Information processing method and device, storage medium and computer program product
By generating and storing the key ciphertext of the target key in the message middleware, the target message is encrypted, which solves the problem of low security in the message middleware transmission and ensures the security and integrity of the message in the cloud environment.
Patent Information
- Application Number
- CN202510452175.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2045-04-10
AI Technical Summary
In the prior art, the problem of low security when transmitting messages through message middleware is relatively low, especially in a cloud environment, how to ensure the security of task data has not been effectively solved.
The target message is received through the message middleware and the key ciphertext of the target key is generated. The target message is encrypted using the target master key, the message ciphertext is generated, and the message ciphertext and key ciphertext are stored in the storage medium to ensure the security of the message during transmission and storage.
It realizes end-to-end security of messages in transmission and storage procedures, prevents unauthorized entities from accessing, and enhances data security.
Smart Images

Figure CN119996081B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and more specifically, to an information processing method and device, a storage medium, and a computer program product. Background Art
[0002] With the rapid development of cloud computing technology, more and more traditional internet data centers are migrating to the cloud, both public and private. For industries like finance, which place high demands on data security and compliance, private cloud deployment is often chosen due to mission-critical constraints. In this scenario, IaaS (Infrastructure as a Service) is typically privately deployed in local data centers, while PaaS (Platform as a Service) leverages products and services provided by cloud vendors to leverage the lower costs and reduced technical complexity offered by serverless computing.
[0003] However, during this migration process, enterprises face numerous challenges, particularly ensuring the security and stability of mission systems. Current mission systems are often highly complex, consisting of multiple interconnected subsystems. To improve system flexibility and maintainability, these subsystems often need to be decoupled. Message-based middleware plays a crucial role in achieving system decoupling. It not only facilitates asynchronous communication between different subsystems but also handles data transmission in many mission-critical processes, such as order processing and payment confirmation. Given the extremely stringent data security requirements of industries like finance, government, and enterprises, ensuring the security of mission data in cloud environments has become a pressing issue.
[0004] With respect to the problem of relatively low security when transmitting messages through message middleware in the above-mentioned related technologies, no effective solution has been proposed so far. Summary of the Invention
[0005] The embodiments of the present application provide an information processing method and apparatus, a storage medium, and a computer program product to at least solve the technical problem of low security when transmitting messages through message middleware in the related art.
[0006] According to one aspect of an embodiment of the present application, an information processing method is provided, including: receiving a target message uploaded by a message producer through a message middleware; obtaining a target key and a target key ciphertext corresponding to the target key through the message middleware, wherein the target key is generated by a target master key, and the target master key has a corresponding relationship with the message producer; encrypting the target message based on the target key through the message middleware to generate a message ciphertext, and storing the message ciphertext and the target key ciphertext to a storage medium in the message middleware, wherein the message ciphertext and the target key ciphertext are sent to a message consumer through the message middleware, so that the message consumer obtains the target message.
[0007] Furthermore, obtaining the target key and the target key ciphertext corresponding to the target key through the message middleware includes: obtaining the target master key identifier corresponding to the message producer; based on the target master key identifier, calling the target master key in the key management service to generate the key and obtain the target key; encrypting the target key through the target master key to obtain the target key ciphertext.
[0008] Furthermore, calling the target master key in the key management service to generate a key, and obtaining the target key includes: determining the key type of the target master key; determining the key generation method based on the key type; and generating a key based on the key generation method to obtain the target key.
[0009] Furthermore, before receiving the target message uploaded by the message producer through the message middleware, the method also includes: receiving key parameter information selected by the message producer through the key management service, wherein the key parameter information includes at least: key type and key source; based on the key parameter information, determining the target master key and the target master key identifier corresponding to the target master key in the key management service; and returning the target master key identifier to the message producer.
[0010] Furthermore, after storing the message ciphertext and the target key ciphertext in the storage medium in the message middleware, the method also includes: receiving a data acquisition request from the message consumer through the message middleware; acquiring the message ciphertext and the target key ciphertext based on the data acquisition request; and acquiring the target message based on the message ciphertext and the target key ciphertext.
[0011] Furthermore, based on the message ciphertext and the target key ciphertext, obtaining the target message includes: decrypting the target key ciphertext by calling the target master key in the key management service through the message middleware to obtain the target key; decrypting the message ciphertext through the target key to obtain the target message.
[0012] Furthermore, after the target message is encrypted based on the target key by the message middleware, the method further includes: deleting the target key in the message middleware.
[0013] According to another aspect of an embodiment of the present application, an information processing device is also provided, including: a first receiving unit, used to receive a target message uploaded by a message producer through a message middleware; a first acquisition unit, used to obtain a target key and a target key ciphertext corresponding to the target key through the message middleware, wherein the target key is generated by a target master key, and the target master key has a corresponding relationship with the message producer; an encryption unit, used to encrypt the target message based on the target key through the message middleware, generate a message ciphertext, and store the message ciphertext and the target key ciphertext to a storage medium in the message middleware, wherein the message ciphertext and the target key ciphertext are sent to a message consumer through the message middleware, so that the message consumer obtains the target message.
[0014] Furthermore, the first acquisition unit includes: an acquisition module, used to obtain the target master key identifier corresponding to the message producer; a first calling module, used to call the target master key in the key management service to generate a key based on the target master key identifier to obtain the target key; and a processing module, used to encrypt the target key through the target master key to obtain the target key ciphertext.
[0015] Furthermore, the first calling module includes: a first determination submodule, used to determine the key type of the target master key; a second determination submodule, used to determine the key generation method based on the key type; and a generation submodule, used to generate a key based on the key generation method to obtain the target key.
[0016] Furthermore, the device also includes: a second receiving unit, used to receive key parameter information selected by the message producer through the key management service before receiving the target message uploaded by the message producer through the message middleware, wherein the key parameter information includes at least: key type and key source; a generation unit, used to determine the target master key and the target master key identifier corresponding to the target master key in the key management service based on the key parameter information; and a return unit, used to return the target master key identifier to the message producer.
[0017] Furthermore, the device also includes: a third receiving unit, used to receive the data acquisition request of the message consumer through the message middleware after storing the message ciphertext and the target key ciphertext in the storage medium in the message middleware; a second acquisition unit, used to acquire the message ciphertext and the target key ciphertext based on the data acquisition request; and a third acquisition unit, used to acquire the target message based on the message ciphertext and the target key ciphertext.
[0018] Furthermore, the third acquisition unit includes: a second calling module, used to decrypt the target key ciphertext by calling the target master key in the key management service through the message middleware to obtain the target key; a decryption module, used to decrypt the message ciphertext through the target key to obtain the target message.
[0019] Furthermore, the apparatus further includes: a deleting unit, configured to delete the target key in the message middleware after the target message is encrypted based on the target key by the message middleware.
[0020] According to another aspect of an embodiment of the present invention, an electronic device is provided, including: a memory storing an executable program; and a processor for running the program, wherein any one of the above-mentioned information processing methods is executed when the program is running.
[0021] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is provided, which stores a program, wherein when the program is running, the device where the storage medium is located is controlled to execute any one of the above-mentioned information processing methods.
[0022] According to another aspect of an embodiment of the present invention, a computer program product is provided, including a computer program or instructions, which implements any one of the above information processing methods when executed by a processor.
[0023] In an embodiment of the present application, the following steps are adopted: receiving a target message uploaded by a message producer through a message middleware; obtaining a target key and a target key ciphertext corresponding to the target key through the message middleware, wherein the target key is generated by a target master key, and the target master key has a corresponding relationship with the message producer; encrypting the target message based on the target key through the message middleware to generate a message ciphertext, and storing the message ciphertext and the target key ciphertext to a storage medium in the message middleware, wherein the message ciphertext and the target key ciphertext are sent to a message consumer through the message middleware so that the message consumer obtains the target message, thereby solving the technical problem of relatively low security when transmitting messages through the message middleware in the related art.
[0024] In this solution, when a message is transmitted through a message middleware, the message middleware obtains the target key and the target key ciphertext corresponding to the target key. The message middleware encrypts the target message using the target key and stores the message ciphertext and the target key ciphertext on a storage medium within the message middleware, ensuring that the message content cannot be accessed by unauthorized entities during transmission and storage. Storing the target key ciphertext on a storage medium further enhances security. Even if the storage medium is accessed, unauthorized users cannot directly decrypt the message due to the presence of the target key ciphertext. The target message remains encrypted throughout the message's journey from producer to consumer, ensuring end-to-end security and thereby achieving the technical effect of improving data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0026] Figure 1 This is a hardware structure block diagram of a computer terminal provided according to the first embodiment of the present application;
[0027] Figure 2 is a flowchart of the information processing method provided in Example 1 of the present application;
[0028] Figure 3 is a schematic diagram of an information processing method provided according to Example 1 of the present application;
[0029] Figure 4 is a schematic diagram of an information processing device provided according to Embodiment 2 of the present application;
[0030] Figure 5 This is a structural block diagram of an electronic device provided according to Example 3 of the present application. DETAILED DESCRIPTION
[0031] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0033] Example 1
[0034] According to an embodiment of the present application, an information processing method is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0035] The method embodiment provided in the first embodiment of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 The hardware structure block diagram of a computer terminal (or mobile device) for implementing the information processing method is shown in FIG. Figure 1 As shown, the computer terminal (or mobile device) 10 may include a processor set 102 (the processor set 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA, and the processor set 102 may include a processor set, Figure 1 102a, 102b, ..., 102n are used to illustrate), a memory 104 for storing data, and a transmission module 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. Those skilled in the art will understand that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.
[0036] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry." This data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be fully or partially integrated into any of the other components of the computer terminal 10 (or mobile device). As discussed in the embodiments of this application, this data processing circuitry functions as a processor control (e.g., selecting a variable resistor terminal path connected to an interface).
[0037] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the information processing method in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implementing the above-mentioned information processing method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0038] Transmission device 106 is configured to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of computer terminal 10. In one embodiment, transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, transmission device 106 may be a radio frequency (RF) module configured to communicate with the Internet wirelessly.
[0039] The display may be, for example, a touch screen liquid crystal display that enables a user to interact with a user interface of the computer terminal 10 (or mobile device).
[0040] Under the above operating environment, this application provides Figure 2 The information processing method shown. Figure 2 : is a flowchart of an information processing method according to Embodiment 1 of the present application. The method includes:
[0041] Step S201: Receive the target message uploaded by the message producer through the message middleware.
[0042] Optionally, message middleware is a software layer used for messaging in distributed systems, acting as a bridge between message producers and consumers. It receives messages from producers and delivers them to appropriate consumers. It receives targeted messages from message producers through its exposed APIs or communication protocols. These messages can be a variety of information types, including task data, user requests, and system events.
[0043] It should be noted that message producers can transmit the target message to the message middleware using the Transport Layer Security (TLS) protocol. TLS provides network communication security, including data encryption, authentication, and integrity protection. In messaging, TLS is often used to encrypt message transmission between producers and middleware or consumers, preventing man-in-the-middle attacks and data leaks.
[0044] Step S202: Obtain the target key and the target key ciphertext corresponding to the target key through the message middleware, wherein the target key is generated by the target master key, and the target master key has a corresponding relationship with the message producer.
[0045] Optionally, after receiving the target message, the message middleware first needs to obtain the key required to encrypt the message, namely the target key. The use of the target key ensures the security of the message during storage and transmission, preventing unauthorized access and data leakage. At the same time, the message middleware also needs to obtain the target key ciphertext corresponding to the target key. It should be noted that the target key is generated from the target master key, and the target master key has a direct correspondence with the message producer. This means that the message producer can have an independent and customized master key, enhancing security and data isolation. For example, a key derivation function is used to generate the target key based on the target master key.
[0046] In an optional embodiment, the target master key can be stored in a key management service. When a message producer uploads a message to the message middleware, the message middleware obtains a target key and the key ciphertext encrypted by the key from the key management service. It should be noted that the target key obtained by the message middleware from the key management service can be a target key generated by the key management service for the current request of the message producer.
[0047] In step S203, the target message is encrypted based on the target key through the message middleware to generate a message ciphertext, and the message ciphertext and the target key ciphertext are stored in the storage medium in the message middleware, wherein the message ciphertext and the target key ciphertext are sent to the message consumer through the message middleware so that the message consumer obtains the target message.
[0048] Optionally, after obtaining the target key and the target key ciphertext corresponding to the target key, the message middleware encrypts the target message based on the obtained target key. In an optional embodiment, encryption of the target message can be achieved using a symmetric encryption algorithm. After encryption is complete, the message middleware stores the message ciphertext and the ciphertext version of the target key used for encryption (i.e., the target key ciphertext) on a storage medium it manages. The storage medium can be a local disk, a remote storage service, or cloud storage. The original message content and the target key are both stored in encrypted form, making it difficult to directly decrypt and exploit the data even if the storage medium is maliciously accessed.
[0049] When a message consumer needs to consume a target message from the message middleware, it can obtain the target message through the message ciphertext and target key ciphertext in the message middleware.
[0050] In summary, when a message is transmitted through the message middleware, the target key and the target key ciphertext corresponding to the target key are obtained through the message middleware. The message middleware encrypts the target message using the target key and stores the message ciphertext and the target key ciphertext on the storage medium within the message middleware, ensuring that the message content cannot be accessed by unauthorized entities during transmission and storage. Storing the target key ciphertext on the storage medium further enhances security protection. Even if the storage medium is accessed, unauthorized users cannot directly decrypt the message due to the presence of the target key ciphertext. The target message remains encrypted throughout the message's journey from producer to consumer, ensuring end-to-end security and thereby achieving the technical effect of improving data security.
[0051] How to obtain the target key and the target key ciphertext corresponding to the target key is crucial. Therefore, in the information processing method provided in Example 1 of the present application, obtaining the target key and the target key ciphertext corresponding to the target key through the message middleware includes: obtaining the target master key identifier corresponding to the message producer; based on the target master key identifier, calling the target master key in the key management service to generate the key to obtain the target key; encrypting the target key through the target master key to obtain the target key ciphertext.
[0052] Optionally, when a message producer prepares to send a message, it first needs to determine the target key to be used to encrypt the message. The target key is derived from the target master key, a user-managed key that has a direct relationship with the message producer. Therefore, the message producer needs to provide the target master key identifier, which it sends to a key management service (e.g., KMS). A key management service is a service specifically designed to manage, store, and control encryption keys.
[0053] After receiving the target master key identifier, the key management service uses the target master key corresponding to the target master key identifier to generate a new target key. The target key is used to encrypt data. The target master key is then used to encrypt the target key to produce the target key ciphertext. This target key ciphertext ensures that even if the storage medium is accessed, the target key, and therefore the message data, cannot be decrypted without the corresponding master key. It should be noted that the target master key can be encrypted using an asymmetric encryption algorithm to produce the target key ciphertext.
[0054] By using the target master key identifier corresponding to the message producer, producers can independently manage their data encryption keys. This mechanism reduces the risk of data leakage because different producers will use different keys to encrypt their messages. Even if the key of one producer is leaked, the messages of other producers are still protected.
[0055] In order to improve the security of the key, in the information processing method provided in Example 1 of the present application, the target master key is called in the key management service to generate the key, and obtaining the target key includes: determining the key type of the target master key; based on the key type, determining the key generation method; generating the key based on the key generation method to obtain the target key.
[0056] Optionally, the target master key's key type needs to be determined during key generation. The target master key can be a different type of encryption key, such as a symmetric key or part of an asymmetric key pair. Selecting the appropriate key type is crucial for ensuring the security and performance of encrypted data. For example, symmetric keys are often used to quickly encrypt large amounts of data, while asymmetric keys are used for authentication and key exchange. In an optional embodiment, the target master key's key type can be either AES_256 or SM4.
[0057] After determining the target master key type, the corresponding key generation method is determined based on the key type. For example, if the key type is a symmetric key, the target master key can be combined with different parameters through a hash function or pseudo-random function to calculate the corresponding target key. For another example, if the key type is an asymmetric key, the target key can be generated through a key encapsulation mechanism.
[0058] The key generation method improves the accuracy of generating the target key and further improves the security of the information.
[0059] How to generate the master key is crucial. Therefore, in the information processing method provided in Example 1 of the present application, before receiving the target message uploaded by the message producer through the message middleware, the method also includes: receiving the key parameter information selected by the message producer through the key management service, wherein the key parameter information includes at least: key type and key source; based on the key parameter information, determining the target master key and the target master key identifier corresponding to the target master key in the key management service; and returning the target master key identifier to the message producer.
[0060] Optionally, the following steps can be used to obtain the target master key corresponding to the message producer in the key management service: The user (i.e., the message producer mentioned above) sets key parameter information in the key management service. It should be noted that key parameter information may include the key type and key source. For example, select a symmetric key type (such as AES_256 or SM4) and a key source (such as KMS or EXTERNAL). KMS indicates that the user chooses to have the key management service generate the target master key. EXTERNAL indicates that the user uploads the master key to the key management service and determines it as the target master key.
[0061] After obtaining the target master key, the key management service generates a target master key identifier (Key Id) corresponding to the target master key and returns the target master key identifier to the user. The user can then use the Key Id to reference and manage the master key without directly accessing or storing the master key itself. For example, the key management service can use a hash algorithm to calculate the target master key to obtain a string and determine this string as the target master key identifier corresponding to the target master key.
[0062] It should be noted that in order to improve the security of the master key, the master key in the key management service can be updated, rotated, and revoked.
[0063] Receiving key parameter information through the key management service and generating the target master key and master key identifier based on it not only improves data security, but also simplifies the complexity of key management and improves operational efficiency.
[0064] When a message consumer needs to consume a target message, in the information processing method provided in Example 1 of the present application, after storing the message ciphertext and the target key ciphertext in the storage medium in the message middleware, the method also includes: receiving a data acquisition request from the message consumer through the message middleware; acquiring the message ciphertext and the target key ciphertext based on the data acquisition request; and acquiring the target message based on the message ciphertext and the target key ciphertext.
[0065] Optionally, when a message consumer (such as an application or service) needs to consume a target message, it sends a data retrieval request to the messaging middleware. The request can include message identification information (such as a message ID or timestamp).
[0066] After receiving a data retrieval request, the message middleware searches the storage medium for the corresponding message ciphertext (the encrypted message) and target key ciphertext (the encrypted target key in ciphertext form) based on the information in the request. Finally, the target message is retrieved from the message ciphertext and target key ciphertext. For example, by calling the KMS decryption API and specifying the master key identifier (Key ID), the target key ciphertext is decrypted to obtain the target key in plaintext. Subsequently, the message ciphertext is decrypted using the plaintext target key to obtain the original target message.
[0067] Through the above steps, throughout the entire life cycle of the message, whether it is stored in the storage medium of the message middleware or in network transmission, the message exists in ciphertext form, ensuring the security of data in both static and dynamic states.
[0068] In order to improve the security of the target message, in the information processing method provided in Example 1 of the present application, based on the message ciphertext and the target key ciphertext, obtaining the target message includes: decrypting the target key ciphertext by calling the target master key in the key management service through the message middleware to obtain the target key; decrypting the message ciphertext through the target key to obtain the target message.
[0069] Optionally, when a message consumer receives an encrypted message (message ciphertext) and target key ciphertext from the message middleware, it needs to decrypt the target key used to encrypt the message. To decrypt the ciphertext form of the target key, the message middleware can call the KMS Decrypt interface (the Decrypt interface is a function or service used in an encryption system to decrypt data) and specify the target master key using the previously stored target master key identifier (Key Id). The KMS uses the target master key to decrypt the target key ciphertext and restore the target key in plaintext. Finally, the message consumer can use the obtained target key (the plaintext form of the target key) to decrypt the message ciphertext and obtain the target message.
[0070] This dual-layer encryption mechanism significantly improves data security by using the target master key to decrypt the target key ciphertext, and then using the target key to decrypt the message ciphertext. Even if the message ciphertext and target key ciphertext are intercepted during transmission, without the target master key, the attacker cannot recover the target key and, consequently, cannot decrypt the message content, effectively protecting the confidentiality and privacy of the message.
[0071] In order to further improve the security of the target message, in the information processing method provided in the first embodiment of the present application, after the target message is encrypted based on the target key through the message middleware, the method also includes: deleting the target key in the message middleware.
[0072] Optionally, after the message middleware encrypts the target message using the target key, the target key in the message middleware is immediately deleted to prevent any unauthorized access or potential leakage.
[0073] By ensuring that no plaintext keys are stored in the message middleware, data can be prevented from being decrypted during transmission and storage, effectively improving the security of data during transmission and storage.
[0074] In an optional embodiment, the following may be used: Figure 3 The diagram below implements information processing, specifically: When using the message middleware, a Customer Master Key (CMK) must be created to generate a Data Key (DK). There are two key types: AES_256 is the only option when no encryption machine is available, while SM4 is available when an encryption machine is available. Furthermore, the origin key source must be selected, which can be either KMS or EXTERNAL. Customers can choose this option based on their needs. When creating the CMK, ensure key security to prevent it from being obtained and exploited by malicious attackers.
[0075] When a user needs to transmit a message to the message middleware, the plaintext message is transmitted to the message middleware. The message middleware generates a data key based on the user's master key to encrypt the plaintext message. KMS returns the plaintext DataKey and the ciphertext Blob, which is the encrypted data key. The DataKey is encrypted using the master key corresponding to the KeyId. The message middleware then uses the Key Spec (AES_256) encryption algorithm to encrypt the plaintext message using the plaintext DataKey. The plaintext DataKey in the message middleware's memory rotates over time, and the encrypted key CiphertextBlob and the encrypted message are stored in storage media.
[0076] When a user needs to consume a message, he obtains the data key ciphertext and the message ciphertext, calls the Decrypt interface of KMS, specifies the DK ciphertext to be decrypted, obtains the DK plaintext, and uses the plaintext DK returned by KMS to decrypt the message ciphertext to obtain the required message.
[0077] In the information processing method provided in Example 1 of the present application, a target message uploaded by a message producer is received through a message middleware; a target key and a target key ciphertext corresponding to the target key are obtained through the message middleware, wherein the target key is generated by a target master key, and the target master key has a corresponding relationship with the message producer; the target message is encrypted based on the target key through the message middleware to generate a message ciphertext, and the message ciphertext and the target key ciphertext are stored in a storage medium in the message middleware, wherein the message ciphertext and the target key ciphertext are sent to a message consumer through the message middleware so that the message consumer obtains the target message, thereby solving the technical problem of relatively low security when transmitting messages through the message middleware in the related art.
[0078] In this solution, when a message is transmitted through a message middleware, the message middleware obtains the target key and the target key ciphertext corresponding to the target key. The message middleware encrypts the target message using the target key and stores the message ciphertext and the target key ciphertext on a storage medium within the message middleware, ensuring that the message content cannot be accessed by unauthorized entities during transmission and storage. Storing the target key ciphertext on a storage medium further enhances security. Even if the storage medium is accessed, unauthorized users cannot directly decrypt the message due to the presence of the target key ciphertext. The target message remains encrypted throughout the message's journey from producer to consumer, ensuring end-to-end security and thereby achieving the technical effect of improving data security.
[0079] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0080] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus the necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the existing technology, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of each embodiment of the present application.
[0081] Example 2
[0082] According to an embodiment of the present application, an information processing device for implementing the above information processing method is also provided. Figure 4 As shown, the device includes: a first receiving unit 401, a first acquiring unit 402 and an encryption unit 403.
[0083] The first receiving unit 401 is configured to receive a target message uploaded by a message producer through a message middleware;
[0084] A first acquiring unit 402 is configured to acquire, through the message middleware, a target key and a target key ciphertext corresponding to the target key, wherein the target key is generated by a target master key, and the target master key corresponds to a message producer;
[0085] The encryption unit 403 is used to encrypt the target message based on the target key through the message middleware, generate a message ciphertext, and store the message ciphertext and the target key ciphertext to the storage medium in the message middleware, wherein the message ciphertext and the target key ciphertext are sent to the message consumer through the message middleware so that the message consumer obtains the target message.
[0086] In the information processing device provided in Example 2 of the present application, the target message uploaded by the message producer is received by the first receiving unit 40 through the message middleware; the first acquisition unit 402 obtains the target key and the target key ciphertext corresponding to the target key through the message middleware, wherein the target key is generated by the target master key, and the target master key has a corresponding relationship with the message producer; the encryption unit 403 encrypts the target message based on the target key through the message middleware, generates a message ciphertext, and stores the message ciphertext and the target key ciphertext to the storage medium in the message middleware, wherein the message ciphertext and the target key ciphertext are sent to the message consumer through the message middleware, so that the message consumer obtains the target message, which solves the technical problem of relatively low security when transmitting messages through the message middleware in the related technology.
[0087] In this solution, when a message is transmitted through a message middleware, the message middleware obtains the target key and the target key ciphertext corresponding to the target key. The message middleware encrypts the target message using the target key and stores the message ciphertext and the target key ciphertext on a storage medium within the message middleware, ensuring that the message content cannot be accessed by unauthorized entities during transmission and storage. Storing the target key ciphertext on a storage medium further enhances security. Even if the storage medium is accessed, unauthorized users cannot directly decrypt the message due to the presence of the target key ciphertext. The target message remains encrypted throughout the message's journey from producer to consumer, ensuring end-to-end security and thereby achieving the technical effect of improving data security.
[0088] Optionally, in the information processing device provided in Example 2 of the present application, the first acquisition unit includes: an acquisition module, used to obtain the target master key identifier corresponding to the message producer; a first calling module, used to call the target master key in the key management service to generate a key based on the target master key identifier, and obtain a target key; and a processing module, used to encrypt the target key through the target master key to obtain a target key ciphertext.
[0089] Optionally, in the information processing device provided in Example 2 of the present application, the first calling module includes: a first determination sub-module, used to determine the key type of the target master key; a second determination sub-module, used to determine the key generation method based on the key type; and a generation sub-module, used to generate the key based on the key generation method to obtain the target key.
[0090] Optionally, in the information processing device provided in Example 2 of the present application, the device also includes: a second receiving unit, used to receive key parameter information selected by the message producer through the key management service before receiving the target message uploaded by the message producer through the message middleware, wherein the key parameter information includes at least: key type and key source; a generation unit, used to determine the target master key and the target master key identifier corresponding to the target master key in the key management service based on the key parameter information; and a return unit, used to return the target master key identifier to the message producer.
[0091] Optionally, in the information processing device provided in Example 2 of the present application, the device also includes: a third receiving unit, used to receive a data acquisition request from a message consumer through the message middleware after storing the message ciphertext and the target key ciphertext in a storage medium in the message middleware; a second acquisition unit, used to acquire the message ciphertext and the target key ciphertext based on the data acquisition request; and a third acquisition unit, used to acquire the target message based on the message ciphertext and the target key ciphertext.
[0092] Optionally, in the information processing device provided in Example 2 of the present application, the third acquisition unit includes: a second calling module, used to call the target master key in the key management service through the message middleware to decrypt the target key ciphertext to obtain the target key; a decryption module, used to decrypt the message ciphertext through the target key to obtain the target message.
[0093] Optionally, in the information processing device provided in Example 2 of the present application, the device further includes: a deleting unit, configured to delete the target key in the message middleware after the target message is encrypted based on the target key through the message middleware.
[0094] It should be noted that the first receiving unit 401, the first obtaining unit 402, and the encryption unit 403 described above correspond to steps S201 to S203 in the first embodiment. The examples and application scenarios implemented by the three units and the corresponding steps are the same, but are not limited to the contents disclosed in the first embodiment. It should be noted that the above modules, as part of the device, can be run in the computer terminal 10 provided in the first embodiment.
[0095] It should be noted that the preferred implementation scheme involved in the above embodiments of this application is the same as the scheme provided in Example 1, as well as the application scenario and implementation process, but is not limited to the scheme provided in Example 1.
[0096] Example 3
[0097] The embodiment of the present application may provide an electronic device, which may be any electronic device in a group of electronic device terminals. Optionally, in this embodiment, the electronic device may also be replaced by a terminal device such as a mobile terminal.
[0098] Optionally, in this embodiment, the electronic device may be located in at least one network device among a plurality of network devices of a computer network.
[0099] In this embodiment, the above-mentioned electronic device can execute the program code of the following steps in the information processing method: receiving the target message uploaded by the message producer through the message middleware; obtaining the target key and the target key ciphertext corresponding to the target key through the message middleware, wherein the target key is generated by the target master key, and the target master key has a corresponding relationship with the message producer; encrypting the target message based on the target key through the message middleware to generate a message ciphertext, and storing the message ciphertext and the target key ciphertext to the storage medium in the message middleware, wherein the message ciphertext and the target key ciphertext are sent to the message consumer through the message middleware so that the message consumer obtains the target message.
[0100] The above-mentioned electronic device can execute the program code of the following steps in the information processing method: obtaining the target key and the target key ciphertext corresponding to the target key through the message middleware includes: obtaining the target master key identifier corresponding to the message producer; based on the target master key identifier, calling the target master key in the key management service to generate the key to obtain the target key; encrypting the target key through the target master key to obtain the target key ciphertext.
[0101] The above-mentioned electronic device can execute the program code of the following steps in the information processing method: calling the target master key in the key management service to generate a key, and obtaining the target key includes: determining the key type of the target master key; based on the key type, determining the key generation method; generating the key based on the key generation method to obtain the target key.
[0102] The above-mentioned electronic device can execute the program code of the following steps in the information processing method: before receiving the target message uploaded by the message producer through the message middleware, the method also includes: receiving key parameter information selected by the message producer through the key management service, wherein the key parameter information includes at least: key type and key source; based on the key parameter information, determining the target master key and the target master key identifier corresponding to the target master key in the key management service; and returning the target master key identifier to the message producer.
[0103] The above-mentioned electronic device can execute the program code of the following steps in the information processing method: after storing the message ciphertext and the target key ciphertext to the storage medium in the message middleware, the method also includes: receiving a data acquisition request from the message consumer through the message middleware; based on the data acquisition request, obtaining the message ciphertext and the target key ciphertext; based on the message ciphertext and the target key ciphertext, obtaining the target message.
[0104] The above-mentioned electronic device can execute the program code of the following steps in the information processing method: based on the message ciphertext and the target key ciphertext, obtaining the target message includes: calling the target master key in the key management service through the message middleware to decrypt the target key ciphertext to obtain the target key; decrypting the message ciphertext through the target key to obtain the target message.
[0105] The electronic device can execute the program code of the following steps in the information processing method: after encrypting the target message based on the target key through the message middleware, the method further includes: deleting the target key in the message middleware.
[0106] Optionally, Figure 5 This is a structural block diagram of an electronic device according to an embodiment of the present application. Figure 5 As shown, the electronic device 50 may include: one or more ( Figure 5 (only one is shown) a processor 502 and a memory 504. The electronic device 50 may further include a memory controller to control and manage the memory 504; the electronic device 50 may further include a peripheral interface to connect to a radio frequency module, an audio module, a display screen, etc.
[0107] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the information processing method and device in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned information processing method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the electronic device 50 via a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network and a combination thereof.
[0108] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: receive the target message uploaded by the message producer through the message middleware; obtain the target key and the target key ciphertext corresponding to the target key through the message middleware, wherein the target key is generated by the target master key, and the target master key has a corresponding relationship with the message producer; encrypt the target message based on the target key through the message middleware to generate a message ciphertext, and store the message ciphertext and the target key ciphertext to the storage medium in the message middleware, wherein the message ciphertext and the target key ciphertext are sent to the message consumer through the message middleware so that the message consumer obtains the target message.
[0109] Optionally, the above-mentioned processor can also execute the program code of the following steps: obtaining the target key and the target key ciphertext corresponding to the target key through the message middleware includes: obtaining the target master key identifier corresponding to the message producer; based on the target master key identifier, calling the target master key in the key management service to generate the key and obtain the target key; encrypting the target key through the target master key to obtain the target key ciphertext.
[0110] Optionally, the above-mentioned processor can also execute the program code of the following steps: calling the target master key in the key management service to generate a key, and obtaining the target key includes: determining the key type of the target master key; determining the key generation method based on the key type; generating the key based on the key generation method to obtain the target key.
[0111] Optionally, the above-mentioned processor can also execute the program code of the following steps: before receiving the target message uploaded by the message producer through the message middleware, the method also includes: receiving key parameter information selected by the message producer through the key management service, wherein the key parameter information includes at least: key type and key source; based on the key parameter information, determining the target master key and the target master key identifier corresponding to the target master key in the key management service; and returning the target master key identifier to the message producer.
[0112] Optionally, the above-mentioned processor can also execute the program code of the following steps: after storing the message ciphertext and the target key ciphertext to the storage medium in the message middleware, the method also includes: receiving a data acquisition request from the message consumer through the message middleware; based on the data acquisition request, acquiring the message ciphertext and the target key ciphertext; based on the message ciphertext and the target key ciphertext, acquiring the target message.
[0113] Optionally, the above-mentioned processor can also execute the program code of the following steps: based on the message ciphertext and the target key ciphertext, obtaining the target message includes: decrypting the target key ciphertext by calling the target master key in the key management service through the message middleware to obtain the target key; decrypting the message ciphertext through the target key to obtain the target message.
[0114] Optionally, the processor may further execute program code of the following steps: after encrypting the target message based on the target key through the message middleware, the method further includes: deleting the target key in the message middleware.
[0115] It can be understood by those skilled in the art that Figure 5 The structure shown is for illustration only, and the electronic device 50 may also be a terminal device such as a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet device (MID), or a PAD. Figure 5 It does not limit the structure of the above electronic device. For example, the electronic device 50 may also include Figure 5 More or fewer components (such as network interfaces, display devices, etc.) shown in, or with Figure 5 Different configurations shown.
[0116] A person skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0117] Example 4
[0118] The embodiment of the present application further provides a computer program product. Optionally, in this embodiment, the computer program product can be used to store the program code executed by the information processing method provided in the first embodiment.
[0119] Optionally, in this embodiment, the computer program product may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0120] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0121] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0122] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0123] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0124] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0125] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the existing technology, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store program code.
[0126] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. An information processing method, characterized in that: include: Receive target messages uploaded by message producers through the message middleware; Obtaining, through the message middleware, a target key and a target key ciphertext corresponding to the target key, wherein the target key is generated by a target master key, and the target master key has a corresponding relationship with the message producer; Encrypting the target message based on the target key by the message middleware to generate a message ciphertext, and storing the message ciphertext and the target key ciphertext in a storage medium in the message middleware, wherein the message ciphertext and the target key ciphertext are sent to a message consumer by the message middleware, so that the message consumer obtains the target message; The step of obtaining the target key and the target key ciphertext corresponding to the target key through the message middleware includes: Obtain the target master key identifier corresponding to the message producer; Based on the target master key identifier, calling the target master key in the key management service to perform key generation to obtain the target key; The target key is encrypted using the target master key to obtain the target key ciphertext.
2. The method according to claim 1, characterized in that Invoking the target master key in the key management service to generate a key, to obtain the target key includes: Determining a key type of the target master key; Determining a key generation method based on the key type; A key is generated based on the key generation method to obtain the target key.
3. The method according to claim 1, characterized in that Before receiving the target message uploaded by the message producer through the message middleware, the method further includes: Receiving key parameter information selected by the message producer through a key management service, wherein the key parameter information includes at least: a key type and a key source; Determining, in the key management service, the target master key and a target master key identifier corresponding to the target master key based on the key parameter information; The target master key identifier is returned to the message producer.
4. The method according to claim 1, wherein After storing the message ciphertext and the target key ciphertext in a storage medium in the message middleware, the method further includes: Receiving a data acquisition request from the message consumer through the message middleware; Based on the data acquisition request, acquiring the message ciphertext and the target key ciphertext; The target message is obtained based on the message ciphertext and the target key ciphertext.
5. The method according to claim 4, characterized in that Acquiring the target message based on the message ciphertext and the target key ciphertext includes: Decrypting the target key ciphertext by calling the target master key in the key management service through the message middleware to obtain the target key; The message ciphertext is decrypted using the target key to obtain the target message.
6. The method according to any one of claims 1 to 5, characterized in that After the target message is encrypted based on the target key by the message middleware, the method further includes: deleting the target key in the message middleware.
7. An information processing device, characterized in that include: The first receiving unit is configured to receive a target message uploaded by a message producer through a message middleware; a first acquiring unit, configured to acquire, through the message middleware, a target key and a target key ciphertext corresponding to the target key, wherein the target key is generated by a target master key, and the target master key has a corresponding relationship with the message producer; an encryption unit, configured to encrypt the target message based on the target key through the message middleware to generate a message ciphertext, and store the message ciphertext and the target key ciphertext in a storage medium in the message middleware, wherein a message consumer obtains the target message through the message ciphertext and the target key ciphertext in the message middleware; Among them, the first acquisition unit includes: an acquisition module, used to obtain the target master key identifier corresponding to the message producer; a first calling module, used to call the target master key in the key management service based on the target master key identifier to generate a key and obtain the target key; a processing module, used to encrypt the target key through the target master key to obtain the target key ciphertext.
8. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the storage medium is located is controlled to execute the information processing method according to any one of claims 1 to 6.
9. An electronic device, characterized in that: include: a memory storing an executable program; A processor, configured to run the program, wherein the program, when running, executes the information processing method according to any one of claims 1 to 6.
10. A computer program product, characterized in that The computer program or instructions comprises a computer program or an instruction, which implements the information processing method according to any one of claims 1 to 6 when executed by a processor.
Citation Information
Patent Citations
Message processing method and device, equipment and medium
CN119276579A