Quantum key management system, operation processing method, electronic equipment and storage medium
By designing the user access module, interface module, system management module, key management module and audit module of the quantum key management system, the limitations and complexity of the existing system are solved, and higher operational security and operation performance are achieved.
Patent Information
- Application Number
- CN202311831916.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-06-27
AI Technical Summary
The existing quantum key management system has limitations and is only applicable to a certain link in key management. The system structure is complex, which affects operating speed and reliability.
A quantum key management system is designed to realize the full life cycle management of quantum keys through user access modules, interface modules, system management modules, key management modules and audit modules, and decouple them from the back-end system through interfaces to reduce system complexity.
It improves the operating safety, operating speed, reliability and scalability of the system, and complies with the requirements of graded protection and confidentiality standards in relevant safety specifications.
Smart Images

Figure CN120223294A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular, to a quantum key management system, an operation processing method, an electronic device, and a storage medium. Background Art
[0002] With the rapid development of informatization, information security has become a top priority, and key management is an important part of information security. With the development of quantum technology, more and more fields apply technical means such as quantum entanglement and quantum key distribution to achieve secure information transmission, ensuring the integrity, confidentiality, and non-forgeability of information, and can effectively protect sensitive information and data. Therefore, the industry has made a large number of attempts in the fields of quantum key generation, distribution, storage, etc. For example, the quantum key management device provided by the Chinese patent with the publication number CN 111475822B and the invention name "A Quantum Key Management Method and Device Based on a Database" performs sub-table management on the relevant field content involved in quantum key storage management to improve the reading rate of quantum keys and the reliability and fault tolerance of quantum key storage. Another example is the Chinese patent application with the publication number CN116192376 A and the invention name "A Quantum Key Management Method and Its Application System", which reads quantum key files and arranges them in a quantum key queue, and the required quantum keys are obtained by reading the quantum key queue to solve the problem of resource occupation and waste caused by repeatedly opening and closing files during the process of obtaining keys by reading key files for quantum encryption and decryption. There are also some other quantum key management solutions, which will not be elaborated here one by one. The foregoing various quantum key management solutions are usually proposed based on the specific problems faced by quantum keys in different links such as generation, distribution, and storage, and are only applicable to a certain link in key management, with certain limitations. On the other hand, in the foregoing quantum key management solutions, the front end and the back end are coupled together, and the system structure is complex, thus affecting the operation speed and reliability of the system. Summary of the Invention
[0003] In view of this, the embodiments of the present application provide a quantum key management system, an operation processing method, an electronic device, and a storage medium from the perspective of system operation security.
[0004] According to one aspect of the present invention, the present invention provides a quantum key management system, including:
[0005] A user access module, configured to authenticate the user's access operation, verify the identity and role of the user, and determine the function component corresponding to the user based on the role of the user; when the role is an administrator role, an operator role, or an auditor role, the function components corresponding to the user are a management component, a key component, or an audit component, respectively.
[0006] The interface module is configured to provide a corresponding visual management interface for the functional components.
[0007] The system management module is configured to provide multiple management components for system and user management. Among them, when a user with the role of administrator performs an administrator operation based on the corresponding management components, the system management module calls the corresponding interface provided by the backend system to send the administrator operation information to the backend system, and the backend system generates an administrator operation log by recording the call information of the interface, where the call information includes the administrator operation information implemented each time the interface is called.
[0008] The key management module is configured to provide key components for key policy configuration, key components for monitoring the entire life cycle of keys, and key components for general key management. Among them, when a user with the role of operator performs an operator operation based on the corresponding key components, the key management module calls the corresponding interface provided by the backend system to send the operator operation information to the backend system, and the backend system generates an operator operation log by recording the call information of the interface, where the call information includes the operator operation information implemented each time the interface is called.
[0009] The audit module is configured to provide audit components for auditing administrator operations and operator operations. When a user with the role of auditor performs an audit operation on administrator operations and / or operator operations based on the audit components, the audit module calls the interface provided by the backend system to obtain the corresponding administrator operation log and / or operator operation log.
[0010] Preferably, the user access module includes:
[0011] The authentication unit is configured to call the authentication interface to send the access information provided by the user to the backend system for access security and legality authentication, and confirm whether the access information provided by the user passes the authentication based on the authentication result returned by the backend system.
[0012] The login unit is configured to, after authentication is passed, call the login interface to send the user information provided by the user to the backend system to verify the identity and role of the user, and confirm whether the user has logged in successfully based on the verification result returned by the backend system.
[0013] The loading unit is configured to, after successful login, load the corresponding functional components based on the user role.
[0014] Correspondingly, the interface module provides a corresponding visual management interface for the loaded functional components.
[0015] Preferably, the interface module is configured to use a browser to provide a corresponding visual management interface for the determined functional components; the functional components are loaded into the browser in the form of pages, and when switching functional components, the pages corresponding to the functional components are switched through the routing components embedded in the browser.
[0016] Preferably, the quantum key management system further includes a network request encapsulation module, which is configured to use the network request method encapsulated by Axios to call the interfaces provided by the backend system to communicate with the backend system when calling the interfaces provided by the backend system.
[0017] Preferably, the key component is configured to monitor the entire life cycle of the key and communicate with the backend system through a data interface to obtain the real-time status of the key, and display the real-time status of the key in the corresponding visual management interface.
[0018] Preferably, the audit module is further configured to send the audit results to the backend system through a data interface. Correspondingly, the backend system modifies the corresponding data in the database based on the administrator operations passed the audit to make the administrator operations effective.
[0019] According to another aspect of the present invention, the present invention also provides an operation processing method for any of the foregoing quantum key management systems, including:
[0020] When a user accesses the system, authenticate the user's access operation and verify the identity and role of the user; the role is an administrator role or an operator role or an auditor role.
[0021] Based on the role of the accessing user, determine the functional components corresponding to the user, and provide a corresponding visual management interface. When the role is an administrator role or an operator role or an auditor role, the functional components corresponding to the user are a management component or a key component or an audit component respectively;
[0022] Based on the user operations implemented by the user from the visual management interface, call the corresponding interfaces provided by the backend system to send the user operation information to the backend system.
[0023] Wherein, the backend system records the call information of the interface to generate corresponding operation logs. The call information includes administrator operation logs when administrator operation information is implemented when calling the interface, and the call information includes operator operation logs when operator operation information is implemented when calling the interface.
[0024] Preferably, authenticating the user's access operation and verifying the identity and role of the user when the user accesses the system includes:
[0025] Based on the access information provided by the user, the authentication interface is called to send the access information to the backend system through the authentication interface for access security and legality authentication.
[0026] In response to receiving the information that the access security and legality authentication by the backend system is passed, the login interface is called to send the user information to the backend system for user identity and role verification.
[0027] In response to receiving the information that the verification result by the backend system is successful, it is determined that the login is successful, and the user information is stored.
[0028] Correspondingly, in response to the user's successful login, the corresponding function components are loaded based on the user role.
[0029] According to another aspect of the present invention, the present invention also provides an electronic device, including a processor and a memory storing computer program instructions; when the electronic device executes the computer program instructions, the foregoing quantum key management system is implemented.
[0030] According to another aspect of the present invention, the present invention also provides a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the foregoing quantum key management system is implemented.
[0031] The present invention sets up users with three roles (administrator, operator, and auditor, hereinafter referred to as the three system users), and displays the corresponding function components for users with different roles, enabling users to only operate the function components corresponding to their roles, thereby improving the operation security of the system; the present invention adopts the user mode of the three system users, standardizes the quantum key management at the system level, and complies with the relevant regulations on hierarchical protection and the requirements of confidentiality standards in relevant security specifications; the present invention conducts data interaction with the backend system through the interface, decouples the front end from the backend, reduces the complexity of the system, and also improves the operation speed, reliability, and scalability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings in the embodiments of the present application.
[0033] Figure 1 is a schematic block diagram of a quantum key management system according to an embodiment of the present invention.
[0034] Figure 2 is a schematic block diagram of a user access module according to an embodiment of the present invention.
[0035] Figure 3 is a schematic block diagram of a quantum key management system according to another embodiment of the present invention.
[0036] Figure 4 It is a flowchart of a processing method based on the operation of an administrator assigning an operator role to user A according to an embodiment of the present invention.
[0037] Figure 5 It is a flowchart of a processing method based on the configuration operation of an operator according to an embodiment of the present invention.
[0038] Figure 6 It is a flowchart of an operation processing method of a quantum key management system provided according to an embodiment of the present invention.
[0039] Figure 7 It is a block diagram of the structural principle of an electronic device according to an embodiment of the present invention. Detailed implementation manners
[0040] Hereinafter, the principles and spirit of the present application will be described with reference to several exemplary embodiments. It should be understood that the purpose of providing these embodiments is to make the principles and spirit of the present application clearer and more thorough, so that those skilled in the art can better understand and then implement the principles and spirit of the present application. The exemplary embodiments provided herein are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments herein, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0041] Those skilled in the art know that the embodiments of the present application can be implemented as a system, a device, an equipment, a method, a computer-readable storage medium or a computer program product. Therefore, the present disclosure can be specifically implemented in at least one of the following forms: complete hardware, complete software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.
[0042] In this article, elements (such as components, components, processes, steps) defined by the statement "including..." do not exclude the existence of other elements outside the listed elements, that is, other elements that are not explicitly listed may also be included. In this article, any element and its quantity in the drawings are for illustration rather than limitation, and any naming in the drawings is only for distinction and does not have any limiting meaning.
[0043] Hereinafter, with reference to several exemplary or representative embodiments of the present application, the principles and spirit of the present application will be explained in detail.
[0044] Figure 1It is a schematic block diagram of a quantum key management system according to an embodiment of the present invention. In this embodiment, the quantum key management system 1 is connected to the backend system 2 through an interface (API). The interface module 21 in the backend system 2 provides multiple interfaces for the quantum key management system 1 to call, for data transmission between the two. The quantum key management system 1 includes a user access module 11, an interface module 12, a system management module 13, a key management module 14, and an audit module 15. Among them, when a user accesses the quantum key management system 1, the user access module 11 calls the corresponding interface provided by the interface module 21, and the backend processing module 22 in the backend system 2 authenticates the user's access operation and verifies the user's identity and role. The user access module 11 determines the functional components corresponding to the user's role based on the role of the accessing user. When the role is an administrator role or an operator role or an auditor role, the corresponding functional components are a management component or a key component or an audit component respectively. The user access module 11 is connected to the interface module 12 and sends a notification to it to inform the interface module 12 of the functional components determined based on the user role and identity. The interface module 12 provides an interactive interface and provides a corresponding visual management interface for the determined functional components.
[0045] The system management module 13 is used to provide multiple management components for system, device, and user management. Among them, when a user with the role of an administrator performs an administrator operation based on the corresponding management component, the system management module 13 calls the corresponding interface provided by the backend system 2 to send the administrator operation information to the backend system 2. The backend system 2 generates an administrator operation log by recording the call information of the interface and stores it in the operation log in the database 23, where the call information includes the administrator operation information implemented each time the interface is called.
[0046] The key management module 14 is used to provide key components for key policy configuration, key components for monitoring the entire life cycle of keys, and key components for general key management. Among them, when a user with the role of an operator performs an operator operation based on the corresponding key component, the key management module 14 calls the corresponding interface provided by the backend system 2 to send the operator operation information to the backend system 2. The backend system 2 generates an operator operation log by recording the call information of the interface and stores it in the operation log in the database 23, where the call information includes the operator operation information implemented each time the interface is called.
[0047] The auditing module 15 is used to provide an auditing component for auditing administrator operations and operator operations. When a user with the role of auditor performs an auditing operation on administrator operations and / or operator operations based on the auditing component, the auditing module 15 calls the interfaces provided by the backend system 2 to obtain the corresponding administrator operation logs and / or operator operation logs.
[0048] The backend system 2 includes an interface module 21, a backend processing module 22, and a database 23. The interface module 21 provides a variety of interfaces for communicating with the quantum key management system 1. The relevant information of various operations performed by users of various roles through the quantum key management system 1 is sent to the backend system 2 through the corresponding interfaces and processed by the corresponding processing units in the backend processing module 22. The database 23 is used to store various data, such as operation logs, such as administrator operation logs, operator operation logs, etc., such as the cryptographic machine resource pool, cryptographic archives, cryptographic templates / cryptographic policy libraries, and configuration data. It is used to store the configuration data of various systems and users performed by administrator users, the key generation and distribution policies configured by operators, the cryptographic templates applied, the passwords used, and so on.
[0049] Users perform various operations by accessing the quantum key management system 1 of the present invention and send the operation information of the users to the backend system 2 for processing through the interfaces. The quantum key management system 1 and the backend system 2 communicate through the interfaces, and the relevant processing performed during key management is implemented by the backend system, achieving the decoupling of the front end and the back end during key management. It can not only expand the system at any time according to the needs of the application, but also reduce the complexity of system development.
[0050] See Figure 2 , Figure 2 is a schematic block diagram of a user access module according to an embodiment of the present invention. The user access module 11 in this embodiment includes an authentication unit 111, a login unit 112, and a loading unit 113. Among them, the user access module 11 is respectively connected to the interface module 12 and the backend system 2. When a user wants to log in and use the quantum key management system 1, the interface module 12 provides an initial access interface, and the user provides access information for authentication of security and legality through the initial access interface. For example, the quantum key management system 1 runs on an electronic device, such as a desktop personal computer, a laptop computer, a tablet computer, etc. The user connects a device with access information, such as a Ukey, to the electronic device, and the electronic device reads the access information from it and transfers it to the user access module 11 in this embodiment.
[0051] The authentication unit 111 in the user access module 11 calls the authentication interface provided by the backend system 2, sends the access information to the backend system 2 through the authentication interface, and the authentication processing unit in the backend system 2 performs authentication processing on the current access information for access security and legality, and returns the processing result to the authentication unit 111 through the authentication interface. When the returned authentication result is passed, the authentication unit 111 sends a notice to the login unit 112. The login unit 112 calls the login interface to send the user information in the access information to the login verification processing unit of the backend system 2 to verify the identity and role of the user, and the backend system 2 returns the verification result to the login unit 112 through the login interface. In another embodiment, after passing the authentication, the login unit 112 sends a notice to the loading unit 113, the loading unit 113 determines the login interface, and notifies the interface module 12, and the interface module 12 displays the login interface in the interaction interface 121, and the user inputs user information such as username and password through the login interface. The interface module 12 sends the user information input by the user on the login interface to the login unit 112, and at this time, the login unit 112 calls the login interface to send the user information to the backend system 2 to verify the identity and role of the user. After the verification is passed and the login is successful, the login unit 112 sends a notice to the loading unit 113, the loading unit 113 loads the corresponding function components based on the user role, and sends a notice to the interface module 12, and the interface module 12 provides a corresponding visual management interface for the loaded function components.
[0052] In one embodiment, the interface module 12 uses a browser to provide the interface. When implementing various interfaces, a UI component library such as Ant Design Vue is used to design various interfaces such as the initial access interface, the login interface, and various management interfaces. Since Ant Design Vue provides a large number of UI components such as buttons, labels, tables, etc., and also provides various attributes such as fonts, colors, shapes, etc., the visual interface implemented by the present invention has a perfect function and convenient operation.
[0053] In this embodiment, when providing a corresponding visual management interface for the determined function component, the function component is loaded into the browser in the form of a page, and when switching the function component, the page corresponding to the function component is switched through the routing component embedded in the browser, such as VueRouter.
[0054] Figure 3 is a schematic block diagram of a quantum key management system according to another embodiment of the present invention, and Figure 1Compared with the embodiments shown, the quantum key management system 1 in this embodiment further includes a network request encapsulation module 16. When the user access module 11, the system management module 13, the key management module 14, and the audit module 15 call an interface, they send the interface call request to the network request encapsulation module 16. The network request encapsulation module 16 uses the network request method encapsulated by Axios to call the corresponding interface provided by the backend system 2 to communicate with the backend system 2. Since each functional component in this embodiment is loaded into the browser in the form of a page, when communicating with the backend system 2 by calling the interface, the access information, user information, various operation information, etc. that need to be sent are sent to the backend system 2 in the form of a network request. Among them, Axios is an HTTP client that can create XMLHttpRequests. When initiating an Http request, in order to save time, Axios is encapsulated, including setting the baseURL or configuring a proxy, configuring the request header, request address, error handling, request interceptor, response interceptor, etc. Then, an api.js file is created, and the foregoing configuration data is loaded into the api.js file. When the interface (API) of the backend system 2 needs to be called, the configured Axios encapsulation is used to initiate a network request, thus saving the repetitive operations when initiating a request. Therefore, both development time and running time are saved, and the data processing speed is improved.
[0055] When the role of the accessing user is an administrator role, the interface module 12 provides the corresponding management interfaces for multiple management components. The administrator can perform user management, role management, and menu management. For example, the administrator can perform operations such as adding, deleting, modifying, and querying users, roles, and menus. The administrator can assign users as administrators, operators, and auditors or other system roles (such as testers, surrogate administrators, or surrogate operators), and can also assign menus for display and operable buttons to users with different roles. The permissions of users with different roles can be reconfigured, and different roles can only open part of the operation permissions to assist the three system administrators in management. When the administrator performs each of the above operations, the interface provided by the backend system 2 is called for the operation. The backend system 2 records the specific information of the operation in the database. The backend system 2 records each operation of the administrator according to the interface call situation and generates an administrator operation log.
[0056] Taking the operation of an administrator assigning an operator role to a user as an example to illustrate the processing process of this operation, see Figure 4 , Figure 4 is a flowchart of a processing method based on the operation of an administrator assigning an operator role to a user A according to an embodiment of the present invention, including the following steps:
[0057] Step S11, obtain the operation information implemented by the administrator user, including the operation category, such as role assignment, and also including the operation content data, such as the user name of User A and the newly assigned operator role.
[0058] Step S12, create a network request, and add the operation information to the network request through the network request encapsulation module 16.
[0059] Step S13, the network request encapsulation module 16 calls the relevant interface of the backend system 2 to send the network request to the backend system 2.
[0060] Step S21, the backend system 2 receives the network request, obtains the operation information from it and records it in the database.
[0061] Step S22, the backend system 2 records the call information of the interface to generate an administrator operation log.
[0062] In one embodiment, after receiving the operation information implemented by the administrator, the backend system 2 generates an audit form and stores it in a preset location in the database. For the processing of the audit form, either send an audit notice to the auditor (such as a user with an audit role) when it is generated, or the auditor processes the audit form according to a preset processing cycle. After the aforementioned administrator operation is audited and passed by the auditing user, in step S23, modify the corresponding data in the database 23 based on the data corresponding to the administrator operation that has passed the audit to make the administrator operation effective. For example, modify the role of User A to an operator and configure its corresponding permissions. In step S24, send the information of successful audit and effective operation to the system management module 13 through the interface.
[0063] After receiving the information returned by the backend system 2, in step S14, the system management module 13 displays the corresponding information indicating the successful administrator operation in the corresponding interface. If the audit of the administrator operation fails, the audit result is also sent to the system management module 13 through the interface, and the information indicating the unsuccessful administrator operation is displayed in the corresponding interface. Optionally, when sending the audit result to the system management module 13, the reason for non-passing can also be included. Correspondingly, the reason for the failure of the administrator operation audit is displayed in the corresponding interface.
[0064] The processing method of other operations of the administrator in the present invention is the same as that of the aforementioned operations and will not be elaborated here.
[0065] When the role of the accessing user is an operator role, the management interface provided by the interface module 12 corresponds to multiple key components provided by the key management module 14 respectively. The operator configures the key generation policy and manages the entire life cycle of the key through the management interface. In the present invention, the key management module 14 is separated from the backend system 2, and the communication between the two is implemented through the interface provided by the backend system 2, realizing the decoupling of the front end and the backend, and solving the problems of low development efficiency, high coupling degree and difficulty in handling complex services when the front end and the backend are integrated during key management.
[0066] In one embodiment, the operator is provided with a key component for key policy configuration based on the key management module 14. The policy configuration operation is divided into a key generation policy configuration operation and a key distribution policy configuration operation. The key generation policy configuration includes configuring the source of quantum random numbers, the key length, the key encryption algorithm, and the key update period. After the operator completes the configuration operation, the configuration data is submitted. The processing method for the operator's configuration operation in this embodiment is as Figure 5 shown Figure 5 is a flowchart of a processing method based on the operator's configuration operation according to an embodiment of the present invention.
[0067] Step S31, obtain the operation information implemented by the operator user, including the operation category, such as the key generation policy, and also including the operation content data, such as data on the source of quantum random numbers, the key length, the key encryption algorithm, and the key update period.
[0068] Step S32, create a network request, and add the operation information to the network request through the network request encapsulation module 16.
[0069] Step S33, the network request encapsulation module 16 calls the relevant interface of the backend system 2 to send the network request to the backend system 2.
[0070] Step S41, the backend system 2 receives the network request, obtains the operation information from it and records it in the database.
[0071] Step S42, the backend system 2 records the call information of the interface to generate an operator operation log.
[0072] Step S43, generate a key list. The backend system 2 docks with the device and generates keys and a key list. The key list includes key identification, key length, key start and end times, and key status.
[0073] Step S44, the backend system 2 sends the generated key list to the key management module 14 through the interface.
[0074] Step S34, after the key management module 14 receives the key list, it is displayed in the management interface.
[0075] The key management module 14 also provides a key component for monitoring the entire life cycle of keys, which is used to monitor various states of each key in the key list. The key component communicates with the backend system 2 through a data interface, obtains the real-time status of the keys from the backend system, and displays the real-time status of the keys in the corresponding visualization management interface.
[0076] The key statuses include "to be distributed", "to be stored", "to be backed up", "to be archived", "to be restored", and "to be destroyed". In different statuses, there are different operation buttons corresponding in the display list. The operation buttons include "go to distribute", "go to store", "go to back up", "go to archive", "go to restore", and "go to destroy", etc. During the entire life cycle of the keys, the operator can perform corresponding operations based on the operation buttons.
[0077] For example, when the status of a key is "to be distributed", the operator clicks the "go to distribute" button in the management interface. In one embodiment, when the key management module 14 receives the operation information of the "go to distribute" button, it displays a distribution policy configuration interface, which includes distribution configuration parameter options such as "offline distribution", "online distribution", "IP of the distribution device", and "port". The operator configures the distribution policy in this management interface. In response to the completion of the operator's configuration operation, the key management module 14 creates a network request, adds the distribution configuration parameter data to the network request, calls the distribution interface provided by the backend system 2, sends the distribution configuration parameter data to the backend system 2, the backend system 2 performs the distribution operation, and feeds back the distribution result to the key management module 14. The key management module 14 gives corresponding prompts according to the received distribution result and displays them in the management interface.
[0078] Also for example, when the status of one or more keys is "to be stored", the operator can single-select a key to be stored or multi-select multiple keys to be stored at the same time, click the "go to store" button to complete the key storage. The processing process between the key management module 14 and the backend system 2 during the key storage process is similar to the aforementioned distribution process and will not be elaborated here. The backend system 2 or the storage interface provided by the backend system 2 performs the key storage. The key can be stored in a smart card, a USB flash drive, or the relevant ciphertext can be stored in a hard disk.
[0079] Also for example, when the status of one or more keys is "to be backed up", the operator can select the keys to be backed up and perform backup configuration, such as selecting a key escrow center or setting to back up in the way of key splitting during backup, and complete the backup of the keys through the provided backend interface.
[0080] For another example, when the status of one or more keys is "to be archived", it indicates that the keys are in an enabled or disabled state, and the operator can archive the keys through the "unarchive" button. In one embodiment, when the operator clicks the "unarchive" button, the key management module 14 responds to this operation and generates a prompt message to prompt the operator that the key can only be decrypted after archiving and cannot be encrypted. After the operator clicks the confirmation button, the key management module 14 communicates with the backend system 2 through the backend interface to perform the archiving operation.
[0081] For another example, when the status of one or more keys is "to be restored", the operator can perform a key restoration operation. The key restoration supports user key restoration and judicial key restoration, and records relevant information such as the restoration time.
[0082] When the status of one or more keys is "to be destroyed", a key destruction operation can be performed. When the operator clicks the "destroy" button, the key management module 14 responds to this operation and generates a prompt message to prompt that the original key cannot be restored after key destruction, and the destruction will delete all key copies. After the operator clicks the confirmation button, the key management module 14 communicates with the backend system 2 through the interface of the backend system 2 to perform the key deletion operation.
[0083] The key management module 14 also provides key components for general key management, such as key templates, key application management, key application, user account authorization management, and security and confidentiality devices.
[0084] The key management module 14 responds to the above various operations of the operator by calling the interface of the backend system 2. The backend system records the above various operations in the database and generates an operator operation log based on the call situation of the interface.
[0085] When the role of the accessing user is the auditor role, the management interface provided by the interface module 12 corresponds to one or more audit components provided by the audit module 15.
[0086] The content that the audit module 15 needs to audit is the operation logs of various operations of administrators, operators or other types of personnel. In one embodiment, the audit module 15 obtains the administrator logs and / or operator logs by calling the interfaces provided by the backend system 2. The auditor analyzes and monitors by viewing the operation logs, and can also export and back up the log list to ensure that the operations of users of each role in the system are safe and authorized and approved. The audit results of the auditor are sent by the audit module 15 to the backend system 2 through a data interface. The backend system 2 modifies the corresponding data in the database based on the data corresponding to the administrator operations that pass the audit to make the administrator operations effective. For example, when an administrator assigns an operator role to a user, this operation does not take effect immediately. After the auditor audits and passes this operation, and the audit results are sent by the audit module 15 to the backend system 2 through the data interface, the backend system 2 records the audit results, and according to the specific information of the administrator's role assignment operation, queries the personal information of the user in the database 23, modifies its role to operator, and sets the corresponding permissions for it according to the permission rules of the operator, so as to make the administrator's operation effective. Optionally, the backend system 2 sends a validation notice to the system management module 13 so that the administrator can know whether his operation has taken effect. Similarly, if the auditor fails to pass the audit of the administrator operation, the backend system 2 records the audit results and sends a message that the audit has not passed to the system management module 13 so that the administrator can know that his operation has not been audited.
[0087] The present invention sets three types of user roles (administrator, operator, and auditor, hereinafter referred to as the three system personnel) for the system. The administrator is mainly responsible for the daily operation and maintenance of the system; the operator is mainly responsible for the daily security and confidentiality management of the system, including user account authorization management and operations related to security and confidentiality equipment and system keys; the auditor is mainly responsible for auditing, tracking, analyzing, and supervising the operation behaviors of the administrator and the operator in order to detect violations in a timely manner. First, the backend system 2 initializes the user accounts and configuration information of the three system personnel, and the account information of the users cannot be modified through this system, thus ensuring the operation security of the key management system and meeting the relevant regulations of hierarchical protection and the requirements of confidentiality standards in relevant security specifications.
[0088] In one embodiment, the quantum key management system provided by the present invention is based on the Vue architecture, uses Vite to build various management function components, and the loading speed of the function components is fast; uses Ant Design Vue to provide a visual interaction interface, which is convenient to operate; generates corresponding request information based on user operations, and conducts data interaction with the backend system 2 through the interfaces provided by C language, decoupling the front end from the backend, reducing the complexity of the system, and also improving the running speed, reliability and scalability of the system.
[0089] On the other hand, the present invention provides an operation processing method for a quantum key management system. Refer to Figure 6 , Figure 6 which is a flowchart of the operation processing method for a quantum key management system provided according to an embodiment of the present invention. The operation processing method includes the following steps:
[0090] S101, authenticate the access operation of the user and verify the identity and role of the user when the user accesses the system. The role is an administrator role or an operator role or an auditor role.
[0091] S102, determine the function component corresponding to the user based on the role of the accessing user, and provide a corresponding visual management interface. When the role is an administrator role or an operator role or an auditor role, the function components corresponding to the user are a management component or a key component or an audit component respectively.
[0092] S103, based on the user operation implemented by the user from the visual management interface, call the corresponding interface provided by the backend system to send the user operation information to the backend system.
[0093] Among them, refer to Figure 1 or Figure 3 , the interface module 12 of the quantum key management system 1 provides an initial access interface, a login interface, a main interface, and management interfaces corresponding to each management module component. In step S101, when the quantum key management system 1 is started on an electronic device, an initial access interface is provided. When the user inserts a device such as a Ukey into the electronic device running the quantum key management system 1, the access information is read from the Ukey and transmitted to the quantum key management system 1. The quantum key management system 1 calls the authentication interface to send the access information to the backend system 2 for access security and legality authentication. When receiving the information that the access security and legality authentication by the backend system 2 is passed, the login interface is displayed. The user inputs user information, such as a username, password, etc., on the login interface. The quantum key management system 1 calls the login interface to send the user information to the backend system 2 to verify the identity and role of the user. When receiving the information that the verification result by the backend system 2 is successful, it is determined that the login is successful. When the interface module 12 provides the interface using a browser, after successful login, it is redirected to the user home page by Vue Router, and the currently logged-in user information, such as Token, mobile phone number, etc., is saved using Pinia (a repository of Vue). After entering the user home page, the interface module 12 obtains the user information through the user information interface and displays it on the user home page. The user information includes relevant information such as the user name, login method, login IP, and login time, etc.
[0094] Based on the user information of the accessing user, the role of the accessing user can be determined. In step S102, when the role of the accessing user is an administrator, the management components provided by the system management module 13 are loaded in the form of a page; when the role of the accessing user is an operator, the key components provided by the key management module 14 are loaded in the form of a page; when the role of the accessing user is an auditor, the audit components provided by the audit module 15 are loaded in the form of a page.
[0095] In step S103, when the user performs a user operation from the visual management interface, the corresponding interface provided by the backend system 2 is called to send the user operation information to the backend system 2.
[0096] The backend system 2 records the call information of the interface to generate the corresponding operation log. Among them, when the call information includes the administrator operation information implemented when calling the interface, an administrator operation log is generated, and when the call information includes the operator operation information implemented when calling the interface, an operator operation log is generated. For specific reference, see the foregoing description of the quantum key management system 1, which will not be elaborated here.
[0097] On the other hand, the present invention also provides an electronic device. See Figure 7 , Figure 7 is the structural principle block diagram of an electronic device according to an embodiment of the present invention. As Figure 7 shown, the electronic device includes a processor 601 and a memory 602 storing computer program instructions; when the processor 601 executes the computer program instructions, the quantum key management system in the foregoing embodiment is implemented.
[0098] Specifically, the processor 601 may include a central processing unit (CPU) or a graphics processing unit (GPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention. The memory 602 may include a memory for data or instructions. For example, the memory 602 may be at least one of the following: a hard disk drive (HDD), a read-only memory (ROM), a random access memory (RAM), a floppy disk drive, a flash memory, an optical disc, a magneto-optical disc, a magnetic tape, a universal serial bus (USB) drive, or other physical / tangible memory storage devices. Also, the memory 602 includes a removable or non-removable (or fixed) medium. Further, the memory 602 may be inside or outside the integrated gateway disaster recovery device. The memory 602 may be a non-volatile solid-state memory. In other words, generally, the memory 602 includes a tangible (non-transitory) computer-readable storage medium (such as a memory device) encoded with executable instructions, and when the stored executable instructions are executed by the processor 601 (such as by one or more processors), the quantum key management system 1 in the embodiments of the present invention can be implemented.
[0099] In one example, Figure 7 The illustrated electronic device may further include a communication interface 603 and a bus 610. Among them, the processor 601, the memory 602, and the communication interface 603 are connected through the bus 610 to complete communication with each other. The communication interface 603 is mainly used to implement communication between various modules, devices, units, and / or devices in the electronic device.
[0100] The bus 610 includes hardware, software, or both, and can couple the components of the online data flow charging device to each other. For example, the bus may include at least one of the following: an accelerated graphics port (AGP) or other graphics buses, an enhanced industry standard architecture (EISA) bus, a front-side bus (FSB), a hypertransport (HT) interconnect, an industry standard architecture (ISA) bus, an infinite bandwidth interconnect, a low pin count (LPC) bus, a memory bus, a microchannel architecture (MCA) bus, a peripheral component interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a serial advanced technology attachment (SATA) bus, a video electronics standards association local (VLB) bus, or other suitable buses. The bus 610 may include one or more buses. Although the embodiments of the present invention describe or illustrate specific buses, the embodiments of the present invention may contemplate any suitable bus or interconnect method.
[0101] On the other hand, an embodiment of the present invention further provides a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the foregoing quantum key management system is implemented.
[0102] The flowcharts and / or block diagrams of the methods, systems, and computer program products of the embodiments of the present invention are described above by way of example, and the relevant aspects are described. It should be understood that each block or a combination thereof in the flowchart and / or block diagram can be implemented by computer program instructions, or by dedicated hardware that performs a specified function or action, or by a combination of dedicated hardware and computer instructions. For example, these computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to form a machine, so that these instructions executed by such a processor enable the implementation of the specified function / action in each block or a combination thereof in the flowchart and / or block diagram. Such a processor can be a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit.
[0103] The functional blocks shown in the structural block diagrams of the embodiments of the present invention can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc.; when implemented in software, it is a program or a code segment for performing the required tasks. The program or code segment can be stored in a memory, or transmitted via a data signal carried in a carrier wave on a transmission medium or a communication link. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.
[0104] It should be noted that the present invention is not limited to the specific configurations and processes described above or shown in the figures. The above are only specific embodiments of the present invention. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the described systems, devices, modules, or units can refer to the corresponding processes in the method embodiments and will not be repeated here. It should be understood that the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered by the protection scope of the present invention.
Claims
1. A quantum key management system, characterized in that, Including: A user access module, configured to authenticate a user's access operation, verify the identity and role of the user, and determine the corresponding functional component of the user based on the role of the user; when the role is an administrator role or an operator role or an auditor role, the corresponding functional components of the user are a management component or a key component or an audit component respectively; An interface module, configured to provide a corresponding visual management interface for the functional component; A system management module, configured to provide multiple management components for system and user management. Among them, when a user with the role of administrator performs an administrator operation based on the corresponding management component, the system management module calls the corresponding interface provided by the backend system to send the administrator operation information to the backend system, and the backend system generates an administrator operation log by recording the call information of the interface, where the call information includes the administrator operation information implemented each time the interface is called; A key management module, configured to provide a key component for key policy configuration, a key component for monitoring the entire life cycle of keys, and a key component for general key management. Among them, when a user with the role of operator performs an operator operation based on the corresponding key component, the key management module calls the corresponding interface provided by the backend system to send the operator operation information to the backend system, and the backend system generates an operator operation log by recording the call information of the interface, where the call information includes the operator operation information implemented each time the interface is called; An audit module, configured to provide an audit component for auditing administrator operations and operator operations. When a user with the role of auditor performs an audit operation on administrator operations and / or operator operations based on the audit component, the audit module calls the interface provided by the backend system to obtain the corresponding administrator operation log and / or operator operation log.
2. The quantum key management system according to claim 1, wherein The user access module includes: An authentication unit, configured to call an authentication interface to send the access information provided by the user to the backend system for access security and legality authentication, and confirm whether the access information provided by the user passes the authentication based on the authentication result returned by the backend system; A login unit, configured to, after authentication passes, call a login interface to send the user information provided by the user to the backend system to verify the identity and role of the user, and confirm whether the user logs in successfully based on the verification result returned by the backend system; A loading unit, configured to, after successful login, load the corresponding functional component based on the user role; Correspondingly, the interface module provides a corresponding visual management interface for the loaded functional component.
3. The quantum key management system according to claim 1, wherein The interface module is configured to use a browser to provide a corresponding visual management interface for the determined functional component; the functional component is loaded into the browser in the form of a page, and when switching the functional component, the page corresponding to the functional component is switched through the routing component embedded in the browser.
4. The quantum key management system according to claim 3, wherein It further includes a network request encapsulation module, configured to, when communicating with the backend system by calling the interface provided by the backend system, call the interface provided by the backend system to communicate with the backend system by using the network request method encapsulated by Axios.
5. The quantum key management system according to claim 3, wherein The key component is configured to monitor the entire life cycle of the key, communicate with the backend system through a data interface to obtain the real-time status of the key, and display the real-time status of the key in the corresponding visualization management interface.
6. The quantum key management system according to claim 1, characterized in that, The audit module is further configured to send the audit result to the backend system through a data interface. Correspondingly, the backend system modifies the corresponding data in the database based on the administrator operation that passes the audit to make the administrator operation effective.
7. A method for operating and processing a quantum key management system according to any one of claims 1-6, characterized in that, including: Authenticate the user's access operation when the user accesses the system and verify the identity and role of the user; The role is an administrator role or an operator role or an auditor role; Determine the function component corresponding to the user based on the role of the accessing user, and provide the corresponding visualization management interface. When the role is an administrator role or an operator role or an auditor role, the function components corresponding to the user are a management component, a key component, or an audit component respectively; Based on the user operation implemented by the user from the visualization management interface, call the corresponding interface provided by the backend system to send the user operation information to the backend system; Among them, the backend system records the call information of the interface to generate the corresponding operation log. The call information includes generating an administrator operation log when the administrator operation information implemented when calling the interface, and the call information includes generating an operator operation log when the operator operation information implemented when calling the interface.
8. The operation processing method of the quantum key management system according to claim 7, characterized in that Authenticating the user's access operation and verifying the identity and role of the user when the user accesses the system includes: Based on the access information provided by the user, call the authentication interface to send the access information to the backend system through the authentication interface for access security and legality authentication; In response to receiving the information that the access security and legality authentication passed returned by the backend system, call the login interface to send the user information provided by the user to the backend system to verify the identity and role of the user; In response to receiving the information that the verification result is successful returned by the backend system, determine that the login is successful and store the user information; Correspondingly, in response to the user logging in successfully, load the corresponding function component based on the user role.
9. An electronic device, characterized in that, including a processor and a memory storing computer program instructions; when the electronic device executes the computer program instructions, it implements the quantum key management system according to any one of claims 1-6.
10. A computer-readable storage medium, characterized in that, Computer program instructions are stored on the computer-readable storage medium, and when the computer program instructions are executed by the processor, the quantum key management system according to any one of claims 1-6 is implemented.
Citation Information
Patent Citations
A database-based quantum key management method and device
CN111475822B
Quantum key management method and application system thereof
CN116192376A