Secret key calling updating and quantity display method based on USB interface and related equipment
Through the update and quantity display method of the secret key call based on the USB interface, the number and proportion of the secret keys are displayed in real time, which solves the problem of unclear use of the secret key and realizes reasonable update of the secret key management.
Patent Information
- Application Number
- CN202510342122.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-08-01
AI Technical Summary
In the prior art, the usage of the key is unclear, resulting in the problem of untimely or premature update of the key.
Through the update and quantity display method of the secret key call based on the USB interface, the key management module and the secret key storage module can be used to judge the secret key call or update in real time, display the number and proportion of the target key, and display it through the display screen.
Users can quickly and accurately understand the usage of secret keys, avoid the problem of untimely or premature updates, and ensure the reasonable management of the number of secret keys in the key storage module.
Smart Images

Figure CN120407047A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of data processing, and particularly relates to a method for calling, updating and displaying the quantity of keys based on a USB interface and related devices. Background Art
[0002] With the development of encryption technology, in order to ensure the security of data during transmission, data is encrypted. The process of encrypting and decrypting data consumes keys, so it is necessary to update the stored keys regularly. However, due to the consumption or regular update of the stored keys, there is a problem that the usage situation of the keys is not clear, which may lead to the problem of not being able to update the keys in time or updating the keys prematurely.
[0003] In view of this, how to quickly and accurately understand the usage situation of keys has become a technical problem to be solved urgently. Summary of the Invention
[0004] In view of this, an object of the present disclosure is to provide a method for calling, updating and displaying the quantity of keys based on a USB interface and related devices to solve or partially solve the above technical problems.
[0005] Based on the above object, a first aspect of the present disclosure provides a method for calling, updating and displaying the quantity of keys based on a USB interface, which is applied to a device for calling, updating and displaying the quantity of keys based on a USB interface; the device includes: a key management module and a key storage module; the method includes:
[0006] The key management module determines whether there is a call or update to the keys in the key storage module;
[0007] In response to determining that there is a call or update to the keys in the key storage module, the key management module determines a target key ratio according to the target key quantity at the current moment and the maximum key quantity, and displays the target key quantity and the target key ratio.
[0008] Based on the same inventive concept, a second aspect of the present disclosure provides a device for calling, updating and displaying the quantity of keys based on a USB interface, the device includes: a key management module and a key storage module; the key management module is electrically connected to the key storage module;
[0009] The key management module is specifically configured to:
[0010] Determine whether there is a call or update to the keys in the key storage module;
[0011] In response to determining that there is a call or update to the secret key in the secret key storage module, determine the target secret key ratio according to the target secret key quantity and the maximum secret key quantity at the current moment, and display the target secret key quantity and the target secret key ratio.
[0012] Based on the same inventive concept, a third aspect of the present disclosure provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable by the processor. When the processor executes the computer program, the above-described method is implemented.
[0013] Based on the same inventive concept, a fourth aspect of the present disclosure provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the above-described method.
[0014] As can be seen from the above, the present disclosure provides a method and related devices for secret key call update and quantity display based on a USB interface. The method for secret key call update and quantity display based on a USB interface is applied to a device for secret key call update and quantity display based on a USB interface, which includes a secret key management module and a secret key storage module. The secret key management module determines whether there is a call or update to the secret key in the secret key storage module. When there is a call or update to the secret key in the secret key storage module, the secret key management module determines the target secret key ratio according to the target secret key quantity and the maximum secret key quantity at the current moment, and displays the target secret key quantity and the target secret key ratio. In this way, the target secret key ratio can be accurately determined according to the target secret key quantity and the maximum secret key quantity. By displaying the target secret key quantity and the target secret key ratio, it is convenient for the user to quickly and clearly understand the quantity and proportion of the secret keys that can be used at the current moment, avoiding the problem that the user is unclear about the usage situation of the secret keys. At the same time, it is convenient for the user to judge whether it is necessary to update the secret keys according to the usage situation of the secret keys, avoiding the problems of premature secret key update or untimely secret key update. Description of the Drawings
[0015] In order to more clearly illustrate the technical solutions in the present disclosure or related technologies, the following will briefly introduce the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings in the following description are only embodiments of the present disclosure. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1 It is a flowchart of the method for secret key call update and quantity display based on a USB interface according to an embodiment of the present disclosure;
[0017] Figure 2Schematic diagram of the key storage and management device according to an embodiment of the present disclosure;
[0018] Figure 3 Flowchart of the key invocation method according to an embodiment of the present disclosure;
[0019] Figure 4 Flowchart of the key update method according to an embodiment of the present disclosure;
[0020] Figure 5 Schematic diagram of the key invocation, update and quantity display device based on the USB interface according to an embodiment of the present disclosure;
[0021] Figure 6 Schematic diagram of the electronic device according to an embodiment of the present disclosure. Detailed implementation manners
[0022] To make the objectives, technical solutions and advantages of the present disclosure clearer and more understandable, the present disclosure will be further described in detail below with reference to specific embodiments and the accompanying drawings.
[0023] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should have the ordinary meanings understood by those of ordinary skill in the art to which the present disclosure belongs. The "first", "second" and similar terms used in the embodiments of the present disclosure do not denote any order, quantity or importance, but are only used to distinguish different components. The terms such as "including" or "comprising" mean that the elements or objects appearing before this term cover the elements or objects listed after this term and their equivalents, without excluding other elements or objects. The terms such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The terms such as "upper", "lower", "left" and "right" are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.
[0024] Based on the description of the background art, with the development and improvement of encryption technology, encryption technology is required in the data processing and transmission processes. Currently, in the encryption calculation process, the keys issued by professional cryptographic institutions are used, and in combination with encryption / decryption algorithms, the encryption and decryption functions of data or communications are realized. In the above process, whether it is a symmetric key or an asymmetric key, each encryption process will consume at least one pair of keys. Therefore, it is necessary to update the keys regularly. However, with regular updates, it is impossible to know the consumption situation of the current key pair. Therefore, it may result in a shortage of keys during the encryption process, or the situation of key updates when the keys are sufficient.
[0025] As described above, how to quickly and accurately understand the key usage situation has become an important research issue.
[0026] Based on the above description, as Figure 1 shown, the method for key invocation update and quantity display based on a USB interface proposed in this embodiment is applied to a device for key invocation update and quantity display based on a USB interface; the device includes: a key management module and a key storage module; the method includes:
[0027] Step 101, the key management module determines whether there is a key invocation or update in the key storage module.
[0028] In specific implementation, the device for key invocation update and quantity display based on a USB interface further includes a display screen. The display screen is used to display the available key quantity, the maximum key quantity, and the available key ratio. Among them, the available key quantity is the number of keys stored in the key storage module that can be used to encrypt and decrypt data, the maximum key quantity is the maximum number of keys that can be stored in the key storage module, and the available key ratio is the ratio between the available key quantity and the maximum key quantity.
[0029] Before there is a key invocation or update in the key storage module, the display screen displays the current key quantity, the maximum key quantity, and the current key ratio. Among them, the current key quantity is the available key quantity in the key storage module before the change of the key quantity, and the current key ratio is the ratio between the current key quantity and the maximum key quantity.
[0030] In order to display the available key quantity and the available key ratio in the key storage module in real time, the key management module determines whether there is a key invocation or update in the key storage module, so as to determine whether the key quantity in the key storage module has changed. Specifically, the key management module determines whether the key quantity in the key storage module has changed by judging whether there is a key invocation or a key update in the key storage module. Or, the key management module obtains the key quantity in the key storage module in real time, and judges whether the key quantity in the key storage module has changed according to the historical key quantity at the previous moment and the target key quantity at the current moment.
[0031] Step 102, in response to determining that there is a key invocation or update in the key storage module, the key management module determines a target key ratio according to the target key quantity at the current moment and the maximum key quantity, and displays the target key quantity and the target key ratio.
[0032] In specific implementation, when the key in the key storage module is called or updated, it is determined that the number of keys in the key storage module has changed. In order to display the available key number and available key ratio in the key storage module in real time, the key management module uses the ratio of the target key number to the maximum key number as the target key ratio, and displays the updated target key number and target key ratio through the display screen.
[0033] For example, before the key in the key storage module is called or updated, the display screen shows that the current key number is 60, the maximum key number is 100, and the current key ratio is 60%. When the key number in the key storage module changes to 85, the updated target key number is 85, the maximum key number is 100, and the target key ratio is 85% are displayed through the display screen.
[0034] Through the above embodiments, the key call update and quantity display method based on the USB interface is applied to the key call update and quantity display device based on the USB interface. The key call update and quantity display device based on the USB interface includes: a key management module and a key storage module. The key management module determines whether the key in the key storage module is called or updated. When the key in the key storage module is called or updated, the key management module determines the target key ratio according to the target key number and the maximum key number at the current moment, and displays the target key number and the target key ratio. In this way, the target key ratio can be accurately determined according to the target key number and the maximum key number. By displaying the target key number and the target key ratio, it is convenient for the user to quickly and clearly understand the number of keys that can be used at the current moment and the proportion, avoiding the problem that the user is not clear about the key usage situation. At the same time, it is convenient for the user to judge whether the key needs to be updated according to the key usage situation, avoiding the problems of premature key update or untimely key update.
[0035] In some embodiments, the method further includes:
[0036] Step 103, the key management module compares and processes the target key number with a preset quantity threshold.
[0037] Step 104, in response to determining that the target key number is less than the preset quantity threshold, the key management module displays a prompt message indicating that the key quantity is too small.
[0038] In specific implementation, in order to facilitate the user to quickly and accurately understand whether the key stored in the key storage module needs to be updated, when the number of available keys stored in the key storage module is too small, a prompt message indicating that the key quantity is too small is displayed through the display screen, facilitating the user to update the key stored in the key storage module in time after receiving the prompt message indicating that the key quantity is too small.
[0039] Specifically, the key management module compares the number of target keys with a preset number threshold. When the number of target keys is less than the preset number threshold, a prompt message indicating that the number of keys is too small is displayed on the display screen. For example, the preset number threshold is 20. When the number of target keys is 19, a prompt message indicating that the number of keys is too small is displayed on the display screen, facilitating the user to understand the key usage situation and timely update the keys stored in the key storage module.
[0040] In addition, the method further includes:
[0041] Step 105, the key management module compares the target key ratio with a preset ratio threshold.
[0042] Step 106, in response to determining that the target key ratio is less than the preset ratio threshold, the key management module displays a prompt message indicating that the number of keys is too small.
[0043] Specifically, the key management module compares the target key ratio with a preset ratio threshold. When the target key ratio is less than the preset ratio threshold, a prompt message indicating that the number of keys is too small is displayed on the display screen. For example, the preset ratio threshold is 20%. When the target key ratio is 19%, a prompt message indicating that the number of keys is too small is displayed on the display screen, facilitating the user to understand the key usage situation and timely update the keys stored in the key storage module.
[0044] Through the above solution, when the number of target keys is less than the preset number threshold, it can be accurately determined that the number of available keys in the key storage module is too small. The key management module displays a prompt message indicating that the number of keys is too small, facilitating the user to timely update the keys stored in the key storage module after receiving the prompt message, and avoiding the situation where the keys stored in the key storage module are exhausted and the keys cannot be called.
[0045] In some embodiments, the key management module includes a key invocation unit and a key update unit; Step 102 includes:
[0046] Step 1021, in response to determining that the key invocation unit receives a key invocation request, the key invocation unit invokes a key from the key storage module, and then determines that there is a key invocation in the key storage module.
[0047] In specific implementation, when the key invocation unit receives a key invocation request, the key invocation unit invokes a key from the key storage module, and the number of available keys in the key storage module decreases. When there is a key invocation in the key storage module, it can accurately determine that the number of keys in the key storage module has changed. Specifically, each time the key invocation unit completes a key invocation from the key storage module, the number of available keys in the key storage module decreases by one pair.
[0048] For example, the current number of keys displayed by the key management module through the display screen is 60, the maximum number of keys is 100, and the current key ratio is 60%. When the key invocation unit receives a key invocation request and the key invocation unit invokes a key from the key storage module, it is determined that there is a key invocation in the key storage module, and the number of keys and the key ratio displayed on the display screen are updated. Specifically, when the key invocation unit completes a key invocation from the key storage module, the updated target number of keys displayed through the display screen is 59, the maximum number of keys is 100, and the target key ratio is 59%.
[0049] Or, in step 1022, in response to determining that the key update unit has received a key update request, the key update unit saves the obtained updated key to the key storage module, and then determines that there is a key update in the key storage module.
[0050] In specific implementation, when the key update unit receives a key update request, the key update unit saves the obtained updated key to the key storage module, and the number of available keys in the key storage module increases. When there is a key update in the key storage module, it can accurately determine that the number of keys in the key storage module has changed. Specifically, when the key update unit saves a preset number of updated keys to the key storage module, the number of available keys in the key storage module increases by the preset number.
[0051] For example, the current number of keys displayed by the key management module through the display screen is 60, the maximum number of keys is 100, and the current key ratio is 60%. When the key update unit receives a key update request and the key update unit saves the obtained updated key to the key storage module, it is determined that there is a key update in the key storage module, and the number of keys and the key ratio displayed on the display screen are updated. Specifically, when the key update unit saves 20 pairs of keys obtained to the key storage module, the updated target number of keys displayed through the display screen is 80, the maximum number of keys is 100, and the target key ratio is 80%.
[0052] Through the above solution, when the key invocation unit receives a key invocation request, the key invocation unit invokes a key from the key storage module, and the number of available keys in the key storage module decreases, so that it can accurately determine that a key in the key storage module has been invoked. When the key update unit receives a key update request, the key update unit saves the obtained updated key to the key storage module, and the number of available keys in the key storage module increases, so that it can accurately determine that a key in the key storage module has been updated.
[0053] In some embodiments, the USB interface-based key invocation update and quantity display device is provided with a USB interface; the pluggable USB interface-based key invocation update and quantity display device is connected to the data encryption device in an inserted manner by using the USB interface; step 1021 includes:
[0054] Step 10211, the key invocation unit receives a key invocation request sent by the data encryption device and sends a response data frame to the data encryption device; wherein, the response data frame includes permission invocation information or prohibition invocation information.
[0055] Step 10212, the key invocation unit receives a function request generated by the data encryption device based on the permission invocation information and sends a first key response frame to the data encryption device; wherein, the first key response frame includes a first key.
[0056] Step 10213, the key invocation unit receives a first key invocation success message sent by the data encryption device and determines that a key in the key storage module has been invoked based on the first key invocation success message.
[0057] In specific implementation, the key storage module of the USB interface-based key invocation update and quantity display device stores keys, and the key management module can invoke keys, update keys and display the key quantity in real time. The data encryption device is used to encrypt data by using the invoked key and the encryption algorithm. Before encrypting the data, the data encryption device needs to invoke a key from the key storage module of the USB interface-based key invocation update and quantity display device.
[0058] The USB interface-based key invocation update and quantity display device is a pluggable device. The USB interface-based key invocation update and quantity display device is provided with a Universal Serial Bus (USB) interface. The USB interface-based key invocation update and quantity display device can be connected to a data encryption device or a key distribution device respectively in an insertion manner by using the USB interface, so as to realize key invocation or key update. In this way, by splitting data encryption and key update out of the USB interface-based key invocation update and quantity display device, it is convenient to use the USB interface-based key invocation update and quantity display device. When the data encryption device needs to encrypt data, the USB interface-based key invocation update and quantity display device is inserted into the data encryption device through the USB interface, and the data encryption device invokes the key from the key storage module of the USB interface-based key invocation update and quantity display device through the USB interface. When the key storage module of the USB interface-based key invocation update and quantity display device needs to update the key, the USB interface-based key invocation update and quantity display device is inserted into the key distribution device through the USB interface, and the key distribution device distributes the updated key to the key storage module of the USB interface-based key invocation update and quantity display device through the USB interface.
[0059] Specifically, the process by which the data encryption device calls the key from the USB interface-based key call update and quantity display device includes: inserting the USB interface-based key call update and quantity display device into the data encryption device through the USB interface in an insertion manner, and realizing key call between the USB interface-based key call update and quantity display device and the data encryption device through the USB interface. The data encryption device sends a key call request, Request0, to the USB interface-based key call update and quantity display device. After receiving the key call request, the key call unit returns an acknowledgement data frame, Response0. Among them, an acknowledgement data frame of 01 indicates permission to call information, and an acknowledgement data frame of 00 indicates prohibition of call information. When the data encryption device receives the acknowledgement data frame Response0, if the acknowledgement data frame is 01, it sends a function request Request1 that is needed for the call to the key call unit; if the acknowledgement data frame is 00, it does not send a function request. According to the function request Request1, the key call unit calls the corresponding key in the key storage module and returns a first key acknowledgement frame Response1 to the data encryption device. The first key acknowledgement frame Response1 contains the first key for the corresponding function. After receiving the first key acknowledgement frame Response1, the data encryption device encrypts the data with the first key. After successful encryption, it sends a first key call success message Final0 to the key call unit to complete the call of the first key. Since the call of the first key is completed, the key management unit determines that there is a call of the key in the key storage module based on the first key call success message Final0. The key management unit counts the keys in the key storage module to obtain the target key quantity, determines the target key ratio according to the target key quantity and the maximum key quantity, and displays the target key quantity and the target key ratio through a display screen.
[0060] Through the above solution, the USB interface-based key call update and quantity display device is connected to the data encryption device through the USB interface in an insertion manner, facilitating the data encryption device to call the key from the key storage module of the key quantity information device. When the key call unit receives the key call request sent by the data encryption device, it sends an acknowledgement data frame to the data encryption device so that the data encryption device can determine whether to allow the key call according to the acknowledgement data frame. When the key call unit receives the function request sent by the data encryption device, it sends a first key acknowledgement frame containing the first key to the data encryption device, thereby realizing the call of the first key. The key call unit receives the first key call success message sent by the data encryption device, thereby determining that the call of the first key is completed, and further determining that there is a call of the key in the key storage module.
[0061] In some embodiments, after step 10212, it further includes:
[0062] Step 10212A, the key invocation unit receives the first key invocation failure message sent by the data encryption device, and sends a second key response frame to the data encryption device; wherein, the second key response frame includes a second key.
[0063] Step 10212B, the key invocation unit receives the second key invocation success message sent by the data encryption device, and determines that there is a key invocation in the key storage module based on the second key invocation success message.
[0064] In specific implementation, the data encryption device receives the first key response frame Response1, encrypts the data using the first key, and sends the first key invocation failure message Final1 to the key invocation unit after successful encryption. The key invocation unit receives the first key invocation failure message Final1, and sends a new second key response frame Response2 to the data encryption device. The second key response frame Response2 contains a new second key.
[0065] After the second key invocation is completed, the key management unit determines that there is a key invocation in the key storage module based on the second key invocation success message Final0. The key management unit counts the keys in the key storage module to obtain the target key quantity, determines the target key ratio according to the target key quantity and the maximum key quantity, and displays the target key quantity and the target key ratio through a display screen.
[0066] Through the above solution, when the key invocation unit receives the first key invocation failure message sent by the data encryption device, it can accurately determine that the data encryption device fails to encrypt the data using the first key. To ensure that the data encryption device can encrypt the data, the key invocation unit sends a second key response frame containing the second key to the data encryption device, so that the data encryption device can encrypt the data using the second key.
[0067] In some embodiments, after step 10212, it further includes:
[0068] Step 10212a, start timing after sending the first key response frame to the data encryption device, and determine whether the first key invocation success message or the first key invocation failure message sent by the data encryption device is received within a preset duration after starting the timing.
[0069] Step 10212b, in response to determining that the first key invocation success message or the first key invocation failure message sent by the data encryption device is not received within the preset duration after starting the timing, re-send the first key response frame to the data encryption device.
[0070] During specific implementation, if the key invocation unit does not receive the first key invocation success message Final0 or the first key invocation failure message Final1 from the external application system within a preset duration (e.g., T cycle) after returning the first key response frame Response1 to the data encryption device, it determines that the first key invocation has timed out, and the key invocation unit resends the first key response frame Response1 containing the first key to the data encryption device.
[0071] For example, the preset duration is 5s. Timing starts after the key invocation unit sends the first key response frame containing the first key to the data encryption device. If the key invocation unit does not receive the first key invocation success message or the first key invocation failure message sent by the data encryption device at the 5th second after timing, it determines that the first key invocation has timed out, and the key invocation unit resends the first key response frame containing the first key to the data encryption device, which can avoid the problem that the data encryption device cannot encrypt data due to not receiving the first key.
[0072] Through the above solution, when the key invocation unit does not receive the first key invocation success message or the first key invocation failure message sent by the data encryption device within the preset duration after starting timing, it can accurately determine that the first key invocation has timed out. The key invocation unit resends the first key response frame containing the first key to the data encryption device, which can avoid the problem that the data encryption device cannot encrypt data due to not receiving the first key.
[0073] In some embodiments, the USB interface-based key invocation update and quantity display device is provided with a USB interface; the USB interface-based key invocation update and quantity display device is connected to the key distribution device in an insertion manner using the USB interface; step 1022 includes:
[0074] Step 10221, the key update unit receives the key update request sent by the key distribution device and determines whether the key distribution device meets the key update permission.
[0075] Step 10222, in response to determining that the key distribution device meets the key update permission, the key update unit sends a permission response frame to the key distribution device.
[0076] Step 10223, the key update unit receives the data packet sent by the key distribution device and obtains the updated key from the data packet.
[0077] Step 10224, the key update unit saves the updated key to the key storage module, generates key update completion information, and determines that there is an update to the key in the key storage module based on the key update completion information.
[0078] In specific implementation, the key storage module of the key call update and quantity display device based on the USB interface stores keys. The key management module can call keys, update keys, and display the key quantity in real time. The key distribution device is used to distribute the updated key to the key storage module in the key call update and quantity display device based on the USB interface.
[0079] The key call update and quantity display device based on the USB interface is a pluggable device. The key call update and quantity display device based on the USB interface is provided with a Universal Serial Bus (USB) interface. The key call update and quantity display device based on the USB interface can be connected to the data encryption device or the key distribution device respectively in an inserted manner by using the USB interface, so as to implement key call or key update. In this way, by splitting data encryption and key update from the key call update and quantity display device based on the USB interface, it is convenient to use the key call update and quantity display device based on the USB interface. When the data encryption device needs to encrypt data, the key call update and quantity display device based on the USB interface is inserted into the data encryption device through the USB interface, and the data encryption device calls the key from the key storage module of the key call update and quantity display device based on the USB interface through the USB interface. When the key storage module of the key call update and quantity display device based on the USB interface needs to update the key, the key call update and quantity display device based on the USB interface is inserted into the key distribution device through the USB interface, and the key distribution device distributes the updated key to the key storage module of the key call update and quantity display device based on the USB interface through the USB interface.
[0080] Specifically, the process by which the key distribution device distributes the updated key to the key call update and quantity display device based on the USB interface includes: inserting the key call update and quantity display device based on the USB interface into the key distribution device by means of the USB interface. The key update between the key call update and quantity display device based on the USB interface and the key distribution device is realized through the USB interface. The key distribution device sends a key update request UpdateRequest0 to the key update unit. After receiving the key update request Update Request0, the key update unit determines whether the key distribution device meets the key update permission. When it is determined that the key distribution device meets the key update permission, the key update unit returns an authority response frame Response3 to the key distribution device. When the key distribution device receives the authority response frame Response3, it sends an update data packet to the key update unit. After receiving the update data packet, the key update unit saves the updated key in the update data packet to the key storage module, completing the key update. Since the key update is completed, the key update unit generates key update completion information and determines that the key in the key storage module has been updated based on the key update completion information. The key management unit counts the keys in the key storage module to obtain the target key quantity, determines the target key ratio according to the target key quantity and the maximum key quantity, and displays the target key quantity and the target key ratio through the display screen.
[0081] Through the above solution, the key call update and quantity display device based on the USB interface is connected to the key distribution device by means of insertion through the USB interface, which facilitates the key distribution device to distribute the updated key to the key storage module of the key quantity information device. When the key update unit receives the key update request sent by the key distribution device, it determines whether the key distribution device meets the key update permission, avoiding the situation where a key distribution device that does not meet the key update permission updates the key in the key storage module. When the key distribution device meets the key update permission, the key update unit sends an authority response frame to the key distribution device so that the key distribution device can distribute the updated key to the key storage module. When the key update unit receives the data packet sent by the key distribution device, it obtains the updated key from the data packet, saves the updated key to the key storage module, generates key update completion information, thereby determining that the key update is completed, and further determining that the key in the key storage module has been updated.
[0082] In some embodiments, step 102 includes:
[0083] Step 102A, the key management module continuously obtains the key quantity in the key storage module; wherein, the key quantity includes: the historical key quantity at the previous moment and the target key quantity at the current moment.
[0084] Step 102B, the key management module compares the number of target keys with the number of historical keys.
[0085] Step 102C, in response to determining that the number of target keys is less than the number of historical keys, the key management module determines that there is a call to the keys in the key storage module.
[0086] Alternatively, in Step 102D, in response to determining that the number of target keys is greater than the number of historical keys, the key management module determines that there is an update to the keys in the key storage module.
[0087] In specific implementation, the key management module obtains the number of available keys in the key storage module in real time. By judging whether the number of available keys at the previous moment is the same as that at the current moment, it determines whether there is a call or update to the keys in the key storage module, so as to accurately determine whether the number of keys in the key storage module has changed. When the number of historical keys at the previous moment is inconsistent with the number of target keys at the current moment, the key management module determines that there is a call or update to the keys in the key storage module.
[0088] Specifically, when the number of target keys is less than the number of historical keys, it means that the number of available keys at the current moment is less than that at the previous moment, so it is determined that there is a call to the keys in the key storage module. When the number of target keys is greater than the number of historical keys, it means that the number of available keys at the current moment is more than that at the previous moment, so it is determined that there is an update to the keys in the key storage module.
[0089] For example, if the number of historical keys at the previous moment is 60 and the number of target keys at the current moment is 59, it is determined that there is a call to the keys in the key storage module. Another example, if the number of historical keys at the previous moment is 20 and the number of target keys at the current moment is 80, it is determined that there is an update to the keys in the key storage module. Another example, if the number of historical keys at the previous moment is 60 and the number of target keys at the current moment is 60, it is determined that there is no call or update to the keys in the key storage module.
[0090] Through the above solution, when the number of target keys at the current moment is inconsistent with the number of historical keys at the previous moment, the key management module can accurately determine that the number of keys in the key storage module has changed. When the number of target keys is less than the number of historical keys, the key management module can accurately determine that there is a call to the keys in the key storage module. When the number of target keys is greater than the number of historical keys, the key management module can accurately determine that there is an update to the keys in the key storage module.
[0091] Through the above embodiments, the method for key call update and quantity display based on the USB interface is applied to the device for key call update and quantity display based on the USB interface. The device for key call update and quantity display based on the USB interface includes: a key management module and a key storage module. The key management module determines whether there is a call or update for the keys in the key storage module. When there is a call or update for the keys in the key storage module, the key management module determines the target key ratio according to the target key quantity at the current moment and the maximum key quantity, and displays the target key quantity and the target key ratio. In this way, the target key ratio can be accurately determined according to the target key quantity and the maximum key quantity. By displaying the target key quantity and the target key ratio, it is convenient for the user to quickly and clearly understand the quantity and proportion of the keys that can be used at the current moment, avoiding the problem that the user is not clear about the key usage situation. At the same time, it is convenient for the user to judge whether it is necessary to update the keys according to the key usage situation, avoiding the problems of premature key update or untimely key update.
[0092] It should be noted that the embodiments of the present disclosure can also be further described in the following ways:
[0093] Figure 2 It is a schematic structural diagram of the key storage and management device of the embodiments of the present disclosure. As Figure 2 shown, the key visualization display device includes: a key management module, a key storage module, a USB interface, and a display screen. The key management module includes: a key call unit, a key update unit, and a key management unit. Among them, keys are stored in the key storage module. The key call unit is used to call keys from the key storage module and send the called keys to the data encryption device through the USB interface for the data encryption device to use the keys to perform encryption and decryption processing on data. The key update unit is used to obtain updated keys from the key distribution device through the USB interface and store the updated keys in the key storage module. The key management unit is used for key counting and quantity display. The display screen is used to display the target key quantity and the target key ratio.
[0094] The method for realizing key call, update, and visualization and quantification display through the USB interface aims to split the encryption function and the key storage function in the encryption device, integrate the key storage module and the key management module in the form of modules with the USB interface and the display screen, complete the functions of calling keys, updating keys, and real-time displaying the key usage situation through the USB interface, and realize the flexible combination of the encryption device.
[0095] The key storage module is used to batch save key pairs and support key call and update functions.
[0096] The key management module is used for data processing, including key invocation through the USB interface, key update, quantity monitoring, etc.; the key management unit performs real-time counting and quantity display of keys. When a key is invoked through the USB interface, the key management unit monitors the change in the number of key pairs in the key storage module, updates the key count, and through the quantity display function, displays the updated target key quantity and target key ratio on the display screen. When the key update through the USB interface is completed, the key management unit monitors the key quantity and displays the target key quantity.
[0097] (1) Key invocation process
[0098] Figure 3 This is the flowchart of the key invocation method of the present disclosure embodiment. As Figure 3 shown, the key invocation method includes:
[0099] Step 301, the external application system (i.e., the data encryption device) sends a key invocation request, request frame Request0;
[0100] Step 302, the key management module returns a response data frame Response0, where 01 indicates that it can be invoked (permission to invoke information), and 00 indicates that it cannot be invoked (prohibition of invocation information);
[0101] Step 303, the external application system receives Response0. If it is 01, it sends a function request Request1 that is needed. If it is 00, it does not send a function request;
[0102] Step 304, the key management module invokes the corresponding key in the key storage module according to the function request Request1, and returns the first key response frame Response1 to the external application system. The first key response frame contains the first key corresponding to the function;
[0103] Step 305, the external application system receives the first key response frame Response1, operates using the first key, and after success, sends the first key invocation success information Final0 to the key management module to complete the invocation of the first key;
[0104] Step 306, the key management module receives the first key invocation success information Final0, operates on the key count, subtracts 1 from the key quantity, and updates the display screen;
[0105] Step 307, the external application system receives the first key response frame Response1, operates using the first key. If the operation fails, it sends the first key invocation failure information Final1;
[0106] Step 308: The key management module receives the first key call failure message Final1, sends a new second key response frame Response2 to the external application system, which contains the new second key, decrements the key count by 1, and updates the display screen.
[0107] Step 309: If the key management module does not receive the first key call success message Final0 or the first key call failure message Final1 from the external application system within a preset duration (e.g., T cycle) after returning the first key response frame Response1, it determines a timeout and resends the old first key response frame Response1.
[0108] (2) Key update process
[0109] Figure 4 is a flowchart of the key update method according to an embodiment of the present disclosure. As Figure 4 shown, the key update method includes:
[0110] Step 401: The external key update module (i.e., the key distribution device) sends a key update request Update Request0 to the key management module.
[0111] Step 402: The key management module receives the key update request Update Request0, determines the permission of the external key update module. If it passes, it returns a permission response frame Response3.
[0112] Step 403: The external key update module receives the permission response frame Response3 and sends an update data packet to the key management module.
[0113] Step 404: The key management module receives the update data packet, saves the updated key in the update data packet to the key storage module, and completes the key update.
[0114] Through the above embodiments, the problem of cumbersome key update operations for the data encryption module is solved. Through modular design, the key storage and management module is separated from the data encryption module, and the key update work only needs to operate on the key storage and management module. The problem that the number of keys cannot be intuitively identified is solved by adding a liquid crystal display screen to the key storage and management module to display the key usage percentage, the number of available key pairs, the number of used key pairs, etc. The problem that the encryption function cannot be flexibly combined is solved by splitting the key storage and management part and the data encryption part into independent modules to achieve flexible combination of the encryption function. The device can directly call the key module without passing through the encryption module.
[0115] It should be noted that the method of the embodiments of the present disclosure can be executed by a single device, such as a computer or a server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In this case of a distributed scenario, one of the multiple devices can only execute one or more steps of the method of the embodiments of the present disclosure, and these multiple devices will interact with each other to complete the described method.
[0116] It should be noted that some embodiments of the present disclosure have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order from that in the above embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0117] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present disclosure also provides a key call update and quantity display device based on a USB interface.
[0118] Referring to Figure 5 , for the key call update and quantity display device based on a USB interface, the device includes: a key management module 501 and a key storage module 502; the key management module 501 is electrically connected to the key storage module 502;
[0119] The key management module 501 is specifically configured to:
[0120] Determine whether there is a call or update for the key in the key storage module 502;
[0121] In response to determining that there is a call or update for the key in the key storage module 502, determine a target key ratio based on the target key quantity at the current moment and the maximum key quantity, and display the target key quantity and the target key ratio.
[0122] In some embodiments, the key management module 501 is further configured to:
[0123] Compare the target key quantity with a preset quantity threshold;
[0124] In response to determining that the target key quantity is less than the preset quantity threshold, display a prompt message indicating that the key quantity is too small.
[0125] In some embodiments, the key management module 501 includes a key call unit and a key update unit;
[0126] The key invocation unit is configured to, in response to determining that the key invocation unit receives a key invocation request, invoke a key from the key storage module 502, and then determine that there is an invocation of the key in the key storage module 502;
[0127] Or,
[0128] The key update unit is configured to, in response to determining that the key update unit receives a key update request, save the obtained updated key to the key storage module 502, and then determine that there is an update of the key in the key storage module 502.
[0129] In some embodiments, the USB interface-based key invocation update and quantity display device is provided with a USB interface; the pluggable USB interface-based key invocation update and quantity display device uses the USB interface to be connected to the data encryption device by insertion;
[0130] The key invocation unit is specifically configured to:
[0131] Upon receiving the key invocation request sent by the data encryption device, send a response data frame to the data encryption device; wherein, the response data frame includes an allow invocation message or a prohibit invocation message;
[0132] Upon receiving the function request generated by the data encryption device based on the allow invocation message, send a first key response frame to the data encryption device; wherein, the first key response frame includes a first key;
[0133] Upon receiving the first key invocation success message sent by the data encryption device, determine that there is an invocation of the key in the key storage module 502 based on the first key invocation success message.
[0134] In some embodiments, the key invocation unit is further configured to:
[0135] Upon receiving the first key invocation failure message sent by the data encryption device, send a second key response frame to the data encryption device; wherein, the second key response frame includes a second key;
[0136] Upon receiving the second key invocation success message sent by the data encryption device, determine that there is an invocation of the key in the key storage module 502 based on the second key invocation success message.
[0137] In some embodiments, the USB interface-based key invocation update and quantity display device is provided with a USB interface; the pluggable USB interface-based key invocation update and quantity display device uses the USB interface to be connected to the key distribution device by insertion;
[0138] The key update unit is specifically configured to:
[0139] Upon receiving the key update request sent by the key distribution device, determine whether the key distribution device meets the key update permission;
[0140] In response to determining that the key distribution device meets the key update permission, send a permission response frame to the key distribution device;
[0141] Upon receiving the data packet sent by the key distribution device, obtain the updated key from the data packet;
[0142] Save the updated key to the key storage module 502, generate key update completion information, and determine that the key in the key storage module 502 has been updated based on the key update completion information.
[0143] In some embodiments, the key management module 501 is further configured to:
[0144] Obtain the number of keys in the key storage module 502 in real time; wherein, the number of keys includes: the historical number of keys at the previous moment and the target number of keys at the current moment;
[0145] Compare the target number of keys with the historical number of keys;
[0146] In response to determining that the target number of keys is less than the historical number of keys, determine that the keys in the key storage module 502 have been called; or,
[0147] In response to determining that the target number of keys is greater than the historical number of keys, determine that the keys in the key storage module 502 have been updated.
[0148] For the convenience of description, when describing the above device, various modules are described separately according to their functions. Of course, when implementing the present disclosure, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0149] The device in the above embodiment is used to implement the corresponding key call update and quantity display method based on the USB interface in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0150] Based on the same inventive concept, corresponding to the method in any of the above embodiments, the present disclosure further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, it implements the key call update and quantity display method based on the USB interface in any of the above embodiments.
[0151] Figure 6 Shows a more specific schematic diagram of the hardware structure of the electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. Among them, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other inside the device through the bus 1050.
[0152] The processor 1010 can be implemented in the form of a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0153] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.
[0154] The input / output interface 1030 is used to connect to the input / output module to achieve information input and output. The input / output module can be configured as a component in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Among them, the input device can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device can include a display, a speaker, a vibrator, an indicator light, etc.
[0155] The communication interface 1040 is used to connect to the communication module (not shown in the figure) to achieve communication interaction between this device and other devices. Among them, the communication module can communicate through a wired method (such as USB (Universal Serial Bus), network cable, etc.) or through a wireless method (such as a mobile network, WIFI (Wireless Fidelity), Bluetooth, etc.).
[0156] The bus 1050 includes a path for transmitting information between various components of the device, such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040.
[0157] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solution of the embodiments of this specification, and does not necessarily include all the components shown in the figure.
[0158] The electronic device of the above embodiment is used to implement the corresponding method for updating and displaying the number of keys based on the USB interface in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0159] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present disclosure also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the method for updating and displaying the number of keys based on the USB interface as described in any of the foregoing embodiments.
[0160] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0161] The computer instructions stored in the storage medium of the above embodiment are used to cause the computer to execute the method for updating and displaying the number of keys based on the USB interface as described in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0162] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application further provides a computer program product, including computer program instructions. When the computer program instructions run on a computer, the computer is enabled to execute the method for key call update and quantity display based on a USB interface described in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated herein.
[0163] It can be understood that before using the technical solutions of the various embodiments in the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved will be informed to the user in an appropriate manner, and the user's authorization will be obtained.
[0164] For example, when responding to a user's active request, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that executes the operations of the technical solutions of the present disclosure according to the prompt message.
[0165] As an optional but non-limiting implementation manner, the manner of sending a prompt message to the user in response to receiving the user's active request may be, for example, in the form of a pop-up window. The prompt message may be presented in text in the pop-up window. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0166] It can be understood that the above process of notifying and obtaining the user's authorization is only illustrative and does not limit the implementation manner of the present disclosure. Other manners that meet relevant laws and regulations can also be applied to the implementation manner of the present disclosure.
[0167] Those of ordinary skill in the art should understand that the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the present disclosure is limited to these examples; under the idea of the present disclosure, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present disclosure as described above, which are not provided in detail for the sake of brevity.
[0168] In addition, for simplicity of explanation and discussion, and so as not to make the embodiments of the present disclosure difficult to understand, well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Further, the devices may be shown in block diagram form in order to avoid making the embodiments of the present disclosure difficult to understand, and this also takes into account the fact that details regarding the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present disclosure are to be implemented (i.e., these details should be entirely within the understanding of those skilled in the art). In cases where specific details (such as circuits) are set forth to describe exemplary embodiments of the present disclosure, it will be apparent to those skilled in the art that the embodiments of the present disclosure may be practiced without these specific details or with variations of these specific details. Accordingly, these descriptions are to be regarded as illustrative rather than restrictive.
[0169] Although the present disclosure has been described in connection with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0170] Embodiments of the present disclosure are intended to cover all such alternatives, modifications, and variations that fall within the broad scope of the present disclosure. Accordingly, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the embodiments of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. A method for calling, updating and displaying secret keys based on a USB interface, characterized in that: Applied to a key call update and quantity display device based on a USB interface; The device includes: a key management module and a key storage module; The method includes: The key management module determines whether there is a call or update for the key in the key storage module; In response to determining that there is a call or update for the key in the key storage module, the key management module determines a target key ratio based on the target key quantity and the maximum key quantity at the current moment, and displays the target key quantity and the target key ratio.
2. The method according to claim 1, wherein The method further includes: The key management module compares the target key quantity with a preset quantity threshold; In response to determining that the target key quantity is less than the preset quantity threshold, the key management module displays a prompt message indicating that the key quantity is too small.
3. The method according to claim 1, wherein The key management module includes a key call unit and a key update unit; The determination that there is a call or update for the key in the key storage module includes: In response to determining that the key call unit receives a key call request, the key call unit calls the key from the key storage module, and then determines that there is a call for the key in the key storage module; Or, In response to determining that the key update unit receives a key update request, the key update unit saves the obtained updated key to the key storage module, and then determines that there is an update for the key in the key storage module.
4. The method according to claim 3, characterized in that The key call update and quantity display device based on the USB interface is provided with a USB interface; The key call update and quantity display device based on the USB interface is connected to the data encryption device in an inserted manner by using the USB interface; The determination that, in response to determining that the key call unit receives a key call request, the key call unit calls the key from the key storage module, and then determines that there is a call for the key in the key storage module includes: The key call unit receives the key call request sent by the data encryption device and sends a response data frame to the data encryption device; Wherein, the response data frame includes an allow call message or a prohibit call message; The key call unit receives the function request generated by the data encryption device based on the allow call message and sends a first key response frame to the data encryption device; Wherein, the first key response frame includes a first key; The key call unit receives the first key call success message sent by the data encryption device and determines that there is a call for the key in the key storage module based on the first key call success message.
5. The method according to claim 4, wherein After the key call unit receives the function request generated by the data encryption device based on the allow call message and sends a first key response frame to the data encryption device, it further includes: The key call unit receives the first key call failure message sent by the data encryption device and sends a second key response frame to the data encryption device; Wherein, the second key response frame includes a second key; The key invocation unit receives the second key invocation success information sent by the data encryption device, and determines that there is a key invocation in the key storage module based on the second key invocation success information.
6. The method according to claim 3, wherein The USB interface-based key invocation update and quantity display device is provided with a USB interface; the USB interface-based key invocation update and quantity display device uses the USB interface to be connected to the key distribution device in an insertion manner. In response to determining that the key update unit receives a key update request, the key update unit saves the obtained updated key to the key storage module, and determines that there is an update to the key in the key storage module, including: The key update unit receives the key update request sent by the key distribution device, and determines whether the key distribution device meets the key update permission. In response to determining that the key distribution device meets the key update permission, the key update unit sends a permission response frame to the key distribution device. The key update unit receives the data packet sent by the key distribution device, and obtains the updated key from the data packet. The key update unit saves the updated key to the key storage module, generates key update completion information, and determines that there is an update to the key in the key storage module based on the key update completion information.
7. The method according to claim 1, wherein Determining that there is an invocation or update to the key in the key storage module includes: The key management module obtains the key quantity in the key storage module in real time; wherein, the key quantity includes: the historical key quantity at the previous moment and the target key quantity at the current moment. The key management module compares the target key quantity with the historical key quantity. In response to determining that the target key quantity is less than the historical key quantity, the key management module determines that there is an invocation of the key in the key storage module; or, In response to determining that the target key quantity is greater than the historical key quantity, the key management module determines that there is an update to the key in the key storage module.
8. A key call update and quantity display device based on a USB interface, characterized in that, The device includes: a key management module and a key storage module; the key management module is electrically connected to the key storage module. The key management module is specifically configured to: Determine whether there is an invocation or update to the key in the key storage module. In response to determining that there is an invocation or update to the key in the key storage module, determine the target key ratio according to the target key quantity at the current moment and the maximum key quantity, and display the target key quantity and the target key ratio.
9. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and running on the processor. When the processor executes the program, it implements the method according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause a computer to execute the method according to any one of claims 1 to 7.