Semi-distributed secret key management method and system and medium

By separating the secret keys of the encryption device into sub-permissions and managing them in a distributed network, the security and reliability problems of the traditional centralized key system are solved, and more efficient key management and security guarantees are achieved.

CN120456015AActive Publication Date: 2025-08-08LIUPANSHUI NORMAL UNIV
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510861286.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-25
Publication Date
2025-08-08
Estimated Expiration
2045-06-25

AI Technical Summary

Technical Problem

Traditional centralized key management systems have the risk of single-point theft, are prone to malicious cloning and cracking, and are insufficient in security and reliability when facing professional attacks.

Method used

The original secret key of the encryption device is separated into a complete key entity and multiple sub-key permissions. The sub-permissions are stored on the edge node of the authentication information through ZigBee communication. The edge node of the secret key authentication centrally stores the complete key entity, and the permission verification and decryption request processing are performed through the central computing node.

Benefits of technology

It significantly reduces the risk of single-point theft, enhances the system's fault tolerance and attack resistance, and is suitable for efficient and reliable key management in large-scale scenarios, improving the security and reliability of keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120456015A_ABST
    Figure CN120456015A_ABST
Patent Text Reader

Abstract

The invention discloses a semi-distributed secret key management method, and relates to the technical field of cryptography. Comprising the following steps that an original secret key of encryption equipment is separated into a complete secret key entity and a plurality of secret key sub-authorities, and based on ZigBee communication, only one secret key sub-authority is stored on each authentication information edge node; the secret key authentication edge node stores a complete secret key entity in a centralized manner; all authentication information edge nodes periodically send secret key sub-permissions to the central computing node; the front-end equipment sends a calling request instruction of the original secret key of the encryption equipment, the central computing node compares the calling request instruction of the original secret key of the encryption equipment with all secret key sub-permissions, and when the use permission level for decrypting the encryption equipment is reached after comparison, the encryption equipment is decrypted; the secret key authentication edge node finds a complete secret key entity of the corresponding encryption equipment according to the use permission level; decrypting the encryption device by using the complete key entity; according to the invention, the security guarantee and the reliability of the key permission are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of cryptography technology, and in particular to a semi-distributed key management method, system and medium. Background Art

[0002] With the rapid development of information technology, data security has become a crucial core issue in the information technology sector. In traditional centralized key management systems, keys are typically stored on a single device. For example, the encryption scheme used in computer grade examination encryption systems integrates the key system into a single hardware device and relies on increasing key complexity to enhance system security. However, in practical applications, it has been found that centralized key systems suffer from vulnerabilities in personnel oversight, leading to multiple security risks. First, hardware devices can be maliciously cloned or directly copied, exposing the entire key system to risk. Second, attackers can use debugging tools like SoftICE to track data interactions and decrypt them. Furthermore, programming interception programs to tamper with communications between software and encryption devices has become a common method for cracking centralized key systems. The combination of these technical vulnerabilities and management shortcomings makes traditional centralized key systems subject to a high risk of key leakage and system compromise in the face of specialized attacks. Summary of the Invention

[0003] The purpose of the present invention is to provide a semi-distributed key management method, system and medium, which improve the security and reliability of key use.

[0004] To solve the above technical problems, an embodiment of the present invention provides a semi-distributed key management method, comprising the following steps: A semi-distributed key management method is applied to a semi-distributed key management system, the system comprising: an authentication information edge node, a key authentication edge node, a central computing node, a front-end device, multiple authentication information edge nodes, and multiple encryption devices; the method comprises: The original secret key of the encryption device is separated into a complete secret key entity and multiple secret key sub-authorities. Based on ZigBee communication, each authentication information edge node only stores one secret key sub-authority; the secret key authentication edge node centrally stores the complete secret key entity; all authentication information edge nodes periodically send secret key sub-authorities to the central computing node; The front-end device sends a call request instruction for the encryption device's original secret key to the central computing node. The central computing node compares the call request instruction for the encryption device's original secret key with all the secret key sub-authorities. When the comparison reaches the permission level for decrypting the encryption device, the key authentication edge node finds the corresponding encryption device complete secret key entity based on the permission level for decrypting the encryption device. Use the complete key entity to decrypt the encrypted device.

[0005] In some optional embodiments, the key authentication edge node is specifically used to: The key authentication edge node supports the parallel storage of multiple original key entities and can configure differentiated usage permissions for different original key entities.

[0006] In some optional embodiments, the central computing node is specifically configured to: The central computing node is only involved in receiving the secret key sub-authority stored in the authentication information edge node, receiving the call request instruction of the original secret key of the encryption device initiated by the front-end device, and sending the usage permission level for decryption of the encryption device to the secret key authentication edge node.

[0007] In some optional embodiments, the authentication information edge node periodically sends different levels of key usage permissions to the central computing node, specifically including: All authentication information edge nodes periodically send secret key sub-authorities to the central computing node. Each secret key sub-authority sent has a certain life cycle. When the life cycle reaches the upper limit, if the central computing node does not receive the secret key sub-authority updated by the authentication information edge node, the secret key sub-authority information will be lost.

[0008] The semi-distributed key management method provided by the present invention has at least the following beneficial effects: The original key is separated into a complete key entity and key usage permissions, and key usage permissions are generated, distributed, stored, and updated using distributed computing and storage technologies. This architecture significantly reduces the risk of single-point theft, enhances system fault tolerance and anti-attack capabilities, and is more suitable for managing massive keys in large-scale scenarios such as cloud computing and the Internet of Things, providing efficient and reliable protection for data encryption transmission and storage.

[0009] The authentication information edge node in the system is responsible only for authorization verification during the authentication process and does not store the physical key. This reduces network transmission security requirements and simplifies the design of the ZigBee network management center. Furthermore, a separate key storage node is designed to independently manage keys, increasing system deployment flexibility. Centralized storage facilitates centralized key management, backup, and safekeeping, further enhancing security. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0011] Figure 1 This is a flow chart of a semi-distributed key management method provided according to an embodiment of the present invention; Figure 2 This is a physical diagram of an authentication information edge node provided according to an embodiment of the present invention; Figure 3 This is a flow chart of an authentication information edge node provided according to an embodiment of the present invention; Figure 4 This is a physical diagram of a key authentication edge node provided according to an embodiment of the present invention; Figure 5 This is a flow chart of a key authentication edge node provided according to an embodiment of the present invention; Figure 6 This is a physical diagram of a central computing node provided according to an embodiment of the present invention; Figure 7 This is a flow chart of a central computing node provided according to an embodiment of the present invention; Figure 8 This is a schematic diagram of a user using a WeChat mini program according to an embodiment of the present invention; Figure 9 This is a system diagram of a semi-distributed key management method provided according to an embodiment of the present invention; DETAILED DESCRIPTION

[0012] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with specific embodiments of the present invention and corresponding drawings. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0013] One embodiment of the present invention relates to a semi-distributed key management method. The implementation details of the grape bud quantitative evaluation method of this embodiment are specifically described below. The following content is only provided for easy understanding of the implementation details and is not necessary for implementing this solution.

[0014] The specific process of the semi-distributed key management method of this embodiment is as follows: Figure 1 Shown, including: Step 101: Separate the original secret key of the encryption device into a complete secret key entity and multiple secret key sub-authorities. Based on ZigBee communication, only one secret key sub-authority is stored on each authentication information edge node; the secret key authentication edge node centrally stores the complete secret key entity; all authentication information edge nodes periodically send secret key sub-authorities to the central computing node.

[0015] The authentication information edge node is implemented using CC2530. To meet the requirements of compactness and portability, CC2530 and power module need to be integrated into the design. Figure 2 shown.

[0016] The authentication information edge node stores different levels of key usage permissions and sends different levels of key usage permissions to the central computing node when needed. The authentication information edge node flow chart is as follows Figure 3 As shown, the process starts with the initialization of the authentication information edge node, judging the network access status, and continuously retrying if it is not connected; after successful access, it waits for the key operation to be sent. If it is not pressed, it will continue to wait. After pressing, the different levels of key usage permissions will be sent to the central computing node, and the system will be exited after the sending is completed.

[0017] The authentication information edge node periodically sends different levels of key usage permissions to the central computing node. Each permission sent has a certain life cycle. When the life cycle reaches the upper limit, if the authentication information edge node does not receive the different levels of key usage permissions updated, the central computing node will lose the different levels of key usage permission information.

[0018] The key authentication edge node is implemented by combining CC2530 and CH9329. The actual picture of the key authentication edge node is as follows Figure 4 shown.

[0019] The key authentication edge node stores the complete key entity in a centralized manner, identifies the target key entity corresponding to the original key call request, and outputs the key entity after retrieving it. The key authentication edge node flow chart is as follows: Figure 5 As shown, the process begins with the initialization of the key authentication edge node, which then continuously attempts to connect to the network until successful. After successful connection, the node enters a standby state, awaiting control commands from the central computing node. Upon receiving a control command, the key authentication edge node identifies the original key call request type and outputs the corresponding key entity based on the original key call request. After key output is complete, the process ends and the node exits the system. The key authentication edge node supports parallel storage of multiple original keys and can configure differentiated usage permissions for different original keys.

[0020] The central computing node uses the CC2530 WIFI transparent transmission gateway module, which integrates the CC2530 main control chip, ESP8266 module and power supply, USB, debug interface and standard IO port. The integration of the two facilitates development. This design uses the CC2530 main control chip, ESP8266 module, IO interface, and USB to serial port to achieve the function. The actual picture of the central computing node is as follows Figure 6 shown.

[0021] The central computing node is only involved in receiving the different levels of key usage permissions stored in the authentication information edge node, receiving the original key call request initiated by the front-end device, and sending the original key call request to the key authentication edge node; after the central computing node receives the different levels of key usage permissions stored in the authentication information edge node, it calculates the different levels of key usage permissions. If the original key call request initiated by the front-end device reaches the usage permission level, it sends the original key call request to the key authentication edge node. The flow chart of the central computing node is as follows: Figure 7 As shown, the process begins with the initialization of the central computing node, which then enters a state where it waits for control commands. Upon receiving authentication information, it performs computations and then determines whether it matches the received control command. If not, it continues to wait for a matching control command. If so, it sends the control command to the key authentication node and exits the system upon successful transmission.

[0022] Step 102: The front-end device sends a call request instruction for the original secret key of the encryption device to the central computing node. The central computing node compares the call request instruction for the original secret key of the encryption device with all the secret key sub-authorities. When the comparison reaches the usage permission level for decrypting the encryption device, the key authentication edge node finds the corresponding encryption device complete secret key entity based on the usage permission level for decrypting the encryption device.

[0023] The front-end device is implemented using WeChat applet, which has four modules: key control module, time tracing module (to check the time of key use), user registration and login, and user password retrieval. Figure 7 The figure shows a schematic diagram of a user using a WeChat mini program, including registration and login, secret key control, time tracing, and password retrieval.

[0024] Key usage records are stored and traced using the ONENET cloud server management platform, which supports multiple communication protocols, including MQTT, EDP, and HTTP / HTTPS. MQTT is particularly advantageous, featuring a lightweight publish-subscribe mechanism. This makes it highly adaptable to IoT devices with limited computing resources and network bandwidth, effectively reducing the communication burden on these devices.

[0025] Based on authentication information edge nodes, secret key authentication edge nodes, central computing nodes, ONENET cloud server management platform and WeChat applet, Figure 8This is a system diagram of a semi-distributed key management method, which clearly shows that different levels of key usage permissions are distributedly stored on the authentication information edge node, the complete key entity is stored on the key authentication edge node, the central computing node compares the original key call request with different levels of key usage permissions, the ONENET cloud server management platform performs cross-network interaction, and the WeChat applet sends the original key call request to control it.

[0026] Step 103: Decrypt the encrypted device using the complete secret key entity.

[0027] The steps of the above methods are divided only for clarity of description and can be combined into one step when implemented. The steps or the splitting and decomposition of some steps into multiple steps, as long as they include the same logical relationship, are within the scope of protection of the present invention; adding insignificant modifications to the algorithm or process or introducing irrelevant The core design that does not change its algorithm and process is within the scope of protection of the invention.

[0028] Those skilled in the art will appreciate that the above embodiments are specific embodiments for implementing the present invention and that in actual applications, various changes may be made thereto in form and detail without departing from the spirit and scope of the present invention.

Claims

1. A semi-distributed key management method, characterized in that: Applied to semi-distributed key management The system comprises: an authentication information edge node, a key authentication edge node, a central computing node, a front-end device, multiple authentication information edge nodes and multiple encryption devices; The method comprises: The original secret key of the encryption device is separated into a complete secret key entity and multiple secret key sub-authorities. Based on ZigBee communication, each authentication information edge node only stores one secret key sub-authority; the secret key authentication edge node centrally stores the complete secret key entity; all authentication information edge nodes periodically send secret key sub-authorities to the central computing node; The front-end device sends a call request instruction for the encryption device's original secret key to the central computing node. The central computing node compares the call request instruction for the encryption device's original secret key with all the secret key sub-authorities. When the comparison reaches the permission level for decrypting the encryption device, the key authentication edge node finds the corresponding encryption device complete secret key entity based on the permission level for decrypting the encryption device. Use the complete key entity to decrypt the encrypted device.

2. A semi-distributed key management method according to claim 1, characterized in that: The secret key authentication edge node is specifically used to: The key authentication edge node supports the parallel storage of multiple original key entities and can configure differentiated usage permissions for different original key entities.

3. A semi-distributed key management method according to claim 1, characterized in that: The central computing node is specifically used to: The central computing node is only involved in receiving the secret key sub-authority stored in the authentication information edge node, receiving the call request instruction of the original secret key of the encryption device initiated by the front-end device, and sending the usage permission level for decryption of the encryption device to the secret key authentication edge node.

4. A semi-distributed key management method according to claim 1, characterized in that: The authentication information edge node periodically sends different levels of key usage permissions to the central computing node, specifically including: All authentication information edge nodes periodically send secret key sub-authorities to the central computing node. Each secret key sub-authority sent has a certain life cycle. When the life cycle reaches the upper limit, if the central computing node does not receive the secret key sub-authority updated by the authentication information edge node, the secret key sub-authority information will be lost.

Citation Information

Patent Citations

  • Electronic file encryption method and device, electronic file decryption method and device and electronic file encryption and decryption system

    CN106650482A

  • Storage equipment encryption method and decryption method, and storage equipment

    CN108833090A

  • Database data safety management method and system

    CN110489996A

  • Secret key management method, controller and system

    CN111614686A

  • Interface authentication method and system between micro-services, terminal and storage medium

    CN113872932A