Password card
By using the PCI-E interface to transmit operation data in the password card, the USB interface transmits sensitive data, and logically isolates information flow, solving the security problem of data transmission in the password card, achieving higher security and efficiency.
Patent Information
- Application Number
- CN202510262505.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-07-11
AI Technical Summary
During the data transmission process, existing password cards have a security risk that private keys are illegally acquired and digital signatures are forged.
The first physical interface (PCI-E interface) is used to transmit operation data, and the second physical interface (USB interface) is used to transmit sensitive data, realizing physical isolation of operation data and sensitive data, and isolating information flows through different logical interfaces.
It effectively avoids the risk of illegal acquisition of private keys and forged digital signatures, and improves the security and data transmission efficiency of password cards.
Smart Images

Figure CN120296807A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a cryptographic card. Background Art
[0002] The cryptographic card has functions such as cryptographic operation, key management, random number generation and verification, access control, and file storage management. Currently, it has been applied to high-end hardware products such as SSL VPN gateways, SVS signature verification servers, timestamp servers, and server cryptographic machines.
[0003] In the related art, as the carrier of the private key, the security of the cryptographic card is crucial. If a security problem occurs, the private key may be illegally obtained and the digital signature may be forged. Therefore, how to achieve the secure transmission of data in the cryptographic card is a technical problem that those skilled in the art urgently need to solve. Summary of the Invention
[0004] The present invention provides a cryptographic card, which transmits operation data through a first physical interface and sensitive data through a second physical interface, realizing the physical isolation of operation data and sensitive data, thereby avoiding the risk of illegal acquisition of private keys and forgery of digital signatures, and effectively improving the security of the cryptographic card.
[0005] The present invention provides a cryptographic card, comprising: A first physical interface and a second physical interface; wherein, the first physical interface is used for transmitting operation data; the second physical interface is used for transmitting sensitive data.
[0006] According to the cryptographic card provided by the present invention, the first physical interface is a PCI-E interface; the second physical interface is a USB interface.
[0007] According to the cryptographic card provided by the present invention, an operation data input logic interface and an operation data output logic interface are configured on the first physical interface; a sensitive data input logic interface and a sensitive data output logic interface are configured on the second physical interface.
[0008] According to the cryptographic card provided by the present invention, a control input logic interface, a control output logic interface, and a status output logic interface are further configured on the second physical interface.
[0009] According to the cryptographic card provided by the present invention, the cryptographic card further comprises: A third physical interface; the third physical interface is a USB interface; the third physical interface is used for the combination of the cryptographic card and the cryptographic key hardware to realize user identity authentication.
[0010] According to the cryptographic card provided by the present invention, the cryptographic card further comprises: A fourth physical interface; a control input logic interface is configured on the fourth physical interface for implementing the destruction of a secret key.
[0011] A cryptographic card provided by the present invention further includes: A fifth physical interface; a status output logic interface is configured on the fifth physical interface for outputting the status information of the cryptographic card.
[0012] The present invention also provides a data transmission method, including: Transmitting arithmetic data based on a first physical interface; Transmitting sensitive data based on a second physical interface.
[0013] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the above data transmission method is implemented.
[0014] The present invention also provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above data transmission method is implemented.
[0015] The cryptographic card provided by the present invention transmits arithmetic data through a first physical interface and transmits sensitive data through a second physical interface, realizing the physical isolation of arithmetic data and sensitive data, thereby avoiding the risk of illegal acquisition of private keys and forgery of digital signatures, and effectively improving the security of the cryptographic card. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0017] Figure 1 is one of the schematic diagrams of the cryptographic card provided by the present invention.
[0018] Figure 2 is another schematic diagram of the cryptographic card provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention with reference to the drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.
[0020] The following will describe the cryptographic card of the present invention in conjunction with Figure 1 - Figure 2 Describe the cryptographic card of the present invention.
[0021] Figure 1 is a schematic diagram of the cryptographic card provided by the present invention, as Figure 1 shown, the cryptographic card includes: A first physical interface and a second physical interface; wherein, the first physical interface is used to transmit arithmetic data; the second physical interface is used to transmit sensitive data.
[0022] Specifically, the cryptographic card in the embodiment of the present application includes a first physical interface and a second physical interface; wherein, the first physical interface is used to transmit arithmetic data; the second physical interface is used to transmit sensitive data, thereby realizing physical isolation of arithmetic data and sensitive data, and effectively avoiding the risk of private keys being illegally obtained and digital signatures being forged, improving the security of the cryptographic card. Optionally, the arithmetic data is the original data, such as personal information, etc. The sensitive data is the data related to the key. Optionally, after realizing physical isolation transmission of arithmetic data and sensitive data, data can then be processed by the processor in the cryptographic card, which is not elaborated in the embodiment of the present application.
[0023] In the cryptographic card of the above embodiment, arithmetic data is transmitted through the first physical interface, and sensitive data is transmitted through the second physical interface, realizing physical isolation of arithmetic data and sensitive data, thereby avoiding the risk of private keys being illegally obtained and digital signatures being forged, and effectively improving the security of the cryptographic card.
[0024] In one embodiment, the first physical interface is a PCI-E interface; the second physical interface is a USB interface.
[0025] Specifically, the amount of arithmetic data is relatively large. In the embodiment of the present application, the first physical interface of the cryptographic card is a PCI-E interface, so as to make full use of the high data transmission efficiency of the PCI-E interface and realize fast and accurate transmission of arithmetic data. Optionally, the amount of sensitive data is not large, but the security requirement is relatively high. In the embodiment of the present application, the second physical interface of the cryptographic card is a USB interface, so as to realize secure transmission of sensitive data. That is, in the embodiment of the present application, based on the characteristics of different data types, different physical interfaces are used for data transmission, which can not only realize physical isolation of arithmetic data and sensitive data, but also effectively improve the security and efficiency of data transmission.
[0026] In the password card of the above embodiment, the first physical interface is a PCI-E interface; the second physical interface is a USB interface. That is, based on the characteristics of different data types, different physical interfaces are used for data transmission, which can not only achieve physical isolation of computing data and sensitive data, but also effectively improve the security and efficiency of data transmission.
[0027] In one embodiment, an arithmetic data input logic interface and an arithmetic data output logic interface are configured on the first physical interface; a sensitive data input logic interface and a sensitive data output logic interface are configured on the second physical interface.
[0028] Specifically, in the embodiment of the present application, an arithmetic data input logic interface and an arithmetic data output logic interface are configured on the first physical interface, that is, the arithmetic data input logic interface and the arithmetic data output logic interface are mapped to the PCI-E interface; a sensitive data input logic interface and a sensitive data output logic interface are configured on the second physical interface, that is, the sensitive data input logic interface and the sensitive data output logic interface are mapped to the USB interface, realizing logical isolation of information flows of different types of interfaces and effectively improving the security of the password card. Optionally, the arithmetic data input logic interface is used for the PC to input arithmetic data to the password card; the arithmetic data output logic interface is used for the password card to output arithmetic data to the PC. Optionally, the sensitive data input logic interface is used for the PC to input sensitive data to the password card; the sensitive data output logic interface is used for the password card to output sensitive data to the PC. Optionally, the arithmetic data is the original data, such as personal information, etc. The sensitive data is the data related to the key.
[0029] In the password card of the above embodiment, an arithmetic data input logic interface and an arithmetic data output logic interface are configured on the first physical interface, and a sensitive data input logic interface and a sensitive data output logic interface are configured on the second physical interface, realizing logical isolation of information flows of different types of interfaces and effectively improving the security of the password card.
[0030] In one embodiment, a control input logic interface, a control output logic interface, and a status output logic interface are further configured on the second physical interface.
[0031] Specifically, in the embodiment of the present application, a control input logic interface, a control output logic interface, and a status output logic interface are further configured on the second physical interface, thus realizing multiplexing of the second physical interface, so that not only sensitive data but also control data and status data of the password card can be transmitted through the second physical interface, realizing logical isolation of information flows of different types of interfaces and effectively improving the performance of the password card. Optionally, the control data includes instructions such as key encryption and key derivation.
[0032] In the password card of the above embodiments, a control input logic interface, a control output logic interface, and a status output logic interface are further configured on the second physical interface, so that not only sensitive data but also control data and the status data of the password card can be transmitted through the second physical interface, realizing the multiplexing of the second physical interface, and enabling the information flows of different types of interfaces to be logically isolated from each other, effectively improving the performance of the password card.
[0033] In one embodiment, the password card further includes: A third physical interface; the third physical interface is a USB interface; the third physical interface is used for the combination of the password card and the password key hardware to implement user identity authentication.
[0034] Specifically, the password card in the embodiments of the present application further includes a third physical interface. Optionally, the third physical interface is a USB interface to implement the combination of the password card and the intelligent password key hardware entity and realize the user identity authentication function. Optionally, the third physical interface follows the USB Mass storage protocol.
[0035] In the password card of the above embodiments, the combination of the password card and the password key hardware is realized through the third physical interface to implement user identity authentication, thereby effectively improving the security of the password card and avoiding the risks of illegal acquisition of private keys and forgery of digital signatures.
[0036] In one embodiment, the password card further includes: A fourth physical interface; a control input logic interface is configured on the fourth physical interface for implementing the destruction of keys.
[0037] Specifically, in the embodiments of the present application, the password card further includes a fourth physical interface. Optionally, a control input logic interface is configured on the fourth physical interface to perform the destruction of keys according to the instructions input by the user, thereby effectively improving the security of the password card.
[0038] In the password card of the above embodiments, the keys can be actively destroyed through the fourth physical interface, effectively improving the security of the password card.
[0039] In one embodiment, the password card further includes: A fifth physical interface; a status output logic interface is configured on the fifth physical interface for outputting the status information of the password card.
[0040] Specifically, the password card in the embodiments of the present application further includes a fifth physical interface.
[0041] Specifically, the password card in the embodiments of the present application further includes a fifth physical interface. Optionally, a status output logic interface is configured on the fifth physical interface to output the status information of the password card in real time, so that the user can intuitively and quickly obtain the status information of the current password card, effectively improving the security of the password card.
[0042] That is, the present application provides a security-enhanced password card, which realizes the isolation of algorithm operation input / output data and sensitive input / output data through physical interfaces, the isolation of algorithm operation input data and algorithm operation output data through logic interfaces, the isolation of sensitive input data and sensitive output data through logic interfaces, and the isolation of control input data, control output data, and status output data through logic interfaces, effectively improving the security of the password card.
[0043] In the password card of the above embodiment, the status information of the password card can be intuitively and quickly displayed to the user through the fifth physical interface, effectively improving the security of the password card.
[0044] Exemplarily, the password card in the embodiments of the present application is as Figure 2 shown and includes: (1) Password card physical interface (1) The first physical interface (PCI-E interface). The password card is connected to the PC through the PCI-E interface, which complies with the PCI-E v2.0 specification and is implemented by the PCI-E interface module of the password coprocessor chip.
[0045] (2) The second physical interface (USB-1 interface). The password card is connected to the PC through the USB-1 interface to implement a trusted channel. The USB-1 interface complies with the USB 2.0 protocol specification and is implemented by the USB interface module of the security chip.
[0046] (3) The third physical interface (USB-2 interface). Through the USB-2 interface, the password card realizes the combination with the intelligent password key hardware entity to implement the user identity authentication function. The USB-2 interface follows the USB Mass storage protocol.
[0047] (4) The fourth physical interface (key destruction interface). The emergency destruction function is realized by the password card button method. In the powered-on state, if the button is detected to be pressed, the password coprocessor chip and the security chip start the self-destruction program to destroy the device key, user key, key encryption key, session key, backup key, private key access control code hash value, and registered identity authentication data inside the password card, and the device returns to the initial state.
[0048] (5) The fifth physical interface (status indicator interface). The status indicator interface includes two operation status indicators for the cryptographic cards and one access status indicator for the intelligent cryptographic key. The two operation status indicators are the power indicator and the power-on self-test indicator respectively. After the cryptographic card is powered on, if the power supply is normal, the power indicator (red light) is on; after the power-on self-test is completed and passed, the power-on self-test indicator (green light) is on. In the powered-on state of the cryptographic card, when the intelligent cryptographic key is connected to the USB-2 interface of the cryptographic card, the green light of the access status indicator for the intelligent cryptographic key is on, otherwise the yellow light is on.
[0049] (2) The logical interfaces of the cryptographic card The logical interfaces supported by the cryptographic card include: the operation data input logical interface, the operation data output logical interface, the sensitive data input logical interface, the sensitive data output logical interface, the control input logical interface, the control output logical interface, and the status output logical interface.
[0050] (3) The information flows of different types of interfaces are logically isolated from each other (1) The operation data input logical interface is mapped to the PCI-E interface; (2) The operation data output logical interface is mapped to the PCI-E interface; (3) The sensitive data input logical interface is mapped to the trusted channel USB-1 interface; (4) The sensitive data output logical interface is mapped to the trusted channel USB-1 interface; (5) The control input logical interface is mapped to the trusted channel USB-1 interface and the key destruction button interface; (6) The control output logical interface is mapped to the trusted channel USB-1 interface; the status output logical interface is mapped to the trusted channel USB-1 interface and the status indicator.
[0051] (7) The device is powered through the PCI-E interface.
[0052] The operation data input, operation data output, and power supply interfaces of the cryptographic card share the PCI-E interface. PETp0~15 and PETn0~15 in the pins of the PCI-E interface of the cryptographic card are the operation data input interfaces; PERp0~15 and PERn0~15 are the operation data output interfaces; +12V and GND are the power supply interfaces.
[0053] The sensitive data input, sensitive data output, control input, control output, and status output interfaces of the cryptographic card share the USB-1 interface. DP and DM in the pins of the trusted channel USB-1 interface of the cryptographic card are the sensitive data input and output interfaces. The key destruction button is an independent control input interface. The status indicator is an independent status output interface.
[0054] The operation data input interface and the sensitive data input interface are isolated through a physical interface. The sensitive data input and the control input interface are separated through a logical path.
[0055] Each type of data input and control input consists of different commands and is encapsulated into different input command messages. The input command structure of the password card is shown in Table 1, and the input commands are distinguished by command codes (TAG1 and TAG2).
[0056] The control input interface transmits control commands, such as: generating key pairs, algorithm self-check, integrity self-check, creating files, deleting files, restoring factory settings, etc. The data input interface transmits data input commands, such as: setting the private key access control code, writing data files, and password operation commands, etc.
[0057] Table 1 Password Card Input Command Structure
[0058] The command codes TAG1 and TAG2 represent data types: C0C0 indicates that the input is algorithm data, C0A1 indicates that the input is sensitive data, and C0F1 indicates that the input is control data. The command codes TAG3 and TAG4 represent sub-commands: A0A0 indicates generating user key pairs, A0A1 indicates SM2 signature, and A0A2 indicates SM2 signature verification. Lc represents the length of the input data. DATA represents the input data.
[0059] The operation data output interface and the sensitive data output interface are isolated through a physical interface. The sensitive data output, control output, and status output interfaces are separated through a logical path. Different inputs correspond to different outputs. For each input, there will be an output status indicating whether the command is executed correctly. For those with data output, the data will follow immediately after the status indication.
[0060] The output response structure of the password card is shown in Table 2. The status word in the output response structure represents the output status; the content after the status word is the output data.
[0061] Table 2
[0062] The command codes TAG1 and TAG2 represent data types: C0C0 indicates that the output is algorithm data, and C0A1 indicates that the output is sensitive data. The command codes TAG3 and TAG4 represent sub-commands: A0A0 indicates generating user key pairs, A0A1 indicates internal key SM2 signature, and A0A2 indicates internal key SM2 signature verification. Le represents the length of the input / output data. DATA represents the output data. The status code (SW1, SW2): The successful status code is 0x9000.
[0063] Different inputs correspond to different outputs. For each input, there will be an output status indicating whether the command is executed correctly. For those with data output, the data will follow immediately after the status indication. The status word in the output response structure of the password card represents the output status; the content following the status word is the output data.
[0064] (4) Data Input Interface The data input interfaces of the password card include the PCI-E interface and the trusted channel USB-1 interface. Data such as the original text / ciphertext of the data to be computed and the external public key plaintext are input through the PCI-E interface, and the rest of the sensitive data information is input through the trusted channel USB-1 interface. The command input data transmitted through the data bus of the trusted channel USB-1 interface is shown in the following table: Table 3
[0065] The command input data transmitted through the data bus of the PCI-E interface is shown in the following table: Table 4
[0066] (5) Data Output Interface The data output interfaces of the password card include the trusted channel USB-1 interface and the PCI-E interface. When the host application can send password operation commands to the device through the data bus of the PCI-E interface, the internal firmware of the device interprets and processes the input commands and data, and after completion, returns the command response and the data to be output to the host application through the data bus of the PCI-E interface.
[0067] When the host application can send management commands and others to the device through the data bus of the trusted channel USB-1 interface, the internal firmware of the device interprets and processes the input commands and data, and after completion, returns the command response and the data to be output to the host application through the data bus of the trusted channel USB-1 interface.
[0068] The output data is filled in the data field of the response structure. The output data of the password module is shown in the following table.
[0069] Table 5
[0070] Table 6
[0071] The cryptographic card in the embodiment of the present application has operation data input, operation data output, sensitive data input, sensitive data output, control input, control output, status output, and power supply interface. The operation data communicates through the PCI-E interface, and the sensitive data, control data, and status data communicate through the trusted channel USB-1 interface. Through physical isolation and logical isolation, the security of the cryptographic card can be effectively improved.
[0072] Exemplarily, the present application also provides a data transmission method in the implementation, including: Transmitting operation data based on a first physical interface; Transmitting sensitive data based on a second physical interface.
[0073] Specifically, in the embodiment of the present application, the operation data is transmitted based on the first physical interface, and the sensitive data is transmitted based on the second physical interface, thereby realizing physical isolation of the operation data and the sensitive data, effectively avoiding the risk of the private key being illegally obtained and the digital signature being forged, and improving the security of the cryptographic card. Optionally, the operation data is the original data, such as personal information, etc. The sensitive data is the data related to the key.
[0074] That is, the operation data communicates through the PCI-E interface, and the sensitive data, control data, and status data communicate through the trusted channel USB-1 interface. Optionally, services related to non-cryptographic device applications of the cryptographic card (sensitive data related) are all transmitted through the trusted channel USB-1 interface. Before a registered user of the cryptographic card performs a login and management operation, a trusted channel between the host computer and the cryptographic card needs to be established at the cryptographic card management interface (USB-1 interface). The intelligent cryptographic key is used as the initiator, and the cryptographic card is used as the responder. Through the SM2 key negotiation algorithm, a message key is shared to establish a trusted channel. After the trusted channel is successfully established, identity authentication is realized through the trusted channel. Identity authentication uses the intelligent cryptographic key to implement identity authentication using digital signature technology, and uses the username + password to implement identity authentication using symmetric encryption algorithms. During the identity authentication process, the SM2, SM3, and SM4 cryptographic algorithms and random numbers are used to ensure the security of the authentication process. After the identity verification is passed, the current status is set according to the role corresponding to the identity registration.
[0075] The method of the above embodiment transmits the operation data through the first physical interface and the sensitive data through the second physical interface, realizing physical isolation of the operation data and the sensitive data, and thus can avoid the risk of the private key being illegally obtained and the digital signature being forged, effectively improving the security of the cryptographic card.
[0076] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the data transmission method provided by each of the above methods, and the method includes: transmitting arithmetic data based on a first physical interface; transmitting sensitive data based on a second physical interface.
[0077] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the data transmission method provided by each of the above methods, and the method includes: transmitting arithmetic data based on a first physical interface; transmitting sensitive data based on a second physical interface.
[0078] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0079] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0080] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in each of the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of each embodiment of the present invention.
Claims
1. A cryptographic card, characterized in that, Comprising: A first physical interface and a second physical interface; wherein, the first physical interface is used for transmitting operation data; The second physical interface is used for transmitting sensitive data.
2. The cryptographic card according to claim 1, wherein The first physical interface is a PCI-E interface; the second physical interface is a USB interface.
3. The password card according to claim 1, characterized in that, An operation data input logic interface and an operation data output logic interface are configured on the first physical interface; a sensitive data input logic interface and a sensitive data output logic interface are configured on the second physical interface.
4. The password card according to claim 3, characterized in that, A control input logic interface, a control output logic interface and a status output logic interface are further configured on the second physical interface.
5. The password card according to any one of claims 1 to 3, characterized in that, The cryptographic card further comprises: A third physical interface; the third physical interface is a USB interface; the third physical interface is used for the combination of the cryptographic card and the cryptographic key hardware to implement user identity authentication.
6. The cryptographic card according to any one of claims 1-3, characterized in that, The cryptographic card further comprises: A fourth physical interface; a control input logic interface is configured on the fourth physical interface to implement the destruction of keys.
7. The password card according to any one of claims 1-3, characterized in that, The cryptographic card further comprises: A fifth physical interface; a status output logic interface is configured on the fifth physical interface to output the status information of the cryptographic card.
8. A data transmission method is applied to the cryptographic card according to any one of claims 1-7, characterized in that, Comprising: Transmitting operation data based on the first physical interface; Transmitting sensitive data based on the second physical interface.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the data transmission method as claimed in claim 8.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the data transmission method as claimed in claim 8.