A cloud password service management system and an application method, medium and device thereof
By virtualizing physical cryptographic cards into virtual cryptographic cards in a cloud environment and providing isolated management and business networks in a private cloud, the limitations and security risks of deploying commercial cryptographic services in a cloud environment are solved, enabling flexible cryptographic service management and efficient resource utilization.
Patent Information
- Application Number
- CN202511308698.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-15
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2045-09-15
AI Technical Summary
In existing technologies, the deployment of commercial cryptography services in cloud environments is limited, failing to fully leverage the flexibility and scalability of cloud computing. Furthermore, due to insufficient network isolation, there are issues of security risks and high management complexity.
By isolating the management and business networks, a cloud-based cryptographic service management system is provided. Through virtualization technology, physical cryptographic cards are virtualized into virtual cryptographic cards, and cryptographic services are provided in a private cloud, thereby achieving isolation between the management network and the business network and improving system security and flexibility.
It enables flexible deployment and efficient management of cryptographic services in the cloud environment, improves system security and resource utilization, and reduces management complexity and cost.
Smart Images

Figure CN120825339B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of password management, in particular to a cloud password service management system and an application method, a medium and an equipment thereof. BACKGROUND
[0002] In the prior art, commercial secret services usually need to install password cards on their respective host machines to realize encryption capabilities. At the same time, there is no clear network isolation configuration between the password service management platform and the cloud server password machine, VSM (Virtual Security Module) and commercial secret services, and they may run in the same network environment.
[0003] Since commercial secret services need to install password cards on host machines, this makes the deployment of commercial secret services highly dependent on physical hardware devices. In a complex cloud environment, password cards cannot be installed in virtual machines, which limits the deployment and application of commercial secret services in the cloud environment and cannot fully exert the flexibility and scalability of cloud computing. At the same time, there is no effective network isolation between the password service management platform, the cloud server password machine, the VSM and the commercial secret services, which easily leads to security risks, such as mutual interference or network attacks between different services, thereby affecting the security of the entire system. In the case of insufficient network isolation, sensitive data and encryption operations may face a higher risk of leakage. In addition, each commercial secret service needs to be installed with a password card on its respective host machine, which means that each service needs to be configured and managed separately. This decentralized management mode increases the complexity and cost of management, and also reduces the maintainability and scalability of the system, making it difficult to realize centralized management and unified scheduling. SUMMARY
[0004] The purpose of the present application is to provide a cloud password service management system, a cloud password service application method, a computer readable storage medium and an electronic equipment, which realizes the isolation of the management network and the business network and improves the security of the system.
[0005] To solve the above technical problems, the present application provides a cloud password service management system, and the specific technical solutions are as follows:
[0006] A password service platform is configured to manage a management network and a business network, and to manage a first virtual machine and a second virtual machine. The management network is a network for managing a cloud server password machine and a virtual machine. The business network is a network isolated from the management network and used for processing business operations.
[0007] A private cloud includes the first virtual machine running an elastic cloud server. The first virtual machine is used to provide password services, and each virtual machine is isolated from each other.
[0008] The cloud server cryptomachine comprises a physical cryptographic card and the second virtual machine, and is used for virtualizing the physical cryptographic card into a virtual cryptographic card, and the virtual cryptographic card is used for providing encryption and decryption resources for the second virtual machine.
[0009] Optionally, the cryptographic service platform comprises:
[0010] a gateway and a cryptographic agent component; the gateway is used for configuring the service network; the cryptographic agent component comprises a first network card and a second network card, the first network card is used for receiving configuration information issued by the cryptographic service platform via a management network, and the second network card is used for accessing the service network.
[0011] Optionally, the gateway comprises a first gateway and a second gateway;
[0012] the first gateway is used for forwarding the cryptographic service application request to the first virtual machine on the private cloud after the cryptographic service application request is authenticated and passed.
[0013] the second gateway is used for forwarding the cryptographic service application request issued by the first virtual machine to the second virtual machine after at least one of the following configurations is performed: master-slave configuration, agent configuration and load balancing configuration.
[0014] Optionally, the cryptographic service platform further comprises:
[0015] a key management system, which is used for synchronizing a newly added key corresponding to a key addition event or an updated key corresponding to a key update event to the second virtual machine on the cloud server cryptomachine when the key addition event or the key update event is generated by the first virtual machine.
[0016] Optionally, the private cloud further comprises:
[0017] a server monitoring module, which is used for monitoring running states of the cryptographic agent component and the first virtual machine, and issuing a configuration file used for defining corresponding running parameters of the first virtual machine.
[0018] Optionally, the server monitoring module is provided with an external virtual address, and internally comprises at least two cryptographic agent components, which are used for switching to a standby cryptographic agent component when a main cryptographic agent component fails.
[0019] Optionally, the cryptographic service platform is further used for dividing the service network into a plurality of regional service networks, and a virtual local area network is used for allocating a unique port identifier to each of the regional service networks; wherein the cryptographic agent component and the second virtual machine respectively exist in corresponding regional service networks.
[0020] When the password service platform and the second virtual machine perform service network communication, the password service platform is configured to configure a Vlan policy on a three-layer switch network port, determine a first network port corresponding to the password agent component and a second network port corresponding to the second virtual machine, and configure a switch port connecting the password agent component and the second virtual machine as a trunk port mode to allow traffic of the first network port and the second network port to interact via the trunk port.
[0021] The application also provides a cloud password service application method based on the cloud password service management system, and the specific technical solutions are as follows:
[0022] The private cloud receives a commercial secret application request through a service network.
[0023] The commercial secret application request is parsed to determine a password service type corresponding to the commercial secret application request.
[0024] The commercial secret application request is forwarded to a first virtual machine corresponding to the password service type.
[0025] After the first virtual machine forwards the commercial secret application request to a second virtual machine, a physical password card in a cloud server password machine is called to allocate corresponding encryption and decryption resources to the second virtual machine to respond to the commercial secret application request.
[0026] The application also provides a computer readable storage medium having a computer program stored thereon, and the computer program is executed by a processor to implement the steps of the method.
[0027] The application also provides an electronic device including a memory and a processor, and the memory has a computer program stored therein, and the processor calls the computer program in the memory to implement the steps of the method.
[0028] The application provides a cloud password service management system, including: a password service platform configured to manage a management network and a service network, and manage a first virtual machine and a second virtual machine; the management network is a network for managing a cloud server password machine and virtual machines; the service network is a network isolated from the management network and used for processing business operations; a private cloud containing the first virtual machine running an elastic cloud server; the first virtual machine is configured to provide password services, and the virtual machines are isolated from each other; a cloud server password machine containing a physical password card and the second virtual machine, the cloud server password machine is configured to virtualize the physical password card into a virtual password card, and the virtual password card is configured to provide encryption and decryption resources for the second virtual machine.
[0029] The application isolates the management network from the service network, which can effectively improve the security of the system. The management network is used for managing the cloud server password machine and virtual machine, and the service network is used for processing specific business operations. The two are independent of each other, which ensures the stability of the entire system management function, avoids the loss of control of password service management due to network chaos, and ensures the reliability and security of the password service. In a private cloud environment, the first virtual machine is used to provide password service, which makes the deployment of password service more flexible. It is convenient to adjust and expand the first virtual machine according to business needs, such as increasing or reducing the number of virtual machines, adjusting resource configuration, etc., to adapt to different scales of password service requirements. At the same time, the virtual machines are isolated from each other, avoiding the spread of security risks and ensuring the security of the password service in the entire private cloud environment. The cloud server password machine includes a physical password card and a second virtual machine, and can virtualize the physical password card into a virtual password card to provide encryption and decryption resources for the second virtual machine. The utilization rate of the physical password card is improved, so that limited physical resources can serve multiple virtual machines in a more flexible way, improving the use efficiency of resources. At the same time, the virtual password card provides encryption and decryption resources for the second virtual machine, so that the encryption and decryption operation can be carried out more efficiently, meeting the business requirements for password service performance, and better adapting to the dynamic changes of business requirements, providing an efficient, flexible and secure operation environment for the entire password service management system.
[0030] The application also provides a cloud password service application method, a computer readable storage medium and an electronic device, which have the above beneficial effects, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0031] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description only belong to the embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of the provided drawings.
[0032] Figure 1 A structural schematic diagram of a cloud password service management system provided by an embodiment of the application;
[0033] Figure 2 A structural schematic diagram of another cloud password service management system provided by an embodiment of the application;
[0034] Figure 3 A flowchart of a cloud password service application method provided by an embodiment of the application. DETAILED DESCRIPTION
[0035] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0036] Referring to Figure 1 , Figure 1 A structural schematic diagram of a cloud-based password service management system provided by the embodiments of the present application is shown in the figure. The system comprises:
[0037] A password service platform is configured to manage a management network and a business network, and manage a first virtual machine and a second virtual machine. The management network is a network for managing cloud server password machines and virtual machines. The business network is isolated from the management network and is used for processing business operations.
[0038] A private cloud comprises the first virtual machine running an elastic cloud server. The first virtual machine is used to provide password services, and each of the virtual machines is isolated from each other.
[0039] A cloud server password machine comprises a physical password card and the second virtual machine. The cloud server password machine is used to virtualize the physical password card into a virtual password card, and the virtual password card is used to provide encryption and decryption resources for the second virtual machine.
[0040] The cloud-based password service management system disclosed in the embodiments comprises a password service platform, a management network, a business network, a first virtual machine in a private cloud and a second virtual machine in a cloud server password machine. The password service platform is configured to manage the management network and the business network, and manage the first virtual machine and the second virtual machine. The management network is used to manage cloud server password machines and virtual machines. The business network is isolated from the management network and is used to process business operations. The first virtual machine provides password services in the private cloud, and each of the virtual machines is isolated from each other. The cloud server password machine virtualizes the physical password card into a virtual password card, and provides encryption and decryption resources for the second virtual machine.
[0041] The management network is a network specially used for managing cloud server password machines and virtual machines. It is responsible for carrying all communications and operations related to system management, including but not limited to configuration of cloud server password machines, state monitoring, and transmission of management instructions such as starting, stopping and resource allocation of the first virtual machine and the second virtual machine. Through strict access control strategies and identity authentication mechanisms, only authorized administrators and system components can access the management network, thereby ensuring the security and reliability of the management operations.
[0042] The business network is isolated from the management network and is mainly used for processing business operations. The isolation design is to prevent business data from being affected by potential security threats in the management network during transmission and processing, and also to avoid unnecessary impact of management operations on business processing performance. The business network connects various business systems and applications that need to use password services. The business systems interact with the first virtual machine through the business network to obtain the required password services, such as data encryption, decryption, digital signature verification, etc. By using different network devices, network address segments, and strict access control policies, the communication between the management network and the business network is completely isolated. Data packets in the management network cannot directly enter the business network, and vice versa, thereby preventing potential risks that management operations may cause to business data, and also avoiding the impact of business data leakage or tampering on management operations.
[0043] The private cloud is the core infrastructure of the cloud-based password service management system and is used to provide a running environment for elastic cloud servers, including the first virtual machine for providing password services. The private cloud has high flexibility and scalability, and can dynamically adjust resource allocation according to business needs to ensure efficient and stable operation of password services. The first virtual machine runs in the private cloud and fully utilizes the computing, storage, and network resources of the private cloud through virtualization technology to provide reliable password services for business systems in the business network. For example, when the business load increases, the private cloud can automatically allocate more computing resources to the first virtual machine according to the preset strategy to meet the business requirements for password service performance. In addition, the private cloud can use security components such as firewalls and intrusion detection systems to strictly filter and monitor network traffic entering the private cloud to prevent malicious attacks from damaging the first virtual machine.
[0044] The first virtual machine is a key component in the private cloud and is mainly used to provide password services. It runs on the elastic cloud server of the private cloud and is tightly integrated with other resources of the private cloud through virtualization technology, which can efficiently utilize the hardware resources of the private cloud. The first virtual machine can deploy password service software and support multiple encryption algorithms (such as AES, RSA, etc.), hash algorithms, and digital signature algorithms, etc. The business systems in the business network communicate with the first virtual machine through the business network and send data that needs to be processed to the first virtual machine. The first virtual machine calls the password service software to perform corresponding password operations on the data according to the request of the business system, such as encryption, decryption, digital signature generation, etc., and returns the processing result to the business system.
[0045] The cloud server cryptomachine comprises a physical cryptographic card and a second virtual machine. The physical cryptographic card is a hardware device specially used for cryptographic operation, which integrates multiple cryptographic algorithm hardware implementations inside and can quickly and efficiently complete complex cryptographic operation tasks such as key generation, encryption and decryption operation, digital signature generation and verification. The cloud server cryptomachine virtualizes the physical cryptographic card into a virtual cryptographic card through virtualization technology, so that the second virtual machine can use the virtual cryptographic card like using the physical cryptographic card, and provides encryption and decryption resources for the second virtual machine. The second virtual machine can run various application programs that need to use cryptographic services, and complete its own cryptographic processing requirements by calling the interface provided by the virtual cryptographic card and using the physical cryptographic card behind the virtual cryptographic card.
[0046] The embodiment of the application isolates the management network from the service network, which can effectively improve the security of the system. The management network is specially used for management operations on the cloud server cryptomachine and virtual machines, while the service network focuses on handling specific business operations. The two are independent of each other, ensuring the stability of the entire system management function, avoiding the loss of control of cryptographic service management due to network chaos, and ensuring the reliability and security of the cryptographic service. In a private cloud environment, the first virtual machine is used to provide cryptographic services, making the deployment of cryptographic services more flexible. It is convenient to adjust and expand the first virtual machine according to business needs, such as increasing or decreasing the number of virtual machines, adjusting resource configuration, etc., to adapt to different scales of cryptographic service requirements. At the same time, the virtual machines are isolated from each other, avoiding the spread of security risks and ensuring the security of the cryptographic service in the entire private cloud environment. The cloud server cryptomachine comprises a physical cryptographic card and a second virtual machine, and can virtualize the physical cryptographic card into a virtual cryptographic card to provide encryption and decryption resources for the second virtual machine. This improves the utilization rate of the physical cryptographic card, so that limited physical resources can serve multiple virtual machines in a more flexible way, improving the use efficiency of resources. At the same time, the virtual cryptographic card provides encryption and decryption resources for the second virtual machine, so that encryption and decryption operations can be performed more efficiently, meeting the business requirements for cryptographic service performance, and better adapting to dynamic changes in business requirements, providing an efficient, flexible and secure operating environment for the entire cryptographic service management system.
[0047] In a feasible implementation, the cryptographic service platform comprises a gateway and a cryptographic agent component. The gateway is configured to configure the service network, and the cryptographic agent component comprises a first network card and a second network card. The first network card is configured to receive configuration information issued by the cryptographic service platform via the management network, and the second network card is configured to access the service network.
[0048] The gateway is one of the core components of the password service platform, mainly responsible for configuring the business network. It serves as a communication bridge between the management network and the business network, receives configuration instructions from the management network, and converts them into configuration information suitable for the business network. The gateway can receive configuration information of the business network from the management network, including network address allocation, security policy setting, business system access rules, etc., and distribute these configuration information to each node in the business network, and can convert the management protocol used in the management network into the protocol suitable for the business network.
[0049] The password agent component includes a first network card and a second network card, respectively used to connect the management network and the business network. The first network card is connected to the management network for receiving configuration information issued by the password service platform via the management network. The configuration information can include but is not limited to parameter settings of the password service, start and stop instructions of the virtual machine, security policy updates, etc. Through the first network card, the password agent component can perform identity authentication and authorization with the management network, ensuring that only legitimate management instructions can be received and executed.
[0050] At the same time, the second network card of the password agent component is connected to the business network for connecting the password service to the business network, allowing the password agent component to communicate with the business system in the business network and provide password service. Specifically, the password service request sent by the business system can be forwarded to the processing module (such as the first virtual machine or cloud server password machine) of the password service platform, and the processing result is returned to the business system.
[0051] Through the setting of the gateway and the password agent component, efficient connection and configuration management of the management network and the business network are realized. The dual-network card design of the password agent component ensures accurate transmission of configuration information and stable access of the business network, improving the overall operation efficiency of the system.
[0052] In a specific application mode, the gateway can include a first gateway and a second gateway. The first gateway is used to forward the password service application request to the first virtual machine on the private cloud after the password service application request is authenticated. The second gateway is used to forward the password service application request issued by the first virtual machine to the second virtual machine after performing at least one of the master-slave configuration, agent configuration and load balancing configuration. Through the application of the first gateway and the second gateway, the authentication function of the first gateway ensures the security of the password service application request and prevents unauthorized access. The master-slave configuration, agent configuration and load balancing configuration function of the second gateway improve the reliability and performance of the system, ensuring stable operation under high load or fault conditions.
[0053] In a feasible implementation, the password service platform can further include a key management system for synchronizing the added key or updated key to the second virtual machine on the cloud server password machine when the first virtual machine generates a key addition event or a key update event.
[0054] In the cryptographic service platform, the first virtual machine is used for key generation and update. When a key addition or update event is triggered by business demand, the key management system on the first virtual machine generates or updates the key according to the preset security policy and algorithm, so that the key can be used for cryptographic service operations such as encryption and decryption, to ensure the security and integrity of data.
[0055] On this basis, the key management system can realize key synchronization. Once the first virtual machine completes the key addition or update operation, the key management system starts the synchronization process, transmits the added key or updated key information to the second virtual machine on the cloud server cryptographic machine through a secure communication channel.
[0056] Therefore, the key management system is used to ensure the real-time synchronization and consistency of the key, and improves the security and reliability of the cryptographic service. Through dynamic management and synchronization of the key, the system can better cope with various changes in the key life cycle and ensure the continuous availability of the cryptographic service.
[0057] In a feasible implementation, the cloud cryptographic service management system can further include a server monitoring module for monitoring the running state of the cryptographic agent component and the first virtual machine, and issuing a configuration file for defining the corresponding running parameters of the first virtual machine.
[0058] The server monitoring module is provided with an external virtual address and internally includes at least two cryptographic agent components, which are used to switch to a standby cryptographic agent component when the main cryptographic agent component fails.
[0059] The server monitoring module can be used to monitor the running state of the cryptographic agent component and the first virtual machine. Through real-time monitoring, potential faults or abnormal conditions can be found in time.
[0060] In order to ensure the high availability of the system, the server monitoring module internally integrates at least two cryptographic agent components, including a main cryptographic agent component and at least one standby cryptographic agent component. In the normal running state, the main cryptographic agent component is responsible for processing all cryptographic-related requests and operations. When the main cryptographic agent component fails (such as network interruption, software crash or hardware failure), the server monitoring module can quickly switch the request to the standby cryptographic agent component, thereby ensuring the continuity of the cryptographic agent service.
[0061] Referring to Figure 2 , Figure 2 Another structural schematic diagram of a cloud cryptographic service management system provided by the embodiments of the present application is shown in FIG. 3. Figure 2 In the cloud cryptographic service management system, a cryptographic service platform, a private cloud and a cloud server cryptographic machine connected with the cloud platform, and an external cryptographic service invoker are included. Figure 2In this context, the first virtual machine exists as an ECS (Elastic Compute Service) cluster providing different cryptographic services. Figure 2 The diagram shows an ECS cluster for encryption / decryption services, an ECS cluster for signature verification services, an ECS for security authentication servers, an ECS for secure channel services, and an ECS for collaborative signature services. Keepalived is open-source software primarily used to provide high availability (HA) solutions. It achieves high availability by monitoring and managing the running status of load balancers and servers, equivalent to the server monitoring module described in the previous example. It should be noted that the gateway and cryptographic proxy components included in the cryptographic service platform refer to those enabled and configured through the cryptographic service platform; they do not necessarily have to be located within the cryptographic service platform itself. Figure 2 As shown, it resides in a private cloud, meaning the cryptographic service platform serves as the medium for providing services. It can be used to activate services and distribute configurations. This platform can be a physical machine or, in essence, a virtual machine within the private cloud. If the cryptographic service platform is a virtual machine in the private cloud, such as... Figure 2 As shown, the cryptographic proxy component it creates is actually located in a private cloud. A private cloud essentially corresponds to at least one physical machine, and the cloud server cryptographic machine corresponds to the physical machine containing the physical cryptographic card. Figure 2 In this example, VSM (Virtual Security Module) is used as the second virtual machine described in the previous embodiment. Figure 2 It can be seen that the cryptographic service platform is also used to distribute network address ranges to physical cryptographic cards through the managed network.
[0062] In addition, the cryptographic service platform is also used to distribute service configuration information to the first virtual machine via the management network to manage the cryptographic services on the first virtual machine. This service configuration information is used to perform at least one of the following: obtaining detailed information about the first virtual machine, obtaining the running status of the first virtual machine, configuring the network information of the first virtual machine, configuring the token information of the first virtual machine, exporting the image of the first virtual machine, importing the image of the first virtual machine, starting the first virtual machine, stopping the first virtual machine, restarting the first virtual machine, resetting the first virtual machine, upgrading the first virtual machine, creating the first virtual machine, and deleting the first virtual machine.
[0063] like Figure 2 As shown, the cryptographic service platform can be used to manage cloud server cryptographic machines, configure a VSM network segment (the business network), and create a VSM. Specifically, the business network can be divided into several regional business networks, and a virtual LAN is used to assign a unique port identifier to each regional business network. The cryptographic proxy component and the second virtual machine each exist in their respective regional business networks.
[0064] When the password service platform and the second virtual machine communicate through the business network, the password service platform is configured with a Vlan policy on the network port of the three-layer switch, determines the first network port corresponding to the password agent component and the second network port corresponding to the second virtual machine, and configures the switch port connecting the password agent component and the second virtual machine as a trunk port mode to allow the traffic of the first network port and the second network port to interact through the trunk port.
[0065] The password service platform communicates with the second virtual machine through the business network, and the communication process depends on the network port configuration of the three-layer switch. The three-layer switch has routing function and can realize communication between different Vlans (virtual local area networks), and supports port trunking technology to improve network bandwidth and reliability.
[0066] The password service platform is configured with a Vlan policy on the network port of the three-layer switch, and divides the network into multiple logical subnets. Through Vlan division, the isolation of different business traffic can be realized, and the security and management efficiency of the network can be improved. The password service platform configures the switch port connecting the password agent component and the second virtual machine as a trunk port mode (configured as a trunk port). The port trunking technology can virtualize multiple physical ports as one logical port, thereby realizing load balancing and redundant backup of traffic.
[0067] Specifically, a trunk group (such as Trunk1) can be created on the three-layer switch, and the first network port and the second network port are added to the trunk group. The trunk group is configured in dynamic or static mode. In dynamic mode, the switch will automatically negotiate the parameters of port trunking, such as link aggregation control protocol (LACP); in static mode, the port trunking parameters are manually configured. After the configuration is completed, the traffic of the first network port and the second network port will interact through the trunk port. The trunk port can automatically distribute traffic to different physical ports, improve network bandwidth utilization, and automatically switch to other available ports when a physical port fails to ensure the continuity of communication. The corresponding communication process is as follows:
[0068] Traffic initiation: the password service platform initiates business traffic through the first network port (Vlan10).
[0069] Vlan forwarding: the three-layer switch forwards the traffic from Vlan10 to Vlan20 according to the Vlan policy.
[0070] Trunk port interaction: the traffic reaches the second network port (Vlan20) of the second virtual machine through the trunk port (Trunk1).
[0071] Traffic return: the response traffic of the second virtual machine returns through the second network port (Vlan20), is forwarded to the first network port (Vlan10) through the aggregation port (Trunk1), and finally reaches the password service platform.
[0072] As can be seen, the business network communication between the password service platform and the second virtual machine can realize efficient, reliable and secure interaction, and meet the strict requirements of modern data centers on network performance and security.
[0073] Referring to Figure 3 , Figure 3 A flowchart of a cloud password service application method provided by an embodiment of the present application is shown in FIG. 1. The method includes the following steps:
[0074] S301: The private cloud receives a commercial secret application request through a business network.
[0075] S302: The commercial secret application request is parsed to determine the password service type corresponding to the commercial secret application request.
[0076] S303: The commercial secret application request is forwarded to the first virtual machine corresponding to the password service type.
[0077] S304: After the first virtual machine forwards the commercial secret application request to the second virtual machine, the physical password card in the cloud server password machine is called to allocate corresponding encryption and decryption resources to the second virtual machine to respond to the commercial secret application request.
[0078] The private cloud receives a commercial secret application request from a client through a business network. The business network is a dedicated network for communication between the private cloud and external systems, and is responsible for carrying various business traffic. The commercial secret application request usually contains user identity information, business type, data encryption demand and other contents.
[0079] Thereafter, the received commercial secret application request is parsed to determine the password service type corresponding to the request. The parsing process includes format analysis, keyword extraction and business logic judgment of the request data packet. For example, the request may contain different password service requirements such as encryption, decryption, signature verification, key management, etc. The private cloud identifies the specific password service type by analyzing specific fields (such as service type identifier, operation code, etc.) in the request, providing a basis for subsequent request forwarding.
[0080] According to the analysis result, the private cloud forwards the commercial secret application request to the corresponding first virtual machine. The first virtual machine is a virtual machine instance in the private cloud that is specifically used to process password service requests, and it is responsible for receiving requests from the private cloud and further processing. The private cloud sends the request to the first virtual machine through the internal network, ensuring that the request is transmitted in a secure network environment. After receiving the request, the first virtual machine will perform preliminary processing according to the specific content of the request, such as verifying the authority of the request and checking whether the parameters of the request meet the requirements.
[0081] After the first virtual machine forwards the commercial secret application request to the second virtual machine, the private cloud calls the physical password card in the cloud server password machine to allocate corresponding encryption and decryption resources to the second virtual machine. The private cloud communicates with the cloud server password machine through the internal management interface, and allocates appropriate encryption and decryption resources to the second virtual machine according to the specific needs of the commercial secret application request (such as encryption algorithm type, key length, etc.).
[0082] After the second virtual machine receives the allocated encryption and decryption resources, it begins to process the commercial secret application request. After processing is complete, the second virtual machine returns the result to the first virtual machine, and the first virtual machine forwards the result back to the client through the private cloud, completing the entire commercial secret application request processing flow.
[0083] During the entire processing process, the security and processing performance of the commercial secret application request can be ensured. Without going through the password service platform, the network isolation and access control strategy within the private cloud ensures that only authorized virtual machines can access the physical password card resources in the cloud server password machine.
[0084] The present application also provides an embodiment corresponding to a computer-readable storage medium. The computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the method described in the above method embodiment.
[0085] It can be understood that if the method in the above embodiment is implemented in the form of a software function unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts that make contributions to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and executes all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0086] The computer readable storage medium provided in the embodiment comprises the method mentioned above, and the effects are the same.
[0087] The application also provides a computer program product comprising a computer program which, when executed, implements the steps of the cloud password service application method described in the above embodiment.
[0088] The embodiments in the specification are described in a progressive manner, and each embodiment focuses on the difference from other embodiments. The same or similar parts of each embodiment can be referred to each other. For the system provided by the embodiments, since it corresponds to the method provided by the embodiments, the description is relatively simple, and the related parts can be referred to the method part.
[0089] The principles and implementation manners of the application are described by using specific examples in the specification. The above embodiment description is only used to help understand the method of the application and its core idea. It should be noted that, for those skilled in the art, without departing from the principles of the application, some improvements and modifications can be made to the application, and these improvements and modifications also fall within the protection scope of the application.
[0090] It should also be noted that in the specification, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or sequence between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or equipment. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or equipment including the element.
Claims
1. A cloud-based cryptographic service management system, characterized in that, include: A cryptographic service platform is used to configure the management network and the business network, as well as to manage the first virtual machine and the second virtual machine; the management network is a network used to manage the cloud server cryptographic machine and the virtual machine; the business network is a network isolated from the management network and used to process business operations. A private cloud includes the first virtual machine running an elastic cloud server; the first virtual machine is used to provide cryptographic services, and the virtual machines are isolated from each other. The cloud server cryptographic machine includes a physical cryptographic card and a second virtual machine. The cloud server cryptographic machine is used to virtualize the physical cryptographic card into a virtual cryptographic card. The virtual cryptographic card is used to provide encryption and decryption resources for the second virtual machine. The cryptographic service platform includes: A gateway and a cryptographic proxy component; the gateway is used to configure the service network; the cryptographic proxy component includes a first network interface card (NIC) and a second NIC, the first NIC being used to receive configuration information issued by the cryptographic service platform via the management network, and the second NIC being used to access the service network; The gateway includes a first gateway and a second gateway; When the first gateway receives a cryptographic service application request, it authenticates the cryptographic service application request and then forwards the cryptographic service application request to the first virtual machine on the private cloud. The second gateway is used to perform at least one of the primary / standby configuration, proxy configuration, and load balancing configuration, and then forward the cryptographic service application request issued by the first virtual machine to the second virtual machine. The cryptographic service platform is further used to divide the business network into several regional business networks, and the virtual local area network is used to assign a unique port identifier to each regional business network; wherein the cryptographic proxy component and the second virtual machine each have their own corresponding regional business network; When the cryptographic service platform and the second virtual machine communicate on the service network, the cryptographic service platform is used to configure VLAN policies on the Layer 3 switch port, determine the first network port corresponding to the cryptographic proxy component and the second network port corresponding to the second virtual machine, and configure the switch port connecting the cryptographic proxy component and the second virtual machine as an aggregation port mode so as to allow traffic from the first network port and the second network port to interact via the aggregation port.
2. The system according to claim 1, characterized in that, The cryptographic service platform also includes: A key management system is used to synchronize the newly added key corresponding to the key addition event or the updated key corresponding to the key update event to the second virtual machine on the cloud server cryptographic machine when the first virtual machine generates a key addition event or a key update event.
3. The system according to claim 1, characterized in that, The private cloud also includes: The server monitoring module is used to monitor the running status of the password proxy component and the first virtual machine, and to issue a configuration file for defining the corresponding running parameters of the first virtual machine.
4. The system according to claim 3, characterized in that, The server monitoring module has an external virtual address and contains at least two password proxy components, which are used to switch to the backup password proxy component when the primary password proxy component fails.
5. A cloud-based cryptographic service application method, based on the cloud-based cryptographic service management system according to any one of claims 1-4, characterized in that, include: The private cloud receives requests for commercial cryptographic applications through the business network; Parse the commercial cryptography application request to determine the cryptographic service type corresponding to the commercial cryptography application request; The commercial cryptographic application request is forwarded to the first virtual machine corresponding to the cryptographic service type; After the first virtual machine forwards the commercial cryptographic application request to the second virtual machine, the physical cryptographic card in the cloud server cryptographic machine is invoked to allocate corresponding encryption and decryption resources to the second virtual machine in response to the commercial cryptographic application request.
6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed, implements the steps of the method as described in claim 5.
7. A computer program product, characterized in that, It includes a computer program that, when executed, implements the steps of the method as described in claim 5.
Citation Information
Patent Citations
Password service implementation method and device, equipment and storage medium
CN118152072A