System for monitoring quantum key traffic and security execution module
By monitoring the parameters of the API interface in quantum key distribution technology, counting and reporting quantum key traffic, the problem of difficulty in monitoring quantum key traffic in the existing technology is solved, and effective monitoring and management of quantum key application scenario traffic is achieved.
Patent Information
- Application Number
- CN202311399333.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-25
- Publication Date
- 2025-05-06
AI Technical Summary
In quantum key distribution technology, the prior art is difficult to effectively monitor the traffic of quantum keys, resulting in the inability to timely control the traffic of key data and application data during the encrypt/decryption and authentication operations.
When the quantum key is called by the API interface, the interface parameters of the API interface are monitored, these parameters are counted to monitor the quantum key traffic, and the monitoring results are reported to the converged security management platform for associated storage.
It realizes effective monitoring of traffic in quantum key application scenarios, which facilitates users to monitor and query traffic by accessing the converged security management platform, and improves the efficiency of security management.
Smart Images

Figure CN119945947A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of quantum technology, and in particular to a system for monitoring quantum key flow and a secure execution module. Background Art
[0002] Quantum Key Distribution (QKD) technology uses the characteristics of quantum mechanics to ensure communication security. It enables both parties in communication to generate and share a random, secure key to encrypt and decrypt (abbreviated as "encryption / decryption") data, which does not rely on the requirements and assumptions of computational complexity and has the advantage of theoretically unconditional security. The quantum no-cloning theorem can ensure that any quantum state cannot be perfectly cloned.
[0003] In the wide range of application scenarios of quantum keys, especially in the operations of encrypting / decrypting or authenticating data, quantum keys and application data operated by quantum keys are transmitted in large quantities over the network. Therefore, monitoring the flow of related key data and application data in the application scenarios of quantum keys has become a core concern in this field. Summary of the invention
[0004] The purpose of the embodiments of the present invention is to provide a system and a secure execution module for monitoring quantum key traffic, which can effectively monitor the traffic in quantum key application scenarios.
[0005] An embodiment of the present invention provides a method for monitoring quantum key traffic, comprising: obtaining a quantum key; when the quantum key is called via a first interface, monitoring first interface parameters, wherein the first interface parameters include application / facility parameters and / or business content parameters; monitoring quantum key traffic by counting the first interface parameters, and reporting the quantum key traffic to a converged security management platform for associated storage.
[0006] An embodiment of the present invention also provides a secure execution module, comprising: at least one processor; and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method for monitoring quantum key flow as described above.
[0007] An embodiment of the present invention also provides a system for monitoring quantum key traffic, comprising: the secure execution module and the integrated security management platform as described above.
[0008] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the method for monitoring quantum key flow as described above.
[0009] Compared with the prior art, in the embodiments of the present invention, after acquiring the quantum key, when the quantum key is called via the first interface, the first security execution module monitors the first interface parameters, that is, monitors the application / facility parameters for calling the quantum key and / or the business content parameters to be executed by calling the quantum key; monitors the quantum key flow by counting the first interface parameters, and reports the monitored quantum key flow to the fusion security management platform for associated storage, thereby realizing the monitoring of the flow in the quantum key application scenario, so that users can monitor and query the relevant flow of the quantum key by accessing the fusion security management platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplified descriptions do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.
[0011] Figure 1 is a system architecture diagram for monitoring quantum key traffic according to an embodiment of the present invention;
[0012] Figure 2 is a specific flow chart of a method for monitoring the flow of a quantum key according to an embodiment of the present invention;
[0013] Figure 3 is a timing diagram for monitoring quantum key traffic according to an embodiment of the present invention;
[0014] Figure 4 is a schematic structural diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0015] In order to make the purpose, technical scheme and advantages of the embodiments of the present invention clearer, the following will be described in detail with reference to the accompanying drawings. However, it will be appreciated by those skilled in the art that in the various embodiments of the present invention, many technical details are provided in order to enable the reader to better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical scheme claimed in the present application can be implemented.
[0016] With the widespread use of quantum keys, quantum keys are used every time data is encrypted / decrypted or authenticated, and controlling the quantum key flow has become one of the core tasks in the application process. The core point of this application is to monitor the interface parameters of the API interface when the quantum key is called by the API interface by standardizing the API (Application Programming Interface), thereby monitoring the quantum key flow. Figure 1 The main architecture diagram of monitoring quantum key flow provided by this application is a system architecture diagram for monitoring quantum key flow. Figure 1 As shown in , the system for monitoring quantum key traffic includes:
[0017] The security execution module (SEM for short) includes a first security execution module SEM1 and a second security execution module SEM2. Here, the security execution module (SEM) is a cryptographic operation device for data encryption / decryption, and has the capabilities of key generation / storage, digital signature / signature verification, identity authentication, data encryption / decryption, quantum random numbers, and key management. The quantum key distribution (QKD) network provides the quantum key vector (hereinafter referred to as the parent key ID) to the SEM through the quantum key management machine (QKMT). The SEM's external application interface supports JAVA and C language APIs to achieve mutual control of security services with applications / facilities. At the same time, the SEM can also provide key services and key management (referred to as "key services / key management") to applications / facilities. The application / facility refers to a specific application or facility in the business system, such as a cloud desktop, a quantum virtual machine, a distributed storage system, and a file encryption device. The business system refers to the business links required for the company to achieve its positioning, the roles played by each partner, and the ways and contents of cooperation and transactions among stakeholders, such as Customer Relationship Management (CRM) and Warehouse Management System (WMS).
[0018] The Harmonized Security Control Module (HSCM) is the central management platform of SEM. HSCM is connected to SEM to centrally manage and control SEM. Multiple HSCMs form a HSCM network. The first security execution module SEM1 and the second security execution module SEM2 pre-negotiate quantum key through the HSCM. The purpose of quantum key negotiation is to enable SEM1 to fill the local offline key pool with quantum key, and SEM2 can also synchronously fill the local offline key pool with the same quantum key.
[0019] It can be seen that the core subject involved in the system for monitoring quantum key traffic is SEM1. SEM1 obtains quantum keys from the QKD network and exchanges quantum key traffic with HSCM. Therefore, the problem of monitoring quantum key traffic can be solved through the C plane (control plane) and the U plane (user plane). In the C plane (control plane), it mainly involves the specification of interface specifications, data encryption / decryption call timing, transmission data packet size, etc.; S3-c represents the protocol process of the control plane, which includes interface specifications, data encryption / decryption call timing, and transmission data packet size. In the U plane (user plane), the key traffic and user data traffic used by users are mainly monitored; S3-u represents the user plane process.
[0020] At least one embodiment of the present application provides a secure execution module, such as SEM1, Figure 2 As shown, it includes at least one processor 202; and a memory 201 that is communicatively connected to the at least one processor 202; wherein the memory 201 stores instructions that can be executed by the at least one processor 202, and the instructions are executed by the at least one processor 202 so that the at least one processor 202 can execute the method for monitoring quantum key flow developed by the present invention.
[0021] Among them, the memory 201 and the processor 202 are connected in a bus manner, and the bus may include any number of interconnected buses and bridges, and the bus connects one or more processors 202 and various circuits of the memory 201 together. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and therefore, are not further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be one element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices on a transmission medium. The data processed by the processor 202 is transmitted on a wireless medium through an antenna, and further, the antenna also receives data and transmits the data to the processor 202.
[0022] Processor 202 is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interfaces, voltage regulation, power management and other control functions. Memory 201 can be used to store data used by processor 202 when performing operations. In the above-mentioned system for monitoring quantum key flow and the operating environment of the secure execution module, the method for monitoring quantum key flow in this application will be described below through multiple embodiments. At least one embodiment of the present invention provides a method for monitoring quantum key flow, which is applied to a first secure execution module (SEM1). As Figure 3 As shown, the method for monitoring quantum key flow includes the following steps:
[0023] Step 302, obtaining a quantum key;
[0024] Step 304, when the quantum key is called via the first interface, monitoring the first interface parameters, wherein the first interface parameters include application / facility parameters and / or business content parameters;
[0025] Step 306: Count the first interface parameters to monitor the quantum key flow, and report the quantum key flow to the integrated security management platform for associated storage.
[0026] Compared with the prior art, in the embodiments of the present invention, after acquiring the quantum key, when the quantum key is called via the first interface, the first security execution module monitors the first interface parameters, that is, monitors the application / facility parameters for calling the quantum key and / or the business content parameters to be executed by calling the quantum key; monitors the quantum key flow by counting the first interface parameters, and reports the monitored quantum key flow to the fusion security management platform for associated storage, thereby realizing the monitoring of the flow in the quantum key application scenario, so that users can monitor and query the relevant flow of the quantum key by accessing the fusion security management platform.
[0027] In step 102, a quantum key is obtained. For example, the first security execution module SEM1 obtains a quantum key from the QKD network and stores the obtained quantum key in a local offline key pool; since the first security execution module SEM1 and the second security execution module SEM2 have previously negotiated a quantum key through the converged security management platform HSCM, after SEM1 fills the quantum key into the local offline key pool, SEM2 can also synchronously complete filling the same quantum key into the local offline key pool.
[0028] The process of the first security execution module SEM1 obtaining a quantum key from the QKD network and storing the obtained quantum key in a local offline key pool may be as follows: after quantum key negotiation, SEM1 receives a first request, wherein the first request is a KMIP (Key Management Interoperability Protocol) request sent by the converged security management platform HSCM, and the request is used to instruct to fill the quantum key into the offline key pool of the first security execution module SEM1; thereafter, SEM1 obtains the quantum key from the QKD network according to the KMIP request and fills the quantum key into the offline key pool of the first security execution module SEM1.
[0029] After SEM1 fills the quantum key into the local offline key pool, SEM2 can also synchronously complete filling the same quantum key into the local offline key pool: Since SEM1 and SEM2 have previously negotiated the quantum key through the fused security management platform HSCM, after SEM1 obtains the quantum key, the HSCM callback mechanism can be used to enable SEM2 to synchronously complete filling the same quantum key into the local offline key pool, that is, the quantum key is shared to the second security execution module through the quantum key negotiation of the fused security management platform.
[0030] Among them, the capacity of the offline key pool can be customized by the application / facility connected to the SEM, that is, the application / facility reports its identity ID in the business system, such as user ID, component ID, etc., to the HSCM through the connected SEM, and then sets the capacity of the offline key pool of the SEM connected to the application / facility through the HSCM.
[0031] In step 304, when the quantum key is called via the first interface, the first interface parameters are monitored, wherein the first interface parameters include application / facility parameters and / or business content parameters. The application / facility parameters may be parameters related to identifying the device or component of the application / facility that initiates the key service request, which region, which cloud system, or which application, and these parameters may uniquely identify an application / facility; this embodiment does not limit the number and content of parameters contained in the application / facility, as long as an application / facility can be uniquely identified, for example, the application / facility parameters at least include: component ID (including customer ID, application ID, device ID, etc.). The business content parameters may be parameters related to identifying the business functions and business processes of the key service, and these parameters may uniquely identify a key service; for example, the business content parameters may include a business ID and a sub-business ID, wherein the business ID is the upper-layer business function information representing the key service, and when the upper-layer business function information is relatively complex, it may also be decomposed into multiple sub-business function information and form a corresponding sub-business ID.
[0032] That is to say, the first security execution module SEM 1 and the application / facility implement the call of the quantum key through the first interface (API). When the quantum key is called through the first interface, SEM 1 can synchronously monitor the first interface parameters. For example, a key creation request initiated by the application / facility is obtained through the first interface, wherein the key creation request carries public parameters and key parameters, and the public parameters include business content parameters; a quantum key that meets the key parameter requirements is taken out from the offline key pool; a key operation is performed on the business corresponding to the business content parameters using the quantum key, and the first interface parameters monitored during the key operation are counted.
[0033] First, a key creation request initiated by an application / facility is obtained through a first interface, wherein the key creation request carries public parameters and key parameters, and the public parameters include service content parameters. Given that the first security execution module SEM1 will first create a quantum key for the key service to be processed each time it processes a key service (wherein the created quantum key may be a symmetric key or an asymmetric key), in order to facilitate monitoring of the first interface parameters, this embodiment sets the interface specification included in the S3-c protocol process as follows: SEM1 identifies and manages programs that call the interface through a set of security processes, such as a key creation request, that is, each key creation request for a key service needs to carry public parameters and key parameters.
[0034] The public parameter request header contains the following information:
[0035] POST / model / method HTTP / 1.1
[0036] Date:GMT Date / / Time
[0037] Content-Length: ContentLength / / text length
[0038] Content-Type: application / json; charset=UTF-8 / / text type
[0039] Report-Information:eyJXaG8iOiJ4eHgiLCJBY3Rpb2……XJrMiI6IiIsIlJlbWFyazMiOiIifQ==
[0040] / / Report information
[0041] FlowNo:1000000001 / / Anti-replay attack flow number
[0042] Token:RyH9pGeP......an6Yk / / Token serial number
[0043] The above Report-Information is the Base64 encoded value of the information content reported by the business system every time it calls the interface to initiate a request for key business. The content is in the JSON structure as follows:
[0044] {"Who":"xxx","Action":"xxx","SubAction":"xxx","Remark1":"","Remark2":"","Remark3":""}, the mandatory items of the JSON structure are as follows: Who: component ID (the business system needs to inform SEM1 of the component hierarchy and naming rules in advance, with a length limit of 512 bytes, divided into service class code and device class code); Action: business ID, the business function to be implemented by the current call to the key business, for example: verifying the integrity of the XXX image file, etc.; SubAction: sub-business ID, for relatively logically complex businesses, fill in the name of the sub-business action included in the business; Remark1: reserved field; Remark2: reserved field; Remark3: reserved field; FlowNo: anti-replay attack serial number; the business system needs to add a gradually increasing integer in the request header, and the maximum value of the anti-replay attack serial number does not exceed 9999999999999. The serial number can be counted again each time the authentication interface is called again to obtain the token serial number; Token: serial number.
[0045] In the above public parameter information, Who can be used as an application / facility parameter, and Action and SubAction can be used as business content parameters. Note: Each field "xxx" is a plaintext string, and it is not allowed to upload ID-type numbers. In addition, the public parameters may include parameter items including Report-Information, FlowNo, and Token in the above public parameter request header, as well as configuration parameters, performance alarm parameters, security parameters, and public KPI parameters carried in other locations (such as the request body). The key parameter request header contains the following information: the key parameters include a key algorithm identifier, validity period, update cycle, and parent key ID. Among them, the key algorithm identifier is used to uniquely identify a key algorithm, which can be but is not limited to: SM1, SM2, SM4, AES128, AES256, RSA2048, SHA256 and other algorithms; according to the key algorithm identifier, the corresponding key algorithm can be uniquely determined.
[0046] Therefore, when the first security execution module SEM 1 obtains the key creation request initiated by the application / facility through the first interface, the above-mentioned public parameters (including at least service content parameters and application / facility parameters) and key parameters passed by the application / facility can be obtained through the first interface. In addition, before initiating a key creation request for a key service, the application / facility can first report the above-mentioned public parameters corresponding to the key service to be requested to SEM1 separately, and SEM1 will feedback the parameter response ID corresponding to the public parameter to the application / facility; the parameter response ID serves as a unique identifier for responding to the public parameter and will not be repeated. When the application / facility subsequently wants to initiate a request for a key service containing the above-mentioned public parameters, the unique identifier of the public parameter can be used to proxy the public parameter transmission, thereby reducing the occupation of network transmission resources.
[0047] Second, take out a quantum key that meets the key parameter requirements from the offline key pool. The above-mentioned offline key pool includes a spare key library and an in-use key library. That is to say, after receiving the above-mentioned key creation request, the first security execution module SEM1 takes out a quantum key that meets the key parameter requirements from the offline key pool. The process includes: taking out a quantum key that meets the key parameter requirements from the spare key library and putting it into the in-use key library, and feeding back the key ID of the quantum key to the application / facility, wherein the state of the quantum key is adjusted to the in-use state; recording the current timestamp, validity period and update period of the quantum key, and reporting the key ID, current timestamp, validity period and update period to the integrated security management platform for associated storage.
[0048] First, after SEM1 obtains the quantum key from the QKD network and stores it in the offline key pool, it will assign the parent key ID corresponding to the quantum key to the customer. In this way, when the customer initiates a request to SEM1 through the application / facility to create a quantum key for processing key services, the customer will carry the parent key ID and the key parameters set for the validity period and update period of the created quantum key in the request and send it to SEM1.
[0049] Secondly, after receiving the key creation request, SEM1 extracts the key parameters from the key creation request, and extracts the quantum key that meets the key parameter requirements from the standby key library of the offline key pool and puts it into the in-use key library. For example, the quantum key corresponding to the parent key ID in the key parameters can be extracted from the standby key library as the quantum key that meets the requirements. This quantum key is the quantum key created by SEM1 for the current creation request, and the state of the quantum key is adjusted to the in-use state. At the same time, the key ID of the quantum key is generated, and the key ID is fed back to the application / facility.
[0050] Finally, SEM1 records the current timestamp, validity period, and update cycle of the quantum key, and reports the key ID, current timestamp, validity period, and update cycle to the integrated security management platform for associated storage.
[0051] Third, the quantum key is used to perform key operations on the services corresponding to the service content parameters, and the first interface parameters monitored during the key operations are counted. That is to say, after the quantum key is created, when the key service is subsequently processed, SEM1 can use the quantum key to perform key operations on the services corresponding to the service content parameters carried in the key creation request, and count the first interface parameters monitored during the key operations. Among them, the process of performing key operations on the services corresponding to the service content parameters using the quantum key includes: creating a service unique identifier based on the key ID, operation mode and initial vector passed in by the application / facility, and feeding back the service unique identifier to the application / facility; performing key operations on the services corresponding to the service content parameters using the quantum key, operation mode and initial vector corresponding to the key ID pointed to by the service unique identifier.
[0052] First, a unique service identifier is created based on the key ID, operation mode and initial vector passed in by the application / facility, and the unique service identifier is fed back to the application / facility. For example, after the application / facility obtains the key ID from SEM1, it will send a key service processing request carrying the public parameters (or the parameter response ID corresponding to the public parameters) and the key ID, operation mode and initial vector (also called "IV") to SEM1, so as to request SEM1 to initialize the process of the key service to be processed, including coordinating the key operation resources used to process the key service, retrieving the quantum key corresponding to the key ID from the local key library in use, and extracting the key algorithm corresponding to the key algorithm identifier from the key algorithm stored locally. SEM1 determines that the key service requested this time is the key service pointed to by the public parameter (parameter response ID) based on the key ID, operation mode and initial vector passed in by the application / facility, and the key service requested this time needs to use the quantum key corresponding to the key ID for key operation, and creates a unique service identifier for the key ID, operation mode and initial vector passed in by the application / facility, and feeds back the unique service identifier to the application / facility. From then on, the initialization process of this key service processing is completed. The business unique identifier is used to uniquely identify a business processing process.
[0053] Then, SEM1 can use the quantum key, operation mode and initial vector corresponding to the key ID pointed to by the business unique identifier to perform key operation on the business corresponding to the business content parameters. For example, after obtaining the business unique identifier, the application / facility begins to submit business data that needs to be key processed to SEM1. For example, the application / facility sends a key business processing request containing the business unique identifier and the business data to be processed to SEM1. SEM1 uses the quantum key, operation mode and initial vector corresponding to the key ID pointed to by the business unique identifier to perform key operation on the business data in the request (i.e., the business corresponding to the business content parameters carried in the quantum key creation request). The result data of the key operation is then fed back to the application / facility.
[0054] Among them, if the key service to be processed is an encryption / decryption data service, then the service data in the key service processing request should contain the plaintext / ciphertext data to be encrypted / decrypted; if the key service to be processed is an authentication service, then the service data in the key service processing request should contain the data to be authenticated. The key algorithm used in the key service processing can be uniquely determined by the key algorithm identifier in the key parameters received in the previous quantum key creation process, and the operation mode and initial vector are related settings for the key operation process.
[0055] Finally, after the key operation is completed, SEM 1 will count the first interface parameters monitored during the key operation. In some embodiments, the amount of business data submitted by the application / facility to SEM1 may be very large. In this case, the business data can be divided into multiple groups and submitted to SEM1 for key operation processing. For example, SEM1 can use the quantum key corresponding to the key ID to perform key operation on the multiple groups of business data submitted by the application / facility group by using the key algorithm corresponding to the key algorithm identifier, and feedback the result data group of the key operation corresponding to each group of business data to the application / facility.
[0056] When performing key calculation processing on grouped business data, the application / facility can submit one group of business data to SEM1 each time; after SEM1 completes processing on one group of business data and feeds back the corresponding result data to the application / facility, the application / facility can submit the next group of business data to SEM1 for processing after receiving the result data. The amount of business data submitted each time can be pre-regulated, for example, the data packet size of a group of business data is set to not exceed 64K (65,535 bytes). If the data packet size is larger than 64K, the application / facility needs to trim the data packet in advance to obtain multiple groups of business data for group submission.
[0057] After all business data processing is completed, SEM1 will receive a key operation termination request containing a business unique identifier initiated by the application / facility, terminate the key operation process, and release the key operation resources. For example, when the application / facility has submitted all business data to be processed and received the result data, and needs to terminate the processing of this key business, it can initiate a key operation termination request containing a business unique identifier to SEM1. After receiving the request, SEM1 terminates the processing of this key business and releases the key operation resources for use in the next key business processing process.
[0058] In addition, it should be noted that before SEM1 uses the quantum key corresponding to the key ID to process the key service, it needs to first determine whether the state of the extracted quantum key is in an available state. Only when it is determined that the state of the quantum key corresponding to the key ID is in an available state can the quantum key be used to process the key service; the state of the quantum key includes: in use, expired, cancelled and deactivated. The explanation of the state of the quantum key is as follows.
[0059] 1. When in use, it indicates that key operations such as data encryption / decryption can be performed.
[0060] 2. When in expired state, it means that decryption operation can be performed, but encryption operation cannot be performed.
[0061] 3. When in the logged-out state, it cannot be reactivated and encryption / decryption operations cannot be performed.
[0062] 4. When in the disabled state, it can be reactivated and encryption / decryption operations can be performed after activation, but encryption / decryption operations cannot be performed when in the disabled state.
[0063] Among them, the in-use and expired states applied in the decryption service are both available states; the other states are unavailable states. During the key calculation process, SEM1 counts the first interface parameters monitored during the key calculation process.
[0064] In step 306, the first interface parameters are counted to monitor the quantum key flow, and the quantum key flow is reported to the fusion security management platform for associated storage. For example, after the key service processing is completed, SEM1 counts the quantum key flow used for the key service processing this time, including the flow of quantum keys and / or the flow of processed business data according to the detected first interface parameters, and uploads the statistical result data and the previous public parameters (parameter response ID) to the fusion security management platform for associated storage. At this time, the first interface parameters of the key service, parameter response ID, key ID, key parameters of the quantum key, and the flow of quantum keys used for key service processing and / or the flow of processed business data have been associated and stored in the fusion security management platform, that is, after SEM1 processes each key service, this whole set of data can be counted, and then this whole set of data is associated and stored in the HSCM.
[0065] In some examples, counting the first interface parameters to monitor the quantum key flow may include: counting the first interface parameters to obtain at least one of the total flow of using quantum random numbers, the total flow of creating keys, the total flow of updating keys, the total flow of canceling keys, the total flow of encryption services, the total flow of decryption services, the total flow of signatures, the total flow of signature verification, the total flow of hashes, and the total flow of HMAC (Hash-based Message Authentication Code, key-related hash operation message authentication code) to monitor the quantum key flow.
[0066] In some examples, customers can query the data stored in HSCM to learn about the flow of quantum keys used by SEM1 in the process of processing key services and / or the flow of business data being processed. For example, the first security execution module SEM1 can provide an API query quantum key flow interface / v1 / flow / flowTotal to the outside, and accordingly, a quantum key flow query service can be provided through / v1 / flow / flowTotal. After the customer initiates a request to query the quantum key flow to the first security execution module SEM1 through / v1 / flow / flowTotal, SEM1 obtains the query data from the integrated security management platform and feeds it back to the customer through / v1 / flow / flowTotal.
[0067] Through the above implementation of the present invention, the quantum key flow is monitored by counting the first interface parameter of SEM1, and the monitored quantum key flow is reported to the fusion security management platform for associated storage, thereby realizing the monitoring of the flow in the quantum key application scenario, so that users can monitor and query the relevant flow of quantum keys by accessing the fusion security management platform. Based on the above inventive concept, Figure 4As shown, an embodiment of the present invention provides a complete timing diagram regarding the data encryption / decryption call timing.
[0068] Step 401: Obtain the quantum key. The SEM obtains the quantum key from the QKD network and puts it into the offline key pool.
[0069] Step 402: Sending the parent key ID. The SEM sends the parent key ID corresponding to the quantum key to the application / facility, which then distributes it to the designated customer.
[0070] Step 403: Sending public parameters corresponding to the key service to be requested. The application / facility sends the public parameters corresponding to the key service to be requested to the SEM, and the public parameters at least include: application / facility parameters and / or service content parameters.
[0071] Step 404: Return parameter response ID. The SEM generates and returns a parameter response ID corresponding to the public parameter to the application / facility. The parameter response ID can uniquely identify the public parameter.
[0072] Step 405: Send a request to create a symmetric key. The application / facility sends a request to the SEM for creating a symmetric key, which carries a parameter response ID, and key parameters including the validity period and update period of the quantum key to be created, and the parent key ID corresponding to the quantum key.
[0073] Step 406: Create a symmetric key and generate a key ID. The SEM extracts a quantum key that meets the key parameter requirements from the backup key library of the offline key pool and puts it into the in-use key library, sets the state of the quantum key to the in-use state, and records the current timestamp, the validity period of the quantum key, the update cycle and other parameters. Generate a corresponding key ID for the created quantum key.
[0074] Step 407-1: Upload key information and key service information. The SEM uploads key information (key ID, current timestamp and key parameters) and key service information (public parameters, parameter response ID) to the HSCM.
[0075] Step 407-2: Recording key information and key service information: HSCM associates and stores the key information and key service information uploaded by SEM locally.
[0076] Step 408: Return the key ID. The SEM returns the key ID generated after creating the quantum key to the application / facility.
[0077] Step 409: Send a request for initializing symmetric encryption / decryption services. The application / facility sends a request for initializing symmetric encryption / decryption services to the SEM, which carries a key ID, a parameter response ID, and a key algorithm identifier (and, if necessary, an algorithm mode and initial vector (IV) corresponding to the key algorithm).
[0078] Step 410: Perform symmetric encryption / decryption service initialization and create a unique encryption / decryption service identifier. After receiving the request for symmetric encryption / decryption service initialization, the SEM performs initialization operations such as coordinating key operation resources for processing key services, retrieving the quantum key corresponding to the key ID from the local key library in use, and extracting the key algorithm corresponding to the cryptographic algorithm identifier from the locally stored key algorithm. At the same time, a unique encryption / decryption service identifier is created when performing encryption / decryption services.
[0079] Step 411: Return the unique identifier of the encryption / decryption service. The SEM returns the created unique identifier of the encryption / decryption service to the application / facility.
[0080] Step 412: Send a processing request carrying the unique identifier of the encryption / decryption service and the plaintext / ciphertext to be encrypted / decrypted. The application / facility sends a processing request to the SEM, which carries the unique identifier of the encryption / decryption service and the plaintext / ciphertext to be encrypted / decrypted.
[0081] Step 413: Execute key operation to generate ciphertext / plaintext. SEM uses the quantum key corresponding to the key ID extracted from the local in-use key library and the key algorithm corresponding to the key algorithm identifier extracted from the local, and uses the extracted quantum key to perform key operation on the plaintext / ciphertext to be encrypted / decrypted submitted by the application / facility using the key algorithm corresponding to the extracted key algorithm identifier, to generate the encrypted / decrypted ciphertext / plaintext.
[0082] Step 414: Return ciphertext / plaintext. SEM feeds back the ciphertext / plaintext obtained after encryption / decryption to the application / facility.
[0083] Step 415: Send an end request carrying the unique identifier of the encryption / decryption service. After the application / facility submits all the plaintext / ciphertext to be encrypted / decrypted and receives the corresponding ciphertext / plaintext obtained after encryption / decryption, it sends an end request carrying the unique identifier of the encryption / decryption service to the SEM to request the SEM to end the key calculation process corresponding to the unique identifier of the service.
[0084] Step 416: Release the key computing resources. After receiving the end request sent by the application / facility, the SEM releases the key computing resources used in the current key computing process.
[0085] Step 417: Return an end response. The SEM notifies the application / facility that the key calculation process is complete.
[0086] Step 418-1: Upload key service information and data traffic. SEM counts the data traffic used in this key operation process, including the traffic of quantum keys and the traffic of service data processed by quantum keys (plaintext / ciphertext to be encrypted / decrypted), and then uploads the counted data traffic together with the key service information to HSCM.
[0087] Step 418-2: Record key service information and data traffic. HSCM associates and stores the data traffic and key service information uploaded by SEM locally. Combined with the previously stored key information and key service information, the data traffic used in the key service process can be well monitored. Customers can keep track of the traffic situation in the quantum key service at any time by querying HSCM. In addition, it should be noted that regarding the size of the transmitted data packet, in each request (key creation request, key service processing request, etc.) initiated by the application / facility containing the parameter response ID, the size of the transmitted data packet will be limited and marked, so as to facilitate the subsequent SEM to count the size of the received data packet.
[0088] At least one embodiment of the present application provides a computer-readable storage medium, which is built into the first secure execution module SEM1 and stores a computer program. When the computer program is executed by the processor, the method for monitoring quantum key flow developed by the present application and its embodiments are implemented. That is, those skilled in the art can understand that all or part of the steps in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a program, and the program is stored in a storage medium, including several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0089] Those skilled in the art will appreciate that the above-mentioned embodiments are specific examples for implementing the present invention, and in actual applications, various changes may be made thereto in form and detail without departing from the spirit and scope of the present invention.
Claims
1. A method for monitoring quantum key flow, applied to a first secure execution module, characterized in that: include: Obtain quantum keys; When the quantum key is called via the first interface, monitoring first interface parameters, wherein the first interface parameters include application / facility parameters and / or business content parameters; The first interface parameter is counted to monitor the quantum key flow, and the quantum key flow is reported to the fusion security management platform for associated storage.
2. The method according to claim 1, wherein the first security execution module and the second security execution module perform quantum key negotiation through a fusion security management platform, wherein: The obtaining of the quantum key comprises: Receiving a first request, wherein the first request is a KMIP request sent by the converged security management platform; According to the KMIP request, a quantum key is obtained from the QKD network and the quantum key is filled into the offline key pool of the first security execution module, wherein the quantum key is shared to the second security execution module via quantum key negotiation of the fusion security management platform.
3. The method according to claim 1, wherein the first security execution module is further connected to an application / facility, characterized in that: When the quantum key is called via the first interface, monitoring the first interface parameters includes: Acquire a key creation request initiated by an application / facility through a first interface, wherein the key creation request carries a public parameter and a key parameter, and the public parameter includes a service content parameter; Taking out a quantum key that meets the key parameter requirements from an offline key pool; The quantum key is used to perform a key operation on the service corresponding to the service content parameter, and statistics are collected on the first interface parameter monitored during the key operation.
4. The method according to claim 3, wherein the public parameters further include application / facility parameters, characterized in that: Acquiring a key creation request initiated by an application / facility through the first interface includes: The key parameters and the public parameters passed by the application / facility are obtained through the first interface, wherein the key parameters include a key algorithm identifier, a validity period, an update period, and a parent key ID; the public parameters include Report-Information, FlowNo, Token, configuration parameters, performance alarm parameters, security parameters, and public KPI parameters; the Report-Information is a JSON structure {"Who":"xxx","Action":"xxx","SubAction":"xxx","Remark1":"","Remark2":"","Remark3":""}, wherein Who represents a component ID, the Action represents a business function to be implemented through the first interface call, the SubAction represents a sub-business action of the business, the Remark1 is a first reserved field, the Remark2 is a second reserved field, the Remark3 is a third reserved field, the xxx represents a plaintext string, the Who belongs to the application / facility parameters, the Action and the SubAction belong to the business content parameters, the FlowNo represents an anti-replay attack serial number, and the Token represents a serial number.
5. The method according to claim 3, wherein the offline key pool comprises a standby key library and an in-use key library, wherein: The quantum key that meets the key parameter requirements is taken out from the offline key pool and includes: Taking out a quantum key that meets the key parameter requirements from the standby key library and putting it into the in-use key library, and feeding back the key ID of the quantum key to the application / facility, wherein the state of the quantum key is adjusted to the in-use state; The current timestamp, validity period and update period of the quantum key are recorded, and the key ID, the current timestamp, the validity period and the update period are reported to the fusion security management platform for associated storage.
6. The method according to claim 3, characterized in that Using the quantum key to perform key calculation on the service corresponding to the service content parameter includes: Create a unique business identifier according to the key ID, operation mode and initial vector passed by the application / facility, and feed back the unique business identifier to the application / facility; The key operation is performed on the service corresponding to the service content parameters using the quantum key, operation mode and initial vector corresponding to the key ID pointed to by the service unique identifier.
7. According to the method of claim 1, the first security execution module provides an API query quantum key flow interface / v1 / flow / flowTotal, characterized in that: Also includes: The query service of the quantum key flow is provided through / v1 / flow / flowTotal, and the query data of the quantum key flow is obtained from the integrated security management platform.
8. The method according to claim 1, characterized in that Counting the first interface parameter to monitor quantum key traffic includes: The first interface parameter is counted to obtain at least one of the total flow of using quantum random numbers, the total flow of creating keys, the total flow of updating keys, the total flow of canceling keys, the total flow of encryption services, the total flow of decryption services, the total flow of signatures, the total flow of signature verification, the total flow of hashes, and the total flow of HMAC to monitor the quantum key flow.
9. A secure execution module, characterized in that: include: at least one processor; A memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method for monitoring quantum key flow as described in any one of claims 1 to 8.
10. A system for monitoring quantum key traffic, characterized in that: include: The security execution module and integrated security management platform as described in claim 9.