Full lifecycle key management service method and system supporting KMIP protocol
By using authentication keys, biometric library and random configuration models in user authentication and key management, the problems of low key security and irregular life cycle management are solved, achieving higher data security and authentication reliability.
Patent Information
- Application Number
- CN202510488378.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2045-04-18
AI Technical Summary
In the prior art, the low security of keys, irregular life cycle management, and unreliable user identity authentication lead to insufficient data security.
By creating a user's authentication key and biometric library, using trusted three-party storage and verification of user identity, creating and distributing key pairs in combination with a random configuration model, and performing device binding and behavior monitoring, ensuring the security and compliance of the keys over the life cycle.
Improves interoperability of key management and reliability of user authentication, enhances data security, and prevents key leakage and unauthorized access.
Smart Images

Figure CN120034395B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field related to key management, and specifically to a full life cycle key management service method and system supporting the KMIP protocol. Background Art
[0002] With the rapid development of information technology, data security has become a focus of attention across various industries. The importance of key management in data storage, transmission, and processing has become increasingly prominent. Traditional key management methods have many drawbacks, such as insufficient key security, which makes them vulnerable to attacks and data leaks; and irregular key lifecycle management, which makes it difficult to meet the strict requirements for key creation, distribution, use, and destruction in complex business scenarios. The KMIP protocol is committed to providing a standardized key management interaction method to promote interoperability between key management systems from different manufacturers. However, in actual applications, it is difficult to ensure reliable verification of user identities, and it is impossible to guarantee the security and compliance of keys throughout their lifecycle, which in turn affects the accuracy and security of key lifecycle management.
[0003] Therefore, at the current stage, relevant technologies have technical problems such as low key security, irregular lifecycle management, and unreliable user identity authentication, which in turn lead to insufficient data security. Summary of the Invention
[0004] This application solves the technical problems in the existing technology of low key security, irregular lifecycle management and unreliable user identity authentication, which lead to insufficient data security, by providing a full lifecycle key management service method and system that supports the KMIP protocol. It achieves the technical effect of improving key management interoperability, enhancing user identity authentication and data security.
[0005] The present application provides a full lifecycle key management service method supporting the KMIP protocol, the method comprising: creating a user's authentication key, and configuring an entity key and a user biometric library mapped to the authentication key, respectively storing the authentication key, the user biometric library, and the verification key pair in different trusted third parties, wherein the verification key pair is a key for performing entity key verification; after performing user authentication using the trusted third party, establishing authentication trust and reading the user's scheduled tasks, and detecting the current operating status of the user's device; after parsing the scheduled tasks and the current operating status, inputting the parsing results and the authentication trust as input data into a random configuration model to establish random configuration constraints; creating a key pair using the random configuration constraints, and distributing the key pair to the user device and the target file respectively; after the key pair is successfully paired, allowing the user device to read the target file, and destroying the key pair at the end of the validity period.
[0006] In a possible implementation, the full lifecycle key management service method that supports the KMIP protocol also performs the following processing: extracting the task level characteristics, data sensitivity characteristics, and device trusted status characteristics of the parsing results through the preprocessing layer; normalizing the task level characteristics, data sensitivity characteristics, device trusted status characteristics, and authentication trust, and establishing first input data; inputting the first input data into the calculation layer of the random configuration model to establish a calibration configuration constraint; introducing a random factor based on the data sensitivity characteristics, and establishing a second input data with the random factor; and randomly compensating the calibration configuration constraint with the second input data to establish the random configuration constraint.
[0007] In a possible implementation, the full life cycle key management service method that supports the KMIP protocol also performs the following processing: after the user device receives the key pair, a unique device binding instruction is triggered; the device identifier of the target device is read according to the unique device binding instruction, the device identifier and the key pair are used for fusion binding, and the key pair is updated; after reading the target file, the key pair distributed to the target file is verified using the updated key pair. If the key pairs match and the device binding verification passes, the key pair is paired successfully.
[0008] In a possible implementation, the full life cycle key management service method that supports the KMIP protocol also performs the following processing: after the key pair is successfully paired, temporary access rights to the target file are enabled on the user device, and device behavior monitoring is simultaneously enabled; the device behavior monitoring results are used to identify abnormal behavior of the user device and establish cumulative abnormality points; after the cumulative abnormality points meet the preset requirements, the validity period of the key pair is ended and the user device's access to the target file is stopped.
[0009] In a possible implementation, the full life cycle key management service method that supports the KMIP protocol also performs the following processing: obtaining the user's input verification account; reading the user's input identity authentication key and the user's entity key, synchronously performing the user's biometric collection, and establishing a real-time biometric set; packaging the input verification account with the input identity authentication key, the entity key reading result, and the real-time biometric set, and sending them to the corresponding trusted three parties; obtaining the verification receipt of the trusted three parties, and when the verification results returned by all the trusted three parties are passing results, the identity authentication is passed.
[0010] In a possible implementation, the full lifecycle key management service method that supports the KMIP protocol also performs the following processing: establishing the user's access record and generating an access security evaluation; using the access record and access security evaluation to generate an additional verification database; and optimizing the user's subsequent access verification key based on the additional verification database.
[0011] In a possible implementation, the full life cycle key management service method that supports the KMIP protocol also performs the following processing: determining whether the security level of the scheduled task is lower than a preset security threshold; when the security level is lower than the security threshold, generating a general key access verification; and performing user verification management based on the general key access verification.
[0012] The present application also provides a full life cycle key management service system that supports the KMIP protocol, and the system includes: an authentication key creation module, which is used to create a user's authentication key, and configure an entity key and a user biometric library mapped to the authentication key, and store the authentication key, the user biometric library and the verification key pair in different trusted third parties, respectively, wherein the verification key pair is a key for performing entity key verification; a device operation status detection module, which is used to establish authentication trust and read the user's appointment task after using the trusted third party to authenticate the user, and detect the current operation status of the user's device; a random configuration constraint establishment module, which is used to parse the appointment task and the current operation status, and input the parsing result and the authentication trust as input data into a random configuration model to establish a random configuration constraint; a key pair creation module, which is used to create a key pair using the random configuration constraint, and distribute the key pair to the user device and the target file respectively; a target file reading module, which is used to allow the user device to read the target file after the key pair is successfully paired, and destroy the key pair at the end of the validity period.
[0013] The proposed full-lifecycle key management service method and system supporting the KMIP protocol will create a user's authentication key, configure a physical key, and configure a user biometric database. This will utilize a trusted third party to authenticate the user, establish authentication trust, read the user's scheduled tasks, and detect the current operating status of the user's device. The scheduled tasks and current operating status will be analyzed, and random configuration constraints will be established using a random configuration model. Key pairs will be created and distributed to the user's device and target file. The user's device will be allowed to read the target file, and the key pair will be destroyed at the end of its validity period. This method addresses the technical issues of low key security, irregular lifecycle management, and unreliable user authentication in existing technologies, which in turn lead to insufficient data security. This approach achieves the technical benefits of improving key management interoperability, enhancing user authentication, and strengthening data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings of the embodiments of the present disclosure are briefly introduced below. Flowcharts are used in this application to illustrate the operations performed by the systems according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed in precise order. Instead, various steps may be processed in reverse order or simultaneously as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.
[0015] Figure 1 A flowchart of a full lifecycle key management service method supporting the KMIP protocol provided in an embodiment of the present application.
[0016] Figure 2 A schematic diagram of the structure of a full-lifecycle key management service system supporting the KMIP protocol provided in an embodiment of the present application.
[0017] Description of the reference numerals: identity authentication key creation module 10 , device operation status detection module 20 , random configuration constraint establishment module 30 , key pair creation module 40 , target file reading module 50 . DETAILED DESCRIPTION
[0018] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below.
[0019] In order to make the purpose, technical solutions and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limiting this application. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0020] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict, and the terms “first\second” involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. The terms “including” and “having” and any variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or server that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or modules that are not clearly listed or that are inherent to these processes, methods, products or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs. The terms used herein are for the purpose of describing the embodiments of this application only.
[0021] The present invention provides a full life cycle key management service method that supports the KMIP protocol, such as Figure 1 As shown, the method includes:
[0022] Step S100: Create a user's authentication key, and configure an entity key and a user biometric library mapped to the authentication key, and store the authentication key, the user biometric library and the verification key pair in different trusted parties, respectively. The verification key pair is a key for performing entity key verification.
[0023] Preferably, a user authentication key is created, i.e., a key for authentication is generated for each user. This key is equivalent to the user's digital identity token. When the user performs various operations, the key is verified to confirm the user's identity compliance. Furthermore, a physical key and a user biometric database mapped to the authentication key are configured. The physical key is associated with the authentication key and used to perform operations such as encryption and decryption on actual data. Only after authentication is passed can the corresponding physical key be obtained and the relevant data processed. Biometric information of the user, such as fingerprints, facial features, and irises, is collected and stored. Biometric information is unique and non-replicable and can be used for authentication. The authentication key, user biometric database, and verification key pair are then stored in three different trusted parties (three independent and reliable storage parties) to prevent the leakage of all critical information due to a single point of failure or attack. For example, if this critical information is stored in a centralized location, once that storage point is attacked, all sensitive information may be leaked, posing a serious security risk. The verification key pair, consisting of a public key and a private key, is used to verify the physical key, ensuring its authenticity and integrity and preventing it from being tampered with or forged.
[0024] Preferably, if a bank wants to provide secure online banking services to its customers, it creates an authentication key for each user, similar to a special key that only users holding this key can log in. At the same time, the bank collects the customer's fingerprint information, facial features, and other information to establish a user biometric database. The authentication key is stored on an authentication server, the user biometric database is stored in a biometric recognition database, and the verification key pair is stored on another secure key management server. When a customer logs in to the online banking service, the authentication key entered by the customer is first verified. Then, the customer's fingerprint information or facial features are compared using biometric recognition technology. If the verification is successful, the verification key pair is used to confirm the validity of the physical key. Finally, the customer can use the physical key to encrypt and decrypt their account information. By distributing key information across different trusted third parties, the risk of concentrated attacks is reduced. Even if the data of one of the trusted third parties is leaked, the attacker cannot obtain the complete authentication information and physical key, thereby effectively protecting the user's privacy and data security. Furthermore, using the biometric database for authentication further enhances the accuracy and reliability of authentication.
[0025] Furthermore, step S100 also includes step S110, establishing the user's access record and generating an access security evaluation; step S120, generating an additional verification database using the access record and access security evaluation; step S130, optimizing the user's subsequent access verification key based on the additional verification database.
[0026] Preferably, each access behavior of the user is recorded in detail to form an access record, which usually includes the access time (recording when the user performs the access operation, such as the specific year, month, day, hour, minute, and second), the access location (determining the geographical location of the user when accessing the system through the IP address, etc., or a specific network environment, such as the company intranet, home network, etc.), the access content (clarifying which system resources the user has accessed, such as specific files, functional modules, etc.) and the access operation (recording which operations the user has performed during the access process, such as reading, modifying, deleting, etc.); based on the access record, the security of each access is evaluated, including checking whether the user's access operation complies with the system regulations and permission settings, judging whether the access time is consistent with the user's normal usage habits, and checking whether the access location is consistent with the user's previous access location, thereby generating an access security evaluation.
[0027] Preferably, the collected access records and the generated access security evaluation are integrated to generate an additional verification database, i.e., a user behavior profile, which stores the user's historical access information and the corresponding security evaluation results, thereby better understanding the user's normal access pattern or potential security risks. When the user accesses, the verification key is optimized in combination with the information in the additional verification database. Specifically, this may include dynamically adjusting the verification strength. For example, if the user's historical access behavior has always been good and the security evaluation is high, the system can appropriately reduce the verification strength, such as simplifying the verification process or reducing verification factors, to improve the user experience. Conversely, if there are abnormalities in the user's access record and the security evaluation is low, the system will increase the verification strength, such as requiring the user to provide more authentication information or perform more complex verification operations. The system also includes periodic or irregular updates of the user's verification key based on the user's access pattern and security risk to prevent the key from being leaked or abused. For example, if a user recently logged in from an unfamiliar IP address, the system may require the user to use more verification methods such as SMS verification code and fingerprint recognition to ensure the authenticity of their identity, thereby optimizing the use of the verification key and improving the security of the system.
[0028] Step S200: After the user's identity is authenticated by a trusted third party, the identity authentication trust is established, the user's scheduled tasks are read, and the current operating status of the user's device is detected.
[0029] Preferably, a trusted third party is used to authenticate the user. This involves obtaining relevant information from three trusted parties for comprehensive verification, including preliminary confirmation of the user's identity using an authentication key; comparing data from the user's biometric database, such as fingerprints and facial features, with the user's currently provided biometrics; and verifying the validity of the physical key using a verification key pair. Only when all three verifications are successful is the user's authentication considered successful. After authentication is complete, the credibility of the authentication is assessed based on the strength of the authentication methods used, the user's historical authentication history, and environmental factors (such as the security of the user's network environment and whether the user's geographic location is consistent with past logins). This determines the trustworthiness of the authentication attempt and establishes a confidence level. Specifically, if multiple strong authentication methods are used, such as biometrics combined with complex password verification, the trust level is likely to be high, while if only a simple password is used, the trust level is relatively low. If the user's previous authentication process has been smooth and unannounced, the trust level will increase. Conversely, if a user has experienced authentication failures or abnormal logins, the trust level will decrease. If the network environment is secure and the login location is normal, the trust level will increase. If the network is risky or the login location is abnormal, the trust level will decrease.
[0030] Preferably, the user's scheduled tasks are read, which may include file access requests, data processing tasks, etc., to understand the user's needs and determine the user's next operations, and then the status of the device used by the user is detected, mainly including detecting the device security, device performance, device software environment, etc. Specifically, check whether the device has installed effective anti-virus software, firewall and other security protection software, and whether these software are in normal operation. If the device has security vulnerabilities or is infected by viruses, it may affect the security of the system; evaluate the hardware performance of the device, such as CPU usage, memory usage, etc. If the device performance is too low, it may not be able to execute subsequent tasks normally, or there may be problems such as freezes and errors during the execution of tasks; check whether the versions of the operating system and application installed on the device meet the system requirements. For example, some systems may require that the operating system version of the user's device is not lower than a specific version, otherwise it may not work properly.
[0031] Furthermore, step S200 also includes step S210, obtaining the user's input verification account; step S220, reading the user's input identity authentication key and the user's physical key, synchronously performing the user's biometric collection, and establishing a real-time biometric set; step S230, packaging the input verification account with the input identity authentication key, the physical key reading result, and the real-time biometric set, and sending them to the corresponding trusted third parties; step S240, obtaining the verification receipt of the trusted third parties. When the verification results returned by all the trusted third parties are pass results, the identity authentication is passed.
[0032] Preferably, the user's input verification account is obtained, that is, information that uniquely identifies oneself, such as user name, mobile phone number, email address, etc. After receiving the input verification account, it is used as the basic identifier of the verification operation to find and match relevant user information; then the user's input identity authentication key is read, prepared to be compared with the stored correct key, and the user's physical key is read to verify the validity of the identity; at the same time, the user's biometric features, such as fingerprints, facial features, irises, etc., are collected through corresponding devices (such as fingerprint recognition devices, cameras, etc.), and the collected biometric data are combined into a real-time biometric feature set as important data for identity authentication. The obtained input verification account is then associated with the input authentication key, the physical key reading result, and the real-time biometric feature set, and the package is sent to three independent and trusted third parties. The three trust parties respectively store the user's authentication key, physical key, and biometric feature library, and are each responsible for verifying the corresponding data. After receiving the data packet, each trust party compares and verifies the data in it with the original data stored by itself. After the verification is complete, the verification result (i.e., verification receipt) is returned to the system. Only when the verification results returned by all trust parties are "passed" will the system determine that the user's authentication is successful and allow the user to access protected resources or perform the corresponding operation. By combining multiple verification factors (account, key, biometric features) and multi-trust party authentication, the security of user accounts and data is ensured and the security of the system is greatly improved.
[0033] Furthermore, step S200 also includes step S250, determining whether the security level of the scheduled task is lower than a preset security threshold; step S260, when the security level is lower than the security threshold, generating a general key access verification; step S270, performing user verification management based on the general key access verification.
[0034] Preferably, different scheduled tasks may involve different degrees of sensitive information or have different security impacts, and therefore will be assigned different security levels. For example, in an enterprise information system, querying ordinary public documents is a low-security level task; while accessing core business data, conducting financial transactions, etc. are high-security level tasks. The preset security threshold is a security level standard pre-set by the system, which is used to distinguish tasks with different security requirements. When the security level of a task is lower than the preset security threshold, it means that the security risk of the task is relatively low.
[0035] Preferably, the user's scheduled task is analyzed to determine its security level, and compared with a preset security threshold to determine whether the task is a low-risk task. That is, if the security level of the scheduled task is lower than the preset security threshold, the system generates a universal and convenient access verification method for the task, namely, universal key access verification. This verification method may not require complex multi-factor verification like high-security level tasks, but instead adopts a relatively simple verification mechanism that still ensures a certain degree of security; then the user is authenticated and permission managed based on the universal key access verification. Specifically, when the user initiates an access request to the scheduled task, the system will require the user to provide the information required for the universal key access verification (such as the universal access key) and verify this information. If the verification is successful, the system will allow the user to access the resources corresponding to the scheduled task or perform corresponding operations; if the verification fails, the user's access request will be rejected.
[0036] Step S300: After parsing the scheduled task and the current running status, the parsing result and the identity authentication trust are input into a random configuration model as input data to establish a random configuration constraint.
[0037] Preferably, the scheduled tasks are parsed to determine the user's specific needs and task information, such as the type of task (data query, file editing or other operations), the resources involved in the task (specifically which files, data modules, etc.), the urgency of the task, the expected execution time of the task, etc.; the current operating status is parsed to determine whether the device has the ability and conditions to execute the scheduled tasks, such as the device's hardware status (such as CPU usage, remaining memory, hard disk space, etc.), the device's software status (operating system version, installed applications and versions, security protection software operation status, etc.), network connection status (network speed, connection stability, IP address, etc.), and then this information is combined into a parsed result.
[0038] Preferably, the parsing results and the identity authentication trust information are used as input data and input into a random configuration model. The random configuration model is a model based on probability and statistical principles that can generate a reasonable configuration plan based on the input data. Specifically, after the parsing results and identity authentication trust are input into the model, the model will generate multiple random configuration constraints based on the characteristics and requirements of these data, which may include but are not limited to key-related constraints, such as generating a key pair of specific strength and type, specifying the validity period of the key, etc. If the user's identity authentication trust is high and the security level of the scheduled task is low, a relatively simple key may be generated. Conversely, if the trust is low or the task security level is high, a more complex and more secure key is generated; resource allocation constraints, that is, determining how much system resources, such as CPU time and memory space, to allocate to the task based on the current operating status of the device and task requirements. If device resources are scarce, the task's resource usage may be restricted to ensure stable system operation; access permission constraints, that is, determining the user's access permission level to the resources involved in the task based on the identity authentication trust and task characteristics, such as read-only, read-write, etc., to ensure that the task can be executed safely and reasonably under limited device resources.
[0039] Furthermore, step S300 also includes step S310, extracting the task level characteristics, data sensitivity characteristics, and device trusted state characteristics of the analysis results through the preprocessing layer; step S320, normalizing the task level characteristics, data sensitivity characteristics, device trusted state characteristics, and authentication trust, and establishing the first input data; step S330, inputting the first input data into the calculation layer of the random configuration model to establish a calibration configuration constraint; step S340, introducing a random factor according to the data sensitivity characteristics, and establishing the second input data with the random factor; step S350, randomly compensating the calibration configuration constraint with the second input data to establish the random configuration constraint.
[0040] Preferably, the preprocessing layer is a functional module that processes input data and is used to extract key feature information from complex parsing results, including task level features, data sensitivity features and device trust status features. Specifically, the task level features indicate the importance and urgency of the scheduled task. For example, tasks may be divided into three levels: high, medium and low. High-level tasks may involve core business or need to be processed immediately, while low-level tasks are relatively unimportant or can be processed later; the data sensitivity features indicate the sensitivity of the data involved in the task. For example, the data may contain highly sensitive data such as personal privacy information and commercial secrets, or it may be ordinary public data; the device trust status features indicate the credibility of the device, such as whether the device has installed the latest security patch, whether the antivirus software is running normally, whether the device hardware has faults, etc.
[0041] Preferably, since the value ranges and dimensions of task level characteristics, data sensitivity characteristics, device trusted state characteristics and identity authentication trust may be different, they are normalized, that is, converted into a unified value range, and then these characteristics are integrated together to form the first input data; the first input data is then input into the calculation layer of the random configuration model to establish a calibration configuration constraint. Specifically, the calculation layer of the random configuration model is the core part of the calculation and processing in the random configuration model. After the first input data is input into the calculation layer, the calculation layer analyzes and calculates these data to generate a set of basic configuration constraints based on the input data as calibration configuration constraints. For example, the basic strength of the key is determined according to the task level and data sensitivity, and the basic resource allocation plan is determined according to the device trusted state and identity authentication trust.
[0042] Preferably, considering the importance of data sensitivity and in order to increase the flexibility and security of the configuration, a random factor (a parameter with random values within a certain range) is introduced according to the data sensitivity characteristics, wherein the value range and generation method can be determined according to the specific system requirements and security policies. If the data sensitivity is high, the value range of the random factor may be larger to increase the security of the configuration. If the data sensitivity is low, the value range of the random factor may be smaller; the introduced random factor is combined with other relevant features (such as task level features, device trusted status features, authentication trust, etc.) to form a second input data; finally, the second input data is used to randomly compensate the calibration configuration constraints, that is, the second input data is input into the system to adjust and supplement the previously established calibration configuration constraints. The calibration configuration constraints can be dynamically adjusted according to different data sensitivities and other factors. Through random compensation, the configuration constraints finally generated are random configuration constraints, which can more accurately adapt to different tasks and user situations and ensure data security.
[0043] Step S400: Create a key pair using the random configuration constraint, and distribute the key pair to the user device and the target file respectively.
[0044] Preferably, a key pair is created based on the random configuration constraint, a key pair is generated for ensuring data security, and the key pair is reasonably distributed to the corresponding location to achieve encryption protection of data interaction between the user device and the target file. Specifically, according to the requirements of the random configuration constraint, the system calls the corresponding key generation algorithm to create a key pair, which is usually composed of a public key and a private key. In asymmetric encryption, the public key can be made public and used to encrypt data; the private key is properly kept by the user or the relevant system and is used to decrypt data encrypted by the corresponding public key; in symmetric encryption, the same key is used for encryption and decryption, for example, the RSA algorithm is used to generate an asymmetric key pair, or the AES algorithm is used to generate a symmetric key pair. The key pair is then distributed to the user device and the target file respectively, that is, a part of the created key pair (usually the private key, or the entire key if it is symmetric encryption) is securely sent to the user device. The security of the key during transmission needs to be ensured to prevent it from being stolen or tampered with. For example, an encrypted channel (such as SSL / TLS protocol) is used to transmit the key. After receiving the key, the user device will store it in a secure storage location, such as the device's key storage module or an encrypted file system; the other part of the key pair (usually the public key) is then associated with the target file. For target files that need to be encrypted and protected, the public key can be used to encrypt the file, or combined with the file's access control mechanism. Only user devices with the correct key can decrypt and access the file, thereby achieving secure access control for sensitive documents.
[0045] Furthermore, step S400 also includes step S410, triggering a unique device binding instruction after the user device receives the key pair; step S420, reading the device identifier of the target device according to the unique device binding instruction, using the device identifier and the key pair for fusion binding, and updating the key pair; step S430, after reading the target file, using the updated key pair to verify the key pair distributed to the target file, and if the key pairs match and the device binding verification passes, the key pair is paired successfully.
[0046] Preferably, when a user device successfully receives a key pair distributed by the system, a unique device binding instruction is automatically triggered to bind the key pair to the device currently receiving the key pair, ensuring that the key pair can only be used on a specific device and preventing the key pair from being illegally transferred to other devices for use, thereby increasing security. The device identifier of the target device is then read according to the unique device binding instruction. Each device has a unique identifier, such as the International Mobile Equipment Identity (IMEI) of a mobile phone or the physical address of the network card (MAC address) of a computer. The device identifier of the target device (i.e., the user device receiving the key pair) is read according to the unique device binding instruction to obtain this unique identification information. The read device identifier is then associated and bound with the received key pair, so that only devices with a specific device identifier can use the key pair. For example, the MAC address of the device is combined with certain parameters of the key pair for encryption. The original key pair is then updated, including modifying or regenerating the parameters of the key pair to match the state after binding with the device identifier. The updated key pair contains relevant information about the device identifier, further enhancing the security and device relevance of the key pair.
[0047] Preferably, when the user device attempts to read the target file, the updated key pair is used to verify whether the key pair (usually the public key) distributed to the target file matches, including checking whether the two key pairs are consistent. For example, in asymmetric encryption, the private key is used to sign certain data of the target file, and then the public key is used to verify the validity of the signature. If the verification passes, it means that the key pairs match; in addition to the key pair matching verification, device binding verification is also performed, that is, checking whether the device identifier of the device currently using the key pair is consistent with the previously bound device identifier. If the device identifier matches, it means that the device is authorized to use the key pair, and the device binding verification passes; only when the key pair matches and the device binding verification passes, the key pair pairing is determined to be successful. At this time, the user device is allowed to perform further operations on the target file, such as decryption, reading or editing. If any of the verifications fails, the system will deny the user device access to the target file, thereby ensuring the security of the target file.
[0048] Step S500: After the key pair is successfully paired, the user device is allowed to read the target file, and the key pair is destroyed at the end of the validity period.
[0049] Preferably, after the key pair is successfully paired, the user device is granted permission to access the target file. Specifically, the user device performs read operations on the target file according to the operating procedures, such as opening the file to view the content, downloading the file to the local computer, etc., and ensures that only legitimate devices and users can obtain the information of the target file after meeting the corresponding conditions, thereby preventing unauthorized access. When creating a key pair, a time limit, i.e., a validity period, is set for it according to specific business needs and security policies. When the validity period of the key pair expires, the system automatically performs a destruction operation to prevent the key pair from being abused or leaked. For asymmetric key pairs, the public key and private key are destroyed separately; for symmetric key pairs, the entire key is destroyed. The destruction operation usually adopts a safe method, such as overwriting the area where the key is stored with random data to ensure that the key cannot be recovered, thereby ensuring the security of data and authentication.
[0050] Furthermore, step S500 also includes step S510, after the key pair is successfully paired, enabling temporary access rights to the target file on the user device and synchronously enabling device behavior monitoring; step S520, using the device behavior monitoring results to identify behavioral anomalies of the user device and establish cumulative anomaly points; step S530, after the cumulative anomaly points meet the preset requirements, ending the validity period of the key pair and stopping the user device's access to the target file.
[0051] Preferably, when the key pair is paired successfully and it is confirmed that the user device has legal access qualifications, a temporary access right is enabled for the target file on the user device, which means that the user device can read, edit, and perform other operations on the target file within a certain period of time. However, this access right is not permanent, but is granted temporarily, so that the user can complete related tasks under the premise of meeting security and management requirements. At the same time as the temporary access right is enabled, the system starts the behavior monitoring function of the user device. The monitoring content may include the device's operating behavior (such as the specific operation on the target file, such as opening, copying, deleting, etc.), network activity (such as the size of the network traffic, the connected server address, etc.), device performance indicators (such as CPU usage, memory usage, etc.), and device usage time and other information, so as to understand the dynamic situation of the user device in the process of accessing the target file in real time.
[0052] Preferably, the monitored user device behavior data is analyzed to determine whether the device behavior is abnormal. For example, if the user device performs a large number of copy operations on the target file in a short period of time, or attempts to connect to some abnormal server addresses, it may be determined to be abnormal. For each identified abnormal behavior, the system accumulates a certain number of abnormal points for the user device based on the severity of the abnormality. The more serious the abnormality, the higher the accumulated points. For example, a minor abnormal behavior may accumulate 1 point, while a serious security threat behavior may accumulate 5 points or more. The degree of abnormality of the user device is quantified by the accumulated abnormal points. Taking into account the security of the system and the convenience of user operation, a threshold for the accumulated abnormal points is pre-set. When the accumulated abnormal points of the user device reaches or exceeds this threshold, it is considered that the preset requirements are met, and the validity period of the key pair is immediately terminated, even if the originally set validity period has not yet expired. At the same time, the user device's access rights to the target file are stopped, and the user device will no longer be able to perform any operations on the target file, thereby preventing possible security risks in a timely manner and protecting the data security of the target file.
[0053] In the above, refer to Figure 1 The full life cycle key management service method supporting the KMIP protocol according to an embodiment of the present invention is described in detail. Figure 2 A full lifecycle key management service system supporting the KMIP protocol according to an embodiment of the present invention is described.
[0054] The full lifecycle key management service system supporting the KMIP protocol according to the embodiment of the present invention is used to solve the technical problems existing in the prior art, such as low key security, irregular lifecycle management, and unreliable user authentication, which in turn lead to insufficient data security, thereby achieving the technical effects of improving key management interoperability, enhancing user authentication, and data security. Figure 2 As shown, the full life cycle key management service system supporting the KMIP protocol includes: an authentication key creation module 10, a device operation status detection module 20, a random configuration constraint establishment module 30, a key pair creation module 40, and a target file reading module 50.
[0055] The authentication key creation module 10 is used to create the user's authentication key, and configure the entity key and user biometric library mapped to the authentication key, and store the authentication key, the user biometric library and the verification key pair in different trusted third parties respectively, wherein the verification key pair is the key for performing entity key verification; the device operation status detection module 20 is used to establish authentication trust and read the user's scheduled tasks after using the trusted third party to authenticate the user, and detect the current operation status of the user's device; the random configuration constraint establishment module 30 is used to parse the scheduled tasks and the current operation status, and input the parsing results and the authentication trust as input data into the random configuration model to establish random configuration constraints; the key pair creation module 40 is used to create a key pair using the random configuration constraints, and distribute the key pair to the user device and the target file respectively; the target file reading module 50 is used to allow the user device to read the target file after the key pair is successfully paired, and destroy the key pair at the end of the validity period.
[0056] The specific configuration of the random configuration constraint establishment module 30 will be described in detail below. The random configuration constraint establishment module 30 further includes: extracting the task level characteristics, data sensitivity characteristics, and device trust status characteristics of the parsing results through the preprocessing layer; normalizing the task level characteristics, data sensitivity characteristics, device trust status characteristics, and authentication trust to establish first input data; inputting the first input data into the calculation layer of the random configuration model to establish a calibration configuration constraint; introducing a random factor based on the data sensitivity characteristics and establishing second input data with the random factor; and randomly compensating the calibration configuration constraint with the second input data to establish the random configuration constraint.
[0057] The specific configuration of key pair creation module 40 will be described in detail below. Key pair creation module 40 further includes: after the user device receives the key pair, triggering a unique device binding instruction; reading the device identifier of the target device according to the unique device binding instruction, performing a fusion binding using the device identifier and the key pair, and updating the key pair; after reading the target file, using the updated key pair to verify the key pair distributed to the target file; if the key pairs match and the device binding verification passes, the key pair pairing is successful.
[0058] The specific configuration of the target file reading module 50 will be described in detail below. The target file reading module 50 further includes: after the key pair is successfully paired, enabling temporary access rights to the target file on the user device and simultaneously enabling device behavior monitoring; using the device behavior monitoring results to identify abnormal behavior of the user device and establish a cumulative abnormality score; and when the cumulative abnormality score meets a preset requirement, terminating the validity period of the key pair and stopping the user device from accessing the target file.
[0059] The specific configuration of the device operation status detection module 20 will be described in detail below. The device operation status detection module 20 further includes: obtaining the user's input verification account; reading the user's input identity authentication key and the user's physical key, and simultaneously performing the user's biometric feature collection to establish a real-time biometric feature set; packaging the input verification account with the input identity authentication key, the physical key reading result, and the real-time biometric feature set, and sending the package to the corresponding trusted three parties; obtaining verification receipts from the trusted three parties, and when all the trusted three parties return verification results that are passed, the authentication is passed.
[0060] The following describes the detailed configuration of the authentication key creation module 10. The authentication key creation module 10 further includes: establishing a user's access history and generating an access security evaluation; utilizing the access history and access security evaluation to generate an additional verification database; and optimizing the user's subsequent access verification key based on the additional verification database.
[0061] The specific configuration of the device operation status detection module 20 will be described in detail below. The device operation status detection module 20 further includes: determining whether the security level of the scheduled task is below a preset security threshold; generating a universal key access verification when the security level is below the threshold; and performing user authentication management based on the universal key access verification.
[0062] The full lifecycle key management service system supporting the KMIP protocol provided by the embodiment of the present invention can execute the full lifecycle key management service method supporting the KMIP protocol provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0063] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, any number of different modules may be used and run on the user terminal and / or server, and the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other and are not used to limit the scope of protection of the present invention.
[0064] The above specific embodiments do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application shall be included within the scope of protection of this application.
Claims
1. A full lifecycle key management service method supporting the KMIP protocol, characterized in that: The method comprises: Create a user authentication key, configure an entity key and a user biometric database mapped to the authentication key, and store the authentication key, the user biometric database, and the verification key pair in different trusted parties, respectively. The verification key pair is the key for verifying the entity key. After using a trusted third party to authenticate the user, establish authentication trust, read the user's scheduled tasks, and detect the current operating status of the user's device; After parsing the scheduled task and the current running status, the parsing result and the identity authentication trust are input into a random configuration model as input data to establish a random configuration constraint; Creating a key pair using the random configuration constraint, and distributing the key pair to a user device and a target file respectively; After the key pair is successfully paired, the user device is allowed to read the target file and the key pair is destroyed at the end of the validity period; The step of inputting the parsing result and the identity authentication trust as input data into a random configuration model to establish random configuration constraints includes: The pre-processing layer extracts the task level features, data sensitivity features, and device trust status features of the analysis results; After normalizing the task level feature, data sensitivity feature, device trust status feature, and identity authentication trust, first input data is established; Inputting the first input data into a computational layer of a random configuration model to establish calibration configuration constraints; Introducing a random factor according to the data sensitivity feature, and establishing second input data with the random factor; The calibrated configuration constraint is randomly compensated using the second input data to establish the random configuration constraint.
2. The full lifecycle key management service method supporting the KMIP protocol according to claim 1, characterized in that: The distributing the key pair to the user device and the target file respectively includes: After the user device receives the key pair, triggering a unique device binding instruction; Reading a device identifier of a target device according to a unique device binding instruction, performing fusion binding using the device identifier and the key pair, and updating the key pair; After reading the target file, the updated key pair is used to verify the key pair distributed to the target file. If the key pairs match and the device binding verification passes, the key pair pairing is successful.
3. The full lifecycle key management service method supporting the KMIP protocol according to claim 2, characterized in that: After the key pair is successfully paired, the user device is allowed to read the target file, and the key pair is destroyed at the end of the validity period, including: After the key pair is successfully paired, temporary access rights to the target file are enabled on the user device, and device behavior monitoring is simultaneously enabled; Use device behavior monitoring results to identify abnormal behavior of user devices and establish cumulative abnormality points; When the accumulated abnormal points meet the preset requirements, the validity period of the key pair ends and the user device stops accessing the target file.
4. The full lifecycle key management service method supporting the KMIP protocol according to claim 1, characterized in that: Utilize trusted third parties to authenticate users, including: Get the user's input verification account; Read the user's input authentication key and the user's physical key, and simultaneously perform the user's biometric collection to establish a real-time biometric feature set; The input verification account is packaged and combined with the input identity verification key, the entity key reading result, and the real-time biometric feature set, and then sent to the corresponding trusted three parties; Obtain verification receipts from the three trusted parties. When all the verification results returned by the three trusted parties are positive, the identity verification is successful.
5. The full lifecycle key management service method supporting the KMIP protocol according to claim 1, characterized in that: The method further comprises: Establish user access records and generate access security evaluations; generating an additional verification database using the access records and access security evaluation; The user's subsequent access authentication key is optimized based on the additional authentication database.
6. The full lifecycle key management service method supporting the KMIP protocol according to claim 1, characterized in that: After detecting the current operating status of the user equipment, the method further includes: Determine whether the security level of the scheduled task is lower than a preset security threshold; When the security level is lower than the security threshold, a universal key access verification is generated; User authentication management is performed based on the universal key access authentication.
7. Support the full life cycle key management service system of KMIP protocol, characterized by: The system is used to implement the full lifecycle key management service method supporting the KMIP protocol according to any one of claims 1 to 6, and the system includes: An authentication key creation module is used to create an authentication key for a user, configure an entity key and a user biometric database mapped to the authentication key, and store the authentication key, the user biometric database, and the verification key pair in different trusted parties, wherein the verification key pair is a key for performing entity key verification; The device operation status detection module is used to establish the authentication trust level and read the user's scheduled tasks after using the trusted third party to verify the user's identity and detect the current operation status of the user's device; A random configuration constraint establishment module is used to analyze the scheduled task and the current running status, and input the analysis result and the identity authentication trust as input data into the random configuration model to establish random configuration constraints; A key pair creation module, configured to create a key pair using the random configuration constraint, and distribute the key pair to a user device and a target file respectively; The target file reading module is used to allow the user device to read the target file after the key pair is successfully paired, and to destroy the key pair at the end of its validity period.
Citation Information
Patent Citations
Identity verification method and device, computer equipment and storage medium
CN112528259A
Hierarchical optimization encryption lossless privacy protection method
CN112989375A