Data encryption method and device, equipment, medium and product
By encrypting and serializing data in a distributed environment, and performing identity checksum permission isolation, the shortcomings of traditional solutions in key management and permission verification are solved, and an efficient and secure data encryption and decryption process is achieved.
Patent Information
- Application Number
- CN202510279390.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-05-13
AI Technical Summary
In a distributed environment, data encryption and decryption solutions need to take into account security and performance. Traditional solutions are difficult to balance efficiency and security, especially in key management and permission verification.
The initial data is encrypted by using the data encryption key of the first service, and the encrypted data and meta information are serialized to generate serialized encrypted data. The meta information includes at least the identity of the first service. This solution performs identity checksum permission isolation during the encryption and decryption process to ensure that only authorized services can decrypt data.
It significantly improves the security and access control capabilities of data encryption and decryption, ensures the security and integrity of data during transmission and storage, and optimizes data transmission efficiency and key life cycle management, achieving a balance of security, flexibility and performance.
Smart Images

Figure CN119996046A_ABST
Abstract
Description
Technical Field
[0001] Example embodiments of the present disclosure generally relate to the field of computers, and more particularly, to methods, devices, apparatuses, and computer-readable storage media for data encryption. Background Art
[0002] With the rapid development of information technology and network communications, data security has become a key issue of concern to all industries. Data needs to be strictly protected during storage, transmission and use to prevent information leakage or tampering. At the same time, the widespread application of modern distributed systems and cloud computing has made encryption and decryption technology a key supporting technology for data protection. However, due to the high-frequency interaction of data and complex operation processes in distributed environments, encryption and decryption solutions must ensure both security and efficiency to meet the system's performance requirements. Summary of the invention
[0003] In a first aspect of the present disclosure, a data encryption method is provided. The method comprises: using a first data encryption key of a first service, encrypting initial data to be encrypted from a first service to obtain first encrypted data; determining first serialized encrypted data by serializing the first encrypted data and meta information related to the first encrypted data, wherein the meta information at least includes an identity of the first service; and providing the first serialized encrypted data to the first service.
[0004] In a second aspect of the present disclosure, a method for data encryption is provided. The method includes: in response to receiving a key acquisition request from a first service, performing identity authentication on the first service based on an identity identifier of the first service included in the key acquisition request; if it is determined that the first service passes the identity authentication, acquiring a data encryption key for the first service; and sending the data encryption key to the first service.
[0005] In a third aspect of the present disclosure, a data encryption device is provided. The device includes: an encryption module configured to encrypt initial data to be encrypted from a first service using a first data encryption key of the first service to obtain first encrypted data; a serialization module configured to determine first serialized encrypted data by serializing the first encrypted data and meta information related to the first encrypted data, wherein the meta information includes at least an identity of the first service; and a providing module configured to provide the first serialized encrypted data to the first service.
[0006] In a fourth aspect of the present disclosure, a device for data encryption is provided. The device includes: an identity authentication module, configured to, in response to receiving a key acquisition request from a first service, perform identity authentication on the first service based on the identity of the first service included in the key acquisition request; an acquisition module, configured to acquire a data encryption key for the first service if it is determined that the first service passes the identity authentication; and a sending module, configured to send the data encryption key to the first service.
[0007] In a fifth aspect of the present disclosure, an electronic device is provided. The device includes at least one processor; and at least one memory, the at least one memory is coupled to the at least one processor and stores instructions for execution by the at least one processor. When the instructions are executed by the at least one processor, the device executes the method of the first aspect or the second aspect.
[0008] In a sixth aspect of the present disclosure, a computer-readable storage medium is provided, wherein computer-executable instructions are stored on the computer-readable storage medium, and the computer-executable instructions can be executed by a processor to implement the method of the first aspect or the second aspect.
[0009] In a seventh aspect of the present disclosure, a computer executable instruction product is provided, which is tangibly stored in a computer storage medium and includes computer executable instructions, which, when executed by a device, cause the device to perform the method of the first aspect or the second aspect.
[0010] It should be understood that the contents described in this content section are not intended to limit the key features or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. In the accompanying drawings, the same or similar reference numerals represent the same or similar elements, wherein:
[0012] Figure 1 A schematic diagram showing an example environment in which embodiments of the present disclosure can be implemented;
[0013] Figure 2 A schematic diagram showing the architecture of a system for data encryption according to some embodiments of the present disclosure;
[0014] Figure 3A A schematic diagram showing an example process of initialization according to some embodiments of the present disclosure;
[0015] Figure 3BA schematic diagram showing an example process of data encryption according to some embodiments of the present disclosure;
[0016] Figure 3C A schematic diagram showing data that needs to be serialized according to some embodiments of the present disclosure;
[0017] Figure 3D A schematic diagram showing an example process of data decryption according to some embodiments of the present disclosure;
[0018] Figure 4A Schematic diagram showing an example process of updating a key encryption key (KEK) according to some embodiments of the present disclosure
[0019] Figure 4B A schematic diagram illustrating an example process of updating a data encryption key (DEK) according to some embodiments of the present disclosure;
[0020] Figure 5 A flowchart illustrating an example process of data encryption according to some embodiments of the present disclosure;
[0021] Figure 6 A flowchart illustrating an example process for data encryption according to some embodiments of the present disclosure is shown;
[0022] Figure 7 A schematic structural block diagram of a data encryption device according to some embodiments of the present disclosure is shown;
[0023] Figure 8 A schematic structural block diagram of a device for data encryption according to some embodiments of the present disclosure is shown; and
[0024] Fig. 9 A block diagram of an electronic device is shown in which one or more embodiments of the present disclosure may be implemented. DETAILED DESCRIPTION
[0025] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.
[0026] In the description of the embodiments of the present disclosure, the term "including" and similar terms should be understood as open inclusion, that is, "including but not limited to". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions may also be included below.
[0027] Herein, unless explicitly stated, executing a step “in response to A” does not mean executing the step immediately after “A” but may include one or more intermediate steps.
[0028] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.
[0029] It is understandable that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, scope of use, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0030] For example, in response to receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested to be performed will require obtaining and using the user's personal information, so that the user can independently choose whether to provide personal information to software or hardware such as electronic devices, applications, servers or storage media that execute the operations of the technical solution of the present disclosure based on the prompt message.
[0031] As an optional but non-limiting implementation, in response to receiving an active request from the user, the prompt information is sent to the user in a manner such as a pop-up window, in which the prompt information can be presented in text form. In addition, the pop-up window can also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0032] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that meet relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0033] Figure 1 A schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented is shown. In the example environment 100, an application 120 is installed in a terminal device 110. A user 140 can interact with the application 120 via the terminal device 110 and / or an attached device of the terminal device 110. The application 120 can be a content presentation application, an online shopping application, or any other appropriate application.
[0034] exist Figure 1 In the environment 100, if the application 120 is in an active state, the terminal device 110 can present the interface 150 of the application 120. The interface 150 may include various user interfaces that the application 120 can provide, such as a content presentation interface, a content creation interface, a content publishing interface, a message interface, a personal homepage, and the like. The application 120 may provide a content viewing function to view various types of content published in the application 120. Through the corresponding page, the application 120 can provide various types of online content to the user 140. The embodiments of the present disclosure do not limit the specific functions of the application and the content presented. The operation of the application can be activated through an appropriate triggering method, such as clicking or selecting an application icon.
[0035] In some embodiments, the terminal device 110 communicates with the server 130 to provide services for the application 120. For example, the user 140 may communicate with the service via the terminal device 110 and / or an attached device of the terminal device 110. The service may be any type of application service, such as e-commerce service, online education service, data analysis service, financial system service, etc., or may be a functional service that provides computing task processing, such as information storage, data compression, or information transmission.
[0036] In some embodiments, the terminal device 110 can be any type of mobile terminal, fixed terminal or portable terminal, including mobile phones, desktop computers, laptop computers, notebook computers, netbook computers, tablet computers, media computers, multimedia tablets, personal communication systems (PCS) devices, personal navigation devices, personal digital assistants (PDAs), audio / video players, digital cameras / camcorders, positioning devices, television receivers, radio broadcast receivers, e-book devices, gaming devices, or any combination of the foregoing, including accessories and peripherals of these devices or any combination thereof. In some embodiments, the terminal device 110 can also support any type of interface for the user (such as "wearable" circuits, etc.). The server 130 can be various types of computing systems / servers that can provide computing power, including but not limited to mainframes, edge computing nodes, computing devices in cloud environments, and the like.
[0037] It should be understood that the structure and function of the various elements in the environment 100 are described for exemplary purposes only and do not imply any limitation on the scope of the present disclosure.
[0038] As briefly mentioned above, with the rapid development of the Internet and the widespread application of data technology, more and more data needs to be transmitted and processed in the network, storage or system. Whether it is enterprise-level business data (such as user information, transaction records) or personal privacy data, it faces the risk of data leakage, tampering and illegal access. In order to protect the security of this data, encryption and decryption technology has become an indispensable core means in the field of data security.
[0039] Data encryption and decryption technology is the process of converting plaintext data (i.e. readable initial data) into ciphertext data (i.e. unreadable encoded data) through a specific encryption algorithm and restoring ciphertext data to plaintext data through the corresponding key and decryption algorithm. By selecting appropriate encryption and decryption algorithms and key management strategies, the security and integrity of data during transmission and storage can be ensured. However, there are still some problems with traditional data encryption and decryption processing solutions. The following describes several typical implementation methods.
[0040] A typical implementation method involves encryption and decryption based on a software development kit (SDK). Specifically, by providing an encryption and decryption SDK to the business party, the business party directly calls the SDK in the code to perform encryption and decryption operations. The SDK usually provides the ability to cache keys and has encryption and decryption functions, which can be executed directly on the business party's host machine. Since the encryption and decryption operations occur locally, this method has the advantages of low latency and high performance. However, there is an important problem with this method, that is, the keys and encryption and decryption logic are directly exposed to the business code. If the key is leaked or the SDK code is decompiled, it may lead to data leakage, seriously affecting the security of the data. In addition, for business systems in different programming languages, different SDK versions need to be developed for each language. This will result in additional development and maintenance costs.
[0041] Another typical implementation involves a centralized encryption and decryption service. Specifically, a centralized encryption and decryption service is provided, and the business party sends the data to be encrypted to this service. The server is responsible for performing encryption and decryption operations and key management processes. The keys and encryption and decryption logic are performed in the remote server and are not exposed to the business party. Therefore, this method has more centralized key management, lower risk of key leakage, and higher security. However, since encryption and decryption operations need to be called through remote procedure calls (RPCs) to call centralized services, network latency will be introduced. For business applications that require high performance and low latency, this may become a performance bottleneck. In addition, various business parties may share the same set of computing resources (such as the same encryption and decryption service instance), which will lead to resource competition between different business services. If resources are occupied by other business services, the performance or security of the current business service may be affected.
[0042] In addition, the decryption permission verification of traditional data encryption and decryption solutions may be relatively simple or even missing. For example, only the server verifies whether the key matches, but does not verify whether the identity of the decryption request has the corresponding permission. Ciphertext data usually only contains the encrypted data itself, and does not include information about the service that encrypted the data. In this case, if the key is leaked or obtained by other services, other services may decrypt data that does not belong to them. This situation poses a data security risk.
[0043] In view of this, according to an embodiment of the present disclosure, an improved scheme for data encryption is proposed. The scheme includes first encrypting the initial data to be encrypted from the first service using the first data encryption key of the first service to obtain first encrypted data. Then, by serializing the first encrypted data and meta information related to the first encrypted data, the first serialized encrypted data is determined. The meta information includes at least the identity of the first service. Further, the first serialized encrypted data is provided to the first service.
[0044] Therefore, by serializing the encrypted data and meta-information including identity identifiers into complete structured data, the security and access control capabilities of data encryption and decryption are significantly improved. By verifying the identity of the encrypted data and isolating permissions, it is ensured that only authorized services can decrypt the relevant data, and even if the ciphertext is leaked, it cannot be decrypted by other services. In addition, by utilizing efficient serialization and flexible encryption key management mechanisms, data transmission efficiency and key lifecycle management are optimized. In this way, the balance between security, flexibility and performance in the data encryption process can be maximized.
[0045] Figure 2 A schematic diagram of an architecture 200 of a system for data encryption according to some embodiments of the present disclosure is shown. Figure 1 The system architecture 200 is described.
[0046] refer to Figure 2 , the user 140 can communicate with the business service (such as the first service 210) deployed by the server via the terminal device 110 and / or the attached device of the terminal device 110 to complete the call and processing of specific business functions. In this interactive process, data processing, transmission and storage are involved. In order to ensure the security and privacy of data, some data may need to be encrypted and decrypted.
[0047] In some embodiments of the present disclosure, a software development kit (Crypto SDK) 215 for calling data encryption and decryption functions is provided. The software development kit 215 encapsulates an interface that can call encryption and decryption plug-ins, which is convenient for business parties to call. The actual encryption and decryption logic is implemented by the encryption and decryption plug-in (Crypto Plugin) 220. In addition, the plug-in and business service codes are isolated. In this way, the business party corresponding to the first service 210 cannot directly see the code related to the encryption and decryption logic, thereby improving data security.
[0048] Continue to refer Figure 2 , the encryption and decryption plug-in 220 can be deployed in the same host (e.g., the first host machine 205) as the first service 210. The encryption and decryption plug-in 220 may run in the same process or in an isolated process as the first service 210. For example, the encryption and decryption plug-in 220 plug-in can be packaged in the form of a dynamic link library and distributed through a plug-in management platform. When the first service 210 is started, the compiled encryption and decryption plug-in 220 can be downloaded through the software development kit 215 and loaded into the first host machine 205 for operation. In this way, the first service 210 can perform encryption and decryption without relying on remote services, avoiding the delay and performance loss caused by remote calls.
[0049] The encryption and decryption plug-in 220 can send an encryption request to the encryption service 230 by carrying the business identity of the first service 210 to obtain a key for data encryption. Encryption and decryption authority management and key management are implemented by the encryption service 230. The first service 210 and the encryption service 230 can be deployed on the same server or on different servers.
[0050] The first service 210 interacts with the encryption service 230 through the encryption and decryption plug-in 220, for example, to query the key or verify the identity. The key management service 240 may be responsible for managing and storing encryption keys and updating and rotating the keys.
[0051] Since the encryption and decryption logic is executed in the local plug-in, remote procedure calls are avoided, thereby reducing latency. At the same time, key management remains centralized. In addition, strict identity authentication can further ensure the security of the encryption and decryption process.
[0052] In some examples, the data encryption scheme in the embodiments of the present disclosure also supports business scenarios of dynamic expansion and contraction. For example, user 140 can call the first service 210 on the server side through an asynchronous task (such as event-driven, message queue), and the first service 210 may run in the form of function as a service (FaaS).
[0053] During the execution process, the FaaS service calls the encryption and decryption plug-in 220 deployed in the FaaS container 10 through the software development kit 215. The encryption and decryption plug-in 220 can send an encryption request to the encryption service 230 by carrying the identity corresponding to the FaaS service to obtain the key used for data encryption. The encryption and decryption plug-in 220 can also be deployed in the FaaS container 10 in the form of a dynamic link library, and share computing and memory resources with the FaaS service, thereby avoiding the delay problem caused by cross-network calls.
[0054] As an example, Figure 3A FIG. 3 is a schematic diagram showing an example process 300A of initialization according to some embodiments of the present disclosure. Figure 3A As shown, when the first service 210 is started, it can first be initialized ( 301 ) through the integrated software development kit 215 , so as to deploy the encryption and decryption plug-in 220 to the host machine of the first service 210 .
[0055] The encryption and decryption plug-in 220 first obtains (302) the identity of the first service 210. For example, the encryption and decryption plug-in 220 obtains the identity of the first service 210 from an environment variable. An environment variable is a global variable provided by an operating system, which can be used to share configuration information between applications or services. Obtaining the identity generated or assigned by the service at startup from the environment variable can ensure the uniqueness and accuracy of the identity. In addition, environment variables are usually only accessible in the running environment and are not directly exposed in the code base, thereby reducing the risk of information leakage.
[0056] In order to ensure the security of the identity during transmission, the encryption and decryption plug-in 220 can encrypt the identity (303). The encryption and decryption plug-in 220 can include the encrypted identity of the first service 210 in a key acquisition request, and send the key acquisition request (304) to the encryption service 230. The key acquisition request is used to request the acquisition of the DEK required for encryption and decryption.
[0057] The encryption service 230 receives a key acquisition request from the first service 210, and decrypts the encrypted identity in the request (311). Based on the identity obtained by decryption, the encryption service 230 can verify the identity of the first service 210. After confirming that the identity of the first service 210 has the corresponding decryption authority, the encryption service 230 can query (312) the DEK corresponding to the identity in the database 250. Stored in the database 250 is the DEK ciphertext (encrypted DEK) and the identifier (ID) of the KEK. Therefore, even if the database 250 is attacked, the key will not be directly leaked. This further improves the security of data encryption.
[0058] Database 250 returns (313) the ciphertext of the DEK and the ID of the KEK to encryption service 230. Based on the received KEK ID, encryption service 230 can query (314) the corresponding KEK from Key Management Service (KMS) 240. Then, encryption service 230 uses the KEK to decrypt (315) the DEK ciphertext retrieved from database 250 to obtain the unencrypted DEK (i.e., plaintext DEK).
[0059] Finally, the encryption service 230 returns (316) the decrypted DEK to the encryption and decryption plug-in 220 for use in decryption. In order to improve performance, the encryption and decryption plug-in 220 can cache (305) the received DEK locally to avoid the need to frequently request the DEK through remote calls. In this way, the time delay of the encryption and decryption plug-in 220 for encrypting data can be reduced.
[0060] After the initialization is completed, the first service 210 can perform encryption using a specific encryption algorithm. By converting the data to be encrypted into encrypted data that cannot be directly read, the security and integrity of the data during transmission and storage are ensured. For example, the first DEK of the first service 210 is used to encrypt the initial data to be encrypted from the first service 210 to obtain the first encrypted data.
[0061] As an example, Figure 3B FIG. 3 is a schematic diagram showing an example process 300B of data encryption according to some embodiments of the present disclosure. Figure 3B The first service 210 first determines the encoded data by encoding the initial data to be encrypted (321). The encoded data includes the initial data and an identifier. The identifier is used to indicate the type of the initial data.
[0062] In order to ensure that the decrypted data can be restored correctly and without loss of accuracy, the first service 210 can encode the data to be encrypted before encryption. For example, before encryption, an identifier byte is added to each piece of data to indicate the data type (e.g., string, value, etc.) of the initial data. The subsequent bytes represent the actual content of the initial data. This method ensures that during the encryption and decryption process, no matter what type of data it is, it can be processed accordingly according to the type of data.
[0063] Through this unified encoding mechanism for data types, business services can share encrypted and decrypted data between different languages without worrying about inconsistent data formats. Regardless of the programming language used for encryption and decryption, the decrypted data can be restored in the correct type. In this way, cross-platform and cross-language encryption and decryption becomes possible.
[0064] In some embodiments, the first service 210 encrypts the encoded data using the first data encryption key. For example, the first service 210 may request (322) the encryption and decryption plug-in 220 to encrypt the initial data through the software development kit 215.
[0065] refer to Figure 3B , the encryption / decryption plug-in 220 first checks whether there is a corresponding first DEK in the local cache. If the first DEK exists in the cache, the encryption / decryption plug-in 220 can directly obtain (323) the DEK corresponding to the first service 210 from the cache. If the DEK in the cache has expired, is invalid, or does not exist, the encryption / decryption plug-in 220 can send (324) a key acquisition request to the encryption service 230. Through the key acquisition request, the first DEK is requested to be acquired.
[0066] In some embodiments, the key acquisition request includes the identity of the first service 210. Different business services usually have their own independent DEKs. Through the identity, the encryption service 230 can clearly know which business service the queried DEK belongs to, thereby determining whether to return (325) the corresponding DEK. In this way, incorrect key usage due to lack of identity authentication can be avoided, and the DEK can be prevented from being leaked to services or users that do not have relevant permissions.
[0067] In order to prevent other unauthorized services from obtaining keys and decrypting data that does not belong to them, the encryption service needs to verify whether the requesting service is legitimate and whether the service has the authority to access the requested key before obtaining the DEK. In some embodiments, the encryption service 230 performs identity authentication on the first service based on the identity of the first service included in the key acquisition request in response to receiving the key acquisition request from the first service 210.
[0068] In some embodiments, the key acquisition request includes an identity encrypted using a public key of the encryption service. The encryption service 230 obtains the identity encrypted by the public key from the received key acquisition request. Then, the encryption service 230 can decrypt the encrypted identity using a private key corresponding to the public key. Based on the decrypted identity, the encryption service 230 determines the identity of the first service 210.
[0069] If the identity is transmitted in plain text, other services or attackers may intercept and tamper with the identity during network transmission, and send a forged key acquisition request by pretending to be the first service 210. By encrypting the identity, the authenticity and security of the identity can be guaranteed, thereby preventing it from being forged or requesting to bypass verification.
[0070] As an example, an identity identifier may be encrypted in an asymmetric encryption manner. For example, before sending a key acquisition request, the first service 210 encrypts its own identity identifier using a public key. The encrypted identity identifier is included in the key acquisition request and passed to the encryption service 230. After receiving the key acquisition request, the encryption service 230 extracts the encrypted identity identifier therein. Then, the encryption service 230 may decrypt the encrypted identity identifier using a private key corresponding to the public key, thereby determining the identity identifier of the first service 210. Based on the decrypted identity identifier, the encryption service 230 may verify whether the identity of the first service 210 is valid and whether it has the corresponding decryption authority. After confirming that the identity of the first service 210 has the corresponding decryption authority, the encryption service 230 may obtain a data encryption key for the first service 210.
[0071] In some embodiments, the encryption service 230 determines the identifiers of the encrypted first DEK and the first KEK corresponding to the identity identifier of the first service. For example, the encryption service 230 can query the DEK corresponding to the identity identifier in the database 250. Stored in the database 250 is the DEK ciphertext (encrypted DEK) and the ID of the KEK. Therefore, even if the database 250 is attacked, the key will not be directly leaked. This further improves the security of data encryption. The database 250 returns the ciphertext of the DEK and the ID of the KEK to the encryption service 230.
[0072] In some embodiments, the encryption service 230 obtains a first KEK corresponding to the ID of the first KED from the KMS 240. The encryption service 230 may decrypt the encrypted DEK by using the first KEK. For example, based on receiving the KEK ID, the encryption service 230 may query the corresponding KEK from the KMS 240. Then, the encryption service 230 uses the KEK to decrypt the DEK ciphertext found from the database 250 to obtain the unencrypted DEK.
[0073] KMS is a security authentication service module, which is usually supported by a hardware security module (HSM) and can provide stronger security protection. KMS240 is responsible for generating and managing KEK, and encryption service 230 obtains KEK based on KEK ID to further improve data security.
[0074] In the embodiment of the present disclosure, DEK is encrypted by using KEK in envelope encryption, so that the security of DEK during storage and transmission can be protected. In addition, the encrypted DEK is stored in the database 250 instead of the plaintext DEK directly, which can minimize the exposure of the plaintext DEK. In this way, unauthorized services are prevented from directly obtaining the DEK and decrypting related data.
[0075] Continue to refer Figure 3B , the encryption service 230 returns (325) the decrypted DEK to the encryption and decryption plug-in 220 for use in decryption. To improve performance, the encryption and decryption plug-in 220 can cache the received DEK locally to avoid the need to frequently request the DEK through remote calls.
[0076] In some examples, in addition to the plaintext DEK obtained by decryption, the encryption service 230 can also return (325) the ciphertext DEK to the encryption and decryption plug-in 220. When the first service 210 requests a key for the first time and uses the encryption and decryption plug-in 220 to request the DEK, it needs to obtain the mapping of the plaintext DEK and the ciphertext DEK at the same time. The ciphertext DEK can be used as a "key" for the plaintext DEK in the cache, and is used to quickly find the corresponding plaintext DEK in the cache later.
[0077] Continue to refer Figure 3B The encryption and decryption plug-in 220 can encrypt (326) the initial data using the DEK returned by the encryption service 230, thereby obtaining the first encrypted data. In order to prevent the first encrypted data from being accessed by a business service that does not have relevant permissions, in some embodiments of the present disclosure, a further permission verification mechanism is introduced.
[0078] refer to Figure 3B The encryption / decryption plug-in 220 may determine the first serialized encrypted data by serializing (327) the first encrypted data and meta-information related to the first encrypted data. The meta-information includes at least an identity of the first service.
[0079] Since the encrypted data itself is only the encryption result of encoding the initial data using a specific encryption algorithm, there is no other context information. In order to achieve the isolation of encryption and decryption permissions for each business service, the encrypted data can be serialized. By including the identity of the first service 210 in the serialized data, the encryption service 230 can perform identity authentication based on the identity. In this way, only services with legal identities can obtain the corresponding DEK. In this way, data leakage or illegal decryption across business services can be prevented.
[0080] As an example, Figure 3C FIG. 3 is a schematic diagram showing data 330 that needs to be serialized according to some embodiments of the present disclosure. Figure 3C As shown, the data 330 to be serialized includes encrypted data 331 encrypted by DEK and meta information 332. In addition to the identity, the meta information 332 may also include the type of encryption algorithm used to encrypt the initial data. By including the type of algorithm used for the encryption operation in the meta information 332, it is ensured that the same algorithm as that used for encryption can be selected during decryption. In this way, decryption failure or data corruption caused by algorithm mismatch during the decryption process is prevented.
[0081] The meta information 332 also includes an identifier (ID) of the first KEK. KEK is a key used to encrypt DEK, and KEK ID is used to identify a specific KEK. The identifier is obtained by mapping through a predetermined conversion algorithm, such as a value after hashing the KEK ID. Hash processing can avoid direct exposure of the KEK ID. In this way, even if the serialized encrypted data is stolen, the KEK ID cannot be directly inferred. Alternatively or additionally, the meta information 332 also includes the first DEK encrypted using the first KEK (i.e., ciphertext DEK).
[0082] The meta information 332 may also include a serialization version number. The serialization version number is used to identify the format version of the serialization data. When the system or protocol is updated, the serialization data structure may need to be adjusted. By identifying the serialization version number, different versions of serialization data can be compatible to ensure that the correct parsing rules are used during decryption.
[0083] In some examples, to ensure the efficiency and readability of the encrypted data after serialization. The encryption and decryption plug-in 220 can use the Protocol Buffers (PB) serialization protocol to perform serialization. PB is an efficient serialization protocol that can provide high-performance serialization and deserialization operations, while effectively compressing data and reducing the burden of storage and transmission. The encryption and decryption plug-in 220 can encode the data serialized by the PB protocol (for example, Base64 encoding) or add a readable prefix. In this way, the serialized encrypted data can be made easier to store and transmit, while improving readability.
[0084] In some embodiments, the first service 210 can decrypt the serialized encrypted data. As an example, Figure 3D FIG. 3 is a schematic diagram showing an example process 300D for data decryption according to some embodiments of the present disclosure. Figure 3D As shown, the first service 210 initiates (341) a decryption request through the software development kit 215, indicating decryption of the second serialized encrypted data. After receiving the decryption request, the encryption / decryption plug-in 220 determines to decrypt the second serialized encrypted data.
[0085] In some embodiments, the encryption / decryption plug-in 220 may perform identity authentication on the first service 210 based on the identity included in the second serialized encrypted data. If it is determined that the first service 210 passes the identity authentication, the encryption / decryption plug-in 220 may decrypt the second serialized encrypted data.
[0086] In some embodiments, the encryption / decryption plug-in 220 determines the second encrypted data corresponding to the second serialized encrypted data and the meta information of the second encrypted data by deserializing the second serialized encrypted data. Figure 3D After receiving the decryption request, the encryption / decryption plug-in 220 can first deserialize (342) the encrypted data to obtain the second encrypted data and the corresponding meta information. The meta information includes the ciphertext DEK used in encryption, the identity of the business service, the encryption algorithm type and other information.
[0087] After deserialization, the encryption and decryption plug-in 220 can perform identity authentication (343) to verify whether the current service 131 has the authority to decrypt the data. The verification is performed by comparing the business service identifier in the ciphertext with the identity of the current caller. If the current business service does not have the authority to decrypt the data, an error may be reported and further execution may be refused. Only if the authority verification passes can subsequent decryption operations be continued. This authority verification mechanism ensures that only authorized business services can decrypt ciphertext to prevent data leakage.
[0088] In some embodiments, the second encrypted data may be data encrypted by the first service 210 itself. In this case, the encryption / decryption plug-in 220 only needs to verify whether the identity of the business service in the meta information matches the identity of the current first service 210. If they match, the encryption / decryption plug-in 220 may determine that the first service 210 has passed the identity authentication.
[0089] In some embodiments, the second encrypted data may also be data encrypted by other services. In order to support this business scenario, a dynamic authorization mechanism is introduced in some embodiments of the present disclosure. For example, the meta information records the identity of the service to which the second encrypted data belongs (such as the second service). When the first service 210 requests to decrypt the second encrypted data, the encryption and decryption plug-in 220 can verify whether the first service 210 has obtained decryption authorization for the encrypted data. In the case of determining that the identity of the service to which the second encrypted data belongs is the identity authorized by the first service 210, the encryption and decryption plug-in 220 can determine that the first service 210 has passed the identity authentication.
[0090] In this embodiment of the present disclosure, the encryption and decryption plug-in not only supports decrypting data encrypted by its own service, but also supports decrypting data encrypted by other services under strict permission verification. This design enhances the ability to share data across services. In addition, the security and compliance of the decryption operation are further ensured through the meta information in the ciphertext and the dynamic permission verification mechanism.
[0091] If it is determined that the first service passes the identity verification, the encryption / decryption plug-in 220 can decrypt the second serialized encrypted data. For example, the encryption / decryption plug-in 220 determines the second DEK based on the identity included in the second serialized encrypted data.
[0092] refer to Figure 3D , the encryption / decryption plug-in 220 may obtain (344) the corresponding second DEK from the cache. If the DEK in the cache has expired, is invalid, or does not exist, the encryption / decryption plug-in 220 may send (345) a key acquisition request for the second DEK to the encryption service 230.
[0093] In some embodiments, the key acquisition request for the second DEK includes the identity of the first service 210. The encryption service 230 can determine which business service the requested DEK belongs to, thereby determining whether to return (346) the corresponding DEK. The encryption service 230 can query the database 250 for the DEK corresponding to the identity. Stored in the database 250 are the DEK ciphertext and the KEK ID. For example, based on receiving the KEK ID, the encryption service 230 can query the corresponding second KEK from the KMS 240. Then, the encryption service 230 uses the second KEK to decrypt the DEK ciphertext retrieved from the database 250 to obtain the unencrypted second DEK.
[0094] After obtaining the second DEK, the encryption / decryption plug-in 220 can use the DEK to decrypt (347) the encrypted data to obtain the encoded original data. The decrypted data is returned (348) to the first service 210, at which point the data is still in the encoded format.
[0095] The first service 210 may de-encode the data according to the encoding rules used when encoding the data (for example, according to the identifier of the data type) (349), and finally obtain the initial data before encryption (plaintext data) for subsequent use.
[0096] In the embodiments of the present disclosure, through deserialization, permission verification, DEK request, decryption and de-encoding, the process of restoring the encrypted data after serialization to the plaintext data before encryption is finally realized. In this way, the performance of data decryption is improved, and the overhead caused by network communication and repeated calculation is reduced. In addition, through strict permission control and key management, the security of data is enhanced. In this way, unauthorized access can be avoided and the consistency and integrity of data decryption can be ensured.
[0097] In addition, if the key is used for a long time without being updated, if the key is leaked, it may cause serious data security problems. In order to further improve the security of data encryption and decryption, DEK and KEK update strategies are introduced in some embodiments of the present disclosure.
[0098] As an example, Figure 4A FIG. 4 is a schematic diagram showing an example process 400A for updating a KEK according to some embodiments of the present disclosure. Figure 4A As shown, if the first KEK used for the first service 210 reaches a predetermined update period, or the encryption service 230 receives an update request for the first KEK, the encryption service 230 may determine that a KEK update request may be sent (411) to the KMS 240. In response to the request, the KMS 240 may generate a new KEK, and then the KMS 240 returns (412) the unique identifier (KEK ID) of the newly generated KEK to the encryption service 230.
[0099] The encryption service 230 receives the updated KEK ID sent by the KMS 240. The encryption service 230 may store (413) the ID in the database 250 for subsequent use and management of the KEK. For example, the encryption service 230 may store the updated KEK ID in the storage structure Key_ring of the database 250. The Key_ring is a logical container in the database 250 to ensure that the KEK ID is properly managed and organized.
[0100] Continue to refer Figure 4A After the database 250 confirms (414) that the storage is successful, the encryption service 230 can use the first KEK before the update to decrypt (415) the encrypted first DEK. Based on the updated first KEK encryption, the encryption service 230 can encrypt (416) the first DEK. In this way, it is ensured that the DEK can continue to be used after the KEK is updated and is protected by the updated KEK, thereby completing the secure rotation of the KEK.
[0101] Cryptographic service 230 may store (417) the updated first KEK-encrypted first DEK and the ID of the updated first KEK in database 250. In response to database 250 confirming (418) that the storage is successful, the full rollover process for the first KEK is completed.
[0102] In some embodiments of the present disclosure, KEK updates are automatically triggered based on the update cycle and manually triggered to deal with emergencies. The generation and management of updated KEKs rely on KMS, and the encryption service only obtains KEKs through the corresponding ID. In this way, key leakage can be further avoided. In addition, in the process of updating KEK, the decryption and encryption of DEK ensure that the usage relationship between DEK and business services is not affected. In this way, a smooth transition between historical KEKs and updated KEKs can be achieved.
[0103] As another example, Figure 4B FIG. 4 is a schematic diagram showing an example process 400B for updating a DEK according to some embodiments of the present disclosure. Figure 4B As shown, if the first DEK for the first service 210 reaches a predetermined update period, or the encryption service 230 receives an update request for the first DEK, the encryption service 230 may update (421) the first DEK. After the update is completed, the encryption service 230 may encrypt the updated first DEK using the first KEK corresponding to the first service 210.
[0104] refer to Figure 4B, the encryption service 230 queries (422) the KEK ID currently in use from the database 250. Based on the KEK ID returned (423) by the database 250, the encryption service 230 sends (424) a KEK acquisition request to the KMS 240. The encryption service 230 acquires the KEK returned (425) by the KMS 240. Based on the KEK returned by the KMS 240, the encryption service 230 encrypts the updated DEK (426).
[0105] The encrypted DEK can be securely stored to avoid direct exposure of the DEK plaintext. The encryption service 230 can store (427) the updated first DEK encrypted by the first KEK in the database 250. In response to the database 250 confirming (428) that the storage is successful, the complete rotation process for the first DEK is completed.
[0106] In the embodiments of the present disclosure, by updating DEK, the potential risk of leakage caused by long-term use of keys can be effectively reduced. In addition, it supports flexible configuration of update cycles according to business needs or manual triggering of updates in emergency situations to ensure rapid response when security incidents occur. Overall, the DEK update strategy further improves the security of data and can meet diverse business security requirements.
[0107] In summary, according to various embodiments of the present disclosure, the metadata of the data is recorded in the complete encrypted data in a serialized manner. During the encryption and decryption process, strict identity verification is performed based on the serialized information to ensure that the encrypted data can only be decrypted by authorized business services. In addition, the encryption and decryption logic is implemented in an encryption and decryption plug-in, and the encryption and decryption plug-in is deployed in the same host as the business service. In this way, code exposure is avoided, the security of the encryption and decryption logic is improved, remote calls are avoided, and performance is improved. Overall, while taking into account both security and high-efficiency performance, it provides reliable protection for data protection in multiple business scenarios. Example Process
[0108] Figure 5 1 is a flowchart of an example process 500 for data encryption according to some embodiments of the present disclosure. The process 500 may be implemented at the first host 205. Figure 2 The process 500 is described below.
[0109] In block 510 , the first host machine 205 encrypts the initial data to be encrypted from the first service 210 using the first data encryption key of the first service 210 .
[0110] In block 520 , the first host machine 205 determines first serialized encrypted data by serializing the first encrypted data and meta information related to the first encrypted data. The meta information includes at least an identifier of the first service 210 .
[0111] At block 530 , the first host machine 205 provides the first serialized encrypted data to the first service 210 .
[0112] In some embodiments, the meta information also includes at least one of the following: the type of encryption algorithm used to encrypt the initial data, the identifier of the first key encryption key, the identifier is obtained by mapping via a predetermined conversion algorithm, and the first data encryption key encrypted using the first key encryption key.
[0113] In some embodiments, encrypting the initial data to be encrypted from the first service 210 includes: determining the encoded data by encoding the initial data to be encrypted, the encoded data including the initial data and an identifier, the identifier being used to indicate the type of the initial data; and encrypting the encoded data using a first data encryption key to obtain first encrypted data.
[0114] In some embodiments, the first data encryption key is obtained by: sending a key acquisition request for the first data encryption key to the encryption service 230, the key acquisition request including the identity of the first service 210; and receiving a response to the key acquisition request from the encryption service 230, the response including at least the first data encryption key, the first data encryption key being determined by the encryption service 230 based on the first key encryption key.
[0115] In some embodiments, process 500 also includes: in response to determining that the second serialized encrypted data is to be decrypted, performing authentication on the first service 210 based on an identity included in the second serialized encrypted data; and if it is determined that the first service 210 passes the authentication, decrypting the second serialized encrypted data.
[0116] In some embodiments, performing identity authentication on the first service 210 based on the identity included in the second serialized encrypted data includes: determining the second encrypted data corresponding to the second serialized encrypted data and the metadata of the second encrypted data by deserializing the second serialized encrypted data; and determining that the first service 210 has passed the identity authentication in response to determining that the identity included in the metadata of the second encrypted data is the identity of the first service 210 or other identity authorized by the first service 210.
[0117] In some embodiments, decrypting the second serialized encrypted data includes: determining a second data encryption key based on an identity included in the second serialized encrypted data; decrypting the second encrypted data corresponding to the second serialized encrypted data using the second data encryption key to obtain decrypted data; and determining initial data corresponding to the second encrypted data by reverse encoding the decrypted data.
[0118] In some embodiments, the second data encryption key is obtained by: sending a key acquisition request for the second data encryption key to the encryption service 230, the key acquisition request including the identity of the first service 210; and receiving a response to the key acquisition request from the encryption service 230, the response including at least the second data encryption key, the second data encryption key being determined by the encryption service 230 based on the second key encryption key.
[0119] In some embodiments, process 500 is performed using plugin 220 deployed in the same host as first service 210 .
[0120] Figure 6 600 for data encryption according to some embodiments of the present disclosure. Process 500 may be implemented at encryption service 230. Figure 2 600 is described below.
[0121] In block 610 , in response to receiving a key acquisition request from the first service 210 , the encryption service 230 performs identity authentication on the first service 210 based on the identity of the first service 210 included in the key acquisition request.
[0122] In block 620 , if the encryption service 230 determines that the first service 210 has passed the authentication, the encryption service 230 obtains the data encryption key for the first service 210 .
[0123] At block 630 , the encryption service 230 sends the data encryption key to the first service 210 .
[0124] In some embodiments, the key acquisition request includes an identity encrypted using a public key of the encryption service 230. The identity of the encryption service 210 is determined by: obtaining the identity encrypted using the public key of the encryption service 230 from the key acquisition request; and decrypting the encrypted identity using a private key corresponding to the public key to determine the identity of the encryption service 210.
[0125] In some embodiments, obtaining a data encryption key for the encryption service 210 includes: determining an encrypted first data encryption key and an identifier of a first key encryption key corresponding to the identity of the encryption service 210; obtaining a first key encryption key corresponding to the identifier of the first key encryption key from a key management service; and determining the data encryption key by decrypting the encrypted data encryption key using the first key encryption key.
[0126] In some embodiments, process 600 also includes: in response to determining that the first key encryption key used for the encryption service 210 has reached a predetermined update cycle or receiving an update request for the first key encryption key, updating the first key encryption key based on communication with the key management service; using the first key encryption key before the update, decrypting the encrypted first data encryption key corresponding to the encryption service 210; using the updated first key encryption key to encrypt the first data encryption key; and storing the first data encryption key encrypted by the updated first key encryption key and the identifier of the updated first key encryption key.
[0127] In some embodiments, process 600 also includes: in response to determining that the first data encryption key used for the encryption service 210 has reached a predetermined update cycle or receiving an update request for the first data encryption key, updating the first data encryption key; encrypting the updated first data encryption key using the first key encryption key corresponding to the encryption service 210; and storing the encrypted updated first data encryption key. Example devices and equipment
[0128] Figure 7 A schematic structural block diagram of a data encryption device 700 according to some embodiments of the present disclosure is shown. The device 700 may be implemented as or included in the first host machine 205. Each module / component in the device 700 may be implemented by hardware, software, firmware, or any combination thereof.
[0129] As shown in the figure, the device 700 includes an encryption module 710, which is configured to encrypt the initial data to be encrypted from the first service using the first data encryption key of the first service to obtain first encrypted data; a serialization module 720, which is configured to determine the first serialized encrypted data by serializing the first encrypted data and metadata related to the first encrypted data, wherein the metadata includes at least an identity identifier of the first service; and a providing module 730, which is configured to provide the first serialized encrypted data to the first service.
[0130] In some embodiments, the meta information also includes at least one of the following: the type of encryption algorithm used to encrypt the initial data, the identifier of the first key encryption key, the identifier is obtained by mapping via a predetermined conversion algorithm, and the first data encryption key encrypted using the first key encryption key.
[0131] In some embodiments, the encryption module 710 is further configured to determine the encoded data by encoding the initial data to be encrypted, the encoded data including the initial data and an identifier, the identifier being used to indicate the type of the initial data; and encrypt the encoded data using a first data encryption key to obtain first encrypted data.
[0132] In some embodiments, the first data encryption key is obtained by: sending a key acquisition request for the first data encryption key to an encryption service, the key acquisition request including an identity of the first service; and receiving a response to the key acquisition request from the encryption service, the response including at least the first data encryption key, the first data encryption key being determined by the encryption service based on the first key encryption key.
[0133] In some embodiments, the device 700 also includes a decryption module, which is configured to, in response to determining that the second serialized encrypted data is to be decrypted, perform authentication on the first service based on the identity included in the second serialized encrypted data; and if it is determined that the first service passes the authentication, decrypt the second serialized encrypted data.
[0134] In some embodiments, the decryption module is further configured to determine the second encrypted data corresponding to the second serialized encrypted data and the metadata of the second encrypted data by deserializing the second serialized encrypted data; and determine that the first service has passed the authentication in response to determining that the identity included in the metadata of the second encrypted data is the identity of the first service or other identity authorized by the first service.
[0135] In some embodiments, the decryption module is further configured to determine a second data encryption key based on the identity included in the second serialized encrypted data; use the second data encryption key to decrypt the second encrypted data corresponding to the second serialized encrypted data to obtain decrypted data; and determine the initial data corresponding to the second encrypted data by reverse encoding the decrypted data.
[0136] In some embodiments, the second data encryption key is obtained by: sending a key acquisition request for the second data encryption key to an encryption service, the key acquisition request including the identity of the first service; and receiving a response to the key acquisition request from the encryption service, the response including at least the second data encryption key, the second data encryption key being determined by the encryption service based on the second key encryption key.
[0137] In some embodiments, the apparatus 700 includes a plug-in in which the first service is deployed in the same host.
[0138] Figure 8 A schematic structural block diagram of an apparatus 800 for data encryption according to some embodiments of the present disclosure is shown. The apparatus 800 may be implemented as or included in the encryption service 230. Each module / component in the apparatus 800 may be implemented by hardware, software, firmware, or any combination thereof.
[0139] like Figure 8 As shown, the device 800 includes an identity authentication module 810, which is configured to, in response to receiving a key acquisition request from the first service, perform identity authentication on the first service based on the identity of the first service included in the key acquisition request; an acquisition module 820, which is configured to obtain a data encryption key for the first service if it is determined that the first service passes the authentication; and a sending module 830, which is configured to send the data encryption key to the first service.
[0140] In some embodiments, the apparatus 800 further includes an updating module configured to determine that a first triggering event is detected in response to determining a press event for an application based on the detected touch operation.
[0141] In some embodiments, the key acquisition request includes an identity encrypted using a public key of the encryption service. The identity of the encryption service 210 is determined by: obtaining the identity encrypted using the public key of the encryption service from the key acquisition request; and decrypting the encrypted identity using a private key corresponding to the public key to determine the identity of the encryption service 210.
[0142] In some embodiments, the acquisition module 820 is further configured to determine the identifier of the encrypted first data encryption key and the first key encryption key corresponding to the identity identifier of the encryption service 210; obtain the first key encryption key corresponding to the identifier of the first key encryption key from the key management service; and determine the data encryption key by decrypting the encrypted data encryption key using the first key encryption key.
[0143] In some embodiments, the device 800 also includes an update module, which is configured to update the first key encryption key based on communication with the key management service in response to determining that the first key encryption key used for the encryption service 210 has reached a predetermined update cycle or receiving an update request for the first key encryption key; decrypt the encrypted first data encryption key corresponding to the encryption service 210 using the first key encryption key before the update; encrypt the first data encryption key using the updated first key encryption key; and store the first data encryption key encrypted by the updated first key encryption key and the identification of the updated first key encryption key.
[0144] In some embodiments, the update module is also configured to update the first data encryption key in response to determining that the first data encryption key used for the encryption service 210 has reached a predetermined update cycle or receiving an update request for the first data encryption key; encrypt the updated first data encryption key using the first key encryption key corresponding to the encryption service 210; and store the encrypted updated first data encryption key.
[0145] Fig. 9 900 is a block diagram of an electronic device in which one or more embodiments of the present disclosure may be implemented. It should be understood that Fig. 9 The electronic device 900 shown is merely exemplary and should not constitute any limitation on the functionality and scope of the embodiments described herein. Fig. 9 The electronic device 900 shown can be used to implement Figure 1 terminal device 110.
[0146] like Fig. 9 As shown, the electronic device 900 is in the form of a general electronic device. The components of the electronic device 900 may include, but are not limited to, one or more processors or processing units 910, a memory 920, a storage device 930, one or more communication units 940, one or more input devices 950, and one or more output devices 960. The processing unit 910 may be an actual or virtual processor and is capable of performing various processes according to a program stored in the memory 920. In a multi-processor system, multiple processing units execute computer executable instructions in parallel to improve the parallel processing capability of the electronic device 900.
[0147] The electronic device 900 typically includes a plurality of computer storage media. Such media may be any accessible media that is accessible to the electronic device 900, including but not limited to volatile and non-volatile media, removable and non-removable media. The memory 920 may be a volatile memory (e.g., a register, a cache, a random access memory (RAM)), a non-volatile memory (e.g., a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. The storage device 930 may be a removable or non-removable medium, and may include a machine-readable medium, such as a flash drive, a disk, or any other medium, which may be capable of being used to store information and / or data (e.g., training data for training) and may be accessed within the electronic device 900.
[0148] The electronic device 900 may further include additional removable / non-removable, volatile / non-volatile storage media. Fig. 9 As shown in , a disk drive for reading or writing from a removable, non-volatile disk (e.g., a "floppy disk") and an optical drive for reading or writing from a removable, non-volatile optical disk may be provided. In these cases, each drive may be connected to the bus (not shown) by one or more data media interfaces. Memory 920 may include a computer program product 925 having one or more program modules that are configured to perform various methods or actions of various embodiments of the present disclosure.
[0149] The communication unit 940 implements communication with other electronic devices through a communication medium. Additionally, the functions of the components of the electronic device 900 can be implemented with a single computing cluster or multiple computing machines that can communicate through a communication connection. Therefore, the electronic device 900 can operate in a networked environment using a logical connection with one or more other servers, a network personal computer (PC), or another network node.
[0150] The input device 950 may be one or more input devices, such as a mouse, a keyboard, a tracking ball, etc. The output device 960 may be one or more output devices, such as a display, a speaker, a printer, etc. The electronic device 900 may also communicate with one or more external devices (not shown) through the communication unit 940 as needed, such as a storage device, a display device, etc., communicate with one or more devices that allow a user to interact with the electronic device 900, or communicate with any device that allows the electronic device 900 to communicate with one or more other electronic devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface (not shown).
[0151] According to an exemplary implementation of the present disclosure, a computer-readable storage medium is provided, on which computer-executable instructions are stored, wherein the computer-executable instructions are executed by a processor to implement the method described above. According to an exemplary implementation of the present disclosure, a computer program product is also provided, which is tangibly stored on a non-transitory computer-readable medium and includes computer-executable instructions, and the computer-executable instructions are executed by a processor to implement the method described above.
[0152] Various aspects of the present disclosure are described herein with reference to the flowcharts and / or block diagrams of the methods, devices, equipment, and computer program products implemented according to the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer-readable program instructions.
[0153] These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processing unit of the computer or other programmable data processing device, a device that implements the functions / actions specified in one or more boxes in the flowchart and / or block diagram is generated. These computer-readable program instructions can also be stored in a computer-readable storage medium, and these instructions cause the computer, programmable data processing device, and / or other equipment to work in a specific manner, so that the computer-readable medium storing the instructions includes a manufactured product, which includes instructions for implementing various aspects of the functions / actions specified in one or more boxes in the flowchart and / or block diagram.
[0154] Computer-readable program instructions can be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operational steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, so that the instructions executed on the computer, other programmable data processing apparatus, or other device implement the functions / actions specified in one or more boxes in the flowchart and / or block diagram.
[0155] The flow chart and block diagram in the accompanying drawings show the possible architecture, function and operation of the system, method and computer program product according to multiple implementations of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a part of a module, program segment or instruction, and a part of a module, program segment or instruction includes one or more executable instructions for realizing the logical function of the specification. In some implementations as replacements, the function marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two continuous square boxes can actually be executed substantially in parallel, and they can sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be realized by a special hardware-based system that performs the function or action of the specification, or can be realized by a combination of special hardware and computer instructions.
[0156] The above descriptions of various implementations of the present disclosure are exemplary, non-exhaustive, and not limited to the disclosed implementations. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described implementations. The selection of terms used herein is intended to best explain the principles of the implementations, practical applications, or improvements to the technology in the market, or to enable other persons of ordinary skill in the art to understand the various implementations disclosed herein.
Claims
1. A data encryption method, comprising: Encrypting the initial data to be encrypted from the first service using the first data encryption key of the first service to obtain first encrypted data; Determine first serialized encrypted data by serializing the first encrypted data and meta information related to the first encrypted data, wherein the meta information includes at least an identity identifier of the first service; as well as The first serialized encrypted data is provided to the first service.
2. The method according to claim 1, wherein the meta information further comprises at least one of the following: the type of encryption algorithm used to encrypt the initial data, an identifier of the first key encryption key, the identifier being obtained by mapping via a predetermined conversion algorithm, or The first data encryption key is encrypted using the first key encryption key.
3. The method of claim 1 , wherein encrypting the initial data to be encrypted from the first service comprises: Determining encoded data by encoding the initial data to be encrypted, wherein the encoded data includes the initial data and an identifier, and the identifier is used to indicate a type of the initial data; The encoded data is encrypted using the first data encryption key to obtain the first encrypted data.
4. The method according to claim 1, wherein the first data encryption key is obtained by: Sending a key acquisition request for the first data encryption key to an encryption service, the key acquisition request including an identity of the first service; and A response to the key acquisition request is received from the encryption service, the response including at least the first data encryption key, the first data encryption key being determined by the encryption service based on a first key encryption key.
5. The method according to claim 1, further comprising: In response to determining to decrypt the second serialized encrypted data, performing identity authentication on the first service based on an identity included in the second serialized encrypted data; as well as If it is determined that the first service passes the identity authentication, the second serialized encrypted data is decrypted.
6. The method according to claim 5, wherein performing identity authentication on the first service based on the identity included in the second serialized encrypted data comprises: Determine, by deserializing the second serialized encrypted data, second encrypted data corresponding to the second serialized encrypted data and meta information of the second encrypted data; as well as In response to determining that the identity included in the meta information of the second encrypted data is the identity of the first service or another identity authorized by the first service, it is determined that the first service passes the identity authentication.
7. The method of claim 5, wherein decrypting the second serialized encrypted data comprises: Determining a second data encryption key based on the identity included in the second serialized encrypted data; decrypting second encrypted data corresponding to the second serialized encrypted data using the second data encryption key to obtain decrypted data; as well as Initial data corresponding to the second encrypted data is determined by inversely encoding the decrypted data.
8. The method according to claim 7, wherein the second data encryption key is obtained by: Sending a key acquisition request for the second data encryption key to an encryption service, wherein the key acquisition request includes an identity identifier of the first service; and A response to the key acquisition request is received from the encryption service, the response including at least the second data encryption key, the second data encryption key being determined by the encryption service based on a second key encryption key.
9. The method of claim 1, wherein the method is performed using a plug-in deployed in the same host as the first service.
10. A method for data encryption, comprising: In response to receiving a key acquisition request from a first service, performing identity authentication on the first service based on an identity identifier of the first service included in the key acquisition request; If it is determined that the first service passes the identity authentication, obtaining a data encryption key for the first service; as well as The data encryption key is sent to the first service.
11. The method according to claim 10, wherein the key acquisition request comprises an identity encrypted using a public key of an encryption service, wherein the identity of the first service is determined by: Obtaining, from the key acquisition request, an identity encrypted using a public key of an encryption service; and The encrypted identity is decrypted by using a private key corresponding to the public key to determine the identity of the first service.
12. The method according to claim 10, wherein obtaining a data encryption key for the first service comprises: determining an identifier of an encrypted first data encryption key and a first key encryption key corresponding to an identifier of the first service; obtaining, from a key management service, a first key encryption key corresponding to the identifier of the first key encryption key; as well as The data encryption key is determined by decrypting the encrypted data encryption key using the first key encryption key.
13. The method according to claim 10, further comprising: in response to determining that a first key encryption key for the first service reaches a predetermined update period or receiving an update request for the first key encryption key, updating the first key encryption key based on communication with a key management service; decrypting the encrypted first data encryption key corresponding to the first service by using the first key encryption key before updating; encrypting the first data encryption key using the updated first key encryption key; as well as The first data encryption key encrypted by the updated first key encryption key and an identification of the updated first key encryption key are stored.
14. The method according to claim 10, further comprising: In response to determining that a first data encryption key for the first service reaches a predetermined update period or receiving an update request for the first data encryption key, updating the first data encryption key; encrypting the updated first data encryption key using a first key encryption key corresponding to the first service; as well as The updated first data encryption key is stored encrypted.
15. A data encryption device, comprising: an encryption module, configured to encrypt the initial data to be encrypted from the first service using a first data encryption key of the first service to obtain first encrypted data; a serialization module configured to determine first serialized encrypted data by serializing the first encrypted data and meta information related to the first encrypted data, wherein the meta information includes at least an identity identifier of the first service; as well as A providing module is configured to provide the first serialized encrypted data to the first service.
16. A device for data encryption, comprising: an identity authentication module, configured to, in response to receiving a key acquisition request from a first service, perform identity authentication on the first service based on an identity identifier of the first service included in the key acquisition request; an acquisition module, configured to acquire a data encryption key for the first service if it is determined that the first service passes the identity authentication; as well as A sending module is configured to send the data encryption key to the first service.
17. An electronic device comprising: at least one processor; as well as At least one memory, the at least one memory being coupled to the at least one processor and storing instructions for execution by the at least one processor, the instructions, when executed by the at least one processor, causing the electronic device to perform a method according to any one of claims 1 to 9 or claims 10 to 14.
18. A computer-readable storage medium having computer-executable instructions stored thereon, wherein the computer-executable instructions can be executed by a processor to implement the method according to any one of claims 1 to 9 or claims 10 to 14.
19. A computer executable instruction product tangibly stored in a computer storage medium and comprising computer executable instructions which, when executed by a device, cause the device to perform the method according to any one of claims 1 to 9 or claims 10 to 14.