Cloud VPN (Virtual Private Network) key security protection method, device, equipment and medium

By adopting a layered key protection system and permission control key isolation solution in the cloud VPN security gateway, the problems of key interception and theft between virtual VPNs are solved, the secure storage and use of keys are realized, and the security and reliability of cloud VPNs are improved.

CN120263498APending Publication Date: 2025-07-04CHENGDU WEISHITONG INFORMATION SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510475797.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing key protection system cannot meet the scenario where multiple virtual VPNs are running on the same host in the cloud VPN security gateway, resulting in the possibility of intermittent use and stealing of keys between each virtual VPN, resulting in the unavailability of virtual VPNs and service interruption of other tenants.

Method used

Using a layered key protection system and a key isolation scheme based on permission control, the device key is encrypted through the management key in the cryptographic component, and the encrypted device key is saved to the isolation area of ​​the target virtual VPN, allowing only the corresponding virtual VPN to access, ensuring the security of each layer of key in storage and use.

Benefits of technology

Key isolation between virtual VPNs, cloud VPN administrators and virtual VPNs is realized, key snooping and theft is avoided, key storage security is improved, and hardware costs are reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263498A_ABST
    Figure CN120263498A_ABST
Patent Text Reader

Abstract

The invention discloses a cloud virtual private network (VPN) key security protection method and device, equipment and a medium, and relates to the technical field of cloud virtual private networks, and the method comprises the steps: when a target virtual VPN receives a service request, decrypting an equipment key encrypted and stored in the target virtual VPN, and calling the decrypted equipment key into a target isolation region corresponding to the target virtual VPN in a password component; the target key negotiation process is protected based on the device key in the target isolation area through the target virtual VPN, and a target service key which is generated in the target key negotiation process and corresponds to the service request is acquired; wherein the target key negotiation process is a process in which the target virtual VPN carries out key negotiation with the corresponding to-be-interacted device for the service request; and storing the target service key in a target isolation region corresponding to the target virtual VPN, so that the target virtual VPN performs service processing related to the target virtual VPN based on the target service key in the target isolation region.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of cloud virtual private network, and particularly relates to a cloud VPN key security protection method, device, equipment and medium. Background Art

[0002] As a network security device on the cloud, the cloud VPN security gateway can create multiple VVPNs (i.e., Virtual VPNs; VPN stands for Virtual Private Network) for tenants to use. Since the virtual VPNs leased by different tenants run on the same host, it is necessary to securely isolate the keys in different virtual VPNs. At the same time, it is also necessary to prevent the administrator of the cloud VPN security gateway from obtaining the tenant's keys. The existing key protection system generally includes device keys, working keys, and session keys. The device keys are stored in the secure storage area of the cryptographic component to protect the generation of the working keys. The working keys protect the generation of the session keys. Both the working keys and the session keys are stored in the memory and disappear when the power is off.

[0003] The existing key protection system cannot meet the scenario where multiple virtual VPNs in the cloud VPN security gateway run on the same host. If the existing key protection system is directly used in the cloud VPN security gateway, there may be situations where keys are misused or stolen between virtual VPNs, or the device keys of other virtual VPNs are directly damaged, resulting in the unavailability of the virtual VPNs of other tenants and business interruptions. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a cloud VPN key security protection method, device, equipment and medium, which adopts a hierarchical key protection system and a key isolation scheme based on permission control to ensure the security of each layer of keys in terms of storage and use between virtual VPNs, between the cloud VPN administrator and the virtual VPNs. The specific scheme is as follows:

[0005] In the first aspect, this application provides a cloud VPN key security protection method, which is applied to a cloud security gateway. The cloud security gateway includes a cryptographic component and several virtual VPNs running on a host. Among them, the method includes:

[0006] When the target virtual VPN receives a service request, decrypt the device key encrypted and saved in the target virtual VPN and transfer it to the target isolation area corresponding to the target virtual VPN in the password component; wherein, the target virtual VPN is any one of the several virtual VPNs; use the management key in the password component to encrypt the device key and save the encrypted device key to the corresponding target virtual VPN; the target isolation area in the password component is an area with access permission only for the corresponding target virtual VPN.

[0007] Protect the target key negotiation process through the target virtual VPN based on the device key in the target isolation area, and obtain the target service key corresponding to the service request generated by the target key negotiation process; the target key negotiation process is the process of the target virtual VPN negotiating keys with the corresponding device to be interacted with for the service request.

[0008] Save the target service key to the target isolation area corresponding to the target virtual VPN, so that the target virtual VPN performs service processing related to the target virtual VPN based on the target service key in the target isolation area.

[0009] Optionally, the cloud VPN key security protection method further includes:

[0010] Store the management key in the target storage area of the password component; wherein, the target storage area is a non-volatile storage area.

[0011] Use the management key saved in the target storage area by the virtual VPN to encrypt its own device key, and store the encrypted device key in its own file system.

[0012] Correspondingly, when the target virtual VPN receives a service request, decrypt the device key encrypted and saved in the target virtual VPN and transfer it to the target isolation area corresponding to the target virtual VPN in the password component, includes:

[0013] When the target virtual VPN receives a service request, decrypt the device key encrypted and saved in the file system corresponding to the target virtual VPN and transfer it to the target isolation area corresponding to the target virtual VPN in the password component, so as to protect the target key negotiation process using the device key in the target isolation area; wherein, the target isolation area is a volatile storage area.

[0014] Optionally, the cloud VPN key security protection method further includes:

[0015] Assign management permissions to the host through the password component and assign corresponding tenant access permissions to each virtual VPN;

[0016] Send a quarantine area application request to the password component through the target virtual VPN, so that after the password component responds to the quarantine area application request, create the corresponding target quarantine area for the target virtual VPN locally;

[0017] Execute key management operations on the management key in the target storage area by the host based on the management permissions, and prohibit the host from accessing the target quarantine areas assigned by the password component to each virtual VPN; the key management operations include modification, addition, and deletion operations on the management key;

[0018] Access the management key in the target storage area by the target virtual VPN based on the tenant access permissions and access, modify, and delete the device key and target service key in the target quarantine area.

[0019] Optionally, after the password component responds to the quarantine area application request, creating the corresponding target quarantine area for the target virtual VPN locally includes:

[0020] After the password component responds to the quarantine area application request, allocate a target quarantine area for the target virtual VPN in the local volatile storage area and return the quarantine area identifier of the target quarantine area to the target virtual VPN;

[0021] And, decrypting the device key encrypted and saved in the target virtual VPN and transferring it into the target quarantine area corresponding to the target virtual VPN in the password component includes:

[0022] Decrypt the device key encrypted and saved in the target virtual VPN and transfer it into the target quarantine area, and obtain the first identifier corresponding to the device key returned by the password component through the target virtual VPN; the first identifier includes a key index;

[0023] Correspondingly, after obtaining the target service key corresponding to the service request generated by the target key negotiation process, further includes:

[0024] Obtain the second identifier corresponding to the target service key returned by the password component through the target virtual VPN; the second identifier includes a key handle.

[0025] Optionally, before protecting the target key negotiation process by the target virtual VPN based on the device key in the target quarantine area, further includes:

[0026] The target virtual VPN determines a corresponding target isolation area in the password component based on the isolation area identifier stored therein, and accesses the device key stored in the target isolation area based on the first identifier;

[0027] Correspondingly, the target virtual VPN performs service processing related to the target virtual VPN based on the target service key in the target isolation area, including:

[0028] The target virtual VPN determines a corresponding target isolation area in the password component based on the isolation area identifier stored therein, and accesses the target service key stored in the target isolation area based on the second identifier.

[0029] Optionally, the device key of the target virtual VPN includes a signature key and / or an encryption key; the target service key includes an IPSec key and / or an SSL key; wherein, the IPSec key includes an IPSec working key and an IPSec session key; the SSL key includes an SSL pre-master key, an SSL master key, and an SSL working key.

[0030] Optionally, the cloud VPN key security protection method further includes:

[0031] After the password component creates the signature key for the target virtual VPN, the signature private key is encrypted based on the management key corresponding to the target virtual VPN in the password component and saved to the file system of the target virtual VPN, and the signature public key is saved to the file system of the target virtual VPN in the form of an encrypted certificate in plain text; the signature key includes the signature private key and the signature public key;

[0032] After the certificate authority issues the encryption key for the target virtual VPN, the encryption private key is encrypted based on the management key corresponding to the target virtual VPN in the password component and saved to the file system of the target virtual VPN, and the encryption public key is saved to the file system of the target virtual VPN in the form of an encrypted certificate in plain text; the encryption key includes the encryption private key and the encryption public key.

[0033] In a second aspect, the present application provides a cloud VPN key security protection device, which is applied to a cloud security gateway. The cloud security gateway includes a password component and a plurality of virtual VPNs running on a host; wherein, the device includes:

[0034] The first key storage module is configured to decrypt the device key encrypted and saved in the target virtual VPN and transfer it to the target isolation area corresponding to the target virtual VPN in the password component when the target virtual VPN receives a service request; wherein, the target virtual VPN is any one of the several virtual VPNs; encrypt the device key using the management key in the password component and save the encrypted device key to the corresponding target virtual VPN; the target isolation area in the password component is an area to which only the corresponding target virtual VPN has access rights;

[0035] The key acquisition module is configured to protect the target key negotiation process based on the device key in the target isolation area through the target virtual VPN and acquire the target service key corresponding to the service request generated by the target key negotiation process; the target key negotiation process is a process in which the target virtual VPN negotiates keys with the corresponding device to be interacted with for the service request;

[0036] The second key storage module is configured to save the target service key to the target isolation area corresponding to the target virtual VPN, so that the target virtual VPN performs service processing related to the target virtual VPN based on the target service key in the target isolation area.

[0037] In a third aspect, the present application provides an electronic device, including:

[0038] A memory for saving a computer program;

[0039] A processor for executing the computer program to implement the foregoing cloud VPN key security protection method.

[0040] In a fourth aspect, the present application provides a computer-readable storage medium for saving a computer program, wherein the computer program, when executed by a processor, implements the foregoing cloud VPN key security protection method.

[0041] In this application, when the target virtual VPN receives a service request, the device key encrypted and saved in the target virtual VPN is decrypted and transferred to the target isolation area corresponding to the target virtual VPN in the password component; where the target virtual VPN is any one of the several virtual VPNs; the management key in the password component is used to encrypt the device key and the encrypted device key is saved to the corresponding target virtual VPN; the target isolation area in the password component is an area to which only the corresponding target virtual VPN has access rights; the target virtual VPN is used to protect the target key negotiation process based on the device key in the target isolation area and obtain the target service key corresponding to the service request generated by the target key negotiation process; the target key negotiation process is a process in which the target virtual VPN negotiates keys with the corresponding device to be interacted with for the service request; the target service key is saved to the target isolation area corresponding to the target virtual VPN, so that the target virtual VPN can perform service processing related to the target virtual VPN based on the target service key in the target isolation area. As can be seen from the above, this application uses the management key in the password component to encrypt the device key of the target virtual VPN and saves the encrypted device key to the corresponding target virtual VPN to protect the device key through the management key; by setting a target isolation area to which only the corresponding target virtual VPN has access rights, and when using the corresponding key, transferring the target service key and the decrypted device key to the target isolation area for use, it ensures the isolation between the keys corresponding to different virtual VPNs, avoids the situation that keys may be misused or stolen between virtual VPNs and the host illegally accessing the keys corresponding to the virtual VPN, and improves the security of key storage. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0043] Figure 1 It is a schematic diagram of a specific hierarchical key protection system disclosed in the present application;

[0044] Figure 2 It is a flowchart of a cloud VPN key security protection method disclosed in the present application;

[0045] Figure 3 It is a schematic diagram of a key isolation method based on permission control disclosed in the present application;

[0046] Figure 4 Structural schematic diagram of a cloud VPN key security protection device disclosed in this application;

[0047] Figure 5 Structural schematic diagram of an electronic device disclosed in this application. Detailed implementation manners

[0048] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0049] The existing key protection system cannot meet the scenario where multiple virtual VPNs in the cloud VPN security gateway run on the same host. If the existing key protection system is directly used, in the cloud VPN security gateway, there may be situations where keys are misused or stolen between virtual VPNs, or the device keys of other virtual VPNs are directly damaged, resulting in the unavailability of virtual VPNs of other tenants and service interruptions. For this reason, the present application provides a cloud VPN key security protection method, which adopts a hierarchical key protection system and a key isolation scheme based on permission control to ensure the security of each layer of keys in storage and use between virtual VPNs, between the cloud VPN administrator and virtual VPNs.

[0050] Refer to Figure 1 As shown, the embodiments of the present application disclose a hierarchical key protection system.

[0051] In the hierarchical key protection system, the cloud VPN management key is at the top layer; the device key is at the second layer, and after being encrypted by the management key, it is saved to the file system of the virtual VPN (i.e., VVPN, Virtual Virtual Private Network); below the device key are the IPSec key (Internet Protocol Security Key) and the SSL key (Secure Sockets Layer Key). The IPSec key includes the IPSec working key and the IPSec session key, and the SSL key includes the SSL pre-master key, the SSL master key, and the SSL working key. Among them, the generation of the IPSec key follows key negotiation, the generation of the SSL key follows the SSL protocol, and the IPSec key and the SSL key are protected by the device key.

[0052] As can be seen from the above, the key hierarchical protection system in this embodiment adds a management key on the basis of the traditional hierarchical structure, uses the management key to protect the device key, and uses the device key to protect the IPSec key and the SSL key. In this way, the keys are divided into different levels, and each level has clear functions and responsibilities, making the key management clearer and more organized.

[0053] Refer to Figure 2 As shown, an embodiment of the present application discloses a cloud VPN key security protection method, which is applied to a cloud security gateway. The cloud security gateway includes a cryptographic component and a number of virtual VPNs running on a host; wherein, the method includes:

[0054] Step S11, when a target virtual VPN receives a service request, decrypt the device key encrypted and stored in the target virtual VPN and transfer it to the target isolation area corresponding to the target virtual VPN in the cryptographic component; wherein, the target virtual VPN is any one of the number of virtual VPNs; use the management key in the cryptographic component to encrypt the device key and save the encrypted device key to the corresponding target virtual VPN; the target isolation area in the cryptographic component is an area to which only the corresponding target virtual VPN has access rights.

[0055] In this embodiment, the cryptographic component is divided into a non-volatile storage area and a volatile storage area. The non-volatile storage area is used to save the management key, such as LMK (LOCAL MAIN KEY, local main key); the volatile storage area is divided into multiple target isolation areas, and the target isolation areas are used to save the device key and service keys, such as IPSec working key, IPSec session key, and SSL working key, etc. By granting different permissions to the host and virtual VPNs respectively through the cryptographic component, the host is assigned management permissions and each virtual VPN is assigned tenant access permissions, so as to control the permissions of the host and virtual VPNs to use the cryptographic component. Among them, the host performs key management operations on the management key in the non-volatile storage area based on the management permissions, and the virtual VPN performs key usage operations on the management key in the non-volatile storage area based on the tenant access permissions, but cannot manage it. Moreover, the virtual VPN can also perform access, modification, and deletion on the device key and service key in the target isolation area based on the tenant access permissions. However, the virtual VPN can only access its corresponding target isolation area through the isolation area identifier to use the key in the target isolation area for key operations, and at the same time, the host is prohibited from accessing the target isolation areas assigned to each virtual VPN by the cryptographic component; wherein, the key management operations include modification, addition, and deletion operations on the management key.

[0056] Before the target virtual VPN receives a service request, it first stores the management key in the target storage area of the password component; then, the virtual VPN encrypts its device key using the management key stored in the target storage area and stores the encrypted device key in its own file system. Among them, the target storage area is a non-volatile storage area. Using the non-volatile storage area to store the management key, even if the device is powered off, the management key will not be lost, which can continuously ensure security; the device key of the target virtual VPN can be a signature key and / or an encryption key.

[0057] Specifically, after the password component creates a signature key for the target virtual VPN, it encrypts the signature private key based on the management key corresponding to the target virtual VPN in the password component and saves it to the file system of the target virtual VPN, and saves the signature public key in plain text in the form of an encrypted certificate to the file system of the target virtual VPN; among them, the signature key includes a signature private key and a signature public key. After the certificate authority issues an encryption key for the target virtual VPN, it encrypts the encryption private key based on the management key corresponding to the target virtual VPN in the password component and saves it to the file system of the target virtual VPN, and saves the encryption public key in plain text in the form of an encrypted certificate to the file system of the target virtual VPN; among them, the encryption key includes an encryption private key and an encryption public key. For example, after the password component generates a signature key pair for the virtual VPN, the virtual VPN calls the key-related interface to encrypt the signature private key using the management key and saves the signature private key to its own file system, and at the same time stores the signature public key in plain text in the form of an encrypted certificate in its own file system and performs integrity protection using a password hashing algorithm; after the certificate authority issues an encryption key pair for the virtual VPN, it encrypts the encryption private key with the management key and saves it to the file system of the virtual VPN, and stores the encryption public key in plain text in the form of an encrypted certificate in the file system of the virtual VPN, and can also perform integrity protection using a password hashing algorithm.

[0058] When the target virtual VPN receives a service request, it can first send a quarantine area application request to the password component through the target virtual VPN, so that after the password component responds to the quarantine area application request, it creates a corresponding target quarantine area for the target virtual VPN locally. Specifically, after the password component responds to the quarantine area application request, it allocates a target quarantine area for the target virtual VPN in the local volatile storage area and returns the quarantine area identifier of the target quarantine area to the target virtual VPN.

[0059] Then, based on the isolation area identifier, decrypt the device key encrypted and saved in the file system corresponding to the target virtual VPN, and load it into the password component into the target isolation area corresponding to the target virtual VPN, so as to use the device key in the target isolation area to protect the target key negotiation process, and obtain the first identifier corresponding to the device key returned by the password component through the target virtual VPN; wherein, the target isolation area is a volatile storage area; the first identifier includes a key index.

[0060] Step S12, protect the target key negotiation process based on the device key in the target isolation area through the target virtual VPN, and obtain the target service key corresponding to the service request generated by the target key negotiation process; the target key negotiation process is a process in which the target virtual VPN negotiates a key with the corresponding device to be interacted with for the service request.

[0061] In this embodiment, before protecting the target key negotiation process based on the device key in the target isolation area through the target virtual VPN, it may further include: determining the corresponding target isolation area in the password component based on the isolation area identifier saved by the target virtual VPN, and accessing the device key saved in the target isolation area based on the first identifier.

[0062] It should be noted that when the target virtual VPN receives a service request, it needs to negotiate a key with the corresponding device to be interacted with. Key negotiation is a process in which both parties (or multiple parties) jointly generate a shared key through specific algorithms and protocols, and the shared key will be used for subsequent service communication to ensure the confidentiality and integrity of the communication content. Therefore, it is necessary for the target virtual VPN to use the device key in the target isolation area to protect the target key negotiation process. Specifically, the device key can participate in operations such as encryption and authentication to prevent the key negotiation process from being maliciously attacked, such as man-in-the-middle attacks and eavesdropping, to ensure that the negotiated target service key is secure and reliable. Among them, the target service key may include an IPSec key and / or an SSL key; the IPSec key includes an IPSec working key and an IPSec session key; the SSL key includes an SSL pre-master key, an SSL master key, and an SSL working key.

[0063] Step S13, save the target service key into the target isolation area corresponding to the target virtual VPN, so that the target virtual VPN performs service processing related to the target virtual VPN based on the target service key in the target isolation area.

[0064] In this embodiment, the target service key can be saved in the target isolation area corresponding to the target virtual VPN, and then the second identifier corresponding to the target service key returned by the password component can be obtained through the target virtual VPN; wherein, the second identifier includes a key handle.

[0065] Furthermore, when performing service processing, the target virtual VPN can determine the corresponding target isolation area in the password component based on the saved isolation area identifier, and access the target service key saved in the target isolation area based on the second identifier. In this way, the specific target service key in the target isolation area can be accessed in combination with the second identifier, so that the target virtual VPN can perform service processing related to the target virtual VPN based on the target service key.

[0066] As can be seen from the above, on the one hand, in this embodiment, a management key is added, and the management key is used to encrypt the device key of the target virtual VPN and save the encrypted device key to the corresponding target virtual VPN to protect the device key through the management key, and the host and the virtual VPN have different permissions for the management key; on the other hand, by setting a target isolation area with access permissions only for the corresponding target virtual VPN, and when using the corresponding key, the target service key and the decrypted device key are transferred to the target isolation area for use; in this way, combined with the new hierarchical key protection system and key isolation method, the isolation between the keys corresponding to different virtual VPNs is ensured, and the situation where keys may be misused or stolen between virtual VPNs, as well as the illegal access of the host to the keys corresponding to the virtual VPN, is avoided, improving the security of key storage. At the same time, the management key is saved in the password component, and the device key is saved in the file system of the virtual VPN. The software-hardware combined key protection and isolation scheme not only ensures the security of the keys but also reduces the capacity requirement for the non-volatile secure storage area of the password component, thereby reducing the hardware cost.

[0067] See Figure 3 As shown, an embodiment of the present application discloses a key isolation method based on permission control.

[0068] Among them, the management key (such as LMK) is located in the non-volatile storage area of the password component. The host can perform operations such as modification, addition, and deletion of the management key in the non-volatile storage area based on the management permission. The VVPN can perform key usage operations on the management key based on the tenant access permission and cannot manage it. The device key and the service key are located in the key isolation area in the volatile storage area of the password component. The VVPN can perform operations such as access, modification, and deletion on the device key and the service key in its corresponding key isolation area based on the tenant access permission, while prohibiting the host from accessing the key isolation areas allocated by the password component for each VVPN.

[0069] In this embodiment, after the device key is generated, it is first encrypted by the LMK in the cryptographic component and saved to the file system of the corresponding VVPN. Among them, container technology can be used to ensure the isolation of the file system, thereby ensuring the isolation of each device key.

[0070] When the VVPN receives a service requirement for the first time, the VVPN accesses the cryptographic component and sends a quarantine area application request to the cryptographic component. After the cryptographic component responds to the quarantine area application request, it creates a corresponding key quarantine area for the VVPN locally and returns a quarantine area ID to the VVPN. In this way, the cryptographic component distinguishes different VVPNs through different quarantine area IDs, establishing a binding relationship between the VVPN and the corresponding key quarantine area. Then, based on the quarantine area ID, the device key encrypted and saved in the file system corresponding to the VVPN is decrypted and transferred into the key quarantine area corresponding to the VVPN in the cryptographic component, and the VVPN obtains the key index corresponding to the device key returned by the cryptographic component.

[0071] Furthermore, based on the key index, the device key in the key quarantine area is used to protect the target key negotiation process, and the target service keys such as the IPSec working key, IPSec session key, and SSL working key obtained based on the target key negotiation process are saved to the key quarantine area corresponding to the VVPN. Then, the VVPN obtains the key handle corresponding to the target service key returned by the cryptographic component. When performing service processing, the VVPN can determine the corresponding key quarantine area in the cryptographic component based on the quarantine area ID saved by itself, and access the target service key saved in the target quarantine area based on the key handle.

[0072] As can be seen from the above, the management key is saved in the non-volatile storage area of the cryptographic component. The host and the virtual VPN have different permissions for the management key. The device keys of the virtual VPNs are saved in their respective file systems, and together with the file system isolation function implemented by container technology, they jointly ensure the secure storage of the management key and the device key, preventing unauthorized access. At the same time, when the virtual VPN receives a service requirement, the device key encrypted and saved in the virtual VPN is decrypted and transferred into the key quarantine area corresponding to the virtual VPN in the cryptographic component for use, and the service keys such as the working key and session key generated based on the service requirement are also saved to the key quarantine area corresponding to the virtual VPN. According to the logical isolation function of the cryptographic component, isolation in the use of device keys and service keys for each virtual VPN is achieved.

[0073] See Figure 4 As shown, the embodiment of the present application also discloses a cloud VPN key security protection device, which is applied to a cloud security gateway. The cloud security gateway includes a cryptographic component and several virtual VPNs running on the host; among them, the device includes:

[0074] The first key storage module 11 is configured to decrypt the device key encrypted and saved in the target virtual VPN and transfer it to the target isolation area corresponding to the target virtual VPN in the cryptographic component when the target virtual VPN receives a service request; wherein, the target virtual VPN is any one of the plurality of virtual VPNs; encrypt the device key using the management key in the cryptographic component and save the encrypted device key to the corresponding target virtual VPN; the target isolation area in the cryptographic component is an area to which only the corresponding target virtual VPN has access rights.

[0075] The key acquisition module 12 is configured to protect the target key negotiation process based on the device key in the target isolation area through the target virtual VPN and acquire the target service key corresponding to the service request generated by the target key negotiation process; the target key negotiation process is a process in which the target virtual VPN negotiates keys with the corresponding device to be interacted with for the service request.

[0076] The second key storage module 13 is configured to save the target service key to the target isolation area corresponding to the target virtual VPN, so that the target virtual VPN performs service processing related to the target virtual VPN based on the target service key in the target isolation area.

[0077] As can be seen from the above, the present application encrypts the device key of the target virtual VPN using the management key in the cryptographic component and saves the encrypted device key to the corresponding target virtual VPN to protect the device key through the management key; by setting a target isolation area to which only the corresponding target virtual VPN has access rights, and when using the corresponding key, transferring the target service key and the decrypted device key to the target isolation area for use, it ensures the isolation between the keys corresponding to different virtual VPNs, avoids the situation where keys may be misused or stolen between virtual VPNs and the illegal access of the keys corresponding to the virtual VPN by the host machine, and improves the security of key storage.

[0078] In some specific embodiments, the cloud VPN key security protection device further includes:

[0079] The first key storage unit is configured to store the management key in the target storage area of the cryptographic component; wherein, the target storage area is a non-volatile storage area.

[0080] The second key storage unit is configured to encrypt its own device key using the management key saved in the target storage area through the virtual VPN and store the encrypted device key in its own file system.

[0081] Correspondingly, the first key storage module 11 includes:

[0082] A key invocation unit, configured to decrypt the device key saved in the file system corresponding to the target virtual VPN and transfer it into the target isolation area corresponding to the target virtual VPN in the password component when the target virtual VPN receives a service request, so as to protect the target key negotiation process by using the device key in the target isolation area; wherein, the target isolation area is a volatile storage area.

[0083] In some specific embodiments, the cloud VPN key security protection device further includes:

[0084] A permission allocation unit, configured to allocate management permissions for the host and corresponding tenant access permissions for each virtual VPN through the password component;

[0085] An isolation area creation sub-module, configured to send an isolation area application request to the password component through the target virtual VPN, so that after the password component responds to the isolation area application request, a corresponding target isolation area is created for the target virtual VPN locally;

[0086] A first execution unit, configured to perform key management operations on the management key in the target storage area based on the management permissions through the host, and prohibit the host from accessing each target isolation area allocated by the password component for each virtual VPN; the key management operations include modification, addition, and deletion operations on the management key;

[0087] A second execution unit, configured to access the management key in the target storage area and access, modify, and delete the device key and target service key in the target isolation area based on the tenant access permissions through the target virtual VPN.

[0088] In some specific embodiments, the isolation area creation sub-module includes:

[0089] An isolation area allocation unit, configured to allocate a target isolation area for the target virtual VPN in the local volatile storage area after the password component responds to the isolation area application request, and return the isolation area identifier of the target isolation area to the target virtual VPN;

[0090] And, the first key storage module 11 includes:

[0091] A first identifier determination unit, configured to decrypt the device key encrypted and saved in the target virtual VPN and load it into the target isolation area, and obtain, through the target virtual VPN, a first identifier corresponding to the device key returned by the password component; the first identifier includes a key index.

[0092] Correspondingly, the key acquisition module 12 further includes:

[0093] A second identifier determination unit, configured to obtain, through the target virtual VPN, a second identifier corresponding to the target service key returned by the password component; the second identifier includes a key handle.

[0094] In some specific embodiments, the key acquisition module 12 further includes:

[0095] A first key access unit, configured to determine a corresponding target isolation area in the password component through the target virtual VPN based on the isolation area identifier saved by itself, and access the device key saved in the target isolation area based on the first identifier.

[0096] Correspondingly, the second key storage module 13 includes:

[0097] A second key access unit, configured to determine a corresponding target isolation area in the password component through the target virtual VPN based on the isolation area identifier saved by itself, and access the target service key saved in the target isolation area based on the second identifier.

[0098] In some specific embodiments, the device key of the target virtual VPN includes a signature key and / or an encryption key; the target service key includes an IPSec key and / or an SSL key; wherein, the IPSec key includes an IPSec working key and an IPSec session key; the SSL key includes an SSL pre-master key, an SSL master key, and an SSL working key.

[0099] In some specific embodiments, the cloud VPN key security protection device further includes:

[0100] A first key storage unit, configured to, after the password component creates the signature key for the target virtual VPN, encrypt the signature private key based on the management key corresponding to the target virtual VPN in the password component and save it to the file system of the target virtual VPN, and save the signature public key in plain text in the form of an encrypted certificate to the file system of the target virtual VPN; the signature key includes the signature private key and the signature public key.

[0101] A second key storage unit, configured to, after a certificate authority issues the encryption key for the target virtual VPN, encrypt the encryption private key based on the management key corresponding to the target virtual VPN in the password component and store the encrypted private key in the file system of the target virtual VPN, and store the encrypted public key in the file system of the target virtual VPN in the form of an encrypted certificate in plain text; the encryption key includes the encryption private key and the encryption public key.

[0102] Furthermore, an embodiment of the present application also discloses an electronic device. Figure 5 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure should not be considered as any limitation to the scope of use of the present application.

[0103] Figure 5 It is a schematic structural diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the cloud VPN key security protection method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0104] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is made here.

[0105] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a disk, or an optical disc, etc., and the resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be temporary storage or permanent storage.

[0106] Among them, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device 20, and it may be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the cloud VPN key security protection method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program that can be used to complete other specific tasks.

[0107] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program. When the computer program is executed by a processor, it implements the cloud VPN key security protection method disclosed above. For the specific steps of this method, reference may be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated herein.

[0108] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference may be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference may be made to the description in the method section.

[0109] Those skilled in the art can further realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0110] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0111] Finally, it should also be noted that in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

[0112] The above has introduced the technical solution provided by this application in detail. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A cloud VPN key security protection method, characterized in that Applied to a cloud security gateway, the cloud security gateway includes a password component and a number of virtual VPNs running on a host; wherein, the method includes: When a target virtual VPN receives a service request, decrypt the device key encrypted and saved in the target virtual VPN and transfer it to the target isolation area corresponding to the target virtual VPN in the password component; wherein, the target virtual VPN is any one of the number of virtual VPNs; encrypt the device key using the management key in the password component and save the encrypted device key to the corresponding target virtual VPN; the target isolation area in the password component is an area to which only the corresponding target virtual VPN has access rights; Protect the target key negotiation process based on the device key in the target isolation area through the target virtual VPN, and obtain the target service key corresponding to the service request generated by the target key negotiation process; the target key negotiation process is a process in which the target virtual VPN negotiates keys with a corresponding device to be interacted with for the service request; Save the target service key to the target isolation area corresponding to the target virtual VPN, so that the target virtual VPN performs service processing related to the target virtual VPN based on the target service key in the target isolation area.

2. The cloud VPN key security protection method according to claim 1, characterized in that Further includes: Store the management key in the target storage area of the password component; wherein, the target storage area is a non-volatile storage area; Encrypt the device key of itself using the management key saved in the target storage area through the virtual VPN, and store the encrypted device key in its own file system; Correspondingly, the step of when the target virtual VPN receives a service request, decrypt the device key encrypted and saved in the target virtual VPN and transfer it to the target isolation area corresponding to the target virtual VPN in the password component includes: When the target virtual VPN receives a service request, decrypt the device key encrypted and saved in the file system corresponding to the target virtual VPN and transfer it to the target isolation area corresponding to the target virtual VPN in the password component, so as to protect the target key negotiation process using the device key in the target isolation area; wherein, the target isolation area is a volatile storage area.

3. The cloud VPN key security protection method according to claim 2, characterized in that Further includes: Assign management permissions to the host through the password component and assign corresponding tenant access permissions to each virtual VPN; Send an isolation area application request to the password component through the target virtual VPN, so that after the password component responds to the isolation area application request, create the corresponding target isolation area for the target virtual VPN locally; The host machine performs key management operations on the management key in the target storage area based on the management authority, and prohibits the host machine from accessing the target isolation areas allocated by the password component for each virtual VPN; the key management operations include modification, addition, and deletion operations for the management key. The target virtual VPN accesses the management key in the target storage area and accesses, modifies, and deletes the device key and the target service key in the target isolation area based on the tenant access authority.

4. The cloud VPN key security protection method according to claim 3, characterized in that After the password component responds to the isolation area application request, it creates the corresponding target isolation area for the target virtual VPN locally, including: After the password component responds to the isolation area application request, it allocates a target isolation area for the target virtual VPN in the local volatile storage area and returns the isolation area identifier of the target isolation area to the target virtual VPN. Moreover, decrypting the device key encrypted and saved in the target virtual VPN and transferring it into the target isolation area corresponding to the target virtual VPN in the password component includes: Decrypting the device key encrypted and saved in the target virtual VPN and transferring it into the target isolation area, and obtaining the first identifier corresponding to the device key returned by the password component through the target virtual VPN; the first identifier includes a key index. Correspondingly, after obtaining the target service key corresponding to the service request generated by the target key negotiation process, it further includes: Obtaining the second identifier corresponding to the target service key returned by the password component through the target virtual VPN; the second identifier includes a key handle.

5. The cloud VPN key security protection method according to claim 4, characterized in that, Before protecting the target key negotiation process by the target virtual VPN based on the device key in the target isolation area, it further includes: Determining the corresponding target isolation area in the password component based on the isolation area identifier saved by the target virtual VPN itself, and accessing the device key saved in the target isolation area based on the first identifier. Correspondingly, the target virtual VPN performs service processing related to the target virtual VPN based on the target service key in the target isolation area, including: Determining the corresponding target isolation area in the password component based on the isolation area identifier saved by the target virtual VPN itself, and accessing the target service key saved in the target isolation area based on the second identifier.

6. The cloud VPN key security protection method according to any one of claims 1 to 5, characterized in that The device key of the target virtual VPN includes a signature key and / or an encryption key; the target service key includes an IPSec key and / or an SSL key; wherein, the IPSec key includes an IPSec working key and an IPSec session key; the SSL key includes an SSL pre-master key, an SSL master key, and an SSL working key.

7. The cloud VPN key security protection method according to claim 6, wherein It further includes: After the cryptographic component creates the signature key for the target virtual VPN, encrypt the signature private key based on the management key corresponding to the target virtual VPN in the cryptographic component and save it to the file system of the target virtual VPN, and save the signature public key in plain text in the form of an encrypted certificate to the file system of the target virtual VPN; the signature key includes the signature private key and the signature public key; After the certificate authority issues the encryption key for the target virtual VPN, encrypt the encryption private key based on the management key corresponding to the target virtual VPN in the cryptographic component and save it to the file system of the target virtual VPN, and save the encryption public key in plain text in the form of an encrypted certificate to the file system of the target virtual VPN; the encryption key includes the encryption private key and the encryption public key.

8. A cloud VPN key security protection device, characterized in that, Applied to a cloud security gateway, the cloud security gateway includes a cryptographic component and a number of virtual VPNs running on a host; wherein, the device includes: A first key storage module, configured to decrypt the device key encrypted in the target virtual VPN and transfer it to the target isolation area corresponding to the target virtual VPN in the cryptographic component when the target virtual VPN receives a service request; wherein, the target virtual VPN is any one of the number of virtual VPNs; encrypt the device key using the management key in the cryptographic component and save the encrypted device key to the corresponding target virtual VPN; the target isolation area in the cryptographic component is an area to which only the corresponding target virtual VPN has access rights; A key acquisition module, configured to protect the target key negotiation process based on the device key in the target isolation area through the target virtual VPN, and acquire the target service key corresponding to the service request generated by the target key negotiation process; the target key negotiation process is a process in which the target virtual VPN negotiates keys with a corresponding device to be interacted with for the service request; A second key storage module, configured to save the target service key to the target isolation area corresponding to the target virtual VPN, so that the target virtual VPN performs service processing related to the target virtual VPN based on the target service key in the target isolation area.

9. An electronic device, characterized in that, Includes: A memory, configured to save a computer program; A processor, configured to execute the computer program to implement the cloud VPN key security protection method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, For saving a computer program, the computer program, when executed by a processor, implements the cloud VPN key security protection method according to any one of claims 1 to 7.