Key generation method and device, equipment, medium and product

By judging the comparison of the total number of keys in the database and the preset target value, and using the encryption machine to generate and encrypt the key, the key duplication and security issues are solved, and the key is high security and accuracy are achieved.

CN120128336APending Publication Date: 2025-06-10CHONGQING WEIBINAI TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510384838.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

When the number of times a key is used increases, the prior art is difficult to effectively solve the problems of pseudo-random number of keys, data security and key duplication, which affects the security and accuracy of the key.

Method used

By determining in the database whether the total number of keys currently stored is the same as the preset target value. If it is not the same, a random key is generated by an encryption machine, and then encrypted by an encryption algorithm and stored in the database. This process is repeated until the total number of keys is the same as the preset target value.

Benefits of technology

It effectively avoids the existence of duplicate keys in the key, improves the security and accuracy of the key, and ensures the security and reliability of the key generation process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128336A_ABST
    Figure CN120128336A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a key generation method and device, equipment, a medium and a product, and the method comprises the steps: generating a random key through an encryption machine under the condition that the total number of keys currently stored in a database is different from a preset target value; encrypting the random key through an encryption algorithm, and storing the encrypted random key as a key in the database; and returning to the step of generating the random key by using the encryption machine under the condition that the total number of the keys currently stored in the database is different from the preset target value until the total number of the keys is the same as the preset target value. According to the technical scheme, the total number of the keys stored in the database is judged based on the preset target value, and the random keys are generated by using the encryption machine until the total number of the keys is the same as the preset target value under the condition that the total number of the keys is different from the preset target value, so that the condition that repeated keys exist in the keys is avoided, and the user experience is improved. And the security and the accuracy of the secret key are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of communication technologies, and in particular, to a method, apparatus, device, medium, and product for generating keys. Background Art

[0002] With the rapid development of the field of communication technologies, people's requirements for the quality and security of communication are constantly increasing. When the number of times of using keys increases, how to solve the factors of pseudo-random numbers of keys, data security, and factors of random repetition of keys also continuously raises the requirements for keys. Summary of the Invention

[0003] Embodiments of the present disclosure provide a method, apparatus, device, medium, and product for generating keys, which avoid the situation of duplicate keys in the keys and improve the security and accuracy of the keys.

[0004] In a first aspect, a method for generating a key is provided, including:

[0005] When the total number of currently stored keys in the database is different from a preset target value, a random key is generated by using an encryption machine;

[0006] The random key is encrypted through an encryption algorithm, and the encrypted random key is stored as a key in the database;

[0007] Return to the step of generating a random key by using an encryption machine when the total number of currently stored keys in the database is different from a preset target value, until the total number of the keys is the same as the preset target value.

[0008] In a second aspect, a key generation apparatus is provided, including:

[0009] A random key generation module, configured to generate a random key by using an encryption machine when the total number of currently stored keys in the database is different from a preset target value;

[0010] A storage module, configured to encrypt the random key through an encryption algorithm and store the encrypted random key as a key in the database;

[0011] A return module, configured to return to the step of generating a random key by using an encryption machine when the total number of currently stored keys in the database is different from a preset target value, until the total number of the keys is the same as the preset target value.

[0012] In a third aspect, an electronic device is provided, including:

[0013] At least one processor; and,

[0014] A memory communicatively connected to the at least one processor; wherein,

[0015] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the key generation method as described in the first aspect above.

[0016] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the key generation method as described in the first aspect above is implemented.

[0017] In a fifth aspect, a computer program product is provided, the computer program product includes a computer program, and when the computer program is executed by a processor, the key generation method as described in the first aspect above is implemented.

[0018] Embodiments of the present disclosure disclose a key generation method, apparatus, device, medium and product. The method includes: when the total number of keys currently stored in the database is different from a preset target value, generating a random key by using an encryption machine; encrypting the random key through an encryption algorithm, and storing the encrypted random key as a key in the database; returning to the step of generating a random key by using an encryption machine when the total number of keys currently stored in the database is different from the preset target value, until the total number of keys is the same as the preset target value. This technical solution judges the total number of keys stored in the database based on the preset target value. When the total number of keys is different from the preset target value, a random key is generated by using an encryption machine until the total number of keys is the same as the preset target value, avoiding the situation of duplicate keys in the keys and improving the security and accuracy of the keys.

[0019] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the embodiments of the present disclosure. Other features of the embodiments of the present disclosure will become easily understood through the following description. Description of the Drawings

[0020] To more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the embodiments of the present disclosure. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0021] Figure 1 is a flowchart of a key generation method provided in Embodiment 1 of the present disclosure;

[0022] Figure 2 It is a schematic diagram of a KI key generation process for a telecommunications IC card provided in Embodiment 1 of the present disclosure;

[0023] Figure 3 It is a schematic diagram of another KI key generation process for a telecommunications IC card provided in Embodiment 1 of the present disclosure;

[0024] Figure 4 It is a schematic structural diagram of an adjustment device for key generation provided in Embodiment 2 of the present disclosure;

[0025] Figure 5 It is a schematic structural diagram of an electronic device provided in Embodiment 3 of the present disclosure. Detailed implementation manners

[0026] In order to enable those skilled in the art to better understand the solutions of the embodiments of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the embodiments of the present disclosure.

[0027] It should be noted that the terms "first", "second", etc. in the description and claims of the embodiments of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0028] Embodiment 1

[0029] Figure 1 It is a flowchart of a key generation method provided in Embodiment 1 of the present disclosure. This embodiment is applicable to the situation of generating keys. This method can be executed by a key generation device, which can be implemented in the form of hardware and / or software. The key generation device can be configured in an electronic device, and the electronic device includes but is not limited to devices with data processing capabilities such as computers, laptops, terminals, and servers. As Figure 1 shown, the method includes:

[0030] S110. When the total number of currently stored keys in the database is different from the preset target value, use an encryption machine to generate a random key.

[0031] In this embodiment, the total number of currently generated and stored keys can be read from the database. The keys can be used to use and encrypt integrated circuit (IC) data such as key identifier (KI), key identifier code (KIC), key identifier data (KID), and key identifier key (KIK). Exemplarily, the key can be a KI key. The KI key can be generated by a telecommunications IC card key generation system. The KI key can be the key for encrypting data transmission between a subscriber identity module (SIM) and an operator, and is mainly used for communication encryption between the SIM card and the network. Among them, the IC card key generation system can be a system for generating, managing, and maintaining IC card keys. The database can be a MySQL database.

[0032] Continuing with the above description, after reading the total number of currently stored keys, it can be determined whether the total number of currently stored keys is the same as the preset target value, where the preset target value can be a preset target value. When the total number of currently stored keys in the database is different from the preset target value, an encryption machine can be connected to generate a random key using the encryption machine, and the encryption machine is a SafNet encryption machine. The random key can be a key generated by a secure random number generator, the purpose of which is to ensure the unpredictability and uniqueness of the key, and avoid the situation of duplicate keys in the key.

[0033] S120. Encrypt the random key through an encryption algorithm, and store the encrypted random key as a key in the database.

[0034] Specifically, after obtaining the random key using the encryption machine, the random key can be encrypted through an encryption algorithm. Among them, the encryption algorithm can be a high-strength symmetric encryption algorithm or an asymmetric encryption algorithm. After the random key is encrypted, the encrypted random key can be stored as a key in the database, effectively preventing the risk of key leakage when the database is attacked.

[0035] S130. Return to the step of generating a random key using the encryption machine when the total number of currently stored keys in the database is different from the preset target value, until the total number of keys is the same as the preset target value.

[0036] Specifically, after storing the encrypted random key as a key in the database, the step of obtaining the total number of keys currently stored in the database can be executed again, and it is determined again whether the total number of keys currently stored in the database is the same as a preset target value. If the total number of keys currently stored in the database is not the same as the preset target value, the encryption machine can be connected again to generate a random key using the encryption machine until the total number of keys is the same as the preset target value.

[0037] This embodiment provides a key generation method, including: when the total number of keys currently stored in the database is not the same as a preset target value, generating a random key using an encryption machine; encrypting the random key through an encryption algorithm, and storing the encrypted random key as a key in the database; returning to the step of generating a random key using the encryption machine when the total number of keys currently stored in the database is not the same as the preset target value, until the total number of keys is the same as the preset target value, avoiding the situation of duplicate keys in the keys, and improving the security and accuracy of the keys.

[0038] As an optional implementation manner of this embodiment, the key generation method provided in this embodiment further includes:

[0039] 1) Obtain a pre-configured file of the key generation system.

[0040] In this embodiment, the pre-configured file may be a file used to define system operation parameters, rules, and initial settings in the key generation system. Exemplarily, the pre-configured file may include parameters of the key generation algorithm: such as key length, encryption algorithm type; configuration of the system operation environment: such as key storage path, backup strategy, etc.; security policy: such as key life cycle management rules (generation, update, destruction, etc.); other related settings: such as key distribution method, key usage permission, etc. The key generation system may be a telecommunication IC card key generation system.

[0041] Specifically, the pre-configured file of the key generation system can be obtained.

[0042] 2) Determine the preset target value based on the pre-configured file of the key generation system.

[0043] In this embodiment, the preset target value refers to a specific parameter or result that needs to be achieved during the key generation process, and the preset target value can be determined based on the pre-configured file of the key generation system. Exemplarily, the preset target value may be the maximum number of keys set in the pre-configured file.

[0044] As an optional implementation manner of this embodiment, the key generation method provided in this embodiment includes:

[0045] 1) Read the key based on the pre-configured file to generate key generation timing task information; the key generation timing task information includes the key generation task setting time.

[0046] Specifically, after obtaining the pre-configured file, the key generation timing task information can also be read based on the pre-configured file. The key generation timing task information can be a part of the content in the pre-configured file, and the key generation timing task information can include the key generation task setting time. The generation task setting time can be the planned execution time of the key generation task. Exemplarily, the generation task setting time can be a specific time point (such as 1 am every day), or it can be a time interval (such as generating a key every 7 days).

[0047] 2) Determine whether the current time meets the key generation task setting time, and when the current time meets the task start setting, generate a key through the key generation system and store it in the database.

[0048] Specifically, after the generation task setting time is determined, it can be determined whether the current time meets the key generation task setting time. If the current time does not meet the key generation task setting time, continue to wait until the time meets the condition and start the key generation process again. If the current time meets the key generation task setting time, start generating the key again through the key generation system and store it in the database.

[0049] As an optional implementation manner of this embodiment, the generation of a random key using an encryption machine includes:

[0050] 1) Send a random key generation instruction to the encryption machine and obtain the generation result of the encryption machine.

[0051] In this embodiment, the encryption machine can be a SafNet encryption machine. A random key generation instruction can be sent to the encryption machine. After receiving the random key instruction, the encryption machine can obtain the generation result based on the random key instruction. Among them, the random key instruction includes: a decimal number with a custom length, a flag bit, and a custom random key length. The custom random key length can be a length obtained by the encryption machine generating a string of keys and then a person selecting the keys generated by the encryption machine. It should be noted that the custom random key length can also be a length custom-generated by a person, or a length custom-generated by the encryption machine.

[0052] 2) If the generation result includes a random key, return the generated random key.

[0053] Continuing from the above description, after the generation result is determined, it is possible to determine whether the generation result contains a random key. A random key can be a string or combination of numbers generated through an algorithm, with high randomness and uniqueness. If the generation result contains a random key, the generated random key can be returned.

[0054] 3) Otherwise, return to the step of sending an instruction to the encryption machine to generate a random key and obtaining the generation result of the encryption machine.

[0055] Specifically, if the generation result does not contain a random key, it is necessary to continue to execute the step of sending an instruction to the encryption machine to generate a random key and obtaining the generation result of the encryption machine until the generation result contains a random key.

[0056] As an optional implementation manner of this embodiment, the key generation method provided in this embodiment includes:

[0057] 1) Use the supervision log of the key generation system to record the operation log of the key generation process; the operation log includes the timestamp corresponding to the key, the number of keys, the key generation status, and / or exception information.

[0058] Specifically, the operation log of the key generation process can be recorded using the supervision log of the key generation system. The supervision log can be a mechanism for recording system operations and events, usually used for auditing, compliance checking, and security monitoring. It records all important operations that occur in the system, including time, operation content, operation results, etc. The operation log can be a part of the supervision log, specifically used to record the specific operations during the key generation process. These logs can provide detailed information about the key generation process, helping administrators understand whether the key generation is proceeding normally and whether there are any problems. The operation log can include the timestamp corresponding to the key, the number of keys, the key generation status, and / or exception information.

[0059] 2) If abnormal information is detected and the abnormal information meets the alarm trigger condition, record the abnormal log and trigger an alarm.

[0060] Specifically, during the key generation process, various operations and events can be monitored in real time. If an error occurs, these abnormal information can be detected in a timely manner. Abnormal information can include abnormal timestamps corresponding to keys, abnormal numbers of keys, abnormal key generation statuses; at the same time, abnormal information can also include: error code: a system-defined error identifier used to quickly locate the type of problem; error description: a specific description of the abnormal situation, such as "key storage failure" or "encryption algorithm error"; stack trace: if the exception is caused by a program error, the system will record detailed stack information to help developers locate the problem; context of operation failure: for example, the user, time, and operation steps when the operation fails.

[0061] It should be noted that if abnormal information is detected and the abnormal information meets the alarm trigger condition, an abnormal log will be recorded and an alarm will be triggered. Among them, the alarm trigger condition can be a rule for judging whether the abnormal information needs to trigger an alarm, and these rules can be stored in a pre-configured file of the key generation system. The abnormal log can include the following content: Timestamp: The specific time when the abnormality occurred; Abnormal description: A detailed description of the abnormal situation; Operation context: For example, the user of the operation, the target of the operation, the operation steps, etc.; System status: The running status of the system when the abnormality occurred, such as memory usage, thread status, etc.

[0062] Continuing with the above description, triggering an alarm can be used to promptly remind the administrator or relevant personnel to take measures to ensure that abnormal situations can be detected and handled in a timely manner, preventing the problem from deteriorating further. The alarm can be triggered in the following ways: Email notification: Sending an email containing the abnormal information to the administrator; SMS notification: Sending the alarm information through the SMS platform; Log record: Recording the alarm event in the log; Sound or visual alarm: Emitting a sound or displaying a visual alarm on the local system.

[0063] Figure 2 This is a schematic diagram of the KI key generation process for a telecommunications IC card provided in this embodiment. As Figure 2 shown, the telecommunications IC card key generation system can be used to generate the KI key of the telecommunications IC card. First, it is necessary to set a maximum number of generated keys (preset target value) in the configuration file to control the upper limit of key generation and avoid generating too many keys. And add (or read) key generation scheduled task information in the configuration file (pre-configured file) to automatically generate keys according to a preset time interval. Before generating each key, it can be checked whether the current number of generated keys is less than the maximum number (preset target value). When the number of generated keys is less than the maximum number, connect to the SafNet encryption machine, which is used to provide a secure key generation and storage environment. Generate the KI key through the SafNet encryption machine to be used to identify and manage the keys of the IC card. When the number of generated keys is equal to or greater than the maximum number, no new keys will be generated. Then, according to the scheduled generation task (key generation scheduled task information) in the configuration file (pre-configured file), continuously obtain the current time, and regularly start the key generation process according to whether the current time reaches the cycle of the scheduled generation task. The above technical solution realizes the automatic generation and management of keys, while ensuring that the quantity and time of key generation are within control, improving the security and reliability of the system.

[0064] Figure 3 This is another schematic diagram of the KI key generation process for a telecommunications IC card provided in this embodiment. As Figure 3As shown in the figure, the telecommunication IC card key generation system is used to generate the KI key of the telecommunication IC card. First, the total number of generated KI keys (the total number of keys) in the database can be read. When the total number is not equal to the number in the configuration file (the preset target value), it will check whether the number of KI keys in the current database has reached the maximum number (the preset target value) set in the configuration file. If the numbers are not equal, it can connect to the SafNet encryption machine to generate a new KI key, and the generated KI key is saved to the database. Then, it determines again whether the generated number in the database is consistent. If it is consistent, it proceeds to the next step. If the number of KI keys in the database is inconsistent with the expectation (the preset target value), the system will continue to generate new KI keys until the numbers are consistent. At the same time, a timing task can be started according to a preset time interval. It checks whether the current time meets the preset timing task time (the key generation task setting time). If it meets, the telecommunication IC card key generation system is enabled. If it does not meet, it continues to wait. When the current time meets the key generation task setting time, the system will restart the KI key generation process, which ensures the security of the key from multiple dimensions, avoids the problem of duplicate keys, and can send commands at a specified time to require the encryption machine to return the KI key and query the database content, etc. A string of KI keys returned by the SaftNet encryption machine is written into the smart card data and saved in the database in a specific way to prevent operators from accessing the plaintext or ciphertext KI keys.

[0065] The technical effects achieved by the above technical solution include: reducing the manual generation of keys by the telecommunication IC card KI key module; reducing duplicate data in the generation of telecommunication IC card KI keys; avoiding pseudo-random numbers in the telecommunication IC card KI keys; adding a timing task to realize the timed detection of KI keys within a preset time every day; returning the KI key through the SaftNet encryption machine instruction, enhancing the security of the generated key, and adding a log record in this technical solution for querying and managing the key generation process.

[0066] Embodiment 2

[0067] Figure 4 is a schematic structural diagram of a key generation device provided by Embodiment 2 of the present disclosure; as Figure 4 shown, the device includes: a random key generation module 210, a storage module 220, and a return module 230.

[0068] Among them, the random key generation module 210 is used to generate a random key using the encryption machine when the total number of currently stored keys in the database is different from the preset target value;

[0069] A storage module 220, configured to encrypt the random key through an encryption algorithm and store the encrypted random key as a key in the database;

[0070] A return module 230, configured to return the step of generating a random key by using an encryption machine until the total number of keys currently stored in the database is the same as a preset target value when the total number of keys currently stored in the database is different from the preset target value.

[0071] Embodiment 2 of the present disclosure provides a key generation device, which avoids the situation of duplicate keys in the keys and improves the security and accuracy of the keys.

[0072] Further, the encryption machine is a SafNet encryption machine; the database is a MySQL database.

[0073] Further, the device further includes:

[0074] A pre-configured file acquisition module, configured to acquire a pre-configured file of a key generation system;

[0075] A preset target value determination module, configured to determine the preset target value based on the pre-configured file of the key generation system.

[0076] Further, the device further includes:

[0077] A reading module, configured to read key generation timing task information based on the pre-configured file; the key generation timing task information includes a key generation task setting time;

[0078] A storage module, configured to determine whether the current time meets the key generation task setting time, and generate a key through a key generation system and store the key in the database when the current time meets the key generation task setting time.

[0079] Further, the random key generation module 210 is further configured to:

[0080] Send a random key generation instruction to the encryption machine and obtain a generation result of the encryption machine;

[0081] If the generation result includes a random key, return the generated random key;

[0082] Otherwise, return the step of sending a random key generation instruction to the encryption machine and obtaining a generation result of the encryption machine;

[0083] Wherein, the random key instruction includes: a decimal number with a custom length, a flag bit, and a custom random key length.

[0084] Further, the device further includes:

[0085] An operation log generation module, configured to use the key to generate an operation log of the supervision log recording the key generation process of the system; the operation log includes a timestamp corresponding to the key, the number of keys, the key generation status, and / or exception information;

[0086] An alarm module, configured to record an exception log and trigger an alarm if an exception information is detected and the exception information meets an alarm trigger condition.

[0087] The key generation device provided by an embodiment of the present disclosure can execute the key generation method provided by any embodiment of the present disclosure, and has functional modules and beneficial effects corresponding to the execution of the method.

[0088] Embodiment III

[0089] Figure 5 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement an embodiment of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, for example, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the embodiments of the present disclosure described and / or claimed herein.

[0090] As Figure 5 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.

[0091] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0092] The processor 11 may be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microprocessor, etc. The processor 11 executes the various methods and processes described above, such as the key generation method.

[0093] In some embodiments, the key generation method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the key generation method described above may be executed. Alternatively, in other embodiments, the processor 11 may be configured to execute the key generation method by any other suitable means (e.g., by means of firmware).

[0094] The various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0095] The computer programs for implementing the methods of the embodiments of the present disclosure can be written in any combination of one or more programming languages. These computer programs can be provided to the processors of a general-purpose computer, a special-purpose computer, or other programmable data processing devices such that when the computer programs are executed by the processors, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0096] In the context of the embodiments of the present disclosure, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0097] In order to provide an interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide an interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0098] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by any form or medium of digital data communication (e.g., a communication network). Examples of the communication network include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0099] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0100] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the embodiments of the present disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions of the embodiments of the present disclosure can be achieved, and no limitations are imposed herein.

[0101] The above specific embodiments do not constitute a limitation on the protection scope of the embodiments of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the embodiments of the present disclosure shall be included within the protection scope of the embodiments of the present disclosure.

[0102] The embodiments of the present disclosure also provide a computer program product, including a computer program and / or instructions, which when executed by a processor implement the key generation method provided in any embodiment of the present application.

[0103] In the process of implementing the computer program product, computer program code for performing the operations of the embodiments of the present disclosure can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network - including a local area network (LAN) or a wide area network (WAN) - or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0104] Note that the above are only the preferred embodiments of the present disclosure and the applied technical principles. Those skilled in the art will understand that the embodiments of the present disclosure are not limited to the specific embodiments here, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the embodiments of the present disclosure. Therefore, although the embodiments of the present disclosure have been described in more detail through the above embodiments, the embodiments of the present disclosure are not limited to the above embodiments only. Without departing from the concept of the embodiments of the present disclosure, more other equivalent embodiments can be included, and the scope of the embodiments of the present disclosure is determined by the scope of the appended claims.

Claims

1. A key generation method, characterized in that: include: When the total number of keys currently stored in the database is different from the preset target value, a random key is generated using an encryption machine; Encrypting the random key by using an encryption algorithm, and storing the encrypted random key as a key in the database; Returns the step of generating random keys using an encryption machine when the total number of keys currently stored in the database is different from the preset target value, until the total number of keys is the same as the preset target value.

2. The method according to claim 1, characterized in that The encryption machine is a SafNet encryption machine; the database is a MySQL database.

3. The method according to claim 1, characterized in that The method further comprises: Obtain a pre-configuration file for the key generation system; The preset target value is determined based on a pre-configuration file of the key generation system.

4. The method according to claim 3, characterized in that The method further comprises: Reading the key generation scheduled task information based on the pre-configuration file; the key generation scheduled task information includes the key generation task setting time; Determine whether the current time meets the key generation task setting time, and if the current time meets the key generation task setting time, generate a key through a key generation system and store it in the database.

5. The method according to claim 1, characterized in that The method of generating a random key by using an encryption machine includes: Sending a random key generation instruction to the encryption machine, and obtaining the generation result of the encryption machine; If the generated result includes a random key, returning the generated random key; Otherwise, return to the step of sending a random key generation instruction to the encryption machine and obtaining the generation result of the encryption machine; The random key instruction includes: a decimal number of a custom length, a flag bit, and a custom random key length.

6. The method according to claim 1, characterized in that The method further comprises: The supervision log of the key generation system is used to record the operation log of the key generation process; the operation log includes the timestamp corresponding to the key, the number of keys, the key generation status and / or abnormal information; if the abnormal information is detected and the abnormal information meets the alarm triggering condition, the abnormal log is recorded and the alarm is triggered.

7. A key generation device, characterized in that: include: A random key generation module, used to generate a random key using an encryption machine when the total number of keys currently stored in the database is different from a preset target value; A storage module, used for encrypting the random key by an encryption algorithm, and storing the encrypted random key as a key in the database; The return module is used to return the step of generating random keys using an encryption machine when the total number of keys currently stored in the database is different from the preset target value, until the total number of keys is the same as the preset target value.

8. An electronic device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the key generation method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the key generation method as described in any one of claims 1 to 6 is implemented.

10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the computer program implements the key generation method according to any one of claims 1 to 6.

Citation Information

Cited By

  • Key generation method and device, equipment, medium and product

    CN120880661A