Communication method, key management system and storage medium

By setting up encrypted memory areas in the client and the key server and adding device verification links, the problem of the key server relying on user information for client verification is solved, achieving higher communication security.

CN120281554APending Publication Date: 2025-07-08LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510552947.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In the prior art, the verification of the client by the key server depends on the client's user information in the key management request, and the key management request is usually transmitted in plain text, which makes it easy for a third party to steal user information, reducing the communication security between the key server and the client.

Method used

Set up an encrypted memory area in the client and the key server, and add a device verification process between the client and the key server. The client proxy module and the service proxy module generate and verify device verification information in the encrypted memory area to improve communication security.

Benefits of technology

By adding device verification links to the encrypted memory area to avoid plaintext transmission, the device verification of the key server to the client is enhanced and communication security is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281554A_ABST
    Figure CN120281554A_ABST
Patent Text Reader

Abstract

The invention discloses a communication method, a key management system and a storage medium, relates to the field of key management, and can set encrypted memory areas in a client and a key server, set a client agent module in the encrypted memory area of the client, and set a service agent module in the encrypted memory area of the key server. When a client agent module receives a key management request sent by a client application program, equipment verification information can be generated by using operation data in a client encryption memory area, the key management request and the equipment verification information are combined and encrypted into encryption request information, and then the encryption request information is sent to a service agent module. The service agent module can decrypt the encrypted request information and verify the equipment verification information by using the pre-stored equipment reference information of the client agent module, so that the key management request is issued to the key server application program when the equipment verification information passes the verification, and the communication security can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of key management, and particularly to a communication method, a key management system, and a storage medium. Background Art

[0002] With the enhancement of people's data security awareness, setting up a key server to achieve unified management of various keys has become a common choice. In related technologies, the verification of the client by the key server only depends on the user information set by the client in the key management request, and the key management request usually uses plaintext transmission. This makes it easy for a third party to steal user information from the key management request, and then maliciously access the key server, reducing the communication security between the key server and the client. Summary of the Invention

[0003] This application provides a communication method, a key management system, and a storage medium, which can improve the communication security between the client and the key server by setting up an encrypted memory area in the client and the key server, and adding a device verification link based on the encrypted memory area.

[0004] To solve the above technical problems, this application provides a communication method, which is applied to a client proxy module. The client proxy module is set in the encrypted memory area of the client. The method includes:

[0005] When receiving a key management request sent by the client application, generating device verification information using the running data in the encrypted memory area;

[0006] Combining the key management request and the device verification information into a request message, and encrypting the request message into an encrypted request message;

[0007] Sending the encrypted request message to the service proxy module in the key server, so that the service proxy module decrypts the encrypted request message, verifies the device verification information using the pre-stored device reference information of the client proxy module, and when the device verification information passes the verification, sends the key management request to the key server application of the key server; the service proxy module is set in the encrypted memory area of the key server.

[0008] Optionally, generating device verification information using the running data in the encrypted memory area includes:

[0009] Generating a device value to be tested using the running data in the encrypted memory area;

[0010] Signing the device value to be tested using the built-in key of the processor to obtain signature information;

[0011] Combine the device value to be measured and the signature information into device verification information, so that the service proxy module uses the root key corresponding to the built-in key of the processor to verify the signature information and uses the pre-stored device reference value of the client proxy module to verify the device value to be measured.

[0012] Optionally, before receiving the key management request sent by the client application, it further includes:

[0013] When receiving the temporary random number sent by the service proxy module, generate the device reference value using the running data in the encrypted memory area, combine the device reference value and the temporary random number into proof information, and sign the proof information using the built-in key of the processor to obtain the proof signature information;

[0014] Send the proof information and the proof signature information to the service proxy module, so that the service proxy module uses the root key to verify the proof signature information, verify the temporary random number in the proof information, and save the device reference value after both the proof signature information and the temporary random number pass the verification.

[0015] Optionally, after sending the proof information and the proof signature information to the service proxy module, it further includes:

[0016] When detecting that the running data in the encrypted memory area is normally modified, regenerate and update the device reference value according to the running data in the encrypted memory area, and sign the updated device reference value using the built-in key of the processor to obtain the reference value signature information;

[0017] Send the updated device reference value and the reference value signature information to the service proxy module, so that the service proxy module uses the root key to verify the reference value signature information, and updates the pre-stored device reference value using the updated device reference value when the reference value signature information passes the verification.

[0018] Optionally, after sending the proof information and the proof signature information to the service proxy module, it further includes:

[0019] Receive the communication session key issued by the service proxy module and save the communication session key in the encrypted memory area;

[0020] Encrypt the request information into encrypted request information, including:

[0021] Encrypt the request information into encrypted request information using the communication session key.

[0022] This application also provides a communication method, which is applied to the service proxy module. The service proxy module is set in the encrypted memory area of the key server. The method includes:

[0023] When receiving the encrypted request information sent by the client proxy module, decrypt the encrypted request information to obtain a key management request and device verification information; the client proxy module is set in the encrypted memory area of the client, and the device verification information is generated by the client proxy module using the running data in the encrypted memory area of the client;

[0024] Verify the device verification information using the pre-stored device reference information of the client proxy module;

[0025] When the device verification information passes the verification, send the key management request to the key server application program of the key server.

[0026] Optionally, the device verification information includes a device value to be measured and signature information. The device value to be measured is generated by the client proxy module using the running data in the encrypted memory area of the client, and the signature information is obtained by the client proxy module signing the device value to be measured using the built-in key of the processor;

[0027] Verifying the device verification information using the pre-stored device reference information of the client proxy module includes:

[0028] Verify the signature information using the root key corresponding to the built-in key of the processor in the processor key server;

[0029] When the signature information passes the verification, verify the device value to be measured using the pre-stored device reference value of the client proxy module.

[0030] Optionally, before receiving the encrypted request information sent by the client proxy module, it further includes:

[0031] Obtain the communication information of the pre-stored client proxy module, generate a temporary random number, and send the temporary random number to the client proxy module according to the communication information;

[0032] Receive the proof information and proof signature information sent by the client proxy module, and extract the device reference value and the random number to be measured from the proof information; the device reference value is generated by the client proxy module using the running data in the encrypted memory area of the client, and the proof signature information is obtained by the client proxy module signing the proof information using the built-in key of the processor;

[0033] Verify the proof signature information using the root key corresponding to the built-in key of the processor in the processor key server;

[0034] When the signature information passes the verification, verify the random number to be measured using the temporary random number;

[0035] When the random number to be measured passes the verification, save the device reference value.

[0036] Optionally, after saving the device reference value, it further includes:

[0037] Receive the updated device reference value and reference value signature information sent by the client agent module; the updated device reference value is generated by the client agent module using the running data in the encrypted memory area of the client when it detects a normal modification of the running data in the encrypted memory area of the client, and the reference value signature information is obtained by the client agent module signing the updated device reference value using the built-in key of the processor;

[0038] Verify the reference value signature information using the root key, and update the pre-stored device reference value with the updated device reference value when the reference value signature information passes the verification.

[0039] Optionally, after saving the device reference value, it further includes:

[0040] Send the communication session key to the client agent module;

[0041] Decrypt the encrypted request information, including:

[0042] Decrypt the encrypted request information using the communication session key.

[0043] This application also provides a key management system, including a client and a key server. The encrypted memory area of the client is provided with a client agent module, and the encrypted memory area of the key server is provided with a service agent module;

[0044] The client agent module is used to execute the above communication method applied to the client agent module;

[0045] The service agent module is used to execute the above communication method applied to the service agent module.

[0046] This application also provides a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are loaded and executed by a processor, the communication method applied to the client agent module or the communication method applied to the service agent module as described above is implemented.

[0047] The present application provides a communication method, which is applied to a client proxy module. The client proxy module is set in the encrypted memory area of the client. The method includes: when receiving a key management request sent by a client application, generating device verification information by using the running data in the encrypted memory area; combining the key management request and the device verification information into a request message, and encrypting the request message into an encrypted request message; sending the encrypted request message to a service proxy module in a key server, so that the service proxy module decrypts the encrypted request message, verifies the device verification information by using the pre-stored device reference information of the client proxy module, and when the device verification information passes the verification, sending the key management request to a key server application of the key server; the service proxy module is set in the encrypted memory area of the key server.

[0048] The beneficial effects of the present application are as follows: The present application can set encrypted memory areas in both the client and the key server, and set a client proxy module in the encrypted memory area of the client and a service proxy module in the encrypted memory area of the key server. When the client proxy module receives a key management request sent by a client application, it can generate device verification information by using the running data in the encrypted memory area of the client, combine and encrypt the key management request and the device verification information into an encrypted request message, and then send the encrypted request message to the service proxy module. The service proxy module can decrypt the encrypted request message, verify the device verification information by using the pre-stored device reference information of the client proxy module, and further send the key management request to the key server application when the device verification information passes the verification. In this way, the client proxy module can add device verification information to the key management request in the encrypted memory area, and the service proxy module can verify the device verification information in the encrypted memory area and then send the key management request to the key server application, which can increase the device verification of the key server for the client, thereby improving communication security.

[0049] The present application also provides a key management system and a computer-readable storage medium, which have the above beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0051] Figure 1 It is a structural block diagram of a key management system provided by an embodiment of the present application;

[0052] Figure 2 It is a flowchart of a communication method provided by an embodiment of the present application;

[0053] Figure 3 Flow chart of another communication method provided by the embodiments of the present application;

[0054] Figure 4 Structural block diagram of another key management system provided by the present application;

[0055] Figure 5 Schematic diagram of an identity authentication process provided by the embodiments of the present application. Detailed implementation manners

[0056] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0057] It should be noted that in the description of the present application, the terms "including", "comprising" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0058] In order to enable those skilled in the art of the present technology to better understand the solutions of the present application, the present application will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.

[0059] With the enhancement of people's awareness of data security, setting up a key server to achieve unified management of various keys has become a common choice. In related technologies, the verification of the client by the key server only depends on the user information set by the client in the key management request, and the key management request usually uses plaintext transmission. For example, when communicating between the client and the key server based on the KMIP protocol (Key Management Interoperability Protocol), the client can generate a TTLV message (Tag-Type-Length-Value) according to the key management operation to be performed, and add the user information of the client, such as UsernameAndPassword (username and password) or Device (device identity ID), to the TTLV message. Subsequently, the client can send the plaintext TTLV message to the key server. The key server can first verify the user information and perform the key management operation according to the TTLV message after the verification passes. However, it is easy for a third party to intercept the key management request and steal the user information from it, and then maliciously access the key server. Therefore, the related technologies reduce the communication security between the key server and the client.

[0060] In view of this, aiming at the technical problem of how to improve the communication security between the client and the key server, this application can provide a communication method, which can improve the communication security between the client and the key server by setting up an encrypted memory area in the client and the key server and adding a device verification link based on the encrypted memory area.

[0061] For easy understanding, the structure of the key management system provided by this application will be introduced first below. Please refer to Figure 1 , Figure 1The block diagram of a key management system provided by an embodiment of the present application. This system may include a client and a key server. The client includes a client proxy module and a client application, and the client proxy module is set in the encrypted memory area of the client. The key server includes a service proxy module and a key server application, and the service proxy module is set in the encrypted memory area of the key server. The running data in the encrypted memory area has been encrypted, which means that the data of the client proxy module and the service proxy module cannot be directly accessed externally, and can only be accessed by the client proxy module and the service proxy module themselves. It can be seen that in this embodiment, the client application and the key server application do not directly communicate, but communicate through the client proxy module and the service proxy module. In other words, the key management request generated by the client application is not directly sent to the key server application, but first sent to the client proxy module, processed by the client proxy module and then sent to the service proxy module, and then processed by the service proxy module and sent to the key server application.

[0062] Furthermore, to improve the communication security between the client and the key server, when the client proxy module in this embodiment receives the key management request sent by the client, it can generate device verification information using the running data in the client's encrypted memory area. This device verification information is used to indicate whether the encrypted memory area of the client has been tampered with. Subsequently, the client proxy module can combine, encrypt the key management request and the device verification information into encrypted request information, and send it to the service proxy module. The service proxy module can decrypt the encrypted request information, verify the device verification information using the pre-stored device reference information corresponding to the client proxy module, and after the verification passes, then send the key management request to the key server application. It can be seen that the client proxy module and the service proxy module can transfer encrypted request information, which can avoid transferring the plaintext key management request. More importantly, the client proxy module can add device verification information to the key management request in the encrypted memory area, and the service proxy module can verify the device verification information in the encrypted memory area and then send the key management request to the key server application, thereby increasing the device verification process of the key server for the client, avoiding the key server only verifying the client based on the user information in the key management request, and thus improving the communication security.

[0063] It should be noted that this embodiment does not limit how to set up the client proxy module and the service proxy module in the encrypted memory area. For example, a virtual machine can be set up in the encrypted memory area of the client, and the client proxy module can be run using the virtual machine. Also, a virtual machine can be set up in the encrypted memory area of the key server, and the service proxy module can be run using the virtual machine. This embodiment also does not limit the number of clients. The key server can communicate with multiple clients and can pre-store the corresponding device reference information for each client to improve application flexibility. This embodiment also does not limit the specific hardware forms of the client and the key server, which can be set according to actual application requirements.

[0064] Based on the above introduction of the system structure, the communication method provided in this embodiment will be introduced below. Please refer to Figure 2 , Figure 2 which is a flowchart of a communication method provided in an embodiment of the present application. This method is applied to the client proxy module, which is set in the encrypted memory area of the client. This method may include:

[0065] S201. When receiving a key management request sent by the client application, generate device verification information using the running data in the encrypted memory area.

[0066] In this embodiment, the client application can regard the client proxy module as the key server application. Specifically, the client proxy module can provide communication information, including the IP address and port number. The client application can set the communication information of the client proxy module as the communication information of the key server application, so that the key management request can be sent to the client proxy module.

[0067] Furthermore, to verify the identity of the client proxy module and to verify whether the client proxy module has been abnormally tampered with, the service proxy module can pre-store the device reference information of the client proxy module in its encrypted memory area. This device reference information is generated by the client proxy module based on the running data in its encrypted memory area and has been verified as trustworthy by the service proxy module. For example, when the client proxy module runs based on a virtual machine in the encrypted memory area, the client proxy module can generate device reference information based on the integrity measurement value of the virtual machine, the virtual machine configuration, the virtual machine hardware status, etc. Correspondingly, to prove its identity and to prove that it has not been abnormally tampered with, when receiving the key management request, the client proxy module needs to generate device verification information (Attestation Report) based on the running data in its encrypted memory area. For example, it can generate a device value to be measured based on the current integrity measurement value of the virtual machine, the virtual machine configuration, the virtual machine hardware status, etc. Subsequently, the client proxy module needs to combine the key management request and the device verification information and send them to the service proxy module for verification.

[0068] Further, to prove the validity of the device value to be measured, the client agent module can use the processor - built - in key PEK (Platform Endorsement Key) in the client to sign the device measurement value to obtain signature information, and can combine the device value to be measured and the signature information into device verification information. Among them, the processor - built - in key is set inside the processor based on hardware encryption technology. And the service agent module can use the root key corresponding to the processor - built - in key to verify the signature information, and the root key is the key for deriving the processor - built - in key.

[0069] Based on this, generating device verification information using the running data in the encrypted memory area may include:

[0070] Step 11: Generate the device value to be measured using the running data in the encrypted memory area.

[0071] Step 12: Use the processor - built - in key to sign the device value to be measured to obtain signature information.

[0072] Step 13: Combine the device value to be measured and the signature information into device verification information, so that the service agent module uses the root key corresponding to the processor - built - in key to verify the signature information and uses the pre - stored device reference value of the client agent module to verify the device value to be measured.

[0073] S202: Combine the key management request and the device verification information into a request information, and encrypt the request information into an encrypted request information.

[0074] In this step, the client agent module needs to combine the key management request and the device verification information into a request information, and encrypt the request information into an encrypted request information. The client agent module can use the communication session key to encrypt the request information into an encrypted request information, where the communication session key is sent by the service agent module to the client agent module.

[0075] S203: Send the encrypted request information to the service agent module in the key server, so that the service agent module decrypts the encrypted request information, uses the pre - stored device reference information of the client agent module to verify the device verification information, and when the device verification information passes the verification, sends the key management request to the key server application program of the key server; the service agent module is set in the encrypted memory area of the key server.

[0076] In this step, the client agent module may send the encrypted request information to the service agent module. The service agent module may first decrypt the encrypted request information, such as decrypting the encrypted request information using the communication session key issued to the client agent module. Subsequently, the service agent module may verify the device verification information by using the pre-stored device reference information of the client agent module, and issue a key management request to the key server application when the device verification information passes the verification. In this way, the client agent module and the service agent module can transmit the key management request in an encrypted form; moreover, the key server verifies the client device, which can avoid the key server verifying the client only based on the user information in the key management request, thereby improving communication security.

[0077] Furthermore, when the key server application finishes processing the key management request and generates a key management request response, it may send it to the service agent module. The service agent module may encrypt the key management request response to obtain an encrypted key management request response, and send the encrypted key management request response to the client agent module. The client agent module may decrypt the encrypted key management request response to obtain the key management request response, and send the key management request response to the client application.

[0078] Based on this, after sending the encrypted request information to the service agent module in the key server, it further includes:

[0079] Step 21: Receive the encrypted key management request response sent by the service agent module;

[0080] Step 22: Decrypt the encrypted key management request response to obtain the key management request response, and send the key management request response to the client application.

[0081] Based on the above embodiments, the present application can set up encrypted memory areas in both the client and the key server, and set up a client proxy module in the encrypted memory area of the client and a service proxy module in the encrypted memory area of the key server. When the client proxy module receives a key management request sent by the client application, it can generate device verification information using the running data in the client's encrypted memory area, combine the key management request and the device verification information, encrypt them into encrypted request information, and then send the encrypted request information to the service proxy module. The service proxy module can decrypt the encrypted request information, verify the device verification information using the pre-stored device reference information of the client proxy module, and then send the key management request to the key server application when the device verification information passes the verification. In this way, the client proxy module can add device verification information to the key management request in the encrypted memory area, and the service proxy module can verify the device verification information in the encrypted memory area and then send the key management request to the key server application, which can increase the device verification of the key server for the client, thereby improving communication security.

[0082] Based on the above embodiments, the process of the client proxy module and the service proxy module verifying their identities and uploading the device reference value will be introduced below. Based on this, before receiving the key management request sent by the client application, it may further include:

[0083] S301. When receiving the temporary random number sent by the service proxy module, generate a device reference value using the running data in the encrypted memory area, combine the device reference value and the temporary random number into proof information, and sign the proof information using the built-in key of the processor to obtain proof signature information.

[0084] In this step, the service proxy module can first send a temporary random number to the client proxy module to trigger the client proxy module to start the identity verification process. When the client proxy module receives the temporary random number, it can generate a device reference value using the running data in the encrypted memory area, combine the device reference value and the temporary random number into proof information, and sign the proof information using the built-in key of the processor to obtain proof signature information.

[0085] Of course, to improve the security of the service proxy module and the client proxy module during the identity verification process, a TLS certificate can be set in the service proxy module. The client proxy module and the service proxy module can first establish a secure transmission channel based on the TLS protocol, and then receive the temporary random number sent by the service proxy module based on the secure transmission channel.

[0086] S302. Send the proof information and the proof signature information to the service proxy module, so that the service proxy module uses the root key to verify the proof signature information, verify the nonce in the proof information, and save the device reference value after both the proof signature information and the nonce pass the verification.

[0087] In this step, the client proxy module sends the proof information and the proof signature information to the service proxy module. The service proxy module can first use the root key to verify the proof signature information. When the proof signature information passes the verification, the service proxy module can use the nonce in the proof information as the to-be-verified nonce, and use the local nonce to verify the to-be-verified nonce. When the to-be-verified nonce also passes the verification, the service proxy module can save the device reference value in the proof information to complete the identity verification process.

[0088] Furthermore, after the service proxy module saves the device reference value, it can also set a communication session key for the client proxy module, establish a correspondence between the communication session key and the device reference value, and send the communication session key to the client proxy module. The client proxy module can save the communication session key in its own encrypted memory area to ensure communication security.

[0089] Based on this, after sending the proof information and the proof signature information to the service proxy module, it may further include:

[0090] Step 31. Receive the communication session key sent by the service proxy module, and save the communication session key in the encrypted memory area.

[0091] Based on the above embodiments, considering that normal modification of the running data may occur in the encrypted memory area where the client proxy module is located, such as virtual machine configuration adjustment, etc., and the modification of the running data will affect the device reference value in the service proxy module. Therefore, when it is detected that normal modification of the running data occurs in the encrypted memory area, the client proxy module can also regenerate and update the device reference value according to the running data in the encrypted memory area, sign the updated device reference value using the built-in key of the processor to obtain the reference value signature information, and send the updated device reference value and the reference value signature information to the service proxy module for the service proxy module to update the device reference value.

[0092] Based on this, after sending the proof information and the proof signature information to the service proxy module, it further includes:

[0093] Step 41. When it is detected that normal modification of the running data occurs in the encrypted memory area, regenerate and update the device reference value according to the running data in the encrypted memory area, and sign the updated device reference value using the built-in key of the processor to obtain the reference value signature information.

[0094] Step 42: Send the updated device reference value and the reference value signature information to the service proxy module, so that the service proxy module uses the root key to verify the reference value signature information, and updates the pre-stored device reference value with the updated device reference value when the reference value signature information passes the verification.

[0095] Based on the above embodiments, the implementation of the present communication method on the service proxy module side will be introduced below. Please refer to Figure 3 , Figure 3 which is a flowchart of another communication method provided by the embodiments of the present application. This method is applied to the service proxy module, and the service proxy module is set in the encrypted memory area of the key server, and may include:

[0096] S401. When receiving the encrypted request information sent by the client proxy module, decrypt the encrypted request information to obtain a key management request and device verification information; the client proxy module is set in the encrypted memory area of the client, and the device verification information is generated by the client proxy module using the running data in the encrypted memory area of the client.

[0097] In this step, when the service proxy module receives the encrypted request information sent by the client, it can decrypt the encrypted request information, such as decrypting the encrypted request information using the communication session key issued to the client proxy module. Subsequently, the service proxy module can extract the key management request and device verification information from the encrypted request information. The device verification information is generated by the client proxy module using the running data in the encrypted memory area of the client. The service proxy module needs to verify the device verification information first and then send the key management request to the key server application.

[0098] S402. Verify the device verification information using the pre-stored device reference information of the client proxy module.

[0099] In this step, the service proxy module can verify the device verification information using the pre-stored device reference information of the client proxy module, and then send the key management request to the key server application when the device verification information passes the verification. In this way, the key server can verify the client device, which can avoid the key server verifying the client only based on the user information in the key management request, thereby improving communication security.

[0100] Specifically, the above device verification information may include a device value to be measured and signature information. The device value to be measured is generated by the client proxy module using the running data in the encrypted memory area of the client, and the signature information is obtained by the client proxy module signing the device value to be measured using the built-in key of the processor. The service proxy module needs to first verify the signature information using the root key corresponding to the built-in key of the processor, and then verify the device value to be measured using the device reference value corresponding to the client proxy module.

[0101] Based on this, the device verification information is verified using the device reference information of the pre-stored customer agent module, including:

[0102] Step 51: Verify the signature information using the root key corresponding to the built-in key of the processor in the processor key server.

[0103] In this step, the processor key server is responsible for setting the built-in key of the processor for the client and storing the root key corresponding to the built-in key of the processor. Therefore, the service agent module can verify the above signature information through the processor key server. For easy understanding, please refer to Figure 4 , Figure 4 which is the structural block diagram of another key management system provided by this application, showing that the service agent module can also be connected to the processor key server.

[0104] Step 52: When the signature information passes the verification, verify the device value to be measured using the pre-stored device reference value of the customer agent module.

[0105] S403. When the device verification information passes the verification, send the key management request to the key server application program of the key server.

[0106] In this step, the service agent module can send the key management request to the key server application program when the device verification information passes the verification.

[0107] Furthermore, when the key server application program completes the processing of the key management request and generates a key management request response, it can send it to the service agent module. The service agent module can encrypt the key management request response to obtain an encrypted key management request response and send the encrypted key management request response to the customer agent module. And the customer agent module can decrypt the encrypted key management request response to obtain the key management request response and send the key management request response to the client application program.

[0108] Based on this, after sending the key management request to the key server application program of the key server, it further includes:

[0109] Step 61: Receive the key management request response sent by the key server application program;

[0110] Step 62: Encrypt the key management request response to obtain an encrypted key management request response and send the encrypted key management request response to the customer agent module.

[0111] Based on the above embodiments, the process of the service proxy module and the client proxy module verifying their identities and receiving the device reference value will be introduced below. Based on this, before receiving the encrypted request information sent by the client proxy module, this method may further include:

[0112] S501. Obtain the pre-stored communication information of the client proxy module, generate a temporary random number, and send the temporary random number to the client proxy module according to the communication information.

[0113] In this step, the service proxy module can first send a temporary random number to the client proxy module according to the pre-stored communication information of the client proxy module to trigger the client proxy module to start the identity verification process. When the client proxy module receives the temporary random number, it can generate a device reference value using the running data in the encrypted memory area, combine the device reference value and the temporary random number into proof information, and sign the proof information using the built-in key of the processor to obtain the proof signature information.

[0114] Of course, to improve the security of the service proxy module and the client proxy module during the identity verification process, a TLS certificate can be set in the service proxy module. The client proxy module and the service proxy module can first establish a secure transmission channel based on the TLS protocol, and then receive the temporary random number sent by the service proxy module based on the secure transmission channel.

[0115] S502. Receive the proof information and the proof signature information sent by the client proxy module, and extract the device reference value and the random number to be tested from the proof information; the device reference value is generated by the client proxy module using the running data in the encrypted memory area of the client, and the proof signature information is obtained by the client proxy module signing the proof information using the built-in key of the processor.

[0116] S503. Verify the proof signature information using the root key corresponding to the built-in key of the processor in the processor key server.

[0117] S504. When the signature information passes the verification, verify the random number to be tested using the temporary random number.

[0118] S505. When the random number to be tested passes the verification, save the device reference value.

[0119] In steps S502 - S505, the service proxy module can first verify the proof signature information using the root key. When the proof signature information passes the verification, the service proxy module can extract the random number to be tested from the proof information and verify the random number to be tested using the local temporary random number. When the random number to be tested also passes the verification, the service proxy module can save the device reference value in the proof information to complete the identity verification process.

[0120] Further, after the service proxy module saves the device reference value, it can also set a communication session key for the client proxy module, establish a correspondence between the communication session key and the device reference value, and send the communication session key to the client proxy module. The client proxy module can save the communication session key in its own encrypted memory area to ensure communication security.

[0121] Based on this, after saving the device reference value, it may further include:

[0122] Step 71: Sending a communication session key to the client proxy module.

[0123] Finally, for ease of understanding the authentication process between the client proxy module and the service proxy module, please refer to Figure 5 , Figure 5 which is a schematic diagram of an authentication process provided by an embodiment of the present application.

[0124] Based on the above embodiments, considering that the running data in the encrypted memory area where the client proxy module is located may be normally modified, such as virtual machine configuration adjustment, etc., and the modification of the running data will affect the device reference value in the service proxy module. Therefore, when it is detected that the running data in the encrypted memory area has been normally modified, the client proxy module can also regenerate and update the device reference value according to the running data in the encrypted memory area, sign the updated device reference value using the built-in key of the processor to obtain the reference value signature information, and send the updated device reference value and the reference value signature information to the service proxy module. The service proxy module can verify the reference value signature information, and after the verification passes, update the pre-stored device reference value using the updated device reference value.

[0125] Based on this, after saving the device reference value, it further includes:

[0126] S601: Receiving the updated device reference value and the reference value signature information sent by the client proxy module; the updated device reference value is generated by the client proxy module using the running data in the encrypted memory area of the client when it is detected that the running data in the encrypted memory area of the client has been normally modified, and the reference value signature information is obtained by the client proxy module signing the updated device reference value using the built-in key of the processor;

[0127] S602: Verifying the reference value signature information using the root key, and updating the pre-stored device reference value using the updated device reference value when the reference value signature information passes the verification.

[0128] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.

[0129] Embodiments of the present application also provide a key management system. Please refer to Figure 1 , Figure 1 , which is a structural block diagram of a key management system provided by an embodiment of the present application. The system includes a client and a key server. A client proxy module is set in the encrypted memory area of the client, and a service proxy module is set in the encrypted memory area of the key server;

[0130] The client proxy module is configured to generate device verification information by using the running data in the encrypted memory area when receiving a key management request sent by a client application; combine the key management request and the device verification information into a request message, and encrypt the request message into an encrypted request message; send the encrypted request message to the service proxy module in the key server;

[0131] The service proxy module is configured to decrypt the encrypted request message when receiving the encrypted request message sent by the client proxy module to obtain the key management request and the device verification information; verify the device verification information by using the pre-stored device reference information of the client proxy module; when the device verification information passes the verification, send the key management request to the key server application of the key server.

[0132] The client proxy module is further configured to receive an encrypted key management request response sent by the service proxy module; decrypt the encrypted key management request response to obtain the key management request response, and send the key management request response to the client application.

[0133] The service proxy module is further configured to receive a key management request response sent by the key server application; encrypt the key management request response to obtain an encrypted key management request response, and send the encrypted key management request response to the client proxy module.

[0134] Optionally, the client proxy module is further configured to generate a device value to be measured by using the running data in the encrypted memory area; sign the device value to be measured by using the built-in key of the processor to obtain signature information; combine the device value to be measured and the signature information into device verification information;

[0135] The service proxy module is further configured to verify the signature information by using the root key corresponding to the built-in key of the processor in the key server of the processor; when the signature information passes the verification, verify the device value to be measured by using the pre-stored device reference value of the client proxy module.

[0136] Optionally, the client agent module is further configured to, when receiving the temporary random number sent by the service agent module, generate a device reference value using the running data in the encrypted memory area, combine the device reference value and the temporary random number into proof information, and sign the proof information using the built-in key of the processor to obtain proof signature information; send the proof information and the proof signature information to the service agent module;

[0137] The service agent module is further configured to obtain the pre-stored communication information of the client agent module, generate a temporary random number, and send the temporary random number to the client agent module according to the communication information; receive the proof information and the proof signature information sent by the client agent module, and extract the device reference value and the random number to be measured from the proof information; verify the proof signature information using the root key corresponding to the built-in key of the processor in the processor key server; when the signature information passes the verification, verify the random number to be measured using the temporary random number; when the random number to be measured passes the verification, save the device reference value.

[0138] Optionally, the client agent module is further configured to, when detecting a normal modification of the running data in the encrypted memory area, regenerate and update the device reference value according to the running data in the encrypted memory area, and sign the updated device reference value using the built-in key of the processor to obtain reference value signature information; send the updated device reference value and the reference value signature information to the service agent module;

[0139] The service agent module is further configured to receive the updated device reference value and the reference value signature information sent by the client agent module; verify the reference value signature information using the root key, and update the pre-stored device reference value using the updated device reference value when the reference value signature information passes the verification.

[0140] Optionally, the client agent module is further configured to receive the communication session key sent by the service agent module and save the communication session key in the encrypted memory area; encrypt the request information using the communication session key to obtain encrypted request information.

[0141] The service agent module is further configured to send the communication session key to the client agent module; decrypt the encrypted request information using the communication session key.

[0142] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, and the computer program is configured to execute the steps in any one of the above communication method embodiments when running.

[0143] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as USB flash drives, read-only memory (ROM), random access memory (RAM), mobile hard disks, magnetic disks, or optical discs.

[0144] An embodiment of the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any one of the above communication method embodiments.

[0145] Another embodiment of the present application also provides a computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any one of the above communication method embodiments.

[0146] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0147] The above has introduced in detail a communication method, a key management system, and a storage medium provided by the present application. Specific examples are used herein to elaborate on the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the present application.

Claims

1. A communication method, characterized in that, Applied to the client agent module, the client agent module is set in the encrypted memory area of the client, and the method includes: When receiving a key management request sent by the client application, generating device verification information by using the running data in the encrypted memory area; Combining the key management request and the device verification information into a request message, and encrypting the request message into an encrypted request message; Sending the encrypted request message to the service agent module in the key server, so that the service agent module decrypts the encrypted request message, verifies the device verification information by using the pre-stored device reference information of the client agent module, and when the device verification information passes the verification, sending the key management request to the key server application of the key server; the service agent module is set in the encrypted memory area of the key server.

2. The communication method according to claim 1, characterized in that The generating device verification information by using the running data in the encrypted memory area includes: Generating a device value to be measured by using the running data in the encrypted memory area; Signing the device value to be measured by using the built-in key of the processor to obtain signature information; Combining the device value to be measured and the signature information into the device verification information, so that the service agent module verifies the signature information by using the root key corresponding to the built-in key of the processor and verifies the device value to be measured by using the pre-stored device reference value of the client agent module.

3. The communication method according to claim 2, wherein Before receiving the key management request sent by the client application, it further includes: When receiving a temporary random number sent by the service agent module, generating the device reference value by using the running data in the encrypted memory area, combining the device reference value and the temporary random number into proof information, and signing the proof information by using the built-in key of the processor to obtain proof signature information; Sending the proof information and the proof signature information to the service agent module, so that the service agent module verifies the proof signature information by using the root key, verifies the temporary random number in the proof information, and saves the device reference value after both the proof signature information and the temporary random number pass the verification.

4. The communication method according to claim 3, wherein After sending the proof information and the proof signature information to the service agent module, it further includes: Receiving the communication session key sent by the service agent module, and saving the communication session key in the encrypted memory area; The encrypting the request message into an encrypted request message includes: Encrypting the request message into an encrypted request message by using the communication session key.

5. A communication method, characterized in that, Applied to the service agent module, the service agent module is set in the encrypted memory area of the key server, and the method includes: When receiving the encrypted request message sent by the client agent module, decrypting the encrypted request message to obtain a key management request and device verification information; the client agent module is set in the encrypted memory area of the client, and the device verification information is generated by the client agent module by using the running data in the encrypted memory area of the client. Verify the device verification information by using the pre-stored device reference information of the client agent module; When the device verification information passes the verification, send the key management request to the key server application program of the key server.

6. The communication method according to claim 5, wherein, The device verification information includes a device value to be measured and signature information. The device value to be measured is generated by the client agent module using the running data in the encrypted memory area of the client. The signature information is obtained by the client agent module signing the device value to be measured using the built-in key of the processor; The verification of the device verification information by using the pre-stored device reference information of the client agent module includes: Verify the signature information by using the root key corresponding to the built-in key of the processor in the processor key server; When the signature information passes the verification, verify the device value to be measured by using the pre-stored device reference value of the client agent module.

7. The communication method according to claim 6, wherein Before receiving the encrypted request information sent by the client agent module, it further includes: Obtain the pre-stored communication information of the client agent module, generate a temporary random number, and send the temporary random number to the client agent module according to the communication information; Receive the proof information and proof signature information sent by the client agent module, and extract the device reference value and the random number to be measured from the proof information; the device reference value is generated by the client agent module using the running data in the encrypted memory area of the client, and the proof signature information is obtained by the client agent module signing the proof information using the built-in key of the processor; Verify the proof signature information by using the root key corresponding to the built-in key of the processor in the processor key server; When the signature information passes the verification, verify the random number to be measured by using the temporary random number; When the random number to be measured passes the verification, save the device reference value.

8. The communication method according to claim 7, wherein After saving the device reference value, it further includes: Send a communication session key to the client agent module; The decryption of the encrypted request information includes: Decrypt the encrypted request information by using the communication session key.

9. A key management system, characterized in that, It includes a client and a key server. The encrypted memory area of the client is provided with a client agent module, and the encrypted memory area of the key server is provided with a service agent module; The client agent module is used to execute the communication method according to any one of claims 1 to 4; The service agent module is used to execute the communication method according to any one of claims 5 to 8.

10. A non-volatile computer-readable storage medium, characterized in that, The non-volatile computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are loaded and executed by a processor, the communication method according to any one of claims 1 to 4 or the communication method according to any one of claims 5 to 8 is implemented.