Data processing method and device based on multiple cloud keys, equipment, medium and product

By generating and distributing unified multi-cloud keys through a central server, the problem of low data processing efficiency caused by different encryption and decryption methods between different clouds is solved, and unified data processing capability is achieved across various cloud servers.

CN120979635APending Publication Date: 2025-11-18SF TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410605240.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-15
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Because different cloud platforms use different encryption and decryption methods, data cannot be processed when transmitted between different cloud platforms, resulting in reduced data processing efficiency.

Method used

A multi-cloud key-based data processing method is adopted. A unified target key is generated by a central server and distributed to each cloud server. The cloud servers query the target key using key credentials to process data, ensuring that each cloud server uses a unified encryption and decryption method.

Benefits of technology

It improves data processing efficiency, overcomes the problem of data inability to be processed due to different encryption and decryption methods between clouds, and ensures the data processing capabilities of various cloud servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979635A_ABST
    Figure CN120979635A_ABST
Patent Text Reader

Abstract

The invention relates to a data processing method and device based on multiple cloud keys, equipment, a medium and a product, and relates to the technical field of data processing. The method comprises the following steps: in response to a data processing instruction for target data, obtaining a key certificate corresponding to the data processing instruction; through the key voucher, querying to obtain a target key corresponding to the key voucher; the target key is a unified key issued to the cloud server by the central server, and the unified key is generated based on a plurality of different types of keys; and based on the target key plaintext corresponding to the target key, performing data processing on the target data to obtain a data processing result corresponding to the target data. By adopting the method, the efficiency of data processing based on multiple cloud keys can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, in particular to a data processing method and device based on multi-cloud keys, equipment, medium and product. BACKGROUND

[0002] With the rise of the Internet of Things and new generation communication technology, the data transmission volume between clouds increases. In order to ensure the security of data in the transmission process, encryption and decryption processing of data is essential.

[0003] However, each cloud has its own independent encryption and decryption processing method. In the case of data transmission between different clouds, the encryption and decryption methods of different clouds are different, which may lead to the fact that data cannot be processed on other clouds, thereby reducing the efficiency of data processing. SUMMARY

[0004] Therefore, it is necessary to provide a data processing method and device based on multi-cloud keys to improve the efficiency of data processing.

[0005] In a first aspect, the present application provides a data processing method based on multi-cloud keys. The method is applied to a cloud server and includes: in response to a data processing instruction for target data, obtaining a key certificate corresponding to the data processing instruction; querying a target key corresponding to the key certificate through the key certificate; the target key is a unified key issued by a center server to the cloud server, and the unified key is generated based on multiple different types of keys; and performing data processing on the target data based on a target key plaintext corresponding to the target key to obtain a data processing result corresponding to the target data.

[0006] In a second aspect, the present application also provides a data processing device based on multi-cloud keys. The device includes: a certificate obtaining module configured to, in response to a data processing instruction for target data, obtain a key certificate corresponding to the data processing instruction; a key obtaining module configured to query a target key corresponding to the key certificate through the key certificate; the target key is a unified key issued by a center server to the cloud server, and the unified key is generated based on multiple different types of keys; and a data processing module configured to perform data processing on the target data based on a target key plaintext corresponding to the target key to obtain a data processing result corresponding to the target data.

[0007] In a third aspect, the present application also provides a computer device. The computer device comprises a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the following steps are implemented: in response to a data processing instruction for target data, obtaining a key certificate corresponding to the data processing instruction; querying a target key corresponding to the key certificate through the key certificate; the target key is a unified key issued by a center server to a cloud server, and the unified key is generated based on a plurality of different types of keys; and performing data processing on the target data based on a target key plaintext corresponding to the target key, to obtain a data processing result corresponding to the target data.

[0008] In a fourth aspect, the present application also provides a computer readable storage medium. The computer readable storage medium stores a computer program. When the computer program is executed by a processor, the following steps are implemented: in response to a data processing instruction for target data, obtaining a key certificate corresponding to the data processing instruction; querying a target key corresponding to the key certificate through the key certificate; the target key is a unified key issued by a center server to a cloud server, and the unified key is generated based on a plurality of different types of keys; and performing data processing on the target data based on a target key plaintext corresponding to the target key, to obtain a data processing result corresponding to the target data.

[0009] In a fifth aspect, the present application also provides a computer program product. The computer program product comprises a computer program. When the computer program is executed by a processor, the following steps are implemented: in response to a data processing instruction for target data, obtaining a key certificate corresponding to the data processing instruction; querying a target key corresponding to the key certificate through the key certificate; the target key is a unified key issued by a center server to a cloud server, and the unified key is generated based on a plurality of different types of keys; and performing data processing on the target data based on a target key plaintext corresponding to the target key, to obtain a data processing result corresponding to the target data.

[0010] The multi-cloud key-based data processing method, device, computer equipment, computer readable storage medium and computer program product can be applied to a cloud server. First, in response to a data processing instruction for target data, a key certificate corresponding to the data processing instruction is obtained, and then based on the key certificate, a target key corresponding to the key certificate is queried. The target key is a unified key issued by a center server to each cloud server, and the unified key is generated based on multiple different types of keys to ensure the security of the unified key. Finally, based on a target key plaintext corresponding to the target key, the target data is processed to obtain a data processing result corresponding to the target data. Since the unified target key is used between each cloud server, data can be processed on each cloud server, overcoming the technical defect that the data cannot be processed on other cloud servers due to different encryption and decryption methods between each cloud server, thereby reducing the efficiency of data processing. Therefore, the above method can effectively improve the efficiency of data processing. BRIEF DESCRIPTION OF DRAWINGS

[0011] Figure 1 An application scenario diagram of a multi-cloud key-based data processing method in an embodiment is shown.

[0012] Figure 2 A flowchart of a multi-cloud key-based data processing method in an embodiment is shown.

[0013] Figure 3 A flowchart of data encryption in an embodiment is shown.

[0014] Figure 4 A flowchart of data decryption in an embodiment is shown.

[0015] Figure 5 A flowchart of obtaining a target key plaintext in an embodiment is shown.

[0016] Figure 6 Another flowchart of a multi-cloud key-based data processing method in an embodiment is shown.

[0017] Figure 7 A block diagram of a multi-cloud key-based data processing device in an embodiment is shown.

[0018] Figure 8 An internal structure diagram of a computer equipment in an embodiment is shown. DETAILED DESCRIPTION

[0019] In order to make the purpose, technical scheme and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0020] With the rise of the Internet of Things and the new generation of communication technology, the amount of data transmission between clouds increases. In order to ensure the security of data in the transmission process, it is necessary to encrypt and decrypt the data. However, each cloud has its own independent encryption and decryption processing method. In the case of data transmission between different clouds, the encryption and decryption methods of different clouds are different, which may cause the data to be unable to migrate between different cloud environments in the form of ciphertext, and thus unable to be processed on other clouds, resulting in a decrease in data processing efficiency.

[0021] The multi-cloud key data processing method provided by the embodiments of the present disclosure can be applied to an application environment as shown in Figure 1 The application environment includes a cloud server 102 and a center server 104. The cloud server 102 and the center server 104 communicate with each other, and there can be multiple cloud servers 102. Before performing multi-cloud key data processing, the center server 104 can generate a unified key based on multiple candidate keys and distribute the unified key to the cloud server 102. In this way, when the cloud server 102 receives a data processing instruction for target data, the cloud server 102 first obtains the key certificate corresponding to the data processing instruction, queries the corresponding target key, that is, the unified key, based on the key certificate, and performs data processing on the target data based on the key plaintext of the target key, to obtain the data processing result corresponding to the target data. In this way, each cloud server uniformly processes data during data processing, and no matter where the data is migrated, it can be received and processed by the cloud server, thereby improving the efficiency of data processing.

[0022] The center server or the cloud server can be implemented by an independent server or a server cluster composed of multiple servers. The center server can be deployed in any cloud, and each cloud server can be deployed in a cloud other than the cloud where the center server is located. The cloud can be a public cloud or a private cloud.

[0023] In an embodiment, the cloud server can further include an encryption and decryption program and a business module. The encryption and decryption program can be a program for generating a data key plaintext and a data key ciphertext based on a target key plaintext of a target key. The business module can be a module for receiving the data key plaintext and the data key ciphertext sent by the encryption and decryption program, and performing encryption and decryption processing on the target data based on the data key plaintext and the data key ciphertext.

[0024] In an embodiment, as shown in Figure 2 A multi-cloud key-based data processing method is provided. Taking the cloud server 104 in Figure 1 as an example, the method includes the following steps:

[0025] In step S202, in response to the data processing instruction for the target data, the key certificate corresponding to the data processing instruction is obtained.

[0026] The target data can be business data that needs to be processed in the cloud server. The data processing instruction can be used to instruct the cloud server to process the target data, and the data processing includes data encryption or data decryption. The key certificate is a certificate representing the use permission of the target object initiating the data processing instruction for the target key. In an example, the key certificate can be an AK / SK certificate.

[0027] In an embodiment, the center server can generate a set of key certificates corresponding to the target key and synchronously issue the key certificates to the cloud server when creating the target key. The business module can obtain the target key plaintext from the encryption and decryption program through the key certificate, and use the target key plaintext for data processing.

[0028] Specifically, when the business module in the cloud server receives the data processing instruction for the target data initiated by the user through the terminal, the key certificate corresponding to the data processing instruction is obtained first, and the key certificate is sent to the encryption and decryption program in the cloud server, so that the encryption and decryption program verifies the use permission of the target object for the target key based on the key certificate, and obtains the target key and the target key plaintext of the target key in the case where it is determined that the target object has the permission to use the target key. The business module sends the data key plaintext and the data key ciphertext corresponding to the target key plaintext to the business module, so that the business module processes the target data based on the data key plaintext and the data key ciphertext.

[0029] In an embodiment, the business program can also perform communication encryption on the request instruction initiated by the business program and containing the key certificate, and perform communication encryption on the data key plaintext and the data key ciphertext issued by the encryption and decryption program in the process of requesting the target key plaintext from the encryption and decryption program, so as to improve the security of the request instruction, the data key plaintext and the data key ciphertext, and prevent them from being illegally obtained by intermediate programs.

[0030] Taking the communication encryption of the request instruction as an example: firstly, a canonical request string is spliced, that is, the request instruction is spliced according to the splicing specification to obtain a final request string, in an example, the request string can be expressed as: canonicalRequest=httpRequestMethod+”\n”+canonicalHeaders+”\n”+SHA256Hex(params), wherein, canonicalRequest represents the request string, httpRequestMethod represents the http request method, canonicalHeaders represents the request header, and SHA256Hex(params) represents the parameter obtained by performing hash encryption on the request parameter params using the SHA (Secure Hash Algorithm, secure hash algorithm) 256 algorithm. Then, a to-be-signed string is spliced, in an example, the to-be-signed string can be expressed as: stringToSign=timestamp+”\n”+SHA256Hex(canonicalRequest), wherein, stringToSign represents the to-be-signed string, timestamp represents the request timestamp, and SHA256Hex(canonicalRequest) represents the hash value obtained by performing hash encryption on the request string obtained by splicing above using SHA256. After obtaining the to-be-signed string, the signature can be calculated, and the expression of the signature calculation can be: signature =hmac256(sk, stringToSign), wherein, hmac256 (Hash-based Message Authentication Code 256) is a hash function-based message signature authentication algorithm, and sk refers to a secret key certificate, that is, the SK part in the AK / SK certificate. In the AK / SK certificate, AK is an access key used to identify the identity of the user, and SK is used to encrypt and sign the access key to verify the identity. Finally, the authorization is spliced: authorization= “Credential=” + ak + “, ” + “Signature=” + signature, wherein, Credential identifies the scope of the certificate. The process of communication encryption of the data key plaintext and the data key ciphertext issued by the encryption and decryption program is similar to the communication encryption process of the request instruction, which will not be described here.

[0031] In step S204, the target key corresponding to the key certificate is obtained by querying through the key certificate; the target key is a unified key issued by the center server to the cloud server, and the unified key is generated based on a plurality of different types of keys.

[0032] Wherein, before data processing, the center server can generate a unified key, i.e. target key, based on multiple different types of keys, and distribute the target key to each cloud server. In an example, the target key can be a cmk (Customer Master Key, user key) key.

[0033] In actual application, after the encryption and decryption program receives the key certificate sent by the business module, the permission relationship between the key certificate and the target key can be verified first. In an embodiment, the target key corresponding to the key certificate is obtained by querying through the key certificate, including: verifying the permission of the target object using the target key through the key certificate to obtain a permission verification result, wherein the target object is the user triggering the data processing instruction; when the permission verification result indicates that the target object has the permission to use the target key, the target key is obtained.

[0034] Wherein, the verification result is used to represent whether the target object corresponding to the key certificate has the permission to use the target key, which can include permission verification pass and permission verification fail.

[0035] Specifically, the encryption and decryption program verifies the permission of the target object corresponding to the key certificate to use the target key, i.e. whether the target object triggering the data processing instruction has the permission to use the target key. If it is detected that there is a permission relationship between the key certificate and the target key, it indicates that the target object corresponding to the key certificate has the permission to use the target key, so the permission verification passes, and the target key and the target key plaintext of the target key are obtained, and the data key plaintext and the data key ciphertext corresponding to the target key plaintext are sent to the business module, so that the business module performs data processing on the target data based on the data key plaintext and the data key ciphertext. If it is detected that there is no permission relationship between the key certificate and the target key, it indicates that the target object corresponding to the key certificate does not have the permission to use the target key, so the permission verification fails, and the current data processing request is rejected.

[0036] Step S206, based on the target key plaintext corresponding to the target key, the target data is processed to obtain the data processing result corresponding to the target data.

[0037] Wherein, the target key plaintext refers to the plaintext information of the target key. It can be understood that the target key has corresponding key plaintext and key ciphertext, and the center server uses various different keys to encrypt the target key plaintext to obtain a unified target key ciphertext, and distributes the target key ciphertext to each cloud server. Each cloud server can request the target key plaintext from the center server, so as to perform data encryption and decryption processing based on the target key plaintext.

[0038] Specifically, after receiving the data key plaintext and the data key ciphertext sent by the encryption and decryption program, the service module can perform data encryption or data decryption on the target data based on the data key plaintext and the data key ciphertext, so as to obtain the data processing result corresponding to the target data.

[0039] In this embodiment, in response to the data processing instruction for the target data, the key certificate corresponding to the data processing instruction is first obtained, so that the target key corresponding to the key certificate is queried based on the key certificate, the target key is a unified key issued by the center server to each cloud server, and the unified key is generated based on multiple different types of keys to ensure the security of the unified key. Finally, the target data is processed based on the target key plaintext corresponding to the target key, and the data processing result corresponding to the target data is obtained. Since the unified target key is used between each cloud server, data can be processed on each cloud server, which overcomes the technical defect that the data cannot be processed on other cloud servers due to different encryption and decryption modes between each cloud server, thereby reducing the efficiency of data processing. Therefore, the embodiment can effectively improve the efficiency of data processing.

[0040] In an embodiment, as shown in Figure 3 Based on the target key plaintext corresponding to the target key, the target data is processed to obtain the data processing result corresponding to the target data, including:

[0041] Step S302, receiving the data key plaintext and the data key ciphertext sent by the encryption and decryption program through the service module; the data key ciphertext is obtained by encrypting the data key plaintext based on the target key plaintext by the encryption and decryption program.

[0042] The data processing instruction can include a data encryption instruction and a data decryption instruction, the data encryption instruction is used for encrypting the target data, and the data decryption instruction is used for decrypting the target data. The target data can include to-be-encrypted data, and the data processing result includes target encrypted data corresponding to the to-be-encrypted data. The data key plaintext and the data key ciphertext correspond to the same data encryption key (Disk Encryption Key, DEK). The data key plaintext is used to encrypt the target data to obtain initial encrypted data. The data key ciphertext is used to combine the initial encrypted data to obtain the final target encrypted data.

[0043] Specifically, after the service module sends the key certificate to the encryption and decryption program, the encryption and decryption program obtains the target key and the target key plaintext corresponding to the target key, and randomly generates a unique data key plaintext, encrypts the data key plaintext using the target key plaintext to obtain the data key ciphertext corresponding to the data key plaintext, and finally returns the data key ciphertext and the data key plaintext to the service module after communication encryption.

[0044] In step S304, the service module encrypts the data to be encrypted based on the data key plaintext to obtain initial encrypted data corresponding to the data to be encrypted.

[0045] In step S306, the data key ciphertext and the initial encrypted data are combined to obtain target encrypted data.

[0046] The initial encrypted data refers to data obtained by encrypting the data to be encrypted using the data key plaintext.

[0047] Specifically, after the service module receives the data key plaintext and the data key ciphertext, the service module first encrypts the data to be encrypted using the data key plaintext to obtain initial encrypted data. Then, the initial encrypted data, the data key ciphertext, and the index ciphertext of the target key are combined to obtain target encrypted data. It should be noted that the order of combination can be set according to actual conditions, which is not limited herein. The index ciphertext refers to ciphertext obtained by encrypting the index position of the target key, and the index ciphertext is used for the encryption and decryption program to query the target key.

[0048] In this embodiment, the security of the data to be encrypted is ensured by re-encrypting the data to be encrypted, and the security of each key in the data processing process is also ensured by encrypting the data key ciphertext of the encrypted data to be encrypted.

[0049] In an embodiment, as shown in FIG. 4, the data processing based on the target key plaintext corresponding to the target key obtains a data processing result corresponding to the target data, and further includes: Figure 4

[0050] In step S402, the service module parses the data key ciphertext in the data to be decrypted, and sends the data key ciphertext to the encryption and decryption program.

[0051] The data processing instruction includes a data decryption instruction, the target data includes the data to be decrypted, and the data processing result includes target decrypted data corresponding to the data to be decrypted.

[0052] Specifically, the service module can first parse the data key ciphertext and the index ciphertext from the data to be decrypted, and send them to the encryption and decryption program together with the key certificate.

[0053] ​Step S404, the service module receives the data key plaintext returned by the encryption and decryption program based on the data key ciphertext; the data key plaintext is obtained by the encryption and decryption program based on the target key plaintext decrypting the data key ciphertext.

[0054] Specifically, after the encryption and decryption program receives the data key ciphertext, the index ciphertext and the key certificate sent by the service module, the encryption and decryption program can first verify the authority relationship between the key certificate and the target key, and if the authority verification is passed, the encryption and decryption program further indexes according to the index ciphertext to obtain the target key and the target key plaintext, uses the target key plaintext to decrypt the data key ciphertext to obtain the data key plaintext, and returns the data key plaintext to the service module.

[0055] Step S406, the service module decrypts the to-be-decrypted data based on the data key plaintext to obtain target decryption data.

[0056] Specifically, after the service module receives the data key plaintext sent by the encryption and decryption program, the service module uses the data key plaintext to decrypt the initial decryption data extracted from the to-be-decrypted data to obtain the final target decryption data.

[0057] In an embodiment, after the service module completes the data encryption processing or the data decryption processing, the service module can clear the data key plaintext.

[0058] In this embodiment, by decrypting the data key plaintext first and then decrypting the to-be-decrypted data based on the data key plaintext, the security of the data in the decryption process is ensured.

[0059] In an embodiment, as shown in FIG. 6, before the step of responding to the data processing instruction for the target data, the process of receiving the target key plaintext is further included. Figure 5

[0060] Step S502, in response to a receiving instruction for the target key plaintext, a pre-stored protection key ciphertext is sent to the center server.

[0061] The receiving instruction is an instruction indicating that the cloud server requests the target key plaintext from the center server. The protection key ciphertext is the ciphertext of the protection key, and the protection key is a symmetric key that can be used to encrypt a public key. The public key can be used to decrypt the key encrypted by the private key, that is, the private key can encrypt the target key, and the public key can decrypt the target key. The protection key ciphertext is the ciphertext obtained by the center server using an encryption machine to encrypt a randomly generated symmetric key, and the center server distributes the protection key ciphertext to each cloud server for storage.

[0062] ​Specifically, the cloud server can further include a management program, which is equivalent to a key relay station. When the cloud server receives a receiving instruction for the target key plaintext, the cloud server obtains the pre-stored protection key ciphertext and sends the protection key ciphertext to the center server to request the protection key plaintext.

[0063] At step S504, the center server returns communication ciphertext based on the protection key ciphertext. The communication ciphertext is ciphertext obtained by encrypting the protection key plaintext based on multiple communication keys.

[0064] The communication key refers to a key for encrypting the protection key plaintext, and the communication key can include a local key, a database key, and a random key.

[0065] Specifically, after the center server receives the protection key ciphertext sent by the management program, the center server first decrypts the protection key ciphertext by using an encryption machine to obtain the protection key plaintext. To ensure the security of the protection key plaintext, the protection key plaintext can be encrypted, that is, the protection key plaintext is encrypted by using a communication key to obtain communication ciphertext, and the communication ciphertext is returned to the management program.

[0066] At step S506, the communication ciphertext is decrypted to obtain the protection key plaintext.

[0067] Specifically, after the management program receives the communication ciphertext, the management program first decrypts the random key, and then calculates the local key and the database key. The decryption method is not limited here, and the encryption machine can be used, or other decryption methods can be selected according to actual conditions. Finally, the protection key plaintext is obtained.

[0068] At step S508, the target key plaintext is obtained based on the protection key plaintext.

[0069] In an embodiment, the target key plaintext is obtained based on the protection key plaintext, and the method further includes: decrypting the public key ciphertext based on the protection key plaintext to obtain public key plaintext corresponding to the public key ciphertext; the public key ciphertext refers to ciphertext of a public key corresponding to a private key used to encrypt the target key in the center server; and obtaining the pre-stored target key ciphertext and decrypting the target key ciphertext by using the public key plaintext to obtain the target key plaintext.

[0070] The public key and the private key are a pair of asymmetric keys. In an example, the public key can be a root key, and the private key can be a cloud key.

[0071] In an embodiment, the center server can generate a private key plaintext and a public key plaintext corresponding to the private key plaintext in advance, encrypt the private key plaintext using the encryption machine to obtain a private key ciphertext, and encrypt the public key plaintext using the encryption machine to obtain a public key ciphertext.

[0072] It should be noted that before data processing, the center server can perform key initialization, that is, generate different types of keys, including a protection key, a private key, and a public key. The private key is used to encrypt the target key, the public key is used to decrypt the target key, and the protection key is used to encrypt and decrypt the public key.

[0073] Specifically, after the management program decrypts the protection key plaintext, the management program uses the protection key plaintext to decrypt the public key ciphertext to obtain the public key ciphertext encrypted using the encryption machine, and then uses the encryption machine to decrypt the current public key ciphertext to obtain the public key plaintext. It can be understood that after the center server generates the public key ciphertext, the center server sends the public key ciphertext to the cloud server for storage. Therefore, after the management program obtains the protection key plaintext, the management program can directly use the protection key plaintext to decrypt the public key ciphertext to obtain the public key plaintext. Since the target key is encrypted using the private key, the public key plaintext can be used for decryption, that is, the public key plaintext is used to decrypt the target key to obtain the target key plaintext.

[0074] In this embodiment, the target key is encrypted layer by layer, so when the target key plaintext is obtained, it also needs to be decrypted layer by layer. This greatly protects the security of the target key, thereby further protecting the security of subsequent data processing using the target key.

[0075] In a specific embodiment, as shown in Figure 6 The center server is deployed on a private cloud. It should be noted that the center server is not limited to being deployed on a private cloud, but can also be deployed on a public cloud. The cloud server is a server in a public cloud. Similarly, the cloud server is not limited to being a server in a public cloud, but can also be a server in a private cloud. The cloud server includes a management program, an encryption and decryption program, and a business module.

[0076] Before data processing, the center server can first perform key initialization, first create symmetric keys and asymmetric keys, the symmetric keys can be protection keys, the asymmetric keys can be public keys and private keys, the public keys can be cloud keys, and the private keys can be root keys. After encrypting these keys by the encryption machine, they are respectively stored in the database of the center server or the database of the cloud server. In this embodiment, the root key plaintext is encrypted by the HSM (Hardware Security Module) to generate a root key ciphertext, which is stored in the private cloud database. The protection key plaintext is encrypted by the HSM to generate a protection key ciphertext, which is stored in the public cloud database. The cloud key plaintext is encrypted by the HSM to generate a temporary cloud key ciphertext, which is stored in the public cloud database. The temporary cloud key ciphertext is further encrypted by the protection key ciphertext in the public cloud to obtain the final cloud key ciphertext. Storing each key in different cloud sides can further ensure the security of the key.

[0077] After the center server creates different types of keys, it needs to create a unified target key for data encryption and decryption, that is, a cmk key. When creating the cmk key, the center server can synchronously generate the cmk plaintext of the cmk key. It can be understood that subsequent data encryption and decryption processing is realized by the cmk plaintext. In order to ensure the security of the cmk plaintext, the center server encrypts the cmk plaintext by using the encrypted root key ciphertext to obtain the cmk ciphertext, and sends it to the database of the cloud server for storage. It should be noted that when the center server synchronizes the cmk ciphertext to the cloud server, it generates a key certificate corresponding to the cmk key, that is, an AK / SK certificate. The AK / SK certificate is used to verify whether the target object initiating the data encryption and decryption instruction has the permission to use the cmk key.

[0078] Since the cmk ciphertext is stored in the cloud server, the cloud server needs to use the cmk plaintext when processing data, and therefore the cloud server needs to decrypt the cmk ciphertext. The management program in the cloud server sends the protection key ciphertext to the center server to request the protection key plaintext from the center server. After receiving the protection key ciphertext, the center server first decrypts the protection key ciphertext through the encryption machine to obtain the protection key plaintext. In order to ensure the security of the protection key plaintext in the transmission process, the center server encrypts the protection key plaintext using the local key, the database key and the random key to obtain a communication ciphertext, and returns the communication ciphertext to the management program. After receiving the communication ciphertext, the management program first decrypts the random key, then calculates the local key and the database key, and finally calculates the protection key plaintext. It can be understood that, since the cmk ciphertext is encrypted by the root key ciphertext, and the root key and the cloud key are a set of asymmetric keys, the root key ciphertext can be used to encrypt the cmk plaintext, and the cloud key ciphertext can be used to decrypt the cmk ciphertext. Since the cloud key ciphertext is encrypted by the protection key ciphertext, and the protection key is a symmetric key, the protection key ciphertext is directly decrypted to obtain the protection key plaintext, and then the protection key plaintext is used to decrypt the cloud key ciphertext to obtain the temporary cloud key ciphertext encrypted by the encryption machine, and then the encryption machine is used to decrypt the temporary cloud key ciphertext to obtain the cloud key plaintext, and finally the cloud key plaintext is used to decrypt the cmk ciphertext to obtain the cmk plaintext.

[0079] When the service module in the cloud server receives a data encryption instruction for the to-be-encrypted data, it first acquires the AK / SK credential carried by the instruction and sends the credential to the encryption and decryption program in the cloud server. After receiving the key credential, the encryption and decryption program first verifies whether the key credential has a permission relationship with the cmk key, that is, verifies whether the target object corresponding to the key credential has the permission to use the cmk key. When the verification result indicates that the target object has the permission to use the cmk key, the encryption and decryption program randomly generates a unique data key plaintext, that is, dek plaintext, acquires the cmk key and the cmk plaintext of the cmk key, and encrypts the dek plaintext using the cmk plaintext to obtain the data key ciphertext, that is, dek ciphertext. Finally, the encryption and decryption program returns the dek plaintext and the dek ciphertext to the service module, so that the service module uses the dek plaintext to encrypt the to-be-encrypted data to obtain initial encrypted data, and then combines the initial encrypted data, the dek ciphertext and the cmk index ciphertext to obtain the final target encrypted data.

[0080] When the service module in the cloud server receives the data decryption instruction for the to-be-decrypted data, the AK / SK credential carried by the instruction is first acquired, and the dek ciphertext, the cmk index ciphertext and the initial decrypted data are parsed from the to-be-decrypted data, and the dek ciphertext, the cmk index ciphertext, the initial decrypted data and the AK / SK credential are sent to the encryption and decryption program. The encryption and decryption program first verifies whether the target object initiating the data decryption instruction has the permission to use the cmk key, and when the verification result indicates that the target object has the permission to use the cmk key, the encryption and decryption program decrypts the cmk index ciphertext to obtain the cmk index, and queries according to the cmk index to obtain the cmk plaintext. The dek ciphertext is decrypted by using the cmk plaintext to obtain the dek plaintext, and is returned to the service module. The service module decrypts the initial decrypted data by using the received dek plaintext to obtain the final target decrypted data.

[0081] In the embodiment, the center server pre-generates a unified key, i.e., a cmk key, and issues the cmk key to each cloud server. Each cloud server first acquires the AK / SK credential corresponding to the data processing instruction for the target data, thereby querying the corresponding cmk key based on the AK / SK credential, and finally performs data encryption processing on the to-be-encrypted data based on the cmk plaintext corresponding to the cmk key, to obtain the target encrypted data corresponding to the to-be-encrypted data, or performs data decryption processing on the to-be-decrypted data, to obtain the target decrypted data corresponding to the to-be-decrypted data. Since the cmk key is unified among the cloud servers, data can be processed on each cloud server, thereby overcoming the technical defect that the data cannot be processed on other cloud servers due to different encryption and decryption modes among the cloud servers, thereby reducing the efficiency of data processing. Therefore, the above method can effectively improve the efficiency of data processing. Moreover, the cmk key is encrypted based on other different types of keys, thereby further ensuring the security of the cmk key, and protecting the security in the process of data processing based on the cmk key.

[0082] It should be understood that, although each step in the flowchart involved in each of the above embodiments is displayed in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other sequences. Moreover, at least part of the steps in the flowchart involved in each of the above embodiments can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.

[0083] Based on the same inventive concept, the embodiments of the present application also provide a multi-cloud key-based data processing apparatus for implementing the above-mentioned multi-cloud key-based data processing method. The implementation scheme for solving the problem provided by the apparatus is similar to the implementation scheme described in the above-mentioned method, and therefore the specific limitations in one or more multi-cloud key-based data processing apparatus embodiments provided below can refer to the limitations of the multi-cloud key-based data processing method described above, which will not be repeated here.

[0084] In one embodiment, as shown in Figure 7 A multi-cloud key-based data processing apparatus is provided, comprising: a credential acquisition module 702, a key acquisition module 704, and a data processing module 706, wherein:

[0085] The credential acquisition module 702 is configured to acquire a key credential corresponding to a data processing instruction in response to the data processing instruction for target data; the key acquisition module 704 is configured to query a target key corresponding to the key credential through the key credential; the target key is a unified key issued by a center server to a cloud server, and the unified key is generated based on a plurality of different types of keys; and the data processing module 706 is configured to perform data processing on the target data based on a target key plaintext corresponding to the target key, to obtain a data processing result corresponding to the target data.

[0086] In one embodiment, the data processing module 706 further comprises: a data receiving unit configured to receive a data key plaintext and a data key ciphertext sent by an encryption and decryption program through a business module; the data key ciphertext is obtained by encrypting the data key plaintext based on the target key plaintext by the encryption and decryption program; an encryption processing unit configured to encrypt to-be-encrypted data based on the data key plaintext by the business module to obtain initial encrypted data corresponding to the to-be-encrypted data; and a combination unit configured to combine the data key ciphertext and the initial encrypted data to obtain target encrypted data.

[0087] In one embodiment, the key acquisition module 704 is further configured to verify a use permission of the target object using the target key through the key credential to obtain a use permission verification result, wherein the target object is a user triggering the data processing instruction; and the target key is acquired when the use permission verification result indicates that the target object has the use permission of the target key.

[0088] In one of the embodiments, the data processing module 706 is further configured to: parse, by the service module, the data key ciphertext in the data to be decrypted, and send the data key ciphertext to the encryption and decryption program; receive, by the service module, the data key plaintext returned by the encryption and decryption program based on the data key ciphertext; the data key plaintext is obtained by the encryption and decryption program based on the target key plaintext decrypting the data key ciphertext; and decrypt, by the service module, the data to be decrypted based on the data key plaintext to obtain the target decrypted data.

[0089] In one of the embodiments, the multi-cloud key-based data processing apparatus further includes: a protection key sending unit configured to send, in response to a receiving instruction for the target key plaintext, the pre-stored protection key ciphertext to the center server; a communication ciphertext receiving unit configured to receive the communication ciphertext returned by the center server based on the protection key ciphertext; the communication ciphertext is ciphertext obtained by encrypting the protection key plaintext based on a plurality of communication keys; a decryption unit configured to decrypt the communication ciphertext to obtain the protection key plaintext; and a target key plaintext obtaining unit configured to obtain the target key plaintext based on the protection key plaintext.

[0090] In one of the embodiments, the target key plaintext obtaining unit is further configured to: decrypt, based on the protection key plaintext, the public key ciphertext to obtain the public key plaintext corresponding to the public key ciphertext; the public key ciphertext is ciphertext of a public key corresponding to a private key used to encrypt the target key in the center server; and obtain the pre-stored target key ciphertext, and decrypt, by the public key plaintext, the target key ciphertext to obtain the target key plaintext.

[0091] The above-mentioned modules in the multi-cloud key-based data processing apparatus can be all or partially implemented by software, hardware, and combinations thereof. The above-mentioned modules can be embedded in or independent of a processor in a computer device in a hardware form, or can be stored in a memory in the computer device in a software form, so as to be called and executed by a processor to perform the operations corresponding to the above-mentioned modules.

[0092] In one of the embodiments, a computer device is provided, which can be a server, and an internal structure diagram of the computer device can be as shown in FIG. 1. Figure 8As shown in the figure. The computer device includes a processor, a memory and a network interface connected by a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store item recommendation data. The network interface of the computer device is used to communicate with external terminals through network connection. The computer program is executed by the processor to implement a multi-cloud key-based data processing method.

[0093] Those skilled in the art can understand that, Figure 8 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.

[0094] In one embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the following steps: in response to a data processing instruction for target data, obtaining a key certificate corresponding to the data processing instruction; querying a target key corresponding to the key certificate through the key certificate; the target key is a unified key issued by a center server to a cloud server, and the unified key is generated based on a plurality of different types of keys; based on a target key plaintext corresponding to the target key, performing data processing on the target data to obtain a data processing result corresponding to the target data.

[0095] In one embodiment, the processor executing the computer program further implements the following steps: receiving, by a business module, a data key plaintext and a data key ciphertext sent by an encryption and decryption program; the data key ciphertext is obtained by encrypting the data key plaintext based on the target key plaintext by the encryption and decryption program; the business module encrypts the data to be encrypted based on the data key plaintext to obtain initial encrypted data corresponding to the data to be encrypted; and the data key ciphertext and the initial encrypted data are combined to obtain target encrypted data.

[0096] In one embodiment, the processor executing the computer program further implements the following steps: verifying, by the key certificate, the permission of the target object to use the target key to obtain a use permission verification result, wherein the target object is a user triggering the data processing instruction; and obtaining the target key when the use permission verification result indicates that the target object has the permission to use the target key.

[0097] In one embodiment, the processor, when executing the computer program, also implements the following steps: through the business module, parsing the data key ciphertext in the data to be decrypted, and sending the data key ciphertext to the encryption and decryption program; the business module receives the data key plaintext returned by the encryption and decryption program based on the data key ciphertext; the data key plaintext is obtained by the encryption and decryption program based on the target key plaintext decrypting the data key ciphertext; the business module decrypts the data to be decrypted based on the data key plaintext to obtain the target decryption data.

[0098] In one embodiment, the processor, when executing the computer program, also implements the following steps: in response to the receiving instruction for the target key, sending the pre-stored protection key ciphertext to the center server; receiving the communication ciphertext returned by the center server based on the protection key ciphertext; the communication ciphertext is the ciphertext obtained by encrypting the protection key plaintext based on a plurality of communication keys; decrypting the communication ciphertext to obtain the protection key plaintext; obtaining the target key plaintext based on the protection key plaintext.

[0099] In one embodiment, the processor, when executing the computer program, also implements the following steps: based on the protection key plaintext, decrypting the public key ciphertext to obtain the public key plaintext corresponding to the public key ciphertext; the public key plaintext refers to the plaintext of the public key corresponding to the private key for encrypting the target key in the center server; obtaining the pre-stored target key ciphertext, and decrypting the target key ciphertext through the public key plaintext to obtain the target key plaintext.

[0100] In one embodiment, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the following steps: in response to a data processing instruction for target data, obtaining a key credential corresponding to the data processing instruction; querying the target key corresponding to the key credential through the key credential; the target key refers to a unified key issued by a center server to a cloud server, and the unified key is generated based on a plurality of different types of keys; based on the target key plaintext corresponding to the target key, processing the target data to obtain a data processing result corresponding to the target data.

[0101] In one embodiment, the computer program is executed by the processor to also implement the following steps: through the business module, receiving the data key plaintext and the data key ciphertext sent by the encryption and decryption program; the data key ciphertext is obtained by the encryption and decryption program based on the target key plaintext encrypting the data key plaintext; the business module encrypts the data to be encrypted based on the data key plaintext to obtain the initial encrypted data corresponding to the data to be encrypted; combining the data key ciphertext and the initial encrypted data to obtain the target encrypted data.

[0102] In one embodiment, the computer program, when executed by the processor, further implements the following steps: verifying, by the key credential, the right of the target object to use the target key, to obtain a use right verification result, wherein the target object is a user triggering the data processing instruction; and obtaining the target key when the use right verification result indicates that the target object has the right to use the target key.

[0103] In one embodiment, the computer program, when executed by the processor, further implements the following steps: parsing, by the business module, the data key ciphertext in the to-be-decrypted data, and sending the data key ciphertext to the encryption and decryption program; the business module receives the data key plaintext returned by the encryption and decryption program based on the data key ciphertext; the data key plaintext is obtained by the encryption and decryption program based on the target key plaintext decrypting the data key ciphertext; and the business module decrypts the to-be-decrypted data based on the data key plaintext to obtain the target decrypted data.

[0104] In one embodiment, the computer program, when executed by the processor, further implements the following steps: in response to a receiving instruction for the target key, sending the pre-stored protection key ciphertext to the center server; receiving the communication ciphertext returned by the center server based on the protection key ciphertext; the communication ciphertext is ciphertext obtained by encrypting the protection key plaintext based on a plurality of communication keys; decrypting the communication ciphertext to obtain the protection key plaintext; and obtaining the target key plaintext based on the protection key plaintext.

[0105] In one embodiment, the computer program, when executed by the processor, further implements the following steps: decrypting, based on the protection key plaintext, the public key ciphertext to obtain the public key plaintext corresponding to the public key ciphertext; the public key plaintext refers to the plaintext of the public key corresponding to the private key used to encrypt the target key in the center server; obtaining the pre-stored target key ciphertext, and decrypting the target key ciphertext based on the public key plaintext to obtain the target key plaintext.

[0106] In one embodiment, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the following steps: in response to a data processing instruction for target data, obtaining a key credential corresponding to the data processing instruction; querying, by the key credential, a target key corresponding to the key credential; the target key is a unified key issued by a center server to a cloud server, and the unified key is generated based on a plurality of different types of keys; and performing data processing on the target data based on a target key plaintext corresponding to the target key, to obtain a data processing result corresponding to the target data.

[0107] In one embodiment, the computer program, when executed by the processor, further implements the following steps: receiving, by the business module, the data key plaintext and the data key ciphertext sent by the encryption and decryption program; the data key ciphertext is obtained by the encryption and decryption program encrypting the data key plaintext based on the target key plaintext; the business module encrypts the to-be-encrypted data based on the data key plaintext to obtain initial encrypted data corresponding to the to-be-encrypted data; and the data key ciphertext and the initial encrypted data are combined to obtain the target encrypted data.

[0108] In one embodiment, the computer program, when executed by the processor, further implements the following steps: verifying, by the key certificate, the permission of the target object to use the target key to obtain a use permission verification result, wherein the target object is a user triggering the data processing instruction; and obtaining the target key when the use permission verification result indicates that the target object has the permission to use the target key.

[0109] In one embodiment, the computer program, when executed by the processor, further implements the following steps: receiving, by the business module, the data key plaintext and the data key ciphertext sent by the encryption and decryption program; the data key ciphertext is obtained by the encryption and decryption program encrypting the data key plaintext based on the target key plaintext; and the business module encrypts the to-be-encrypted data based on the data key plaintext and the data key ciphertext to obtain the target encrypted data.

[0110] In one embodiment, the computer program, when executed by the processor, further implements the following steps: in response to a receiving instruction for the target key, sending the pre-stored protection key ciphertext to the center server; receiving the communication ciphertext returned by the center server based on the protection key ciphertext; the communication ciphertext is ciphertext obtained by encrypting the protection key plaintext based on a plurality of communication keys; decrypting the communication ciphertext to obtain the protection key plaintext; and obtaining the target key plaintext based on the protection key plaintext.

[0111] In one embodiment, the computer program, when executed by the processor, further implements the following steps: decrypting, based on the protection key plaintext, the public key ciphertext to obtain the public key plaintext corresponding to the public key ciphertext; the public key plaintext is plaintext of a public key corresponding to a private key used to encrypt the target key in the center server; obtaining the pre-stored target key ciphertext, and decrypting the target key ciphertext based on the public key plaintext to obtain the target key plaintext.

[0112] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties.

[0113] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.

[0114] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist, it should be considered as the scope of the present application.

[0115] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A multi-cloud key-based data processing method, characterized by, The method applied to a cloud server comprises: In response to a data processing instruction for target data, a key certificate corresponding to the data processing instruction is acquired; A target key corresponding to the key certificate is obtained by querying through the key certificate; the target key is a unified key issued by a center server to the cloud server, and the unified key is generated based on multiple different types of keys; Based on a target key plaintext corresponding to the target key, the target data is processed to obtain a data processing result corresponding to the target data.

2. The method of claim 1, wherein, The cloud server comprises an encryption and decryption program and a business module, the data processing instruction comprises a data encryption instruction, the target data comprises to-be-encrypted data, and the data processing result comprises target encrypted data corresponding to the to-be-encrypted data; Based on a target key plaintext corresponding to the target key, the target data is processed to obtain a data processing result corresponding to the target data, which comprises: The business module receives data key plaintext and data key ciphertext sent by the encryption and decryption program; the data key ciphertext is obtained by the encryption and decryption program based on the target key plaintext encrypting the data key plaintext; The business module encrypts the to-be-encrypted data based on the data key plaintext to obtain initial encrypted data corresponding to the to-be-encrypted data; The data key ciphertext and the initial encrypted data are combined to obtain the target encrypted data.

3. The method of claim 1, wherein, The target key corresponding to the key certificate is obtained by querying through the key certificate, which comprises: The use permission of the target object using the target key is verified through the key certificate to obtain a use permission verification result, wherein the target object is a user triggering the data processing instruction; When the use permission verification result indicates that the target object has the permission to use the target key, the target key is acquired.

4. The method of claim 1, wherein, The cloud server comprises an encryption and decryption program and a business module, the data processing instruction comprises a data decryption instruction, the target data comprises to-be-decrypted data, and the data processing result comprises target decrypted data corresponding to the to-be-decrypted data; Based on a target key plaintext corresponding to the target key, the target data is processed to obtain a data processing result corresponding to the target data, which comprises: The data key ciphertext in the to-be-decrypted data is parsed by the business module, and the data key ciphertext is sent to the encryption and decryption program; The business module receives data key plaintext returned by the encryption and decryption program based on the data key ciphertext; the data key plaintext is obtained by the encryption and decryption program based on the target key plaintext decrypting the data key ciphertext; The business module decrypts the to-be-decrypted data based on the data key plaintext to obtain the target decrypted data.

5. The method of claim 1, wherein, Before the step of responding to the data processing instruction for the target data, the method further comprises a process of receiving the target key plaintext: In response to a receiving instruction for the target key plaintext, a pre-stored protection key ciphertext is sent to the center server; receive communication ciphertext returned by the center server based on the protection key ciphertext; the communication ciphertext is ciphertext obtained by encrypting the protection key plaintext based on multiple communication keys; decrypt the communication ciphertext to obtain the protection key plaintext; obtain the target key plaintext based on the protection key plaintext.

6. The method of claim 5, wherein, The obtaining the target key plaintext based on the protection key plaintext comprises: decrypt the public key ciphertext based on the protection key plaintext to obtain public key plaintext corresponding to the public key ciphertext; the public key ciphertext refers to ciphertext of a public key corresponding to a private key used to encrypt the target key plaintext in the center server; obtain target key ciphertext stored in advance and decrypt the target key ciphertext based on the public key plaintext to obtain the target key plaintext.

7. A multi-cloud key based data processing apparatus, characterized by, The apparatus comprises: a credential obtaining module configured to obtain a key credential corresponding to a data processing instruction in response to the data processing instruction for target data; a key obtaining module configured to query a target key corresponding to the key credential based on the key credential; the target key refers to a unified key issued by a center server to the cloud server, and the unified key is generated based on multiple different types of keys; a data processing module configured to perform data processing on the target data based on target key plaintext corresponding to the target key to obtain a data processing result corresponding to the target data.

8. A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that, The processor executes the computer program to implement the steps of the method in any one of claims 1 to 6.

9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method in any one of claims 1 to 6.

10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method for key management and computer-based system

    CN117063439A

  • Distributed key management system

    US11658812B1

  • Cross-region replication of secrets

    US11849037B1