Standardized interface-based cross-domain cryptographic equipment master key security synchronization method
By establishing a standardized interface and secure channel between the cryptographic device management system and the target device to generate and transmit encryption master keys, the security risks and compatibility issues in the master key synchronization process in cryptographic devices are resolved, efficient and secure cross-domain and cross-vendor master key synchronization is achieved, and master key management under multi-cloud architecture is supported.
Patent Information
- Application Number
- CN202511130529.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-13
- Publication Date
- 2025-10-10
AI Technical Summary
Existing technologies have security risks, high operational complexity, poor real-time performance, and poor compatibility in the synchronization process of master keys in cryptographic devices. It is particularly difficult to achieve efficient and secure key synchronization in cross-regional and cross-vendor environments.
A method based on standardized interfaces is adopted to generate and transmit encryption master keys by establishing a secure channel between the cryptographic device management system and the target device. The SM2 key pair and HMAC algorithm are used to ensure the security and integrity of the keys. Automatic certificate updates and management are achieved through the national secret SSL/TLS channel, supporting master key synchronization of devices from different manufacturers.
It achieves cross-domain and cross-vendor master key synchronization, reduces operation and maintenance complexity, improves system security and efficiency, supports master key management under multi-cloud architecture, ensures key security and consistency, and solves compatibility issues of heterogeneous devices.
Smart Images

Figure CN120768544A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and more particularly to a cross-domain cryptographic device master key security synchronization method based on a standardized interface. Background Art
[0002] Cryptographic devices play a vital role in modern information security systems, and are particularly widely used in encrypted communications, data protection, and identity authentication. These devices typically rely on master keys for in-device key management. However, with the increase in the number of cryptographic devices and their application scenarios, how to synchronize master keys securely, accurately, and promptly has become a critical issue that needs to be addressed. Traditional master key storage and synchronization methods typically rely on physical storage media (such as Ukey, IC cards, USB flash drives, etc.), and manually back up and restore keys to other devices. However, this approach has the following limitations:
[0003] Security risks include the risk of man-in-the-middle attacks during key transmission, as well as potential threats of key leakage and loss. Physical storage media can be easily damaged, lost, or copied, leading to the risk of key leakage. This poses a significant security risk, especially during cross-region backup and recovery.
[0004] High O&M costs and difficulty: Traditional manual synchronization increases O&M complexity, especially in large-scale distributed environments, where cross-region synchronization significantly increases labor and equipment costs. In systems with a large number of cryptographic devices, manually managing and synchronizing master keys significantly increases O&M complexity.
[0005] Poor real-time performance: Existing solutions usually cannot guarantee efficient real-time performance. In large-scale distributed systems, the delay of key synchronization affects system performance. Especially in cloud computing environments, the key synchronization delay is high, which affects system performance.
[0006] Poor compatibility: Cryptographic devices from different manufacturers lack unified interface specifications, making key synchronization impossible. Key synchronization requires manual export, conversion, and import, increasing development workload and the risk of key leaks.
[0007] Therefore, how to ensure the security and efficiency of the synchronization process while reducing the complexity of system operation and maintenance and providing a unified interface specification to support the master keys of devices from different manufacturers is an urgent problem that technicians in this field need to solve. Summary of the Invention
[0008] In view of this, the present invention provides a cross-domain cryptographic device master key security synchronization method based on a standardized interface, which can reduce the complexity of system operation and maintenance while ensuring the security and efficiency of the synchronization process, and provide a unified interface specification, thereby supporting the master keys of devices from different manufacturers.
[0009] In order to achieve the above object, the present invention adopts the following technical solutions:
[0010] A cross-domain cryptographic device master key security synchronization method based on a standardized interface includes the following steps:
[0011] S1, between the cryptographic device management system and a single target cryptographic device HSM_A, and between the cryptographic device management system and the target cryptographic device group {HSM_B1, HSM_N2, HSM_B3, ..., HSM_B n} establish secure channels between the devices;
[0012] S2. The cryptographic device management system calls the relevant interface of the target cryptographic device HSM_A based on the secure channel to generate the local master key LMK A , public symmetric key ciphertext EncSymmKey and master key integrity check value HmaxcLMK A ;
[0013] S3. The cryptographic device management system calls the relevant interfaces of each device in the target cryptographic device group based on the secure channel to generate a local temporary master key for each device. And exclusive SM2 key pair , among which, its own SM2 exclusive private key ciphertext By using a local temporary master key encryption;
[0014] S4. The cryptographic device management system transmits its own SM2 exclusive public key list of the target cryptographic device group to the target cryptographic device HSM_A. Use each device's own SM2 exclusive public key to encrypt the local master key LMK one by one A , generate an encrypted master key list And return to the password device management system;
[0015] S5. The cryptographic device management system sends a dedicated synchronization package to each device in the target cryptographic device group. The dedicated synchronization package contains: the encryption master key specific to each device Its own SM2 exclusive private key ciphertext Public symmetric key ciphertext EncSymmKey, master key integrity check value HmacLMK A ;
[0016] S6, each device checks the integrity of the main key value HmacLMK issued A If the verification is successful, the main key LMK A is written to the secure storage area, replacing the original temporary main key If the verification fails, the operation is terminated.
[0017] Further, S1 includes:
[0018] The cryptographic device is preset with an initial certificate issued by a third-party CA through a device certificate preset interface when it is shipped;
[0019] The cryptographic device management system synchronously enters the initial certificate into the trust library;
[0020] The cryptographic device management system establishes a secure channel with the cryptographic device based on the initial certificate;
[0021] The cryptographic device management system calls the cryptographic device's certificate generation request interface through the secure channel, and the cryptographic device generates an SM2 key pair and a certificate signing request (CSR);
[0022] The cryptographic device management system submits the certificate signing request (CSR) to the third-party CA, which issues an SM2 device certificate as a new certificate after verification;
[0023] The cryptographic device management system enters the new certificate into the trust library and imports the new certificate into the cryptographic device through the cryptographic device's certificate import interface via the secure channel;
[0024] The cryptographic device activates the new certificate and destroys the initial certificate, and the cryptographic device management system and the cryptographic device establish a new secure channel based on the new certificate.
[0025] Further, the secure channel established in S1 is a national SSL channel or a national TLS channel.
[0026] Further, S2 includes:
[0027] The cryptographic device management system calls the cryptographic device HSM_A's main key generation interface to generate a device local main key LMK A : LMK A = GenerateLmk(), where GenerateLmk represents the cryptographic device's interface function for generating a local main key;
[0028] The cryptographic device management system calls the cryptographic device HSM_A's external ciphertext symmetric key generation interface, and the cryptographic device HSM_A generates a temporary symmetric key SymmKey: SymmKey = GenerateSymmKey(), where GenerateSymmKey represents the cryptographic device's interface function for generating a symmetric key;
[0029] Cryptographic device HSM_A uses the local master key LMK A Encrypt the temporary symmetric key SymmKey to generate the public symmetric key ciphertext EncSymmKey and return it to the cryptographic device management system; EncSymmKey = LmkEnc(LMK A ,SymmKey), where LmkEnc represents the interface function of the cryptographic device using the local master key to encrypt the symmetric key;
[0030] The cryptographic device management system calls the HMAC calculation interface of the master key of the cryptographic device HSM_A. The cryptographic device HSM_A uses the master key LMK. A Decrypt the symmetric key ciphertext EncSymmKey to obtain the plaintext SymmKey: SymmKey=LmkDec(LMK A ,EncSymmKey), where LmkDec represents the interface function of the cryptographic device using the local master key to decrypt the symmetric key;
[0031] The cryptographic device HSM_A uses the plaintext SymmKey to calculate the local master key LMK. A HMAC value HmacLMK A , and returns to the password device management system; HmacLMK A =HMAC(LMK A ,SymmKey), where HMAC represents the interface function of the cryptographic device using the symmetric key to calculate HMAC.
[0032] Furthermore, in S3, the cryptographic device management system first calls the i-th cryptographic device HSM_B in the target cryptographic device group i Master key generation interface, cryptographic device HSM_B i Generate a local temporary master key
[0033] Then call the i-th cryptographic device HSM_B i Generate external SM2 ciphertext key interface, cryptographic device HSM_B i Generate a unique SM2 key pair And return to the password device management system; Among them, GenerateKeyPair_SM2 represents the interface function of the cryptographic device to generate an external SM2 ciphertext key.
[0034] Furthermore, S3 also includes:
[0035] The cryptographic device management system invokes a device state detection interface of each device in the target cryptographic device group in a broadcast manner, detects the device state, alarms an abnormal device and puts the abnormal device into an abnormal device group for management.
[0036] Further, in S4, the cryptographic device management system invokes an export master key interface of the target cryptographic device HSM_A to export a list of encrypted master keys, wherein an encrypted master key of a local master key of the target cryptographic device HSM_A encrypted by an SM2 private key of an i-th device in the target cryptographic device group is denoted as EncLMK (LMK, PubKey), wherein EncLMK represents an interface function of encrypting a local master key by a cryptographic device using an external public key.
[0037] Further, S6 includes:
[0038] For an i-th cryptographic device in the target cryptographic device group, the local temporary master key decrypts the SM2 private key ciphertext obtains the SM2 private key plaintext DecSM2PriKey (Ciphertext, LMK), wherein DecSM2PriKey represents an interface function of a cryptographic device for decrypting an SM2 private key ciphertext using a local master key;
[0039] decrypts the encrypted master key using the SM2 private key plaintext obtains the plaintext master key DecLMK (Ciphertext, PriKey), wherein DecLMK represents an interface function of a cryptographic device for decrypting a master key ciphertext using an SM2 private key;
[0040] decrypts the common symmetric key ciphertext EncSymmKey using the plaintext master key LMK A obtains the plaintext symmetric key SymmKey: SymmKey = DecSymmKey (EncSymmKey, LMK A ), wherein DecSymmKey represents a function interface of a cryptographic device for decrypting a symmetric key ciphertext using a master key;
[0041] calculates an HMAC value of LMK A using the plaintext symmetric key SymmKey: HmacLMK = HMAC (LMK A , SymmKey), compares the calculated HMAC value with the master key integrity check value HmacLMK A delivered by the cryptographic device management system; if they are consistent, the check is successful, the master key LMK A is written into a secure storage area to replace the original temporary master key If they are inconsistent, the verification fails, the operation is terminated and an alarm is issued.
[0042] Furthermore, S6 also includes: the cryptographic device management system calls the HMAC calculation interface of all target devices, calculates the HMAC value of the current master key, and compares it with the currently saved master key integrity check value HmacLMK A A comparison is performed. If there is any inconsistency, the retry mechanism is triggered to resynchronize the master key.
[0043] Furthermore, the method further comprises:
[0044] S7. Each cryptographic device has a master key history stack inside. When the new master key is abnormal or the historical master key needs to be restored, the cryptographic device management system calls the master key recovery interface of the cryptographic device to restore the master key to the specified historical version.
[0045] It can be seen from the above technical solutions that compared with the prior art, the present invention has the following beneficial effects:
[0046] 1. This invention can be applied in cloud environments to synchronize cryptographic device master keys across cloud environments. Alternatively, it can synchronize cryptographic device master keys between regional primary and backup centers, enabling synchronization between different cloud platforms or cloud environments. This supports enterprises' device master key management needs in multi-cloud architectures, ensuring the security and consistency of master keys. It can address security, efficiency, and scalability issues faced in the process of managing and synchronizing master keys across multiple devices in distributed environments.
[0047] 2. A set of standard interfaces is defined to quickly bring cryptographic devices from different manufacturers under management, breaking down the barriers to device management and key synchronization between cryptographic manufacturers, reducing compatibility issues between devices and manufacturers, and improving the flexibility and scalability of the cryptographic device management system. By defining a unified interface specification, an interactive bridge for cryptographic devices across manufacturers is built, enabling rapid synchronization of management instructions and device master keys between cryptographic devices of different brands, or synchronization of cryptographic device master keys between different regions or primary and backup centers. This reduces the complexity of manual configuration and management, improves operational efficiency, effectively solves the compatibility problem of heterogeneous devices, and greatly enhances the versatility and integration efficiency of the key management system.
[0048] 3. This invention addresses the conflict between initial trust and dynamic certificate updates by establishing a secure channel that complies with national cryptographic standards and enables automatic replacement of pre-configured certificates. Furthermore, through secure key transmission and management mechanisms, it effectively prevents master keys from being tampered with or leaked during transmission, thereby enhancing the overall security of the system.
[0049] 4. This invention combines the cryptographic machine's internal key encryption technology with the HMAC (Hash Message Authentication Code) algorithm to completely confine key encryption and decryption operations to the secure environment of the cryptographic machine. This design not only ensures the confidentiality of the key during transmission but also implements data integrity verification through a message authentication mechanism, comprehensively safeguarding the security of the key throughout its entire lifecycle.
[0050] 5. In response to the key anomaly problems that may occur in security incidents, the present invention has built a historical master key tracing system. When a security incident occurs, the system can quickly call the historical version key recovery mechanism to avoid business interruptions and data security risks caused by the loss of historical master keys, and realize the traceability and controllability of key use throughout the entire life cycle. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0052] Figure 1 The overall flow chart of the cross-domain cryptographic device master key security synchronization method based on the standardized interface provided by the present invention;
[0053] Figure 2 A flowchart for establishing a secure channel provided by the present invention;
[0054] Figure 3 The device master key generation flow chart provided by the present invention;
[0055] Figure 4 A flowchart of multi-device synchronization preparation in S3-S4 provided by the present invention;
[0056] Figure 5 This is a flow chart for importing and verifying the device master key in S5-S6 provided by the present invention. DETAILED DESCRIPTION
[0057] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0058] like Figure 1As shown, an embodiment of the present invention discloses a cross-domain cryptographic device master key security synchronization method based on a standardized interface, comprising the following steps:
[0059] S1, between the cryptographic device management system and a single target cryptographic device HSM_A, and between the cryptographic device management system and a group of target cryptographic devices {HSM_B1, HSM_B2, HSM_B3, ..., HSM_B n} establish secure channels between the devices;
[0060] S2. The cryptographic device management system calls the relevant interface of the target cryptographic device HSM_A based on the secure channel to generate the local master key LMK A , public symmetric key ciphertext EncSymmKey and master key integrity check value HmacLMK A ;
[0061] S3. The cryptographic device management system calls the relevant interfaces of each device in the target cryptographic device group based on the secure channel to generate a local temporary master key for each device. And exclusive SM2 key pair And return to the password device management system, including its own SM2 exclusive private key ciphertext By using a local temporary master key encryption;
[0062] S4. The cryptographic device management system transmits its own SM2 exclusive public key list of the target cryptographic device group to the target cryptographic device HSM_A. Use each device's own SM2 exclusive public key to encrypt the local master key LMK one by one A , generate an encrypted master key list And return to the password device management system;
[0063] S5. The cryptographic device management system sends a dedicated synchronization package to each device in the target cryptographic device group. The dedicated synchronization package contains: the encryption master key specific to each device Its own SM2 exclusive private key ciphertext Public symmetric key ciphertext EncSymmKey, master key integrity check value HmacLMK A ;
[0064] S6. Each device verifies the integrity of the master key HmacLMK A Perform verification. If the verification is successful, the master key LMK A Write to the secure storage area to replace the original temporary master key If the verification fails, the operation is terminated.
[0065] The above steps of the present invention are further described below.
[0066] S1. Establishment of a secure channel. The "bootstrapping-update-switching" closed loop of certificates is achieved through a dual secure channel. This is accomplished collaboratively by the Cryptographic Device Management System (CDMS), Cryptographic Device (HSM) and a third-party CA. The detailed steps are as follows: Figure 2 As shown, the details are as follows:
[0067] Initialization phase: When the cryptographic device leaves the factory, the initial certificate issued by the third-party CA is preset through the device certificate preset interface; the cryptographic device management system simultaneously enters the initial certificate into the trust store.
[0068] Initial channel establishment: The cryptographic device management system establishes a national secret SSL channel or a national secret TLS security channel based on the initial certificate and the cryptographic device.
[0069] Certificate request generation: The cryptographic device management system calls the certificate request generation interface of the cryptographic device through a secure channel, and the cryptographic device generates an SM2 key pair and a certificate signing request CSR.
[0070] Issuing a new certificate: The cryptographic device management system submits the certificate signing request (CSR) to a third-party CA. After verification, the third-party CA issues the SM2 device certificate as a new certificate.
[0071] New certificate deployment: The cryptographic device management system enters the new certificate into the trust store and calls the cryptographic device certificate import interface through a secure channel to import the new certificate into the cryptographic device.
[0072] Trust chain switching: The cryptographic device activates the new certificate and destroys the initial certificate. A new secure channel is established between the cryptographic device management system and the cryptographic device based on the new certificate.
[0073] Security management: Remote device management, key management, and cryptographic operations are achieved through the new national secret SSL / TLS channel.
[0074] S2, device master key generation, such as Figure 3 The detailed steps are as follows:
[0075] S21. Establishment of secure channel: The device management system (CDMS) and the target cryptographic device (HSM_A) establish a secure channel based on the national cryptographic SSL.
[0076] S22. Master key generation:
[0077] The cryptographic device management system calls the master key generation interface of the cryptographic device HSM_A to generate the device local master key LMK A :LMK A =GenerateLmk(), where GenerateLmk represents the cryptographic device generating a local master key interface function;
[0078] S23. Symmetric key (ciphertext key) generation:
[0079] The cryptographic device management system calls the external ciphertext symmetric key generation interface of the cryptographic device HSM_A. The cryptographic device HSM_A generates a temporary symmetric key SymmKey: SymmKey = GenerateSymmKey(), where enerateSymmKey represents the interface function for the cryptographic device to generate a symmetric key.
[0080] Cryptographic device HSM_A uses the local master key LMK A Encrypt the temporary symmetric key SymmKey to generate the public symmetric key ciphertext EncSymmKey and return it to the cryptographic device management system; EncSymmKey = LmkEnc(LMK A ,SymmKey), where LmkEnc represents the interface function of the cryptographic device using the local master key to encrypt the symmetric key;
[0081] S24. Master key integrity protection:
[0082] The cryptographic device management system calls the HMAC calculation interface of the master key of the cryptographic device HSM_A. The cryptographic device HSM_A uses the master key LMK. A Decrypt the symmetric key ciphertext EncSymmmKey to obtain the plaintext SymmKey: SymmKey=LmkDec(LMK A ,EncSymmKey), where LmkDec represents the interface function of the cryptographic device using the local master key to decrypt the symmetric key;
[0083] The cryptographic device HSM_A uses the plaintext SymmKey to calculate the local master key LMK. A HMAC value HmacLMK A , and returns to the password device management system; HmacLMK A =HMAC(LMK A ,SymmKey), where HMAC represents the interface function of the cryptographic device using the symmetric key to calculate HMAC.
[0084] S3, local temporary master key generation, such as Figure 4 As shown, specifically including:
[0085] S31, equipment status detection:
[0086] The cryptographic device management system and the target cryptographic device group {HSM_B1, HSM_B2, HSM_B3, ..., HSM_B n}Establish secure channels respectively.
[0087] The cryptographic device management system calls the target cryptographic device group {HSM_B1, HSM_B2, HSM_B3, ..., HSM_B n}The device status detection interface of each device in the system detects the device status, issues alarms for abnormal devices and puts them into the abnormal device group for management.
[0088] S32. Generate a temporary master key:
[0089] The cryptographic device management system calls the i-th cryptographic device HSM_B in the target cryptographic device group i Master key generation interface, cryptographic device HSM_B i Generate a local temporary master key
[0090] S33. Generate a dedicated SM2 key pair:
[0091] The cryptographic device management system calls the i-th cryptographic device HSM_B i Generate external SM2 ciphertext key interface, cryptographic device HSM_B i Generate a unique SM2 key pair And return to the password device management system; Among them, GenerateKeyPair_SM2 represents the interface function of the cryptographic device to generate an external SM2 ciphertext key.
[0092] S4, encapsulate and distribute the master key, such as Figure 4 As shown, specifically including:
[0093] The cryptographic device management system calls the export master key interface of the target cryptographic device HSM_A and passes the SM2 exclusive public key list of the target cryptographic device group to the cryptographic device HSM_A. Use each Encrypt LMK one by one A , generate an encrypted master key list
[0094] The encrypted master key obtained by encrypting the local master key of the target cryptographic device HSM_A with the SM2 exclusive public key of the i-th device in the target cryptographic device group is expressed as EncLMK represents the interface function that the cryptographic device uses to encrypt the local master key using an external public key.
[0095] S5. Send the exclusive synchronization package, and the cryptographic device management system calls each target cryptographic device HSM_B iImport device master key interface, send its exclusive synchronization package, exclusive synchronization package contains: each device's exclusive encryption master key Its own SM2 exclusive private key ciphertext Public symmetric key ciphertext EncSymmKey, master key integrity check value HmacLMK A .
[0096] S6. Import and verification of device master key, such as Figure 5 As shown, specifically including:
[0097] S61, for the i-th cryptographic device in the target cryptographic device group, use the local temporary master key Decrypt your own SM2 exclusive private key ciphertext Get the SM2 private key plaintext
[0098] Among them, DecSM2PriKey represents the interface function of the cryptographic device using the local master key to decrypt the SM2 private key ciphertext.
[0099] S62, using SM2 private key plaintext Decrypting the encrypted master key Obtain the plaintext master key LMK A :
[0100] Among them, DecLMK represents the interface function of the cryptographic device using the SM2 private key to decrypt the master key ciphertext.
[0101] S63, using the plaintext master key LMK A Decrypt the public symmetric key ciphertext EncSymmKey to obtain the plaintext symmetric key SymmKey:
[0102] SymmKey=DecSymmKey(EncSymmKey,LMK A ), DecSymmKey represents the function interface of the cryptographic device using the master key to decrypt the symmetric key ciphertext.
[0103] S64. Calculate LMK using the plaintext symmetric key SymmKey A The HMAC value:
[0104] HmacLMK=HMAC(LMK A ,SymmKey).
[0105] S65, the calculated HMAC value and the issued master key integrity check value HmacLMK A Compare; if they are consistent, the verification is successful and the master key LMK AWrite to the secure storage area to replace the original temporary master key If they are inconsistent, the verification fails, the operation is terminated and an alarm is issued.
[0106] In other embodiments, S6 also includes: auditing the master key HAMC value of all current target devices, specifically: the cryptographic device management system calls the HMAC calculation interface of all target devices, calculates the HMAC value of the current master key, and compares it with the currently saved master key integrity check value HmacLMK A A comparison is performed. If there is any inconsistency, the retry mechanism is triggered to resynchronize the master key.
[0107] More advantageously, the method further comprises:
[0108] S7. Historical key management:
[0109] Each cryptographic device has a master key history stack, which includes the following fields: current key version, key HMAC value, master key value, status flag (active / history), timestamp (active / history), old version, and old key HMAC value.
[0110] If the new master key is abnormal or a historical master key needs to be restored, the cryptographic device management system calls the master key recovery interface of the cryptographic device to restore the master key to a specified historical version. The cryptographic device uses the historical HMAC value to guide the specified historical key version, verify the integrity of the old key, and switch the current master key to a valid historical version.
[0111] The application scenarios of the present invention are: suitable for master key update scenarios of cryptographic devices such as financial multi-center disaster recovery, government cloud password pool synchronization, Internet of Things security gateway clusters, and disaster recovery centers. The following two specific implementation scenarios will further illustrate the method of the present invention.
[0112] Scenario 1: Master key synchronization across cloud cryptographic devices The specific steps are as follows:
[0113] 1. Participants:
[0114] HUAWEI CLOUD: Deploy cryptographic device HSM_A (manufacturer X) and the unified cryptographic device management system CDMS.
[0115] Alibaba Cloud: Deploy cryptographic device HSM_B (manufacturer Y).
[0116] 2. Achieve the following goals: Manage heterogeneous devices (manufacturer X / Y); automatically synchronize master keys across clouds; and support cross-cloud encryption interoperability (Huawei Cloud encryption → Alibaba Cloud decryption).
[0117] 3. Optimization implementation steps:
[0118] (1) Password device management authentication:
[0119] 1) The password device HSM_A and HSM_B registers with the password device management system CDMS through a standard access interface.
[0120] 2) The password device management system CDMS imports the device certificate through the password device certificate application request interface, and updates and replaces the pre-stored certificate in the password device with the new certificate issued by the CA.
[0121] 3) The CDMS and the password device HSM_A and HSM_B establish a national SSL / TLS channel based on the new certificate.
[0122] (2) Master key generation and protection:
[0123] 4) The CDMS calls the master key generation interface of the password device HSM_A, the external ciphertext symmetric key generation interface, and the HMAC calculation interface, to obtain the ciphertext symmetric key EncSymmKey and the master key HmacLMK of the password device HSM_A. A ;
[0124] 5) The CDMS calls the master key generation interface and the external SM2 ciphertext key generation interface of the password device HSM_B, to obtain the SM2 key pair PubKey_b, EbcPriKey_B specific to the password device HSM_B.
[0125] (3) Master key automatic synchronization:
[0126] 6) The CDMS calls the export master key interface of the password device MSM_A, and inputs the SM2 public key PubKey_B generated by the password device HSM_B, to export the SM2 public key encrypted master key EncLMK A_B .
[0127] 7) The CDMS calls the import device master key interface of the password device HSM_B, and issues its exclusive synchronization package, which contains: {the encrypted master key EncLMK A_B specific to the device, the SM2 ciphertext private key (protected by LMK B ) EncPriKey B , the common symmetric key ciphertext EncSymmKey, and the master key integrity verification value HmacLMK A}, and the device HSM_B replaces the local master key with the imported master key LMK A .
[0128] The above operations complete the master key synchronization of the password devices HSM_A and HSM_B.
[0129] (4) Cross-cloud cryptographic service interoperability:
[0130] 1) Encryption scenario: The Huawei cloud service system calls the data encryption interface of the cryptographic device HSM_A to generate ciphertext data.
[0131] 2) Decryption scenario: The Ali cloud service system decrypts the ciphertext data through the data decryption interface of HSM_B.
[0132] Scenario two: Regional disaster recovery center switching
[0133] 1. Participants:
[0134] Main center (A place): cryptographic device cluster {HSM_A1, HSM_A2, HSM_A3, …, HSM_A n}, cryptographic device management system CDMS_P.
[0135] Backup center (B place): cryptographic device cluster {HSM_B1, HSM_B2, HSM_B3, …, HSM_B n}, cryptographic device management system CDMS_S.
[0136] 2. Implementation goal: Realize automatic synchronization of master keys of cryptographic devices within the center; realize automatic synchronization of master keys of cryptographic devices between the main and backup centers; realize high availability of business between the main and backup centers.
[0137] 3. Optimization implementation steps:
[0138] (1) Main and backup center cryptographic device management authentication:
[0139] 1) The cryptographic device management system CDMS_P of the main center completes the management of the cryptographic devices {HSM_A1, HSM_A2, HSM_A3, …, HSM_A n} within the center by calling the standard access interface, certificate application request interface, and device certificate import interface.
[0140] 2) The cryptographic device management system CDMS_S of the backup center completes the management of the cryptographic devices {HSM_B1, HSM_B2, HSM_B3, …, HSM_B n} within the center by calling the standard access interface, certificate application request interface, and device certificate import interface.
[0141] (2) Main center device master key generation and device master key synchronization
[0142] 3) The cryptographic device management system CDMS_P invokes the master key generation interface, the external symmetric key generation interface and the HMAC calculation interface of the cryptographic device HSM_A1, to obtain the master key LMK A , the symmetric key EncSymmKey and the master key HMAC value HmacLMK A of the cryptographic device HSM_A1, respectively.
[0143] 4) The cryptographic device management system CDMS_P completes the master key synchronization of the cryptographic devices {HSM_A2, HSM_A3, …, HSM_A n} in the center according to the device master key synchronization process described above.
[0144] (3) Master-slave center device master key synchronization
[0145] 5) The slave center CDMS_S invokes the master key generation interface and the external SM2 key generation interface of the current cryptographic device HSM_B1, to obtain the local temporary master key and the SM2 key pair (PubKey_B1, EncPriKey_B1) of the cryptographic device HSM_B1.
[0146] 6) The master center CDMS_P transmits PubKey_B1 to the slave center cryptographic device HSM_B by invoking the derived master key interface of the cryptographic device HSM_A1, to derive the SM2 public key encrypted master key
[0147] 7) The master center transmits the SM2 public key encrypted master key , the common symmetric key ciphertext EncSymmKey and the master key integrity check value HmacLMK A to the slave center through a dedicated channel.
[0148] 8) The slave center CDMS_S invokes the imported device master key interface of the cryptographic device HSM_B1, to issue its dedicated synchronization package, which contains: {the encrypted master key of the device, the SM2 private key ciphertext (protected by LMK B ) EncPriKey_B1, the common symmetric key ciphertext EncSymmKey and the master key integrity check value HmacLMK A}, and the device HSM_B1 replaces the local master key with the imported master key LMK A .
[0149] (4) Slave center device master key synchronization
[0150] The password device management system CDMS_S of the backup center is centered on the password device HSM_B1 with the current synchronized master key, and the password device master key LMK A According to the above device master key synchronization process, the master key synchronization of the password devices {HSM_B2, HSM_B3, …, HSM_B n} in the backup center is completed.
[0151] The above operation completes the device master key synchronization of the password machine cluster between the primary and backup centers.
[0152] (5) Primary and backup center service switching: when the service center of the primary center occurs an exception, the service system can be migrated to the backup center to realize the high availability of the primary and backup center services.
[0153] The embodiments in the specification are described in a progressive manner, and each embodiment focuses on the difference from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed by the embodiments, since it corresponds to the method disclosed by the embodiments, the description is relatively simple, and the related parts can be referred to the method part.
[0154] The above description of the disclosed embodiments enables a person skilled in the art to implement or use the present application. Various modifications to the embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A cross-domain cryptographic device master key security synchronization method based on a standardized interface, characterized in that: The following steps are involved: S1, between the cryptographic device management system and a single target cryptographic device HSM_A, and between the cryptographic device management system and the target cryptographic device group {HSM_B1, HSM_N2, HSM_B3, ..., HSM_B n } establish secure channels between the devices; S2. The cryptographic device management system calls the relevant interface of the target cryptographic device HSM_A based on the secure channel to generate the local master key LMK A , public symmetric key ciphertext EncSymmKey and master key integrity check value HmaxcLMK A ; S3. The cryptographic device management system calls the relevant interfaces of each device in the target cryptographic device group based on the secure channel to generate a local temporary master key for each device. And exclusive SM2 key pair Among them, its own SM2 exclusive private key ciphertext By using a local temporary master key encryption; S4. The cryptographic device management system transmits its own SM2 exclusive public key list of the target cryptographic device group to the target cryptographic device HSM_A. Use each device's own SM2 exclusive public key to encrypt the local master key LMK one by one A , generate an encrypted master key list And return to the password device management system; S5. The cryptographic device management system sends a dedicated synchronization package to each device in the target cryptographic device group. The dedicated synchronization package contains: the encryption master key specific to each device Its own SM2 exclusive private key ciphertext Public symmetric key ciphertext EncSymmKey, master key integrity check value HmacLMK A ; S6. Each device verifies the integrity of the master key HmacLMK A Perform verification. If the verification is successful, the master key LMK A Write to the secure storage area to replace the original temporary master key If the verification fails, the operation is terminated.
2. The cross-domain cryptographic device master key security synchronization method based on a standardized interface according to claim 1 is characterized in that: S1 includes: When the cryptographic device leaves the factory, the initial certificate issued by the third-party CA is preset through the device certificate preset interface; The cryptographic device management system simultaneously enters the initial certificate into the trust store; The cryptographic device management system establishes a secure channel with the cryptographic device based on the initial certificate; The cryptographic device management system calls the certificate request generation interface of the cryptographic device through a secure channel, and the cryptographic device generates an SM2 key pair and a certificate signing request CSR; The cryptographic device management system submits the certificate signing request (CSR) to the third-party CA. After verification, the third-party CA issues the SM2 device certificate as a new certificate. The cryptographic device management system enters the new certificate into the trust store and calls the cryptographic device certificate import interface through a secure channel to import the new certificate into the cryptographic device; The cryptographic device activates the new certificate and destroys the initial certificate. A new secure channel is established between the cryptographic device management system and the cryptographic device based on the new certificate.
3. The cross-domain cryptographic device master key security synchronization method based on a standardized interface according to claim 1 is characterized in that: The secure channel established in S1 is a national secret SSL channel or a national secret TLS channel.
4. The cross-domain cryptographic device master key security synchronization method based on a standardized interface according to claim 1, characterized in that S2 include: The cryptographic device management system calls the master key generation interface of the cryptographic device HSM_A to generate the device local master key LMK A :LMK A =GenerateLmk(), where GenerateLmk represents the cryptographic device generating a local master key interface function; The cryptographic device management system calls the external ciphertext symmetric key generation interface of the cryptographic device HSM_A. The cryptographic device HSM_A generates a temporary symmetric key SymmKey: SymmKey = GenerateSymmKey(), where GenerateSymmKey represents the interface function for the cryptographic device to generate a symmetric key. Cryptographic device HSM_A uses the local master key LMK A Encrypt the temporary symmetric key SymmKey to generate the public symmetric key ciphertext EncSymmKey and return it to the cryptographic device management system; EncSymmKey = LmkEnc(LMK A ,SymmKey), where LmkEnc represents the interface function of the cryptographic device using the local master key to encrypt the symmetric key; The cryptographic device management system calls the HMAC calculation interface of the master key of the cryptographic device HSM_A. The cryptographic device HSM_A uses the master key LMK. A Decrypt the symmetric key ciphertext EncSymmKey to obtain the plaintext SymmKey: SymmKey=LmkDec(LMK A ,EncSymmKey), where LmkDec represents the interface function of the cryptographic device using the local master key to decrypt the symmetric key; The cryptographic device HSM_A uses the plaintext SymmKey to calculate the local master key LMK. A HMAC value HmacLMK A , and returns to the password device management system; HmacLMK A =HMAC(LMK A ,SymmKey), where HMAC represents the interface function of the cryptographic device using the symmetric key to calculate HMAC.
5. The cross-domain cryptographic device master key security synchronization method based on a standardized interface according to claim 4 is characterized in that: In S3, the cryptographic device management system first calls the i-th cryptographic device HSM_B in the target cryptographic device group. i Master key generation interface, cryptographic device HSM_B i Generate a local temporary master key Then call the i-th cryptographic device HSM_B i Generate external SM2 ciphertext key interface, cryptographic device HSM_B i Generate a unique SM2 key pair And return to the password device management system; Among them, GenerateKeyPair_SM2 represents the interface function of the cryptographic device to generate an external SM2 ciphertext key.
6. The cross-domain cryptographic device master key security synchronization method based on a standardized interface according to claim 1 is characterized in that: S3 also includes: The cryptographic device management system calls the device status detection interface of each device in the target cryptographic device group in the form of broadcast, detects the device status, issues alarms for abnormal devices and puts them into the abnormal device group for management.
7. The cross-domain cryptographic device master key security synchronization method based on a standardized interface according to claim 5 is characterized in that: In S4, the cryptographic device management system calls the export master key interface of the target cryptographic device HSM_A to export the encrypted master key list, where the encrypted master key obtained by encrypting the local master key of the target cryptographic device HSM_A with the SM2 exclusive public key of the i-th device in the target cryptographic device group is expressed as EncLMK represents the interface function that the cryptographic device uses to encrypt the local master key using an external public key.
8. The cross-domain cryptographic device master key security synchronization method based on a standardized interface according to claim 1, characterized in that S6 include: For the i-th cryptographic device in the target cryptographic device group, use the local temporary master key Decrypt your own SM2 exclusive private key ciphertext Get the SM2 private key plaintext Among them, DecSM2PriKey represents the interface function of the cryptographic device using the local master key to decrypt the SM2 private key ciphertext; Using SM2 private key plaintext Decrypting the encrypted master key Obtain the plaintext master key Among them, DecLMK represents the interface function of the cryptographic device using the SM2 private key to decrypt the master key ciphertext; Using the plaintext master key LMK A Decrypt the public symmetric key ciphertext EncSymmKey to obtain the plaintext symmetric key SymmKey: SymmKey=DecSymmKey(EncSymmKey,LMK A ), DecSymmKey represents the function interface of the cryptographic device using the master key to decrypt the symmetric key ciphertext; Calculate LMK using the plaintext symmetric key SymmKey A HMAC value: HmaccLMK = HMAC(LMK A ,SymmKey), the calculated HMAC value and the issued master key integrity check value HmacLMK A Compare; if they are consistent, the verification is successful and the master key LMK A Write to the secure storage area to replace the original temporary master key If they are inconsistent, the verification fails, the operation is terminated and an alarm is issued.
9. The cross-domain cryptographic device master key security synchronization method based on a standardized interface according to claim 8 is characterized in that: S6 also includes: the cryptographic device management system calls the HMAC calculation interface of all target devices, calculates the HMAC value of the current master key, and compares it with the currently saved master key integrity check value HmacLMK A A comparison is performed. If there is any inconsistency, the retry mechanism is triggered to resynchronize the master key.
10. The cross-domain cryptographic device master key security synchronization method based on a standardized interface according to claim 1 is characterized in that: The method further includes: S7. Each cryptographic device has a master key history stack inside. When the new master key is abnormal or the historical master key needs to be restored, the cryptographic device management system calls the master key recovery interface of the cryptographic device to restore the master key to the specified historical version.
Citation Information
Cited By
Cryptographic operation device control method and electronic equipment
CN121396458A