Key management method and system based on security verification
By generating and verifying an initial key set, distributing it to the terminal devices of the gas station monitoring system, and monitoring its usage, the security and standardization issues of key management in traditional gas station monitoring systems are solved, thus achieving the security and effectiveness of refueling data collection and tax supervision.
Patent Information
- Application Number
- CN202511115806.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-11
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-08-11
AI Technical Summary
Traditional gas station monitoring systems suffer from insufficient security in key management, insecure distribution processes, and a lack of monitoring in key usage. This makes keys vulnerable to cracking, theft, and misuse, impacting data security and the effectiveness of tax supervision.
An initial key set is generated and security verified, then distributed to the gas station monitoring system terminal equipment to monitor the usage process and record status information, triggering update or revocation operations. Encrypted transmission and dynamic key management are employed.
This improved the security and standardization of key distribution, reduced the risk of cracking, and ensured the accuracy of refueling data collection and the effectiveness of tax supervision.
Smart Images

Figure CN120915441A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of gas station monitoring, in particular to a secret key management method and system based on security verification. BACKGROUND
[0002] In a gas station monitoring system, secret key management is a key link to ensure the safe and stable operation of the system. Traditional secret key management methods have many drawbacks. On the one hand, in the secret key generation stage, there is often a lack of effective evaluation of the security of the secret key, and the generated secret key may have the risk of being easily cracked, for example, using a simple generation algorithm, which makes the randomness and complexity of the secret key insufficient, and it is easy for malicious attackers to obtain it through brute force cracking or cryptanalysis.
[0003] On the other hand, the secret key distribution process lacks standardization and security protection. The traditional method may only simply send the secret key to the terminal device, without encrypting the transmission process of the secret key, which may be stolen or tampered with during transmission. Moreover, there is a lack of real-time monitoring of the use of secret keys by terminal devices, and it is not possible to timely detect abnormal use of secret keys, such as illegal copying and misuse of secret keys. Once the secret key is leaked, it will pose a serious threat to the data security and normal operation of the gas station monitoring system, affecting the accuracy of gas data and the effectiveness of tax supervision. Therefore, a more secure and reliable secret key management method is needed. SUMMARY
[0004] In view of the above, the purpose of the present application is to provide a secret key management method and system based on security verification.
[0005] According to a first aspect of the present application, a secret key management method based on security verification is provided, the method comprising: generating an initial secret key set, the initial secret key set containing a plurality of secret key units with unique identifiers; performing security verification processing on the initial secret key set to obtain a target secret key set that passes the verification; sending the target secret key set to a plurality of terminal devices of a gas station monitoring system according to a preset distribution rule, the terminal devices including gas data acquisition terminals and tax supervision docking terminals; monitoring the process of using the target secret key set by the terminal devices, and recording secret key usage state information; triggering a secret key update operation or a secret key revocation operation according to the secret key usage state information, and generating an updated secret key set or a revoked secret key set.
[0006] According to a second aspect of the present application, a secret key management system based on security verification is provided, which comprises a processor and a readable storage medium, and the readable storage medium stores a program which is executed by the processor to implement the secret key management method based on security verification.
[0007] According to any one of the above aspects, by generating an initial secret key set with unique identification, performing security verification processing on the initial secret key set, the secret keys meeting the security standards can be effectively screened out, and the target secret key set passing the verification is obtained, which greatly improves the security of the secret keys and reduces the risk of secret key cracking. The target secret key set is sent to a plurality of terminal devices of the gas station monitoring system according to a preset distribution rule, including a gas data acquisition terminal and a tax supervision docking terminal, which ensures the standardization and security of secret key distribution and avoids the leakage and tampering of secret keys in the transmission process. The process of using the target secret key set by the monitoring terminal device is monitored and the secret key usage state information is recorded, which can master the usage of the secret keys in real time and discover abnormal behaviors in time. The secret key update operation or the secret key revocation operation is triggered according to the secret key usage state information, and the updated secret key set or the revoked secret key set is generated, which realizes the dynamic management of the secret keys, further guarantees the security of the gas station monitoring system, and ensures the accuracy of the gas data acquisition and the effectiveness of the tax supervision. BRIEF DESCRIPTION OF DRAWINGS
[0008] Figure 1 A flowchart of the secret key management method based on security verification provided by the embodiment of the present application is shown. Figure 2 A component structure diagram of the secret key management system based on security verification provided by the embodiment of the present application is shown. DETAILED DESCRIPTION
[0009] Figure 1 A flowchart of the secret key management method based on security verification provided by the embodiment of the present application is shown. It should be understood that in other embodiments, the order of some steps of the secret key management method based on security verification can be exchanged according to actual needs, or some steps can be omitted or deleted. The detailed steps of the secret key management method based on security verification are as follows.
[0010] Step S110: generating an initial secret key set, the initial secret key set comprising a plurality of secret key units with unique identification.
[0011] The embodiment focuses on the key management of the gas station monitoring system. In the operation of the gas station, in order to ensure the safety of the gas data collection and the tax supervision docking business, the related information needs to be encrypted, and the management of the key is particularly important. Generating an initial key set is the starting point of the entire key management process, which needs to ensure that the generated key unit meets the security requirements of the system and can match various businesses and devices of the gas station monitoring system.
[0012] Step S111: Obtain a basic parameter set of the gas station monitoring system, the basic parameter set including a system identification code, a device type identifier and business scenario classification information.
[0013] In the gas station monitoring system, there is a special data interface for interacting with various devices and business modules. By calling the data interface, the basic parameter set of the gas station monitoring system can be obtained. The system identification code is the unique identification of the gas station monitoring system in the entire network environment, which is composed of specific characters, used to distinguish different gas station monitoring systems. The device type identifier is used to distinguish different devices in the gas station monitoring system, such as the gas data collection terminal and the tax supervision docking terminal, etc., each device has its corresponding identifier. The business scenario classification information clearly shows the business types involved in the gas station monitoring system, such as the collection of gas data, which involves the collection of data such as fueling volume and fueling time; there is also a tax supervision docking business, which mainly interacts with the tax department for data interaction and supervision.
[0014] Step S112: Perform key unit generation processing based on the basic parameter set to generate a candidate key unit including a system identification code associated field, a device type identifier associated field and a business scenario classification information associated field.
[0015] After obtaining the basic parameter set, the candidate key unit can be generated. This process needs to extract and convert each information in the basic parameter set.
[0016] Step S1121: Extract the system identification code from the basic parameter set, and convert the system identification code into a character sequence of a preset length as the system identification code associated field.
[0017] After the system identification code is extracted from the basic parameter set, it needs to be converted into a character sequence of a preset length in order to meet the format requirements of the key unit. This may involve operations such as character truncation, padding, or encoding conversion of the system identification code. For example, if the system identification code is originally a long string, it may need to be truncated to the key part, and then padded according to the preset rules to reach the preset length, finally forming the system identification code associated field. The system identification code associated field can accurately reflect the gas station monitoring system to which the key unit belongs.
[0018] Step S1122: Extract the device type identifier from the basic parameter set, map the device type identifier with the preset device type code table, and generate the device type identifier associated field.
[0019] The preset device type code table is a predefined mapping table that records the codes corresponding to various device types. After the device type identifier is extracted from the basic parameter set, it is compared with the device type code table. If the device type identifier matches an item in the code table, the corresponding code is taken as the device type identifier associated field. For example, the gas data acquisition terminal has a specific code in the device type code table, and when the extracted device type identifier indicates a gas data acquisition terminal, the code is taken as the device type identifier associated field. The purpose of this is to unify the representation of device types, facilitating subsequent key management and device identification.
[0020] Step S1123: Extract the business scenario classification information from the basic parameter set, match the business scenario classification information with the preset business scenario code table, and generate the business scenario classification information associated field.
[0021] The preset business scenario code table records the codes corresponding to various business scenarios involved in the gas station monitoring system. After the business scenario classification information is extracted from the basic parameter set, it is matched with the business scenario code table. If the business scenario classification information matches an item in the code table, the corresponding code is taken as the business scenario classification information associated field. For example, the gas data acquisition business has a corresponding code in the business scenario code table, and when the extracted business scenario classification information is the gas data acquisition business, the code is taken as the business scenario classification information associated field. This helps to clarify the business scenarios applicable to the key unit.
[0022] Step S1124: Concatenate the system identification code associated field, device type identifier associated field, and business scenario classification information associated field in the preset field order to generate the initial key character sequence.
[0023] After the system identification code associated field, the device type identifier associated field and the service scenario classification information associated field are generated, they are spliced together in a preset order. The preset field order is determined according to the specifications and requirements of key management, for example, the system identification code associated field can be placed first, then the device type identifier associated field, and finally the service scenario classification information associated field. By splicing these fields, the initial key character sequence is obtained.
[0024] Step S1125: inserting a preset separator character in the initial key character sequence to generate a candidate key unit containing the system identification code associated field, the device type identifier associated field and the service scenario classification information associated field.
[0025] In order to make the structure of the candidate key unit more clear and facilitate subsequent identification and processing, a preset separator character is inserted in the initial key character sequence. The preset separator character can be a specific symbol, such as a comma, a period, etc. After inserting the separator, a candidate key unit containing the system identification code associated field, the device type identifier associated field and the service scenario classification information associated field is formed.
[0026] Step S113: performing a unique identification allocation process on the candidate key unit to generate a unique identification code combined by the system identification code, the device type identifier and the service scenario classification information for each candidate key unit.
[0027] In order to ensure the uniqueness of each candidate key unit, it needs to be allocated a unique identification code. The unique identification code is combined by the system identification code, the device type identifier and the service scenario classification information. The specific combination method can be to splice these three information in a set order, for example, first splice the system identification code, then splice the device type identifier, and finally splice the service scenario classification information. The unique identification code generated by the above method can accurately identify each candidate key unit, facilitating subsequent management and query.
[0028] Step S114: performing a format specification checking process on the candidate key unit to verify whether the character composition structure, field length and separator usage of the candidate key unit conform to the preset key format specification.
[0029] The predefined key format specifications have clear requirements for the character structure, field length, and delimiter usage of candidate key units. During the format compliance check, the character structure is checked first to ensure that all characters in the candidate key unit are valid and do not contain illegal or special characters. Next, the field lengths are checked to verify that the lengths of the system identifier code associated field, device type identifier associated field, and business scenario classification information associated field meet the predefined requirements. Finally, the delimiter usage is checked to ensure that the position and number of delimiters are correct. Only when the character structure, field length, and delimiter usage of a candidate key unit all conform to the predefined key format specifications is the candidate key unit considered to have passed the format compliance check.
[0030] Step S115: Summarize the candidate key units that have passed the format specification check to form an initial key set, which contains multiple key units with unique identification codes and standard format.
[0031] All candidate key units that pass the format specification check are grouped together to form the initial key set. Each key unit in this initial key set has a unique identifier code and its format conforms to the preset key format specification.
[0032] Step S120: Perform security verification on the initial key set to obtain the target key set that passes the verification.
[0033] After the initial key set is generated, it needs to undergo security verification to ensure that the key units within it meet security requirements. Security verification mainly involves validating the various associated fields of each key unit, including encryption strength, collision detection, and compliance checks.
[0034] Step S121: Extract the system identifier code associated field, device type identifier associated field, and business scenario classification information associated field for each key unit from the initial key set.
[0035] During security verification, the first step is to extract key information for each key unit from the initial key set. This includes the system identification code associated field, the device type identifier associated field, and the business scenario classification information associated field. These fields contain the core information of the key unit and form the basis for security verification. By extracting these fields, each key unit can be subjected to targeted checks.
[0036] Step S122: Perform encryption strength verification on the system identifier encoding associated field to verify whether it contains a random character segment of preset length and an anti-collision hash value.
[0037] The random character segment of the preset length and the anti-collision hash value are important indicators for measuring the encryption strength of the system identification code association field. When verifying the encryption strength, it is checked whether the system identification code association field contains a random character segment of a preset length. The presence of the random character segment can increase the randomness and security of the key, preventing it from being cracked. At the same time, it is verified whether the field contains an anti-collision hash value. The anti-collision hash value is calculated by a set hash algorithm, which can ensure the uniqueness and integrity of the system identification code association field. Only when the system identification code association field contains both the random character segment of the preset length and the anti-collision hash value, is the encryption strength of the field considered to meet the requirements.
[0038] Step S123: Perform a conflict detection process on the device type identifier association field, and check whether there is a device type identifier association field of an activated key unit in the current gas station monitoring system that is completely identical to the field.
[0039] In order to avoid conflicts between key units, a conflict detection needs to be performed on the device type identifier association field. The specific operation is as follows: Step S1231: Access the key management database of the gas station monitoring system to obtain a set of device type identifier association fields of all key units currently in an activated state.
[0040] The key management database of the gas station monitoring system records the relevant information of all key units, including the device type identifier association field. By accessing the database, a set of device type identifier association fields of all key units currently in an activated state can be obtained. This set of device type identifier association fields contains the device type information of the currently used key units.
[0041] Step S1232: Extract the same field record as the device type identifier association field of the current key unit to be detected from the set of device type identifier association fields.
[0042] Compare the device type identifier association field of the current key unit to be detected with the set of device type identifier association fields obtained from the database, and extract the same field record as the device type identifier association field of the key unit to be detected. These same field records may indicate the presence of conflicting key units.
[0043] Step S1233: Count the number of the same field records to generate a conflict number statistical result.
[0044] The same field records extracted are counted to obtain a conflict quantity statistical result. The conflict quantity statistical result reflects the conflict between the device type identifier association field of the current to-be-detected key unit and the device type identifier association field of the activated key unit.
[0045] Step S1234: If the conflict quantity statistical result is greater than zero, it is determined that the device type identifier association field of the key unit has a conflict; if the conflict quantity statistical result is equal to zero, it is determined that the device type identifier association field of the key unit has no conflict.
[0046] The conflict quantity statistical result is determined. If the conflict quantity statistical result is greater than zero, it indicates that the device type identifier association field of the current to-be-detected key unit has a conflict with the device type identifier association field of the activated key unit, and the key unit may need to be adjusted or regenerated. If the conflict quantity statistical result is equal to zero, it indicates that the device type identifier association field of the key unit has no conflict, and the subsequent verification can continue.
[0047] Step S124: The compliance verification processing is performed on the business scenario classification information association field to verify whether it matches the preset scene classification information table of the tax supervision docking business and the refueling data collection business.
[0048] The scene classification information table of the tax supervision docking business and the refueling data collection business records the legal business scenario classification information. When the compliance verification is performed, the business scenario classification information association field is compared with the scene classification information table. If the business scenario classification information association field matches a certain item in the scene classification information table, it is considered that the field meets the compliance requirement; if it does not match, it indicates that the key unit may not be suitable for the current business scenario and needs to be adjusted.
[0049] Step S125: The key units that pass the encryption strength verification, conflict detection, and compliance verification are summarized to form a target key set that passes the verification.
[0050] After the encryption strength verification of the system identification code association field, the conflict detection of the device type identifier association field, and the compliance verification of the business scenario classification information association field, all key units that pass the verification are summarized together to form a target key set that passes the verification. The key units in the target key set meet the security requirements and can be used for subsequent distribution and use.
[0051] Step S130: The target key set is sent to a plurality of terminal devices of a gas station monitoring system according to a preset distribution rule, and the terminal devices include a refueling data collection terminal and a tax supervision docking terminal.
[0052] After the target key set is generated, the key units in the target key set need to be distributed to each terminal device of the gas station monitoring system to ensure that these devices can normally use the keys for data encryption and processing.
[0053] Step S131: Extract the unique identification code of each key unit from the target key set, and parse the system identification code, device type identifier, and business scenario classification information in the unique identification code.
[0054] In order to accurately distribute the key units to the corresponding terminal devices, the unique identification code of each key unit needs to be extracted from the target key set, and the system identification code, device type identifier, and business scenario classification information in the unique identification code need to be parsed. These information can help determine the scope of application of the key units and the corresponding terminal devices.
[0055] Step S132: According to the device type identifier, match the target terminal device type, and classify the key units of the device type identifier corresponding to the gas data acquisition terminal into a first distribution subset, and classify the key units of the device type identifier corresponding to the tax supervision docking terminal into a second distribution subset.
[0056] According to the parsed device type identifier, the key units in the target key set are classified. The key units of the device type identifier corresponding to the gas data acquisition terminal are classified into a first distribution subset, and these key units will be used for data encryption and processing of the gas data acquisition terminal. The key units of the device type identifier corresponding to the tax supervision docking terminal are classified into a second distribution subset, and these key units will be used for data interaction and supervision between the tax supervision docking terminal and the tax department.
[0057] Step S133: Perform transmission encryption processing on the first distribution subset and the second distribution subset respectively, and generate an encrypted transmission package containing timestamp information for each key unit in each distribution subset.
[0058] In order to ensure the security of the key units during transmission, transmission encryption processing needs to be performed on the first distribution subset and the second distribution subset respectively. The specific operation is as follows: Step S1331: Obtain the current system time as the timestamp information, and convert the timestamp information into a time character sequence in a preset format.
[0059] Obtain the current system time as the timestamp information, which can record the transmission time of the key units. Convert the timestamp information into a time character sequence in a preset format to facilitate subsequent splicing and encryption processing.
[0060] Step S1332: Extract the unique identification code and key content of each key unit from the first distribution subset, splice the unique identification code, key content and time character sequence to generate the first original transmission data.
[0061] The unique identification code and key content of each key unit are extracted from the first distribution subset, and then the unique identification code, key content and time character sequence are spliced in a set order to generate the first original transmission data. The original transmission data contains key information of the key unit and transmission time.
[0062] Step S1333: Use a preset symmetric encryption algorithm to encrypt the first original transmission data to generate the first encrypted transmission package.
[0063] The preset symmetric encryption algorithm is a commonly used encryption method, which uses the same key for encryption and decryption. The symmetric encryption algorithm is used to encrypt the first original transmission data to generate the first encrypted transmission package. The encrypted transmission package can ensure that the key unit is not stolen or tampered with during transmission.
[0064] Step S1334: Extract the unique identification code and key content of each key unit from the second distribution subset, splice the unique identification code, key content and time character sequence to generate the second original transmission data.
[0065] Similar to processing the first distribution subset, the unique identification code and key content of each key unit are extracted from the second distribution subset, and then the unique identification code, key content and time character sequence are spliced to generate the second original transmission data.
[0066] Step S1335: Use a preset asymmetric encryption algorithm to encrypt the second original transmission data to generate the second encrypted transmission package.
[0067] The preset asymmetric encryption algorithm uses a pair of keys, namely public key and private key. The asymmetric encryption algorithm is used to encrypt the second original transmission data to generate the second encrypted transmission package. The security of the asymmetric encryption algorithm is higher, and is suitable for tax supervision docking business with higher security requirements.
[0068] Step S134: Obtain the online state information of the fuel data collection terminal and the tax supervision docking terminal, and select the target terminal device in the online state.
[0069] Before distributing the key unit, it is necessary to obtain the online state information of the oil data collection terminal and the tax supervision docking terminal. Through communication with the terminal device or querying the related device management system, the online state of the terminal device is obtained. The target terminal device in the online state is screened out, and only these devices can receive and use the key unit.
[0070] Step S135: Send the encrypted transmission package to the corresponding target terminal device, and record the binding relationship information of the key unit and the target terminal device.
[0071] The generated first encrypted transmission package and second encrypted transmission package are sent to the corresponding target terminal device, i.e. the oil data collection terminal and the tax supervision docking terminal. During the sending process, the accuracy and integrity of the encrypted transmission package are ensured. At the same time, the binding relationship information of the key unit and the target terminal device is recorded for subsequent management and query.
[0072] Step S140: Monitor the process of the terminal device using the target key set, and record the key usage state information.
[0073] In order to ensure the safe use and effective management of the key unit, it is necessary to monitor the process of the terminal device using the target key set, and record the related key usage state information.
[0074] Step S141: Deploy a key usage monitoring module in the terminal device, which is used to capture the calling operation events of the key unit.
[0075] A key usage monitoring module is deployed in the oil data collection terminal and the tax supervision docking terminal. The monitoring module can be a software program that can monitor the calling operation events of the key unit in the terminal device in real time. When the terminal device calls the key unit for data encryption or decryption, the monitoring module can capture these operation events and record the related information.
[0076] Step S142: Analyze the calling operation events, extract the unique identification code of the key unit, the calling timestamp, the calling initiator identity and the calling business type information.
[0077] After the monitoring module captures the calling operation events, it needs to analyze these events. Through analysis, the unique identification code of the key unit can be extracted, which is used to accurately identify the called key unit; the calling timestamp records the specific time when the key unit is called; the calling initiator identity is used to determine which user or program initiates the call of the key unit; and the calling business type information clearly indicates the specific business that the key unit is used for, such as oil data collection business or tax supervision docking business.
[0078] Step S143: Perform compliance judgment processing on the calling service type information, and verify whether it is consistent with the service type indicated by the key unit service scenario classification information association field.
[0079] The extracted calling service type information is compared with the service type indicated by the key unit service scenario classification information association field. For example, if the service type indicated by the key unit service scenario classification information association field is fueling data collection service, and the calling service type information shows tax supervision docking service, it means that the call does not comply with the use rules of the key unit, and there is a compliance problem. Only when the calling service type information is consistent with the service type indicated by the key unit service scenario classification information association field, it is determined that the call is compliant.
[0080] Step S144: Perform frequency statistical processing on the calling operation event, and calculate the number of calls of each key unit in a preset time window and the adjacent calling time interval.
[0081] First, the calling operation event is grouped according to the unique identification code of the key unit. Because each key unit has its unique identification code, the calling operation events of different key units can be distinguished by the unique identification code, and the calling event sequence corresponding to each key unit is obtained.
[0082] Next, the calling time stamps in each calling event sequence are sorted. The purpose of sorting is to arrange the calling time stamps in chronological order, which facilitates subsequent statistics and calculation. After sorting, a calling time stamp list arranged in chronological order is generated.
[0083] Then, the number of time stamps in the calling time stamp list is counted, which is the number of calls of the key unit in the preset time window. The preset time window is a time period set according to the business needs and safety requirements of the gas station monitoring system, and the calling of the key unit in the time period is counted.
[0084] Finally, the calling time stamp list is traversed, and the time difference between adjacent two time stamps is calculated. For example, for a calling time stamp list arranged in chronological order, the difference between the second time stamp and the first time stamp, the difference between the third time stamp and the second time stamp, and so on are calculated in turn, and a list of adjacent calling time intervals is generated. The number of calls and the list of adjacent calling time intervals are stored in association with the unique identification code of the corresponding key unit as the frequency statistical result, so that the usage frequency of each key unit can be clearly understood.
[0085] Step S145: The unique identification code, call timestamp, call initiator identity, call service type information, compliance judgment result, call frequency and adjacent call time interval are summarized to form the key usage state information.
[0086] The unique identification code, call timestamp, call initiator identity, call service type information, compliance judgment result, call frequency and adjacent call time interval extracted and calculated through the above steps are summarized together to form the key usage state information. The key usage state information comprehensively reflects various situations of each key unit in the use process.
[0087] Step S150: Trigger the key update operation or key revocation operation according to the key usage state information, and generate the updated key set or revoked key set.
[0088] The key usage state information records the usage of the key unit. According to these information, it can be judged whether the key needs to be updated or revoked to ensure the security and effectiveness of the key.
[0089] For example, step S151: Extract the compliance judgment result of each key unit from the key usage state information, and screen out the key units with non-compliant service type calls as candidate keys to be revoked.
[0090] In the key usage state information, the compliance judgment result clearly shows whether the call of each key unit meets the service type requirements. By extracting the compliance judgment result, the key units with non-compliant service type calls are screened out. These key units may have been used incorrectly or have security risks, and they are used as candidate keys to be revoked.
[0091] Step S152: Extract the call frequency and adjacent call time interval of each key unit from the key usage state information, and screen out the key units with call frequency exceeding the preset threshold or adjacent call time interval less than the preset threshold as candidate keys to be updated.
[0092] The preset threshold is a standard set according to the security policy and business requirements of the gas station monitoring system. The call frequency and adjacent call time interval of each key unit are extracted from the key usage state information. The key units with call frequency exceeding the preset threshold are screened out, because the high call frequency may mean that the key is overused, which may pose a security risk. At the same time, the key units with adjacent call time interval less than the preset threshold are also screened out, which may indicate that the key is frequently called, or there may be an anomaly. These key units that meet the conditions are used as candidate keys to be updated.
[0093] Step S153: invalidation marking processing is performed on the candidate key to be revoked, a revoked key unit containing an invalidation timestamp is generated, and the revoked key units are aggregated to form a revoked key set.
[0094] The candidate key to be revoked is subjected to invalidation marking processing, and in this process, the invalidation timestamp of the key unit is recorded. The invalidation timestamp is used to specify from when the key unit is no longer valid. After the invalidation marking processing, a revoked key unit containing an invalidation timestamp is generated. All revoked key units are aggregated together to form a revoked key set. The key units in the revoked key set will no longer be used by the terminal device of the gas station monitoring system.
[0095] Step S154: based on the unique identification code of the candidate key to be updated, the corresponding system identification code, device type identifier and business scenario classification information are obtained.
[0096] The unique identification code of the candidate key to be updated contains its corresponding system identification code, device type identifier and business scenario classification information. Through the unique identification code, these information can be obtained from the related database or storage module of the gas station monitoring system. These information are the basis for generating new key units, ensuring that the new key units and the original key units are consistent in applicable system, device and business scenario.
[0097] Step S155: using the same generation rule and format specification as generating the initial key set, based on the system identification code, device type identifier and business scenario classification information, new key units are generated as updated key units, and the updated key units are aggregated to form an updated key set.
[0098] According to the obtained system identification code, device type identifier and business scenario classification information, new key units are generated according to the generation rule and format specification used when generating the initial key set. These new key units will replace the original candidate key to be updated, providing secure encryption services for the terminal device of the gas station monitoring system. All generated updated key units are aggregated together to form an updated key set. The key units in the updated key set will be distributed to the corresponding terminal device to update the original key.
[0099] In the above embodiments, various privacy protection and leakage prevention techniques are used for the data collection, storage and use, etc. involving privacy sensitive data. In the data collection stage, the collected privacy sensitive data is encrypted, for example, symmetric encryption algorithm is used to encrypt the privacy sensitive data containing user identity information, to ensure the security of the data in the transmission process. In the data storage aspect, a secure storage system is used to store the encrypted data, and strict access permission control is set, only authorized personnel can access these data. At the same time, the stored data is backed up regularly to prevent data loss. In the data use process, the operation of accessing and using privacy sensitive data is audited and recorded to discover and handle abnormal situations in time. Through these privacy protection and leakage prevention techniques, the security and confidentiality of privacy sensitive data in the gas station monitoring system are ensured, and the occurrence of data leakage and other security problems is avoided.
[0100] Further, Figure 2 A hardware structure schematic diagram of a security check based key management system 100 for implementing the method provided by the embodiments of the application is shown. As shown in the figure, Figure 2 The security check based key management system 100 can include at least one processor 102 (the processor 102 can include but is not limited to a microprocessor MCU or a programmable logic device FPGA processing device), a memory 104 for storing data, a transmission device 106 for communication function, and a controller 108. Those skilled in the art can understand that, Figure 2 The structure shown in the figure is only a schematic, which does not limit the structure of the security check based key management system 100. For example, the security check based key management system 100 can include more or less components than Figure 2 or have a different configuration from Figure 2 The figure.
[0101] The memory 104 can be used to store software programs and modules of application software, such as the program instructions corresponding to the method embodiments described above in the embodiments of the application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned security check based key management method. The transmission device 106 is used to obtain or send data via a network.
[0102] Those skilled in the art can understand that all or part of the steps of the above-mentioned embodiments can be completed by hardware, or by program to instruct related hardware to complete. The above-mentioned program can be stored in a computer readable storage medium, and the above-mentioned storage medium can be a read only memory, a magnetic disk or an optical disk, etc.
Claims
1. A secret key management method based on security check, characterized by, The method comprises: generating an initial key set, the initial key set comprising a plurality of key units with unique identification; performing security check processing on the initial key set to obtain a target key set that passes the check; sending the target key set to a plurality of terminal devices of a gas station monitoring system according to a preset distribution rule, the terminal devices comprising a gas data acquisition terminal and a tax supervision docking terminal; monitoring the process of using the target key set by the terminal devices and recording key usage state information; triggering a key update operation or a key revocation operation according to the key usage state information to generate an updated key set or a revoked key set.
2. The security check-based key management method of claim 1, wherein, The generating of the initial key set, the initial key set comprising a plurality of key units with unique identification, comprises: obtaining a basic parameter set of the gas station monitoring system, the basic parameter set comprising system identification codes, device type identifiers and business scenario classification information; generating candidate key units comprising system identification code associated fields, device type identifier associated fields and business scenario classification information associated fields based on the basic parameter set; performing unique identification allocation processing on the candidate key units to generate a unique identification code for each candidate key unit, the unique identification code being formed by the combination of the system identification code, the device type identifier and the business scenario classification information; performing format specification check processing on the candidate key units to verify whether the character composition structure, field length and separator usage of the candidate key units conform to the preset key format specification; summarizing the candidate key units that pass the format specification check to form an initial key set, the initial key set comprising a plurality of key units with unique identification codes and format specifications.
3. The security check-based key management method of claim 2, wherein, The generating of the candidate key units based on the basic parameter set comprises: extracting the system identification code from the basic parameter set and converting the system identification code into a character sequence of a preset length as the system identification code associated field; extracting the device type identifier from the basic parameter set, mapping the device type identifier with a preset device type code table to generate the device type identifier associated field; extracting the business scenario classification information from the basic parameter set, matching the business scenario classification information with a preset business scenario code table to generate the business scenario classification information associated field; splicing the system identification code associated field, the device type identifier associated field and the business scenario classification information associated field in a preset field order to generate an initial key character sequence; inserting a preset separator character into the initial key character sequence to generate the candidate key units comprising the system identification code associated field, the device type identifier associated field and the business scenario classification information associated field.
4. The security check-based key management method of claim 1, wherein, The performing of the security check processing on the initial key set to obtain the target key set that passes the check comprises: extracting a system identification code associated field, a device type identifier associated field and service scenario classification information associated field of each key unit from the initial key set; performing encryption strength verification processing on the system identification code associated field to verify whether it contains a random character segment of a preset length and an anti-collision hash value; performing collision detection processing on the device type identifier associated field to check whether there is a device type identifier associated field of an activated key unit in the current gas station monitoring system that is completely consistent with the field; performing compliance verification processing on the service scenario classification information associated field to verify whether it matches the preset scene classification information table of the tax supervision docking service and the gas data collection service; summarizing the key units that pass the encryption strength verification, the collision detection and the compliance verification to form a target key set that passes the verification.
5. The security check-based key management method according to claim 4, wherein The collision detection processing on the device type identifier associated field to check whether there is a device type identifier associated field of an activated key unit in the current gas station monitoring system that is completely consistent with the field includes: accessing the key management database of the gas station monitoring system to obtain a device type identifier associated field set of all key units currently in an activated state; extracting a same field record from the device type identifier associated field set as the device type identifier associated field of the current key unit to be detected; counting the number of the same field records to generate a collision number statistical result; if the collision number statistical result is greater than zero, it is determined that the device type identifier associated field of the key unit has a collision; if the collision number statistical result is equal to zero, it is determined that the device type identifier associated field of the key unit has no collision.
6. The security check-based key management method of claim 1, wherein, The target key set is sent to a plurality of terminal devices of the gas station monitoring system according to a preset distribution rule, the terminal devices include a gas data collection terminal and a tax supervision docking terminal, and the method includes: extracting a unique identification code of each key unit from the target key set, and parsing a system identification code, a device type identifier and service scenario classification information in the unique identification code; according to the device type identifier, matching a target terminal device type, classifying key units corresponding to the gas data collection terminal as a first distribution subset, and classifying key units corresponding to the tax supervision docking terminal as a second distribution subset; performing transmission encryption processing on the first distribution subset and the second distribution subset respectively, and generating an encrypted transmission package containing timestamp information for each key unit in each distribution subset; obtaining online state information of the gas data collection terminal and the tax supervision docking terminal, and screening target terminal devices in an online state; sending the encrypted transmission package to the corresponding target terminal device, and recording the binding relationship information of the key unit and the target terminal device.
7. The security check-based key management method according to claim 6, wherein The transmission encryption processing on the first distribution subset and the second distribution subset respectively, and the generation of the encrypted transmission package containing timestamp information for each key unit in each distribution subset include: Obtaining a current system time as timestamp information, and converting the timestamp information into a time character sequence in a preset format; Extracting a unique identification code and key content of each key unit from the first distribution sub-set, and splicing the unique identification code, key content, and time character sequence to generate first original transmission data; Encrypting the first original transmission data using a preset symmetric encryption algorithm to generate a first encrypted transmission package; Extracting a unique identification code and key content of each key unit from the second distribution sub-set, and splicing the unique identification code, key content, and time character sequence to generate second original transmission data; Encrypting the second original transmission data using a preset asymmetric encryption algorithm to generate a second encrypted transmission package.
8. The security check-based key management method of claim 1, wherein, The monitoring of the process in which the terminal device uses the target key set records key usage state information, and includes: Deploying a key usage monitoring module in the terminal device, where the monitoring module is configured to capture a calling operation event of a key unit; Analyzing the calling operation event to extract a unique identification code, a calling timestamp, a calling initiator identity, and a calling business type information of the key unit; Performing compliance judgment processing on the calling business type information to verify whether the calling business type information is consistent with a business type indicated by an associated field of key unit business scenario classification information; Performing frequency statistical processing on the calling operation event to calculate a calling number and an adjacent calling time interval of each key unit within a preset time window; Summarizing the unique identification code, calling timestamp, calling initiator identity, calling business type information, compliance judgment result, calling number, and adjacent calling time interval to form key usage state information.
9. The security check-based key management method according to claim 8, wherein The frequency statistical processing on the calling operation event to calculate a calling number and an adjacent calling time interval of each key unit within a preset time window includes: Grouping the calling operation event according to the unique identification code of the key unit to obtain a calling event sequence corresponding to each key unit; Sorting the calling timestamp in each calling event sequence to generate a calling timestamp list arranged in chronological order; Counting the number of timestamps in the calling timestamp list as the calling number of the key unit within the preset time window; Iterating through the calling timestamp list to calculate a time difference between two adjacent timestamps to generate an adjacent calling time interval list; Storing the calling number and adjacent calling time interval list as a frequency statistical result in association with the unique identification code of the corresponding key unit.
10. A secret key management system based on security check, characterized by, The device includes a processor and a readable storage medium, where the readable storage medium stores a program, and the program is executed by the processor to implement the key management method based on security verification in any one of claims 1-9.
Citation Information
Patent Citations
Key management method and system based on security verification device
CN120012160A
Asset Management Service for Distributed Computing Environments
US20140131434A1