Method and system suitable for cloud tenant key security management and use
Through the two-layer key structure and secure channel design, the key leakage and illegal call problems in the cloud tenant key management are solved, and the tenant's full life cycle management of the key and high-performance password computing are realized to meet the needs of endogenous use.
Patent Information
- Application Number
- CN202510451318.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-04
AI Technical Summary
In the key management of tenants on the cloud, tenants cannot fully grasp their own keys, and there is a risk of key leakage and illegal call. Moreover, the traditional password usage is limited by network performance and bandwidth, and cannot meet high-performance and endogenous usage scenarios.
Using a two-layer key structure, the tenant key is stored in the tenant key management module. The independent virtual password module is virtualized through the physical password module, and a secure channel is established with the key management agent and the cloud key management system to realize the full life cycle management and secure call of the key by tenants.
Tenants can fully control their own key management and use, prevent illegal calls, realize high-performance password operations and endogenous key management, reduce the risk of key leakage, and improve security and performance.
Smart Images

Figure CN120263492A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security, and in particular relates to a method and system for secure key management and secure password use applicable to cloud tenants. Background Art
[0002] At present, due to the characteristics of cloud computing such as intensive construction, resource sharing, large-scale services, low cost, and high availability, it has become the main computing mode in the digital economy era. Moving business to the cloud has gradually become a trend. Private clouds, operator cloud platforms, Alibaba, Huawei, and Tencent Cloud provide services for enterprises and institutions. When data is moved to the cloud, there will naturally be "endogenous security risks", including data leakage and tampering during data collection, storage, processing, and transmission. Mainly, cloud key technology is used to solve these problems. At present, the keys used by cloud users generally have the situation of key escrow, that is, the keys are generated in the key management system (KMS) on the cloud, and tenants can only call them. Tenants cannot effectively control the management and use of their own keys. Theoretically, there may be situations where malicious internal managers, operations and maintenance personnel, and external malicious attackers illegally call the keys. For the Electronic Signature Law, there may be legal consequences caused by illegal calls.
[0003] Traditional cloud key management adopts forms such as server cryptographic machines and cloud server cryptographic machines, and saves tenant keys in the form of key escrow. As Figure 1 shown, the keys of traditional cloud cryptographic devices are generally divided into three levels: Management key: used to protect the security of other keys and sensitive information, including the management, backup, and recovery of other keys and the authentication of administrators. Generally, means such as key dispersion (threshold) are used for protection.
[0004] Device key: is the identity key of the cloud server cryptographic machine, including signature key pairs and encryption key pairs, used for device management and representing the identity of the cloud server cryptographic machine.
[0005] Key encryption key: is a symmetric key that is replaced regularly. In the case of pre-distributing or importing / exporting keys, the virtual cryptographic machine uses the key encryption key to protect the session key.
[0006] User (tenant) key: includes signature key pairs and encryption key pairs, used to implement user signature, verification, authentication, and the protection and negotiation of session keys, etc., representing the identity of the tenant or application.
[0007] Session key: used for data encryption and decryption.
[0008] There are mainly three problems with traditional cloud key management: The first problem is that the tenant cannot truly hold their own keys in their hands (because they are on the cloud-based cryptographic machine). When the tenant manages keys, they do not have their own complete, traceable, and legally effective identity information to participate in the full life cycle management of the keys. The tenant only knows that they can call their own keys, but they do not know whether their keys are leaked or illegally called by others.
[0009] In the traditional key hierarchy, the tenant's keys are generated by cryptographic devices, and their key management is operated on the cloud platform, generally managed by accounts. Anyone who can log in to the account can manage the keys, which actually cannot be corresponding to the tenant themselves. The tenant themselves cannot truly manage the keys. Any back-end personnel and others who can log in to the tenant's account can operate. The password operations and uses are not truly permitted by the tenant.
[0010] Such as Figure 2 shown, the second problem is that whether it is the server cryptographic machine or the cloud server cryptographic machine, their calls are made through the network. Between the calling party and the server, or on the cloud, data security cannot be fully protected. For example, the data is tampered with. For example, when tenant "Zhang San" transfers funds and signs the data, the data is "Zhang San transfers 100 yuan to Li Si", but since the tenant's signed data is transmitted through the network interface for signing, malicious personnel can easily change the data to "Li Si transfers 100 yuan to Zhang San" through means such as tampering and eavesdropping, and tenant "Zhang San" still signs it, forming a legal evidence, causing losses to "Zhang San".
[0011] The third problem is that the traditional way of using passwords is through network interfaces for calls. Affected by network performance and bandwidth, the performance of password use is limited and cannot meet the needs of high-performance, endogenous, and virtualized password use scenarios. At the same time, the data transmitted over the network during use occupies a large amount of internal network bandwidth, blocking the transmission of other network data. Summary of the Invention
[0012] In view of the above technical problems, the present invention provides a completely new design for the management and use of tenant keys on the cloud, and provides a method and system for tenants to securely manage and use their own keys on the cloud. At the same time, this method supports the endogenous tenant key use mode, thereby realizing the security of endogenous tenant key management and use on the cloud.
[0013] To achieve the above object, the technical solution adopted by the present invention is: A system suitable for secure management and use of tenant keys on the cloud, including a tenant key management module, a cloud key management system, and a cloud server.
[0014] The tenant's identity key is stored in the tenant key management module for the protection and authentication of tenant applications on the cloud.
[0015] The password module on the cloud server includes: several independent virtual password modules virtualized from the physical password module; the cloud server includes a host and virtual machines, and the virtual machines are allocated computing resources and virtual password modules for tenants by the cloud management platform.
[0016] The physical password module on the cloud server supports password operations and key management and supports virtualization. The physical password module can be a password card that supports virtualization or a password module in the CPU.
[0017] The physical password module virtualizes several independent virtual password modules, and each virtual password module has independent and isolated key management and password operation functions.
[0018] The key management agent runs on the virtual machine. The key management agent authenticates with the cloud key management system and establishes a secure channel for the tenant to uniformly manage their own keys throughout the entire life cycle.
[0019] The tenant issues the encrypted tenant trusted instruction to the key management agent through the established secure channel. The key management agent sends the tenant trusted instruction to the virtual password module, and the virtual password module verifies the tenant trusted instruction. If the verification passes, it executes the tenant trusted instruction and completes the secure management of the tenant key.
[0020] This set of operation security framework design can not only be combined with the keys in the tenant's hands, securely manage the tenant's own keys and determine whether password operations can be performed, but also enable the applications deployed in the virtual machine to directly and natively call password resources, avoiding the possibility of being tampered with by the network.
[0021] The method for securely managing and using the keys of cloud tenants according to the present invention adopts a unique two-layer key structure suitable for cloud tenants to master their own keys.
[0022] The key structure of the password module includes: the key structure of the password module itself and the key structure of the tenant.
[0023] The key structure of the password module itself includes two layers, one layer is the management key and the other layer is the device key.
[0024] The management key: used for encrypting and storing the device key (protecting the security of the device key and sensitive information, including encrypting and protecting other keys and management information), and each virtual password module has its own management key.
[0025] Device Key: The identity key representing the virtual password module, including a signature key pair and an encryption key pair, used for device management. The device key of each virtual password module is encrypted and stored by its respective management key. Moreover, the device key serves as the communication key of the virtual password module to communicate securely with the cloud key management system.
[0026] The key structure of the tenant includes the tenant identity public key, the protection key of the tenant application key, and the tenant application key.
[0027] Tenant Identity Public Key: In the tenant initialization phase, the tenant's identity certificate is set in the virtual password module to identify the tenant's identity.
[0028] Tenant Application Key: Includes the asymmetric key pair and the symmetric key pair of the tenant application. The asymmetric key pair includes the signature key pair and the encryption key pair, used for user signature, verification, identity authentication, and protection and negotiation of session keys, etc., representing the identity of the tenant and the application. The symmetric key pair includes the tenant's session key, etc. Each virtual module cannot access the keys of other tenants.
[0029] Protection Key of Tenant Application Key: Used to protect the tenant application key, including two components. One component is stored in the password module, and the other component is generated in the tenant's own tenant key management module.
[0030] Furthermore, it also includes the backup key of the tenant application key: Each backup key is generated by a new random number, encrypted and protected by the tenant identity public key to form a digital envelope, and sent to the cloud key management platform and the tenant; the tenant's application key is encrypted and protected by the backup key of the tenant application key.
[0031] Furthermore, in the password module initialization phase, the initialization of the physical password module PF and the virtual password module VF will be completed; Use the administrator tool to initialize the physical password module PF: The physical password module can generate the management key through physical unclonable function PUF or OPT technology; Configure the administrator identity information of the physical password module, Generate the signature key pair of the physical password module, import the encryption key pair, and encrypt and store the device key using the management key of the physical password module.
[0032] Furthermore, generate a certificate signing request through the device key of the physical password module, register in the cloud key management system, allocate the physical password module identity ID, and issue the physical password module identity certificate; Import the physical password module identity certificate, the physical password module identity ID, and the cloud platform management system certificate into the physical password module and store them securely.
[0033] Further, initialize each virtual password module VF: Each virtual password module derives its own management key from the key generated by physical unclonable technology or OPT encryption technology and the identity ID corresponding to the virtual password module; Configure the administrator identity information of the virtual password module; Generate the device signature key pair of the virtual password module, import the encryption key pair, and encrypt and store the device key of the virtual password module using the management key of the virtual password module.
[0034] Further, generate a certificate signing request through the device key of the virtual password module, register in the cloud key management system, assign the identity ID of the virtual password module, and issue the identity certificate of the virtual password module; Import the virtual password module identity certificate, virtual password module identity ID, cloud platform management system certificate, and cloud key management system certificate into the virtual password module and store them securely.
[0035] Further, the tenant's identity key includes the tenant identity public key and the tenant identity private key; In the tenant initialization stage, the tenant identity public key and the tenant identity private key are generated and securely stored in the tenant key management module. The tenant identity public key is sent to the virtual password module through the secure channel established by authenticating the device key in the virtual password module with the cloud key management system. The virtual password module stores the tenant identity public key and performs integrity measurement.
[0036] The tenant identity public key is generated and stored in the tenant key management module, and is set to the virtual password module during the tenant initialization of the virtual machine through the cloud key management platform.
[0037] Further, the tenant identity public key is used to verify whether the tenant's operation instruction comes from the identity key held by the tenant himself, and is used to encrypt the backup key of the tenant application key. The tenant identity public key is encrypted and saved by the management key.
[0038] Further, the signature key pair of the tenant application key is generated by the security chip in the virtual password module, and the encryption key pair of the tenant application key is generated by the cloud key management system and independently distributed to each virtual password module through the key protection structure.
[0039] Furthermore, the protection key of the tenant application key: It is generated by the exclusive OR of two components during the tenant initialization phase. One component is generated by a random number and stored in the virtual password module, and the other component is generated in the tenant key management module. When the virtual password module is started, it is encrypted through the secure channel established by the device key of the virtual password module and the cloud key management system and transmitted into the virtual password module. In the virtual password module, the two components are exclusive ORed to generate the protection key of the tenant application key, and the tenant application key is decrypted by the protection key of the tenant application key. The virtual password module decrypts the other component and combines it with the original component to form the protection key of the tenant application key.
[0040] Furthermore, the backup key of the tenant application key: Each backup key of the tenant application key is generated by a new random number and protected by encryption with the tenant's identity public key.
[0041] Furthermore, the methods for managing and using tenant keys on the cloud include: S1, The device key is not open to tenants.
[0042] S2, Except for the tenant's identity public key, all keys do not appear in plaintext outside the virtual password module, the running space of the virtual password module, and the secure storage area.
[0043] S3, The virtual password module only executes the tenant instruction and completes the management of the tenant key after receiving the tenant instruction signed by the tenant's identity key stored in the tenant key management module and verifying the signature through the tenant's identity public key in the virtual password module.
[0044] S4, The virtual password module cannot export and use the keys of other virtual password modules, and tenants can only back up and use the keys of their own virtual machines.
[0045] Furthermore, the methods for backing up tenant keys on the cloud include: The virtual password module uses the backup key of the tenant application key for backup, and each backup operation randomly generates a new backup key of the tenant application key; the tenant's application key is protected by encryption with the backup key of the tenant application key, and the backup key of the tenant application key is protected by encryption with the tenant's identity public key to form a digital envelope and sent to the cloud key management platform and the tenant.
[0046] Furthermore, the methods for restoring tenant keys on the cloud include: When the tenant application key stored in the virtual password module is restored to a new virtual password module, the new virtual password module will first initialize the tenant's identity certificate, generate a protection key for the new tenant application key, decrypt the digital envelope through the tenant identity private key of the tenant's tenant key management module to obtain the backup key of the tenant application key, protect the backup key of the tenant application key with the device key of the new virtual password module, and send it to the new virtual password module. Then, decrypt the backup key of the tenant application key in the new virtual password module, decrypt the tenant application key with the backup key of the tenant application key, and encrypt it with the protection key of the new tenant application key and save it in the new virtual password module.
[0047] The present invention also discloses a system suitable for secure management and use of tenant keys on the cloud, characterized in that it includes a tenant key management module, a cloud key management system, and a cloud server; and executes the method for secure management and use of tenant keys on the cloud according to any one of claims 1-15. The tenant's identity key is stored in the tenant key management module for the protection and authentication of tenant applications on the cloud. The cloud server includes virtual machines, and the virtual machines allocate resources and password cards for the tenant. The physical password module on the cloud server supports password operations and key management. The physical password module virtualizes several independent virtual password modules, and the virtual password modules have key management and password operation functions. The key management agent runs on the virtual machine, and the cloud key management system establishes a secure channel with the key management agent. The tenant issues an encrypted tenant instruction to the key management agent, the key management agent sends the tenant instruction to the virtual password module, and the virtual password module verifies the tenant instruction. If the verification passes, the tenant instruction is executed to complete the secure management of the tenant key.
[0048] The present invention has the following beneficial effects: Compared with the traditional key structure, the double-layer key structure designed in this paper enables the tenant to fully control the management and use of their own keys on the virtual module, preventing others on the cloud, including cloud operation and maintenance personnel and management personnel, from illegally managing or using the tenant keys. This key structure can effectively protect the tenant keys on the cloud and realize the secure invocation of tenant keys. Among them, the tenant's identity key is stored in the tenant key management module held by the tenant, the tenant's application key is generated in the virtual password module, and the password module does not expose the plaintext. The tenant's key management instructions are verified through the tenant's public key in the password module.
[0049] The technology of the present invention enables tenants on the cloud to use passwords in such a way that tenant applications can endogenously use password resources. Tenants can safely and correctly use password operations, provide password services similar to IAAS and PAAS, and at the same time, tenants truly own and manage the keys of the tenants on the cloud, rather than using keys in the form of key trusteeship, so that the tenant keys are in the hands of the tenants, greatly reducing the risk of tenant key leakage and illegal invocation. Specifically: For each password module on the cloud server (including the virtual password module VF and the physical password module PF), initialize the key structure of the virtual password module. After the key structure of the virtual password module is initialized, it needs to be registered with the cloud key management system.
[0050] For the tenant-related key structure, after the password module and the cloud key management system establish a secure channel through the cloud key management system and the key management agent, initialize two tenant certificates, one tenant's signature identity certificate and one tenant's encryption identity certificate into the virtual password module.
[0051] The management of tenant keys requires the private key of the tenant key management module held by the tenant to sign the key management instruction, and send it to the virtual password module through a secure channel. It can manage the tenant's keys only after being verified by the tenant's identity public key in the virtual password module. Brief Description of the Drawings
[0052] Figure 1 It is the traditional key hierarchical structure of cloud devices.
[0053] Figure 2 It is the schematic diagram of the data tampering risk of the traditional cloud device key.
[0054] Figure 3 It is the schematic diagram of the system applicable to the secure management and use of tenant keys on the cloud in the embodiment of the present invention.
[0055] Figure 4 It is the schematic diagram of the double-layer key structure of the method applicable to the secure management and use of tenant keys on the cloud in the embodiment of the present invention. Detailed Embodiment
[0056] For the convenience of those skilled in the art, the present invention will be further described below in conjunction with the embodiments and the drawings.
[0057] The system architecture applicable to the secure management and use of tenant keys on the cloud in this embodiment is as Figure 3 shown.
[0058] 1.1 System Architecture: Tenant: A certain user leases a password cloud server for password services. The password cloud allocates resources and password cards to the tenant by means of virtualization technology.
[0059] Identity key of the tenant: A certificate issued by a third-party CA and stored in the tenant key management module held by the tenant, which is used as the key for protecting and authenticating tenant applications on the cloud. The tenant key management module can be a smart password key or other password modules that can ensure security (such as a collaborative key management module).
[0060] Physical password module: A hardware password module on a cloud device that supports password operations and key management and supports virtualization. For example, a password card that supports virtualization or a password module in the CPU.
[0061] Virtual password module: A virtual password module virtualized from a physical password module, which has key management and password operation functions that are completely independent and isolated from other modules.
[0062] Cloud key management system: It is an agent platform for tenants to manage their own keys. A secure channel is established between the key proxy and the cloud key management system. Tenants uniformly manage their own keys to achieve the full life cycle management of tenant keys.
[0063] Agent: It is an agent program running on a virtual machine. The key management agent and the cloud key management system establish a trusted channel through a security protocol. The tenant issues encrypted tenant trusted instructions to the key management agent, and the key management agent sends the tenant trusted instructions to the password module. The password module verifies and executes the tenant's instructions, and executes the tenant's instructions and completes the secure management of the tenant key after verification.
[0064] Security protocol message format: Adopt the security protocol for password device management in GM / T 0050, and add extended management application identifiers and custom PDU formats to transmit key management information.
[0065] (1) The type represents the message type. 0x01 represents the JSON format message content, 0x02 represents the SignedData type in P7 / Q7 (signature type) for the JSON message content in the "GM / T 0010 SM2 Cryptographic Algorithm Encryption and Signature Message Syntax Specification", and 0x03 represents the SignedAndEnvelopedData type in the "GM / T 0010 SM2 Cryptographic Algorithm Encryption and Signature Message Syntax Specification" for the JSON message content with digital envelope (signature with encryption); (2) The message length represents the length of the subsequent message; (3) The message and the transmitted message content can be JSON format message content, or P7 / Q7 (signature type) for JSON, or a digital envelope for JSON.
[0066] This operation security framework design can not only be combined with the keys in the hands of tenants, securely manage the tenants' own keys, and determine whether cryptographic operations can be performed, but also enable applications deployed in virtual machines to directly and natively call cryptographic resources, avoiding the possibility of being tampered with over the network.
[0067] 1.2 Dual-key hierarchical structure to ensure the management of tenants' keys and operation authorization The method for securely managing and using tenants' keys applicable to the cloud in the present invention adopts a unique two-layer key structure suitable for tenants in the cloud to master their own keys.
[0068] For the cryptographic module, two key structures are implemented. One is the key structure of the cryptographic module itself, and the other is the key structure of the tenant.
[0069] The key structure of the cryptographic module itself includes two layers. One layer is the management key, and the other layer is the device key.
[0070] Management key: Used to protect the security of the device key and sensitive information, including the encryption protection of other keys and management information; each virtual cryptographic module has its own key.
[0071] Device key: Represents the identity key of the virtual cryptographic module, including a signature key pair and an encryption key pair, used for device management. The device key of each virtual module is encrypted and stored by its own management key. And the device key is used as the communication key of the virtual module to communicate securely with the cloud key management system.
[0072] The key structure of the tenant includes three layers. One layer is the tenant identity public key, one layer is the protection key of the tenant application key, and one layer is the tenant application key.
[0073] Tenant identity public key: In the tenant initialization stage, the tenant's identity certificate is set into the virtual module to identify the tenant's identity.
[0074] One is to verify whether the tenant's operation instruction is from the identity key held by the tenant himself; The other is the backup key used to encrypt the tenant application key. The tenant identity public key is encrypted and saved by the management key.
[0075] Tenant application key: Includes the asymmetric key pair and symmetric key pair of the tenant application. The asymmetric key pair includes a signature key pair and an encryption key pair, used to implement user signature, verification, identity authentication, and the protection and negotiation of session keys, etc., representing the identity of the tenant and the application. The symmetric key pair includes the tenant's session key, etc. Each virtual module cannot access the keys of other tenants.
[0076] Protection key for tenant application key: Used to protect the tenant application key, including two components. One component is stored in the cryptographic module, and the other component is generated in the tenant's own tenant key management module during initialization.
[0077] Backup key for tenant application key: Each backup key is generated by a new random number and protected by encryption with the tenant identity public key.
[0078] 1.2.1 Key generation and installation Management key: Generated by the PUF (Physical Unclonable Function) physical unclonable technology when powering on or generated through OPT. Each virtual cryptographic module derives its own management key from the key generated by PUF or OPT. Each virtual cryptographic module generates its own management key.
[0079] Device key: In the initialization phase, operated by the administrator tool. The device signature key pair is generated by the security chip in the cryptographic module, and the device identity encryption key is generated by the key management system and independently distributed to each cryptographic module. The encryption key distribution format follows the requirements of GB / T 36322 for the protection format of the encryption key pair and is securely stored encrypted by the management key.
[0080] Tenant identity public key: Generated and stored in the tenant's tenant key management module. Set by the tenant to the virtual module through the cloud key management platform during the tenant initialization of the virtual module.
[0081] Protection key for tenant application key: Generated by the exclusive OR of two components in the initialization phase. One component is generated by a random number and stored in the cryptographic module, and the other component is generated by the tenant and transmitted into the cryptographic module encrypted by the device key.
[0082] Backup key for tenant application key: Each backup key is generated by a new random number and protected by encryption with the tenant identity public key.
[0083] Tenant application key: Protected by the protection key of the tenant application key.
[0084] 1.2.2 Key usage: S1, The device key is not open to the tenant.
[0085] S2, Except for the public key, all keys do not appear in plain text outside the virtual module; all keys other than the virtual module public key cannot appear in plain text outside the virtual module running space and the secure storage area.
[0086] S3, In the virtual cryptographic module, only when receiving the digital envelope signature of the tenant identity private key of the tenant key management module held by the tenant and verifying the signature can operations be performed on the tenant key.
[0087] S4. The virtual module cannot export and use the keys of other virtual modules. The tenant can only back up and use the keys of its own virtual cipher machine.
[0088] 1.2.3 Backup / Recovery Backup: The virtual module uses the backup key of the tenant application key for backup. A new backup key of the tenant application key is randomly generated for each backup operation; the tenant's application key is encrypted and protected by the backup key of the tenant application key, and the backup key of the tenant application key is encrypted and protected by the tenant identity public key to form a digital envelope, which is sent to the cloud key management platform and the tenant.
[0089] Recovery: When the tenant application key is restored to another virtual module, the tenant's identity certificate will be initialized for the other virtual module first, and a new protection key for the tenant application key will be generated. The digital envelope is decrypted through the tenant identity private key in the tenant key management module of the tenant to obtain the backup key of the tenant application key. The backup key of the tenant application key is protected by the device key of the new virtual module and sent to the password module. Then, the backup key of the tenant application key is decrypted in the virtual module, the tenant application key is decrypted by the backup key of the tenant application key, and is encrypted and stored in the virtual module with the new protection key of the tenant application key.
[0090] Compared with the traditional key structure, this embodiment adopts a two-layer key structure, enabling the tenant to fully control the management and use of its own keys on the virtual module, preventing others on the cloud, including cloud operation and maintenance personnel and management personnel, from illegally managing or using the tenant's keys. This key structure can effectively protect the security of the tenant's keys on the cloud and realize the secure invocation of the tenant's keys. Among them, the tenant's identity key is stored in the tenant key management module held by the tenant, the tenant's application key is generated in the virtual cipher module and does not leave the cipher module in plaintext, and the tenant's key management instructions are verified through the tenant's public key in the cipher module.
[0091] Specifically, as Figure 4 shown: For the cipher module, there are two key structures, one is the key related to the virtual card device, and the other is the key structure related to the tenant.
[0092] For each cipher module (including the virtual cipher module VF and the physical cipher module PF), the keys related to the virtual card device, such as the management key and the device key, are initialized.
[0093] After the keys related to the virtual card device are initialized, they need to be registered in the cloud key management system.
[0094] For the tenant-related key structure, after the cloud key management system and the key management agent call the password module to establish a secure channel with the cloud key management system, two tenant certificates need to be initialized, namely a tenant's signature identity certificate and an encrypted identity certificate of the tenant, into the virtual module.
[0095] The management of tenant keys requires the tenant to use the tenant identity private key held by the tenant key management module to sign the key management instructions and send them to the virtual module through a secure channel. The keys of the tenant can be managed only after verification by the tenant's identity public key in the virtual module.
[0096] The process for the tenant to securely manage and use the system with the tenant keys on the cloud includes: 1.3 Initialization of the cloud key management system, cloud platform management system, and cloud identity authentication system 1.31 Each system initializes its own system's super administrators, administrators, auditors, etc.
[0097] 1.32 Each system generates its own platform identity key, generates a certificate signing request, and issues a platform identity certificate through the CA.
[0098] 1.33 Configure the services, configurations, etc. of each system.
[0099] 1.34 Make a secure backup of the platform keys of each system.
[0100] 1.4 Initialization of the password module 1.41 During the initialization stage of the password module, the initialization of the physical password module PF and the virtual password module VF will be completed, and the initialization stage is carried out in an environment that ensures physical security.
[0101] 1.42 Use the administrator tool to initialize the physical password module PF: a. Generate a management key in the security chip of the password module through PUF (Physical Unclonable Function) or OPT technology.
[0102] b. Configure the administrator identity information of the physical password module PF.
[0103] c. Generate a device signature key pair and import the encryption key pair.
[0104] d. Generate a certificate signing request (CSR) through the device key, register in the cloud key management system, assign a physical password module PF identity ID, and issue a physical password module PF identity certificate.
[0105] e. Import the physical password module PF identity certificate, physical password module PF identity ID, and the cloud platform management system certificate into the PF password module and store them securely.
[0106] 1. Initialize each virtual password module VF: a. Generate the management key of the virtual password module in the secure chip of the virtual password module VF (derived through PUF or OPT key); b. Configure the administrator identity information of the virtual password module VF.
[0107] c. Generate the device signature key pair of the virtual password module and import the device encryption key pair.
[0108] d. Generate a certificate signing request (CSR) through the device key, and by registering in the cloud key management system, assign the identity ID of the virtual password module VF and issue the identity certificate of the virtual password module VF.
[0109] Import the identity certificate of the virtual password module VF, the identity ID of the virtual password module VF, and the cloud key management system certificate into the VF card and store them securely.
[0110] 2. Working stage: 2.1 Cloud key management system: After the tenant creates virtual resources in the cloud platform management system, the key proxy in the virtual resources calls the initialized virtual password module (VF) bound to the virtual machine to establish a connection with the cloud key management system, and uses the cloud key management system platform identity certificate, the device certificate of the virtual password module (VF), and the ID in the existing virtual password module (VF) to establish a secure channel with the cloud key management system.
[0111] After the tenant logs in to the cloud key management system, the tenant will see the virtual resources created by the tenant in the cloud platform management system and the corresponding virtual password modules.
[0112] The cloud key management system security protocol uses the security protocol of "GM / T 0050 Technical Specification for Password Device Management" to establish a secure channel, encrypts and transmits using the security protocol message format (hereinafter referred to as SPDU) in "GM / T 0050 Technical Specification for Password Device Management", and the extended messages of this technical report can be found in "Protocol between Key Agent and Cloud Key Management System".
[0113] 2.1.1 Initialization of tenant identity in the cloud key management system: After the virtual machine is started for the first time, the key management agent will inform the tenant of the status of the virtual module. If the tenant certificate is not set, the tenant identity needs to be initialized and the tenant identity certificate is imported into the virtual module, including the tenant's signature certificate and encryption certificate.
[0114] The tenant's identity certificate is stored in the tenant's tenant key management module.
[0115] 2.1.2 Tenant Key Loading in the Virtual Password Module: After the virtual machine is shut down or restarted, the tenant needs to log in again, encrypt the tenant key resources in the virtual password module, and the virtual password module decrypts and restores the tenant's application key.
[0116] 2.1.3 Tenant Identity Public Key Update: When the tenant identity certificate (public key) needs to be changed, the tenant certificate is updated by signing the new tenant identity certificate with the private key corresponding to the old tenant identity certificate.
[0117] 2.1.4 Tenant Application Key Generation / Deletion: The tenant sends a generation / deletion instruction, signs the instruction with the private key corresponding to the tenant's identity certificate, and sends it to the key management agent through the security protocol. The key management agent sends the instruction to the virtual password module, and the virtual password module verifies and executes the instruction internally.
[0118] 2.1.5 Tenant Application Key Backup: For the backup of the tenant application key, a new random number is generated in the virtual module for each backup as the tenant backup key to protect the tenant's application key. The tenant's backup key is encrypted and protected by the public key of the tenant identity certificate and then output.
[0119] 2.1.6 Tenant Application Key Recovery: When the virtual password module is restored to another virtual password module, it will first initialize the tenant's identity certificate for the other virtual password module, generate a new protection key for the tenant application key, decrypt the digital envelope with the private key of the tenant key management module of the tenant to obtain the backup key of the tenant application key, protect the backup key of the tenant application key with the device key of the new virtual module, and send it to the password module. Then, the backup key of the tenant application key is decrypted in the virtual password module, the tenant application key is decrypted with the backup key of the tenant application key, and it is encrypted and stored in the virtual module with the new protection key of the tenant application key.
[0120] The above embodiments are only used to illustrate the technical idea of the present invention, and the protection scope of the present invention cannot be limited thereby. Any changes made on the basis of the technical solution according to the technical idea proposed by the present invention shall fall within the protection scope of the present invention.
Claims
1. A method suitable for the secure management and use of tenant keys on the cloud, characterized in that: A system applicable to the secure management and use of tenant keys on the cloud includes a tenant key management module, a cloud key management system, and a cloud server; The identity key of the tenant is stored in the tenant key management module and is used for the protection and authentication of tenant applications on the cloud; The password module on the cloud server includes: several independent virtual password modules virtualized from the physical password module; The key structure of the password module includes: the key structure of the password module itself and the key structure of the tenant; The key structure of the password module itself includes a management key and a device key; Management key: used to encrypt and store the device key, and each virtual password module has its own management key; Device key: represents the identity key of the virtual password module, including a signature key pair and an encryption key pair; the device key is used as the communication key of the virtual password module to communicate securely with the cloud key management system; The key structure of the tenant includes the tenant identity public key, the protection key of the tenant application key, and the tenant application key; Tenant identity public key: the tenant's identity certificate is set in the virtual password module to identify the tenant's identity; Tenant application key: includes the asymmetric key pair and symmetric key pair of the tenant application. The asymmetric key pair includes a signature key pair and an encryption key pair, representing the identity of the tenant and the application; the symmetric key pair includes the tenant's session key; Protection key of the tenant application key: used to protect the tenant application key, including two components, one component is stored in the virtual password module, and the other component is generated in the tenant key management module.
2. The method applicable to the secure management and use of tenant keys on the cloud according to claim 1, characterized in that: In the initialization stage of the password module, the initialization of the physical password module PF and the virtual password module VF will be completed; Use the administrator tool to initialize the physical password module PF: The physical password module generates a management key through physical unclonable function PUF or OPT technology; Configure the administrator identity information of the physical password module, Generate the signature key pair of the physical password module, import the encryption key pair, and use the management key of the physical password module to encrypt and store the device key.
3. The method applicable to the secure management and use of tenant keys on the cloud according to claim 2, characterized in that: Generate a certificate signing request through the device key of the physical password module, register in the cloud key management system, assign the physical password module identity ID, and issue the physical password module identity certificate; Import the physical password module identity certificate, the physical password module identity ID, and the cloud platform management system certificate into the physical password module and store them securely.
4. The method applicable to the secure management and use of tenant keys on the cloud according to claim 2, characterized in that: Initialize each virtual password module VF: Each virtual password module derives its own management key from the key generated by physical unclonable technology or OPT encryption technology and the identity ID corresponding to the virtual password module; Configure the administrator identity information of the virtual password module; Generate the device signature key pair of the virtual password module, import the encryption key pair, and use the management key of the virtual password module to encrypt and store the device key of the virtual password module.
5. The method for secure management and use of tenant keys on the cloud according to claim 4, characterized in that: Generate a certificate signing request through the device key of the virtual password module, register in the cloud key management system, assign the identity ID of the virtual password module, and issue the identity certificate of the virtual password module; Import the virtual password module identity certificate, the virtual password module identity ID, the cloud platform management system certificate, and the certificate of the cloud key management system into the virtual password module and store them securely.
6. The method for secure management and use of tenant keys on the cloud according to claim 1, characterized in that: The identity key of the tenant includes the tenant identity public key and the tenant identity private key; In the tenant initialization stage, the tenant identity public key and the tenant identity private key are generated and stored in the tenant key management module. The tenant identity public key is sent to the virtual password module through the secure channel established by the device key in the virtual password module and the identity authentication of the cloud key management system. The virtual password module stores the tenant identity public key and performs integrity measurement.
7. The method for secure management and use of tenant keys on the cloud according to claim 6, characterized in that: The tenant identity public key is used to verify whether the tenant's operation instruction comes from the identity key held by the tenant himself; The tenant identity public key is used to encrypt the backup key of the tenant application key, and the tenant identity public key is encrypted and saved by the management key.
8. The method for secure management and use of tenant keys on the cloud according to claim 1, characterized in that: The signature key pair of the tenant is generated by the virtual password module, and the encryption key pair of the tenant is generated by the cloud key management system and independently distributed to each virtual password module.
9. The method for secure management and use of tenant keys on the cloud according to claim 1, characterized in that: The protection key of the tenant application key: In the tenant initialization stage, it is generated by the exclusive OR of two components. One component is generated by a random number and stored in the virtual password module; the other component is generated in the tenant key management module, encrypted by the device key of the virtual password module and transmitted into the virtual password module. In the virtual password module, the two components are exclusive ORed to generate the protection key of the tenant application key, and the tenant application key is decrypted by the protection key of the tenant application key.
10. The method for secure management and use of tenant keys on the cloud according to claim 1, characterized in that: It further includes the backup key of the tenant application key: Each backup key is generated by a new random number, encrypted and protected by the tenant identity public key to form a digital envelope, and sent to the cloud key management platform and the tenant; the tenant's application key is encrypted and protected by the backup key of the tenant application key.
11. The method for secure management and use of tenant keys on the cloud according to claim 1, characterized in that: The device key is not open to the tenant; Except for the tenant identity public key, all keys do not appear in plain text outside the virtual password module, the virtual password module's operating space, and the secure storage area; The virtual password module only executes the tenant instruction and completes the management of the tenant key when it receives the tenant instruction signed by the tenant's identity key stored in the tenant key management module and verifies the signature through the tenant identity public key in the virtual password module.
12. The method for securely managing and using tenant keys on the cloud according to claim 11, characterized in that: The tenant manages the tenant application key in the virtual password module on the cloud through the cloud key management platform; The tenant application key management operation instruction is signed using the tenant's identity private key stored in the tenant key management module, and key generation, deletion, update, backup, and recovery are performed after the signature verification of the tenant instruction in the virtual password module passes.
13. The method for securely managing and using tenant keys on the cloud according to claim 11, characterized in that: The tenant identity certificate update instruction signs the new tenant identity certificate using the private key corresponding to the old tenant identity certificate to form a digital envelope, which is sent to the virtual password module through the secure channel established between the device of the virtual password module and the cloud key management system. After the virtual password module verifies the signature of the old tenant identity certificate, it updates to the new tenant identity certificate.
14. The method for secure management and use of tenant keys on the cloud according to any one of claims 1-13, characterized in that, The key backup method includes: The virtual password module uses the backup key of the tenant application key for backup, and a new backup key of the tenant application key is randomly generated for each backup operation; the tenant's application key is encrypted and protected by the backup key of the tenant application key, and the backup key of the tenant application key is encrypted and protected by the tenant identity public key to form a digital envelope, which is encrypted and sent to the cloud key management platform and the tenant.
15. The method for securely managing and using tenant keys on the cloud according to claim 14, wherein The key recovery method includes: When the tenant application key in the virtual password module is restored to a new virtual password module, the new virtual password module will first initialize the tenant's identity certificate and generate a new protection key for the tenant application key. The digital envelope is decrypted using the tenant identity private key of the tenant's tenant key management module to obtain the backup key of the tenant application key. The backup key of the tenant application key is protected by the device key of the new virtual password module and sent to the new virtual password module. Then, the backup key of the tenant application key is decrypted in the new virtual password module, the tenant application key is decrypted using the backup key of the tenant application key, and it is encrypted and saved in the new virtual password module using the new protection key of the tenant application key.
16. A system suitable for the secure management and use of tenant keys on the cloud, characterized in that: Including a tenant key management module, a cloud key management system, and a cloud server; executing the method for securely managing and using tenant keys on the cloud according to any one of claims 1-15; The tenant's identity key is stored in the tenant key management module and is used for the protection and authentication of tenant applications on the cloud; The cloud server includes a host and a virtual machine, and the virtual machine allocates resources and a password card for the tenant; The physical password module on the cloud server supports password operations and key management; The physical password module virtualizes a number of independent virtual password modules, and the virtual password module has key management and password operation functions; The key management agent runs on a virtual machine, and the cloud key management system establishes a secure channel with the key management agent; The tenant issues the encrypted tenant instructions to the key management agent. The key management agent sends the tenant instructions to the virtual password module. The virtual password module verifies the tenant instructions. If the verification is passed, the tenant instructions are executed to complete the secure management of the tenant key.
Citation Information
Cited By
Enabling using external tenant master keys
US20250192991A1