Key updating method, encryption communication method, device, equipment and storage medium

By querying the consistency of the master key tag in the key cluster within financial information systems such as banks, updating the subkey, and switching the master key tag, the problem of business transaction impact during key updates and cryptographic algorithm switching is solved, achieving smooth key updates and business continuity.

CN121841606APending Publication Date: 2026-04-10CHINA EVERBRIGHT BANK
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-08
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

In financial information systems such as banks, how can we ensure that the correctness and continuity of business transactions are not affected during key updates and cryptographic algorithm switching, especially in distributed, high-concurrency information systems?

Method used

Before updating the key, the consistency of the master key tag of the original key in the entire cryptographic operation cluster is queried. If they are consistent, the subkey is updated; if they are inconsistent, the update is prohibited. After the update is completed, the master key tag is switched and the key attributes are updated synchronously, ensuring the smoothness and agility of business applications during the key update process.

Benefits of technology

It ensures the correctness and continuity of business transactions during the key update process, avoids business impact caused by key errors, and improves the smoothness and agility of key updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841606A_ABST
    Figure CN121841606A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of cryptography, and provides a key updating method, an encryption communication method, a device, equipment and a storage medium, and the method comprises the steps: receiving a key updating request for a target service application represented by a key main index; determining a key sub-index corresponding to the key main index in the full-quantity cryptographic operation cluster; the key sub-index comprises an original key and a key group thereof; determining whether the master key tags corresponding to the original keys in the full-quantity cryptographic operation cluster are consistent; the master key label indicates a master key currently enabled by the original key in the key group; if yes, key updating is carried out on a current auxiliary key of the original key in the full-amount cryptographic operation cluster, and the auxiliary key is the other keys in the key group; and if not, prohibiting key updating on the target service application. According to the embodiment of the invention, the influence on the correctness and continuity of business transaction during key value updating and cryptographic algorithm switching can be reduced or solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cryptography, and in particular to a key update method, encrypted communication method, apparatus, device, and storage medium. Background Technology

[0002] To enhance data security, financial information systems such as banks require regular updates to the keys used for data encryption. Key updates involve either updating the key value or switching cryptographic algorithms.

[0003] Key value updates refer to updating only the key value without updating the cryptographic algorithm, algorithm strength, or other key attributes. This is a standard requirement for key updates and is commonly used to reduce the risk of key leakage, prevent key cracking, and protect data security. Cryptographic algorithm switching, on the other hand, involves updating not only the key value but also changing the cryptographic algorithm, algorithm strength, and other key attributes. This is a less standard requirement, such as replacing international cryptographic algorithms (RSA, DES, etc.) with Chinese cryptographic algorithms (SM2, SM4, etc.); replacing traditional cryptographic algorithms (RSA / DES / SM2 / SM4 are all traditional algorithms) with quantum-resistant cryptographic algorithms, or vice versa, or switching between different quantum-resistant cryptographic algorithms. With the development of quantum computing technology, this need for cryptographic algorithm agility will become even more urgent in the future.

[0004] Regardless of the specific key update requirement, in information systems like those in banking where business continuity is paramount, it's essential that every transaction remains unaffected during the key update process and before the keys are fully synchronized. This is extremely challenging for distributed, high-concurrency information systems, especially given the frequent changes in cryptographic algorithms, which place even greater demands on the agility of the cryptographic service platform. Therefore, there is an urgent need for a key update solution that can ensure the correctness and continuity of business transactions remain unaffected during key value updates and cryptographic algorithm switching. Summary of the Invention

[0005] The purpose of this application is to provide a key update method, encrypted communication method, apparatus, device, and storage medium to reduce or resolve the impact on the correctness and continuity of business transactions during key value updates and cryptographic algorithm switching.

[0006] To achieve the above objectives, in one aspect, embodiments of this application provide a key update method, including:

[0007] Receive key update requests for target business applications represented by the key master index;

[0008] Determine the key sub-index corresponding to the key master index in the full cryptographic operation cluster; the key sub-index includes the original key and its key group.

[0009] Confirm whether the master key label corresponding to the original key in the full cryptographic operation cluster is consistent; the master key label indicates the master key currently enabled by the original key in the key group.

[0010] If the master key tags are consistent, then the current subkey of the original key in the full cryptographic operation cluster is updated, and the subkey is the remaining key in the key group;

[0011] If the master key labels are inconsistent, key updates for the target business application are prohibited.

[0012] In the key update method of this application embodiment, after updating the subkey of the original key in the full cryptographic operation cluster, it further includes:

[0013] Confirm whether the current subkey updates for the original keys in the full cryptographic operation cluster have all been completed;

[0014] If all operations are completed, in the full-scale cryptographic operation cluster, the master key tag corresponding to the original key is switched to point to one of the updated subkeys, and the key attributes corresponding to the original key are updated synchronously to make them consistent with the key attributes of the switched master key.

[0015] In the key update method of this application embodiment, before receiving the key update request for the target business application represented by the key master index, it further includes:

[0016] Maintain a key storage structure containing key records; the key record includes: a key master index, a key sub-index, a master key label, and key attributes; the key master index corresponds to a unique business application; the key sub-index contains the original key and its key group; the master key label indicates the master key currently enabled by the original key in the key group.

[0017] In the key update method of this application embodiment, the key update includes: updating the key value, changing the cryptographic algorithm and / or changing the key strength.

[0018] In the key update method of this application embodiment, the key update request is triggered based on an event or a timer.

[0019] On the other hand, embodiments of this application also provide an encrypted communication method, including:

[0020] Receive a first cryptographic operation request initiated by a first business application; the first cryptographic operation request includes: first data, the key master index and key sub-index of the first business application, and the key sub-index includes the original key;

[0021] Match the key record corresponding to the key master index and the original key from the key storage structure;

[0022] The first cryptographic operation parameters and the master key tag are determined based on the key attributes in the key record;

[0023] The first cryptographic operation is performed on the first data according to the first cryptographic operation parameters to obtain the second data;

[0024] The second data and the master key tag are returned to the first business application.

[0025] In the encrypted communication method of this application embodiment, the first cryptographic operation parameters include: the key value, key strength, and cryptographic algorithm of the original key.

[0026] In the encrypted communication method of this application embodiment, the first cryptographic operation is an encryption operation or a signature operation.

[0027] On the other hand, embodiments of this application also provide another encrypted communication method, including:

[0028] Receive a second cryptographic operation request initiated by a second business application; the second cryptographic operation request includes: second data, a master key tag associated with the second data, and a key master index of the second business application;

[0029] Match the key record corresponding to the key master index and the master key label from the key storage structure;

[0030] The second cryptographic operation parameters are determined based on the key attributes in the key record;

[0031] Perform a second cryptographic operation on the second data according to the second cryptographic operation parameters to obtain the first data;

[0032] Return the first data to the second business application.

[0033] In the encrypted communication method of this application embodiment, the second cryptographic operation parameters include: the key value, key strength, and cryptographic algorithm of the master key tag.

[0034] In the encrypted communication method of this application embodiment, the second cryptographic operation is a decryption operation or a signature verification operation.

[0035] On the other hand, embodiments of this application also provide a key update device, including:

[0036] The first receiving module is used to receive key update requests for the target business application represented by the key master index;

[0037] The first determining module is used to determine the key sub-index corresponding to the key master index in the full cryptographic operation cluster; the key sub-index includes the original key and its key group.

[0038] The key update module is used to confirm whether the master key label corresponding to the original key in the full cryptographic operation cluster is consistent; the master key label indicates the master key currently enabled by the original key in the key group; if the master key labels are consistent, the current secondary key of the original key in the full cryptographic operation cluster is updated, and the secondary key is the other key in the key group; if the master key labels are inconsistent, key updates for the target business application are prohibited.

[0039] The key update device in this application embodiment further includes:

[0040] The master key switching module is used to confirm whether the current subkey updates of the original key in the full cryptographic operation cluster have been completed. If they have been completed, in the full cryptographic operation cluster, the master key tag corresponding to the original key is switched to point to one of the updated subkeys, and the key attributes corresponding to the original key are updated synchronously to make them consistent with the key attributes of the switched master key.

[0041] On the other hand, embodiments of this application also provide an encrypted communication device, including:

[0042] The second receiving module is used to receive a first cryptographic operation request initiated by the first business application; the first cryptographic operation request includes: first data, the key master index and key sub-index of the first business application, and the key sub-index includes the original key;

[0043] The first matching module is used to match the key record corresponding to the key master index and the original key from the key storage structure;

[0044] The second determining module is used to determine the first cryptographic operation parameters and the master key tag based on the key attributes in the key record;

[0045] The first execution module is configured to perform a first cryptographic operation on the first data according to the first cryptographic operation parameters to obtain the second data;

[0046] The first return module is used to return the second data and the master key tag to the first business application.

[0047] On the other hand, embodiments of this application also provide another encrypted communication device, including:

[0048] The third receiving module is used to receive a second cryptographic operation request initiated by the second business application; the second cryptographic operation request includes: second data, a master key tag associated with the second data, and a key master index of the second business application;

[0049] The second matching module is used to match the key record corresponding to the key master index and the master key label from the key storage structure;

[0050] The third determining module is used to determine the second cryptographic operation parameters based on the key attributes in the key record;

[0051] The second execution module is used to perform a second cryptographic operation on the second data according to the second cryptographic operation parameters to obtain the first data;

[0052] The second return module is used to return the first data to the second business application.

[0053] On the other hand, embodiments of this application also provide a computer device, including a memory, a processor, and a computer program stored in the memory, wherein the computer program, when run by the processor, executes instructions of the above-described method.

[0054] On the other hand, embodiments of this application also provide a computer storage medium storing a computer program thereon, wherein the computer program, when run by the processor of a computer device, executes instructions for the above-described method.

[0055] On the other hand, embodiments of this application also provide a computer program product, which includes a computer program that, when run by the processor of a computer device, executes instructions for the above-described method.

[0056] As can be seen from the technical solutions provided in the embodiments of this application above, in these embodiments, the key sub-index includes the original key and its key group. A master key tag can dynamically identify one key in the key group as the master key, while the remaining keys in the key group serve as sub-keys. When a key update request representing a business application using the key master index is received, the system first checks whether the key activation status (i.e., the value of the master key tag) of the original key of the business application is consistent across all cryptographic operation clusters. If consistent, the sub-keys corresponding to the business application in all cryptographic operation clusters can be updated. Since the update is of the sub-key, even if there are ongoing transactions for the business application during the update period, it does not affect the use of the corresponding master key for cryptographic operations in each cryptographic operation cluster. This avoids impacting the correctness and continuity of business transactions during key updates. If inconsistent, key updates for the business application are prohibited, thus preventing key corruption from affecting the correctness and consistency of the business. This achieves smoothness and agility in key updates.

[0057] In addition, in this embodiment of the application, the master key label can also be switched. When switching, the second business application selects the key sub-index to be used according to the master key label sent by the first business application, instead of using the master key label of the original key. At this time, it is allowed that the master key labels of the original keys of different cryptographic services in the cryptographic computing cluster are inconsistent, that is, the enabled key states are different, so that the switching of the master key label does not affect the in-transit transactions of the business application. Attached Figure Description

[0058] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:

[0059] Figure 1 This application shows a schematic diagram of the service architecture of the cryptographic service platform in some embodiments;

[0060] Figure 2 Flowcharts of key update methods in some embodiments of this application are shown;

[0061] Figure 3 Flowcharts of key update methods in other embodiments of this application are shown;

[0062] Figure 4 Flowcharts of encrypted communication methods in some embodiments of this application are shown;

[0063] Figure 5Flowcharts of encrypted communication methods in other embodiments of this application are shown;

[0064] Figure 6 The illustration shows schematic diagrams of key update and cryptographic operations performed on a cryptographic service platform in some embodiments of this application;

[0065] Figure 7 The following are structural block diagrams of the key update apparatus in some embodiments of this application;

[0066] Figure 8 The following are structural block diagrams of encrypted communication devices in some embodiments of this application;

[0067] Figure 9 Structural block diagrams of encrypted communication devices in other embodiments of this application are shown;

[0068] Figure 10 A structural block diagram of a computer device in some embodiments of this application is shown.

[0069] [Explanation of Labels in the Attached Image]

[0070] 10. Cryptography service platform;

[0071] 20. Business Cluster;

[0072] 71. First receiving module;

[0073] 72. First Determined Module;

[0074] 73. Key update module;

[0075] 74. Master key switching module;

[0076] 81. Second receiving module;

[0077] 82. First matching module;

[0078] 83. Second Determination Module;

[0079] 84. First execution module;

[0080] 85. First return module;

[0081] 91. Third receiving module;

[0082] 92. Second matching module;

[0083] 93. The third determining module;

[0084] 94. Second execution module;

[0085] 95. Second return module;

[0086] 1002. Computer equipment;

[0087] 1004, Processor;

[0088] 1006. Memory;

[0089] 1008. Drive mechanism;

[0090] 1010. Input / output interface;

[0091] 1012. Input devices;

[0092] 1014. Output devices;

[0093] 1016. Presentation device;

[0094] 1018. Graphical User Interface;

[0095] 1020. Network interface;

[0096] 1022. Communication link;

[0097] 1024. Communication bus. Detailed Implementation

[0098] To enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this application.

[0099] It should be noted that in the embodiments of this application, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved are all information and data authorized and agreed upon by the user and fully authorized by all parties. That is, the acquisition, transmission, storage, use, and processing of data in the technical solution of this application all comply with the relevant provisions of national laws and regulations.

[0100] Figure 1 The diagram shows a service architecture schematic of a cryptographic service platform in some embodiments of this application; the cryptographic service platform 10 includes a key management cluster (such as...). Figure 1 The key management service 1 and key management service 2) and the cryptographic operation cluster; the key management cluster can maintain and update the keys of the cryptographic operation cluster (e.g., push keys to the cryptographic operation cluster); the cryptographic operation cluster is a business cluster 20 (such as... Figure 1The application includes Business Application 1, Business Application 2, etc., and these applications can communicate with each other for business transactions. It provides cryptographic computation services (e.g., ...). Figure 1 The cryptographic service platform 10 manages the keys used by various business applications, assigns key pairs to them and stores them (key pairs can be the public and private keys of an asymmetric key, or different ciphertext instances of a symmetric key with the same plaintext). Different business applications may access different cryptographic service nodes and use different key instances of the same key pair for encrypted communication.

[0101] This application provides a key update method that can be applied to the aforementioned cryptographic service platform. (Refer to...) Figure 2 As shown, in some embodiments of this application, the key update method may include the following steps:

[0102] Step 201: Receive a key update request for the target business application represented by the key master index.

[0103] Step 202: Determine the key sub-index corresponding to the key master index in the full cryptographic operation cluster; the key sub-index includes the original key and its key group.

[0104] Step 203: Confirm whether the master key tags corresponding to the original keys in the full cryptographic operation cluster are consistent. The master key tag indicates the currently enabled master key for the original key in the key group; if the master key tags are consistent, proceed to step 204; otherwise, proceed to step 205.

[0105] Step 204: Update the subkey of the original key in the full cryptographic operation cluster. The subkey is the remaining key in the key group.

[0106] Step 205: Prohibit key updates for the target business application.

[0107] In this embodiment, the key sub-index includes the original key and its key group. A master key tag dynamically identifies one key in the key group as the master key, while the remaining keys in the key group serve as sub-keys. When a key update request representing a business application using the key master index is received, the system first checks whether the original key of the business application is consistent across all cryptographic clusters in terms of key activation status (i.e., the value of the master key tag). If consistent, the sub-keys corresponding to the business application in all cryptographic clusters can be updated. Since only sub-keys are updated, even if there are ongoing transactions for the business application during the update period, it does not affect the use of the corresponding master key for cryptographic operations in each cryptographic cluster. This avoids impacting the correctness and continuity of business transactions during key updates. If inconsistent, key updates for the business application are prohibited, preventing key corruption from affecting the correctness and consistency of the business. This achieves smooth and agile key updates. This embodiment supports smooth key updates in any communication scenario between business applications, such as one-to-one or one-to-many interactions.

[0108] In some embodiments of this application, a key storage structure containing key records can be maintained in advance before receiving a key update request for a target business application represented by a key master index. Each cryptographic operation cluster of the cryptographic service platform maintains a local key storage structure.

[0109] In the key storage structure of this application embodiment, key information is stored in a structured form. For example, taking the database table storage form as an example, the table structure includes a key master index, a key sub-index, a master key label, and key attribute fields (such as key value, cryptographic algorithm, key strength, etc.).

[0110] Key Master Index: Uniquely identifies a business application in the context of key usage. It is the smallest unit of identification for a business application. Each key master index belongs to a unique business application, and different business applications correspond to different key master indices.

[0111] Key sub-index: Each key master index corresponds to multiple sub-indexes (enumeration type), namely the original key (N) and the key group, where the key group contains at least two keys (e.g., key A, key B). The combination of the key master index and the key sub-index can be used as a unique primary key to identify a key record, and can be denoted as: (key master index, key sub-index).

[0112] Master Key Tag: Used to indicate the key activation status, that is, to indicate the currently activated master key of the original key N in the key group; for example, for key sub-index (N: A, B), if the master key tag value is A, it indicates that the original key N currently has key A as the master key (equivalent to the original key N currently having key A as the instance), and the corresponding key B as the sub-key. If the master key tag value is B, it indicates that the original key N currently has key B as the master key (equivalent to the original key N currently having key B as the instance), and the corresponding key A as the sub-key.

[0113] Key value: A symmetric key has only one key value; an asymmetric key includes two key value fields: a public key value and a private key value, with only the public key value being publicly disclosed.

[0114] Cryptographic algorithms: Symmetric keys can be selected from cryptographic algorithms such as DES, SM4, and AES; asymmetric keys can be selected from traditional cryptographic algorithms such as RSA, ECC, and SM2, as well as quantum-resistant cryptographic algorithms such as Kyber, Dilithium, and Falcon.

[0115] Key strength: For a given cryptographic algorithm, this indicates the key bit length. For example, AES can be configured with 128 bits, 256 bits, etc.

[0116] In the key storage structure of this application embodiment, for the original key, its key attributes such as key value, cryptographic algorithm, and key strength should be consistent with the key indicated by the master key tag (same master index). The key attributes such as key value, cryptographic algorithm, and key strength of different keys in the key group (such as key A and key B) can be different.

[0117] In an exemplary embodiment of this application, the key storage structure can be as shown in Table 1 below. In Table 1, N is the original key, and A and B are the key groups corresponding to the original key.

[0118] Table 1

[0119]

[0120] In another exemplary embodiment of this application, as shown in Table 2 below, the key sub-index can be further expanded. For example, keyindex-X can be expanded into sub-index C, and keyindex-Y can be expanded into sub-indexes C and D. Since the number of sub-indexes is limited and the key attributes are explicit, the key update and switching is simpler and easier to maintain than the version number management method.

[0121] Table 2

[0122]

[0123] In other embodiments of this application, the key storage structure can also be split into two tables: a key table and a key instance table. The key table stores only the key activation status (i.e., master key tag) of the original key N and has two fields: key master index and master key tag. The key instance table stores key information and has key master index, key sub-index, and key attributes.

[0124] In some embodiments of this application, since the key master index can uniquely identify a business application in the context of key usage, when a key update for a business application is required, a key update request carrying the key master index can be sent to the cryptographic service platform. The key update request is triggered by an event (e.g., user-initiated operation, data security-related event triggering) or a timer.

[0125] A full-scale cryptographic computation cluster refers to all cryptographic computation clusters within a cryptographic service platform. Figure 6 In the embodiment shown, the cryptographic service platform may include cryptographic operation cluster 1 and cryptographic operation cluster 2, which together constitute the full cryptographic operation cluster.

[0126] In some embodiments of this application, since the key storage structure contains a mapping relationship between the key master index and the key sub-index, the corresponding key sub-index can be matched from the key storage structure based on the key master index in the key update request. For example, in Table 1, if the key master index carried in the key update request is keyindex-X, then the key sub-index (N: A, B) corresponding to keyindex-X can be matched from Table 1.

[0127] In some embodiments of this application, each cryptographic operation cluster of the cryptographic service platform maintains a local key storage structure. By querying the key storage structure of each cryptographic operation cluster using the key master index carried in the key update request, it can be determined whether the master key labels of the original keys corresponding to the key master index are consistent across all cryptographic operation clusters. If they are consistent, the corresponding key update is allowed; otherwise, the corresponding key update is not allowed. Since the update is of the subkey, even if there are transactions in transit during the update period, it will not affect the use of the corresponding master key for cryptographic operations by each cryptographic operation cluster; thus, the impact on the correctness and continuity of business transactions during the key update period can be avoided. If they are inconsistent, the key update for the corresponding business application is prohibited, thereby preventing the impact on the correctness and consistency of the business due to key confusion. Moreover, in actual implementation, key updates and switching can be completed with a one-click operation in the key management service, without the involvement of business applications. The switching process is transparent and imperceptible to business applications, thereby improving the smoothness and agility of key update switching.

[0128] For example, in Figure 6In the illustrated embodiment, if the key master index carried in the key update request is keyindex-X, and the master key label corresponding to keyindex-X in the key storage structure of cryptographic operation cluster 1 is A, and the master key label corresponding to keyindex-X in the key storage structure of cryptographic operation cluster 2 is A, then the corresponding key update is performed; otherwise, the corresponding key update is prohibited.

[0129] In some embodiments of this application, updating the key may include: updating the key value, changing the cryptographic algorithm, and / or changing the key strength; the specific choice can be made as needed.

[0130] refer to Figure 3 As shown, in other embodiments of this application, the key update method may include the following steps:

[0131] Step 301: Receive a key update request for the target business application represented by the key master index.

[0132] Step 302: Determine the key sub-index corresponding to the key master index in the full cryptographic operation cluster; the key sub-index includes the original key and its key group.

[0133] Step 303: Confirm whether the master key tags corresponding to the original keys in the full cryptographic operation cluster are consistent. The master key tag indicates the currently enabled master key for the original key in the key group; if the master key tags are consistent, proceed to step 304; otherwise, proceed to step 307.

[0134] Step 304: Update the subkey of the original key in the full cryptographic operation cluster. The subkey is the remaining key in the key group.

[0135] Step 305: Confirm whether the current subkey updates of the original key in the full cryptographic operation cluster are all complete. If all are complete, proceed to step 306; otherwise, proceed to the next round of judgment (i.e., continue to confirm whether the current subkey updates of the original key in the full cryptographic operation cluster are all complete).

[0136] Step 306: In the full cryptographic operation cluster, switch the master key tag corresponding to the original key to one of the updated subkeys, and synchronously update the key attributes corresponding to the original key to make them consistent with the key attributes of the switched master key.

[0137] In this embodiment of the application, during the master key label switching transition, it is permissible for the master key labels of different cryptographic services in different cryptographic clusters to be inconsistent.

[0138] In some embodiments of this application, after all the current subkeys corresponding to the original key in the full cryptographic operation cluster have been updated, a master-slave key switch can be performed. This facilitates subsequent key updates to the switched subkeys. For example, taking the key sub-indexes (N: A, B) in Table 1 above as an example, in the cryptographic storage structure of each cryptographic operation cluster, if the value of the master key identifier corresponding to the original key N is A (i.e., key A is the master key), after the subkey B corresponding to the original key N has been updated, the value of the master key identifier corresponding to the original key N can be switched to B. At this time, key B becomes the master key of the original key N, and the corresponding key A becomes the subkey of the original key N. By performing a master-slave key switch, it is convenient to subsequently update the subkey A.

[0139] The updating of the master key tag and key attributes is an atomic operation and cannot be split to avoid encryption / decryption failures and key corruption caused by key asynchrony. Therefore, when switching the master key tag corresponding to the original key to point to one of the updated subkeys, the key attributes corresponding to the original key need to be updated synchronously to make them consistent with the key attributes of the switched master key.

[0140] When switching the master key label, the second business application selects the key sub-index to use based on the master key label sent by the first business application, instead of using the master key label of the original key. At this time, it is allowed that the master key labels of the original keys of different cryptographic services in the cryptographic computing cluster are inconsistent, that is, the enabled key states are different. This ensures that the switching of the master key label has no impact on the transactions in transit of the business application and guarantees business continuity.

[0141] Step 307: Prohibit key updates for the target business application.

[0142] Based on the aforementioned key storage structure and key update method, this application provides an encrypted communication method that can be applied to the aforementioned cryptographic service platform. (Refer to...) Figure 4 As shown, in some embodiments of this application, the encrypted communication method may include the following steps:

[0143] Step 401: Receive a first cryptographic operation request initiated by a first service application; the first cryptographic operation request includes: first data, the key master index and key sub-index of the first service application, and the key sub-index includes the original key. The first data can be plaintext data to be used for the first cryptographic operation.

[0144] In some embodiments of this application, the first business application can be any business application in the business cluster that needs to perform the first cryptographic operation; wherein, the first cryptographic operation is an encryption operation or a signature operation, etc., which can be customized.

[0145] Step 402: Match the key record corresponding to the key master index and the original key from the key storage structure.

[0146] For example, taking Table 1 above as an example, if the key primary index is keyindex-X, the key records (keyindex-X, N) corresponding to keyindex-X and the original key N are shown in Table 3 below:

[0147] Table 3

[0148]

[0149] Step 403: Determine the first cryptographic operation parameters and the master key tag based on the key attributes in the key record.

[0150] In some embodiments of this application, the first cryptographic operation parameters include: the key value, key strength, and cryptographic algorithm of the original key. For example, taking Table 3 above as an example, the cryptographic algorithm SM2, the key strength of 512 bits, the SM2 private key, and the SM2 public key can be used as the first cryptographic operation parameters, and the master key tag B can also be obtained.

[0151] Step 404: Perform a first cryptographic operation on the first data according to the first cryptographic operation parameters to obtain the second data.

[0152] For example, if the first cryptographic operation is an encryption operation, the first data can be encrypted into ciphertext (which is the second data) according to the parameters of the first cryptographic operation. If the first cryptographic operation is a signature operation, the first data can be digitally signed according to the parameters of the first cryptographic operation to generate a signature value (which is the second data).

[0153] Step 405: Return the second data and the master key tag to the first business application.

[0154] For example, in Figure 6 In the illustrated embodiment, the cryptographic service platform can return encrypted data and master key tag B to business application X. Based on this, business application X can then provide downstream business applications (such as...) according to its business logic. Figure 6 Business applications Y and Z provide data ciphertext and master key tag B.

[0155] and Figure 4 Corresponding to the encrypted communication method shown, this application embodiment also provides another encrypted communication method, which can be applied to the aforementioned cryptographic service platform side. (Refer to...) Figure 5 As shown, in some embodiments of this application, the encrypted communication method may include the following steps:

[0156] Step 501: Receive a second cryptographic operation request initiated by the second business application; the second cryptographic operation request includes: second data, the master key tag associated with the second data, and the key master index of the second business application.

[0157] In some embodiments of this application, the second business application can be any business application in the business cluster that requires a second cryptographic operation; wherein, the second cryptographic operation can be the inverse operation of the first cryptographic operation. For example, if the first cryptographic operation is an encryption operation, then the second cryptographic operation is a decryption operation; if the first cryptographic operation is a signature operation, then the second cryptographic operation is a signature verification operation.

[0158] Step 502: Match the key record corresponding to the key master index and the master key tag from the key storage structure.

[0159] In the embodiments of this application, in order to achieve encrypted communication, both communicating parties can use the same key pair to perform cryptographic operations. For example, taking encrypted communication between business application X and business application Y as an example, keyindex-X and keyindex-Y point to the same logical key pair, but each business application has its own master key index to access this key pair. Therefore, the key attribute corresponding to the master key tag B in the key record (keyindex-Y, B) is consistent with the key attribute corresponding to the master key tag B in the key record (keyindex-X, N) or key record (keyindex-X, B).

[0160] Step 503: Determine the second cryptographic operation parameters based on the key attributes in the key record.

[0161] In embodiments of this application, the second cryptographic operation parameters may include the key value, key strength, and cryptographic algorithm of the master key tag.

[0162] Step 504: Perform a second cryptographic operation on the second data according to the second cryptographic operation parameters to obtain the first data.

[0163] For example, if the second cryptographic operation is a decryption operation, the first data can be decrypted into plaintext data (which is the first data) according to the parameters of the second cryptographic operation. If the second cryptographic operation is a signature verification operation, the second data can be signed and verified according to the parameters of the second cryptographic operation. That is, the receiver decrypts the signature using the sender's public key to obtain a hash value (which is the first data), and then verifies the sender's identity by comparing the hash value.

[0164] Step 505: Return the first data to the second business application.

[0165] Under the key storage structure and key update mechanism of this application embodiment, the encrypted communication (encryption / decryption, signature / verification) of this application embodiment no longer relies on a fixed key, but relies on the two communicating parties to dynamically select the key based on a unified status label (master key label), so that the communication has the flexibility or adaptability to adapt to changes in the background key (changes in the background key have no impact or perception on the encrypted communication in transit between the two parties).

[0166] Although the process described above includes multiple operations that occur in a specific order, it should be clearly understood that these processes may include more or fewer operations that can be executed sequentially or in parallel (e.g., using parallel processors or a multithreaded environment).

[0167] Corresponding to the key update method described above, this application also provides a key update device, which can be configured on the aforementioned cryptographic service platform, as shown in the reference. Figure 7 As shown, in some embodiments of this application, the key update device may include:

[0168] The first receiving module 71 is used to receive a key update request for a target business application represented by a key master index;

[0169] The first determining module 72 is used to determine the key sub-index corresponding to the key master index in the full cryptographic operation cluster; the key sub-index includes the original key and its key group.

[0170] The key update module 73 is used to confirm whether the master key label corresponding to the original key in the full cryptographic operation cluster is consistent; the master key label indicates the master key currently enabled by the original key in the key group; if the master key labels are consistent, the current sub-key of the original key in the full cryptographic operation cluster is updated, and the sub-key is the other key in the key group; if the master key labels are inconsistent, the key update for the target business application is prohibited.

[0171] Please continue to refer to this. Figure 7 As shown, in some embodiments of this application, the key update device may further include:

[0172] The master key switching module 74 is used to confirm whether the current subkey updates of the original key in the full cryptographic operation cluster have been completed; if they have been completed, in the full cryptographic operation cluster, the master key tag corresponding to the original key is switched to point to one of the updated subkeys, and the key attributes corresponding to the original key are updated synchronously to make them consistent with the key attributes of the switched master key.

[0173] With the above Figure 4Corresponding to the encrypted communication method shown, this application also provides an encrypted communication device, which can be configured on the aforementioned cryptographic service platform, see reference. Figure 8 As shown, in some embodiments of this application, the encrypted communication device may include:

[0174] The second receiving module 81 is used to receive a first cryptographic operation request initiated by the first business application; the first cryptographic operation request includes: first data, the key master index and key sub-index of the first business application, and the key sub-index includes the original key;

[0175] The first matching module 82 is used to match the key record corresponding to the key master index and the original key from the key storage structure;

[0176] The second determining module 83 is used to determine the first cryptographic operation parameters and the master key tag based on the key attributes in the key record;

[0177] The first execution module 84 is used to perform a first cryptographic operation on the first data according to the first cryptographic operation parameters to obtain the second data;

[0178] The first return module 85 is used to return the second data and the master key tag to the first business application.

[0179] With the above Figure 5 Corresponding to the encrypted communication method shown, this application embodiment also provides another encrypted communication device, which can be configured on the aforementioned cryptographic service platform, see reference. Figure 9 As shown, in some embodiments of this application, the encrypted communication device may include:

[0180] The third receiving module 91 is used to receive a second cryptographic operation request initiated by the second business application; the second cryptographic operation request includes: second data, a master key tag associated with the second data, and a key master index of the second business application;

[0181] The second matching module 92 is used to match the key record corresponding to the key master index and the master key label from the key storage structure;

[0182] The third determining module 93 is used to determine the second cryptographic operation parameters based on the key attributes in the key record;

[0183] The second execution module 94 is used to perform a second cryptographic operation on the second data according to the second cryptographic operation parameters to obtain the first data;

[0184] The second return module 95 is used to return the first data to the second business application.

[0185] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.

[0186] Embodiments of this application also provide a computer device. For example... Figure 10 As shown, in some embodiments of this application, the computer device 1002 may include one or more processors 1004, such as one or more central processing units (CPUs) or graphics processing units (GPUs), each of which may implement one or more hardware threads. The computer device 1002 may also include any memory 1006 for storing any kind of information such as code, settings, data, etc. In one specific embodiment, a computer program on the memory 1006 and executable on the processor 1004, when run by the processor 1004, can execute instructions for the key update method or encrypted communication method described in any of the above embodiments. Non-limitingly, for example, the memory 1006 may include any type of RAM, any type of ROM, flash memory, hard disk, optical disk, etc. More generally, any memory can use any technology to store information. Further, any memory can provide volatile or non-volatile retention of information. Further, any memory may represent a fixed or removable component of the computer device 1002. In one scenario, when processor 1004 executes associated instructions stored in any memory or combination of memories, computer device 1002 can perform any operation of the associated instructions. Computer device 1002 also includes one or more drive mechanisms 1008 for interacting with any memory, such as hard disk drive mechanisms, optical disk drive mechanisms, etc.

[0187] Computer device 1002 may also include an input / output interface 1010 (I / O) for receiving various inputs (via input device 1012) and providing various outputs (via output device 1014). A specific output mechanism may include a presentation device 1016 and an associated graphical user interface 1018 (GUI). In other embodiments, the input / output interface 1010 (I / O), input device 1012, and output device 1014 may be omitted, and the device may function solely as a computer device within a network. Computer device 1002 may also include one or more network interfaces 1020 for exchanging data with other devices via one or more communication links 1022. One or more communication buses 1024 couple the components described above together.

[0188] The communication link 1022 can be implemented in any way, such as via a local area network, a wide area network (e.g., the Internet), a point-to-point connection, or any combination thereof. The communication link 1022 may include any combination of hardwired links, wireless links, routers, gateway functions, name servers, etc., governed by any protocol or combination of protocols.

[0189] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), computer-readable storage media, and computer program products according to some embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processor to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processor, create a machine for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0190] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processor to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0191] These computer program instructions may also be loaded onto a computer or other programmable data processor, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0192] In a typical configuration, a computer device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0193] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0194] Computer-readable media, including both permanent and non-permanent, removable and non-removable media, can store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by computer equipment. As defined in this application, computer-readable media does not include transient media, such as modulated data signals and carrier waves.

[0195] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, embodiments of this application can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of this application can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0196] The embodiments of this application can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. The embodiments of this application can also be practiced in distributed computing environments where tasks are performed by remote processors connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0197] It should also be understood that, in the embodiments of this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.

[0198] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0199] In the description of this application, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the embodiments of this application. In this application, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in a suitable manner in any one or more embodiments or examples. Furthermore, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this application, as well as the features of different embodiments or examples.

[0200] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A key update method, characterized in that, include: Receive key update requests for target business applications represented by the key master index; Determine the key sub-index corresponding to the key master index in the full cryptographic operation cluster; The key sub-index includes the original key and its key group; Confirm whether the master key label corresponding to the original key in the full cryptographic operation cluster is consistent; the master key label indicates the master key currently enabled by the original key in the key group. If the master key tags are consistent, then the current subkey of the original key in the full cryptographic operation cluster is updated, and the subkey is the remaining key in the key group; If the master key labels are inconsistent, key updates for the target business application are prohibited.

2. The key update method as described in claim 1, characterized in that, After updating the subkey of the original key in the full cryptographic operation cluster, the process further includes: Confirm whether the current subkey updates for the original keys in the full cryptographic operation cluster have all been completed; If all operations are completed, in the full cryptographic operation cluster, the master key tag corresponding to the original key is switched to point to one of the updated subkeys, and the key attributes corresponding to the original key are updated synchronously to make them consistent with the key attributes of the switched master key.

3. The key update method as described in claim 2, characterized in that, Before receiving a key update request for the target business application represented by the key master index, the process also includes: Maintain a key storage structure containing key records; the key record includes: a key master index, a key sub-index, a master key label, and key attributes; the key master index corresponds to a unique business application; the key sub-index contains the original key and its key group; the master key label indicates the master key currently enabled by the original key in the key group.

4. The key update method as described in claim 1, characterized in that, The key update includes: updating the key value, changing the cryptographic algorithm, and / or changing the key strength.

5. The key update method as described in claim 1, characterized in that, The key update request is triggered based on an event or timer.

6. An encrypted communication method, characterized in that, include: Receive a first cryptographic operation request initiated by a first business application; the first cryptographic operation request includes: first data, the key master index and key sub-index of the first business application, and the key sub-index includes the original key; Match the key record corresponding to the key master index and the original key from the key storage structure; The first cryptographic operation parameters and the master key tag are determined based on the key attributes in the key record; The first cryptographic operation is performed on the first data according to the first cryptographic operation parameters to obtain the second data; The second data and the master key tag are returned to the first business application.

7. The encrypted communication method as described in claim 6, characterized in that, The first cryptographic operation parameters include: the key value, key strength, and cryptographic algorithm of the original key.

8. The encrypted communication method as described in claim 6, characterized in that, The first cryptographic operation is either an encryption operation or a signature operation.

9. An encrypted communication method, characterized in that, include: Receive a second cryptographic operation request initiated by a second business application; the second cryptographic operation request includes: second data, a master key tag associated with the second data, and a key master index of the second business application; Match the key record corresponding to the key master index and the master key label from the key storage structure; The second cryptographic operation parameters are determined based on the key attributes in the key record; Perform a second cryptographic operation on the second data according to the second cryptographic operation parameters to obtain the first data; Return the first data to the second business application.

10. The encrypted communication method as described in claim 9, characterized in that, The second cryptographic operation parameters include: the key value, key strength, and cryptographic algorithm of the master key tag.

11. The encrypted communication method as described in claim 9, characterized in that, The second cryptographic operation is either a decryption operation or a signature verification operation.

12. A key update device, characterized in that, include: The first receiving module is used to receive key update requests for the target business application represented by the key master index; The first determining module is used to determine the key sub-index corresponding to the key master index in the full cryptographic operation cluster; the key sub-index includes the original key and its key group. The key update module is used to confirm whether the master key label corresponding to the original key in the full cryptographic operation cluster is consistent; the master key label indicates the master key currently enabled by the original key in the key group. If the master key tags are consistent, then the current subkey of the original key in the full cryptographic operation cluster is updated, and the subkey is the remaining key in the key group; If the master key labels are inconsistent, key updates for the target business application are prohibited.

13. The key update device as described in claim 12, characterized in that, Also includes: The master key switching module is used to confirm whether the current subkey updates of the original key in the full cryptographic operation cluster have been completed. If all operations are completed, in the full cryptographic operation cluster, the master key tag corresponding to the original key is switched to point to one of the updated subkeys, and the key attributes corresponding to the original key are updated synchronously to make them consistent with the key attributes of the switched master key.

14. An encrypted communication device, characterized in that, include: The second receiving module is used to receive a first cryptographic operation request initiated by the first business application; the first cryptographic operation request includes: first data, the key master index and key sub-index of the first business application, and the key sub-index includes the original key; The first matching module is used to match the key record corresponding to the key master index and the original key from the key storage structure; The second determining module is used to determine the first cryptographic operation parameters and the master key tag based on the key attributes in the key record; The first execution module is configured to perform a first cryptographic operation on the first data according to the first cryptographic operation parameters to obtain the second data; The first return module is used to return the second data and the master key tag to the first business application.

15. An encrypted communication device, characterized in that, include: The third receiving module is used to receive the second cryptographic operation request initiated by the second business application; The second cryptographic operation request includes: second data, the master key tag associated with the second data, and the key master index of the second business application; The second matching module is used to match the key record corresponding to the key master index and the master key label from the key storage structure; The third determining module is used to determine the second cryptographic operation parameters based on the key attributes in the key record; The second execution module is used to perform a second cryptographic operation on the second data according to the second cryptographic operation parameters to obtain the first data; The second return module is used to return the first data to the second business application.

16. A computer device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, When the computer program is run by the processor, it executes the instructions of the method according to any one of claims 1-11.

17. A computer storage medium having a computer program stored thereon, characterized in that, When the computer program is run by the processor of the computer device, it executes the instructions of the method according to any one of claims 1-11.

18. A computer program product, characterized in that, The computer program product includes a computer program that, when run by the processor of a computer device, executes instructions according to any one of claims 1-11.