Session management method and device and electronic equipment
Through the correspondence between the preset session handle and the preset session ciphertext, the target session ciphertext is determined, which solves the problem of session plaintext leakage and achieves the security and efficiency of the session management process.
Patent Information
- Application Number
- CN202311553292.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-20
- Publication Date
- 2025-05-20
AI Technical Summary
In the prior art, the session handle has a corresponding relationship with the session plaintext, causing a network attacker to forge the session handle and intercept the session plaintext, causing information leakage and security risks.
Through the correspondence between the preset session handle and the preset session ciphertext, the target session ciphertext is determined, which solves the information leakage problem caused by the session plaintext, and integrates the password application and the session management module into one system, ensuring the security of the session management process.
By encrypting the session ciphertext, the leakage of session plaintext is avoided, the data transmission security between the password application and the session management module is improved, and the efficiency of session management is improved.
Smart Images

Figure CN120021193A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular, to a session management method, apparatus, and electronic device. Background Art
[0002] With the development of information security technology, in order to ensure the security of information, password services are introduced. Usually, a session management module in a network system is used to uniformly manage and schedule a set of password devices. Currently, the specific process of implementing password services based on creating a session in a session application is as follows:
[0003] A schematic diagram of the scenario where a password application implements password services through a network system is as Figure 1 shown. In Figure 1 , when a password application needs to implement password services, the password application sends a session establishment request to the session management module in the network system. In response to the session establishment request, the session management module creates a globally unique session handle for the password application and sends the session handle to the password application.
[0004] Since there is a corresponding relationship between the session handle and the session plaintext, the password application can determine the stored session plaintext in the session space based on the received session handle, and the session plaintext is used to support the password application to implement password services.
[0005] Based on the above description, since the password application can directly determine the session plaintext from the session space based on the session handle, when a network attacker forges a session handle and intercepts the session plaintext, it will cause the password application to fail to obtain the session plaintext and cause the leakage of the session plaintext, resulting in a huge security risk in the session management process between the password application and the network system. Summary of the Invention
[0006] This application provides a session management method, apparatus, and electronic device. By presetting the corresponding relationship between the session handle and the preset session ciphertext, the target session ciphertext is determined, the problem of information leakage caused by the session plaintext is solved, and the password application and the session management module are integrated into a system to ensure the security of the session management process between the password application and the system.
[0007] In a first aspect, this application provides a session management method, and the method includes:
[0008] Responding to a session establishment request sent by a password application, where the session establishment request at least includes a target password device corresponding to the password application for establishing a session;
[0009] Determine the target session handle in the session establishment request, and based on the mapping relationship between the preset session handle and the preset session ciphertext, determine the target session ciphertext corresponding to the target session handle in the target cryptographic device;
[0010] Send the target session ciphertext to the cryptographic application.
[0011] Through the above method, the determined target session ciphertext is encrypted, thus being able to solve the problem of information leakage caused by session plaintext. Session management is completed through the information between the cryptographic application and the system. Since the cryptographic device and the session management module are integrated in this system, the efficiency of session management can be improved.
[0012] In a possible design, before responding to the session establishment request sent by the cryptographic application, it includes:
[0013] Respond to at least one preset session establishment request;
[0014] Determine the preset session handle and the cryptographic resource identifier corresponding to each preset session establishment request. Among them, the respective preset session handles are generated based on their corresponding random numbers, and the cryptographic resource identifier includes: at least one cryptographic application identifier, a preset algorithm;
[0015] Encrypt each preset session handle and the cryptographic resource identifier corresponding to each preset session handle based on the session management key to obtain a preset session ciphertext;
[0016] Establish the mapping relationship between each preset session handle and the preset session ciphertext corresponding to each preset session handle.
[0017] Through the above method, encrypting the preset session handle and the corresponding cryptographic resource identifier with the session management key makes the determined preset session ciphertext more secure, and establishing the mapping relationship between the preset session handle and the corresponding preset session ciphertext realizes that the preset session ciphertext can be found through the preset session handle.
[0018] In a possible design, after sending the target session ciphertext to the cryptographic application, it further includes:
[0019] Obtain the first service parameter received by the first cryptographic device, where the first service parameter at least includes: the first cryptographic application identifier, the session ciphertext;
[0020] Decrypt the session ciphertext based on the session management key, and detect whether there is an identifier indicating successful decryption of the session ciphertext;
[0021] If so, determine the session handle and the cryptographic resource identifier in the session ciphertext;
[0022] Otherwise, it is determined that the decryption fails.
[0023] Through the above method, the password application realizes session usage through the first password device corresponding to the first service parameter. By detecting the identifier indicating whether the session ciphertext is successfully decrypted, the result of session usage is made more accurate.
[0024] In a possible design, after sending the target session ciphertext to the password application, it further includes:
[0025] Obtain the second service parameter received by the second password device, where the second service parameter at least includes: the first IP address of the first password device and the session ciphertext;
[0026] Decrypt the session ciphertext based on the session management key, determine the session handle corresponding to the session ciphertext, and detect whether there is a preset session handle in the mapping relationship that is the same as the session handle;
[0027] If so, determine the password resource identifier corresponding to the session ciphertext, and execute the password service required by the password application corresponding to the password resource identifier;
[0028] If not, synchronize the password resources of the first password device to the second password device based on the first IP address.
[0029] Through the above method, since the second service parameter contains the first IP address of the first password device, the password application can open a session in the first password device and use the session in the second password device, making the way of session usage more flexible.
[0030] In a possible design, after sending the target session ciphertext to the password application, it further includes:
[0031] In response to the session close instruction sent by the password application, delete the target session handle and the target session ciphertext corresponding to the target session ciphertext in the mapping relationship; or
[0032] Determine the session call time interval. In response to the session call time interval exceeding the preset session call time interval, delete the target session handle and the target session ciphertext corresponding to the target session ciphertext in the mapping relationship, where the session call time interval is the interval between the current time and the previous session call time.
[0033] Through the above method, the system destroys the session in an active or passive manner and cleans up the resources related to the session in the system, which is beneficial to the flexible invocation of system resources.
[0034] In a second aspect, the present application provides a session management device, and the device includes:
[0035] A response module, configured to respond to a session establishment request sent by a password application, where at least the target password device corresponding to the session established by the password application is included in the session establishment request;
[0036] A ciphertext module, configured to determine a target session handle in the session establishment request, and based on a mapping relationship between a preset session handle and a preset session ciphertext, determine a target session ciphertext corresponding to the target session handle in the target password device;
[0037] A sending module, configured to send the target session ciphertext to the password application.
[0038] In a possible design, the response module is specifically configured to respond to at least one preset session establishment request, determine a preset session handle and a password resource identifier corresponding to each preset session establishment request, encrypt each preset session handle and the password resource identifier corresponding to each preset session handle based on a session management key to obtain a preset session ciphertext, and establish a mapping relationship between each preset session handle and the preset session ciphertext corresponding to each preset session handle.
[0039] In a possible design, the sending module is specifically configured to obtain a first service parameter received by a first password device, decrypt the session ciphertext based on a session management key, and detect whether there is an identifier indicating successful decryption of the session ciphertext. If so, determine the session handle and the password resource identifier in the session ciphertext. If not, determine that the decryption fails.
[0040] In a possible design, the sending module is further configured to decrypt the session ciphertext based on a session management key, determine the session handle corresponding to the session ciphertext, and detect whether there is a preset session handle in the mapping relationship that is the same as the session handle. If so, determine the password resource identifier corresponding to the session ciphertext, and execute the password service required by the password application corresponding to the password resource identifier. If not, synchronize the password resources of the first password device to the second password device based on the first IP address.
[0041] In a possible design, the sending module is further configured to respond to a session closing instruction sent by the password application, delete the target session handle and the target session ciphertext corresponding to the target session ciphertext in the mapping relationship based on the session closing instruction, or determine a session call time interval, and delete the target session handle and the target session ciphertext corresponding to the target session ciphertext in the mapping relationship in response to the session call time interval exceeding a preset session call time interval.
[0042] In a third aspect, the present application provides an electronic device, including:
[0043] a memory for storing a computer program;
[0044] a processor, configured to implement the steps of the above-mentioned session management method when executing the computer program stored in the memory.
[0045] In a fourth aspect, a computer-readable storage medium stores a computer program therein, and when the computer program is executed by a processor, the steps of the above-mentioned session management method are implemented.
[0046] For the technical effects that can be achieved by each of the above first aspect to fourth aspect and each aspect, please refer to the description of the technical effects that can be achieved by the first aspect or various possible solutions in the first aspect above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 It is a schematic diagram of a scenario where a password application provided by the present application realizes a password service through a network system;
[0048] Figure 2 It is a flowchart of the steps of a session management method provided by the present application;
[0049] Figure 3 It is a schematic diagram of a system integrating a session management module and a password device provided by the present application;
[0050] Figure 4 It is a schematic diagram of the process of session creation provided by the present application;
[0051] Figure 5 It is a schematic diagram of the process of creating and using a session by a password application provided by the present application on different password devices;
[0052] Figure 6 It is a schematic diagram of the structure of a session management device provided by the present application;
[0053] Figure 7 It is a schematic diagram of the structure of an electronic device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0054] To make the objectives, technical solutions, and advantages of this application clearer, the following will further describe this application in detail with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of this application, "a plurality of" is understood as "at least two". "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The connection between A and B can represent: A is directly connected to B and A is connected to B through C. In addition, in the description of this application, terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying order.
[0055] In the prior art, since the cipher application can directly determine the session plaintext from the session space based on the session handle, when a network attacker forges the session handle and intercepts the session plaintext, it will cause the cipher application to fail to obtain the session plaintext and result in the leakage of the session plaintext, leading to a huge security risk in the process of transmitting data between the cipher application and the session management module.
[0056] To solve the above problems, this application provides a session management method for encrypting the plaintext in the session space and integrating the session management module and the cipher device into a system to improve the security of the data transmission process between the cipher application and the session management module. Among them, the methods and devices in the embodiments of this application are based on the same technical concept. Since the principles of the problems solved by the methods and devices are similar, the embodiments of the device and the method can be referred to each other, and the repeated parts will not be described again.
[0057] The following will describe the embodiments of this application in detail with reference to the accompanying drawings.
[0058] Refer to Figure 1 , this application provides a session management method, which can enhance the security in the session management process and improve the security of the data transmission process between the cipher application and the session management module. The implementation process of this method is as follows:
[0059] Step S21: Respond to the session establishment request sent by the cipher application.
[0060] The schematic diagram of the system integrating the session management module and the cipher device provided by the embodiments of this application refers to Figure 3 , in Figure 3In it, the password device resource pool in the system is empty in the initial state. Password devices need to be added. In response to at least one preset session establishment request, the preset session handle corresponding to each preset session establishment request and the password resource identifier need to be determined. The preset session handle is generated by a respective random number. The password resource identifier at least includes: at least one password application identifier, a preset algorithm, etc. When adding the first password device to the password resource pool, a session management key K will be generated in the password device. When continuing to add other password devices, the session management key K will be synchronized from the first password device to other password devices, so that all password devices in the password resource pool have the same session management key, and there is a session management module and password resources in each password device. The password resources are stored in the session space.
[0061] It should be noted that the addition of password devices can be completed by the above system or implemented by other device management modules, which can be set according to the actual situation and will not be specifically described here.
[0062] After determining the preset session handle corresponding to each preset session establishment request and the password resource identifier corresponding to the preset session handle, the preset session handle and the corresponding password resource identifier are encrypted to obtain a preset session ciphertext, and then a mapping relationship between the preset session handle and the corresponding preset session ciphertext is established.
[0063] When a password application sends a session establishment request to the system, the system responds to the session establishment request. The session establishment request includes the target password device corresponding to the password application to establish a session. The password application can also obtain the IP address list of the password devices required for the required password service from the system, and then the password application selects the target password device to request to establish a session.
[0064] Through the above method, since the session establishment request contains the target password device, the password application can specify the password device for password service, and there is a session management module in the password device, which is beneficial to the system's management and invocation of the session management module and password resources.
[0065] Step S22: Determine the target session handle in the session establishment request, and based on the mapping relationship between the preset session handle and the preset session ciphertext, determine the target session ciphertext corresponding to the target session handle in the target password device.
[0066] Determine the target session handle in the session request. This target session handle can be extracted from the session establishment request. To enable the password service required for password application, it is necessary to determine the preset session ciphertext that is consistent with the target session handle based on the mapping relationship between the preset session handle and the preset session ciphertext. Since the preset session handle can uniquely point to the mapping space where the preset session ciphertext is stored, the target session ciphertext corresponding to the target session handle can be determined.
[0067] In the embodiment of the present application, the target session handle can also be generated by the system based on a random number after receiving the session establishment request, and the password resource identifier required for password application is assigned to the password application. The target session handle and the password resource identifier are encrypted based on the session management key to obtain the target session ciphertext.
[0068] Through the above method, the target session handle and the password resource identifier are encrypted using the session management key to obtain the target session ciphertext, avoiding obtaining the session plaintext, solving the risk of leakage of the session plaintext during transmission, and improving the security of the data transmission process between the password application and the system.
[0069] Step S23: Send the target session ciphertext to the password application.
[0070] After the system determines the target session ciphertext, it sends the target session ciphertext to the password application.
[0071] After the password application obtains the target session handle and the target session ciphertext, when using the session, it needs to send the first service parameter to the first password device. The system will collect the first service parameter received by the first password device. The first service parameter at least includes: the first password application identifier, the session ciphertext.
[0072] After the system receives the first service parameter, it decrypts the session ciphertext in the first service parameter using the session management key and detects whether there is an identifier indicating successful decryption of the session ciphertext. When there is an identifier indicating successful decryption of the session ciphertext, it determines the password resource identifier corresponding to the session ciphertext and completes the password service required for password application based on the password resource identifier; when there is no identifier indicating successful decryption of the session ciphertext, the decryption fails, and the system controls the password device to send an error back to the password application.
[0073] It should be noted that since the IP address list of all cryptographic devices in the cryptographic device resource pool of the system is stored in the cryptographic application, the cryptographic application can also send second service parameters to the second cryptographic device. The second service parameters record the first IP address of the first cryptographic device and the session ciphertext. The system decrypts the session ciphertext by calling the session management key, determines the session handle corresponding to the session ciphertext, and detects whether there is a preset session handle in the mapping relationship that is the same as the session handle. When there is a preset session handle that is the same as the session handle, the cryptographic resource identifier corresponding to the session ciphertext is determined, and the cryptographic service required by the cryptographic application corresponding to the cryptographic resource identifier is executed; when there is no preset session handle that is the same as the session handle, the cryptographic resources of the first cryptographic device are synchronized to the second cryptographic device based on the first IP address, and the cryptographic service required by the cryptographic application corresponding to the cryptographic identifier is executed.
[0074] After the cryptographic service corresponding to the cryptographic application ends, the session needs to be closed. The specific process of closing the session is as follows:
[0075] Method 1: The cryptographic application sends a session close instruction to the system. In response to the session close instruction, the system determines the target session ciphertext corresponding to the cryptographic application from the session close instruction, and deletes the target session handle and the target session ciphertext corresponding to the target session ciphertext from the mapping relationship.
[0076] Method 2: The system determines the time interval of session invocation. This session invocation time interval is the interval between the current time and the previous session invocation time. When the session invocation time exceeds the preset session invocation time interval, the target session handle and the target session ciphertext corresponding to the target session ciphertext are deleted from the mapping relationship.
[0077] The embodiments of the present application can select the above Method 1 or Method 2 to destroy the session according to the actual situation, and clear the corresponding session space to save system resources.
[0078] The embodiments of the present application provide a schematic diagram of the session creation process. Refer to Figure 4 , the cryptographic application can directly send a session establishment request to the target cryptographic device, or send a session establishment request to the system, and then the system calls the target cryptographic device to respond. Figure 4 In, the system or the target cryptographic device responds to the session establishment request, generates a target session handle based on a random number, allocates a cryptographic resource identifier, encrypts the target session handle and the cryptographic resource identifier to obtain a target session ciphertext, and then saves the target session handle and the target session ciphertext in the mapping relationship, thereby realizing finding the target session ciphertext based on the target session handle. Finally, the target session ciphertext is sent to the cryptographic application.
[0079] In the embodiments of the present application, there is also provided a schematic diagram of the process of creating and using a session by a password application on different password devices. Refer to Figure 5 , since the process of creating a session by the password application is the same as the process described above, therefore, the process of creating a session by the password application refers to the above description and will not be repeated here.
[0080] The process of the password application implementing session usage based on the first password device or system is as follows: The password application sends the first service parameter to the first password device or system. The first password device or system parses the session ciphertext in the first service parameter through the session management key to obtain the session handle and the password resource identifier, and looks up the session handle and the password resource identifier in the mapping relationship, and completes the password service required by the password application based on the password resource pointed to by the password resource identifier, and returns the result to the password application.
[0081] The process of the password application implementing session adaptation based on the second password device or system is as follows: The password application sends the second service parameter to the second password device or system. The second service parameter includes the first IP address of the first password device and the session ciphertext. The second password device or system parses the session ciphertext in the second service parameter through the session management key to obtain the session handle and the password resource identifier, and looks up the session handle and the password resource identifier in the mapping relationship, and detects whether the session handle and the password resource identifier are found. If so, the password service required by the password application is completed based on the password resource pointed to by the password resource identifier; if not, a password resource request is sent to the first password device. The password resource request includes the password resource identifier to be obtained. After receiving the password resource request, the first password device will send the password resource to the second password device, thereby realizing the synchronization of the password resources in the first password device to the second password device.
[0082] The second password device or system then saves the session handle and the session space corresponding to the password resource, completes the password service required by the password application based on the password resource pointed to by the password resource identifier, and returns the result to the password application.
[0083] Based on the above method, the target session handle and the password resource identifier are encrypted by using the session management key to obtain the target session ciphertext, which solves the problem of leakage of session plaintext information. The password resource identifier is encrypted and decrypted by using the session management key, so that the password application can open a session on one password device and use the session to call the password service on another password device, so that it is not necessary to synchronize all password resources in real time between password devices, improving the efficiency of session management and ensuring the security of the session management process between the password application and the system.
[0084] Based on the same inventive concept, an embodiment of the present application further provides a session management device, which is used to implement the functions of a session management method. Refer to Figure 6 , the device includes:
[0085] A response module 601, configured to respond to a session establishment request sent by a password application, where at least the target password device corresponding to the session establishment by the password application is included in the session establishment request;
[0086] A ciphertext module 602, configured to determine the target session handle in the session establishment request, and based on the mapping relationship between the preset session handle and the preset session ciphertext, determine the target session ciphertext corresponding to the target session handle in the target password device;
[0087] A sending module 603, configured to send the target session ciphertext to the password application.
[0088] In a possible design, the response module 601 is specifically configured to respond to at least one preset session establishment request, determine the preset session handle and the password resource identifier corresponding to each preset session establishment request, encrypt each preset session handle and the password resource identifier corresponding to each preset session handle based on the session management key to obtain a preset session ciphertext, and establish a mapping relationship between each preset session handle and the preset session ciphertext corresponding to each preset session handle.
[0089] In a possible design, the sending module 603 is specifically configured to obtain the first service parameter received by the first password device, decrypt the session ciphertext based on the session management key, detect whether there is an identifier indicating successful decryption of the session ciphertext. If so, determine the session handle and the password resource identifier in the session ciphertext. If not, determine that the decryption fails.
[0090] In a possible design, the sending module 603 is further configured to decrypt the session ciphertext based on the session management key, determine the session handle corresponding to the session ciphertext, and detect whether there is a preset session handle in the mapping relationship that is the same as the session handle. If so, determine the password resource identifier corresponding to the session ciphertext, and execute the password service required by the password application corresponding to the password resource identifier. If not, synchronize the password resources of the first password device to the second password device based on the first IP address.
[0091] In a possible design, the sending module 603 is further configured to, in response to a session closing instruction sent by the password application, delete the target session handle and the target session ciphertext corresponding to the target session ciphertext in the mapping relationship based on the session closing instruction, or determine a session call time interval, and in response to the session call time interval exceeding a preset session call time interval, delete the target session handle and the target session ciphertext corresponding to the target session ciphertext in the mapping relationship.
[0092] Based on the same inventive concept, an electronic device is further provided in an embodiment of the present application. The electronic device can implement the functions of the foregoing session management device. Refer to Figure 7 , the electronic device includes:
[0093] At least one processor 701 and a memory 702 connected to the at least one processor 701. In the embodiment of the present application, the specific connection medium between the processor 701 and the memory 702 is not limited. Figure 7 In Figure 7 it is taken as an example that the processor 701 and the memory 702 are connected through a bus 700. The bus 700 is represented by a thick line in Figure 7 . The connection manners between other components are only for illustrative purposes and are not to be construed as limiting. The bus 700 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation,
[0094] in Figure 6 it is only represented by a thick line, but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 701 may also be referred to as a controller, and the name is not limited.
[0095] In the embodiment of the present application, the memory 702 stores instructions executable by the at least one processor 701. The at least one processor 701 can execute a session management method described above by executing the instructions stored in the memory 702. The processor 701 can implement
[0096] In a possible design, the processor 701 may include one or more processing units. The processor 701 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communications. It can be understood that the above-mentioned modem processor may not be integrated into the processor 701 either. In some embodiments, the processor 701 and the memory 702 may be implemented on the same chip, and in some embodiments, they may also be separately implemented on independent chips.
[0097] The processor 701 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of a session management method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0098] As a non-volatile computer-readable storage medium, the memory 702 can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 702 may include at least one type of storage medium. For example, it may include flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (RAM), a static random access memory (SRAM), a programmable read-only memory (PROM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic memory, a magnetic disk, an optical disk, and so on. The memory 702 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 702 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0099] By programming the design of the processor 701, the code corresponding to a session management method introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute when running Figure 2A session management step of the illustrated embodiment. How to design and program the processor 701 is a well-known technology to those skilled in the art and will not be elaborated here.
[0100] Based on the same inventive concept, an embodiment of the present application also provides a storage medium storing computer instructions, which when run on a computer, cause the computer to execute a session management method described above.
[0101] In some possible implementation manners, various aspects of a session management method provided by the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on a device, the program code is used to cause the control device to execute the steps in a session management method according to various exemplary embodiments of the present application described above in this specification.
[0102] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0103] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one or more flows and / or Figure 1 blocks or multiple blocks.
[0104] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one or more flows and / or Figure 1 blocks or multiple blocks.
[0105] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions for implementing the steps of the process Figure 1 in one process or a plurality of processes and / or boxes Figure 1 or steps for implementing the functions specified in a plurality of boxes.
[0106] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. A session management method, characterized in that: A system for integrating a session management module with a cryptographic device, the method comprising: Responding to a session establishment request sent by a cryptographic application, wherein the session establishment request includes at least a target cryptographic device corresponding to a session established by the cryptographic application; Determine a target session handle in the session establishment request, and determine a target session ciphertext corresponding to the target session handle in the target cryptographic device based on a mapping relationship between a preset session handle and a preset session ciphertext; The target session ciphertext is sent to the cryptographic application.
2. The method according to claim 1, characterized in that Before responding to a session establishment request sent by a cryptographic application, including: responding to at least one preset session establishment request; Determine a preset session handle and a cryptographic resource identifier corresponding to each preset session establishment request, wherein each preset session handle is generated based on a corresponding random number, and the cryptographic resource identifier includes: at least one cryptographic application identifier and a preset algorithm; Encrypting each preset session handle and the cryptographic resource identifier corresponding to each preset session handle based on the session management key to obtain a preset session ciphertext; A mapping relationship between each preset session handle and the preset session ciphertext corresponding to each preset session handle is established.
3. The method according to claim 1, characterized in that After sending the target session ciphertext to the cryptographic application, the method further includes: Obtaining a first service parameter received by a first cryptographic device, wherein the first service parameter includes at least: a first cryptographic application identifier and a session ciphertext; Decrypting the session ciphertext based on the session management key, and detecting whether there is an indication that the session ciphertext is successfully decrypted; If yes, determining the session handle and the cryptographic resource identifier in the session ciphertext; If not, it is determined that the decryption has failed.
4. The method according to claim 1, characterized in that After sending the target session ciphertext to the cryptographic application, the method further includes: Obtaining a second service parameter received by the second cryptographic device, wherein the second service parameter includes at least: a first IP address of the first cryptographic device and a session ciphertext; Decrypting the session ciphertext based on the session management key, determining a session handle corresponding to the session ciphertext, and detecting whether there is a preset session handle consistent with the session handle in the mapping relationship; If so, determining the cryptographic resource identifier corresponding to the session ciphertext, and executing the cryptographic service required by the cryptographic application corresponding to the cryptographic resource identifier; If not, synchronizing the cryptographic resources of the first cryptographic device to the second cryptographic device based on the first IP address.
5. The method according to claim 1, characterized in that After sending the target session ciphertext to the cryptographic application, the method further includes: In response to a session closing instruction sent by the cryptographic application, deleting a target session handle and a target session ciphertext corresponding to the target session ciphertext in the mapping relationship based on the session closing instruction; or A session call time interval is determined, and in response to the session call time interval exceeding a preset session call time interval, a target session handle and a target session ciphertext corresponding to the target session ciphertext are deleted in the mapping relationship, wherein the session call time interval is the interval between the current time and the last session call time.
6. A session management device, characterized in that: The device comprises: A response module, configured to respond to a session establishment request sent by a cryptographic application, wherein the session establishment request at least includes a target cryptographic device corresponding to a session established by the cryptographic application; A ciphertext module, configured to determine a target session handle in the session establishment request, and based on a mapping relationship between a preset session handle and a preset session ciphertext, determine a target session ciphertext corresponding to the target session handle in the target cryptographic device; A sending module is used to send the target session ciphertext to the cryptographic application.
7. The device according to claim 6, characterized in that The response module is specifically used to respond to at least one preset session establishment request, determine the preset session handle and the password resource identifier corresponding to each preset session establishment request, encrypt each preset session handle and the password resource identifier corresponding to each preset session handle based on the session management key to obtain the preset session ciphertext, and establish a mapping relationship between each preset session handle and the preset session ciphertext corresponding to each preset session handle.
8. The device according to claim 6, characterized in that The sending module is specifically used to obtain the first service parameter received by the first cryptographic device, decrypt the session ciphertext based on the session management key, and detect whether there is an indication of successful decryption of the session ciphertext. If so, determine the session handle and cryptographic resource identifier in the session ciphertext; if not, determine that the decryption has failed.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, for implementing the method steps described in any one of claims 1 to 5 when executing the computer program stored in the memory.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 1 to 5 are implemented.