Multi-protocol unified encryption cloud service gateway system and method based on password middleware
Through a multi-protocol unified encryption cloud service gateway system based on password middleware, the problem that cloud service gateway is difficult to adapt to different encryption needs of multiple user groups is solved, and unified management and call of encryption protocols is realized, which improves encryption efficiency and security.
Patent Information
- Application Number
- CN202510488379.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-04-18
AI Technical Summary
The existing cloud service gateways are difficult to adapt to the different encryption needs of multiple user groups and the management of multiple encryption protocols is chaotic, resulting in poor overall encryption efficiency and security.
By providing a multi-protocol unified encryption cloud service gateway system based on password middleware, including group identification module, protocol selection module, encryption protocol management module and encryption gateway control module, the identification and protocol combination matching of different encrypted user groups is realized, and a variety of encryption protocols are unifiedly managed and called.
It improves the overall efficiency and security of password cloud service encryption, meets the different encryption needs of multiple user groups, and reduces the complexity of encryption protocol management.
Smart Images

Figure CN120017425A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field related to cloud services, and specifically to a multi-protocol unified encryption cloud service gateway system and method based on cryptographic middleware. Background Art
[0002] With the rapid development of cloud computing technology, more and more users choose to store data in the cloud and use cloud services. Data security and privacy protection are extremely important, and encryption has become a key means to ensure data security. However, different user groups have different security needs, and there are multiple encryption protocols in the network environment. How to efficiently adapt to different user groups and use these protocols reasonably has become a challenge. For example, corporate users have extremely high requirements for data confidentiality and tend to prefer complex and high-intensity encryption protocols; individual users pay more attention to convenience and cost-effectiveness and prefer relatively simple encryption methods; at the same time, different application scenarios, such as financial transactions, medical data transmission, etc., also need to adapt different encryption protocols. The traditional cloud service gateway system lacks a unified encryption management mechanism, which makes it difficult to meet the complex needs of multiple user groups and multiple protocols, thus affecting the efficiency and security of cloud service encryption.
[0003] Therefore, in the current relevant technologies, there are technical problems such as cloud service gateways are difficult to adapt to the different encryption requirements of multiple user groups, and the management of multiple encryption protocols is chaotic, resulting in poor overall encryption performance and security. Summary of the invention
[0004] This application solves the technical problems in the prior art that cloud service gateways are difficult to adapt to the different encryption requirements of multiple user groups, and the management of multiple encryption protocols is chaotic, resulting in poor overall encryption performance and security, by providing a multi-protocol unified encryption cloud service gateway system and method based on cryptographic middleware. This achieves the technical effect of improving the overall encryption performance and security of cryptographic cloud services.
[0005] The present application provides a multi-protocol unified encryption cloud service gateway system based on cryptographic middleware, the system comprising: a group identification module, the group identification module is used to obtain a first user accessing a cloud service gateway and identify the encryption user group to which the first user belongs; a protocol selection module, the protocol selection module performs protocol combination matching analysis based on the received encryption user group to obtain a matching encryption protocol combination; an encryption protocol management module, the encryption protocol management module comprises a plurality of protocol blocks and cryptographic middleware, wherein each protocol block is used to store an encryption protocol of a corresponding type, the cryptographic middleware being connected to the plurality of protocol blocks respectively; an encryption gateway control module, the encryption gateway control module being used to send the matching encryption protocol combination to the cryptographic middleware, the cryptographic middleware performing encryption protocol calls and unified template processing from the plurality of protocol blocks based on the matching encryption protocol combination, and serving the first user according to the returned unified encryption protocol template.
[0006] In a possible implementation, the multi-protocol unified encryption cloud service gateway system based on cryptographic middleware also includes: obtaining a sample of historical user groups accessing the cloud service gateway; identifying a feature vector of each user in the sample of historical user groups, wherein the feature vector includes a data packet mode, an encryption protocol security level, a usage device, and a network environment; using the feature vector as a hierarchical feature of a DBSCAN clustering algorithm, dividing the sample of historical user groups into multiple encryption user groups, and identifying the encryption user group to which the first user belongs when accessing the cloud service gateway.
[0007] In a possible implementation, the multi-protocol unified encryption cloud service gateway system based on cryptographic middleware also includes: constructing a protocol adaptation rule library, which is used to record the protocol combinations adapted for each encryption user group; connecting the protocol adaptation rule library with the protocol selection module, and performing protocol combination matching analysis in the protocol adaptation rule library according to the input encryption user group to obtain a matching encryption protocol combination.
[0008] In a possible implementation, the multi-protocol unified encryption cloud service gateway system based on cryptographic middleware also includes: determining whether the first user included in the cloud service gateway is a newly accessed user; if the first user is a newly accessed user, performing a protocol combination matching analysis in the protocol adaptation rule library according to the encryption user group to which the first user belongs, and obtaining a matching encryption protocol combination; if the first user is not a newly accessed user, obtaining the first user's historical encryption tasks, performing an encryption protocol preference analysis according to the historical encryption tasks, updating the obtained matching encryption protocol combination according to the first user's preferred encryption protocol, and outputting the updated matching encryption protocol combination.
[0009] In a possible implementation, the multi-protocol unified encryption cloud service gateway system based on cryptographic middleware also includes: when the cryptographic middleware receives the matching encryption protocol combination, performing a combination sequence analysis on the matching encryption protocol combination to obtain a serial protocol combination and a parallel protocol combination; based on the serial protocol combination and the parallel protocol combination, generating an encryption protocol scheduling instruction, and based on the encryption protocol scheduling instruction, performing an encryption protocol call from the multiple protocol blocks, and returning the result to the cryptographic middleware.
[0010] In a possible implementation, the multi-protocol unified encryption cloud service gateway system based on cryptographic middleware also includes: a template construction engine encapsulated in the cryptographic middleware, the template construction engine is used to construct a chain template according to the serial protocol combination, and to construct a concurrent template according to the parallel protocol combination; the template fields are configured in the chain template and the concurrent template, the configured chain template and concurrent template are processed to obtain a unified encryption protocol template, and the unified encryption protocol template is bound to the first user; when the first user requests to enter the cloud service gateway, the protocol encryption service is performed according to the returned unified encryption protocol template service.
[0011] In a possible implementation, the multi-protocol unified encryption cloud service gateway system based on cryptographic middleware also includes: the cryptographic middleware includes a unified interface, the cryptographic middleware is connected to the multiple protocol blocks respectively according to the unified interface, the cryptographic middleware issues multiple encryption protocol scheduling instructions to the multiple protocol blocks according to the matching encryption protocol combination, and the multiple protocol blocks transmit the scheduled encryption protocols to the cryptographic middleware respectively according to the issued multiple encryption protocol scheduling instructions; wherein the multiple protocol blocks include at least a symmetric encryption protocol block, an asymmetric encryption protocol block, a transmission security protocol block and a hash algorithm block.
[0012] The present application also provides a multi-protocol unified encryption cloud service gateway method based on cryptographic middleware, the method comprising: obtaining a first user accessing the cloud service gateway, identifying the encryption user group to which the first user belongs; performing protocol combination matching analysis based on the received encryption user group, and obtaining a matching encryption protocol combination; an encryption protocol management module comprises multiple protocol blocks and cryptographic middleware, wherein each protocol block is used to store an encryption protocol of a corresponding type, and the cryptographic middleware is respectively connected to the multiple protocol blocks; sending the matching encryption protocol combination to the cryptographic middleware, the cryptographic middleware performing encryption protocol calls and unified template processing from the multiple protocol blocks based on the matching encryption protocol combination, and serving the first user according to the returned unified encryption protocol template.
[0013] The multi-protocol unified encryption cloud service gateway system and method based on cryptographic middleware proposed in this application includes a group identification module for obtaining the first user and the encryption user group to which he belongs; a protocol selection module for performing protocol combination matching analysis to obtain a matching encryption protocol combination; an encryption protocol management module including multiple protocol blocks and cryptographic middleware; an encryption gateway control module for sending matching encryption protocol combinations to the cryptographic middleware, performing encryption protocol calls and unified template processing from multiple protocol blocks based on the matching encryption protocol combinations, and serving the first user according to the returned unified encryption protocol template. This solves the technical problems in the prior art that the cloud service gateway is difficult to adapt to the different encryption requirements of multiple user groups, the management of multiple encryption protocols is chaotic, and the overall encryption performance and security are poor, thus achieving the technical effect of improving the overall encryption performance and security of cryptographic cloud services. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the technical solution of the embodiment of the present disclosure, the accompanying drawings of the embodiment of the present disclosure will be briefly introduced below. A flow chart is used in the present application to illustrate the operations performed by the system according to the embodiment of the present application. It should be understood that the preceding or following operations are not necessarily performed accurately in order. On the contrary, various steps can be processed in reverse order or simultaneously as needed. At the same time, other operations can also be added to these processes, or one or more operations can be removed from these processes.
[0015] Figure 1 A schematic diagram of the structure of a multi-protocol unified encryption cloud service gateway system based on cryptographic middleware provided in an embodiment of the present application.
[0016] Figure 2 A flowchart of a multi-protocol unified encryption cloud service gateway method based on cryptographic middleware provided in an embodiment of the present application.
[0017] Description of reference numerals: group identification module 10 , protocol selection module 20 , encryption protocol management module 30 , encryption gateway control module 40 . DETAILED DESCRIPTION
[0018] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below.
[0019] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings. The described embodiments should not be regarded as limiting the present application. All other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of this application.
[0020] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments, but it is understood that "some embodiments" may be the same subset or different subsets of all possible embodiments, and may be combined with each other without conflict, and the terms "first\second" involved are merely to distinguish similar objects and do not represent a specific ordering of objects. The terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or modules that are not clearly listed or inherent to these processes, products, or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those generally understood by technicians in the technical field of this application. The terms used herein are for the purpose of describing the embodiments of the present application only.
[0021] The present application embodiment provides a multi-protocol unified encryption cloud service gateway system based on cryptographic middleware, such as Figure 1 As shown, the system includes: The group identification module 10 is used to obtain a first user who accesses the cloud service gateway and identify the encrypted user group to which the first user belongs.
[0022] Preferably, when a user (i.e., the first user) accesses the cloud service gateway system, the group identification module collects and analyzes relevant information of the user, which may include but is not limited to the user's identity (for example, an enterprise user may have specific enterprise registration information, and an individual user may have identity authentication information such as an ID number), the user's usage scenario (such as whether it is used for financial business, medical data processing, daily office work, etc.), the user's security demand preferences (such as the requirement for encryption strength, whether frequent encryption and decryption operations are required, etc.), and the user's authority level (ordinary user, administrator user, etc.); by analyzing and processing this user information, it is determined which specific encryption user group the first user belongs to. For example, users may be divided into enterprise encryption user groups (which can be further divided into different types such as financial enterprises and medical enterprises), personal ordinary encryption user groups, personal high security demand encryption user groups, etc., thereby meeting the needs of this user group in terms of data security and privacy protection.
[0023] Furthermore, the specific configuration of the group identification module 10 also includes obtaining a sample of historical user groups accessing the cloud service gateway; identifying a feature vector of each user in the sample of historical user groups, wherein the feature vector includes a data packet mode, an encryption protocol security level, a usage device, and a network environment; using the feature vector as a hierarchical feature of a DBSCAN clustering algorithm, dividing the sample of historical user groups into a plurality of encrypted user groups, and identifying the encrypted user group to which the first user belongs when accessing the cloud service gateway.
[0024] Preferably, the cloud service gateway accumulates a large amount of user-related data during operation, obtains relevant information of these historical users to form a set, that is, a historical user group sample, such as an information set of all users who have accessed the cloud service gateway in the past month, and then for each user in the historical user group sample, extracts information that can describe the user's characteristics, including data packet mode, encryption protocol security level, usage equipment and network environment, and this information constitutes the user's feature vector, where the data packet mode refers to the characteristics of the data packet during the data transmission process when the user uses the cloud service, such as the size distribution of the data packet, the sending frequency, the time interval between data packets, etc. When different types of users perform data transmission, the data packet mode may be significantly different. For example, enterprise users may have large The data packets transmitted by users are large and relatively regular, while individual users may have relatively small and irregular data packets transmitted; the encryption protocol security level refers to the security level of the encryption protocol adopted by users when using cloud services. Different encryption protocols have different security levels, and some high-level encryption protocols can provide stronger data protection; the device used refers to the type of device used by users to access the cloud service gateway, such as personal computers, smart phones, tablets, etc. The performance and security features of different devices affect the user's use of cloud services and security requirements; the network environment refers to the network environment in which users access cloud services, such as home networks, enterprise LANs, public wireless networks, etc. Different network environments have different security risks, and users may adopt different encryption measures and usage habits in different network environments.
[0025] Preferably, the feature vector is used as the input hierarchical feature of DBSCAN (density-based spatial clustering algorithm), and the historical user group sample is analyzed and processed, and the clusters are automatically divided according to the density distribution of data points in space. Specifically, the neighborhood radius (determines the neighborhood range of the data point) and the minimum number of points (the minimum number of points required to be included in the neighborhood of a data point) are set, and then the feature vector of each user in the historical user group sample is standardized to eliminate the impact of the dimensions between different features. For each user's feature vector, its neighborhood in the feature space is calculated according to the neighborhood radius. If the number of points included in the neighborhood of a certain feature vector is greater than or equal to the minimum number of points, the point corresponding to the feature vector is defined as a core point, and other points in the neighborhood around the core point will be classified into the same cluster as the core point; if a point is neither a core point nor has a path connected to the core point in its neighborhood, it is marked as a noise point, and the historical user group sample is divided into multiple different encrypted user groups. When the first user accesses the cloud service gateway, the user's feature vector is first extracted and standardized, and then the distance between the feature vector and the center of each divided encrypted user group (which can be the mean of all feature vectors in the group) is calculated, and finally the feature vector of the first user is assigned to the encrypted user group with the closest distance.
[0026] The protocol selection module 20 performs protocol combination matching analysis according to the received encryption user group to obtain a matching encryption protocol combination.
[0027] Preferably, the most suitable protocol combination is selected from a large number of encryption protocols according to the characteristics and needs of the encryption user group to provide efficient and secure encryption services. Specifically, different encryption user groups have differences in data security needs, usage scenarios, device capabilities, etc. For example, the enterprise user group may have extremely high requirements for data confidentiality, requiring high-intensity encryption algorithms and strict access control; while the individual user group may pay more attention to the convenience of encryption and less impact on device performance. Then understand the characteristics of various encryption protocols (including encryption strength, key management methods, support for different data types, compatibility with various devices and network environments, etc.) to accurately evaluate their matching degree with the needs of encryption user groups.
[0028] Preferably, based on the analysis of the characteristics of the encryption user group and the evaluation results of the encryption protocol characteristics, the protocol selection module performs a matching analysis, that is, considers how to combine different encryption protocols to best meet the needs of a specific encryption user group. For example, for an encryption user group that has high requirements for data security and real-time performance, a high-intensity symmetric encryption protocol is selected to be combined with a fast asymmetric encryption protocol for key exchange, and a suitable hash algorithm is used to ensure data integrity. The protocol selection module determines the optimal protocol combination based on encryption efficiency, security, compatibility, etc., as the basis for the system to provide encryption services to users in this group, ensuring that user data is effectively protected during transmission and storage, while meeting user usage needs in different scenarios. For example, for a specific encryption user group, the final matching encryption protocol combination may include AES encryption protocol for data encryption, RSA encryption protocol for key management, and HMAC-SHA256 algorithm for data integrity verification.
[0029] Furthermore, the specific configuration of the protocol selection module 20 also includes constructing a protocol adaptation rule library, which is used to record the protocol combination adapted for each encryption user group; connecting the protocol adaptation rule library with the protocol selection module, performing protocol combination matching analysis in the protocol adaptation rule library according to the input encryption user group, and obtaining a matching encryption protocol combination.
[0030] Preferably, various information related to encryption user groups and encryption protocols is collected, including the characteristics of different types of user groups (such as corporate users, individual users, financial institution users, etc.), such as requirements for data security, usage scenarios (such as real-time communication, data storage and backup, etc.), equipment performance limitations, etc., and the characteristics of various encryption protocols are determined, such as encryption strength, operation speed, applicable data types, etc.; based on the collected information, the protocol combination suitable for each encryption user group is analyzed, for example, for corporate user groups with extremely high security requirements and large data volumes, a combination of AES (Advanced Encryption Standard) symmetric encryption protocol and RSA asymmetric encryption protocol may be adapted, wherein RSA is used for key exchange and AES is used for data encryption; then the correspondence between each encryption user group obtained from the analysis and its adapted protocol combination is recorded in the protocol adaptation rule library, wherein the protocol adaptation rule library stores matching information of various user groups and protocol combinations.
[0031] Preferably, the protocol adaptation rule base is connected to the protocol selection module. When new encryption user group information is input, the protocol selection module can analyze and process it according to the content in the rule base. Specifically, when the group identification module identifies the encryption user group to which the first user accessing the cloud service gateway belongs, the information of the encryption user group is passed as input to the protocol selection module; the protocol selection module searches the protocol adaptation rule base for the corresponding protocol combination based on the input encryption user group. For example, if the input is an enterprise user group, the protocol selection module will find a pre-set protocol combination (AES+RSA combination) suitable for the enterprise user group in the rule base; after matching and searching, the protocol selection module obtains the matching encryption protocol combination suitable for the encryption user group from the protocol adaptation rule base, and uses this result for subsequent encryption processing, thereby being able to quickly and accurately provide suitable encryption protocol combinations for different encryption user groups, thereby improving the pertinence and effectiveness of encryption services.
[0032] Furthermore, the specific configuration of the protocol selection module 20 also includes: determining whether the first user included in the cloud service gateway is a newly accessed user; if the first user is a newly accessed user, performing a protocol combination matching analysis in the protocol adaptation rule library according to the encryption user group to which the first user belongs, and obtaining a matching encryption protocol combination; if the first user is not a newly accessed user, obtaining the first user's historical encryption tasks, performing an encryption protocol preference analysis according to the historical encryption tasks, updating the obtained matching encryption protocol combination according to the first user's preferred encryption protocol, and outputting the updated matching encryption protocol combination.
[0033] Preferably, when the first user accesses the cloud service gateway, it is determined whether the user is accessing for the first time, that is, by checking whether the user's identity identifier (such as user ID, device fingerprint, etc.) exists in the user list recorded by the system. If not, the user is determined to be a new access user; if so, the user is determined not to be a new access user, but an old user who has accessed the cloud service gateway before. If it is determined that the first user is a new access user, the group identification module identifies the encryption user group to which the user belongs, and then the protocol selection module searches and matches in the protocol adaptation rule library based on the information of the encryption user group to obtain a matching encryption protocol combination suitable for the encryption user group to which the first user belongs. If it is determined that the first user is not a new user, the encryption task information that the user has performed before is obtained from the user's historical records (such as the encryption protocols, encrypted data types, and encryption scenario details that the user has used in the past), and then the encryption protocol preference analysis is performed, that is, the user's preference for the use of encryption protocols is analyzed. For example, if the user has selected a specific encryption algorithm in multiple encryption tasks in the past, or always uses a combination of certain protocols in certain specific scenarios, the preference for the use of the protocol to be changed is inferred; then, according to the result of the encryption protocol preference analysis, the matching encryption protocol combination obtained in the protocol adaptation rule library according to the encryption user group to which the first user belongs is updated, and finally the updated matching encryption protocol combination is output for providing subsequent encryption services for the first user to better meet the user's personalized needs. Through the processing methods for different types of users, the cloud service gateway system can not only provide new users with a general encryption protocol combination suitable for their group, but also make personalized adjustments based on the historical preferences of old users, thereby improving user satisfaction with encryption services and the security and flexibility of the system.
[0034] The encryption protocol management module 30 includes a plurality of protocol blocks and cryptographic middleware, wherein each protocol block is used to store a corresponding type of encryption protocol, and the cryptographic middleware is connected to the plurality of protocol blocks respectively.
[0035] Preferably, the encryption protocol management module includes multiple protocol blocks and cryptographic middleware. Specifically, the protocol block is a storage unit of the encryption protocol management module. Each protocol block is responsible for storing the corresponding type of encryption protocol. For example, one protocol block specifically stores symmetric encryption protocols, such as AES (Advanced Encryption Standard), DES (Data Encryption Standard), etc.; another protocol block stores asymmetric encryption protocols, such as RSA, ECC (Elliptic Curve Cryptography), etc.; there may also be protocol blocks storing hash algorithm related protocols, such as SHA-1, SHA-256, etc. The cryptographic middleware is the core component of the encryption protocol management module, which is connected to multiple protocol blocks respectively. When the cloud service gateway needs to use a certain encryption protocol to encrypt or decrypt data, the cryptographic middleware obtains the required encryption protocol from the corresponding protocol block according to the system request and provides it to the module or application that needs to use it; the cryptographic middleware can convert between protocols to ensure that data can be correctly transmitted and processed between different encryption environments; the cryptographic middleware is also responsible for managing the keys required for the encryption protocol, including the generation, storage, distribution and update of the keys, so as to ensure the security and correctness of the keys and ensure the normal operation of the encryption protocol. Through the collaborative work of multiple protocol blocks and cryptographic middleware, the encryption protocol management module can efficiently and securely manage various encryption protocols, provide reliable encryption support for the cloud service gateway, and ensure the security and confidentiality of data during transmission and storage.
[0036] The encryption gateway control module 40 is used to send the matching encryption protocol combination to the cryptographic middleware, and the cryptographic middleware performs encryption protocol calls and unified template processing from the multiple protocol blocks based on the matching encryption protocol combination, and serves the first user according to the returned unified encryption protocol template.
[0037] Preferably, the encryption gateway control module is the key part in the system responsible for coordinating and controlling encryption operations. When the system determines the encryption user group to which the first user belongs through the group identification module, and the protocol selection module obtains the matching encryption protocol combination of the user group, the encryption gateway control module obtains the matching encryption protocol combination and sends it to the cryptographic middleware. Assuming that the matching encryption protocol combination is composed of the AES symmetric encryption protocol and the RSA asymmetric encryption protocol, the encryption gateway control module will pass the combination information containing the two protocols to the cryptographic middleware. After the cryptographic middleware receives the matching encryption protocol combination from the encryption gateway control module, since each protocol block stores the corresponding type of encryption protocol, the corresponding encryption protocol is called from multiple protocol blocks according to the protocol information in this combination. Therefore, the cryptographic middleware can accurately call and obtain the AES protocol from the block storing the symmetric encryption protocol and obtain the RSA protocol from the block storing the asymmetric encryption protocol; then the encryption protocol is processed in a unified template, including integrating different encryption protocols according to certain rules and formats to form a unified encryption protocol template, which specifies how to use these protocols to encrypt and decrypt data, including protocol parameter settings, operation sequence, etc. For example, the unified template may specify that the RSA protocol is used for key exchange first, and then the AES protocol is used to encrypt the actual data. After the encryption protocol is called and the unified template is processed, the cryptographic middleware returns a unified encryption protocol template. After receiving the unified encryption protocol template, the encryption gateway control module provides encryption services for the first user in accordance with the provisions of the template. That is, when the data of the first user needs to be encrypted, the system uses the corresponding encryption protocol to process the data according to the method and sequence specified in the unified encryption protocol template, thereby ensuring that the data of the first user is effectively protected during transmission and storage, thereby realizing customized and standardized encryption services for users based on the user group and the matching encryption protocol combination, and ensuring encryption efficiency and security.
[0038] Furthermore, the specific configuration of the encryption gateway control module 40 also includes: a template construction engine is encapsulated in the cryptographic middleware, and the template construction engine is used to construct a chain template according to the serial protocol combination, and to construct a concurrent template according to the parallel protocol combination; the template fields are configured in the chain template and the concurrent template, the configured chain template and concurrent template are processed to obtain a unified encryption protocol template, and the unified encryption protocol template is bound to the first user; when the first user requests to enter the cloud service gateway, the protocol encryption service is performed according to the returned unified encryption protocol template service.
[0039] Preferably, a template building engine is encapsulated in the cryptographic middleware, and the template building engine builds a chain template based on the received serial protocol combination, wherein the serial protocol combination refers to an encryption protocol combination that needs to be executed in sequence in a specific order, for example, it may be necessary to use one encryption protocol to perform preliminary encryption of data first, and then use another protocol to further process the preliminary encrypted data; the template building engine organizes these protocols into a chain structure according to this sequential relationship to form a chain template, and clearly defines the order in which each protocol is executed. For parallel protocol combinations, that is, encryption protocol combinations that can be executed simultaneously, the template building engine builds a concurrent template, for example, two different encryption algorithms are used simultaneously to encrypt different parts of the data to improve encryption efficiency. The template building engine organizes these parallel executed protocols into a concurrent structure to form a concurrent template, and defines the rules in the concurrent template that each protocol can be executed simultaneously.
[0040] Preferably, after constructing the chain template and concurrent template, the template field is configured in the template, which may include various parameters and information related to the encryption operation, such as the parameter settings of the encryption algorithm (such as key length, number of encryption rounds, etc.), format requirements for data input and output, conditions for protocol execution, etc. By configuring the template field, the template is made more specific and operable; then the chain template and concurrent template are integrated to obtain a unified encryption protocol template, wherein the unified encryption protocol template integrates serial and parallel encryption protocol execution methods and related parameter configurations, and is a complete template for guiding encryption operations. Then the generated unified encryption protocol template is bound to the first user, that is, by recording the corresponding relationship between the user identifier and the template, an association relationship between the template and the user is established, and the system records the encryption method customized for this user; when the first user requests to enter the cloud service gateway, the protocol encryption service is provided to the user according to the bound same encryption protocol template, that is, according to the encryption protocol execution order, parameter settings and other requirements specified in the template, the user's data is encrypted to ensure the security and privacy of the user's data in the cloud service gateway, thereby ensuring the standardization and security of the encryption service.
[0041] Furthermore, the specific configuration of the encryption gateway control module 40 also includes that the cryptographic middleware includes a unified interface, and the cryptographic middleware is connected to the multiple protocol blocks respectively according to the unified interface, and the cryptographic middleware issues multiple encryption protocol scheduling instructions to the multiple protocol blocks according to the matching encryption protocol combination, and the multiple protocol blocks transmit the scheduled encryption protocols to the cryptographic middleware respectively according to the issued multiple encryption protocol scheduling instructions; wherein the multiple protocol blocks include at least a symmetric encryption protocol block, an asymmetric encryption protocol block, a transmission security protocol block and a hash algorithm block.
[0042] Preferably, the cryptographic middleware includes a unified interface, which is a standard channel for the cryptographic middleware to connect and communicate with multiple protocol blocks. Specifically, through the unified interface, the cryptographic middleware can interact with different protocol blocks in a consistent manner without having to set different connection methods for each protocol block. It is similar to a universal plug that can be inserted into different types of sockets to achieve connection and data transmission between different devices, thereby improving the compatibility and scalability of the system. According to the unified interface, the cryptographic middleware establishes connections with multiple protocol blocks respectively, that is, whether it is a symmetric encryption protocol block, an asymmetric encryption protocol block, a transmission security protocol block or a hash algorithm block, they are all connected to the cryptographic middleware through this unified interface, thereby enabling the cryptographic middleware to transmit data and interact with instructions with each protocol block. When the cryptographic middleware receives a matching encryption protocol combination (determined by the protocol selection module and sent via the encryption gateway control module), it issues multiple encryption protocol scheduling instructions to multiple protocol blocks based on this combination. The encryption protocol scheduling instructions specify which encryption protocols need to be obtained from each protocol block. For example, if the matching encryption protocol combination includes a symmetric encryption protocol and a hash algorithm, the cryptographic middleware will send corresponding scheduling instructions to the symmetric encryption protocol block and the hash algorithm block respectively to obtain the corresponding encryption protocol.
[0043] Preferably, after receiving the encryption protocol scheduling instructions issued by the cryptographic middleware, the multiple protocol blocks transmit the scheduled encryption protocols to the cryptographic middleware respectively according to the requirements of the encryption protocol scheduling instructions. For example, the symmetric encryption protocol block will transmit the specified symmetric encryption protocol (such as AES protocol) to the cryptographic middleware, the asymmetric encryption protocol block will send the corresponding asymmetric encryption protocol (such as RSA protocol), and the transmission security protocol block and the hash algorithm block will also transmit their corresponding protocols according to the instructions; wherein, the multiple protocol blocks include at least a symmetric encryption protocol block, an asymmetric encryption protocol block, a transmission security protocol block and a hash algorithm block. The symmetric encryption protocol block is used to store protocols related to the symmetric encryption algorithm, and the same key is used for encryption and decryption; the asymmetric encryption protocol block stores the protocols of the asymmetric encryption algorithm, and different keys are used for encryption and decryption; the transmission security protocol block stores the protocols used to ensure the security of data during transmission; the hash algorithm block stores various hash algorithm-related protocols for data integrity verification, etc. Through the classified storage of protocol blocks, the cryptographic middleware can quickly and accurately obtain the required encryption protocols, thereby achieving efficient management and calling of encryption protocols, ensuring that the cloud service gateway can use appropriate encryption protocols to encrypt data according to user needs, thereby ensuring encryption efficiency and encryption security.
[0044] In the above, refer to Figure 1The multi-protocol unified encryption cloud service gateway system based on cryptographic middleware according to an embodiment of the present invention is described in detail. Figure 2 A multi-protocol unified encryption cloud service gateway method based on cryptographic middleware according to an embodiment of the present invention is described.
[0045] A multi-protocol unified encryption cloud service gateway method based on cryptographic middleware, such as Figure 2 As shown, the method includes: obtaining a first user who accesses a cloud service gateway, identifying the encryption user group to which the first user belongs; performing a protocol combination matching analysis based on the received encryption user group, and obtaining a matching encryption protocol combination; an encryption protocol management module includes multiple protocol blocks and cryptographic middleware, wherein each protocol block is used to store an encryption protocol of a corresponding type, and the cryptographic middleware is respectively connected to the multiple protocol blocks; sending the matching encryption protocol combination to the cryptographic middleware, and the cryptographic middleware performs encryption protocol calls and unified template processing from the multiple protocol blocks based on the matching encryption protocol combination, and serves the first user according to the returned unified encryption protocol template.
[0046] In one possible implementation, the multi-protocol unified encryption cloud service gateway method based on cryptographic middleware also includes: obtaining a sample of historical user groups accessing the cloud service gateway; identifying a feature vector of each user in the sample of historical user groups, wherein the feature vector includes a data packet mode, an encryption protocol security level, a usage device, and a network environment; using the feature vector as a hierarchical feature of a DBSCAN clustering algorithm, dividing the sample of historical user groups into multiple encryption user groups, and identifying the encryption user group to which the first user belongs when accessing the cloud service gateway.
[0047] In a possible implementation, the multi-protocol unified encryption cloud service gateway method based on cryptographic middleware also includes: constructing a protocol adaptation rule library, which is used to record the protocol combinations adapted for each encryption user group; connecting the protocol adaptation rule library with the protocol selection module, performing protocol combination matching analysis in the protocol adaptation rule library according to the input encryption user group, and obtaining a matching encryption protocol combination.
[0048] In a possible implementation, the multi-protocol unified encryption cloud service gateway method based on cryptographic middleware also includes: determining whether the first user included in the cloud service gateway is a newly accessed user; if the first user is a newly accessed user, performing a protocol combination matching analysis in the protocol adaptation rule library according to the encryption user group to which the first user belongs, and obtaining a matching encryption protocol combination; if the first user is not a newly accessed user, obtaining the first user's historical encryption tasks, performing an encryption protocol preference analysis according to the historical encryption tasks, updating the obtained matching encryption protocol combination according to the first user's preferred encryption protocol, and outputting the updated matching encryption protocol combination.
[0049] In one possible implementation, the multi-protocol unified encryption cloud service gateway method based on cryptographic middleware also includes: when the cryptographic middleware receives the matching encryption protocol combination, performing a combination sequence analysis on the matching encryption protocol combination to obtain a serial protocol combination and a parallel protocol combination; based on the serial protocol combination and the parallel protocol combination, generating an encryption protocol scheduling instruction, and based on the encryption protocol scheduling instruction, performing an encryption protocol call from the multiple protocol blocks, and returning the result to the cryptographic middleware.
[0050] In a possible implementation, the multi-protocol unified encryption cloud service gateway method based on cryptographic middleware also includes: a template construction engine is encapsulated in the cryptographic middleware, and the template construction engine is used to construct a chain template according to the serial protocol combination, and to construct a concurrent template according to the parallel protocol combination; the template fields are configured in the chain template and the concurrent template, the configured chain template and concurrent template are processed to obtain a unified encryption protocol template, and the unified encryption protocol template is bound to the first user; when the first user requests to enter the cloud service gateway, the protocol encryption service is performed according to the returned unified encryption protocol template service.
[0051] In a possible implementation, the multi-protocol unified encryption cloud service gateway method based on cryptographic middleware also includes: the cryptographic middleware includes a unified interface, the cryptographic middleware is connected to the multiple protocol blocks respectively according to the unified interface, the cryptographic middleware issues multiple encryption protocol scheduling instructions to the multiple protocol blocks according to the matching encryption protocol combination, and the multiple protocol blocks transmit the scheduled encryption protocols to the cryptographic middleware respectively according to the issued multiple encryption protocol scheduling instructions; wherein the multiple protocol blocks include at least a symmetric encryption protocol block, an asymmetric encryption protocol block, a transmission security protocol block and a hash algorithm block.
[0052] The multi-protocol unified encryption cloud service gateway system based on cryptographic middleware provided in an embodiment of the present invention can execute the multi-protocol unified encryption cloud service gateway method based on cryptographic middleware provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0053] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, any number of different modules may be used and run on the user terminal and / or server, and the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.
[0054] The above specific implementations do not constitute a limitation on the protection scope of this application. It should be understood by those skilled in the art that various modifications, combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principles of this application should be included in the protection scope of this application.
Claims
1. A multi-protocol unified encryption cloud service gateway system based on cryptographic middleware, characterized in that: The system comprises: A group identification module, the group identification module is used to obtain a first user who accesses the cloud service gateway and identify the encrypted user group to which the first user belongs; A protocol selection module, wherein the protocol selection module performs a protocol combination matching analysis according to the received encryption user group to obtain a matching encryption protocol combination; An encryption protocol management module, the encryption protocol management module includes a plurality of protocol blocks and cryptographic middleware, wherein each protocol block is used to store an encryption protocol of a corresponding type, and the cryptographic middleware is connected to the plurality of protocol blocks respectively; An encryption gateway control module, wherein the encryption gateway control module is used to send the matching encryption protocol combination to the cryptographic middleware, and the cryptographic middleware performs encryption protocol calls and unified template processing from the multiple protocol blocks based on the matching encryption protocol combination, and serves the first user according to the returned unified encryption protocol template.
2. The multi-protocol unified encryption cloud service gateway system based on cryptographic middleware as claimed in claim 1, characterized in that: The steps performed by the group identification module include: Obtain a historical user group sample accessing the cloud service gateway; Identify the feature vector of each user in the historical user group sample, the feature vector including data packet mode, encryption protocol security level, usage device and network environment; The feature vector is used as a hierarchical feature of a DBSCAN clustering algorithm to divide the historical user group sample into a plurality of encrypted user groups, and the encrypted user group to which the first user belongs is identified when the first user accesses the cloud service gateway.
3. The multi-protocol unified encryption cloud service gateway system based on cryptographic middleware as claimed in claim 1, characterized in that: The steps performed by the protocol selection module include: Constructing a protocol adaptation rule base, wherein the protocol adaptation rule base is used to record the protocol combination adapted for each encryption user group; The protocol adaptation rule base is connected to the protocol selection module, and a protocol combination matching analysis is performed in the protocol adaptation rule base according to the input encryption user group to obtain a matching encryption protocol combination.
4. The multi-protocol unified encryption cloud service gateway system based on cryptographic middleware as claimed in claim 3, characterized in that: The steps performed by the protocol selection module also include: Determining whether the first user included in the cloud service gateway is a new access user; If the first user is a newly accessed user, performing protocol combination matching analysis in the protocol adaptation rule base according to the encryption user group to which the first user belongs, and obtaining a matching encryption protocol combination; If the first user is not a newly accessed user, obtain the first user's historical encryption tasks, perform encryption protocol preference analysis according to the historical encryption tasks, update the obtained matching encryption protocol combination according to the first user's preferred encryption protocol, and output the updated matching encryption protocol combination.
5. The multi-protocol unified encryption cloud service gateway system based on cryptographic middleware as claimed in claim 1, characterized in that: The steps performed by the encryption gateway control module also include: After receiving the matching encryption protocol combination, the cryptographic middleware performs combination sequence analysis on the matching encryption protocol combination to obtain a serial protocol combination and a parallel protocol combination; According to the serial protocol combination and the parallel protocol combination, an encryption protocol scheduling instruction is generated, and according to the encryption protocol scheduling instruction, an encryption protocol call is made from the multiple protocol blocks and returned to the cryptographic middleware.
6. The multi-protocol unified encryption cloud service gateway system based on cryptographic middleware as claimed in claim 5, characterized in that: The steps performed by the encryption gateway control module also include: The cryptographic middleware is encapsulated with a template construction engine, and the template construction engine is used to construct a chain template according to the serial protocol combination and to construct a concurrent template according to the parallel protocol combination; Configuring template fields in the chain template and the concurrent template, processing the configured chain template and concurrent template to obtain a unified encryption protocol template, and binding the unified encryption protocol template to the first user; When the first user requests to enter the cloud service gateway, the protocol encryption service is performed according to the returned unified encryption protocol template service.
7. The multi-protocol unified encryption cloud service gateway system based on cryptographic middleware as claimed in claim 1, characterized in that: The cryptographic middleware includes a unified interface, and the cryptographic middleware is connected to the multiple protocol blocks respectively according to the unified interface. The cryptographic middleware issues multiple encryption protocol scheduling instructions to the multiple protocol blocks according to the matching encryption protocol combination, and the multiple protocol blocks transmit the scheduled encryption protocols to the cryptographic middleware respectively according to the issued multiple encryption protocol scheduling instructions; The multiple protocol blocks include at least a symmetric encryption protocol block, an asymmetric encryption protocol block, a transmission security protocol block and a hash algorithm block.
8. A multi-protocol unified encryption cloud service gateway method based on cryptographic middleware, characterized in that: The method is applied to the multi-protocol unified encryption cloud service gateway system based on cryptographic middleware according to any one of claims 1 to 7, and the method comprises: Acquire a first user accessing the cloud service gateway, and identify the encrypted user group to which the first user belongs; Perform protocol combination matching analysis according to the received encryption user group to obtain a matching encryption protocol combination; The encryption protocol management module includes a plurality of protocol blocks and cryptographic middleware, wherein each protocol block is used to store a corresponding type of encryption protocol, and the cryptographic middleware is connected to the plurality of protocol blocks respectively; The matching encryption protocol combination is sent to the cryptographic middleware, and the cryptographic middleware performs encryption protocol calls and unified template processing from the multiple protocol blocks based on the matching encryption protocol combination, and serves the first user according to the returned unified encryption protocol template.
Citation Information
Patent Citations
Method and system for access of universal encrypted database in cloud environment
CN107370725A
National password SSL protocol luring and detecting method and system, and storage medium
CN115396240A
Message processing method, cloud server and communication system
CN116094699A
Group key negotiation and verification method based on elliptic curve
CN117353941A
Multi-category data encryption system and method based on cloud password unified service platform
CN117728937A