Secret key charging method and system of virtual cryptographic equipment
By using a collaborative approach involving client terminals, servers, quantum distribution devices, and cloud hosts, session keys and filling key ciphertexts are generated and encrypted. This solves the problems of plaintext key exposure and untrusted host risk in virtual cryptographic devices, thereby improving key security and reliability and adapting to the agility requirements of cloud computing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-13
- Publication Date
- 2026-04-10
AI Technical Summary
Existing technologies pose risks of information leakage and untrusted host environments when injecting high-security keys into virtual cryptographic devices, as the plaintext of the keys is exposed in the shared resource environment. Furthermore, traditional physical cryptographic devices have limitations in cloud computing and agile operation and maintenance.
The method employs a collaborative approach involving client terminals, servers, quantum distribution devices, and cloud hosts. Encrypted session keys and filling key ciphertexts are generated through quantum key distribution and written to the filling medium in a secure storage area. The cloud host only processes the encrypted ciphertext data, and the target cloud virtual cryptographic device uses the encrypted private key to decrypt it to obtain the filling key plaintext, ensuring the confidentiality and security of the keys.
It enhances the confidentiality and security of key injection, prevents erroneous injection, and improves the security and reliability of plaintext keys in untrusted host environments, adapting to the agility requirements of modern cryptographic systems.
Smart Images

Figure CN121841635A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of key injection, in particular to a key injection method and system of a virtual cryptographic device. BACKGROUND
[0002] With the rapid development of quantum computing technology, its potential computing power poses a serious challenge to the classical encryption system that relies on computational complexity. Quantum algorithms such as Shor's algorithm can efficiently solve large integer factorization, discrete logarithm and other difficult problems in polynomial time, which makes the widely used RSA encryption algorithm (Rivest-Shamir-Adleman, abbreviated as RSA), elliptic curve cryptography (Elliptic Curve Cryptography, abbreviated as ECC), SM2 elliptic curve public key cryptography (SM2 Cryptographic Algorithm, abbreviated as SM2) and other asymmetric cryptography algorithms no longer secure under quantum attacks.
[0003] In related technologies, to cope with this threat, the industry often uses quantum key distribution (Quantum Key Distribution, abbreviated as QKD) technology based on the principles of quantum mechanics to resist quantum computing attacks. However, when resisting quantum computing attacks based on related technologies, the QKD technology has the problems of limited transmission distance and high deployment cost. In order to balance the cost and security issues, QKD technology is usually used in high-security links of the core backbone network, while in the subnetwork, keys are imported through offline injection to ensure the security of transmission. However, traditional physical cryptographic devices have certain limitations in cloud computing, agile operation and maintenance, etc., and are difficult to meet the needs of modern cryptographic systems, while virtual cryptographic devices, as a software image, can complete deployment, startup, cloning and elastic scaling services in a few seconds, perfectly adapting to the agility requirements and on-demand allocation requirements of modern cryptographic systems in cloud computing.
[0004] However, in the process of injecting high-security keys (such as QKD keys) into virtual cryptographic devices in existing technologies, there are the following defects: the first defect is the risk of transmission of the injection medium, which may cause the key plaintext to be exposed in the shared resource environment during the process of importing the injection medium into the virtual machine, resulting in information leakage; the second defect is the risk of untrusted host environment, which may be subject to malicious program monitoring or theft when the offline injection medium is read on the host. SUMMARY
[0005] The purpose of the present application is to provide a key injection method and system of a virtual cryptographic device, which can improve the confidentiality and security of the injected key, prevent the injected key from being injected incorrectly, and improve the security and reliability of the key plaintext in an untrusted host environment.
[0006] Embodiments of the present application are implemented as follows: In a first aspect, the present application provides a virtual cryptographic device key loading method, which is applied to a virtual cryptographic device key loading system, the virtual cryptographic device key loading system comprising a client terminal, a server, a quantum distribution device and a cloud host, the server and the quantum distribution device being located at a server and being in communication connection, and the cloud host being deployed with at least one cloud virtual cryptographic device; the method comprising: After a loading medium is inserted into the client terminal, the client terminal sends an encryption public key of a target cloud virtual cryptographic device and a length of a loading key to the server, the target cloud virtual cryptographic device being any cloud virtual cryptographic device deployed in the cloud host, and the encryption public key comprising a post-quantum encryption public key and an asymmetric encryption public key; The server initiates a quantum key request to the quantum distribution device based on the encryption public key and the length of the loading key, the quantum distribution device generates a quantum key of a specified length according to the quantum key request, and sends the quantum key to the server; The server generates session key ciphertext and loading key ciphertext based on the quantum key and the encryption public key, and feeds back the session key ciphertext and the loading key ciphertext to the client terminal; The client terminal verifies the loading medium, and writes the session key ciphertext, the loading key ciphertext and the encryption public key of the target cloud virtual cryptographic device into a secure storage area of the loading medium after verification.
[0007] As a possible implementation manner, the above-mentioned virtual cryptographic device key loading method further comprises: After a loading medium is inserted into the cloud host, the cloud host acquires identity information and an encryption public key of a target cloud virtual cryptographic device, verifies the loading medium and the encryption public key, and acquires session key ciphertext and loading key ciphertext from the loading medium after verification, the encryption public key comprising a post-quantum encryption public key and an asymmetric encryption public key; The cloud host copies the session key ciphertext and the loading key ciphertext to the target cloud virtual cryptographic device, and sends a loading request to the target cloud virtual cryptographic device after copying is completed; The target cloud virtual cryptographic device loads the session key ciphertext and the loading key ciphertext according to the loading request, and decrypts the session key ciphertext and the loading key ciphertext using an encryption private key of the target cloud virtual cryptographic device to obtain loading key plaintext.
[0008] As a possible implementation manner, the above-mentioned virtual cryptographic device key loading method further comprises: The target cloud virtual cryptographic device generates an encryption key pair corresponding to the target cloud virtual cryptographic device based on a built-in encryption algorithm, the encryption key pair comprising an encryption public key and an encryption private key; The target cloud virtual password device sends an encryption public key in an encryption key pair to the cloud host; The cloud host broadcasts the encryption public key of the target cloud virtual password device.
[0009] As a possible implementation manner, the server generates the session key ciphertext and the refueling key ciphertext based on the quantum key and the encryption public key, including: The server generates a first session key and a second session key based on the received quantum key; The server encrypts the first session key based on the post-quantum encryption public key to obtain the first session key ciphertext; The server encrypts the second session key based on the asymmetric encryption public key to obtain the second session key ciphertext; The server performs exclusive OR processing on the first session key and the second session key, and encrypts the quantum key based on the exclusive OR processing result to obtain the refueling key ciphertext.
[0010] As a possible implementation manner, the client terminal writes the session key ciphertext, the refueling key ciphertext and the encryption public key of the target cloud virtual password device into the secure storage area of the refueling medium, including: The client terminal splices the post-quantum encryption public key and the asymmetric encryption public key of the target cloud virtual password device to obtain a spliced encryption public key, and calculates a public key fingerprint corresponding to the spliced encryption public key; The client terminal writes the first session key ciphertext, the second session key ciphertext, the refueling key ciphertext and the public key fingerprint into the secure storage area of the refueling medium through the secure channel.
[0011] As a possible implementation manner, the cloud host obtains the identity information and the encryption public key of the target cloud virtual password device, verifies the refueling medium and the encryption public key, and after verification, obtains the session key ciphertext and the refueling key ciphertext from the refueling medium, including: The cloud host sends a refueling request to the target cloud virtual password device, and the target cloud virtual password device responds to the refueling request and sends a virtual machine identifier, a post-quantum encryption public key and an asymmetric encryption public key to the cloud host; The cloud host verifies the refueling medium and performs fingerprint verification on the received post-quantum encryption public key and asymmetric encryption public key; If the verification is passed, the cloud host reads the first session key ciphertext, the second session key ciphertext and the refueling key ciphertext from the secure storage area of the refueling medium.
[0012] As a possible implementation manner, the cloud host performs fingerprint verification on the received post-quantum encryption public key and asymmetric encryption public key, including: The cloud host machine splices the received post-quantum encryption public key and the asymmetric encryption public key to obtain a spliced encryption public key, and calculates a verification fingerprint of the spliced encryption public key; The cloud host machine compares the verification fingerprint with a public key fingerprint stored in the secure storage area of the refilling medium.
[0013] As a possible implementation manner, the encryption private key includes a post-quantum encryption private key and an asymmetric encryption private key; the target cloud virtual password device decrypts the session key ciphertext and the refilling key ciphertext using the encryption private key of the target cloud virtual password device to obtain the refilling key plaintext, including: The target cloud virtual password device decrypts the first session key ciphertext using the post-quantum encryption private key to obtain the first session key; The target cloud virtual password device decrypts the second session key ciphertext using the asymmetric encryption private key to obtain the second session key; The target cloud virtual password device performs exclusive OR processing on the first session key and the second session key, and decrypts the refilling key ciphertext based on the exclusive OR processing result to obtain the refilling key plaintext.
[0014] As a possible implementation manner, the key refilling method of the virtual password device further includes: The target cloud virtual password device encrypts the refilling key plaintext using the master key, and stores the encrypted refilling key plaintext to the secure storage area of the target cloud virtual password device.
[0015] In a second aspect, a key refilling system of a virtual password device is provided, and the key refilling system of the virtual password device includes a client terminal, a server, a quantum distribution device, and a cloud host machine, the server and the quantum distribution device are located at a server side and are in communication connection, and at least one cloud virtual password device is deployed in the cloud host machine; The key refilling system of the virtual password device is configured to perform the steps of the key refilling method of the virtual password device in the first aspect.
[0016] In a third aspect, an electronic device is provided, and the electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the computer program is executed by the processor, the key refilling method of the virtual password device in the first aspect is implemented.
[0017] In a fourth aspect, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program, and when the computer program is executed by a processor, the key refilling method of the virtual password device in the first aspect is implemented.
[0018] The beneficial effects of the embodiments of the present application include: The key charging method of the virtual password device provided in the embodiments of the present application includes the following steps: inserting a charging medium into a client terminal; after the charging medium is inserted, the client terminal encapsulates the encryption public key disclosed by a target cloud virtual password device input or selected by a user and the length of the charging key generated by the user as specified into a charging request and sends the charging request to a server; the server analyzes the received charging request to obtain the encryption public key of the target cloud virtual password device input or selected by the user and the length of the charging key generated by the user as specified, initiates a quantum key request to a quantum distribution device according to the encryption public key of the target cloud virtual password device and the length of the charging key generated by the user as specified, the quantum distribution device generates a quantum key with the specified length in response to the quantum key request and sends the quantum key to the server, the server generates session key ciphertext and charging key ciphertext based on the quantum key and the encryption public key of the target cloud virtual password device, and feeds back the session key ciphertext and the charging key ciphertext to the client terminal, and the client terminal verifies the charging medium based on the charging medium password input by the user, and writes the session key ciphertext, the charging key ciphertext and the public key fingerprint corresponding to the encryption public key of the target cloud virtual password device into the secure storage area of the charging key after the verification is passed. The quantum key is first encrypted by two independent session keys, and the encrypted session keys are further encrypted by a post-quantum encryption public key and an asymmetric encryption public key, which greatly improves the confidentiality and security of the charging key. In addition, the public key fingerprint corresponding to the encryption public key of the target cloud virtual password device is written into the charging medium, which can ensure that the encrypted charging key can only be decrypted and used by the specified and legal target cloud virtual password device, effectively preventing the charging key from being charged incorrectly. Further, in the entire charging process, the plaintext of the charging key can only appear in the secure storage area of the target cloud virtual password device, and exists in the cloud host in the form of encrypted ciphertext. In this way, the confidentiality and security of the charging key can be improved, the charging key can be prevented from being charged incorrectly, and the security and reliability of the key plaintext in the untrusted host environment can be improved. BRIEF DESCRIPTION OF DRAWINGS
[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can also be obtained without creative labor.
[0020] Figure 1 The structure diagram of the key charging system of the virtual password device provided in the embodiments of the present application; Figure 2 The flowchart of the first key charging method of the virtual password device provided in the embodiments of the present application; Figure 3 A flow chart of a third key loading method of a virtual cryptographic device according to an embodiment of the present application is provided in the following; Figure 4 A flow chart of a third key loading method of a virtual cryptographic device according to an embodiment of the present application is provided in the following; Figure 5 A flow chart of a fourth key loading method of a virtual cryptographic device according to an embodiment of the present application is provided in the following; Figure 6 A flow chart of a fifth key loading method of a virtual cryptographic device according to an embodiment of the present application is provided in the following; Figure 7 A flow chart of a sixth key loading method of a virtual cryptographic device according to an embodiment of the present application is provided in the following; Figure 8 A flow chart of a seventh key loading method of a virtual cryptographic device according to an embodiment of the present application is provided in the following; Figure 9 A flow chart of an eighth key loading method of a virtual cryptographic device according to an embodiment of the present application is provided in the following; Figure 10 A flow chart of a ninth key loading method of a virtual cryptographic device according to an embodiment of the present application is provided in the following; Figure 11 A structure schematic diagram of an electronic device according to an embodiment of the present application is provided in the following. DETAILED DESCRIPTION
[0021] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the following will be combined with the accompanying drawings for the embodiments of the present application to make a clear and complete description of the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the accompanying drawings can be arranged and designed in various different configurations.
[0022] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative labor are within the scope of protection of the present application.
[0023] It should be noted that: similar reference numerals and letters represent similar items in the following drawings, thus, once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.
[0024] In the description of the present application, it should be noted that the terms “first”, “second”, etc. are only used for differentiation in description, and cannot be understood as indicating or implying relative importance.
[0025] At present, the industry often resists quantum computing attacks through quantum key distribution technology based on the principles of quantum mechanics, but the quantum key distribution technology has the problems of limited transmission distance and high deployment cost. In order to consider the cost and security problems, the quantum key distribution technology is usually used in the high security link of the core backbone network, and the key is introduced through offline charging in the subnetwork, so as to ensure the security of transmission.
[0026] Physical cryptographic devices are special cryptographic hardware, and deployment requires procurement, shelving, wiring, configuration and other procedures, which will result in a device deployment period of several weeks or even months. In a cloud environment, business virtual machines can be created in minutes, but it is not possible to quickly match a physical cryptographic device for each new instance. For this reason, virtual cryptographic devices, as a kind of software image, can be deployed, started, cloned and scaled out in seconds like ordinary applications, perfectly matching the agile and on-demand allocation characteristics of cloud computing, and are widely used in modern cryptographic systems.
[0027] However, in the process of charging high-security keys into virtual cryptographic devices based on the prior art, there are the following defects: the first defect is the charging medium transmission risk, which may cause the key plaintext to be exposed in the shared resource environment during the process of charging the medium into the virtual machine, resulting in information leakage; the second defect is the risk of untrusted host environment, which may be subject to host malicious program monitoring or theft when the offline charging medium is read on the host.
[0028] To this end, the embodiment of the present application provides a key loading method of a virtual password device, a client terminal inserts a loading medium, the client terminal sends an encryption public key of a target cloud virtual password device and a length of a loading key to a server; the server initiates a quantum key request to a quantum distribution device based on the encryption public key and the length of the loading key vector, to obtain a quantum key of a specified length, and sends the quantum key to the server; the server generates session key ciphertext and loading key ciphertext based on the quantum key and the encryption public key, and feeds back to the client terminal; the client terminal verifies the loading medium, and writes the session key ciphertext and the loading key ciphertext to a secure storage area of the loading medium after verification; the loading medium with completed key loading is inserted into a cloud host, the cloud host obtains identity information and an encryption public key of the target cloud virtual password device, verifies the inserted loading medium, and reads the session key ciphertext and the loading key ciphertext from the secure storage area of the loading medium after verification, and copies to the target cloud virtual password device; after copying is completed, a loading request is sent to the target cloud virtual password device, the target cloud virtual password device loads the session key ciphertext and the loading key ciphertext based on the loading request, and decrypts the session key ciphertext and the loading key ciphertext using an encryption private key of the target cloud virtual password device, to obtain loading key plaintext. In this way, the confidentiality and security of the loading key can be improved, the error loading of the loading key can be prevented, and the security and reliability of the key plaintext in an untrusted host environment can be improved.
[0029] The key loading method and system of the virtual password device provided by the embodiment of the present application are explained and described in detail below in combination with the drawings.
[0030] Figure 1 A structural schematic diagram of a key loading system of a virtual password device provided by the present application is shown in FIG. 1. Figure 1 The key loading system 10 of the virtual password device provided by the embodiment of the present application includes a client terminal 102, a server 1031, a quantum distribution device 1032, and a cloud host 101, the server 1031 and the quantum distribution device 1032 are located in a server 103 and are in communication connection, and the cloud host 101 is deployed with at least one cloud virtual password device 1011.
[0031] The cloud host 101 is in communication connection with the client terminal 102, the client terminal 102 is in communication connection with the server 1031 in the server 103, and the server 1031 in the server 103 is in communication connection with the quantum distribution device 1032.
[0032] It should be noted that the cloud host 101 is a real physical cryptographic device deployed in a cloud environment, and the cloud virtual cryptographic device 1011 is a virtualized cryptographic device created by the cloud host 101 in the cloud environment; the client terminal 102 can be implemented by a terminal device on the client side, such as a personal computer device, and the present application does not make specific limitations thereto.
[0033] Specifically, the client terminal 102 as the initiator of the key recharge operation and the control terminal can provide operation interaction, request initiation, and recharge medium management functions. Among them, the client terminal 102 provides an operation interface for the user, so that the user can input or select the cloud virtual cryptographic device 1011 and specify the recharge key length; the client terminal 102 can encapsulate the encryption public key of the cloud virtual cryptographic device 1011 input or selected by the user and the specified recharge key length into a recharge request and send it to the server 1031 in the server 103; the client terminal 102 can also interact with the recharge medium after receiving the encrypted data returned by the server 103, verify the recharge medium based on the recharge medium password input by the user, and write the encrypted data and the public key fingerprint into the recharge medium securely after verification.
[0034] In addition, the server 1031 as the key processing and encryption engine can provide request processing, key acquisition, cryptographic operation, and data encapsulation functions. Among them, the server 1031 receives and analyzes the recharge request of the client terminal 102, initiates a quantum key request to the quantum distribution device 1032 connected thereto, to obtain a quantum key of a specified length with quantum security from the quantum distribution device 1032 as a quantum key; the server 1031 can also dynamically generate a session key according to the obtained quantum key, and encrypt the session key using the encryption public key provided by the user-selected cloud virtual cryptographic device to obtain the session key ciphertext, and at the same time, XOR process the generated session key, generate the recharge key ciphertext based on the XOR processed session key and the quantum key; the server 1031 encapsulates the session key ciphertext and the recharge key ciphertext and returns them to the client terminal 102.
[0035] Further, the quantum distribution device 1032 as a quantum secure random entropy source is used to provide quantum key generation, key provision, and other functions. Among them, the quantum distribution device 1032 generates an information theory safe random key sequence based on quantum key distribution technology; the quantum distribution device 1032 provides a quantum key of a specified length for the server 1031 as an unconditional secure quantum key, as the recharge key source of the entire system. It should be noted that the security of the key provided by the quantum distribution device 1032 is based on physical laws, which can fundamentally ensure the long-term security and quantum attack resistance of the recharge key.
[0036] Further, the cloud host 101 acts as a virtualization platform and a data transmission pipeline, and is used to provide functions such as environment hosting, operation execution, and communication mediation. The cloud host 101 acts as a real physical cryptographic device, and provides computing, storage, and network resources, and is used to create and run one or more virtual cryptographic devices 1011. The cloud host 101 can perform an operation of copying encrypted data in the charging medium to a secure storage space of a cloud virtual cryptographic device specified by a user in a key import stage. The cloud host 101 can also interact with a hypervisor of the cloud virtual cryptographic device 1011, and send a notification of loading key ciphertext to the cloud virtual cryptographic device 1011, to inform the cloud virtual cryptographic device 1011 to start loading encrypted data. As can be seen, the cloud host 101 provided in the present application only processes encrypted ciphertext data, and cannot decrypt the encrypted ciphertext data. Even if an internal environment of the cloud host 101 is untrusted, the cloud host 101 cannot steal key plaintext.
[0037] Further, the cloud virtual cryptographic device 1011 acts as a final user and a service provider of the key, and is used to provide functions such as identity information, key reception and decryption, secure storage, and cryptographic services. In an initialization stage, the cloud virtual cryptographic device 1011 generates a post-quantum encryption key pair based on a built-in post-quantum cryptographic algorithm, and generates an asymmetric encryption key pair based on a built-in asymmetric cryptographic algorithm, and broadcasts an encryption public key in the encryption key pair, to provide a key basis for encryption operations of other external devices. The cloud virtual cryptographic device 1011 receives the encrypted data packet copied from the cloud host 101, and uses a post-quantum encryption private key and an asymmetric encryption private key of the cloud virtual cryptographic device 1011 to decrypt the encrypted data packet, to obtain charging key plaintext. The cloud virtual cryptographic device 1011 stores the charging key plaintext in a secure storage area of the cloud virtual cryptographic device 1011 after locally re-encrypting the charging key plaintext using a master password of the cloud virtual cryptographic device 1011. The cloud virtual cryptographic device 1011 subsequently uses the charging key plaintext to provide cryptographic operation services such as encryption, decryption, and signature for upper-layer applications.
[0038] In summary, the key charging system 10 of the virtual cryptographic device provided in the embodiments of the present application realizes a complete closed loop of “quantum secure key source—anti-quantum encryption protection—secure transmission in untrusted environment—safe use of cloud virtual cryptographic device”, thereby solving the defects of the prior art.
[0039] Figure 2 A flowchart of a key charging method of a virtual cryptographic device provided in the present application is shown in FIG. 6. The method is applied in the key charging system of the virtual cryptographic device shown in FIG. 1, and includes the following steps. Figure 1 As shown in FIG. 6, the key charging method of the virtual cryptographic device provided in the present application includes the following steps. Figure 2 The key charging method of the virtual cryptographic device provided in the present application includes the following steps. S201: After the client terminal inserts the charging medium, the client terminal sends the encrypted public key of the target cloud virtual password device and the length of the generated charging key to the server, the target cloud virtual password device being any cloud virtual password device deployed in the cloud host, and the encrypted public key including a post-quantum encryption public key and an asymmetric encryption public key.
[0040] The charging medium is a physical device for securely transmitting and storing key data, and can be implemented by a smart password key of a universal serial bus (USB) or a portable password device of a hardware security module, which is not limited in the present application.
[0041] Specifically, the charging medium is an intermediate secure carrier for offline transmission of keys from the backbone network to the subnet virtual password device, and is usually a universal serial bus device with a secure chip to achieve secure storage of key data, encryption and decryption operations, and access control.
[0042] It is worth noting that the charging medium needs to input a specific medium password for identity verification before use to prevent unauthorized access.
[0043] Optionally, the target cloud virtual password device is a virtual password device input or selected by the user on the client terminal, and the target cloud virtual password device can be any one of a plurality of cloud virtual password device instances created by the cloud host, which is not limited in the present application.
[0044] Optionally, when the cloud host creates a plurality of virtual password devices, each virtual password device generates a post-quantum encryption key pair based on a built-in post-quantum password algorithm, the post-quantum encryption key pair including a post-quantum encryption public key and a post-quantum encryption private key; each virtual password device also generates an asymmetric encryption key pair based on a built-in asymmetric password algorithm, the asymmetric encryption key pair including an asymmetric encryption public key and an asymmetric encryption private key. Wherein each virtual password device broadcasts its own post-quantum encryption public key and asymmetric encryption public key through broadcasting, and each virtual password device secretly saves its own post-quantum encryption private key and asymmetric encryption private key.
[0045] Optionally, when the user needs to perform a key charging operation, the operator inserts a dedicated charging medium into the client terminal as an operation terminal, and after the key charging software of the client terminal runs, the user inputs or selects the post-quantum encryption public key and the asymmetric encryption public key provided by the target cloud virtual password device through the operation and interaction interface provided by the key charging software deployed on the client terminal, and specifies the length of the charging key required for this key charging operation, and the client terminal encapsulates the post-quantum encryption public key, the asymmetric encryption public key of the target cloud virtual password device, and the length of the generated charging key as a charging request, and remotely sends it to the server.
[0046] S202: The server generates a quantum key request based on the encryption public key and the length of the generated refill key.
[0047] S203: The server initiates a quantum key request to the quantum distribution device.
[0048] Optionally, after the server receives the refill request sent by the client terminal, the post-quantum encryption public key, the asymmetric encryption public key of the target cloud virtual password device, and the user-specified refill key length are parsed from the refill request. The server initiates a quantum key request to the quantum distribution device based on the parsed refill key length, the post-quantum encryption public key, and the asymmetric encryption public key of the target cloud virtual password device. The quantum key request is a request information for requesting the quantum distribution device to generate a quantum key of a specified length.
[0049] S204: The quantum distribution device generates a quantum key of a specified length according to the quantum key request.
[0050] S205: The quantum key is sent to the server.
[0051] Optionally, the quantum distribution device generates a sequence of true random numbers with a specified length and information theory security through the quantum key distribution technology built-in the quantum distribution device in response to the quantum key request, and sends the sequence of true random numbers as the quantum key to the server.
[0052] S206: The server generates session key ciphertext and refill key ciphertext based on the quantum key and the encryption public key.
[0053] S207: The server feeds back the session key ciphertext and the refill key ciphertext to the client terminal.
[0054] Optionally, after obtaining the quantum key of a specified length, the server performs an encryption encapsulation operation based on the post-quantum encryption public key and the asymmetric encryption public key of the target cloud virtual password device to obtain the session key ciphertext and the refill key ciphertext. The session key ciphertext refers to a temporary symmetric key used to decrypt the final refill key, and two kinds of session ciphertext data generated by encryption with the post-quantum encryption public key and the asymmetric encryption public key, respectively. The refill key ciphertext is the refill key to be injected into the target cloud virtual password device, and the ciphertext data generated by common encryption with the post-quantum encryption public key and the asymmetric encryption public key.
[0055] S208: The client terminal verifies the refill medium.
[0056] S209: The client terminal writes the session key ciphertext, the refill key ciphertext, and the encryption public key of the target cloud virtual password device into the secure storage area of the refill medium after verification.
[0057] Optionally, after the client terminal receives the session key ciphertext and the recharge key ciphertext fed back by the server, the user is prompted to input a recharge medium password, the client terminal verifies the recharge medium based on the recharge medium password input by the user, and only after the verification is passed, the client terminal is authorized to perform the write operation.
[0058] Further, the client terminal splices the received post-quantum encryption public key and the asymmetric encryption public key of the target virtual device to obtain a public key fingerprint corresponding to the encryption public key of the target virtual device, and transmits the received session key ciphertext, the recharge key ciphertext and the public key fingerprint corresponding to the encryption public key of the target cloud virtual password device to the recharge medium through a secure communication channel, and the session key ciphertext, the recharge key ciphertext and the public key fingerprint corresponding to the encryption public key of the target cloud virtual password device are written into the secure storage area inside the recharge medium by the secure chip of the recharge medium for persistent storage.
[0059] In the embodiment of the present application, after the client terminal inserts the charging medium, and after the charging medium is inserted, the client terminal encapsulates the encryption public key disclosed by the target cloud virtual password device input or selected by the user and the length of the charging key specified by the user into a charging request and sends it to the server; the server parses the received charging request to obtain the encryption public key of the target cloud virtual password device input or selected by the user and the length of the charging key specified by the user, and initiates a quantum key request to the quantum distribution device according to the encryption public key of the target cloud virtual password device and the length of the charging key specified by the user; the quantum distribution device generates a quantum key of a specified length in response to the quantum key request and sends the quantum key to the server; the server generates session key ciphertext and charging key ciphertext based on the quantum key and the encryption public key of the target cloud virtual password device, and feeds back the session key ciphertext and the charging key ciphertext to the client terminal; the client terminal verifies the charging medium based on the charging medium password input by the user, and after verification, writes the session key ciphertext, the charging key ciphertext, and the public key fingerprint corresponding to the encryption public key of the target cloud virtual password device into the secure storage area of the charging key. Wherein, the quantum key is first encrypted by two independent session keys, and the encrypted session keys are respectively encrypted by the post-quantum encryption public key and the asymmetric encryption public key, which greatly improves the confidentiality and security of the charging key. In addition, the public key fingerprint corresponding to the encryption public key of the target cloud virtual password device is written into the charging medium, which can ensure that the encrypted charging key can only be decrypted and used by the specified and legal target cloud virtual password device, effectively preventing the charging key from being charged incorrectly. Further, in the entire charging process, the plaintext of the charging key can only appear in the secure storage area of the target cloud virtual password device, and exists in the cloud host in the form of encrypted ciphertext. In this way, the confidentiality and security of the charging key can be improved, the charging key can be prevented from being charged incorrectly, and the security and reliability of the key plaintext in the untrusted host environment can be improved.
[0060] In an optional implementation, referring to Figure 3 The key charging method of the virtual password device further includes: S301: After the charging medium is inserted in the cloud host, the cloud host obtains the identity information and the encryption public key of the target cloud virtual password device, and the encryption public key includes the post-quantum encryption public key and the asymmetric encryption public key.
[0061] Optionally, when it is necessary to import the charging key stored in the charging medium into the cloud environment, the user inserts the charging medium that has completed the key charging into the corresponding interface of the cloud host.
[0062] Further, the user selects the target cloud virtual password device for this time key refilling through the interaction interface provided by the refilling management system deployed in the cloud host, and the refilling management system immediately requests and obtains the identity information of the target cloud virtual password device and the post-quantum encryption public key and the asymmetric encryption public key of the target cloud virtual password device. The identity information can be the unique identifier of the target cloud virtual password device selected by the user for refilling, which is not limited in the present application.
[0063] S302: The cloud host verifies the refilling medium and the encryption public key.
[0064] S303: After verification, the cloud host obtains the session key ciphertext and the refilling key ciphertext from the refilling medium.
[0065] Optionally, the refilling management system of the cloud host prompts the user to input the refilling medium password, and verifies the refilling medium inserted into the cloud host based on the user input refilling medium password, and only after the verification is passed, the refilling medium allows subsequent read operation.
[0066] In addition, in order to ensure the correctness of the key refilling operation and prevent the key from being incorrectly imported into an illegal virtual password device, the refilling medium can further perform identity binding verification.
[0067] Specifically, the cloud host calculates the verification fingerprint corresponding to the encryption public key of the target cloud virtual password device based on the received post-quantum encryption public key and asymmetric encryption public key of the target cloud virtual password device, and compares the verification fingerprint with the public key fingerprint stored in the secure storage area of the refilling medium. After the fingerprint comparison is passed, the cloud host can read the session key ciphertext and the refilling key ciphertext from the secure storage area of the refilling medium and return them to the refilling management system of the cloud host.
[0068] S304: The cloud host copies the session key ciphertext and the refilling key ciphertext to the target cloud virtual password device.
[0069] Optionally, after obtaining the session key ciphertext and the refilling key ciphertext, the cloud host securely copies the session key ciphertext and the refilling key ciphertext as data files to the isolated storage space corresponding to the target cloud virtual password device instance through the data transmission mechanism provided by the virtualization platform.
[0070] S305: After copying is completed, the cloud host sends a loading request to the target cloud virtual password device.
[0071] Optionally, after the session key ciphertext and the top-up key ciphertext are completely copied to the target cloud virtual password device, the top-up management system in the cloud host sends a key loading request to the target cloud virtual password device to inform the target cloud virtual password device that there is a new top-up key ciphertext waiting for it to process.
[0072] S306: The target cloud virtual password device loads the session key ciphertext and the top-up key ciphertext according to the loading request, and decrypts the session key ciphertext and the top-up key ciphertext using the encryption private key of the target cloud virtual password device to obtain the top-up key plaintext.
[0073] Optionally, after receiving the loading request, the target cloud virtual password device loads the transmitted session key ciphertext and top-up key ciphertext, and decrypts the session key ciphertext and the top-up key ciphertext using the post-quantum encryption private key and the asymmetric encryption private key secretly saved by the target cloud virtual password device to obtain the top-up key plaintext.
[0074] In an optional embodiment, referring to Figure 4 The key top-up method of the virtual password device further includes: S401: The target cloud virtual password device generates an encryption key pair corresponding to the target cloud virtual password device based on an internal encryption algorithm, the encryption key pair including an encryption public key and an encryption private key.
[0075] Optionally, after the cloud host successfully creates and starts multiple cloud virtual password devices, a user inputs or selects a target cloud virtual password device through an operation interaction interface provided by top-up software deployed in a client terminal, and the target cloud virtual password device completes its own password identity initialization based on an internal password algorithm.
[0076] Specifically, the target cloud virtual password device generates a post-quantum encryption key pair based on an internal post-quantum password algorithm, which is used to resist future quantum computing attacks; and the target cloud virtual password device also generates an asymmetric encryption key pair based on an internal asymmetric password algorithm. The post-quantum encryption key pair includes a post-quantum encryption public key and a post-quantum encryption private key, and the asymmetric encryption key pair includes an asymmetric encryption public key and an asymmetric encryption private key. The post-quantum encryption private key and the asymmetric encryption private key are both secretly saved by the target cloud virtual password device.
[0077] S402: The target cloud virtual password device sends the encryption public key in the encryption key pair to the cloud host.
[0078] Optionally, the target cloud virtual password device actively sends the post-quantum encryption public key and the asymmetric encryption public key of the target cloud virtual password device to the top-up management system of the cloud host through a secure communication channel inside the cloud host where the target cloud virtual password device is located. In this way, it can be ensured that the post-quantum encryption public key and the asymmetric encryption public key are not tampered with by malicious software during transmission.
[0079] S403: The cloud host broadcasts the encryption public key of the target cloud virtual password device.
[0080] Optionally, after receiving the post-quantum encryption public key and the asymmetric encryption public key reported by the target cloud virtual password device, the refilling management system of the cloud host binds the post-quantum encryption public key and the asymmetric encryption public key of the target cloud virtual password device with the unique identity of the target cloud virtual password device, and stores them in the local trusted device public key registry or the key management service.
[0081] Further, the cloud host broadcasts the identity of the target cloud virtual password device and the corresponding post-quantum encryption public key and asymmetric encryption public key through its management interface or a predetermined publishing mechanism. The broadcast refers to a controlled publishing mechanism, so that the authorized client terminal or server can query and obtain the correct public key of the specified target cloud virtual password device before initiating the refilling operation, which is used for subsequent encryption of the session key.
[0082] In an optional embodiment, referring to Figure 5 The operation of "generating the session key ciphertext and the refilling key ciphertext based on the quantum key and the encryption public key" in step S204 can be specifically as follows: S501: The server generates a first session key and a second session key based on the received quantum key.
[0083] Optionally, after receiving the quantum key of a specified length sent by the quantum distribution device, the server starts a local high-security random number generator to dynamically generate an independent first session key and a second session key with high entropy. It should be noted that the first session key and the second session key will be used as temporary key materials for subsequent encryption operations.
[0084] S502: The server encrypts the first session key based on the post-quantum encryption public key to obtain the first session key ciphertext.
[0085] Optionally, the server uses the post-quantum encryption public key of the target cloud virtual password device to perform encryption operation on the first session key to obtain the first session key ciphertext. It should be noted that this encryption scheme can ensure that the confidentiality of the first session key can still be guaranteed in the future quantum computing environment.
[0086] S503: The server encrypts the second session key based on the asymmetric encryption public key to obtain the second session key ciphertext.
[0087] Optionally, the server performs an encryption operation on the second session key using the asymmetric encryption public key of the target cloud virtual password device to obtain second session key ciphertext. In this way, the compliance requirements of the existing password system can be met, and algorithm-level heterogeneous complementarity with the post-quantum encryption algorithm is formed.
[0088] S504: The server performs an XOR operation on the first session key and the second session key, and encrypts the quantum key based on the XOR operation result to obtain the refueling key ciphertext.
[0089] Optionally, the first session key and the second session key are subjected to an XOR logical operation to obtain a combined password with the same length as the two, and the combined password is used to encrypt the quantum password output by the quantum distribution device to obtain the refueling key ciphertext. It should be noted that the encryption operation takes advantage of the reversibility of the XOR logical operation to facilitate subsequent decryption.
[0090] In an optional embodiment, referring to Figure 6 The operation of "the client terminal writes the session key ciphertext and the refueling key ciphertext into the secure storage area of the refueling medium" in step 205 can be specifically: S601: The client terminal concatenates the post-quantum encryption public key and the asymmetric encryption public key of the target cloud virtual password device to obtain a concatenated encryption public key.
[0091] S602: The client terminal calculates the public key fingerprint corresponding to the concatenated encryption public key.
[0092] Optionally, after receiving the first session key ciphertext, the second session key ciphertext, and the refueling key ciphertext returned by the server, the client terminal does not immediately write into the medium. In order to establish a strong identity binding between the refueling key and the target cloud virtual password device, the client terminal first needs to generate a unique identity verification identifier for the target cloud virtual password device.
[0093] Specifically, the client terminal sequentially concatenates the locally held post-quantum encryption public key and the asymmetric encryption public key of the target cloud virtual password device to form a complete public key data block. Subsequently, the client terminal invokes a cryptographic hash algorithm (such as the symmetric cryptographic algorithm SM3) to calculate the concatenated public key data block and generate a fixed-length hash value with strong collision resistance. This hash value is the public key fingerprint of the target cloud virtual password device. The public key fingerprint uniquely represents the identity of the target cloud virtual password device specified in this refueling operation.
[0094] S603: The client terminal writes the first session key ciphertext, the second session key ciphertext, the refueling key ciphertext, and the public key fingerprint into the secure storage area of the refueling medium through a secure channel.
[0095] Optionally, after the client terminal generates a public key fingerprint for the target cloud virtual cryptographic device, the filling software deployed on the client terminal prompts the user to enter the filling medium password. The client terminal verifies the filling medium based on the user's input filling medium password, and after successful verification, an authenticated secure channel is established between the filling medium and the client terminal. In this way, it is ensured that only authorized users can access the storage function of the filling medium.
[0096] Furthermore, through a secure channel, the client terminal sends the first session key ciphertext, the second session key ciphertext, the refill key ciphertext, and the public key fingerprint to the refill medium. After receiving this data, the security chip of the refill medium persistently stores it in the secure storage area inside the chip.
[0097] In one alternative implementation, see [link to implementation details]. Figure 7 The specific operation of S302 mentioned above can be as follows: S701: The cloud host sends a charge request to the target cloud virtual cryptographic device.
[0098] Optionally, when an operator inserts the key-filled filling medium into the cloud host and selects the target cloud virtual cryptographic device for this filling operation on the operation interface provided by the filling management system on the cloud host, the management system deployed on the cloud host initiates a filling request to the designated target cloud virtual cryptographic device. This filling request is used to notify the target cloud virtual cryptographic device to prepare to receive the key and obtain its necessary identity credentials.
[0099] S702: The target cloud virtual cryptographic device responds to the injection request and sends the virtual machine identifier, post-quantum encryption public key, and asymmetric encryption public key to the cloud host.
[0100] Optionally, upon receiving a charging request from the cloud host, the target cloud virtual cryptographic device immediately responds by sending its own virtual machine unique identifier, as well as the post-quantum encryption public key and the asymmetric encryption public key used for decrypting the charging key, back to the cloud host's charging management system through the secure internal channel of the virtualization platform.
[0101] S703: The cloud host verifies the filling medium.
[0102] Optionally, after obtaining the identity credentials of the target cloud virtual cryptographic device, the cloud host's refill management system prompts the user to enter the refill medium password and verifies the refill medium based on the refill medium password.
[0103] It should be noted that the filling medium only enters a readable state after verification, and only then is the cloud host authorized to conduct subsequent secure data interaction with it.
[0104] S704: Perform fingerprint verification on the received post-quantum encryption public key and asymmetric encryption public key.
[0105] Optionally, after the media password verification, in order to prevent the charging key from being incorrectly imported into an illegal or unintended virtual password device, identity binding verification is performed based on the post-quantum encryption public key and the asymmetric encryption public key of the target cloud virtual password device.
[0106] S705: If the verification is passed, the cloud host reads the first session key ciphertext, the second session key ciphertext, and the charging key ciphertext from the secure storage area of the charging medium.
[0107] Optionally, only when the fingerprint verification is passed, the cloud host is authorized by the charging medium to perform a key data reading operation, and the cloud host reads the first session key ciphertext, the second session key ciphertext, and the charging key ciphertext from the secure storage area of the charging medium through a secure channel.
[0108] In an optional embodiment, referring to Figure 8 The operation of step S704 can be specifically: S801: The cloud host splices the received post-quantum encryption public key and asymmetric encryption public key to obtain a spliced encryption public key, and calculates a verification fingerprint of the spliced encryption public key.
[0109] Optionally, the charging management system of the cloud host performs a fingerprint calculation operation based on the current post-quantum encryption public key and asymmetric encryption public key of the target cloud virtual password device after the charging medium verification is successful.
[0110] Specifically, the cloud host splices the received post-quantum encryption public key and asymmetric encryption public key according to the same rules and order as in the charging key phase to obtain a spliced encryption public key data block. Subsequently, the cloud host calls a preset cryptographic hash function to process the spliced encryption public key data block, and calculates a verification fingerprint of the spliced encryption public key. The verification fingerprint is a fixed-length, unique cryptographic digest value.
[0111] S802: The cloud host compares the verification fingerprint with the public key fingerprint stored in the secure storage area of the charging medium.
[0112] Optionally, the cloud host reads the pre-stored original public key fingerprint from the secure storage area of the authenticated charging medium, and compares the public key fingerprint with the calculated verification fingerprint to determine whether to continue the subsequent key charging process.
[0113] Optionally, if the public key fingerprint and the verification fingerprint are completely consistent, it indicates that the post-quantum encryption public key provided by the target cloud virtual password device for the current request to top up is completely the same as the asymmetric encryption public key, and the public key used when encrypting the top-up key. Therefore, the target cloud virtual password device is the preset legal recipient during encryption, and has the paired private key required for decryption, and the cloud host is authorized to read the encrypted key data from the top-up medium.
[0114] Optionally, if the public key fingerprint and the verification fingerprint are inconsistent, it indicates that the identity is not consistent, and security risks such as device impersonation, public key tampering, or selection of a wrong target device may be encountered. The key top-up system will immediately terminate the key top-up operation this time and return an explicit verification failure error, preventing the key data from being released to an unauthorized entity.
[0115] In an optional implementation, the encrypted private key includes a post-quantum encryption private key and an asymmetric encryption private key, as described in Figure 9 The operation of “the target cloud virtual password device decrypts the session key ciphertext and the top-up key ciphertext using the encrypted private key of the target cloud virtual password device to obtain the top-up key plaintext” in the step S305 can be specifically: S901: The target cloud virtual password device decrypts the first session key ciphertext using the post-quantum encryption private key to obtain the first session key.
[0116] Optionally, after confirming the loading request, the target cloud virtual password device first reads the received first session key ciphertext, and calls the secret saved post-quantum encryption private key to perform decryption operation on the first session key ciphertext, to restore the first session key generated by the server in the top-up key process.
[0117] S902: The target cloud virtual password device decrypts the second session key ciphertext using the asymmetric encryption private key to obtain the second session key.
[0118] Optionally, the target cloud virtual password device reads the second session key ciphertext, and calls the secret saved asymmetric encryption private key to perform decryption operation on the second session key ciphertext, to restore the second session key generated by the server.
[0119] S903: The target cloud virtual password device performs exclusive OR operation on the first session key and the second session key, and decrypts the top-up key ciphertext based on the exclusive OR operation result to obtain the top-up key plaintext.
[0120] Optionally, the target cloud virtual password device performs exclusive OR logical operation on the restored first session key and the second session key to obtain a combined key used by the server to encrypt the top-up key, and decrypts the top-up key ciphertext based on the combined key to obtain the top-up key plaintext.
[0121] In an alternative embodiment, referring to Figure 10 The key loading method of the virtual password device further comprises: S1001: The target cloud virtual password device encrypts the loading key plaintext using the master key.
[0122] Optionally, after the target cloud virtual password device successfully decrypts the loading key plaintext, the loading key plaintext is temporarily stored in the secure storage area of the target cloud virtual password device. To ensure the absolute security of the key loading plaintext when it is stored persistently in the device, and to avoid leaving the loading key plaintext in any storage medium, the target cloud virtual password device immediately starts the local encryption storage program.
[0123] Specifically, the target cloud virtual password device calls the master key, which is pre-installed in the device and protected by hardware or a trusted execution environment, to perform encryption operation on the loading key plaintext, so as to convert the sensitive loading key plaintext into a ciphertext form that can only be decrypted in the current device environment. The master key is a high-strength symmetric key generated or securely injected when the target cloud virtual password device is initially deployed, and is protected by the highest security level mechanism. The master key is used to encrypt other business keys stored in the device.
[0124] S1002: Store the encrypted loading key plaintext in the secure storage area of the target cloud virtual password device.
[0125] Optionally, the target cloud virtual password device writes the generated encrypted data to the local secure storage area through a secure path. The local secure storage area is a storage space with access control and encryption protection features divided in the instance of the target cloud virtual password device. Specifically, it can be an encrypted virtual hard disk volume provided by a virtualization platform, which is not limited in the present application.
[0126] In addition, even if the disk image of the target cloud virtual password device is illegally copied or the cloud host is attacked, the attacker cannot directly read or decrypt the key content stored in the storage area.
[0127] The following describes an electronic device and a computer readable storage medium for performing the key loading method of the virtual password device provided by the present application. The specific implementation process and technical effects are described above, and will not be described here.
[0128] Figure 11 is a structural schematic diagram of an electronic device provided by the present application, referring to Figure 11The electronic device includes a memory 1101 and a processor 1102, the memory 1101 stores a computer program capable of running on the processor 1102, and when the processor 1102 executes the computer program, the steps in any of the above method embodiments are implemented.
[0129] It should be noted that the electronic device can be any one of the client terminal 102, the server 1031, the quantum distribution device 1032 and the cloud host 101, and the present application does not make a specific limitation.
[0130] The embodiment of the present application also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps in each of the above method embodiments.
[0131] Optionally, the present application also provides a program product, for example, a computer readable storage medium, including a program, which is executed by a processor to implement any of the above key loading methods of the virtual password device.
[0132] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited to this, any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0133] The above is only a preferred embodiment of the present application, and is not used to limit the present application, and the present application can have various changes and changes for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application should be included in the protection scope of the present application.
Claims
1. A key filling method for a virtual cryptographic device, characterized in that, The method is applied to a key injection system for a virtual cryptographic device. The key injection system includes: a client terminal, a server, a quantum distribution device, and a cloud host. The server and the quantum distribution device are both located on the server side and are communicatively connected. At least one cloud virtual cryptographic device is deployed in the cloud host. The method includes: After the client terminal inserts the filling medium, the client terminal sends the encryption public key of the target cloud virtual cryptographic device and the length of the generated filling key to the server. The target cloud virtual cryptographic device is any cloud virtual cryptographic device deployed in the cloud host. The encryption public key includes: a post-quantum encryption public key and an asymmetric encryption public key. The server initiates a quantum key request to the quantum distribution device based on the encrypted public key and the length of the generated charging key. The quantum distribution device generates a quantum key of a specified length according to the quantum key request and sends the quantum key to the server. The server generates a session key ciphertext and a charging key ciphertext based on the quantum key and the encryption public key, and feeds the session key ciphertext and the charging key ciphertext back to the client terminal; The client terminal verifies the refill medium, and after successful verification, writes the session key ciphertext, the refill key ciphertext, and the encrypted public key of the target cloud virtual cryptographic device into the secure storage area of the refill medium.
2. The key filling method for a virtual cryptographic device according to claim 1, characterized in that, The method further includes: After the filling medium is inserted into the cloud host, the cloud host obtains the identity information and encryption public key of the target cloud virtual cryptographic device, verifies the filling medium and the encryption public key, and after the verification is successful, obtains the session key ciphertext and the filling key ciphertext from the filling medium. The encryption public key includes: a post-quantum encryption public key and an asymmetric encryption public key. The cloud host copies the session key ciphertext and the injection key ciphertext to the target cloud virtual cryptographic device, and after the copy is completed, sends a loading request to the target cloud virtual cryptographic device; The target cloud virtual cryptographic device loads the session key ciphertext and the charge key ciphertext according to the loading request, and decrypts the session key ciphertext and the charge key ciphertext using the encryption private key of the target cloud virtual cryptographic device to obtain the charge key plaintext.
3. The key filling method for a virtual cryptographic device according to claim 1, characterized in that, The method further includes: The target cloud virtual cryptographic device generates an encryption key pair corresponding to the target cloud virtual cryptographic device based on a built-in encryption algorithm. The encryption key pair includes: an encryption public key and an encryption private key. The target cloud virtual cryptographic device sends the public key of the encryption key pair to the cloud host machine; The cloud host machine broadcasts the public key of the target cloud virtual cryptographic device.
4. The key filling method for a virtual cryptographic device according to claim 1, characterized in that, The server generates session key ciphertext and injection key ciphertext based on the quantum key and the encryption public key, including: The server generates a first session key and a second session key based on the received quantum key; The server encrypts the first session key based on the post-quantum encryption public key to obtain the first session key ciphertext; The server encrypts the second session key based on the asymmetric encryption public key to obtain the second session key ciphertext; The server performs an XOR operation on the first session key and the second session key, and encrypts the quantum key based on the XOR result to obtain the ciphertext of the charging key.
5. The key filling method for a virtual cryptographic device according to claim 1, characterized in that, The client terminal writes the session key ciphertext, the filling key ciphertext, and the encryption public key of the target cloud virtual cryptographic device into the secure storage area of the filling medium, including: The client terminal concatenates the post-quantum encryption public key and the asymmetric encryption public key of the target cloud virtual cryptographic device to obtain the concatenated encryption public key, and calculates the public key fingerprint corresponding to the concatenated encryption public key. The client terminal writes the first session key ciphertext, the second session key ciphertext, the filling key ciphertext, and the public key fingerprint into the secure storage area of the filling medium through a secure channel.
6. The key filling method for a virtual cryptographic device according to claim 2, characterized in that, The cloud host obtains the identity information and encryption public key of the target cloud virtual cryptographic device, verifies the filling medium and the encryption public key, and after successful verification, retrieves the session key ciphertext and the filling key ciphertext from the filling medium, including: The cloud host sends a power-up request to the target cloud virtual cryptographic device, and the target cloud virtual cryptographic device responds to the power-up request by sending a virtual machine identifier, a post-quantum encryption public key, and an asymmetric encryption public key to the cloud host. The cloud host verifies the filling medium and performs fingerprint verification on the received post-quantum encryption public key and asymmetric encryption public key; If the verification is successful, the cloud host machine reads the first session key ciphertext, the second session key ciphertext, and the recharge key ciphertext from the secure storage area of the recharge medium.
7. The key filling method for a virtual cryptographic device according to claim 6, characterized in that, The cloud host performs fingerprint verification on the received post-quantum encryption public key and asymmetric encryption public key, including: The cloud host machine concatenates the received post-quantum encryption public key with the asymmetric encryption public key to obtain the concatenated encryption public key, and calculates the verification fingerprint of the concatenated encryption public key; The cloud host compares the verification fingerprint with the public key fingerprint stored in the secure storage area of the filling medium.
8. The key filling method for a virtual cryptographic device according to claim 2, characterized in that, The encryption private key includes: a post-quantum encryption private key and an asymmetric encryption private key; the target cloud virtual cryptographic device uses its own encryption private key to decrypt the session key ciphertext and the injection key ciphertext to obtain the injection key plaintext, including: The target cloud virtual cryptographic device uses the post-quantum encryption private key to decrypt the ciphertext of the first session key to obtain the first session key; The target cloud virtual cryptographic device uses the asymmetric encryption private key to decrypt the ciphertext of the second session key to obtain the second session key; The target cloud virtual cryptographic device performs an XOR operation on the first session key and the second session key, and decrypts the ciphertext of the charging key based on the XOR operation result to obtain the plaintext of the charging key.
9. The key filling method for a virtual cryptographic device according to claim 8, characterized in that, The method further includes: The target cloud virtual cryptographic device uses a master key to encrypt the plaintext of the charging key, and stores the encrypted plaintext of the charging key in the secure storage area of the target cloud virtual cryptographic device.
10. A key injection system for a virtual cryptographic device, characterized in that, The key filling system of the virtual cryptographic device includes: a client terminal, a server, a quantum distribution device, and a cloud host. The server and the quantum distribution device are both located on the server side and are connected in communication. At least one cloud virtual cryptographic device is deployed in the cloud host. The virtual cryptographic device key filling system is used to perform the steps of the method described in any one of claims 1 to 9.