine an original application payload according to each to-be-protected data and the ciphertext payload, and to generate original service data according to the original application payload.

[0163] The second data sending module is configured to send the original service data to a second service.

[0164] The gatekeeper type password application device provided in the embodiments of the present application can provide fine-grained application data protection for a service system without sensing, and can effectively improve the difficulty and cost of applying passwords to the service system, and can guarantee the security of application-level transmission of service data.

[0165] The gatekeeper type password application device provided in the embodiments of the present application can provide fine-grained application data protection for a service system without sensing, and can effectively improve the difficulty and cost of applying passwords to the service system, and can guarantee the security of application-level transmission of service data.

[0165] The gatekeeper type password application device provided in the embodiments of the present application can provide fine-grained application data protection for a service system without sensing, and can effectively improve the difficulty and cost of applying passwords to the service system, and can guarantee the security of application-level transmission of service data.

Claims

1. A gatekeeper-style cryptographic application method, characterized in that, The method, applied to a first-gatekeeper-style cryptographic machine, includes: Obtain the original business data of the first service, wherein the original business data includes the original application payload; Each sub-content protection strategy is obtained according to the preset data protection strategy. Each sub-content protection strategy includes a data limit parameter to be protected, a protection method, and a protection key index. The data limit parameter to be protected includes a protection start point and a protection length. The data protection strategy includes at least one sub-content protection strategy. The data to be protected is determined according to the protection parameters of each of the sub-contents in the original application payload, corresponding to the protection strategies. The corresponding security control parameters are determined according to each of the protection methods. Based on the corresponding protection methods, security control parameters and protection key index, the data to be protected is encrypted using a preset encryption algorithm to obtain the ciphertext payload. A corresponding sub-extended payload is generated based on each sub-content protection strategy and the corresponding security control parameters. The sub-extended payload includes the protection start point, protection length, protection method, protection key index, and corresponding security control parameters. An extended payload is generated based on each sub-extended payload. The extended payload includes an extension header, each sub-extended payload, and an extension tail. The encrypted payload and the extended payload are combined to form a new application payload, and secure business data is generated based on the new application payload. The security service data is sent to the second gatekeeper application cryptographic machine, so that the second gatekeeper application cryptographic machine obtains the original application payload based on the security service data, generates original service data based on the original application payload, and sends the original service data to the second service.

2. The gatekeeper-style cryptographic application method according to claim 1, characterized in that, The method further includes: Each of the sub-content protection strategies includes protection conditions, and the parameters limiting the data to be protected include the protection start point and the protection length; The data to be protected corresponding to each sub-content protection strategy in the original application payload is determined according to the limiting parameters of each data to be protected, including: Based on each of the protection conditions, determine whether the data corresponding to the sub-content protection strategy in the original application payload needs to be protected; if protection is required, then the data of the protection length starting from the protection start point is taken as the data to be protected corresponding to the sub-content protection strategy.

3. The gatekeeper-style cryptographic application method according to claim 2, characterized in that, The protection conditions include the calculation method, the calculated value, and the preset result; Determine whether the data corresponding to the sub-content protection strategy in the original application payload needs protection based on each of the protection conditions, including: The calculation is performed on the calculated value using the aforementioned calculation method. The calculated result is compared with the preset result. If they match, the data corresponding to the sub-content protection strategy in the original application payload needs to be protected.

4. The gatekeeper-style cryptographic application method according to claim 1, characterized in that, The original business data also includes the protocol header; Before obtaining the protection policies for each sub-content according to the preset data protection policy, the following steps are included: Obtain the network protocol, source port, and destination port from the protocol header; if the network protocol, source port, and destination port meet the requirements of the data protection policy regarding the protocol and port, then obtain the protection policies for each sub-content according to the data protection policy.

5. The gatekeeper-style cryptographic application method according to claim 1, characterized in that, The protection method includes any one of confidentiality protection, integrity protection, or integrity-confidentiality protection. If the protection method includes confidentiality protection, then the corresponding security control parameters include encryption protection vectors; If the protection method includes an integrity protection method, then the corresponding security control parameters include an integrity check value.

6. A gatekeeper-style password application method, characterized in that, The method, applied to a second-gatekeeper-style cryptographic machine, includes: Acquire security business data, the security business data including new application payload, the new application payload including ciphertext payload and extended payload corresponding to all sub-content protection strategies in the preset data protection strategy, the extended payload including extended header, each sub-extended payload and extended tail, the data protection strategy including at least one sub-content protection strategy; Each sub-extended payload is obtained based on the extended payload. Each sub-extended payload is determined according to the security control parameters corresponding to the sub-content protection strategy and protection method. Each sub-content protection strategy includes the data to be protected limitation parameters, the protection method, and the protection key index. The data to be protected limitation parameters include the protection start point and the protection length. The sub-extended payload includes the protection start point, the protection length, the protection method, the protection key index, and the corresponding security control parameters. Based on each protection method, security control parameter, and protection key index, the ciphertext payload is decrypted using a preset decryption algorithm to obtain the data to be protected corresponding to each sub-content protection strategy; the original application payload is determined based on each data to be protected and the ciphertext payload; the original service data is generated based on the original application payload and sent to the second service.

7. The gatekeeper-style cryptographic application method according to claim 6, characterized in that, The protection method includes any one of confidentiality protection, integrity protection, or integrity-confidentiality protection. If the protection method includes confidentiality protection, then the corresponding security control parameters include encryption protection vectors; If the protection method includes an integrity protection method, the corresponding security control parameters include an integrity check value. After decrypting the ciphertext payload, the calculated integrity check result is compared with the received integrity check value. If the two are consistent, it means that the data has maintained its integrity during transmission and has not been tampered with. If the two are inconsistent, the decrypted data to be protected is not used.

8. A gatekeeper-style password application method, characterized in that, It is applied to a gatekeeper-style cryptographic application system, which includes a first gatekeeper-style application cryptographic machine and a second gatekeeper-style application cryptographic machine. The method includes: After the first gatekeeper application cryptographic machine and the second gatekeeper application cryptographic machine establish a communication connection, the first gatekeeper application cryptographic machine obtains the original service data of the first service, and the original service data includes the original application payload. The first gatekeeper-style application cryptographic machine obtains each sub-content protection strategy according to the preset data protection strategy. Each sub-content protection strategy includes the data to be protected limitation parameters, protection method and protection key index. The data to be protected limitation parameters include the protection start point and protection length. The data protection strategy includes at least one sub-content protection strategy. The first gatekeeper-style application cryptographic machine determines the data to be protected corresponding to each sub-content protection strategy in the original application payload according to the limiting parameters of each data to be protected; determines the corresponding security control parameters according to each protection method; and encrypts each data to be protected using a preset encryption algorithm according to the corresponding protection method, security control parameters, and protection key index to obtain a ciphertext payload; generates corresponding sub-extended payloads according to each sub-content protection strategy and corresponding security control parameters, wherein the sub-extended payloads include the protection start point, protection length, protection method, protection key index, and corresponding security control parameters; generates extended payloads according to each sub-extended payload, wherein the extended payloads include an extension header, each sub-extended payload, and an extension tail; combines the ciphertext payload and the extended payloads to form a new application payload, and generates secure business data according to the new application payload; The first gatekeeper-type application cryptographic machine sends the security business data to the second gatekeeper-type application cryptographic machine; The second gatekeeper-type application cryptographic machine acquires the security business data, which includes a new application payload. The new application payload includes ciphertext payloads and extended payloads corresponding to all sub-content protection strategies in the preset data protection strategy. The data protection strategy includes at least one sub-content protection strategy. The second gatekeeper-type application cryptographic machine obtains each sub-extended payload according to the extended payload. Each sub-extended payload is determined according to the security control parameters corresponding to the sub-content protection strategy and protection method. Each sub-content protection strategy includes the data to be protected limitation parameters, the protection method and the protection key index. The second gatekeeper-style application cryptographic machine decrypts the ciphertext payload using a preset decryption algorithm according to each of the protection methods, security control parameters, and protection key indexes to obtain the data to be protected corresponding to each sub-content protection strategy; determines the original application payload based on each of the data to be protected and the ciphertext payload; generates original business data based on the original application payload, and sends the original business data to the second business.

9. A gatekeeper-style password application device, characterized in that, The device, used in a first-gatekeeper-style cryptographic machine, comprises: The first data receiving module is used to acquire the original service data of the first service, the original service data including the original application payload; The first protection strategy acquisition module is used to acquire each sub-content protection strategy according to the preset data protection strategy. Each sub-content protection strategy includes the data to be protected limitation parameters, protection method and protection key index. The data to be protected limitation parameters include the protection start point and protection length. The data protection strategy includes at least one sub-content protection strategy. The data encryption module is used to: determine the data to be protected corresponding to each sub-content protection strategy in the original application payload according to the limiting parameters of each data to be protected; determine the corresponding security control parameters according to each protection method; encrypt each data to be protected using a preset encryption algorithm according to the corresponding protection method, security control parameters, and protection key index to obtain a ciphertext payload; generate corresponding sub-extended payloads according to each sub-content protection strategy and corresponding security control parameters, wherein the sub-extended payloads include the protection start point, protection length, protection method, protection key index, and corresponding security control parameters; generate extended payloads according to each sub-extended payload, wherein the extended payloads include an extension header, each sub-extended payload, and an extension tail; combine the ciphertext payload and the extended payloads to form a new application payload; and generate secure business data according to the new application payload. The first data transmission module is used to send the security service data to the second gatekeeper application cryptographic machine, so that the second gatekeeper application cryptographic machine can obtain the original application payload based on the security service data, generate original service data based on the original application payload, and send the original service data to the second service.

10. A gatekeeper-style password application device, characterized in that, The device, used in a second-gatekeeper-style cryptographic machine, comprises: The second data receiving module is used to acquire security business data. The security business data includes a new application payload. The new application payload includes ciphertext payloads and extended payloads corresponding to all sub-content protection strategies in the preset data protection strategy. The extended payloads include an extended header, each sub-extended payload and an extended tail. The data protection strategy includes at least one sub-content protection strategy. The second protection strategy acquisition module is used to obtain each sub-extended payload according to the extended payload. Each sub-extended payload is determined according to the security control parameters corresponding to the sub-content protection strategy and protection method. Each sub-content protection strategy includes the data to be protected limitation parameters, the protection method, and the protection key index. The data to be protected limitation parameters include the protection start point and the protection length. The sub-extended payload includes the protection start point, the protection length, the protection method, the protection key index, and the corresponding security control parameters. The data decryption module is used to decrypt the ciphertext payload according to each of the protection methods, security control parameters and protection key indexes, using a preset decryption algorithm to obtain the data to be protected corresponding to each sub-content protection strategy; determine the original application payload according to each of the data to be protected and the ciphertext payload; and generate the original business data according to the original application payload. The second data sending module is used to send the original service data to the second service.

Citation Information

Patent Citations

  • Message confidentiality processing method for two-layer network packet

    CN117254926A

  • Data encryption method and system, computer equipment and medium

    CN117527307A