Distributed cryptographic service framework system and cryptographic service processing method

Through the distributed cryptographic service framework system, local cryptographic modules are used to provide cryptographic services, which solves the problem of inefficient cryptographic computing in the prior art and achieves more efficient, secure and flexible cryptographic services.

CN120017282AActive Publication Date: 2025-05-16PEOPLE'S INSURANCE COMPANY OF CHINA

Patent Information

Application Number
CN202510157386.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2025-05-16
Estimated Expiration
2045-02-12

AI Technical Summary

Technical Problem

In the prior art, since all password operations are concentrated on one server, it may cause performance bottlenecks and lead to inefficiency of password operations.

Method used

Provide a distributed cryptographic service framework system, including business applications, cryptographic service management system, cryptographic service system client and local cryptographic module. Through identity authentication and authorization scope verification, we can determine whether the local password module needs to provide password services. After verification through remote proof report, we configure the authorization policy and password resources, and call the local password module to provide password services.

Benefits of technology

Through the distributed architecture, the efficiency of password computing is improved, resource allocation and management is optimized, the security, flexibility and scalability of password services are enhanced, and the allocation of password resources can be dynamically adjusted according to business needs and improved resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017282A_ABST
    Figure CN120017282A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a distributed cryptographic service framework system and a cryptographic service processing method, the distributed cryptographic service framework system comprises one or more business applications and a cryptographic service management system, and each business application corresponds to a locally deployed cryptographic service system client and a local cryptographic module. The business application sends a password service application request to the password service management system, the password service management system sends an authorization strategy and required password resources to the business application when the validity of an identity authentication, authorization range and remote certification report passes verification, and the client of the password service system stores the authorization strategy and sends the password resources to the business application; the local cryptographic module retains cryptographic resources and provides cryptographic service for the cryptographic service request. Based on the distributed cryptographic service framework system and the cryptographic service processing method provided by the embodiment, the security, flexibility and expansibility of the cryptographic service can be improved, and the resource utilization rate is improved, so that the cryptographic operation efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security, and in particular to a distributed cryptographic service framework system and a cryptographic service processing method. Background Art

[0002] With the continuous changes in network service models, more and more business systems adopt cloud or cloud + distributed deployment. Cryptographic services are mainly provided by cryptographic devices to business systems by connecting cryptographic devices with them.

[0003] Under the current network service model, the existing technology mainly connects the distributed business system with the centralized cryptographic server through a unified API interface. The business system sends sensitive data to the cryptographic server, and the cryptographic server processes the cryptographic operations on the sensitive data to realize cryptographic services for the business system.

[0004] However, the existing technology may cause performance bottlenecks and lead to low efficiency of cryptographic operations because all cryptographic operations are concentrated on one server. Summary of the invention

[0005] The embodiments of the present application provide a distributed cryptographic service framework system and a cryptographic service processing method, which can improve the efficiency of cryptographic operations.

[0006] In a first aspect, an embodiment of the present application provides a distributed cryptographic service framework system, characterized in that it includes: one or more business applications and a cryptographic service management system, wherein each business application corresponds to a locally deployed cryptographic service system client and a local cryptographic module;

[0007] Any business application sends a cryptographic service application request to the cryptographic service management system;

[0008] The cryptographic service management system performs identity authentication and authorization scope verification on the cryptographic service application request;

[0009] If both the identity authentication and the authorization scope verification are passed, the cryptographic service management system determines whether the cryptographic service application request requires the local cryptographic module to provide cryptographic services;

[0010] If the local password module is required to provide password services, the password service management system sends a local password module challenge request to the business application;

[0011] The business application sends the local password module challenge request to the password service system client, so that the password service system client sends the local password module challenge request to the local password module;

[0012] The local cryptographic module returns the generated remote attestation report to the cryptographic service system client, so that the cryptographic service system client returns the remote attestation report to the business application;

[0013] The business application sends the remote attestation report to the cryptographic service management system;

[0014] The cryptographic service management system verifies the validity of the remote attestation report;

[0015] If the verification of the validity of the remote attestation report is passed, the cryptographic service management system determines the authorization policy and required cryptographic resources corresponding to the business application;

[0016] The cryptographic service management system sends the authorization policy and the required cryptographic resources to the business application;

[0017] The business application sends the authorization policy and the password resource to the password service system client, so that the password service system client saves the authorization policy, and forwards the password resource to the local password module, so that the local password module uses the password resource to perform password services;

[0018] The business application sends a cryptographic service request to the corresponding cryptographic service system client;

[0019] The cryptographic service system client calls the corresponding local cryptographic module based on the authorization policy, so that the local cryptographic module provides cryptographic services for the cryptographic service request.

[0020] In a possible implementation, the cryptographic service management system performs identity authentication and authorization scope verification on the cryptographic service application request, including:

[0021] The cryptographic service management system obtains the unique user identity carried in the cryptographic service application request;

[0022] The password service management system verifies the correctness of the unique user identity. If the unique user identity is correct, the password service management system determines that the identity authentication has passed the verification. Otherwise, the password service management system determines that the identity authentication has not passed the verification.

[0023] The cryptographic service management system determines the authorization scope corresponding to the business application based on the unique user identity;

[0024] If the cryptographic service application request is within the authorization scope, the cryptographic service management system determines that the authorization scope has passed the verification; otherwise, the cryptographic service management system determines that the authorization scope has not passed the verification.

[0025] In a possible implementation manner, after the cryptographic service management system performs identity authentication and authorization scope verification on the cryptographic service application request, the method further includes:

[0026] If the identity authentication or authorization scope verification fails, the cryptographic service management system rejects the cryptographic service application request.

[0027] In a possible implementation, the cryptographic service management system determines whether the cryptographic service application request requires a local cryptographic module to provide a cryptographic service, including:

[0028] The cryptographic service management system obtains the specified information preset in the cryptographic service application request;

[0029] The cryptographic service management system determines, based on the specified information, whether the business application specifies the use of a corresponding local cryptographic module;

[0030] If the business application specifies the use of the corresponding local cryptographic module, the cryptographic service management system determines that the cryptographic service application request requires the local cryptographic module to provide cryptographic services. Otherwise, the cryptographic service management system determines that the cryptographic service application request does not require the local cryptographic module to provide cryptographic services.

[0031] In one possible implementation, the remote attestation report includes a digital signature;

[0032] Accordingly, the cryptographic service management system verifies the validity of the remote attestation report, including:

[0033] The cryptographic service management system verifies the digital signature in the remote attestation report;

[0034] If the digital signature in the remote attestation report is within the validity period, the cryptographic service management system determines that the validity of the remote attestation report has been verified; otherwise, the cryptographic service management system determines that the validity of the remote attestation report has not been verified.

[0035] In a possible implementation, the cryptographic service management system determines the authorization policy and required cryptographic resources corresponding to the business application, including:

[0036] The cryptographic service management system determines a corresponding authorization policy based on the cryptographic service application request of the business application;

[0037] The cryptographic service management system determines the cryptographic resources required for the authorization scope based on the authorization scope corresponding to the business application.

[0038] In one possible implementation, the remote attestation report includes a temporary public key;

[0039] Accordingly, the cryptographic service management system sends the authorization policy and the required cryptographic resources to the business application, including:

[0040] The cryptographic service management system signs the authorization policy;

[0041] The cryptographic service management system encrypts the cryptographic resource using the temporary public key;

[0042] The cryptographic service management system sends the signed authorization policy and the encrypted cryptographic resources to the business application.

[0043] In a possible implementation, the cryptographic service system client calls a corresponding local cryptographic module based on the authorization policy, including:

[0044] The cryptographic service system client determines whether the cryptographic service request satisfies the corresponding authorization policy;

[0045] If the cryptographic service request satisfies the corresponding authorization policy, the corresponding local cryptographic module is called;

[0046] If the cryptographic service request does not satisfy the corresponding authorization policy, the cryptographic service request is rejected.

[0047] In a possible implementation manner, before any business application sends a cryptographic service application request to the cryptographic service management system, the method further includes:

[0048] Any business application sends a registration application to the cryptographic service management system, wherein the registration application includes registration information;

[0049] The cryptographic service management system determines the unique user identity and authorization scope corresponding to the business application based on the registration information;

[0050] The cryptographic service management system adds the unique user identity and authorization scope corresponding to the business application to the management information to complete the registration of the business application.

[0051] In a second aspect, the present application provides a cryptographic service processing method, which is applied to the distributed cryptographic service framework system as described above, and the method includes:

[0052] Any business application sends a cryptographic service application request to the cryptographic service management system;

[0053] The cryptographic service management system performs identity authentication and authorization scope verification on the cryptographic service application request;

[0054] If both the identity authentication and the authorization scope verification are passed, the cryptographic service management system determines whether the cryptographic service application request requires the local cryptographic module to provide cryptographic services;

[0055] If the local password module is required to provide password services, the password service management system sends a local password module challenge request to the business application;

[0056] The business application sends the local password module challenge request to the password service system client, so that the password service system client sends the local password module challenge request to the local password module;

[0057] The local cryptographic module returns the generated remote attestation report to the cryptographic service system client, so that the cryptographic service system client returns the remote attestation report to the business application;

[0058] The business application sends the remote attestation report to the cryptographic service management system;

[0059] The cryptographic service management system verifies the validity of the remote attestation report;

[0060] If the verification of the validity of the remote attestation report is passed, the cryptographic service management system determines the authorization policy and required cryptographic resources corresponding to the business application;

[0061] The cryptographic service management system sends the authorization policy and the required cryptographic resources to the business application;

[0062] The business application sends the authorization policy and the password resource to the password service system client, so that the password service system client saves the authorization policy, and forwards the password resource to the local password module, so that the local password module uses the password resource to perform password services;

[0063] The business application sends a cryptographic service request to the corresponding cryptographic service system client;

[0064] The cryptographic service system client calls the corresponding local cryptographic module based on the authorization policy, so that the local cryptographic module provides cryptographic services for the cryptographic service request.

[0065] The distributed cryptographic service framework system and cryptographic service processing method provided by the embodiment of the present application, wherein the distributed cryptographic service framework system includes one or more business applications and a cryptographic service management system, wherein each business application corresponds to a locally deployed cryptographic service system client and a local cryptographic module, the business application sends a cryptographic service application request to the cryptographic service management system, the cryptographic service management system performs identity authentication and authorization scope verification, after the verification is passed, if the business application requires the local cryptographic module to provide cryptographic services, the cryptographic service management system verifies the validity of the remote proof report of the local cryptographic module of the business application, after the verification is passed, the cryptographic service management system sends the authorization policy and the required cryptographic resources to the business application, so that the local cryptographic module of the business application provides the corresponding cryptographic service request. The present application adopts a distributed cryptographic service framework system, by configuring cryptographic resources for the local cryptographic module of the business application, and providing cryptographic services by calling the local cryptographic module, on the one hand, it can improve the security, flexibility and scalability of the cryptographic service, on the other hand, it optimizes resource configuration and management, and can dynamically adjust the allocation of cryptographic resources according to business needs, improve resource utilization, and improve cryptographic operation efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0067] Figure 1 The distributed cryptographic service framework system provided for this application;

[0068] Figure 2 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 1 ;

[0069] Figure 3 The information interaction process of the distributed cryptographic service framework system is shown as an example Figure 1 ;

[0070] Figure 4 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 2 ;

[0071] Figure 5 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 3 ;

[0072] Figure 6 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 4 ;

[0073] Figure 7Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 5 ;

[0074] Figure 8 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 6 ;

[0075] Fig. 9 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 7 ;

[0076] Fig.10 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 8 ;

[0077] Fig.11 The information interaction process of the distributed cryptographic service framework system is shown as an example Figure 2 .

[0078] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0079] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0080] First, the terms involved in this application are explained:

[0081] Cryptography: refers to the technology of encrypting and decrypting information through algorithms and protocols to ensure the confidentiality, integrity and authenticity of data;

[0082] Distributed system: A system composed of multiple independent nodes with resource sharing and collaborative processing capabilities, commonly used in cloud computing and big data processing;

[0083] Local cryptographic module: refers to a cryptographic computing unit deployed locally on the user or on an edge device, which can independently perform cryptographic operations, improve security and reduce latency.

[0084] Cryptographic services are mainly connected to business systems through dedicated cryptographic devices, such as directly connecting to a server cryptographic machine through a network cable, directly connecting to a cryptographic card through a high-speed serial computer expansion bus standard (peripheral component interconnectexpress, referred to as PCIE), or directly connecting to a USBKey through a universal serial bus (USB). However, with the continuous changes in network service models, more and more information systems are using cloud or cloud + distributed deployment. In this case, a single business may run on multiple hardware devices, and due to the application of virtualization technology, business functions are no longer bound to fixed hardware devices, but can be run and migrated on different hardware devices.

[0085] Under the current network service model, it is more common to adopt a centralized cryptographic service architecture. Business applications send sensitive data to the central server for processing, and all cryptographic operation requests must be handled by the central server. In addition, business applications rely on standardized application programming interfaces (APIs) to interact with the central server to request cryptographic services. In terms of data transmission security, encryption protocols such as Secure Sockets Layer (SSL) / Transport Layer Security (TLS) are used to ensure the security of data transmission, but there are still network delays and security risks. However, the existing technology may cause performance bottlenecks and low efficiency of cryptographic operations because all cryptographic operations are concentrated on one server.

[0086] Figure 1 The distributed cryptographic service framework system provided for this application, such as Figure 1As shown, the distributed password service framework system includes one or more business applications and a password service management system, wherein each business application corresponds to a locally deployed password service system client and a local password module, the business application sends a password service application request to the password service management system, and the password service management system performs identity authentication and authorization scope verification. After all verifications are passed, if the local password module is required to provide password services, the password service management system sends a local password module challenge request to the business application, the business application sends the local password module challenge request to the password service system client, the password service system client sends the local password module challenge request to the local password module, the local password module returns the generated remote proof report to the password service system client, the password service system client returns the remote proof report to the business application, and the business application sends the remote proof report to the password service management system. The password service management system verifies the validity of the remote proof report, and if the verification is passed, the password service management system sends the authorization policy corresponding to the business application and the required password resources to the business application, the business application sends the authorization policy to the password service system client, and the business application sends the authorization policy password resources to the local password module. The business application sends a password service request to the corresponding password service system client. The password service system client calls the corresponding local password module based on the authorization policy, and the local password module provides password services for the password service request. This application adopts a distributed password service framework system. By configuring password resources for the local password module of the business application and providing password services by calling the local password module, on the one hand, the security, flexibility and scalability of the password service can be improved. On the other hand, resource configuration and management are optimized, and the allocation of password resources can be dynamically adjusted according to business needs, improving resource utilization and improving password operation efficiency.

[0087] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0088] Figure 2 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 1 , including: one or more business applications and a cryptographic service management system, wherein each business application corresponds to a locally deployed cryptographic service system client and a local cryptographic module; such as Figure 2 As shown, the operation process of the distributed cryptographic service framework system is as follows:

[0089] S201. Any business application sends a cryptographic service application request to the cryptographic service management system.

[0090] Combined with the scene example, Figure 3 The information interaction process of the distributed cryptographic service framework system is shown as an example Figure 1 ,like Figure 3 As shown, first in step ①, each business application can send a password service application to the password service management system, and the password service application can include information for identifying the business application.

[0091] S202: The cryptographic service management system performs identity authentication and authorization scope verification on the cryptographic service application request.

[0092] Combined with the scenario example, the cryptographic service management system determines the identity information and authorization scope corresponding to the business application based on the received cryptographic service application request, where the authorization scope is the scope of cryptographic services that the business application can use. At the same time, the identity information and the required cryptographic service carried in the cryptographic service application request are determined based on the cryptographic service application request. Identity authentication of the cryptographic service application request is mainly to determine whether the identity information carried by the cryptographic service application request is equal to the corresponding identity information, and authorization scope verification of the cryptographic service application request is mainly to determine whether the cryptographic service required by the cryptographic service application request is within the corresponding authorization scope.

[0093] S203: If both the identity authentication and the authorization scope verification are passed, the cryptographic service management system determines whether the cryptographic service application request requires a local cryptographic module to provide cryptographic services.

[0094] Combined with the scenario example, if the identity information carried by the password service application request is equal to the corresponding identity information, and the password service required by the password service application request is within the corresponding authorization scope, it is determined that the identity authentication and authorization scope of the password service application request are both passed. At this time, it can be determined whether the password service application request specifies that the local password module needs to provide password services. The local password module provides password services for the local password module corresponding to the business application to encrypt and decrypt the relevant data of the business application.

[0095] S204: If the local cryptographic module is required to provide cryptographic services, the cryptographic service management system sends a local cryptographic module challenge request to the business application.

[0096] Combined with the scenario example, in step ②, when the local cryptographic module is needed to provide cryptographic services, the cryptographic service management system sends a local cryptographic module challenge request to the business application. The local cryptographic module challenge request is a remote proof challenge to the local cryptographic module.

[0097] S205: The business application sends the local password module challenge request to the password service system client, so that the password service system client sends the local password module challenge request to the local password module.

[0098] Combined with the scenario example, in steps ③ and ④, the business application receives the local password module challenge request, and sends the local password module challenge request to the local password module through communication between the business application and the password service system client, and communication between the password service system client and the local password module.

[0099] S206. The local cryptographic module returns the generated remote attestation report to the cryptographic service system client, so that the cryptographic service system client returns the remote attestation report to the business application.

[0100] Combined with the scenario example, in steps 5 and 6, after receiving the local cryptographic module challenge request, the local cryptographic module generates a corresponding remote attestation report and returns it to the business application.

[0101] S207: The business application sends the remote attestation report to the cryptographic service management system.

[0102] In combination with the scenario example, in step 7, the business application returns the received remote attestation report to the cryptographic service management system.

[0103] S208. The cryptographic service management system verifies the validity of the remote attestation report.

[0104] Combined with the scenario example, the cryptographic service management system verifies the validity of the remote report to determine whether the local cryptographic module corresponding to the business application can provide the corresponding cryptographic service.

[0105] S209: If the verification of the validity of the remote attestation report is successful, the cryptographic service management system determines the authorization policy and required cryptographic resources corresponding to the business application.

[0106] Combined with the scenario example, if the validity of the remote attestation report meets the requirements, it is determined that the local cryptographic module corresponding to the business application can provide the corresponding cryptographic service.

[0107] S210. The cryptographic service management system sends the authorization policy and the required cryptographic resources to the business application.

[0108] Combined with the scenario example, in step ⑧, after the validity of the remote attestation report is verified, the cryptographic service management system will send the authorization policy and the required cryptographic resources for encryption and decryption of the business application data to the business application. The cryptographic resources can be the computing resources and storage resources required for encryption and decryption operations.

[0109] S211. The business application sends the authorization policy and the password resource to the password service system client, so that the password service system client saves the authorization policy, and forwards the password resource to the local password module, so that the local password module uses the password resource to perform password services.

[0110] Combined with the scenario example, in steps 9 and 10, after receiving the authorization policy and the required password resources, the business application sends them to the password service system client. The password service system client retains the authorization policy and forwards the password resources to the local password module.

[0111] S212: The business application sends a cryptographic service request to the corresponding cryptographic service system client.

[0112] In combination with the scenario example, after receiving the password resource, the local password module uses the password resource to provide password services for the corresponding business application. Therefore, the business application can directly send the password service request to the password service system client.

[0113] S213: The cryptographic service system client calls the corresponding local cryptographic module based on the authorization policy, so that the local cryptographic module provides cryptographic services for the cryptographic service request.

[0114] Combined with the scenario example, the cryptographic service system client calls the corresponding local cryptographic module based on the obtained authorization policy. The local cryptographic module responds to the cryptographic service request and processes the cryptographic service request based on the received cryptographic resources to complete the corresponding cryptographic service for the business application.

[0115] Based on the method provided in this example, the security, flexibility and scalability of cryptographic services can be improved, and resource configuration and management can be optimized. The allocation of cryptographic resources can be dynamically adjusted according to business needs, resource utilization can be improved, and the efficiency of cryptographic operations can be improved.

[0116] Optional, Figure 4 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 2 ,like Figure 4 As shown, S202 includes:

[0117] S401. The cryptographic service management system obtains a unique user identity carried in the cryptographic service application request.

[0118] In combination with the scenario example, the unique user identity may be a specific identity identifier, such as an identity document (ID for short).

[0119] S402. The cryptographic service management system verifies the correctness of the unique user identity. If the unique user identity is correct, the cryptographic service management system determines that the identity authentication has passed the verification. Otherwise, the cryptographic service management system determines that the identity authentication has not passed the verification.

[0120] Combined with the scenario example, the unique user identity of the business application is assigned by the password service management system, so the unique user identity corresponding to the business application can be stored locally in the password service management system, and the password service management system compares whether the unique user identity corresponding to the business application stored locally is equal to the unique user identity carried in the password service application. If they are equal, it is determined that the unique user identity carried in the password service application is correct; if they are not equal, it is determined that the unique user identity carried in the password service application is wrong.

[0121] S403: The cryptographic service management system determines an authorization scope corresponding to the business application based on the unique user identity.

[0122] Combined with the scenario example, the authorization scope corresponding to the business application is allocated by the cryptographic service management system, so the authorization scope corresponding to the business application can be stored locally in the cryptographic service management system, and the cryptographic service management system can determine the corresponding authorization scope locally based on the unique user identity of the business application.

[0123] S404: If the cryptographic service application request is within the authorization scope, the cryptographic service management system determines that the authorization scope has passed the verification; otherwise, the cryptographic service management system determines that the authorization scope has not passed the verification.

[0124] Combined with the scenario example, the authorization scope can be the scope of content that is authorized to be encrypted and decrypted. If the content encrypted and decrypted required by the cryptographic service application request is within the scope of content that is authorized to be encrypted and decrypted, the authorization scope is verified; if the content encrypted and decrypted required by the cryptographic service application request is not within the scope of content that is authorized to be encrypted and decrypted, the authorization scope is not verified.

[0125] Based on the method provided in this example, the identity authentication and authorization scope verification of the password service application request can be completed.

[0126] Optionally, after S202, the following steps may further be included:

[0127] If the identity authentication or authorization scope verification fails, the cryptographic service management system rejects the cryptographic service application request.

[0128] Combined with the scenario example, if the unique user identity corresponding to the business application stored locally in the cryptographic service management system is not equal to the unique user identity carried in the cryptographic service application, or the encrypted and decrypted content required by the cryptographic service application request is not within the scope of the authorized content that can be encrypted and decrypted, then the cryptographic service management system determines that the cryptographic service application request sent by the business application is not standardized, and the cryptographic service application request can be rejected. Based on the method provided in this example, rejecting the cryptographic service application request that does not meet the requirements can ensure the security of the cryptographic service.

[0129] Optional, Figure 5 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 3 ,like Figure 5 As shown, S203 includes:

[0130] S501. The cryptographic service management system obtains designated information preset in the cryptographic service application request.

[0131] In combination with the scenario example, the specified information represents the information specified when the business application sends a password service application request whether to use the local password module.

[0132] S502: The cryptographic service management system determines, based on the specified information, whether the business application specifies the use of a corresponding local cryptographic module.

[0133] In combination with the scenario example, the specified information may be "yes" or "no", and based on the specified information, it may be determined whether the business application specifies the use of the corresponding local cryptographic module.

[0134] S503. If the business application specifies the use of the corresponding local cryptographic module, the cryptographic service management system determines that the cryptographic service application request requires the local cryptographic module to provide cryptographic services. Otherwise, the cryptographic service management system determines that the cryptographic service application request does not require the local cryptographic module to provide cryptographic services.

[0135] In combination with the scenario example, if the specified information is "yes", the cryptographic service management system determines that a local cryptographic module is required, and if the specified information is "no", the cryptographic service management system determines that a local cryptographic module is not required.

[0136] Based on the method provided in this example, the purpose of accurately determining whether a local password module is needed based on relevant specified information can be achieved.

[0137] Optional, Figure 6Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 4 , the remote attestation report includes a digital signature;

[0138] Accordingly, if Figure 6 As shown, S208 includes:

[0139] S601. The cryptographic service management system verifies the digital signature in the remote attestation report.

[0140] Combined with the scenario example, the digital signature is the signature corresponding to the local cryptographic module, and the validity of the digital signature can be verified.

[0141] S602. If the digital signature in the remote attestation report is within the validity period, the cryptographic service management system determines that the validity of the remote attestation report has passed the verification; otherwise, the cryptographic service management system determines that the validity of the remote attestation report has not passed the verification.

[0142] In combination with the scenario example, the validity period of the digital signature can be a preset time range. If the digital signature is within the preset validity period, it is determined that the digital signature is still valid, and the verification is passed. If the digital signature is not within the preset validity period, it is determined that the digital signature has expired, and the verification is failed.

[0143] Based on the method provided in this example, the validity of the digital signature can be verified.

[0144] Optional, Figure 7 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 5 , S209 includes:

[0145] S701. The cryptographic service management system determines a corresponding authorization policy based on the cryptographic service application request of the business application.

[0146] Combined with the scenario example, if the verification of the validity of the remote proof report is passed, it is determined that the local cryptographic module corresponding to the business application can be uniformly managed by the cryptographic service management system. At this time, the corresponding authorization policy is determined according to the cryptographic service application request sent by the business application.

[0147] S702: The cryptographic service management system determines the cryptographic resources required for the authorization scope based on the authorization scope corresponding to the business application.

[0148] Based on the scenario example, the cryptographic service management system determines the computing resources and storage resources required for the local cryptographic module corresponding to the business application to perform cryptographic services, and determines the determined computing resources and storage resources as the cryptographic resources required for the local cryptographic module corresponding to the business application to perform cryptographic services.

[0149] Based on the method provided in this example, the cryptographic resources required by the local cryptographic module corresponding to the business application to provide cryptographic services can be determined.

[0150] Optionally, the remote attestation report includes a temporary public key;

[0151] Accordingly, Figure 8 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 6 ,like Figure 8 As shown, S210 includes:

[0152] S801. The cryptographic service management system signs the authorization policy.

[0153] In combination with the scenario example, the authorization policy issued by the cryptographic service management system needs to be signed by the cryptographic service management system.

[0154] S802: The cryptographic service management system uses the temporary public key to encrypt the cryptographic resources.

[0155] Combined with the scenario example, the remote attestation report includes the public key corresponding to the public-private key pair temporarily generated by the local cryptographic module. The cryptographic service management system will encrypt the cryptographic resources that need to be sent to the local cryptographic module before sending them down. The encrypted secret key can use the public key in the remote attestation report. After receiving the cryptographic resources, the local cryptographic module can decrypt them according to the private key corresponding to the temporarily generated public-private key pair.

[0156] S803: The cryptographic service management system sends the signed authorization policy and the encrypted cryptographic resources to the business application.

[0157] Based on the scenario example, the password service management system sends the final authorization policy and password resources to the business application.

[0158] Based on the method provided in this example, the authorization policy is signed and the password resources are encrypted to improve the security of the authorization policy and password resources.

[0159] Fig. 9 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 7 ,like Fig. 9 As shown, S213 includes:

[0160] S901. The cryptographic service system client determines whether the cryptographic service request satisfies a corresponding authorization policy.

[0161] Combined with the scenario example, after the cryptographic service system client obtains the authorization policy and the local cryptographic module obtains the cryptographic resources, the business application can directly send a cryptographic service request to the cryptographic service system client. The cryptographic service system client determines whether the cryptographic service request meets the requirements based on the authorization policy, and can determine whether the data that needs to be encrypted and decrypted in the cryptographic service request is within the preset authorization scope.

[0162] S902: If the cryptographic service request satisfies the corresponding authorization policy, the corresponding local cryptographic module is called.

[0163] Combined with the scenario example, if the data that needs to be encrypted involved in the cryptographic service request is within the preset authorization scope, the cryptographic service request is determined to meet the corresponding authorization policy. At this time, the cryptographic service system client calls the local cryptographic module to process the cryptographic service request and encrypts and decrypts the data involved therein.

[0164] S903: If the cryptographic service request does not satisfy the corresponding authorization policy, reject the cryptographic service request.

[0165] Combined with the scenario example, if the data to be encrypted involved in the cryptographic service request is not within the preset authorization scope, it is determined that the cryptographic service request does not meet the corresponding authorization policy. At this time, the cryptographic service system client returns the cryptographic service request to the business application.

[0166] Based on the method provided in this example, the cryptographic service request of the corresponding business application can be processed by directly calling the local cryptographic service, which improves the efficiency of cryptographic operations and reduces the security risks and performance overhead of data transmission.

[0167] Optional, Fig.10 Schematic diagram of the operation process of the distributed cryptographic service framework system provided for this application Figure 8 ,like Fig.10 As shown, before S201, it also includes:

[0168] S1001. Any business application sends a registration application to a cryptographic service management system, wherein the registration application includes registration information.

[0169] Combined with the scene example, Fig.11 The information interaction process of the distributed cryptographic service framework system is shown as an example Figure 2 Each business application that needs password services must first register with the password service management system, such as Fig.11 As shown, the business application can send corresponding registration information to the cryptographic service management system. The registration information includes the application name, the organization to which it belongs, the business type, the expected frequency and scale of use of the cryptographic function, etc.

[0170] S1002. The cryptographic service management system determines a unique user identity and authorization scope corresponding to the business application based on the registration information.

[0171] In combination with the scenario example, the cryptographic service management system assigns a specific unique user identity to the business application that sends the registration information, and determines the authorization scope based on the expected frequency and scale of use of the cryptographic functions in the registration information.

[0172] S1003. The cryptographic service management system adds the unique user identity and authorization scope corresponding to the business application to the management information to complete the registration of the business application.

[0173] Combined with the scenario example, after determining the unique user identity and authorization scope corresponding to the business application, the password service management system can return the unique user identity and authorization scope to the business application, so that the business application can refer to the unique user identity and authorization scope when sending a subsequent password service application. The unique user identity and authorization scope corresponding to the business application are added to the management information, that is, stored locally, to complete the registration of the business application.

[0174] Based on the method provided in this example, you can complete the registration of business applications.

[0175] The cryptographic service processing method provided in the present application is applied to a distributed cryptographic service framework system, and the method includes:

[0176] Any business application sends a cryptographic service application request to the cryptographic service management system;

[0177] The cryptographic service management system performs identity authentication and authorization scope verification on the cryptographic service application request;

[0178] If both the identity authentication and the authorization scope verification are passed, the cryptographic service management system determines whether the cryptographic service application request requires the local cryptographic module to provide cryptographic services;

[0179] If the local password module is required to provide password services, the password service management system sends a local password module challenge request to the business application;

[0180] The business application sends the local password module challenge request to the password service system client, so that the password service system client sends the local password module challenge request to the local password module;

[0181] The local cryptographic module returns the generated remote attestation report to the cryptographic service system client, so that the cryptographic service system client returns the remote attestation report to the business application;

[0182] The business application sends the remote attestation report to the cryptographic service management system;

[0183] The cryptographic service management system verifies the validity of the remote attestation report;

[0184] If the verification of the validity of the remote attestation report is passed, the cryptographic service management system determines the authorization policy and required cryptographic resources corresponding to the business application;

[0185] The cryptographic service management system sends the authorization policy and the required cryptographic resources to the business application;

[0186] The business application sends the authorization policy and the password resource to the password service system client, so that the password service system client saves the authorization policy, and forwards the password resource to the local password module, so that the local password module uses the password resource to perform password services;

[0187] The business application sends a cryptographic service request to the corresponding cryptographic service system client;

[0188] The cryptographic service system client calls the corresponding local cryptographic module based on the authorization policy, so that the local cryptographic module provides cryptographic services for the cryptographic service request.

[0189] The cryptographic service processing method provided in this embodiment is applied to a distributed cryptographic service framework system, and can execute the operation process provided by the distributed cryptographic service framework system embodiment. Its implementation principles and technical effects are similar, and this embodiment will not be repeated here.

[0190] Finally, it should be noted that those skilled in the art will readily conceive of other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses or adaptations of the present invention, which follow the general principles of the present invention and include common knowledge or customary technical means in the art not disclosed by the present invention, are not limited to the precise structure described above and shown in the drawings, and may be modified and changed in various ways without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

Claims

1. A distributed cryptographic service framework system, characterized in that: include: One or more business applications and a cryptographic service management system, wherein each business application corresponds to a locally deployed cryptographic service system client and a local cryptographic module; Any business application sends a cryptographic service application request to the cryptographic service management system; The cryptographic service management system performs identity authentication and authorization scope verification on the cryptographic service application request; If both the identity authentication and the authorization scope verification are passed, the cryptographic service management system determines whether the cryptographic service application request requires the local cryptographic module to provide cryptographic services; If the local password module is required to provide password services, the password service management system sends a local password module challenge request to the business application; The business application sends the local password module challenge request to the password service system client, so that the password service system client sends the local password module challenge request to the local password module; The local cryptographic module returns the generated remote attestation report to the cryptographic service system client, so that the cryptographic service system client returns the remote attestation report to the business application; The business application sends the remote attestation report to the cryptographic service management system; The cryptographic service management system verifies the validity of the remote attestation report; If the verification of the validity of the remote attestation report is passed, the cryptographic service management system determines the authorization policy and required cryptographic resources corresponding to the business application; The cryptographic service management system sends the authorization policy and the required cryptographic resources to the business application; The business application sends the authorization policy and the password resource to the password service system client, so that the password service system client saves the authorization policy, and forwards the password resource to the local password module, so that the local password module uses the password resource to perform password services; The business application sends a cryptographic service request to the corresponding cryptographic service system client; The cryptographic service system client calls the corresponding local cryptographic module based on the authorization policy, so that the local cryptographic module provides cryptographic services for the cryptographic service request.

2. The distributed cryptographic service framework system according to claim 1, characterized in that: The cryptographic service management system performs identity authentication and authorization scope verification on the cryptographic service application request, including: The cryptographic service management system obtains the unique user identity carried in the cryptographic service application request; The password service management system verifies the correctness of the unique user identity. If the unique user identity is correct, the password service management system determines that the identity authentication has passed the verification. Otherwise, the password service management system determines that the identity authentication has not passed the verification. The cryptographic service management system determines the authorization scope corresponding to the business application based on the unique user identity; If the cryptographic service application request is within the authorization scope, the cryptographic service management system determines that the authorization scope has passed the verification; otherwise, the cryptographic service management system determines that the authorization scope has not passed the verification.

3. The distributed cryptographic service framework system according to claim 2, characterized in that: After the cryptographic service management system performs identity authentication and authorization scope verification on the cryptographic service application request, the method further includes: If the identity authentication or authorization scope verification fails, the cryptographic service management system rejects the cryptographic service application request.

4. The distributed cryptographic service framework system according to claim 1, characterized in that: The cryptographic service management system determines whether the cryptographic service application request requires a local cryptographic module to provide a cryptographic service, including: The cryptographic service management system obtains the specified information preset in the cryptographic service application request; The cryptographic service management system determines, based on the specified information, whether the business application specifies the use of a corresponding local cryptographic module; If the business application specifies the use of the corresponding local cryptographic module, the cryptographic service management system determines that the cryptographic service application request requires the local cryptographic module to provide cryptographic services. Otherwise, the cryptographic service management system determines that the cryptographic service application request does not require the local cryptographic module to provide cryptographic services.

5. The distributed cryptographic service framework system according to claim 1, characterized in that: The remote attestation report includes a digital signature; Accordingly, the cryptographic service management system verifies the validity of the remote attestation report, including: The cryptographic service management system verifies the digital signature in the remote attestation report; If the digital signature in the remote attestation report is within the validity period, the cryptographic service management system determines that the validity of the remote attestation report has passed the verification; otherwise, the cryptographic service management system determines that the validity of the remote attestation report has not passed the verification.

6. The distributed cryptographic service framework system according to claim 1, characterized in that: The cryptographic service management system determines the authorization policy and required cryptographic resources corresponding to the business application, including: The cryptographic service management system determines a corresponding authorization policy based on the cryptographic service application request of the business application; The cryptographic service management system determines the cryptographic resources required for the authorization scope based on the authorization scope corresponding to the business application.

7. The distributed cryptographic service framework system according to claim 1, characterized in that: The remote attestation report includes a temporary public key; Accordingly, the cryptographic service management system sends the authorization policy and the required cryptographic resources to the business application, including: The cryptographic service management system signs the authorization policy; The cryptographic service management system encrypts the cryptographic resource using the temporary public key; The cryptographic service management system sends the signed authorization policy and the encrypted cryptographic resources to the business application.

8. The distributed cryptographic service framework system according to claim 1, characterized in that: The cryptographic service system client calls the corresponding local cryptographic module based on the authorization policy, including: The cryptographic service system client determines whether the cryptographic service request satisfies the corresponding authorization policy; If the cryptographic service request satisfies the corresponding authorization policy, the corresponding local cryptographic module is called; If the cryptographic service request does not satisfy the corresponding authorization policy, the cryptographic service request is rejected.

9. The distributed cryptographic service framework system according to any one of claims 1 to 8, characterized in that: Before any of the business applications sends a cryptographic service application request to the cryptographic service management system, the method further includes: Any business application sends a registration application to the cryptographic service management system, wherein the registration application includes registration information; The cryptographic service management system determines the unique user identity and authorization scope corresponding to the business application based on the registration information; The cryptographic service management system adds the unique user identity and authorization scope corresponding to the business application to the management information to complete the registration of the business application.

10. A cryptographic service processing method, characterized in that: The method is applied to the distributed cryptographic service framework system according to claim 1, and the method comprises: Any business application sends a cryptographic service application request to the cryptographic service management system; The cryptographic service management system performs identity authentication and authorization scope verification on the cryptographic service application request; If both the identity authentication and the authorization scope verification are passed, the cryptographic service management system determines whether the cryptographic service application request requires the local cryptographic module to provide cryptographic services; If the local password module is required to provide password services, the password service management system sends a local password module challenge request to the business application; The business application sends the local password module challenge request to the password service system client, so that the password service system client sends the local password module challenge request to the local password module; The local cryptographic module returns the generated remote attestation report to the cryptographic service system client, so that the cryptographic service system client returns the remote attestation report to the business application; The business application sends the remote attestation report to the cryptographic service management system; The cryptographic service management system verifies the validity of the remote attestation report; If the verification of the validity of the remote attestation report is passed, the cryptographic service management system determines the authorization policy and required cryptographic resources corresponding to the business application; The cryptographic service management system sends the authorization policy and the required cryptographic resources to the business application; The business application sends the authorization policy and the password resource to the password service system client, so that the password service system client saves the authorization policy, and forwards the password resource to the local password module, so that the local password module uses the password resource to perform password services; The business application sends a cryptographic service request to the corresponding cryptographic service system client; The cryptographic service system client calls the corresponding local cryptographic module based on the authorization policy, so that the local cryptographic module provides cryptographic services for the cryptographic service request.

Citation Information

Patent Citations

  • Password service system, method and device

    CN112003690A

  • Client login authentication method and system and computer device

    CN113395249A

  • Password resource authorization management method and device, storage medium and electronic equipment

    CN117592030A

  • Distributed password service system and method based on confidential computing technology

    CN118138287A

  • Data security service

    IN202018032568A

Cited By

  • Distributed password service system and method based on interlayer interface decoupling

    CN121418082A