Password service method and system and electronic equipment

By integrating and mapping the password device resources of different manufacturers, determining the utilization rate of VSM and dynamically expanding it, the problems of low password resource utilization and unbalanced equipment use are solved, and the rational allocation and unified management of resources are achieved.

CN120238347APending Publication Date: 2025-07-01CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510376934.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

In the existing data security encryption technology, the password resource allocation method of cryptographic equipment is fixed, resulting in low resource utilization and unbalanced equipment use. There are management barriers between manufacturers, and unified management and reasonable allocation cannot be achieved.

Method used

By integrating the password device resources of different manufacturers, the resource utilization rate of the virtual password machine VSM is determined, the target index resource is selected, and interface mapping and dynamic expansion is carried out to achieve reasonable allocation and call resources.

Benefits of technology

It improves the resource utilization rate of the cryptographic resource pool, breaks down factory barriers, realizes unified management of cryptographic equipment of each manufacturer, reduces the granularity of resource allocation, and avoids resource waste and imbalance problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238347A_ABST
    Figure CN120238347A_ABST
Patent Text Reader

Abstract

The invention discloses a password service method and system and electronic equipment, and the method comprises the steps: integrating password resources of password equipment of different manufacturers, and determining a resource utilization rate corresponding to a VSM in each password equipment; selecting a target index resource according to the resource utilization rate corresponding to each VSM; and calling the password service according to the target index resource. Through the technical scheme provided by the embodiment of the invention, the situation of binding password equipment limited by a single manufacturer is eliminated, the ecology of the password equipment is increased, and the management barrier of the password equipment of each manufacturer is broken, so that the password equipment of each manufacturer can be managed in a unified manner, reasonable allocation and use of password resources are realized, and the user experience is improved. The resource utilization rate of the password resource pool is improved, and the problem of unbalanced use of the password device is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer network technologies, and in particular, to a password service method, system, and electronic device. Background Art

[0002] With the continuous development of the Internet economy, network information is also growing continuously. While network information brings convenience to people, it also exposes a large amount of sensitive data on the network, resulting in information leakage and a series of serious consequences.

[0003] To prevent sensitive data from being exposed on the network, data security encryption technologies can be used to protect sensitive data. Among them, data security encryption technologies can be implemented using password devices.

[0004] However, most of the password service systems of the password devices used in current data security encryption technologies adopt the traditional fixed password resource allocation method to allocate password resources for password service calls, and there are barriers between the password devices of different manufacturers, making it impossible to achieve unified management, and thus impossible to allocate and use password resources reasonably, resulting in low resource utilization of the password resource pool and uneven use of password devices. Summary of the Invention

[0005] This application provides a password service method to solve the problems of low resource utilization of the password resource pool and uneven use of password devices. The specific implementation solution is as follows:

[0006] In a first aspect, this application provides a password service method, and the method includes:

[0007] Integrate the password resources of password devices from different manufacturers, and determine the respective resource utilization rates of the virtual password machines (VSMs) in each of the password devices; where the password resources include the index resources of the VSMs.

[0008] Select target index resources according to the respective resource utilization rates of each VSM.

[0009] Perform password service calls according to the target index resources.

[0010] Through the above application embodiments, the password resources of password devices from different manufacturers are integrated to obtain the respective resource utilization rates of the VSMs in each password device, thus getting rid of the situation restricted by the binding of password devices of a single manufacturer, increasing the ecological nature of password devices, breaking the management barriers of password devices of each manufacturer, so that the password devices of each manufacturer can be uniformly managed. Then, according to the respective resource utilization rates of the VSMs in each password device, the usage situation of the password resources of all password devices can be determined. Thus, based on this resource utilization rate (i.e., the usage situation of password resources), the target index resource can be selected, making the allocation of password resources more reasonable. Then, according to the target index resource, the password service is called, realizing the reasonable use of the index resource (i.e., password resource), making the allocation and use of password resources more rational, thereby improving the resource utilization rate of the password resource pool and making the use of password devices more balanced. Moreover, allocating password resources according to the index dimension reduces the allocation granularity of password resources, further improving the resource utilization rate of the password resource pool and avoiding the problem of unbalanced use of password devices.

[0011] In a possible implementation manner, the password device includes a plurality of cipher machines, each cipher machine includes a plurality of the VSMs, and each VSM includes a plurality of index positions. The integrating the password resources of password devices from different manufacturers and determining the respective resource utilization rates of the virtual cipher machines VSMs in each password device includes:

[0012] Maintaining the first correspondence of the password resources of the password devices from different manufacturers and the second correspondence of the used password resources of the password devices; wherein, the first correspondence is the correspondence among the identification code ID of the cipher machine, the ID of the VSM, and the index capacity, and the second correspondence is the correspondence among the ID of the cipher machine, the ID of the VSM, and the used index positions.

[0013] According to the first correspondence and the second correspondence, determining the third correspondence of the remaining password resources of the password device and maintaining the third correspondence; wherein, the third correspondence is the correspondence among the ID of the cipher machine, the ID of the VSM, and the resource utilization rate of the VSM.

[0014] According to the third correspondence, determining the respective resource utilization rates of the VSMs in each password device.

[0015] Through the above application embodiments, by maintaining the first correspondence relationship (i.e., the correspondence relationship among the ID of the cipher machine, the ID of the VSM, and the index capacity), the index capacity of the VSM can be accurately determined according to the ID of the cipher machine or the ID of the VSM, so as to determine the resource utilization rate of the VSM. Moreover, by maintaining the second correspondence relationship (i.e., the correspondence relationship among the ID of the cipher machine, the ID of the VSM, and the index position), the used cipher resources in the cipher device can be accurately determined, and thus the used index resources in the corresponding VSM can be accurately determined, that is, the used index quantity of the corresponding VSM can be determined, so as to determine the resource utilization rate of the VSM. Then, through the determined third correspondence relationship (i.e., the ID of the cipher machine, the ID of the VSM, and the resource utilization rate of the VSM), the resource utilization rate of the VSM can be accurately determined.

[0016] In a possible implementation manner, the third correspondence relationship for determining the remaining cipher resources of the cipher device according to the first correspondence relationship and the second correspondence relationship includes:

[0017] Determine the index capacity of the VSM in the cipher resources according to the first correspondence relationship; and

[0018] Determine the used index quantity of the VSM according to the second correspondence relationship;

[0019] For each VSM, calculate the ratio between the corresponding used index quantity and the index capacity, and use the ratio as the resource utilization rate of the corresponding VSM;

[0020] Determine the third correspondence relationship of the remaining cipher resources of the cipher device according to the resource utilization rate of the VSM.

[0021] Through the above application embodiments, according to the first correspondence relationship, the index capacity of the VSM is quickly and accurately determined, and according to the second correspondence relationship, the used index quantity of the VSM is quickly and accurately determined; then, according to the ratio between the determined used index quantity and the index capacity of the VSM, the resource utilization rate of the VSM is obtained, making the resource utilization rate of the VSM more accurate, so as to accurately learn the usage of the cipher resources of each cipher device, thereby providing a basis for the flexible allocation of cipher resources.

[0022] In a possible implementation manner, the invoking of the cipher service according to the target index resource includes:

[0023] Select a target cipher device according to the target index resource;

[0024] Convert the standard interface of the target cryptographic device and the manufacturer interface of the target cryptographic device according to the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device.

[0025] Invoke the cryptographic service using the converted interface.

[0026] Through the above application embodiments, the cryptographic service is invoked according to the target index resource and the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device, so as to solve the problem that in the existing cryptographic service management platform, due to the differences in the interfaces of cryptographic devices of each manufacturer, the application party can only use the service capabilities of the cryptographic devices of a single manufacturer, resulting in uneven use of the cryptographic devices in the cryptographic resource pool.

[0027] In a possible implementation manner, before converting the standard interface of the target cryptographic device and the manufacturer interface of the target cryptographic device according to the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device, it further includes:

[0028] Obtain the interface documents corresponding to the cryptographic devices of different manufacturers respectively;

[0029] Parse the content in each of the interface documents to obtain the interface functions and interface parameters included in each of the interface documents respectively;

[0030] According to the interface functions, determine the homogeneous interfaces belonging to the same type of interface functions from multiple interfaces, and calculate the similarity of the attribute values of the interface parameters for each group of the homogeneous interfaces respectively;

[0031] Store the attribute values corresponding to the similarity within the range from the first similarity threshold to the second similarity threshold into the corresponding attribute pool; wherein, the first similarity threshold is less than the second similarity threshold; one attribute pool corresponds to one group of the homogeneous interfaces;

[0032] Normalize the attribute values in each of the attribute pools respectively to obtain the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device.

[0033] Through the above application embodiments, the interface documents of password devices from different manufacturers are parsed to extract the interface functions and interface parameters in the interface documents. Then, through similarity calculation and judgment of the similarity with the first similarity threshold and the second similarity threshold, the attribute values are stored in the corresponding attribute pools. Subsequently, by standardizing the attribute values in each attribute pool respectively, the mapping relationship between the standard interfaces of the password devices and the manufacturer interfaces of the password devices is obtained, thereby providing a unified interface for the manufacturer interfaces of password devices from different manufacturers, so as to eliminate the dependence of the password service application side on the password devices.

[0034] In a possible implementation manner, the method further includes:

[0035] Calculating the trend value of the resource utilization rate within a preset time period;

[0036] If it is determined that the trend value is greater than the trend threshold, it is determined that the change trend of the resource utilization rate is rising, and the password resources are expanded;

[0037] If it is determined that the trend value is less than the trend threshold, it is determined that the change trend is falling, and the password resources are scaled down;

[0038] If it is determined that the trend value is equal to the trend threshold, it is determined that the change trend remains unchanged, and the password resources remain unchanged.

[0039] Through the above application embodiments, after calculating the trend value of the resource utilization rate within a preset time period, according to the comparison result of the trend value with the trend threshold, it is determined whether the change trend of the resource utilization rate is rising, falling or remaining unchanged, so as to expand or scale down the password resources, realizing the dynamic expansion and contraction of the password resources, which can avoid the adverse impact on business operations in the case of insufficient password resources, and avoid the waste of resources caused by excessive password resources.

[0040] In a possible implementation manner, calculating the trend value of the resource utilization rate within a preset time period includes:

[0041] Dividing the preset time period into multiple sub-time periods; wherein, each sub-time period includes a start time and an end time, and the end time of the current sub-time period is the start time of the next sub-time period;

[0042] Calculating the resource utilization rate increment within each sub-time period; wherein, the resource utilization rate increment is the ratio of the difference between the resource utilization rate at the end time corresponding to the sub-time period and the resource utilization rate at the corresponding start time to the difference between the corresponding end time and the corresponding start time;

[0043] Multiply the differences in the increased values of the resource utilization rate for each set of adjacent sub - time periods, and use the resulting product as the trend value of the resource utilization rate within the preset time period; wherein, the difference in the increased values of the resource utilization rate within the adjacent sub - time periods is the difference between the increased value of the resource utilization rate in the next sub - time period and the increased value of the resource utilization rate in the current sub - time period.

[0044] Through the above - mentioned application embodiments, the preset time period is divided into multiple sub - time periods, then the increased value of the resource utilization rate in each sub - time period is calculated, and then based on the product obtained by multiplying the differences in the increased values of the resource utilization rate for each set of adjacent sub - time periods, the trend value of the resource utilization rate within the preset time period is obtained, thereby making the calculated trend value more accurate and better able to represent the change trend of the resource utilization rate within the preset time period. Moreover, by using the ratio of the difference between the resource utilization rate at the end time corresponding to the sub - time period and the resource utilization rate at the start time corresponding to the sub - time period to the difference between the end time corresponding to the sub - time period and the start time corresponding to the sub - time period to obtain the increased value of the resource utilization rate within the sub - time period, the calculated increased value of the resource utilization rate is more accurate, and thus further makes the calculated trend value more accurate.

[0045] In a possible implementation manner, the expansion of the cryptographic resources of the cryptographic device includes:

[0046] Determine whether there is a cryptographic device of the manufacturer corresponding to the cryptographic device to be added in the cryptographic resource pool;

[0047] If not, standardize the manufacturer interface corresponding to the cryptographic device to be added to obtain the mapping relationship between the standard interface corresponding to the cryptographic device to be added and the manufacturer interface corresponding to the cryptographic device to be added, and add the cryptographic device to be added to the cryptographic resource pool;

[0048] If so, add the cryptographic device to be added to the cryptographic resource pool;

[0049] Add the cryptographic resource information of the cryptographic device to be added to the cryptographic resource table.

[0050] Through the above application embodiments, the expansion of password resources is achieved. Moreover, based on the judgment result of whether there is a password device of the manufacturer corresponding to the password device to be added in the password resource pool, it is determined whether it is the first time to import the password device of the manufacturer corresponding to the password device to be added into the password resource pool. So that when there is no password device of the manufacturer corresponding to the password device to be added in the password resource pool, the manufacturer interface corresponding to the password device to be added is first standardized to obtain the mapping relationship between the standard interface corresponding to the password device to be added and the manufacturer interface corresponding to the password device to be added, so that the interface can be converted according to this mapping relationship when using the password resources of the password device to be added subsequently. At the same time, the resource information of the password device to be added is added to the password resource list, so as to facilitate the maintenance of the resource information of the password device to be added and to obtain the resource information of the password device to be added in a timely and accurate manner when needed.

[0051] In a possible implementation manner, the reduction of the password resources of the password device includes:

[0052] Determine the VSM to be migrated with the lowest resource utilization rate from all VSMs, and determine the target virtual node corresponding to the VSM to be migrated on the consistent ring according to the hash values corresponding to all index positions in the VSM to be migrated; wherein, the consistent ring is a closed continuous space constructed based on hash values;

[0053] Perform non-intrusive migration on the data corresponding to the target virtual node;

[0054] After the data migration is completed, remove the password resources corresponding to the VSM to be migrated, and remove the target virtual node from the consistent ring.

[0055] Through the above application embodiments, the password resources corresponding to the VSM with the lowest resource utilization rate (i.e., the VSM to be migrated) are removed, and the virtual node corresponding to the VSM with the lowest utilization rate (i.e., the target virtual node) is removed from the consistent ring, thereby achieving the expansion of password resources. Moreover, selecting the VSM with the lowest resource utilization rate to remove password resources can reduce the migration amount of non-intrusive migration of data during the process of removing resources, thereby improving the migration efficiency of the migration process. In addition, selecting the password resources to be removed and migrating the data according to the consistent ring method ensures the fixity of the password resources and avoids the impact of the reduction of password resources on the data corresponding to the non-removed password resources.

[0056] In a possible implementation manner, the non-intrusive migration is specifically:

[0057] Decrypt the data corresponding to the target virtual node, and encrypt the data corresponding to the target virtual node by using the password resources corresponding to the adjacent virtual nodes of the target virtual node.

[0058] Through the above application embodiments, the seamless migration of the data corresponding to the target virtual node is realized, and the impact of the reduction of password resources on the encryption and decryption of the data corresponding to the password resources to be removed is avoided.

[0059] In a second aspect, the present application further provides a password service system, and the system includes:

[0060] An integration module, configured to integrate the password resources of password devices of different manufacturers, and determine the resource utilization rate corresponding to each virtual security module (VSM) in each password device; wherein, the password resources include the index resources of the VSM.

[0061] A selection module, configured to select target index resources according to the resource utilization rate corresponding to each VSM.

[0062] A processing module, configured to call password services according to the target index resources.

[0063] In a possible implementation manner, the password device includes a plurality of cryptographic machines, the cryptographic machine includes a plurality of the VSMs, the VSM includes a plurality of index positions, and the integration module is specifically configured to maintain a first correspondence relationship of the password resources of the password devices of different manufacturers and a second correspondence relationship of the used password resources of the password device; wherein, the first correspondence relationship is the correspondence relationship between the identification code ID of the cryptographic machine, the ID of the VSM, and the index capacity, and the second correspondence relationship is the correspondence relationship between the ID of the cryptographic machine, the ID of the VSM, and the used index positions.

[0064] According to the first correspondence relationship and the second correspondence relationship, determine a third correspondence relationship of the remaining password resources of the password device, and maintain the third correspondence relationship; wherein, the third correspondence relationship is the correspondence relationship between the ID of the cryptographic machine, the ID of the VSM, and the resource utilization rate of the VSM.

[0065] According to the third correspondence relationship, determine the resource utilization rate corresponding to each VSM in each password device.

[0066] In a possible implementation manner, the integration module is specifically configured to determine the index capacity of the VSM in the password resources according to the first correspondence relationship; and

[0067] Determine the index used amount of the VSM according to the second correspondence relationship.

[0068] For each of the VSMs, calculate the ratio between the corresponding used index amount and the index capacity, and use the ratio as the resource utilization rate of the corresponding VSM.

[0069] Determine the third corresponding relationship of the remaining cryptographic resources of the cryptographic device according to the resource utilization rate of the VSM.

[0070] In a possible implementation manner, the processing module is specifically configured to call a cryptographic service according to the target index resource, including:

[0071] Select a target cryptographic device according to the target index resource.

[0072] Convert the standard interface of the target cryptographic device and the manufacturer interface of the target cryptographic device according to the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device.

[0073] Call a cryptographic service by using the converted interface.

[0074] In a possible implementation manner, the system further includes a difference masking module, and the difference masking module is configured to obtain the interface documents corresponding to the cryptographic devices of different manufacturers before converting the standard interface of the target cryptographic device and the manufacturer interface of the target cryptographic device according to the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device.

[0075] Parse the content in each of the interface documents respectively to obtain the interface functions and interface parameters included in each of the interface documents.

[0076] According to the interface functions, determine the same-type interfaces belonging to the same-type interface functions from multiple interfaces, and calculate the similarity of the attribute values of the interface parameters for each group of the same-type interfaces respectively.

[0077] Store the attribute values corresponding to the similarity within the range from the first similarity threshold to the second similarity threshold into the corresponding attribute pool; wherein, the first similarity threshold is less than the second similarity threshold; one attribute pool corresponds to one group of the same-type interfaces.

[0078] Standardize the attribute values in each of the attribute pools respectively to obtain the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device.

[0079] In a possible implementation, the system further includes a dynamic resource expansion module, which is used to calculate the trend value of the resource utilization rate within a preset time period;

[0080] If it is determined that the trend value is greater than the trend threshold, it is determined that the change trend of the resource utilization rate is rising, and the password resources are expanded;

[0081] If it is determined that the trend value is less than the trend threshold, it is determined that the change trend is falling, and the password resources are scaled down;

[0082] If it is determined that the trend value is equal to the trend threshold, it is determined that the change trend remains unchanged, and the password resources remain unchanged.

[0083] In a possible implementation, the dynamic resource expansion module is specifically used to divide the preset time period into multiple sub-time periods; where each sub-time period includes a start time and an end time, and the end time of the current sub-time period is the start time of the next sub-time period;

[0084] Calculate the resource utilization rate increment within each sub-time period; where the resource utilization rate increment is the ratio of the difference between the resource utilization rate at the end time corresponding to the sub-time period and the resource utilization rate at the corresponding start time to the difference between the corresponding end time and the corresponding start time;

[0085] Multiply the differences between the resource utilization rate increments within each group of adjacent sub-time periods, and use the obtained product as the trend value of the resource utilization rate within the preset time period; where the difference between the resource utilization rate increments within the adjacent sub-time periods is the difference between the resource utilization rate increment in the next sub-time period and the resource utilization rate increment in the current sub-time period.

[0086] In a possible implementation, the dynamic resource expansion module is specifically used to determine whether there is a password device of the manufacturer corresponding to the password device to be added in the password resource pool;

[0087] If not, standardize the manufacturer interface corresponding to the password device to be added to obtain the mapping relationship between the standard interface corresponding to the password device to be added and the manufacturer interface corresponding to the password device to be added, and add the password device to be added to the password resource pool;

[0088] If so, add the password device to be added to the password resource pool;

[0089] Add the password resource information of the password device to be added to the password resource table.

[0090] In a possible implementation manner, the dynamic resource expansion module is specifically configured to determine a VSM to be migrated with the lowest resource utilization rate from all VSMs, and determine a target virtual node corresponding to the VSM to be migrated on the consistent hash ring according to the hash values corresponding to all index positions in the VSM to be migrated; wherein, the consistent hash ring is a closed continuous space constructed based on hash values;

[0091] Perform non-intrusive migration on the data corresponding to the target virtual node;

[0092] After the data migration is completed, remove the password resources corresponding to the VSM to be migrated, and remove the target virtual node from the consistent hash ring.

[0093] In a possible implementation manner, the non-intrusive migration is specifically:

[0094] Decrypt the data corresponding to the target virtual node, and encrypt the data corresponding to the target virtual node by using the password resources corresponding to the adjacent virtual nodes of the target virtual node.

[0095] In a third aspect, the present application provides an electronic device, including:

[0096] A memory for storing a computer program;

[0097] A processor, configured to implement the steps of the above-mentioned password service method when executing the computer program stored on the memory.

[0098] In a fourth aspect, the present application provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned password service method are implemented.

[0099] For the various aspects in the above second aspect to fourth aspect and the possible technical effects that each aspect may achieve, please refer to the technical effects that can be achieved by the above-mentioned first aspect or various possible solutions in the first aspect, and details will not be repeated here. Description of the Drawings

[0100] Figure 1 It is a schematic flowchart of a password service method provided by an embodiment of the present application;

[0101] Figure 2 It is a schematic diagram of a cipher machine provided by an embodiment of the present application;

[0102] Figure 3 It is a schematic flowchart of determining the mapping relationship between the standard interface of a password device and the manufacturer interface of the password device provided by an embodiment of the present application;

[0103] Figure 4 Schematic diagram of the processing procedure of the password service method provided by the embodiment of the present application;

[0104] Figure 5 Schematic diagram of a password service system provided by the embodiment of the present application;

[0105] Figure 6 Schematic diagram of an electronic device provided by the embodiment of the present application. Detailed implementation manners

[0106] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of the present application, "a plurality of" is understood as "at least two". "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The connection between A and B may represent: the direct connection between A and B and the connection between A and B through C. In addition, in the description of the present application, terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying order.

[0107] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0108] In the continuous development process of information system services, the types of password devices are also increasing. However, most of the current password device application systems use the traditional fixed password resource allocation method to allocate password resources, and there are barriers between the password devices of each manufacturer, making it impossible to uniformly manage the password devices of each manufacturer. As a result, the utilization rate of password resources of password devices is low, and thus the reasonable allocation and use of password resources cannot be carried out, leading to unbalanced resource utilization of password resources.

[0109] Therefore, the present application proposes a password service method, which integrates the password resources of password devices from different manufacturers (the password resources are the index resources of the virtual security module (abbreviated as VSM) in the password device), obtains the resource utilization rate of each password device, thus getting rid of the situation of being restricted by the password devices of a single manufacturer, enhancing the ecology of password devices, breaking the management barriers of password devices of each manufacturer, and thus enabling unified management of password devices of each manufacturer. When ordering password resources, there are more choices. Then, according to the resource utilization rate of each password device, the target index resource is selected, and thus, according to the target index resource, the password service is called, realizing the reasonable allocation and use of the index resources (i.e., password resources), making the allocation and use of password resources more reasonable, and thus improving the resource utilization rate of the password resource pool. Moreover, allocating password resources according to the index dimension reduces the allocation granularity of password resources, greatly improves the resource utilization rate of the password resource pool, and solves the problem of uneven use of password devices.

[0110] Refer to Figure 1 The following is a flowchart of a password service method provided by an embodiment of the present application. The method includes:

[0111] S101, Integrate the password resources of password devices from different manufacturers, and determine the respective resource utilization rates corresponding to the VSMs in each password device.

[0112] In the embodiment of the present application, the password resources of the password device may include the password resources of the cipher machine, and the password device may include a cipher machine.

[0113] As Figure 2 shown, a cipher machine can virtualize different numbers of VSMs according to different specifications. Moreover, each VSM contains different index bit resources (i.e., password resources at specific index positions). This index bit resource is the password resource actually used by the password device. Therefore, the above-mentioned password resources of the password device include the index resources of the VSM in the password device.

[0114] In order to get rid of the situation of being restricted by the password devices of a single manufacturer, the password resources of password devices from different manufacturers are integrated to obtain the resource utilization rate of each password device, so as to get rid of the situation of being restricted by the password devices of a single manufacturer, enhance the ecology of password devices, break the management barriers of password devices of each manufacturer, and then enable unified management of password devices of each manufacturer.

[0115] Specifically, first, maintain the first correspondence relationship of the password resources of password devices from different manufacturers, maintain the second correspondence relationship of the used password resources of the password devices, and maintain the third correspondence relationship of the remaining password resources of the password devices, so as to facilitate the integration of the password resources of password devices from different manufacturers.

[0116] In the embodiment of the present application, the above first correspondence relationship is the correspondence relationship among the identification code of the cipher machine (English: Identity document, abbreviated as ID), the ID of the VSM, and the index capacity. Thus, by maintaining the first correspondence relationship, the index capacity of the VSM can be accurately determined according to the ID of the cipher machine and the ID of the VSM, so as to facilitate the determination of the resource utilization rate of the VSM.

[0117] The above second correspondence relationship is the correspondence relationship among the ID of the cipher machine, the ID of the VSM, and the index position, and the index position is the used index position. Thus, by maintaining the second correspondence relationship, the used password resources in the password device can be accurately determined, so as to accurately determine the used index resources in the corresponding VSM, that is, determine the used index quantity of the corresponding VSM.

[0118] Exemplarily, the ID of the cipher machine is 001, and the ID of the VSM is A. Among the multiple existing second correspondence relationships, the second correspondence relationships including 001 and A are: 001 - A - 1, 001 - A - 2, 001 - A - 3, 001 - A - 4. Among them, 1, 2, 3, 4 represent the index positions. It can be seen that the used index positions in the VSM with ID A in the cipher machine with ID 001 are 1, 2, 3, 4, that is, 4 index positions have been used in this VSM, so the used index quantity of this VSM is 4.

[0119] The above third correspondence relationship is the correspondence relationship among the ID of the cipher machine, the ID of the VSM, and the resource utilization rate of the VSM. Thus, by maintaining this third correspondence relationship, the resource utilization rate of the VSM can be accurately determined according to the ID of the cipher machine and the ID of the VSM, so as to perform corresponding processing on the VSM according to this resource utilization rate.

[0120] The resource utilization rate of the VSM in the above third correspondence relationship can be determined according to the first correspondence relationship and the second relationship.

[0121] Specifically, first, determine the index capacity of the VSM according to the first correspondence relationship, and determine the used index quantity of the VSM according to the second correspondence relationship. Then, take the ratio between the used index quantity and the index capacity of the VSM as the resource utilization rate of the VSM, so that the calculated resource utilization rate is more accurate and can better represent the usage situation of the password resources (i.e., index resources) in the VSM.

[0122] S102. Select the target index resource according to the resource utilization rate corresponding to each VSM.

[0123] After obtaining the resource utilization rate corresponding to each VSM in each cryptographic device in step S101, the target index resource is dynamically selected according to the resource utilization rate, so as to rationally utilize the cryptographic device resources and avoid waste of resources.

[0124] Optionally, among the resource utilization rates of all VSMs in all cryptographic devices, select the index resource corresponding to the VSM with the lowest resource utilization rate as the target index resource, so as to rationally utilize the cryptographic resources, avoid waste of resources, and avoid the adverse impact on services when the cryptographic resources are insufficient due to the selection of cryptographic resources with high resource utilization rates.

[0125] S103. Invoke the cryptographic service according to the target index resource.

[0126] Specifically, first, according to the target index resource, select which manufacturer's which cryptographic device to use, that is, determine the target cryptographic device. Then, according to the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device, convert the standard interface of the target cryptographic device and the manufacturer interface of the target cryptographic device. Then, use the converted interface to invoke the cryptographic service, so as to solve the situation that the existing cryptographic service management platform can only be used under the service capabilities of the cryptographic devices of a single manufacturer due to the differences in the interfaces of the cryptographic devices of each manufacturer, resulting in uneven resource utilization rates of the cryptographic devices in the cryptographic resource pool.

[0127] The above mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device can be obtained by parsing the interface documents of the cryptographic devices of different manufacturers, extracting the interface functions and interface parameters in the interface documents, and then performing similarity calculation, similarity threshold judgment, and attribute value standardization. Specifically, this process can be as Figure 3 shown in S301 - S305 below, specifically as follows:

[0128] S301. Obtain the interface documents corresponding to the cryptographic devices of different manufacturers respectively.

[0129] In the embodiments of the present application, a manufacturer can have multiple cryptographic devices, and a cryptographic device can correspond to N interfaces, and each of the N interfaces corresponds to an interface document respectively. The interface document includes information of the corresponding interface, such as interface functions, interface parameters, etc. information. N is a positive integer.

[0130] S302. Parse the content in each interface document separately to obtain the interface functions and interface parameters included in each interface document respectively.

[0131] In the embodiment of the present application, a text parser can be used to parse the content in the interface document, so that the obtained interface functions and interface parameters are more accurate. The interface functions can be functions such as data acquisition functions and configuration information functions.

[0132] In addition, after obtaining the interface functions and interface parameters in the interface document, the fourth correspondence relationship between the interfaces, interface functions, and interface parameters can also be maintained, so as to accurately know which interface has which interface function and what the interface parameters are, so that the relevant information of the interface can be obtained at any time.

[0133] S303. According to the interface functions, determine the similar interfaces with the same type of interface functions from multiple interfaces, and calculate the similarity of the attribute values of the interface parameters for each group of similar interfaces respectively.

[0134] Specifically, determine the similar interfaces with the same type of interface functions from multiple interfaces, and then calculate the similarity between the attribute values of the interface parameters corresponding to each two interfaces in each group of similar interfaces.

[0135] Among them, a group of similar interfaces can include multiple interfaces, and the interface functions of these multiple interfaces are the same, such as all being data acquisition functions. The interfaces of multiple cryptographic devices can be the interfaces corresponding to all the interface documents obtained in step S301; or they can be the interfaces of the cryptographic devices already existing in the cryptographic resource pool.

[0136] Exemplarily, currently there are 2 cryptographic devices from manufacturer A and 3 cryptographic devices from manufacturer B. And each cryptographic device has one interface, so there are a total of 5 interfaces, namely interface A, interface B, interface C, interface D, and interface E. The interface functions corresponding to interface A, interface B, and interface C all belong to the data acquisition function category, so interface A, interface B, and interface C belong to the first group of homogeneous interfaces; the interface functions corresponding to interface D and interface E both belong to the configuration information function category, so interface D and interface E belong to the second group of homogeneous interfaces. Then, among the first group of homogeneous interfaces, calculate the similarity between the attribute value of the interface parameter corresponding to interface A and the attribute value of the interface parameter corresponding to interface B, calculate the similarity between the attribute value of the interface parameter corresponding to interface A and the attribute value of the interface parameter corresponding to interface C, and calculate the similarity between the attribute value of the interface parameter corresponding to interface B and the attribute value of the interface parameter corresponding to interface C. That is, calculate the similarity between the attribute values of the interface parameters corresponding to every two interfaces in the first group of homogeneous interfaces. And in the second group of homogeneous interfaces, calculate the similarity between the attribute value of the interface parameter corresponding to interface D and the attribute value of the interface parameter corresponding to interface E.

[0137] In the embodiment of the present application, the specific calculation process of the above similarity calculation can be as follows:

[0138] First, perform base encoding on the first attribute value and the second attribute value respectively to obtain the base encoding value corresponding to the first attribute value and the base encoding value corresponding to the second attribute value. Among them, the interface functions of the interfaces corresponding to the first attribute value and the second attribute value belong to the same type of interface function. That is, the first attribute value and the second attribute value are the attribute values of the interface parameters corresponding to the same type of interface.

[0139] Next, calculate the distance between the base encoding value corresponding to the first attribute value and the base encoding value corresponding to the second attribute value. Then, use the ratio of the preset value to the sum of the distance and the preset value as the similarity between the first attribute value and the second attribute value, so that the calculated similarity is more accurate and helps to improve the accuracy of storing the attribute value in the corresponding attribute pool.

[0140] The distance between the base encoding value corresponding to the first attribute value and the base encoding value corresponding to the second attribute value can be calculated using the improved Euclidean distance.

[0141] Specifically, first, for the Q (where Q is a positive integer) base encoding values of the first attribute value and the Q base encoding values of the second attribute value, the sum of the squares of the differences between the i-th (where i is an integer from 1 to Q) base encoding value corresponding to the first attribute value and the i-th base encoding value corresponding to the second attribute value is accumulated, and the square root of the accumulated value is taken to obtain the distance between the base encoding value corresponding to the first attribute value and the base encoding value corresponding to the second attribute value, thereby making the obtained distance more accurate, and further making the similarity obtained based on this distance more accurate. This calculation process can be shown by the following formula:

[0142]

[0143] Among them, d represents the distance between the base encoding value corresponding to the first attribute value and the base encoding value corresponding to the second attribute value; x i represents the i-th base encoding value corresponding to the first attribute value; y i represents the i-th base encoding value corresponding to the second attribute value; Q represents the total number of base encoding values.

[0144] The above preset value can be 1. The ratio of the preset value to the sum of the distance and the preset value is used as the similarity between the first attribute value and the second attribute value, which can be shown by the following formula:

[0145]

[0146] Among them, W AB represents the similarity between the first attribute value and the second attribute value.

[0147] S304. Store the attribute values corresponding to the similarities within the range from the first similarity threshold to the second similarity threshold into the corresponding attribute pool.

[0148] Among them, the first similarity threshold is less than the second similarity threshold.

[0149] After using W AB in step S303 to obtain the similarity corresponding to the attribute value, the closer the similarity is to 0.5, the greater the similarity of the corresponding two attribute values, that is, the more similar the two attribute values are; when the similarity deviates at both ends of (0, 1), it indicates that the similarity of the corresponding two attribute values is smaller.

[0150] Therefore, in the embodiments of the present application, it is determined whether two attribute values corresponding to the similarity are similar by whether the similarity is within the range of the first similarity threshold to the second similarity threshold. The first similarity threshold and the second similarity threshold can be flexibly adjusted according to specific application scenarios. For example, the first similarity threshold is 0.4 and the second similarity threshold is 0.6; or the first similarity threshold is 0.45 and the second similarity threshold is 0.55, but it is not limited thereto.

[0151] Specifically, poll the interfaces of password devices of different manufacturers, that is, poll all interfaces, and perform similarity threshold judgment on each similarity corresponding to each attribute value corresponding to each interface. The similarity threshold judgment is as follows:

[0152] Compare the to-be-judged similarity corresponding to the third attribute value (i.e., the to-be-judged attribute value) with the first similarity threshold and the second similarity threshold. Determine whether the to-be-judged similarity is greater than or equal to the first similarity threshold and less than or equal to the second similarity threshold.

[0153] If it is determined that the to-be-judged similarity is greater than or equal to the first similarity threshold and less than or equal to the second similarity threshold, that is, the to-be-judged similarity is within the range of the first similarity threshold and the second similarity threshold, then store the third attribute value into the corresponding attribute pool. The interface functions of the interfaces corresponding to the attribute values included in the corresponding attribute pool all belong to the same type of interface function. In other words, a group of interfaces of the same type corresponds to one attribute pool.

[0154] If it is determined that the to-be-judged similarity is less than the first similarity threshold or greater than the second similarity threshold, that is, the to-be-judged similarity is not between the first similarity threshold and the second similarity threshold, then check the third attribute value and the fourth attribute value corresponding to the to-be-judged similarity, and further determine whether the two attribute values (i.e., the third attribute value and the fourth attribute value) corresponding to the to-be-judged similarity are similar through this check, so as to further improve the accuracy of similarity judgment. Then, after it is determined through the check that the third attribute value and the fourth attribute value are similar, mark the third attribute value and the fourth attribute value to avoid performing similarity threshold judgment on the similarity calculated from the third attribute value and the fourth attribute value again when performing similarity threshold judgment on each similarity corresponding to the fourth attribute value, thereby reducing the number of similarity threshold judgments and improving the efficiency of storing into the attribute pool. Finally, store the third attribute value and the fourth attribute value into the corresponding attribute pool.

[0155] Through the above similarity threshold judgment, the attribute values are accurately stored into the corresponding attribute pools, so that the attribute values in the attribute pools are all the attribute values of the interface parameters corresponding to the corresponding interfaces of the same type.

[0156] Optionally, since the similarity is calculated based on two attribute values, in addition to corresponding to the third attribute value, the similarity to be judged also corresponds to another attribute value (i.e., the fourth attribute value). Therefore, the above-mentioned storing the third attribute value into the corresponding attribute pool can be to determine the other attribute value (i.e., the fourth attribute value) corresponding to the similarity to be judged, and then store the third attribute value and the fourth attribute value into the corresponding attribute pool together, so as to avoid performing the similarity threshold judgment on the similarity calculated from the fourth attribute value and the third attribute value again when performing the similarity threshold judgment for each similarity corresponding to the fourth attribute value, thereby reducing the number of similarity threshold judgments and improving the efficiency of storing into the attribute pool.

[0157] Optionally, the above-mentioned storing the third attribute value into the corresponding attribute pool can also be to only store the third attribute value into the corresponding attribute pool, and then when judging each similarity corresponding to the fourth attribute value, store the fourth attribute value into the corresponding attribute pool to reduce the search time for the other attribute value corresponding to the similarity to be judged.

[0158] S305. Standardize the attribute values in each attribute pool respectively to obtain the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device.

[0159] After storing the attribute values into the corresponding attribute pool in step S305, in each attribute pool, standardize the attribute values in the attribute pool, so as to ensure that when the application party interacts with cryptographic devices from different manufacturers through the interface, the understanding and use of the interface parameters of the interface of the cryptographic device are consistent, which helps to reduce misunderstandings and errors and improve the stability and reliability of the system.

[0160] The standardized attribute value is the standard attribute value of the interface corresponding to the attribute value in the attribute pool. Therefore, the standard interface of the cryptographic device is the interface with the attribute value being the standard attribute value. That is to say, the attribute value corresponding to the standard interface of the cryptographic device is the standard attribute value. And the manufacturer interface of the cryptographic device is the interface with the attribute value being the original attribute value (i.e., the non-standardized attribute value).

[0161] Furthermore, standardize the attribute values corresponding to the interfaces whose interface functions belong to the same type of interface functions, so that the attribute values of the interfaces of the same interface function type from different manufacturers are converted into uniformly standard attribute values, enabling the application party to use the cryptographic resources of the cryptographic devices of all manufacturers, thereby eliminating the application party's dependence on the cryptographic devices and obtaining the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device.

[0162] Through the above steps S301, S302, S303, S304, and S305, the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device is obtained, so that the manufacturer interface of the cryptographic device can be standardized and output, so as to incorporate cryptographic devices of different manufacturers into the cryptographic service system according to the same standard, eliminating the dependence of the application side (i.e., the cryptographic service application side) on the cryptographic device.

[0163] In addition, since the encryption and decryption of the cryptographic device can only be operated using the fixed index of the fixed cryptographic device, when dynamically expanding the cryptographic resources, the fixity of the allocated cryptographic resources must be ensured. Therefore, the embodiment of the present application can adopt the ring consistent sampling method to reallocate the cryptographic resources to ensure the fixity of the cryptographic resources. The specific process of the ring consistent sampling method is as follows:

[0164] First, construct a consistent ring.

[0165] Specifically, form a ring with the head and tail connected from all hash value spaces to obtain a closed continuous space, thus constructing a consistent ring. Therefore, this consistent ring is a closed continuous space constructed based on hash values. The interval of this consistent ring can be from 0 to 2 32-1 , or a larger interval.

[0166] All the above hash value spaces are the set of all possible binary strings in theory.

[0167] In the embodiment of the present application, each participating node (i.e., each physical node, and this physical node can be the index position of the VSM) has a corresponding position on the above consistent ring. Thus, through the position on the consistent ring, the corresponding index resource, that is, the corresponding cryptographic resource, can be determined.

[0168] The corresponding position of each participating node on the consistent ring can be obtained by calculating the ID of the node through a hash function, or by calculating the Internet Protocol (abbreviated as IP) address of the node through a hash function. That is, each participating node will be hashed to a certain position on this consistent ring.

[0169] Next, after constructing the consistent ring, create virtual nodes on this consistent ring.

[0170] To better disperse the load, each actual physical node can be mapped to multiple positions on the consistent ring, and these positions can be called virtual nodes. That is to say, a physical node can correspond to multiple virtual nodes on the consistent ring. That is, the number of virtual nodes can be more than the number of actual physical nodes, so that data can be more evenly distributed on different virtual nodes.

[0171] Further, through a hash function, the application ID is converted into a hash value, thereby obtaining the hash value corresponding to the application ID. Then, based on this hash value, a corresponding position is determined on the consistent ring, that is, the corresponding virtual node.

[0172] Then, the index resource corresponding to the virtual node closest to this virtual node (such as the virtual node closest to this virtual node in the clockwise direction) is used as the password resource for this application ID, thereby realizing the selection of the password resource, so that when the password resource is expanded or contracted, data migration can be better carried out.

[0173] In the embodiment of the present application, the fifth correspondence between the application ID and the index can also be maintained. This fifth correspondence is the correspondence between the ID of the application, the ID of the password machine, the ID of the VSM, and the index position, so as to accurately determine the password resource used by this application according to the application ID.

[0174] In addition, in the embodiment of the present application, when a new virtual node is added to the consistent ring, the newly added virtual node only takes over the keys located between it and the previous virtual node on the consistent ring. Therefore, adding a new virtual node to the consistent ring only affects the migration of a small part of the data.

[0175] When a virtual node is removed from the consistent ring, the keys responsible for by the removed virtual node will be reallocated to the next virtual node, thus only affecting the part of the data responsible for by the removed virtual node and not affecting other data on the consistent ring.

[0176] In addition, in the embodiment of the present application, in order to make the password device resources more reasonable, the password resources of the password device can also be expanded or contracted to avoid affecting the service in the case of insufficient password resources and wasting resources caused by excessive password resources.

[0177] For example, it is determined whether to expand or contract according to whether the resource utilization rate has increased within a certain time range. If the resource utilization rate has not increased within a certain time range, contraction can be considered. If it has increased, expansion can be considered, thereby realizing the dynamic expansion and contraction of the password resources and avoiding the adverse effects on the service caused by insufficient password resources and the resource waste caused by excessive password resources.

[0178] Specifically, first calculate the trend value of the resource utilization rate within a preset time period, so as to determine whether the change trend of the resource utilization rate is increasing, decreasing, or remaining unchanged through this trend value.

[0179] If it is determined that the trend value is greater than the trend threshold, it is determined that the change trend of the resource utilization rate is upward, and the pressure on the password service system to process data increases. At this time, the password resources can be expanded to appropriately increase the password resources, so as to avoid the adverse impact on the service in the case of insufficient password resources.

[0180] If it is determined that the trend value is less than the trend threshold, it is determined that the change trend of the resource utilization rate is downward, and the password service system has excessive data processing capacity. At this time, the password resources can be scaled down to remove some password resources, so as to avoid waste of password resources.

[0181] If it is determined that the trend value is equal to the trend threshold, it is determined that the change trend of the resource utilization rate remains unchanged, and the password service system has a certain data processing capacity during this period. At this time, the password resources can be kept unchanged.

[0182] In the embodiment of the present application, the above-mentioned trend threshold may be 0.

[0183] Optionally, the specific calculation process of the trend value of the above-mentioned resource utilization rate within a preset time period may be as follows:

[0184] First, divide the preset time period into multiple sub-time periods. Each sub-time period includes a start time and an end time, and the end time of the current sub-time period is the start time of the next sub-time period.

[0185] Then, calculate the resource utilization rate increment within each sub-time period.

[0186] The resource utilization rate increment is the ratio of the difference between the resource utilization rate at the end time corresponding to the corresponding sub-time period and the resource utilization rate at the start time corresponding to the sub-time period, to the difference between the end time corresponding to the sub-time period and the start time corresponding to the sub-time period, as shown in the following formula:

[0187]

[0188] Among them, Δr k represents the resource utilization rate increment within the k-th sub-time period; p k represents the resource utilization rate when the segment domain is marked as k, such as the resource utilization rate at the start time corresponding to the k-th sub-time period; p k+1 represents the resource utilization rate when the segment domain is marked as k + 1, such as the resource utilization rate at the end time corresponding to the k-th sub-time period, that is, the resource utilization rate at the start time corresponding to the k + 1-th sub-time period; t k represents the time when the segment domain is marked as k, such as the start time corresponding to the k-th sub-time period; t k+1 represents the time when the segment domain is marked as k + 1, such as the end time corresponding to the k-th sub-time period.

[0189] Next, calculate the difference between the increments of resource utilization in each group of adjacent sub - time periods, and then multiply the calculated multiple differences. That is, perform a cumulative multiplication on the differences between the increments of resource utilization in each group of adjacent sub - time periods. The obtained product is the trend value of the resource utilization within the preset time period, making the calculated trend value more accurate and better representing the change trend of the resource utilization within the preset time period.

[0190] The difference between the increments of resource utilization in the above - mentioned group of adjacent sub - time periods is the difference between the increment of resource utilization in the next sub - time period and the increment of resource utilization in the current sub - time period.

[0191] The above - mentioned cumulative multiplication of the differences between the increments of resource utilization in each group of adjacent sub - time periods can be shown as the following formula:

[0192]

[0193] Among them, s represents the trend value of the resource utilization within the preset time period, Δr k represents the increment of resource utilization in the current sub - time period; Δr k+1 represents the increment of resource utilization in the next sub - time period; the calculation method of Δr k+1 is the same as that of Δr k ; L represents the total number of sub - time periods, that is, the preset time period is divided into L sub - time periods.

[0194] Optionally, the specific process of expanding the password resources can be as follows:

[0195] First, determine whether there is a password device of the manufacturer corresponding to the password device to be added in the password resource pool. That is, determine whether it is the first time to import a password device of the manufacturer corresponding to the password device to be added into the password resource pool.

[0196] If it is determined that there is no password device of the manufacturer corresponding to the password device to be added in the resource pool, that is, it is the first time to import a password device of the manufacturer corresponding to the password device to be added into the password resource pool, then first standardize the interface of the password device to be added to obtain the mapping relationship between the standard interface of the password device to be added and the manufacturer interface of the password device to be added, so that when using the password resources of the password device to be added, the interface of the password device to be added can be standardized for output to eliminate the dependence of the application party on password devices of different manufacturers. Then, add the password device to be added to the password resource pool, thus realizing the dynamic expansion of the password resources.

[0197] The specific process of standardizing the interfaces of the password device to be added to obtain the mapping relationship between the standard interfaces of the password device to be added and the manufacturer interfaces of the password device to be added is the same as the aforementioned steps S301 - S305, and is consistent with the specific process of obtaining the mapping relationship between the standard interfaces of the password device and the manufacturer interfaces of the password device, which will not be elaborated here.

[0198] If it is determined that there is no password device of the manufacturer corresponding to the password device to be added in the resource pool, that is, when the password device of the manufacturer corresponding to the password device to be added is imported into the password resource pool for the first time, the password device to be added is directly added to the password resource pool to achieve the dynamic expansion of password resources.

[0199] Then, after adding the password device to be added to the password resource pool, the resource information of the password device to be added can be added to the password resource table to facilitate the maintenance of the resource information of the password device to be added and to obtain the resource information of the password device to be added in a timely and accurate manner when needed.

[0200] Optionally, the specific process of reducing the capacity of the password resources can be as follows:

[0201] First, determine the VSM to be migrated with the lowest resource utilization rate from all VSMs. The determination process of the VSM to be migrated can be determined according to the maintained third correspondence relationship. The third correspondence relationship includes the resource utilization rate of the VSM.

[0202] Next, determine all the index resources in the VSM to be migrated, that is, all the index positions in the VSM to be migrated. Then, perform hash calculations on each index position in the VSM to be migrated through a hash function to obtain the corresponding hash values. Then, according to the hash values corresponding to all the index positions in the VSM to be migrated, determine the virtual nodes corresponding to all the index positions in the VSM to be migrated on the consistent ring, thereby determining the target virtual nodes.

[0203] Furthermore, perform seamless migration on the data corresponding to the target virtual nodes. That is, decrypt the data corresponding to the target virtual nodes, and then encrypt the data corresponding to the target virtual nodes using the password resources corresponding to the adjacent virtual nodes (such as the next virtual node of the target virtual node) of the target virtual node, thereby realizing the seamless migration of the data corresponding to the target virtual nodes and avoiding the impact of the reduction of password resources on the encryption and decryption of the data corresponding to the password resources to be removed.

[0204] After the migration is completed, remove the password resources corresponding to the target virtual nodes, and remove the target virtual nodes from the consistent ring, thereby realizing the reduction of password resources and avoiding the resource waste caused by excessive password resources.

[0205] In addition, the password service method proposed in this application is also a multi-vendor password device compatibility method that is bottom-up and seamlessly adapts the lower layer to the upper layer. It performs multi-vendor adaptation at the password device adaptation layer, improving the compatibility of the password service platform and expanding the ecosystem of the password service system.

[0206] The technical solution of this application will be further described below in combination with a specific application process.

[0207] As Figure 4 shown in the schematic diagram of the processing process of the password service method, which is applied to a password service system. The password service system includes a device difference shielding module, a password device resource allocation module, and a dynamic resource expansion module. Among them, the password device resource allocation module is interdependent with the device difference shielding module and the dynamic resource expansion module.

[0208] In the device difference shielding module, when the password service system imports a password device of a new manufacturer, first obtain the interface document of the password device of the new manufacturer. Then, through a text parser, parse the content in all the obtained interface documents respectively, extract the interface functions and interface parameters included in each interface document, and maintain the fourth corresponding relationship among the interfaces, interface functions, and interface parameters. Next, according to the interface function of each interface, determine the similar interfaces whose interface functions belong to the same type of interface functions from all the interfaces, that is, classify all the interfaces, and divide the interfaces belonging to the same type of interface functions into one category, namely, obtain the similar interfaces. And calculate the similarity for the attribute values corresponding to the interface parameters of the similar interfaces respectively, and obtain the similarity corresponding to each attribute value. Then poll all the interfaces, and perform a similarity threshold judgment on each similarity corresponding to each attribute value in each interface. When the similarity is between the first similarity threshold and the second similarity threshold, it is determined that the similarity between the two attribute values corresponding to the similarity is high, and store the attribute value in the attribute pool corresponding to the similar interface to which the attribute value belongs. When the similarity is not within the range of the first similarity threshold and the second similarity threshold, it is determined that the similarity between the two attribute values corresponding to the similarity is low, and check whether the two attribute values are similar. If the check passes, it is determined that the two attribute values are similar, and the two attribute values are marked with attributes and then stored in the corresponding attribute pool. Finally, standardize the attribute values in each attribute pool respectively to obtain the mapping relationship between the standard interface of the password device and the manufacturer interface of the password device, and maintain this mapping relationship.

[0209] In the maintenance unit of the cryptographic device resource allocation module, maintain the first correspondence relationship of the cryptographic resources of cryptographic devices from different manufacturers, that is, maintain the correspondence relationship among the ID of the cipher machine, the ID of the VSM, and the index capacity; maintain the second correspondence relationship of the used cryptographic resources of the cryptographic device, that is, maintain the correspondence relationship among the ID of the cipher machine, the ID of the VSM, and the index position; maintain the third correspondence relationship of the remaining cryptographic resources of the cryptographic device, that is, maintain the correspondence relationship among the ID of the cipher machine, the ID of the VSM, and the resource utilization rate of the VSM, so as to integrate the cryptographic resources of cryptographic devices from different manufacturers and obtain the resource utilization rate of the cryptographic device, that is, the resource utilization rate of the VSM.

[0210] In the cryptographic device resource allocation module, then select the target index resource according to the resource utilization rate of each cryptographic device for dynamic resource decision-making. Then, select the target cryptographic device according to the target index resource. Then, according to the mapping relationship between the standard interface of the cryptographic device maintained in the device difference shielding module and the manufacturer interface of the cryptographic device, convert the standard interface of the target cryptographic device and the manufacturer interface of the target cryptographic device. Then, use the converted interface to call the cryptographic service.

[0211] In the dynamic resource expansion module, calculate the trend value of the resource utilization rate within a preset time period. If it is determined that the trend value is greater than the trend threshold, it is determined that the change trend of the resource utilization rate is rising, and the cryptographic resources are expanded, that is, cryptographic devices are added. If it is determined that the trend value is less than the trend threshold, it is determined that the change trend is falling, and the cryptographic resources are scaled down, that is, cryptographic devices are removed from cryptographic device 1, cryptographic device 2,..., cryptographic device I. If it is determined that the trend value is equal to the trend threshold, it is determined that the change trend is unchanged, and the cryptographic resources remain unchanged.

[0212] Based on the same inventive concept, an embodiment of the present application also provides a cryptographic service system, as Figure 5 shown in the structural schematic diagram of a cryptographic service system provided by the present application. The system includes:

[0213] An integration module 501, configured to integrate the cryptographic resources of cryptographic devices from different manufacturers and determine the resource utilization rate corresponding to each virtual cipher machine VSM in each of the cryptographic devices; wherein, the cryptographic resources include the index resources of the VSM.

[0214] A selection module 502, configured to select a target index resource according to the resource utilization rate corresponding to each VSM.

[0215] A processing module 503, configured to call a cryptographic service according to the target index resource.

[0216] In a possible implementation, the cryptographic device includes a plurality of cryptographic machines, each of the cryptographic machines includes a plurality of the VSMs, and each of the VSMs includes a plurality of index positions. The integration module 501 is specifically configured to maintain a first correspondence relationship of the cryptographic resources of the cryptographic devices from different manufacturers and a second correspondence relationship of the used cryptographic resources of the cryptographic device; wherein, the first correspondence relationship is the correspondence relationship among the identification code ID of the cryptographic machine, the ID of the VSM, and the index capacity, and the second correspondence relationship is the correspondence relationship among the ID of the cryptographic machine, the ID of the VSM, and the used index positions.

[0217] According to the first correspondence relationship and the second correspondence relationship, determine a third correspondence relationship of the remaining cryptographic resources of the cryptographic device, and maintain the third correspondence relationship; wherein, the third correspondence relationship is the correspondence relationship among the ID of the cryptographic machine, the ID of the VSM, and the resource utilization rate of the VSM.

[0218] According to the third correspondence relationship, determine the resource utilization rate corresponding to each VSM in each cryptographic device.

[0219] In a possible implementation, the integration module 501 is specifically configured to determine the index capacity of the VSM in the cryptographic resources according to the first correspondence relationship; and

[0220] Determine the index used amount of the VSM according to the second correspondence relationship;

[0221] For each VSM, calculate the ratio between the corresponding index used amount and the index capacity, and use the ratio as the resource utilization rate of the corresponding VSM;

[0222] Determine the third correspondence relationship of the remaining cryptographic resources of the cryptographic device according to the resource utilization rate of the VSM.

[0223] In a possible implementation, the processing module 503 is specifically configured to invoke a cryptographic service according to the target index resource, including:

[0224] Select a target cryptographic device according to the target index resource;

[0225] Convert the standard interface of the target cryptographic device and the manufacturer interface of the target cryptographic device according to the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device;

[0226] Invoke the cryptographic service by using the converted interface.

[0227] In a possible implementation, the system further includes a difference masking module, which is configured to obtain the interface documents corresponding to the cryptographic devices of different manufacturers before converting the standard interface of the target cryptographic device and the manufacturer interface of the target cryptographic device according to the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device;

[0228] Parse the content in each of the interface documents respectively to obtain the interface functions and interface parameters included in each of the interface documents;

[0229] According to the interface functions, determine the same-type interfaces belonging to the same-type interface functions from multiple interfaces, and calculate the similarity of the attribute values of the interface parameters for each group of the same-type interfaces respectively;

[0230] Store the attribute values corresponding to the similarity within the range from the first similarity threshold to the second similarity threshold into the corresponding attribute pool; wherein, the first similarity threshold is less than the second similarity threshold; one attribute pool corresponds to one group of the same-type interfaces;

[0231] Normalize the attribute values in each of the attribute pools respectively to obtain the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device.

[0232] In a possible implementation, the system further includes a dynamic resource expansion module, which is configured to calculate the trend value of the resource utilization rate within a preset time period;

[0233] If it is determined that the trend value is greater than the trend threshold, determine that the change trend of the resource utilization rate is increasing, and expand the cryptographic resources;

[0234] If it is determined that the trend value is less than the trend threshold, determine that the change trend is decreasing, and reduce the cryptographic resources;

[0235] If it is determined that the trend value is equal to the trend threshold, determine that the change trend is unchanged, and keep the cryptographic resources unchanged.

[0236] In a possible implementation, the dynamic resource expansion module is specifically configured to divide the preset time period into multiple sub-time periods; wherein, each sub-time period includes a start time and an end time, and the end time of the current sub-time period is the start time of the next sub-time period;

[0237] Calculate the increment of resource utilization rate within each sub - time period; wherein, the increment of resource utilization rate is the ratio of the difference between the resource utilization rate at the end time corresponding to the sub - time period and the resource utilization rate at the start time corresponding to the sub - time period to the difference between the corresponding end time and the corresponding start time.

[0238] Multiply the differences of the increments of resource utilization rate within each group of adjacent sub - time periods, and use the obtained product as the trend value of the resource utilization rate within the preset time period; wherein, the difference of the increments of resource utilization rate within the adjacent sub - time periods is the difference between the increment of resource utilization rate in the next sub - time period and the increment of resource utilization rate in the current sub - time period.

[0239] In a possible implementation manner, the dynamic resource expansion module is specifically configured to determine whether there is a password device of the manufacturer corresponding to the password device to be added in the password resource pool.

[0240] If not, standardize the manufacturer interface corresponding to the password device to be added to obtain the mapping relationship between the standard interface corresponding to the password device to be added and the manufacturer interface corresponding to the password device to be added, and add the password device to be added to the password resource pool.

[0241] If so, add the password device to be added to the password resource pool.

[0242] Add the password resource information of the password device to be added to the password resource table.

[0243] In a possible implementation manner, the dynamic resource expansion module is specifically configured to determine the VSM to be migrated with the lowest resource utilization rate from all VSMs, and determine the target virtual node corresponding to the VSM to be migrated on the consistent ring according to the hash values corresponding to all index positions in the VSM to be migrated; wherein, the consistent ring is a closed continuous space constructed based on hash values.

[0244] Perform non - intrusive migration on the data corresponding to the target virtual node.

[0245] After the data migration is completed, remove the password resources corresponding to the VSM to be migrated, and remove the target virtual node from the consistent ring.

[0246] In a possible implementation manner, the non - intrusive migration is specifically as follows:

[0247] Decrypt the data corresponding to the target virtual node, and encrypt the data corresponding to the target virtual node using the password resources corresponding to the adjacent virtual nodes of the target virtual node.

[0248] Based on the same inventive concept, an electronic device is further provided in an embodiment of the present application. The above electronic device can implement the functions of the foregoing password service system. Refer to Figure 6 , the above electronic device includes:

[0249] At least one processor 601 and a memory 602 connected to the at least one processor 601. In the embodiment of the present application, the specific connection medium between the processor 601 and the memory 602 is not limited. Figure 6 Taking the connection between the processor 601 and the memory 602 through the bus 600 as an example. The bus 600 is represented by a thick line in Figure 6 . The connection manners between other components are only for illustrative purposes and are not limiting. The bus 600 can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 6 only one thick line is used to represent it in, but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 601 can also be called a controller, and there is no limitation on the name.

[0250] In the embodiment of the present application, the memory 602 stores instructions executable by the at least one processor 601. By executing the instructions stored in the memory 602, the at least one processor 601 can execute the password service method described above. The processor 601 can implement Figure 5 the functions of each module in the system shown.

[0251] Among them, the processor 601 is the control center of the system. It can connect various parts of the entire control device through various interfaces and lines. By running or executing the instructions stored in the memory 602 and calling the data stored in the memory 602, various functions of the system and process data, so as to monitor the system as a whole.

[0252] In a possible design, the processor 601 may include one or more processing units. The processor 601 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above modem processor may not be integrated into the processor 601. In some embodiments, the processor 601 and the memory 602 can be implemented on the same chip. In some embodiments, they can also be separately implemented on independent chips.

[0253] The processor 601 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application specific integrated circuit, a field programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the password service method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0254] The memory 602, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 602 may include at least one type of storage medium, for example, it may include flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disc, and so on. The memory 602 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 602 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.

[0255] By designing and programming the processor 601, the code corresponding to the password service method introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 1 the steps of the password service method of the embodiments shown. How to design and program the processor 601 is a well-known technology to those skilled in the art and will not be elaborated here.

[0256] Based on the same inventive concept, the embodiments of the present application also provide a storage medium, which stores computer instructions, and when the computer instructions run on a computer, the computer is caused to execute the password service method discussed above.

[0257] In some possible embodiments, aspects of the password service method provided in this application can also be implemented in the form of a program product, which includes program code. When the program product runs on a device, the program code is used to cause the control device to execute the steps in the password service method according to various exemplary embodiments of this application described above in this specification.

[0258] Those skilled in the art should understand that the embodiments of this application can be provided as a method, a system, or a computer program product. Therefore, this application can take the form of an all-hardware embodiment, an all-software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0259] This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of this application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0260] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0261] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0262] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to cover these modifications and variations.

Claims

1. A cryptographic service method, characterized in that: include Integrate the cryptographic resources of cryptographic devices from different manufacturers to determine the resource utilization rate of the virtual cryptographic machine VSM in each of the cryptographic devices; wherein the cryptographic resources include the index resources of the VSM; Selecting a target index resource according to the resource utilization rate corresponding to each of the VSMs; A cryptographic service is called according to the target index resource.

2. The method according to claim 1, characterized in that The cryptographic device includes a plurality of cryptographic machines, the cryptographic machines include a plurality of the VSMs, the VSMs include a plurality of index positions, and the cryptographic resources of cryptographic devices from different manufacturers are integrated to determine the resource utilization rate corresponding to each virtual cryptographic machine VSM in each of the cryptographic devices, including: Maintaining a first correspondence between the cryptographic resources of the cryptographic devices of different manufacturers and a second correspondence between the used cryptographic resources of the cryptographic devices; wherein the first correspondence is a correspondence between the identification code ID of the cryptographic machine, the ID of the VSM, and the index capacity, and the second correspondence is a correspondence between the ID of the cryptographic machine, the ID of the VSM, and the used index position; According to the first corresponding relationship and the second corresponding relationship, determine a third corresponding relationship of the remaining cryptographic resources of the cryptographic device, and maintain the third corresponding relationship; wherein the third corresponding relationship is a corresponding relationship between the ID of the cryptographic machine, the ID of the VSM, and the resource utilization rate of the VSM; According to the third corresponding relationship, the resource utilization rate corresponding to each of the VSMs in the cryptographic devices is determined.

3. The method according to claim 2, characterized in that The determining, according to the first corresponding relationship and the second corresponding relationship, a third corresponding relationship of the remaining cryptographic resources of the cryptographic device includes: Determining the index capacity of the VSM in the cryptographic resource according to the first corresponding relationship; and Determine the used amount of the index of the VSM according to the second corresponding relationship; For each of the VSMs, a ratio between the corresponding index usage and the index capacity is calculated, and the ratio is used as the resource utilization of the corresponding VSM; The third corresponding relationship of the remaining cryptographic resources of the cryptographic device is determined according to the resource utilization of the VSM.

4. The method according to claim 1, characterized in that The calling of the cryptographic service according to the target index resource includes: Selecting a target cryptographic device according to the target index resource; Converting the standard interface of the target cryptographic device to the manufacturer's interface of the target cryptographic device according to a mapping relationship between the standard interface of the cryptographic device and the manufacturer's interface of the cryptographic device; Use the converted interface to call the password service.

5. The method according to claim 4, characterized in that Before converting the standard interface of the target cryptographic device with the manufacturer interface of the target cryptographic device according to the mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device, the method further includes: Obtaining the interface documents corresponding to the cryptographic devices of different manufacturers; Parsing the contents of each interface document respectively to obtain the interface functions and interface parameters included in each interface document; According to the interface function, determine similar interfaces belonging to the same interface function from multiple interfaces, and perform similarity calculation for the attribute values ​​of the interface parameters of each group of the similar interfaces respectively; The attribute values ​​corresponding to the similarities within the range from the first similarity threshold to the second similarity threshold are stored in the corresponding attribute pool; wherein the first similarity threshold is less than the second similarity threshold; and one attribute pool corresponds to a group of the same type of interfaces; The attribute values ​​in each of the attribute pools are standardized respectively to obtain a mapping relationship between the standard interface of the cryptographic device and the manufacturer interface of the cryptographic device.

6. The method according to claim 1, characterized in that The method further comprises: Calculate the trend value of resource utilization within a preset time period; If it is determined that the trend value is greater than the trend threshold, it is determined that the change trend of the resource utilization is increasing, and the cryptographic resources are expanded; If it is determined that the trend value is less than the trend threshold, the change trend is determined to be a downward trend, and the cryptographic resources are scaled down; If it is determined that the trend value is equal to the trend threshold, the change trend is determined to be unchanged, and the cryptographic resource is kept unchanged.

7. The method according to claim 6, characterized in that The trend value of the computing resource utilization rate within a preset time period includes: Divide the preset time period into a plurality of sub-time periods; wherein each sub-time period includes a start time and an end time, and the end time of the current sub-time period is the start time of the next sub-time period; Calculate the resource utilization increment in each sub-time period; wherein the resource utilization increment is the ratio of the difference between the resource utilization at the end time corresponding to the sub-time period and the resource utilization at the corresponding start time to the difference between the corresponding end time and the corresponding start time; The difference in the resource utilization value increases in each group of adjacent sub-time periods is multiplied cumulatively, and the obtained product is used as the trend value of the resource utilization in the preset time period; wherein the difference in the resource utilization value increases in adjacent sub-time periods is the difference between the resource utilization value increases in the next sub-time period and the resource utilization value increases in the current sub-time period.

8. The method according to claim 6, characterized in that The expanding the cryptographic resources of the cryptographic device includes: Determine whether there is a password device of the manufacturer corresponding to the password device to be added in the password resource pool; If not, standardize the manufacturer interface corresponding to the to-be-added cryptographic device, obtain a mapping relationship between the standard interface corresponding to the to-be-added cryptographic device and the manufacturer interface corresponding to the to-be-added cryptographic device, and add the to-be-added cryptographic device to the cryptographic resource pool; If yes, adding the to-be-added cryptographic device to the cryptographic resource pool; The password resource information of the password device to be added is added to the password resource table.

9. The method according to claim 6, characterized in that The step of shrinking the cryptographic resources of the cryptographic device includes: Determine the VSM to be migrated with the lowest resource utilization from all VSMs, and determine the target virtual node corresponding to the VSM to be migrated on the consistency ring according to the hash values ​​corresponding to all index positions in the VSM to be migrated; wherein the consistency ring is a closed continuous space constructed based on the hash value; Performing seamless migration of data corresponding to the target virtual node; When the data migration is completed, the cryptographic resources corresponding to the VSM to be migrated are removed, and the target virtual node is removed from the consistency ring.

10. The method according to claim 9, characterized in that The non-sensing migration is specifically: The data corresponding to the target virtual node is decrypted, and the cryptographic resources corresponding to the adjacent virtual nodes of the target virtual node are used to encrypt the data corresponding to the target virtual node.

11. A cryptographic service system, characterized in that: include: An integration module, used to integrate the cryptographic resources of cryptographic devices of different manufacturers, and determine the resource utilization rate corresponding to each virtual cryptographic machine VSM in each of the cryptographic devices; wherein the cryptographic resources include index resources of the VSM; A selection module, configured to select a target index resource according to a resource utilization rate corresponding to each of the VSMs; The processing module is used to call the cryptographic service according to the target index resource.

12. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to implement the method steps of any one of claims 1 to 10 when executing the computer program stored in the memory.

13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 1 to 10 are implemented.