Data processing method and device, storage medium and computer equipment
By storing key information in the metadata of encrypted data and modifying it during the key rotation process, the problem of low key rotation efficiency in the existing technology is solved, and efficient key updates and data security are achieved.
Patent Information
- Application Number
- CN202510764779.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-09-16
AI Technical Summary
During the key rotation process, the existing technology requires the stored encrypted objects to be downloaded, modified and then uploaded, which is inefficient and costly. In addition, the operation is cumbersome when the key information is separated from the encrypted data and may cause data to be out of sync.
The key information is stored in the metadata of the encrypted data and modified during the key rotation process to avoid modifying the stored encrypted objects. The key information in the metadata is repackaged and replaced by generating a new key pair and comparing the version identifier.
It improves data processing efficiency, avoids inefficient downloading and uploading operations, simplifies the key update process, and ensures data security and consistency.
Smart Images

Figure CN120658444A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network technology, and in particular to a data processing method, apparatus, storage medium, and computer equipment. Background Art
[0002] With the rapid development of Internet technology, data exchange has become a core component of the information age. Especially in the fields of cloud computing, big data, and the Internet of Things, the scale and complexity of data exchange are increasing. In order to ensure the security and privacy of exchanged data, encryption protection of data during the exchange process has become an indispensable part.
[0003] Some related systems use a method of specifying a key version number for key rotation. When encrypting data, the data owner records the version number of the key used in the encrypted data. During key rotation, the data management center activates the new version key while retaining the old version key for decryption. Since the key information and the encrypted data are encapsulated into a single file, key rotation requires updating the key information in the file content. Due to the nature of object storage systems, which do not support modifications to existing objects, modifications to existing stored objects must be processed by downloading, modifying, and then uploading. This is also inefficient for systems with large data volumes. Therefore, the related art urgently needs to propose a data processing method to solve the above technical problems. Summary of the Invention
[0004] The main purpose of this application is to provide a data processing method, apparatus, storage medium and computer equipment, which stores key information in the metadata of encrypted data, thereby realizing the modification of key information in the metadata during the key rotation process, avoiding the need to download, modify and then upload the stored encrypted objects when modifying them, thereby improving data processing efficiency.
[0005] In a first aspect, an embodiment of the present application provides a data processing method, comprising:
[0006] When a key pair update time point is reached, generating a first key pair and a first key pair version identifier of the first key pair;
[0007] Obtain each stored encrypted data, where metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, where the first encapsulation key is obtained by encrypting the data encryption key corresponding to each encrypted data using the public key of the second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at the time of the previous key pair update;
[0008] comparing the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and filtering out target encrypted data from each encrypted data;
[0009] re-encapsulating the first encapsulation key corresponding to the target encrypted data according to the second key pair version identifier corresponding to the target encrypted data and the first key pair to obtain a second encapsulation key;
[0010] The first encapsulation key in the metadata corresponding to the target encrypted data is replaced with the second encapsulation key, and the second key pair version identifier in the metadata corresponding to the target encrypted data is replaced with the first key pair version identifier.
[0011] In a second aspect, an embodiment of the present application provides a data processing device, including:
[0012] a generating unit, configured to generate a first key pair and a first key pair version identifier of the first key pair when a key pair update time point is reached;
[0013] an acquiring unit, configured to acquire each stored encrypted data, wherein metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, wherein the first encapsulation key is obtained by encrypting a data encryption key corresponding to each encrypted data using a public key of a second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at a time point when the previous key pair was updated;
[0014] a comparing unit, configured to compare the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and filter out target encrypted data from each encrypted data;
[0015] an encapsulation unit, configured to re-encapsulate the first encapsulation key corresponding to the target encrypted data according to the second key pair version identifier corresponding to the target encrypted data and the first key pair, to obtain a second encapsulation key;
[0016] A replacing unit is configured to replace the first encapsulation key in the metadata corresponding to the target encrypted data with the second encapsulation key, and replace the second key pair version identifier in the metadata corresponding to the target encrypted data with the first key pair version identifier.
[0017] In a third aspect, an embodiment of the present application provides a storage medium, wherein the computer-readable storage medium stores a plurality of instructions, which are suitable for loading by a processor to execute any of the above data processing methods.
[0018] In a fourth aspect, an embodiment of the present application provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements any of the above data processing methods when executing the computer program.
[0019] In an embodiment of the present application, when a key pair update time point is reached, a first key pair and a first key pair version identifier of the first key pair are generated; each stored encrypted data is obtained, and the metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, the first encapsulation key is obtained by encrypting the data encryption key corresponding to each encrypted data with the public key of the second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at the previous key pair update time point; the second key pair version identifier corresponding to each encrypted data is compared with the first key pair version identifier, and the target encrypted data is filtered out from each encrypted data; based on According to the second key pair version identifier corresponding to the target encrypted data and the first key pair, the first encapsulation key corresponding to the target encrypted data is re-encapsulated to obtain a second encapsulation key; the first encapsulation key in the metadata corresponding to the target encrypted data is replaced with the second encapsulation key, and the second key pair version identifier in the metadata corresponding to the target encrypted data is replaced with the first key pair version identifier. In this embodiment of the present application, by storing key information in the metadata of the encrypted data, the key information in the metadata is modified during the key rotation process, avoiding the need to download, modify, and then upload when modifying the stored encrypted object, thereby improving data processing efficiency.
[0020] Other features and advantages of the present disclosure will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present disclosure. The purposes and other advantages of the present disclosure can be realized and obtained by the structures particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0022] Figure 1 This is a schematic diagram of the architecture of a data encryption system in the related technology provided in an embodiment of the present application.
[0023] Figure 2A schematic diagram of a data processing system according to an embodiment of the present invention.
[0024] Figure 3 A flowchart of a data processing method provided in an embodiment of the present application.
[0025] Figure 4 A flowchart of the repackaging process provided in an embodiment of the present application.
[0026] Figure 5 A system diagram of a data processing system provided in an embodiment of the present application.
[0027] Figure 6 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application.
[0028] Figure 7 A schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0029] In order to enable those skilled in the art to better understand the solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of this application.
[0030] It should be noted that some processes described in the specification, claims, and figures above include multiple steps that appear in a specific order. However, it should be understood that these steps may be executed in a different order than the order in which they appear herein or in parallel. The step numbers are used solely to distinguish between the different steps and do not themselves represent any order of execution. Furthermore, terms such as "first," "second," or "target" are used herein to distinguish similar objects and are not necessarily used to describe a specific order or precedence.
[0031] Before further explaining the embodiments of the present disclosure in detail, the nouns and terms involved in the embodiments of the present disclosure are explained. The nouns and terms involved in the embodiments of the present disclosure are subject to the following interpretations:
[0032] A Data Encryption Key (DEK) is a symmetric key used to encrypt actual data. It's a randomly generated symmetric key (such as AES-256) used to encrypt and decrypt actual data (such as user files and database records). Unlike asymmetric keys (such as RSA public / private key pairs), a DEK uses the same key for both encryption and decryption.
[0033] Key rotation is the process of updating the keys used in encryption systems periodically or under specific conditions to reduce the risk of key leaks caused by long-term use and ensure data security. It is a key practice in modern cryptography and is widely used in cloud computing, data storage, communications, and other fields.
[0034] See also Figure 1 , Figure 1 This is a schematic diagram of the architecture of a data encryption system in the related art provided in an embodiment of the present application. The data owner uses a randomly generated DEK to encrypt data using a symmetric encryption algorithm (such as AES) to obtain encrypted data. The DEK is encrypted into a wrapped key (wrappedKey) using a public key (pubKey) provided by a data management center (DMC). The wrappedKey and encrypted data are encapsulated into independent, trusted data.
[0035] The data user downloads encrypted data from the Object Storage Service (OBS), reads the data in a trusted format, obtains the wrappedKey, and then requests the DMC to decrypt the wrappedKey to obtain the DEK. The DMC internally manages a key pair (public key pubKey and private key privateKey). The DMC decides whether to grant access based on the system's permission records. If access is granted, the wrappedKey is decrypted using the private key to obtain the DEK, which is then delivered to the data user through a secure channel. In a trusted environment, the data user uses the DEK to decrypt the encrypted data and obtain the original data.
[0036] With the continuous development of encryption technology and the evolving nature of attack methods, the security risks associated with the long-term use of a single key are increasing. At the same time, some modern security standards require information systems to regularly update keys to reduce the risk of leakage. Key rotation can effectively reduce the security risks associated with long-term key use, but existing data encryption systems have the following problems when implementing key rotation:
[0037] 1. When encrypting data, the data owner records the version number of the key used in the encrypted data. During key rotation, the DMC activates the new version key while retaining the old version key for decryption. This approach requires the DMC to always retain the old version key, which poses certain security risks.
[0038] 2. Some systems encapsulate key information and encrypted data into a single file. Key rotation requires updating the key information in the file. Because OBS storage doesn't support modifying existing objects, modifying existing stored objects requires downloading, modifying, and then uploading. This is inefficient and costly for systems with large data volumes.
[0039] 3. Some systems separate key-related information from encrypted data, such as storing them in a separate database. While this approach facilitates key-related updates, file modifications or deletions require synchronization between the OBS storage system and the database, which is cumbersome and can lead to data asynchrony.
[0040] In order to solve the above problem, the embodiment of the present application generates a first key pair and a first key pair version identifier of the first key pair when a key pair update time point is reached; obtains each stored encrypted data, and the metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, the first encapsulation key is obtained by encrypting the data encryption key corresponding to each encrypted data using the public key of the second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at the previous key pair update time point; compares the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and filters out the encrypted data from each encrypted data. Select the target encrypted data; re-encapsulate the first encapsulation key corresponding to the target encrypted data according to the second key pair version identifier corresponding to the target encrypted data and the first key pair to obtain the second encapsulation key; replace the first encapsulation key in the metadata corresponding to the target encrypted data with the second encapsulation key, and replace the second key pair version identifier in the metadata corresponding to the target encrypted data with the first key pair version identifier. The embodiment of the present application addresses the first problem by updating the key information of the encrypted data stored in the OBS at each key rotation. After the update is completed, the old version of the key can be cleared, thereby avoiding the DMC from retaining the old version of the key. Addressing the second problem, by storing the key information in the metadata of the encrypted data, the key information in the metadata can be modified during the key rotation process, avoiding the need to download, modify, and then upload the stored encrypted object when modifying it, thereby improving data processing efficiency. Addressing the third problem, by storing the key information in the metadata of the encrypted data, the key-related information is avoided from being separated from the encrypted data, thereby avoiding cumbersome operations and data synchronization problems. Please refer to the following specific embodiments for details.
[0041] See also Figure 2 , Figure 2 This is a schematic diagram of a data processing system provided in an embodiment of the present application, which includes a terminal 140, the Internet 130, a gateway 120, a computer device 110, etc.
[0042] Terminal 140 includes, but is not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, and the like. Furthermore, it can be a single device or a collection of multiple devices. Terminal 140 can communicate with Internet 130 via wired or wireless means to exchange data.
[0043] Computer device 110 refers to a computer system that can provide certain services to terminal 140. Compared to ordinary terminal 140, computer device 110 has higher requirements in terms of stability, security, and performance. Computer device 110 can be a single high-performance computer in a network platform, a cluster of multiple high-performance computers, a portion of a single high-performance computer (e.g., a virtual machine), or a combination of portions of multiple high-performance computers (e.g., virtual machines).
[0044] Gateway 120, also known as a gateway or protocol converter, implements network interconnection at the transport layer and is a computer system or device that acts as a converter. It acts as a translator between two systems using different communication protocols, data formats, languages, or even completely different architectures. Gateways can also provide filtering and security functions. Data sent from terminal 140 to computer device 110 is sent through gateway 120 to the corresponding computer device 110. Similarly, data sent from computer device 110 to terminal 140 is also sent through gateway 120 to the corresponding terminal 140.
[0045] The data processing method according to the embodiment of the present disclosure may be implemented on the computer device 110 .
[0046] It should be noted that Figure 2 The scenario diagram of the data processing system shown is only an example. The data processing system and scenario described in the embodiment of the present application are intended to more clearly illustrate the technical solution of the embodiment of the present application, and do not constitute a limitation on the technical solution provided by the embodiment of the present application. Ordinary technicians in this field can know that with the evolution of image processing technology and the emergence of new business scenarios, the technical solution provided by the embodiment of the present application is also applicable to similar technical problems.
[0047] In this embodiment, the description will be made from the perspective of a data processing device, which can be specifically integrated into a computer device having a storage unit and a microprocessor installed therein and having computing capabilities.
[0048] See also Figure 3 , Figure 3This is a flow chart of a data processing method provided in an embodiment of the present application. The data processing method includes:
[0049] In step 201, when a key pair update time point is reached, a first key pair and a first key pair version identifier of the first key pair are generated.
[0050] The key rollover time is a periodic rollover or a rollover time manually configured by the developer. If the rollover time is also the key pair update time, the purpose of key rollover is to replace the key pair generated at the last key pair update time with the newly generated key pair. Therefore, when the key pair update time is reached, a first key pair and a first key pair version identifier of the first key pair are generated.
[0051] Specifically, the first key pair version identifier is used to identify the version of the first key pair. The key pair version identifier can represent the generation time of the corresponding key pair or the number of key polling times.
[0052] For example, the key pair version identifier is "v202502", which is used to indicate that the corresponding key pair was generated in February 2025, or the key pair version identifier is "v2," which means that the corresponding key pair is the key pair generated when the number of key polling is 2 since the start of key polling.
[0053] In some embodiments, when a key pair update time point is reached, generating a first key pair and a first key pair version identifier of the first key pair includes:
[0054] (1) Obtain the last key pair update time point and the preset update period;
[0055] (2) Calculating the sum of the last key pair update time point and the preset update period to obtain the current key pair update time point;
[0056] (3) When the time reaches the key pair update time point, a first key pair and a first key pair version identifier of the first key pair are generated.
[0057] If key rollover is performed periodically, the current key pair update time can be calculated by obtaining the last key pair update time and a preset update period. Specifically, the sum of the last key pair update time and the preset update period is determined, and the sum is the current key pair update time. When the current key pair update time is reached, a first key pair and a first key pair version identifier of the first key pair are generated.
[0058] Specifically, the key pair update time point can be calculated according to the following formula:
[0059] <nextrotationtime> = <lastrotationtime> + <rotationinterval>;
[0060] Among them, NextRotationTime is the time point of the next key rotation, that is, the time point of this key pair update, LastRotationTime is the time of the previous key rotation, that is, the time point of the previous key pair update, and RotationInterval is the key rotation period, that is, the preset update period. In addition, developers can also plan, control the process, and display the status of key rotation services. For key rotation, manual rotation and automatic rotation are supported. Developers can configure and query rotation plans through the management system. Through AutoRotation: Configure whether to enable automatic rotation, thereby realizing whether to enable key rotation.
[0061] For example, if the last key pair update time point is January 1, 2025, and the preset update period is 30 days, then the key pair update time point this time is January 1, 2025 plus 30 days, that is, January 1, 2025 plus 30 days, which is January 31, 2025.
[0062] In this way, the update time point is automatically calculated through a preset period to avoid delays or omissions caused by manual triggering, ensure that the key is rotated regularly as planned, and the result of each calculation is unique and predictable, which facilitates the advance allocation of system resources (such as thread pool scheduling of the scheduled task platform). The fixed-period rotation according to the preset update cycle shortens the usage time of a single key and reduces the probability of the key being cracked or abused.
[0063] In step 202, each stored encrypted data is obtained, and the metadata corresponding to each encrypted data at least includes a first encapsulation key and a second key pair version identifier.
[0064] Among them, after the key polling is completed, the key-related information of the encrypted data stored in the OBS system needs to be updated. Since the encrypted data is stored in the OBS system, the OBS system stores not only encrypted data but also other data. Therefore, it is necessary to obtain each encrypted data from the storage location according to the storage location of the encrypted data in the OBS system. The storage location can specifically be information such as the storage bucket and directory of the encrypted data in the OBS system, which is not limited here.
[0065] Each encrypted data item includes corresponding metadata. Metadata is information used to describe object properties in the OBS system. It consists of a set of name-value pairs and can be used as a method for object management. OBS allows users to add custom metadata using message headers beginning with "x-obs-meta-" for customized object management. OBS supports access and modification of metadata, and metadata access permissions are the same as object access permissions.
[0066] The following example illustrates the metadata corresponding to each encrypted data:
[0067] 'Metadata':
[0068] {
[0069] 'x-obs-meta-wrapped-key':
[0070] 'MkhV34OpO / 9LxJ1XBNZf5CUVJOrVcEdo0LMQ7ZajB0HxUblp+f / sATmu81pcWna+sgg0HIJFTqpaxqSybmIs5 NPoNGnHF+YIIZxRbdeRvUV / AuKcL5gtjhdwyjbs04Lid3yZNdmQr0d2gmJu7vixlD3qJkpM9OhahmMA6DXMlNpZ SNCDogQMN2 / 9eorpbMWEix7dkL73jDl5jKWLL / 8dXpZsgdg19gDc5nFfvfePpbyf80IojR365Z0ok5wJsutwR6 kcDAmyviBE0f5j5YBTn9fOkDVsTyGC5AyRjOtroSxxGvWSymg+CeHtq / tJNhVxNWYQoiFIdmhQG0H4M0 / zVw=='
[0071] 'x-obs-meta-key-version':'v202501'
[0072] 'x-obs-meta-encryption-algorithm':'AES-256-GCM',
[0073] }
[0074] The metadata includes at least the first wrapping key (wrappedKey), where wrapped-key is the wrappedKey encoded in base64, the second key pair version identifier (key-version), and may also include the algorithm used for data encryption (encryption-algorithm). Each element is preceded by "x-obs-meta-", thereby defining the key-related information about each encrypted data in the metadata. The first wrapping key (wrappedKey) is obtained by encrypting the data encryption key DEK corresponding to each encrypted data using the public key of the second key pair corresponding to the second key pair version identifier (key-version). The second key pair is the key pair generated at the time of the previous key pair update.
[0075] In step 203, the second key pair version identifier corresponding to each encrypted data is compared with the first key pair version identifier, and target encrypted data is filtered out from each encrypted data.
[0076] Among them, key polling mainly needs to update the key pair version identifier and the encapsulation key in the metadata corresponding to the encrypted data. Therefore, it is necessary to compare the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier in turn, and filter out the target encrypted data from each encrypted data for which the key pair version identifier and the encapsulation key in the corresponding metadata need to be updated.
[0077] In some embodiments, the first key pair version identifier is higher than the key pair version identifier of any historically generated key pair, and comparing the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier to filter out the target encrypted data from each encrypted data includes:
[0078] The second key pair version identifier corresponding to each encrypted data is compared with the first key pair version identifier, and the encrypted data whose corresponding second key pair version identifier is smaller than the first key pair version identifier is determined as the target encrypted data.
[0079] Since the key pair version identifier can represent the generation time of the corresponding key pair or the number of key rotations, as key rotation proceeds, the newly generated key pair version identifier is necessarily higher than any key pair version identifier generated previously. Based on this characteristic, the method for filtering out target encrypted data for which the key pair version identifier and encapsulation key in the corresponding metadata need to be updated can be: comparing the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and determining the encrypted data whose corresponding second key pair version identifier is lower than the first key pair version identifier as the target encrypted data.
[0080] For example, there are three encrypted data, and the corresponding second key pair version identifiers are all v202501, and the first key pair version identifiers are all v202502. Since the second key pair version identifiers of the three encrypted data are all smaller than the first key pair version identifier, these three encrypted data are all determined as target encrypted data.
[0081] This allows for quick screening of target encrypted data by directly comparing version numbers without traversing the list of historical key pairs. Version identifiers are strictly incremented in the order they were generated (e.g., from v202501 to v202502), avoiding version number conflicts or confusion caused by circular reuse.
[0082] In step 204, the first encapsulation key corresponding to the target encrypted data is re-encapsulated according to the second key pair version identifier corresponding to the target encrypted data and the first key pair to obtain a second encapsulation key.
[0083] Among them, since the first encapsulation key in the metadata corresponding to the encrypted data is generated by encapsulating the data encryption key using the public key of the second key pair, and since the second key pair is an old key pair, after key polling generates a new first key pair, the data encryption key needs to be re-encapsulated using the first key pair, thereby obtaining a second encapsulation key that can only be decapsulated using the first key pair. In this way, even if the user cracks the second key pair as the old key pair, the updated second encapsulation key cannot be decapsulated, thereby improving the data security of the encrypted data.
[0084] In some implementations, repackaging the first encapsulation key corresponding to the target encrypted data based on the second key pair version identifier corresponding to the target encrypted data and the first key pair to obtain the second encapsulation key includes:
[0085] (1) obtaining a second key pair with a second key pair version identifier corresponding to the target encrypted data;
[0086] (2) decapsulating the first encapsulation key using the private key of the second key pair to obtain a first data encryption key;
[0087] (3) Encapsulating the first data encryption key using the public key of the first key pair to obtain a second encapsulation key.
[0088] Among them, the mapping relationship between each key pair version identifier and the key pair is maintained through a mapping relationship table, and the second key pair version identifier corresponding to the target encrypted data is obtained and combined with the mapping relationship between each key pair version identifier and the key pair, so as to determine the second key pair with a mapping relationship established with the second key pair version identifier.
[0089] For details, please refer to Figure 4 , Figure 4 This is a flowchart of the repackaging process provided in an embodiment of the present application. Since the first packaging key is obtained by packaging the data encryption key using the public key of the second key pair, it is necessary to depackage the first packaging key using the private key of the second key pair to obtain the original first data encryption key, and then repackage the first data encryption key using the public key of the first key pair to obtain the second packaging key.
[0090] In this way, when a new first key pair is generated by key rotation, the first encapsulation key is decapsulated by using the private key of the second key pair generated at the update time point of the previous key pair, thereby obtaining the original first data encryption key, and then the first data encryption key is encapsulated by the public key of the newly generated first key pair to obtain a second encapsulation key that can only be decapsulated by the private key of the first key pair, thereby improving the data security of the encrypted data.
[0091] In step 205, the first encapsulation key in the metadata corresponding to the target encrypted data is replaced with the second encapsulation key, and the second key pair version identifier in the metadata corresponding to the target encrypted data is replaced with the first key pair version identifier.
[0092] Among them, after obtaining the second encapsulation key, since the key-related information of the encrypted data is stored in the form of metadata, it is necessary to replace the original first encapsulation key in the metadata corresponding to the target encrypted data with the second encapsulation key, and replace the original second key pair version identifier in the metadata corresponding to the target encrypted data with the first key pair version identifier.
[0093] The following uses the OBS system's request to update metadata for a target encrypted data as an example to illustrate the process of replacing key-related information in the metadata corresponding to the target encrypted data:
[0094] The content requested by the OBS system is:
[0095]
[0096] After replacement, the returned response content is:
[0097]
[0098] Among them, in the original metadata of the target encrypted data, the second key pair version is identified as "v202501", and the first encapsulation key is
[0099] "MkhV34OpO / 9LxJ1XBNZf5CUVJOrVcEdo0LMQ7ZajB0HxUblp+f / sATmu81pcWna+sgg0HIJFTqpaxqSybmIs5NPoNGnHF+YIIZxRbdeRvUV / AuKcL5gtjhdwyjbs04Lid3yZNdmQr0d2gmJu7vixlD3qJkpM9OhahmMA6DXMlNpZSNCDogQMN2 / 9eorpbMWEix7dkL73jDl5jKWLL / 8dXpZ sgdg19gDc5nFfvfePpbyf80IojR365Z0ok5wJsutwR6kcDAmyviBE0f5j5YBTn9fOkDVsTyGC5AyRjOtroSxxGvWSymg+CeHtq / tJNhVxNWYQoiFIdmhQG0H4M0 / zVw==", after the first key pair is re-encapsulated, if the re-encapsulation is successful, the status code (result) and text description (message) of the operation result are returned. The status code 0 and the text description success represent that the encapsulation is successful, and the first key pair is re-encapsulated. The first key pair version identifier "v202502" of the key pair and the re-encapsulated second encapsulation key "Tn+sttqmo2b46G3csEsxm1kWQc5aR1sQvUCtHMWL2jXtKgipFGOsTmPciOyfCQp3P0nSBsiMAOzocy / TEvzgYxZYoTi4a1DszfRQnpcfMgV / kiBKyYFMTIy09WLhAk8Bf4+H / E+H3xgnAqR56OCt25LIVbMYsirkpSd / LQjMzdttwKqFDE The command "oPkiuHklsqAiKYze0lzjeZarGRL18vAbXyLfsK47tzWF4M0XkWA7Mm / oVoZndSb1UkZSOxvT56+TF5Ej4A968bvvhkXyaoZHA+5XFuz0LjyZVQWJG8pjFAevwtzUDA33HOPc03orjIzBtdgMVNECYUrojvTvn / Jgj / jQ==" is returned to the OBS system, causing the OBS system to update the first key pair version identifier and the second encapsulation key to the metadata of the target encrypted data.
[0100] In some implementations, after replacing the second key pair version identifier in the metadata corresponding to the target encrypted data with the first key pair version identifier, the method further includes:
[0101] (1) receiving a first decapsulation request sent by a client, where the first decapsulation request carries a third encapsulation key;
[0102] (2) when the client has access rights, decapsulating the third encapsulation key using the private key of the first key pair;
[0103] (3) when the third encapsulation key is successfully decapsulated using the private key of the first key pair, obtaining the second data encryption key;
[0104] (4) Sending the second data encryption key to the client, so that the client decrypts the encrypted data using the second data encryption key to obtain the original data.
[0105] The data user downloads the encrypted data from the OBS system, reads the data in the trusted format, obtains the wrappedKey, and then requests to decrypt the wrappedKey to obtain the original data encryption key. This request is the first decapsulation request sent by the client, which carries the third encapsulation key to be decapsulated.
[0106] Specifically, since the OBS system may have a delay of several seconds before the new metadata overwrites the old metadata, but the decapsulation request sent by the client may be within these few seconds of delay, when receiving the first decapsulation request sent by the client, it is first necessary to detect whether the client has access rights to access the data. When the client has access rights, since the first decapsulation request only carries the third encapsulation key at this time, it is impossible to know the key pair version identifier of the key pair that encrypts the third encapsulation key. Therefore, it is unclear whether the third encapsulation key is encrypted by the public key of the first key pair or the public key of the second key pair. Therefore, the third encapsulation key is attempted to be decapsulated using the private key of the first key pair. If the third encapsulation key is successfully decapsulated using the private key of the first key pair, it means that the third encapsulation key is encrypted by the public key of the first key pair. The second data encryption key obtained by decapsulation is obtained and sent to the client, so that the client decrypts the encrypted data using the second data encryption key to obtain the original data.
[0107] This ensures that clients can still obtain data encryption keys during the brief delay caused by OBS system metadata updates by attempting to decrypt using the latest key pair, thus avoiding service interruptions. Clients do not need to worry about key version details; they simply need to include the encapsulated key in their requests, and the system automatically adapts the decryption logic, reducing integration complexity. This key decryption attempt mechanism ensures compatibility during the transition period when old and new key pairs coexist, ensuring data availability regardless of key rotation.
[0108] In some embodiments, the method further comprises:
[0109] (1) when the third encapsulation key is not successfully decapsulated using the private key of the first key pair, decapsulating the third encapsulation key using the private key of the second key pair to obtain a second data encryption key;
[0110] (2) Sending the second data encryption key to the client, so that the client decrypts the encrypted data using the second data encryption key to obtain the original data.
[0111] Among them, if the third encapsulation key cannot be decapsulated using the private key of the first key pair, it means that the third encapsulation key is encrypted by the public key of the second key pair. Therefore, the third encapsulation key is decapsulated using the private key of the second key pair to obtain the decapsulated second data encryption key, and the second data encryption key is sent to the client, so that the client decrypts the encrypted data using the second data encryption key to obtain the original data.
[0112] This ensures data access continuity, even if a client initiates a decryption request while both old and new metadata coexist. The system sequentially attempts to decrypt using both the old and new key pairs, avoiding decryption failures due to version inconsistencies. The system automatically adapts to the historical key pair, eliminating the need for the client to detect key versions or manually switch between them. This reduces user complexity, covers all possible states during the transition period, and improves system robustness.
[0113] In some implementations, after replacing the second key pair version identifier in the metadata corresponding to the target encrypted data with the first key pair version identifier, the method further includes:
[0114] (1) receiving a second decapsulation request sent by the client, where the second decapsulation request carries a fourth encapsulation key and a third key pair version identifier;
[0115] (2) when the third key pair version identifier is the same as the first key pair version identifier, decapsulating the fourth encapsulation key using the private key of the first key pair to obtain a third data encryption key;
[0116] (3) Sending the third data encryption key to the client, so that the client decrypts the encrypted data using the third data encryption key to obtain the original data.
[0117] Among them, for the case where the second decapsulation request carries not only the fourth encapsulation key but also the third key pair version identifier of the key pair used to encapsulate the fourth encapsulation key, since the third key pair version identifier of the key pair used to encapsulate the fourth encapsulation key can be known, when the third key pair version identifier is the same as the first key pair version identifier, the fourth encapsulation key is directly decapsulated using the private key of the first key pair to obtain the third data encryption key, and the third data encryption key is sent to the client, so that the client decrypts the encrypted data using the third data encryption key to obtain the original data.
[0118] In this way, by actively carrying the version identifier of the key pair on the client, the system does not need to infer the encapsulation source of the encapsulation key through decryption attempts, and can directly match the corresponding private key based on the version number, thereby improving decryption efficiency. By pre-verifying the consistency of the version identifier with the currently active key pair (the first key pair), the performance loss of multi-version polling decryption is reduced, which is especially suitable for high-concurrency scenarios. The version identifier is required to match the active key pair to prevent unauthorized access using historical old key pairs, and requests that do not carry version information or do not match the version are explicitly rejected.
[0119] In some embodiments, the method further comprises:
[0120] (1) When the third key pair version identifier is different from the first key pair version identifier, the third data encryption key is obtained by decapsulating the fourth encapsulation key using the private key of the second key pair;
[0121] (2) Sending the third data encryption key to the client, so that the client decrypts the encrypted data using the third data encryption key to obtain the original data.
[0122] Among them, when the third key pair version identifier is different from the first key pair version identifier, it means that the fourth encapsulation key is obtained by encapsulating the public key of the second key pair. Therefore, when the fourth encapsulation key is decapsulated using the private key of the second key pair, the third data encryption key is obtained, and the third data encryption key is sent to the client, so that the client decrypts the encrypted data using the third data encryption key to obtain the original data.
[0123] By directly comparing the third key pair version identifier with the currently active version, the system quickly locates the corresponding private key, avoiding attempts to decrypt the wrong key pair and improving processing efficiency. During the coexistence phase of the old and new key pairs after key rotation, the correct key pair can be selected based on the key pair's actual version identifier, ensuring that both historical and new data can be decrypted normally.
[0124] Specifically, the metadata update process of each target encrypted data can be collected in the form of logs. When the metadata updates of all target encrypted data are completed, the metadata update task is completed. If an abnormal situation is encountered during the execution of the metadata update task, it can be manually handled by the developer. If there is no error, the metadata update process is ended according to the key rotation plan or the developer's control. Abnormal situations include situations where metadata cannot be written and updated. In this case, the developer can manually verify whether the write and update permissions are available and implement the metadata write and update process by changing the permissions.
[0125] In an embodiment of the present application, when a key pair update time point is reached, a first key pair and a first key pair version identifier of the first key pair are generated; each stored encrypted data is obtained, and the metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, the first encapsulation key is obtained by encrypting the data encryption key corresponding to each encrypted data with the public key of the second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at the previous key pair update time point; the second key pair version identifier corresponding to each encrypted data is compared with the first key pair version identifier, and the target encrypted data is filtered out from each encrypted data; based on According to the second key pair version identifier corresponding to the target encrypted data and the first key pair, the first encapsulation key corresponding to the target encrypted data is re-encapsulated to obtain a second encapsulation key; the first encapsulation key in the metadata corresponding to the target encrypted data is replaced with the second encapsulation key, and the second key pair version identifier in the metadata corresponding to the target encrypted data is replaced with the first key pair version identifier. In this embodiment of the present application, by storing key information in the metadata of the encrypted data, the key information in the metadata is modified during the key rotation process, avoiding the need to download, modify, and then upload when modifying the stored encrypted object, thereby improving data processing efficiency.
[0126] The above solution is described from the perspective of deploying the background management system, scheduled task platform, KAS key access service and OBS system on the same computer device. The actual processing process is as follows: Figure 5 As shown, Figure 5 The system diagram of the data processing system provided in the embodiment of the present application. The background management system is mainly used to provide developers with key rotation business plan formulation, process control and status display, and supports manual rotation and automatic rotation. Developers can configure and query the rotation plan through the management system. The KAS key access service is used to provide core key services for the data encryption system, on the one hand, it provides data sharing services (such as Figure 1 The data encryption process of the related technology), on the other hand, provides a key re-sealing function during the key rotation process. The scheduled task platform is used to execute metadata update tasks, and at the same time, it provides real-time feedback on the situation during the task execution process to the background management system. The OBS data storage system is used to store encrypted data files, and supports metadata writing and modification functions. The data owner uses the SDK provided by the system to implement data encryption and data upload. When uploading encrypted data to the OBS storage system, the SDK will write information such as the wrappedKey and key version number into the metadata of the object. The data user uses the SDK to download and decrypt data. When downloading an object in the OBS storage system, the SDK reads relevant information from the metadata of the object, applies for key decryption from KAS, obtains the DEK, and then decrypts the object.
[0127] Specifically, after the key rotation task is started, the background management system first sends an instruction to KAS to enter the version switching state; the second step is to send a metadata update task to the scheduled task platform.
[0128] In the first step, after receiving the instruction, KAS enters the key switching state, generates a new RSA key pair (or other asymmetric algorithm key pair) and a new version identifier (such as v202502), and sets the new key pair as the master key and the old version key as the backup key. After completing the state switch, KAS reports the state and the new version identifier to the background management system. The functions of KAS in this state include: (1) / get_public_key interface, which is used to return the new version key and the new key version identifier; (2) / decrypt_key interface, which can use both the old version key pair and the new version key pair for decryption; (3) Enable / rewrap interface, the purpose of / rewrap interface is to accept client requests, decrypt the wrappedKey generated by encrypting the old version key, and then re-encapsulate it with the new version key.
[0129] In the second step, after receiving the KAS switch status, the backend management system sends a metadata update task to the scheduled task platform. This task contains the necessary execution parameters, including the new key version identifier and the OBS bucket and directory where the data to be processed resides. The scheduled task platform schedules the metadata update task for execution. The metadata update task traverses the encrypted data in the OBS system, reads the key-related information stored in its metadata, repackages it with KAS, and then writes it into the encrypted data's metadata.
[0130] The metadata update process is as follows: (1) Task initialization: The scheduled task platform initializes the task according to the task execution parameters. The data directory to be processed is preprocessed, and multiple execution threads are started for parallel processing to speed up the processing. The new key version identifier is passed to the execution thread for comparison; (2) Metadata reading: The execution thread traverses the objects in the corresponding directory, reads the metadata of each object, and obtains key-related information. Compare the key pair version identifier with the latest key pair version identifier to determine whether it needs to be updated; if it needs to be updated, proceed to the next step. (3) Key repackaging: The execution thread initiates a request to the / rewrap interface of KAS to obtain the key repackaging by KAS. (4) Metadata writing: The execution thread writes the updated key-related information to the object metadata through the SetObjectMetadata interface. After writing the metadata, the OBS storage system may have a delay of several seconds before the new metadata data overwrites the old data. During this period, the client may read the old metadata metadata, but it does not affect the decryption of the data. (5) Result feedback: The log during the task execution process is sent to the background management system. After the task execution is completed, the scheduled task platform notifies the background management system that the metadata update task execution has ended. The backend management system controls KAS to switch to normal state and disables the / rewrap interface. The administrator sets the destruction or archiving time of the old version key according to the data lifecycle policy.
[0131] See also Figure 6 , Figure 6 This is a schematic diagram of the structure of a data processing device provided in an embodiment of the present application, which is applied to a computer device. The data processing device may include a generating unit 601, an acquiring unit 602, a comparing unit 603, an encapsulating unit 604, and a replacing unit 605.
[0132] A generating unit 601 is configured to generate a first key pair and a first key pair version identifier of the first key pair when a key pair update time point is reached;
[0133] An acquiring unit 602 is configured to acquire each stored encrypted data, where the metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, where the first encapsulation key is obtained by encrypting the data encryption key corresponding to each encrypted data using the public key of the second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at the time of the previous key pair update.
[0134] a comparing unit 603, configured to compare the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and filter out target encrypted data from each encrypted data;
[0135] an encapsulation unit 604, configured to re-encapsulate the first encapsulation key corresponding to the target encrypted data according to the second key pair version identifier corresponding to the target encrypted data and the first key pair to obtain a second encapsulation key;
[0136] The replacing unit 605 is configured to replace the first encapsulation key in the metadata corresponding to the target encrypted data with the second encapsulation key, and replace the second key pair version identifier in the metadata corresponding to the target encrypted data with the first key pair version identifier.
[0137] In some embodiments, the encapsulation unit 604 includes:
[0138] an acquiring subunit, configured to acquire a second key pair with a second key pair version identifier corresponding to the target encrypted data;
[0139] a decapsulation subunit, configured to decapsulate the first encapsulation key using the private key of the second key pair to obtain a first data encryption key;
[0140] The encapsulation subunit is configured to encapsulate the first data encryption key using the public key of the first key pair to obtain a second encapsulation key.
[0141] In some embodiments, the apparatus further comprises:
[0142] A first receiving unit, configured to receive a first decapsulation request sent by a client, where the first decapsulation request carries a third encapsulation key;
[0143] a first decapsulation unit, configured to decapsulate the third encapsulation key using the private key of the first key pair when the client has access rights;
[0144] a second acquiring unit, configured to acquire a second data encryption key when the third encapsulation key is successfully decapsulated using the private key of the first key pair;
[0145] The first sending unit is configured to send the second data encryption key to the client, so that the client decrypts the encrypted data using the second data encryption key to obtain the original data.
[0146] In some embodiments, the apparatus further comprises:
[0147] a second decapsulation unit, configured to, when the third encapsulation key is not successfully decapsulated by the private key of the first key pair, decapsulate the third encapsulation key by using the private key of the second key pair to obtain a second data encryption key;
[0148] The second sending unit is configured to send the second data encryption key to the client, so that the client decrypts the encrypted data using the second data encryption key to obtain the original data.
[0149] In some embodiments, the apparatus further comprises:
[0150] A second receiving unit is configured to receive a second decapsulation request sent by the client, where the second decapsulation request carries a fourth encapsulation key and a third key pair version identifier;
[0151] a third decapsulation unit, configured to, when the third key pair version identifier is the same as the first key pair version identifier, decapsulate the fourth encapsulation key using the private key of the first key pair to obtain a third data encryption key;
[0152] The third sending unit is configured to send the third data encryption key to the client, so that the client decrypts the encrypted data using the third data encryption key to obtain the original data.
[0153] In some embodiments, the apparatus further comprises:
[0154] a fourth decapsulation unit, configured to, when the third key pair version identifier is different from the first key pair version identifier, decapsulate the fourth encapsulation key using the private key of the second key pair to obtain a third data encryption key;
[0155] The fourth sending unit is configured to send the third data encryption key to the client, so that the client decrypts the encrypted data using the third data encryption key to obtain the original data.
[0156] In some embodiments, the first key pair version identifier is higher than the key pair version identifier of any key pair generated historically, and the comparing unit 603 includes:
[0157] The determination subunit is used to compare the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and determine the encrypted data whose corresponding second key pair version identifier is smaller than the first key pair version identifier as the target encrypted data.
[0158] The specific implementation of each of the above units can be found in the previous embodiments and will not be described again here.
[0159] As can be seen from the above, in the embodiment of the present application, when the key pair update time point is reached, the generation unit 601 generates a first key pair and a first key pair version identifier of the first key pair; the acquisition unit 602 acquires each stored encrypted data, and the metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, the first encapsulation key is obtained by encrypting the data encryption key corresponding to each encrypted data using the public key of the second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at the previous key pair update time point; the comparison unit 603 compares the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and filters out the target encrypted data from each encrypted data; the encapsulation unit 604 re-encapsulates the first encapsulation key corresponding to the target encrypted data according to the second key pair version identifier corresponding to the target encrypted data and the first key pair, to obtain a second encapsulation key; the replacement unit 605 replaces the first encapsulation key in the metadata corresponding to the target encrypted data with the second encapsulation key, and replaces the second key pair version identifier in the metadata corresponding to the target encrypted data with the first key pair version identifier. The embodiment of the present application stores the key information in the metadata of the encrypted data, thereby realizing the modification of the key information in the metadata during the key rotation process, avoiding the need to download, modify and then upload the stored encrypted object when modifying it, thereby improving data processing efficiency.
[0160] The specific implementation of each of the above units can be found in the previous embodiments and will not be described again here.
[0161] Reference Figure 7 , Figure 7 This is a partial structural block diagram of a computer device 1000 for implementing an embodiment of the present disclosure. The computer device 1000 may have relatively large differences due to different configurations or performances, and may include one or more central processing units (CPUs) 622 (for example, one or more processors) and memories 632, and one or more storage media 630 (for example, one or more mass storage devices) for storing application programs 642 or data 644. Among them, the memories 632 and the storage media 630 can be temporary storage or permanent storage. The program stored in the storage medium 630 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the server 600. Furthermore, the central processing unit 622 can be configured to communicate with the storage medium 630 to execute a series of instruction operations in the storage medium 630 on the server 600.
[0162] The computer device 1000 may also include one or more power supplies 626, one or more wired or wireless network interfaces 650, one or more input and output interfaces 658, and / or one or more operating systems 641, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.
[0163] The central processing unit 622 in the computer device 1000 may be used to execute the data processing method of the embodiment of the present disclosure, for example:
[0164] When a key pair update time point is reached, generating a first key pair and a first key pair version identifier of the first key pair;
[0165] Obtain each stored encrypted data, where metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, where the first encapsulation key is obtained by encrypting the data encryption key corresponding to each encrypted data using the public key of the second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at the time of the previous key pair update;
[0166] comparing the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and filtering out target encrypted data from each encrypted data;
[0167] re-encapsulating the first encapsulation key corresponding to the target encrypted data according to the second key pair version identifier corresponding to the target encrypted data and the first key pair to obtain a second encapsulation key;
[0168] The first encapsulation key in the metadata corresponding to the target encrypted data is replaced with the second encapsulation key, and the second key pair version identifier in the metadata corresponding to the target encrypted data is replaced with the first key pair version identifier.
[0169] The embodiments of the present disclosure further provide a computer-readable storage medium, which is used to store program codes, and the program codes are used to execute the data processing methods of the aforementioned embodiments.
[0170] The present disclosure also provides a computer program product, which includes a computer program. A processor of a computer device reads and executes the computer program, so that the computer device executes the above-mentioned data processing method. For example:
[0171] When a key pair update time point is reached, generating a first key pair and a first key pair version identifier of the first key pair;
[0172] Obtain each stored encrypted data, where metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, where the first encapsulation key is obtained by encrypting the data encryption key corresponding to each encrypted data using the public key of the second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at the time of the previous key pair update;
[0173] comparing the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and filtering out target encrypted data from each encrypted data;
[0174] re-encapsulating the first encapsulation key corresponding to the target encrypted data according to the second key pair version identifier corresponding to the target encrypted data and the first key pair to obtain a second encapsulation key;
[0175] The first encapsulation key in the metadata corresponding to the target encrypted data is replaced with the second encapsulation key, and the second key pair version identifier in the metadata corresponding to the target encrypted data is replaced with the first key pair version identifier.
[0176] In addition, the terms "comprises" and "comprising" and any variations thereof are intended to cover a non-exclusive inclusion, for example, a process, method, system, product or apparatus that comprises a series of steps or elements is not necessarily limited to those steps or elements expressly listed but may include other steps or elements not expressly listed or inherent to such process, method, product or apparatus.
[0177] It should be understood that in this application, "at least one (item)" means one or more, and "more" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or plural.
[0178] It should be understood that in the description of the embodiments of the present application, multiple (or multiple items) means more than two, greater than, less than, exceed, etc. are understood to exclude the number itself, and above, below, within, etc. are understood to include the number itself.
[0179] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.
[0180] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0181] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0182] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0183] It should also be understood that the various implementation methods provided in the embodiments of the present application can be combined arbitrarily to achieve different technical effects.
[0184] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program that has a predetermined function and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories), or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the functions of the module or unit.
[0185] The above is a specific description of the implementation methods of the present application, but the present application is not limited to the above implementation methods. Technical personnel familiar with the art can also make various equivalent modifications or substitutions without violating the spirit of the present application. These equivalent modifications or substitutions are all included in the scope defined by the claims of the present application.< / rotationinterval> < / lastrotationtime> < / nextrotationtime>
Claims
1. A data processing method, characterized in that: include: When a key pair update time point is reached, generating a first key pair and a first key pair version identifier of the first key pair; Obtain each stored encrypted data, where metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, where the first encapsulation key is obtained by encrypting the data encryption key corresponding to each encrypted data using the public key of the second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at the time of the previous key pair update; comparing the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and filtering out target encrypted data from each encrypted data; re-encapsulating the first encapsulation key corresponding to the target encrypted data according to the second key pair version identifier corresponding to the target encrypted data and the first key pair to obtain a second encapsulation key; The first encapsulation key in the metadata corresponding to the target encrypted data is replaced with the second encapsulation key, and the second key pair version identifier in the metadata corresponding to the target encrypted data is replaced with the first key pair version identifier.
2. The data processing method according to claim 1, wherein: The step of re-encapsulating the first encapsulation key corresponding to the target encrypted data according to the second key pair version identifier corresponding to the target encrypted data and the first key pair to obtain the second encapsulation key includes: Obtain a second key pair corresponding to the target encrypted data and a second key pair version identifier; Decapsulate the first encapsulation key using the private key of the second key pair to obtain a first data encryption key; The first data encryption key is encapsulated using the public key of the first key pair to obtain a second encapsulation key.
3. The data processing method according to claim 2, characterized in that: After replacing the second key pair version identifier in the metadata corresponding to the target encrypted data with the first key pair version identifier, the method further includes: receiving a first decapsulation request sent by a client, where the first decapsulation request carries a third encapsulation key; When the client has access rights, decapsulate the third encapsulation key using the private key of the first key pair; When the third encapsulation key is successfully decapsulated using the private key of the first key pair, obtaining a second data encryption key; The second data encryption key is sent to the client, so that the client decrypts the encrypted data using the second data encryption key to obtain the original data.
4. The data processing method according to claim 3, wherein: The method further comprises: When the third encapsulation key is not successfully decapsulated using the private key of the first key pair, decapsulating the third encapsulation key using the private key of the second key pair to obtain a second data encryption key; The second data encryption key is sent to the client, so that the client decrypts the encrypted data using the second data encryption key to obtain the original data.
5. The data processing method according to claim 2, wherein: After replacing the second key pair version identifier in the metadata corresponding to the target encrypted data with the first key pair version identifier, the method further includes: Receive a second decapsulation request sent by the client, where the second decapsulation request carries the fourth encapsulation key and the third key pair version identifier; When the third key pair version identifier is the same as the first key pair version identifier, decapsulating the fourth encapsulation key using the private key of the first key pair to obtain a third data encryption key; The third data encryption key is sent to the client, so that the client decrypts the encrypted data using the third data encryption key to obtain the original data.
6. The data processing method according to claim 5, characterized in that: The method further comprises: When the third key pair version identifier is different from the first key pair version identifier, decapsulating the fourth encapsulation key using the private key of the second key pair to obtain a third data encryption key; The third data encryption key is sent to the client, so that the client decrypts the encrypted data using the third data encryption key to obtain the original data.
7. The data processing method according to any one of claims 1 to 6, characterized in that: The first key pair version identifier is higher than the key pair version identifier of any historically generated key pair, and the comparing the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier to filter out the target encrypted data from each encrypted data includes: The second key pair version identifier corresponding to each encrypted data is compared with the first key pair version identifier, and the encrypted data whose corresponding second key pair version identifier is smaller than the first key pair version identifier is determined as the target encrypted data.
8. A data processing device, characterized in that: include: a generating unit, configured to generate a first key pair and a first key pair version identifier of the first key pair when a key pair update time point is reached; an acquiring unit, configured to acquire each stored encrypted data, wherein metadata corresponding to each encrypted data includes at least a first encapsulation key and a second key pair version identifier, wherein the first encapsulation key is obtained by encrypting a data encryption key corresponding to each encrypted data using a public key of a second key pair corresponding to the second key pair version identifier, and the second key pair is a key pair generated at a time point when the previous key pair was updated; a comparing unit, configured to compare the second key pair version identifier corresponding to each encrypted data with the first key pair version identifier, and filter out target encrypted data from each encrypted data; an encapsulation unit, configured to re-encapsulate the first encapsulation key corresponding to the target encrypted data according to the second key pair version identifier corresponding to the target encrypted data and the first key pair, to obtain a second encapsulation key; A replacing unit is configured to replace the first encapsulation key in the metadata corresponding to the target encrypted data with the second encapsulation key, and replace the second key pair version identifier in the metadata corresponding to the target encrypted data with the first key pair version identifier.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the data processing method according to any one of claims 1 to 7.
10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the data processing method according to any one of claims 1 to 7 is implemented.