Cloud password service platform and method for server
By generating keys in the cloud server and distributing keys using layer-by-layer protection and Shamir password sharing methods, the security and efficiency of key distribution on the cloud platform are solved, and key management with high security and convenient access is achieved.
Patent Information
- Application Number
- CN202510519735.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-04-24
AI Technical Summary
Key distribution of existing cloud platforms has security and efficiency problems, making it difficult to effectively protect key information.
Keys are generated through cloud servers, and the generated keys are protected layer by layer using random codes and keys. The keys are distributed in segments to multiple application servers using Shamir password sharing method. The complete key can only be rebuilt when specific conditions are met.
It realizes high security protection and convenient acquisition of keys, improves the security and efficiency of the system, and prevents key leakage and unauthorized access.
Smart Images

Figure CN120034332A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and in particular relates to a cloud cryptographic service platform and method for a server. Background Art
[0002] Currently, key distribution on cloud platforms remains a challenging problem.
[0003] CN108540486A discloses a method for generating and using a cloud key, wherein the method includes: receiving a public key of a first key pair and a key generation request sent by a user; generating a second key pair and a random number; encrypting the second key pair by the random number to obtain a first ciphertext of the second key pair; encrypting the random number by the public key of the first key pair to obtain a second ciphertext of the random number; and saving the first ciphertext and the second ciphertext. The present invention generates a key by a cloud server, and uses a random code and a key pair to generate a key for layer-by-layer protection, so that the user can easily obtain the private key of the key, while having high security.
[0004] CN110830242A discloses a key generation, management method and server to solve the technical problem of easy key leakage. The key generation method includes: generating a corresponding key pair at regular intervals, wherein the key pair includes a private key and a public key; dividing the generated private key into multiple private key fragments, storing them in multiple second servers respectively, and sending the generated public key to the target terminal. The key management method includes: storing a corresponding private key fragment; receiving a service request sent by the target terminal that is encrypted using a public key, and determining the terminal identification of the target terminal; obtaining the private key fragments corresponding to the target terminal from each other second server respectively, and splicing them to obtain a complete private key; and performing decryption verification based on the private key. The key generation, management method and server improve the security of user key information.
[0005] CN106603485B discloses a key negotiation method and device. The method includes: generating a first random number, applying the first public key of the cloud server to encrypt the first random number and the identification information of the terminal device to generate a first ciphertext; sending a key negotiation request including the first ciphertext and the second public key of the terminal device to the cloud server; receiving a key negotiation response including the second ciphertext sent after the cloud server verifies the legality of the terminal device, applying the second public key to encrypt the session key including the first random number; applying the second private key to decrypt the second ciphertext, applying the session key to encrypt the first character string pre-negotiated with the cloud server when the first random number is obtained, and sending a key confirmation response including the third ciphertext to the cloud server. The method can complete the two-way identity authentication of the terminal device and the cloud server, and establish a reliable and secure connection, which reduces the cost, improves the security of data transmission and is highly efficient.
[0006] CN116886317B discloses a method, system and device for distributing keys between a server and a terminal device. The method includes: the terminal device and the server respectively generate a key pair after verifying the legitimacy of the received certificate of the other party; the server verifies the legitimacy of the terminal device hardware serial number sent by the terminal device according to the terminal device certificate and the terminal device verifies the legitimacy of the server code according to the server certificate; the terminal device and the server respectively generate an intermediate key according to the private key of the key pair generated by themselves and the public key of the key pair generated by the other party; a protection key is generated according to the intermediate key, the hardware serial number of the terminal device and the server code; the server generates an application master key according to the terminal device information and stores it, encrypts the application master key with the protection key to obtain the application master key ciphertext, and sends the application master key ciphertext to the terminal device; the terminal device decrypts the application master key ciphertext with the protection key to obtain the application master key, and stores the terminal device information and the application master key in correspondence.
[0007] WO2025016183A1 provides a data processing method and related equipment, wherein the method includes: when a service request initiated by an application is detected, a temporary key randomly assigned to the service request is obtained; the temporary key is encrypted using a certificate public key to obtain an encrypted temporary key; the certificate public key is preset in the source code of the application; the certificate private key corresponding to the certificate public key is stored in the server; the request data of the service request is encrypted using a temporary key to obtain a ciphertext; a network response request packet is generated according to the encrypted temporary key and the ciphertext, and a network response request packet is sent to the server, and the network response request packet is used to request the server to respond to the service request. The embodiment of the present application can ensure the data security during data transmission and save the resource overhead of the server.
[0008] Based on the existing technology, we hope to further improve the security of the system. Summary of the invention
[0009] At least one aspect and advantage of the invention will be set forth in part in the description which follows, or may be obvious from the description, or may be acquired by practicing the disclosed subject matter.
[0010] According to one embodiment of the present invention, a cloud cryptographic service method for a server includes: The first terminal sends a first request to the first server; The first server responds to the first request, selects a number of application servers from the first application server list to obtain a first application program interface list, generates first information according to the first application program interface list, sends the first information to the first terminal, and generates a first message based on the first request and the first information, and sends the message to the first application program interface list; The second server generates a cloud password at least in response to the first message, sets the password for the target terminal through the host, and after the setting is completed, segments the cloud password and sends it as a secret to the first application programming interface list; The first terminal obtains key shards based on the first application programming interface list or through the first server, and obtains the cloud password based on the decryption of the key shards.
[0011] According to an embodiment of the present invention, the first request includes a request entity and the public key of the user, and the request entity contains information of the target terminal; The first information is obtained according to the following method: Determine a list of available application servers according to the region where the first terminal is located, select several application servers from the list of application servers to obtain a second server list; determine a list of application programming interface information based on the application servers in the second server list, and generate the first information based on the application programming interface information. The first information includes application programming interface information and the public key of the second server.
[0012] According to an embodiment of the present invention, in response to the number of available application server lists determined according to the region where the first terminal is located being lower than the first threshold, the available application server list determined according to the region where the first terminal is located is used as the second application server list, and the application servers in other regions are sorted in ascending order of distance from the region of the first terminal. The region of the first terminal is determined by its IP address, and the first m items are taken as the third application server list. The first application server list is obtained according to the second application server list and the third application server list, where m is a natural number not exceeding 20.
[0013] According to an embodiment of the present invention, the second server generates a cloud password at least in response to the first message and the second message; The first message contains the target terminal information and the first information in the first request; The process of obtaining the second message includes: The first terminal selects a third server from the first application server list, the first terminal sends second request information to the third server, the third server creates a second message in response to the second request information, and sends it to the second server. The second message contains the public key of the first terminal.
[0014] According to an embodiment of the present invention, when distributing the sub-ciphertext, distribute the m segmented sub-ciphertexts and the access token to the application servers in the fourth application server list, where the fourth application server list is a subset of the application servers corresponding to the first application programming interface list and does not include the third server.
[0015] According to an embodiment of the present invention, the first message includes the target terminal information in the first request, the first information and the public key of the first terminal.
[0016] According to one embodiment of the present invention, the second server sending the cloud password segment as a secret to the first application program interface list includes: The cloud password is encrypted using the public key of the first terminal to obtain an encrypted cloud password, and then the encrypted cloud password is signed using the private key of the second server to obtain an encrypted cloud password signature, and the encrypted cloud password and the password signature are combined to obtain a first ciphertext; The first ciphertext is divided into m segments, and the sub-ciphertexts and access tokens divided into m segments are distributed to the application servers in the first application server list through the application interface in the first application interface list using the Shamir password sharing method. The access token is used by the application server to authenticate the first terminal or the first server.
[0017] According to an embodiment of the present invention, the process of obtaining the encrypted key information by the first terminal information includes: The first terminal sends a sub-ciphertext acquisition request to an application program interface in the first application program interface list; In response to obtaining the sub-ciphertext not less than the first value, the first terminal performs secret recovery; After completely obtaining the secrets distributed by the second server, the obtained secrets are combined and decrypted to obtain the cloud password.
[0018] According to an embodiment of the present invention, the application program interface responds to the token included in the user request corresponding to the stored token, returns the secret as a response, and deletes the request token and the corresponding secret of the first terminal on the application server.
[0019] According to an embodiment of the present invention, the first terminal obtains the key shards based on the first application program interface list or through the first server: The first terminal initiates a ciphertext acquisition request to the first server. The first server responds to the request of the first terminal by obtaining a secret shared by the second server from the second application server, and sends the obtained secret to the first terminal, and generates a third message based on the obtained secret and sends it to the second server.
[0020] According to one embodiment of the present invention, the servers in the second server list send ciphertext fragments, corresponding tokens and saved ciphertext fragments in response to the request of the first terminal or the first application server, and construct a fourth request to send to the second application server. In response to the number of fourth requests reaching a first threshold, the second server sends a fourth message to the servers in the second server list, and the second server deletes the ciphertext in response to the fourth message.
[0021] According to an embodiment of the present invention, the second application server deletes the stored ciphertext in response to a user's request, an instruction of the second server, or when the storage time of the ciphertext reaches a first time threshold. According to one embodiment of the present invention, a cloud cryptographic service platform for a server includes: The first server is configured to respond to a first request sent by a first terminal used by a user, select a plurality of application servers from a first application server list to obtain a first application program interface list, generate first information according to the first application program interface list, send the first information to the first terminal, and generate a first message based on the first request and the first information, and send the message to the first application program interface list; The second server generates a cloud password in response to at least the first message, and sets a password for the target terminal through the host machine, and after the setting is completed, sends the cloud password segment as a secret to the first application program interface list; The first terminal obtains the key slice based on the first application program interface list or through the first server, and obtains the cloud password based on decryption of the key slice.
[0022] The method and system of the present invention can improve the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 This is a flow chart of a cloud cryptographic service method for a server in an embodiment of the present invention; Figure 2 This is a structural diagram of a cloud cryptographic service platform for a server in an embodiment of the present invention. DETAILED DESCRIPTION
[0024] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0025] The terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices. When an application server is used for expression, it means that the corresponding application is deployed on the server. It should also be understood that the loading of new applications can be achieved in the form of hot deployment, or similar functions can be achieved through containerization technology, so that the server provides services in the form of an application server.
[0026] According to one embodiment of the present invention, referring to Figure 1 As shown, a cloud password service method for a server includes: The first terminal sends a first request to the first server; The first server responds to the first request, selects a number of application servers from the first application server list to obtain a first application program interface list, generates first information according to the first application program interface list, sends the first information to the first terminal, and generates a first message based on the first request and the first information, and sends the message to the first application program interface list; The second server generates a cloud password in response to at least the first message, and sets a password for the target terminal through the host machine, and after the setting is completed, sends the cloud password segment as a secret to the first application program interface list; The first terminal obtains the key slice based on the first application program interface list or through the first server, and obtains the cloud password based on decryption of the key slice.
[0027] Among them, the first terminal is a terminal used by the user, which can be a browser, application App or developer SDK; usually, when the user logs in to the cloud server website, he will obtain a temporary credential, namely a token, which is used to indicate the user's identity. In the following text, the first terminal uses the user token for authentication. Since the setting of the cloud password is usually performed within a cloud service platform, a unified token can be used; in some situations, the user's token is variable, which can be dynamically generated by the server or generated locally by the user.
[0028] When the user resets the password or dynamically generates a password, or generates passwords in batches, the first terminal sends a first request to the first server. The first server here can be preset by the application, or a server built into the SDK, or a request application server corresponding to a function triggered by a user operation.
[0029] The first terminal can be configured with its own certificate or key for encryption and decryption, wherein the user's public key can be temporary, for example, generated in a session and then destroyed after the session ends, thereby achieving secure transmission of information. Accordingly, during a session, it is expected that secure communication or signature can be achieved by transmitting the public key to the corresponding server.
[0030] The first server selects an application server that can respond to the first terminal in response to the first request, and these application servers implement the distribution of cloud passwords based on Shamir secret sharing. The first application interface is used to send the ciphertext information of the stored slices in response to the request of the first terminal or the first server, and then the first server or the first terminal decrypts the ciphertext of each slice to obtain the cloud password. To this end, the number of the selected first application interfaces should be greater than the minimum number of secret holders required for decryption, and further, considering that the first terminal may not be able to access some application service interfaces, such as the corresponding application service running on an ipv6 server, and the first terminal does not support the ipv6 protocol, or the first terminal cannot access it due to network reasons, then a larger value should be considered, that is, the user can flexibly select the number of first application interfaces according to the requirements of the security level. If it is set to 20, 20 are selected from the corresponding available application interfaces as the first application interface list. Those skilled in the art can understand that in order to achieve secret sharing and communication, the application interfaces running on these application servers must be able to communicate with the first server and the second server, and accept requests from the first terminal.
[0031] Furthermore, the first server first responds to the first terminal, that is, notifies that the request has been created and the list of second servers that the first terminal can access. In most cases, it is not desirable for the first terminal to access the interfaces in the first application interface list, such as when the user's device may be located in a public network. In this case, the generated first message may not include specific information about the interface, but only information such as the number of servers generated based on the first application interface list. In an internal corporate network, users can access interfaces in the first application interface list without causing significant information security risks. In this case, the response interface information can be returned to the first terminal as the content of the first message. Afterwards, the first server sends a request to create information to the second server. In general, the second server is isolated from the first terminal, or the second server does not directly provide an interface that can be accessed by the first terminal, such as controlling user access by configuring allowed host information; the information sent by the first server to the second server includes content created based on the first request and the first information, wherein the first request is used to indicate the cloud host corresponding to the task of creating a cloud password, which is usually a string, and may further include user token information to determine whether the user has the authority to operate the cloud host. In the present invention, it further includes first application interface list information, so that the second server can distribute the corresponding cloud password to the second application interface list after generating the cloud password, so that the first terminal can obtain the corresponding cloud password after decryption.
[0032] In most scenarios, you can configure the TLS communication mode between each communicating part, and on this basis further use encryption to obtain better information security to reduce information leakage.
[0033] The host machine is a physical computer or server running virtualization software or container management program, which is responsible for providing hardware resources and managing the operation of virtual machines or containers. It sets or resets passwords through the SDK provided by the platform. In some cases, the cloud host needs to be shut down to set or reset passwords. At this time, it may fail to generate a new password due to the failure to shut down. Therefore, for systems that run cloud hosts and must shut down to change passwords, you can choose to check the status of the cloud host before performing password operations. After setting or resetting the password, the new cloud password can be processed and distributed to the first application program interface by calling the API. For example, a cloud password (19 bits) can be divided into 10 parts, and at least 4 parts are required to reconstruct the secret. The corresponding cloud password is first converted into binary or other processable methods, and then a polynomial is constructed to calculate the secret value of each character or fragment. For example, when calculated by character, the secret corresponding to one character is generally less than 128, and if the secret value is the value corresponding to two characters, the corresponding secret value will be higher than 128. Generally speaking, the time required to set and distribute passwords is short, and can generally be completed within a few seconds. Therefore, the first terminal or the first server can obtain each secret after a fixed time, such as 6 seconds, and restore the message based on the obtained secret.
[0034] Taking the ciphertext above as an example, after the cloud password is segmented, a series of secrets are obtained. These secrets are distributed to the first application interface. The first terminal or the first server can obtain a series of messages by accessing the interface. After each secret is obtained, a password segment can be obtained by decryption. All the password segments are combined to obtain the original password. If a cloud password has 20 secrets to be shared, the first terminal or the first server will perform 20 secret reconstructions. If any one fails, it means that an attack may occur, and the user should take other security actions.
[0035] Obviously, what is sent to the first application program interface list may be a fragment of the password or encrypted information. For example, in one process, the second server may further use the public key of the first terminal to encrypt the password, and then sign the obtained message using the private key. The obtained encrypted message and signature are shared as secrets.
[0036] This method can improve the safety factor of the system.
[0037] According to one embodiment of the present invention, the first request includes a requesting entity and a public key of a user, and the requesting entity includes information of a target terminal; The first information is obtained according to the following method: Determine a list of available application servers according to the region where the first terminal is located, select several application servers in the application server list to obtain a second server list; determine an application interface information list according to the application servers in the second server list, and generate first information based on the application interface information, wherein the first information includes the application interface information and a public key with the second server.
[0038] The first server can select a suitable server based on the region to provide a faster response speed. When a user makes a creation request, it is generally for a server in a specific region, such as "Tianjin District 1", "Guangzhou District 2", and "Beijing District 3". An application interface server can be selected based on the region to provide services; the user's request entity can include the ID of the server to be reset; since the user's information can be retrieved on the server side, in most cases it is necessary to provide the user's terminal information and user authentication information, such as the user token information mentioned above, to complete the identification of the user.
[0039] Furthermore, the region where the first terminal is located is obtained according to its actual IP address, for example, the first two digits of an IP address in the form of xx.xx.xx.xx are obtained through an IP address database to obtain the region where the user is located, and then a registered application server is obtained in the corresponding region.
[0040] Furthermore, the user's public key can be provided to the first server and the key can be synchronized to the second server, so that when the second server distributes the cloud password, the distributed information is encrypted ciphertext, and the encrypted information can only be read by the first terminal. In order to prevent the information from being forged, the first server can send the public key of the second server it stores as a component of the first information to the first terminal, so that the first terminal can verify the signature of the decrypted message based on secret sharing.
[0041] Furthermore, the application interface information list can be provided in the form of URL:port, where URL is the address of the application server and port is the corresponding port. The corresponding information can be obtained through POST or get method, or through a restful call. When the first terminal accesses the interface, a corresponding token can be provided to obtain the corresponding resources. For example, the user token included in the first request can be provided to the corresponding application interface through the second server for verification, or the second server can generate a new user token for use by the first terminal or the first server to obtain the corresponding information.
[0042] In one embodiment of the present invention, the first message further includes a public key of the second server. The public key of the second server is periodically synchronized to the first server, or is obtained from the second server upon request before generating the first message.
[0043] This method can further ensure the security of information.
[0044] According to an embodiment of the present invention, in response to the number of available application servers determined according to the region where the first terminal is located being lower than a first threshold, the list of available application servers determined according to the region where the first terminal is located is used as the second server list, and application servers in other regions are sorted from near to far according to the distance from the region of the first terminal, the region of the first terminal is determined by its IP address, and the first m items are taken as the third server list, and the first application interface list is obtained according to the second application server list and the third application server list; and the first application server list is obtained according to the application information provided by it, and m is a natural number not exceeding 20. The first application interface list can be obtained by merging (if 20 items are required and the number of second application servers is 12, then 8 servers are taken from the second application server to construct the first application interface list), or by merging the set and then randomly removing elements.
[0045] In this way, the number of people for secret distribution can meet the demand, that is, the first server determines the first application server list based on the region where the first terminal is located and the adjacent region where the first terminal is located. However, it should be noted that such processing may lead to a potential increase in response time, so the available servers in the region can be arranged according to the number of requests required.
[0046] According to one embodiment of the present invention, the second server generates a cloud password in response to at least the first message and the second message; The first message includes the target terminal information and the first information in the first request; The process of obtaining the second message includes: The first terminal selects a third server from the first application server list, and sends a second request message to the third server. The third server creates a second message in response to the second request message and sends it to the second server. The second message includes the public key of the first terminal.
[0047] In this way, the request to create a cloud password can be established based on a channel different from the first server, and the corresponding server can also establish a verification mechanism. When a first message and a second message are received, the cloud password will be created and distributed. If other terminals other than the first terminal create the second message, the user will not be able to create a cloud password, that is, the user will receive a prompt. If other users construct similar requests after the first message and the second message are sent (such as creating a third message similar to the second message), the second server will refuse to respond to illegal requests because it lacks the new first message corresponding to the third message, thereby improving the security factor.
[0048] According to one embodiment of the present invention, when distributing sub-ciphertexts, the sub-ciphertexts divided into m segments and the access token are distributed to application servers in a fourth application server list, wherein the fourth application server list does not include the third application server.
[0049] In this way, the application server that acts as a "bridge" can be excluded from the scope of secret sharing, further improving the security factor. It should be understood that the selected third application server can be an application server corresponding to the application interface in the first application interface list, or it can be other servers, such as resources pre-configured on the page in other forms.
[0050] According to an embodiment of the present invention, the first message includes the target terminal information in the first request, the first information and the public key of the first terminal.
[0051] By configuring the first message to include the target terminal information in the first request, authentication information can be provided to avoid unauthorized access; by providing the first information, the second server can distribute the secret to the first terminal or a terminal known to the first server, so that the secret distribution is carried out in a controlled manner; by providing the public key of the first terminal, secondary encryption of the cloud password can be achieved to improve the security factor.
[0052] According to one embodiment of the present invention, the second server encrypts the cloud password and sends the encrypted cloud password to the first application program interface list in segments, including: The cloud password is encrypted using the public key of the first terminal to obtain an encrypted cloud password, and then the encrypted cloud password is signed using the private key of the second server to obtain an encrypted cloud password signature, and the encrypted cloud password and the password signature are combined to obtain a first ciphertext; The first ciphertext is divided into m segments, and the sub-ciphertexts and access tokens divided into m segments are distributed to the application servers in the first application server list through the application interface in the first application interface list using the Shamir password sharing method. The access token is used by the application server to authenticate the first terminal or the first server.
[0053] In this way, encrypted information can be transmitted, and only the first terminal can read the information.
[0054] In another embodiment of the present invention, the second server encrypts the cloud password and sends it in segments to the servers in the second server list, including: The cloud password is divided into n segments, and the n-segmented password is encrypted using the public key of the first terminal to obtain a series of password fragments. The password fragments are then signed using the private key of the second server to obtain signatures corresponding to the password fragments, and the password fragments and the corresponding signatures are combined to obtain a first sequence to be distributed; Then, the first sequence to be distributed is traversed, each element thereof is divided into m segments, and the sub-ciphertexts and access tokens divided into m segments are distributed to the application servers in the second server list through the application program interface in the first application program interface list by using the Shamir password sharing method, wherein the access token is used for the application server to authenticate the first terminal or the first server; The first terminal or the first server obtains the corresponding secret from the second server list, and decrypts the secrets to obtain the secret value, and combines multiple secret values to obtain a password fragment and summary after encryption, and then verifies the signature with the public key of the second server. If the signature is correct, the encrypted password fragment is decrypted with the private key of the first terminal to obtain a password fragment, and all the password fragments are combined to obtain the complete cloud password. This method further improves security performance by adding password encoding and transmission rules.
[0055] It should be understood that the access token here can be consistent with the user's token, or it can be a newly generated token by the second server. If it is the latter, the token generated by the second server can be sent to the first server, and the first terminal can obtain the access token through query or two-way communication; if it is the former, each application server can prevent a message from being obtained by multiple terminals by deleting the token in combination with the access number limit. For example, after the first terminal completes the access, the acceptable token is deleted, and other terminals cannot obtain the secret information, or other terminals obtain the next secret information when accessing. After obtaining the message, the first terminal will prompt a failure when continuing to access, thereby prompting the user that there is a security risk.
[0056] According to an embodiment of the present invention, the process of the first terminal acquiring the encrypted key information includes: The first terminal sends a sub-ciphertext acquisition request to an application program interface in the first application program interface list; In response to obtaining the sub-ciphertext not less than the first value, the first terminal performs secret recovery; After completely obtaining the secrets distributed by the second server, the obtained secrets are combined and decrypted to obtain the cloud password.
[0057] Through this process, the first terminal can obtain the complete password.
[0058] It should be understood that this process is performed multiple times. For example, when a first terminal sends a sub-ciphertext acquisition request to an application program interface in the application program interface list of a second server, the json object returned may contain the total number of secrets. The first terminal may obtain secrets from multiple application program interfaces multiple times or successively, and obtain secret values based on the restoration of the secrets. After completing the restoration of the secret values consistent with the number of secrets on the second server, the secret values may be combined to obtain the encrypted cloud password. The first value mentioned above is the minimum number of sub-ciphertexts required to restore the secret.
[0059] According to an embodiment of the present invention, the application program interface responds to the token included in the user request corresponding to the stored token, returns the secret as a response, and deletes the request token and the corresponding secret of the first terminal on the application server.
[0060] In this way, the application server can always save one or more acceptable number of secrets to prevent the secret from being read by multiple people. After a secret is read, other terminals cannot obtain the same message. If combined with global information, such as the number of times a secret is read, combined with the reading record reported by the first terminal or the first server, security can be further improved.
[0061] According to an embodiment of the present invention, the first terminal obtains the key shards based on the first application program interface list or through the first server: The first terminal initiates a ciphertext acquisition request to the first server. The first server responds to the request of the first terminal by obtaining a secret shared by the second server from the second application server, and sends the obtained secret to the first terminal, and generates a third message based on the obtained secret and sends it to the second server.
[0062] In this way, the secret distributed by the second server is sent to the first terminal through the first server; at the same time, after obtaining the secret that meets the requirements for restoring the secret value, the first server generates a message based on the obtained secret and sends it to the second server. The second server can delete the secret that has been obtained by the first terminal through the application interface in the first application interface list, thereby improving the security factor.
[0063] According to one embodiment of the present invention, the servers in the second server list send ciphertext fragments, corresponding tokens and saved ciphertext fragments in response to the request of the first terminal or the first application server, and construct a fourth request and send it to the second server. In response to the number of fourth requests reaching a second threshold, the second server sends a fourth message to the servers in the second server list, and the second server deletes the ciphertext in response to the fourth message.
[0064] In this way, when the number of secret requests associated with the same secret value by the user reaches the minimum threshold required for decryption, secret sharing is stopped and the secret is deleted. The second threshold is not less than the minimum number of secrets required to recover the secret. In most cases, it is the minimum number of secrets required to recover the secret.
[0065] According to an embodiment of the present invention, the second server deletes the stored ciphertext in response to a user's request, an instruction of the second server, or when the storage time of the ciphertext reaches a first time threshold. This method can ensure the controllability of secret access. Among them, the secret is deleted in response to the user's request. The deletion in response to the instruction of the second server can stop secret sharing and delete the secret when the number of secret requests associated with the same secret value by the user reaches the minimum threshold required for decryption. To achieve this function, the secret request record can be sent to the second server at the same time when each application interface responds to the request; setting a timeout deletion can clear the secret within an expected time, such as deleting the saved secret within 500ms.
[0066] According to one embodiment of the present invention, referring to Figure 2 As shown, a cloud cryptographic service platform for a server includes: The first server is configured to respond to a first request sent by a first terminal used by a user, select a plurality of application servers from a first application server list to obtain a first application program interface list, generate first information according to the first application program interface list, send the first information to the first terminal, and generate a first message based on the first request and the first information, and send the message to the first application program interface list; The second server generates a cloud password in response to at least the first message, and sets a password for the target terminal through the host machine, and after the setting is completed, sends the cloud password segment as a secret to the first application program interface list; The first terminal obtains the key slice based on the first application program interface list or through the first server, and obtains the cloud password based on decryption of the key slice.
[0067] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on an electronic device, the electronic device executes the aforementioned method.
[0068] An embodiment of the present application further provides a computer program product, including: a computer program code, when the computer program code is executed on an electronic device, the electronic device executes the aforementioned method.
[0069] An embodiment of the present application further provides a chip, comprising: a processor, configured to call and run a computer program from a memory, so that an electronic device equipped with the chip executes the aforementioned method.
[0070] Through the description of the above implementation mode, those skilled in the art can understand that for the convenience and simplicity of description, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0071] It should be understood that the devices and processes disclosed in the several embodiments provided in the present application can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device. In addition, some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0072] The units described as separate components may or may not be physically separated. The components shown as units may be one physical unit or multiple physical units. That is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected to achieve the purpose of this solution according to actual needs.
[0073] In addition, each functional unit in each embodiment of the present application may be integrated into a processing unit; or may exist physically separately; or some units may be integrated into one unit, and some units may exist physically separately. The above-mentioned integrated units may be implemented in the form of hardware or in the form of software functional units.
[0074] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, all or part of the technical solution of the embodiment of the present application can be embodied in the form of a software product. The software product is stored in a storage medium. The software product includes several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor to perform all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.
[0075] It should be noted that all or part of the above-mentioned embodiments provided in the present application (for example, part or all of any feature) can be arbitrarily combined or used in combination with each other.
[0076] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A cloud cryptographic service method for a server, characterized in that: include: The first terminal sends a first request to the first server; The first server responds to the first request, selects a number of application servers from the first application server list to obtain a first application program interface list, generates first information according to the first application program interface list, sends the first information to the first terminal, and generates a first message based on the first request and the first information, and sends the message to the first application program interface list; The second server generates a cloud password in response to at least the first message, and sets a password for the target terminal through the host machine, and after the setting is completed, sends the cloud password segment as a secret to the first application program interface list; The first terminal obtains the key slice based on the first application program interface list or through the first server, and obtains the cloud password based on decryption of the key slice.
2. A cloud cryptographic service method for a server as claimed in claim 1, characterized in that: The first request includes a requesting entity and a public key of a user, and the requesting entity includes information of a target terminal; The first information is obtained according to the following method: Determine a list of available application servers according to the region where the first terminal is located, select several application servers in the application server list to obtain a second server list; determine an application interface information list according to the application servers in the second server list, and generate first information based on the application interface information, wherein the first information includes the application interface information and a public key with the second server.
3. A cloud cryptographic service method for a server as claimed in claim 2, characterized in that: In response to the number of available application server lists determined according to the region where the first terminal is located being lower than a first threshold, the available application server list determined according to the region where the first terminal is located is used as the second application server list, application servers in other regions are sorted from near to far according to the distance between them and the region of the first terminal, the region of the first terminal is determined by its IP address, and the first m items are taken as the third application server list, and the first application server list is obtained according to the second application server list and the third application server list, where m is a natural number not exceeding 20.
4. A cloud cryptographic service method for a server as claimed in claim 1, characterized in that: The second server generates a cloud password in response to at least the first message and the second message; The first message includes the target terminal information and the first information in the first request; The process of obtaining the second message includes: The first terminal selects a third server from the first application server list, and sends a second request message to the third server. The third server creates a second message in response to the second request message and sends it to the second server. The second message includes the public key of the first terminal.
5. A cloud cryptographic service method for a server as claimed in claim 4, characterized in that: When distributing the sub-ciphertext, the sub-ciphertext divided into m segments and the access token are distributed to the application servers in the fourth application server list, wherein the fourth application server list is a subset of the application servers corresponding to the first application program interface list and does not include the third application server.
6. A cloud cryptographic service method for a server as claimed in claim 1, characterized in that: The first message includes the target terminal information in the first request, the first information and the public key of the first terminal.
7. A cloud cryptographic service method for a server as claimed in claim 1, characterized in that: The second server sends the cloud password segment as a secret to the first application program interface list including: The cloud password is encrypted using the public key of the first terminal to obtain an encrypted cloud password, and then the encrypted cloud password is signed using the private key of the second server to obtain an encrypted cloud password signature, and the encrypted cloud password and the password signature are combined to obtain a first ciphertext; The first ciphertext is divided into m segments, and the sub-ciphertexts and access tokens divided into m segments are distributed to the application servers in the first application server list through the application interface in the first application interface list using the Shamir password sharing method. The access token is used by the application server to authenticate the first terminal or the first server.
8. A cloud cryptographic service method for a server as claimed in claim 7, characterized in that: The process of obtaining the encrypted key information by the first terminal information includes: The first terminal sends a sub-ciphertext acquisition request to an application program interface in the first application program interface list; In response to obtaining the sub-ciphertext not less than the first value, the first terminal performs secret recovery; After completely obtaining the secrets distributed by the second server, the obtained secrets are combined and decrypted to obtain the cloud password.
9. A cloud cryptographic service method for a server as claimed in claim 8, characterized in that: The application program interface responds to the token included in the user request corresponding to the stored token, returns the secret as a response, and deletes the request token and the corresponding secret of the first terminal on the application server.
10. A cloud cryptographic service platform for a server, characterized in that: include: The first server is configured to respond to a first request sent by a first terminal used by a user, select a plurality of application servers from a first application server list to obtain a first application program interface list, generate first information according to the first application program interface list, send the first information to the first terminal, and generate a first message based on the first request and the first information, and send the message to the first application program interface list; The second server generates a cloud password in response to at least the first message, and sets a password for the target terminal through the host machine, and after the setting is completed, sends the cloud password segment as a secret to the first application program interface list; The first terminal obtains the key slice based on the first application program interface list or through the first server, and obtains the cloud password based on decryption of the key slice.
Citation Information
Patent Citations
Key negotiation method and apparatus
CN106603485B
Cloud key generation and application method
CN108540486A
Key generation and management method and server
CN110830242A
A method, system, and device for distributing keys between a server and a terminal device.
CN116886317B
Data processing method and related device
WO2025016183A1
Cited By
Distributed system password service platform and method supporting secure access and resource management and control
CN121690534A