Key processing method based on hardware security module, storage medium and device
By adopting a key processing method based on a hardware security module, the problems of low security and high cost of key storage in mobile hardware are solved, achieving high security and low cost key use and simplifying the operation process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- RICHFIT INFORMATION TECH
- Filing Date
- 2025-01-22
- Publication Date
- 2026-07-24
Smart Images

Figure CN122451925A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of security, and in particular to a key processing method, storage medium, and device based on a hardware security module. Background Technology
[0002] As the security requirements for data in mobile terminals become increasingly stringent, it is necessary to use keys to process the data.
[0003] In the prior art, the key is stored in mobile hardware (such as a dongle), and then the data in the mobile terminal is processed based on the key in the mobile hardware.
[0004] However, storing the key in mobile hardware as described above results in low security if the mobile hardware is lost, and the mobile hardware is also expensive and complex to operate. Summary of the Invention
[0005] This application provides a key processing method, storage medium, and device based on a hardware security module, which achieves high security, low cost, and ease of operation in key usage.
[0006] In a first aspect, embodiments of this application provide a key processing method based on a hardware security module, comprising:
[0007] In response to an operation request issued by a user through an application, the system reads an encryption key from a preset hardware security module and decrypts the encryption key to obtain a decrypted key; wherein the operation request indicates an operation to be performed on the data to be processed.
[0008] Retrieve the data to be processed indicated by the operation request from other storage spaces that are different from the storage space where the preset hardware security module is located;
[0009] In the preset hardware security module, the retrieved data to be processed is processed according to the decrypted key to obtain the processed data.
[0010] In one possible implementation, the operation request includes a key identifier; reading the encryption key from a preset hardware security module includes:
[0011] Based on the key identifier, the encryption key associated with the key identifier is read from the preset hardware security module.
[0012] In one possible implementation, the method further includes:
[0013] Based on contactless communication, receive the initial key and the identifier of the initial key;
[0014] In the preset hardware security module, the initial key is encrypted to obtain the encryption key, and the identifier of the initial key is determined as the key identifier of the encryption key;
[0015] In the preset hardware security module, the initial key is deleted; and an association is established between the key identifier and the encryption key.
[0016] In one possible implementation, the operation request includes the application's package name and key identifier; before reading the encryption key from a preset hardware security module, it also includes:
[0017] The permission to use the encryption key of the application is verified based on the application's package name and the key identifier;
[0018] If the verification of the application's encryption key usage permission is successful, then the user's identity is verified.
[0019] If the user's authentication is successful, the step of reading the encryption key from the preset hardware security module is executed.
[0020] In one possible implementation, the verification of the application's encryption key usage rights based on the application's package name and the key identifier includes:
[0021] If it is determined that the key identifier is consistent with the first identifier, wherein the first identifier is a key identifier stored in association with the package name of the application, then it is determined that the verification of the application's encryption key usage permission has passed;
[0022] And / or, obtain the current operating system version and the current security patch version. If it is determined that the key identifier is consistent with the second identifier, wherein the second identifier is a key identifier stored in association with both the current operating system version and the current security patch version, then it is determined that the verification of the application's encryption key usage permission has passed.
[0023] In one possible implementation, the method further includes:
[0024] Based on contactless communication, it receives the operating system version, security patch version, and the package name of the application.
[0025] The application's package name and the key identifier are associated and stored together, and the operating system version, security patch version, and the key identifier are also associated and stored together.
[0026] In one possible implementation, the operation request further includes one or more of the following information: user fingerprint, password, facial information; and verifies the user's identity, including:
[0027] If it is determined that the information in the operation request meets the preset conditions, then the user's identity verification is successful.
[0028] The preset conditions include one or more of the following: the user's fingerprint matches the pre-stored fingerprint, the password matches the pre-stored password, and the facial information matches the pre-stored facial information.
[0029] In one possible implementation, the method further includes:
[0030] The decrypted key is deleted from the preset hardware security module.
[0031] In one possible implementation, the method further includes:
[0032] The processed data is retrieved from the hardware security module, and data manipulation is performed on the processed data.
[0033] Secondly, embodiments of this application provide a key processing device based on a hardware security module, comprising:
[0034] The reading module is used to read the encryption key from the preset hardware security module in response to an operation request issued by the user through the application; wherein the operation request indicates that an operation is to be performed on the data to be processed.
[0035] The decryption module is used to decrypt the encryption key to obtain the decrypted key;
[0036] The retrieval module is used to retrieve the data to be processed indicated by the operation request from other storage spaces that are different from the storage space where the preset hardware security module is located.
[0037] The processing module is used in the preset hardware security module to process the retrieved data to be processed according to the decrypted key, so as to obtain the processed data.
[0038] In one possible implementation, the operation request includes a key identifier;
[0039] In one possible implementation, the "read encryption key from preset hardware security module" function in the reading module is specifically used for:
[0040] Based on the key identifier, the encryption key associated with the key identifier is read from the preset hardware security module.
[0041] In one possible implementation, the device is further used for:
[0042] Based on contactless communication, receive the initial key and the identifier of the initial key;
[0043] In the preset hardware security module, the initial key is encrypted to obtain the encryption key, and the identifier of the initial key is determined as the key identifier of the encryption key;
[0044] In the preset hardware security module, the initial key is deleted; and an association is established between the key identifier and the encryption key.
[0045] In one possible implementation, the operation request includes the application's package name and key identifier;
[0046] In one possible implementation, prior to the "reading encryption key from a preset hardware security module" step in the reading module, the device is further configured to:
[0047] The permission to use the encryption key of the application is verified based on the application's package name and the key identifier;
[0048] If the verification of the application's encryption key usage permission is successful, then the user's identity is verified.
[0049] If the user's authentication is successful, the step of reading the encryption key from the preset hardware security module is executed.
[0050] In one possible implementation, the function of "verifying the access rights to the encryption key of the application based on the application's package name and the key identifier" in the device is specifically used for:
[0051] If it is determined that the key identifier is consistent with the first identifier, wherein the first identifier is a key identifier stored in association with the package name of the application, then it is determined that the verification of the application's encryption key usage permission has passed;
[0052] And / or, obtain the current operating system version and the current security patch version. If it is determined that the key identifier is consistent with the second identifier, wherein the second identifier is a key identifier stored in association with both the current operating system version and the current security patch version, then it is determined that the verification of the application's encryption key usage permission has passed.
[0053] In one possible implementation, the device is further used for:
[0054] Based on contactless communication, it receives the operating system version, security patch version, and the package name of the application.
[0055] The application's package name and the key identifier are associated and stored together, and the operating system version, security patch version, and the key identifier are also associated and stored together.
[0056] In one possible implementation, the operation request may also include one or more of the following information: user fingerprint, password, facial information;
[0057] In one possible implementation, "verifying the user's identity" in the device includes:
[0058] If it is determined that the information in the operation request meets the preset conditions, then the user's identity verification is successful.
[0059] The preset conditions include one or more of the following: the user's fingerprint matches the pre-stored fingerprint, the password matches the pre-stored password, and the facial information matches the pre-stored facial information.
[0060] In one possible implementation, the device is further used for:
[0061] The decrypted key is deleted from the preset hardware security module.
[0062] In one possible implementation, the device is further used for:
[0063] The processed data is retrieved from the hardware security module, and data manipulation is performed on the processed data.
[0064] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;
[0065] The memory stores computer-executed instructions;
[0066] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.
[0067] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.
[0068] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.
[0069] The key processing method, storage medium, and device based on a hardware security module provided in this application respond to an operation request issued by a user through an application, reads an encryption key from a preset hardware security module, and decrypts the encryption key to obtain a decrypted key; wherein, the operation request indicates the operation to be performed on the data to be processed; and retrieves the data to be processed indicated by the operation request from a storage space other than the storage space where the preset hardware security module is located; then, in the preset hardware security module, the retrieved data to be processed is processed according to the decrypted key to obtain processed data.
[0070] Because the encryption key is stored in a preset hardware security module, and the storage space of the preset hardware security module is different from the storage space of other storage devices in the terminal device that are different from the preset hardware security module; and the decryption of the key and the use of the decrypted key are both completed automatically in the preset hardware security module, the decrypted key will not appear in the storage space outside the preset hardware security module. The key is highly secure, low-cost, and easy to use. Attached Figure Description
[0071] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0072] Figure 1 A flowchart illustrating a key processing method based on a hardware security module provided in this application;
[0073] Figure 2 A flowchart illustrating another key processing method based on a hardware security module provided in this application;
[0074] Figure 3 A schematic diagram of the key processing device based on a hardware security module provided in this application;
[0075] Figure 4 A schematic diagram of the structure of the electronic device provided in this application.
[0076] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0077] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0078] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation access points for users to choose to authorize or refuse.
[0079] As the requirements for mobile terminal data security continue to increase, it is necessary to use keys to process data.
[0080] In one example, the key can be stored in mobile hardware (such as a dongle). Suppose user U1 connects mobile hardware J to terminal device Z1, and then user U1 enters the text X11 in the "User Information 1" text box on the application C1 page of terminal device Z1 and clicks the "Submit" button A1. After capturing the above user operation, application C1 generates an encryption request based on the above user operation and sends it to the encryption module in terminal device Z1. The encryption request includes a key alias B1 and the text X11. The encryption request indicates that the text X11 should be encrypted based on the key associated with the key alias B1.
[0081] After receiving the encryption request, the encryption module in terminal device Z1 obtains the key associated with key alias B1 from the mobile hardware, and then encrypts the text X11 based on the key associated with key alias B1 to obtain the encrypted text X12, and sends the encrypted text X12 to application C1.
[0082] Application C1 stores the encrypted text X12 in the database, in the preset field D1 of the preset table B2 associated with the "Submit" button A1.
[0083] However, storing the key in mobile hardware as described above results in low security if the mobile hardware is lost, and the mobile hardware is also expensive and complex to operate.
[0084] This application provides a key processing method, storage medium, and device based on a hardware security module to solve the above-mentioned technical problems.
[0085] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0086] Figure 1 A flowchart illustrating a key processing method based on a hardware security module provided in this application is shown below. Figure 1 As shown, the method includes:
[0087] S101. In response to an operation request issued by the user through the application, read the encryption key from the preset hardware security module and decrypt the encryption key to obtain the decrypted key; wherein, the operation request indicates the operation to be performed on the data to be processed.
[0088] For example, the executing entity of this embodiment may be a terminal device, an electronic device, a client, a key processing device or device based on a hardware security module, or other devices or devices that can implement the scheme of this application, and there are no restrictions on this.
[0089] This embodiment uses a terminal device as the execution subject for example.
[0090] For example, the preset hardware security module (HSM) in the terminal device can be a physical device used to process sensitive data. Assuming the preset hardware security module is Y, the sensitive data includes, but is not limited to, encryption keys. The encryption key can be understood as an encrypted key, for example, encryption key M1. The storage space of the preset hardware security module can be physically isolated from the storage space of other data. Therefore, it can be understood that the preset hardware security module can provide a highly secure way to store and process sensitive data.
[0091] The operation request instructs the user to perform key-related operations on the data to be processed, including but not limited to encryption and decryption. In various embodiments of this application, the operation request is illustrated by instructing the user to encrypt the data to be processed.
[0092] The data to be processed can be understood, for example, as data captured by an application on a terminal device from user actions on the application page, indicating that key-related processing is to be performed in a preset hardware security module. In various embodiments of this application, the data to be processed is illustrated by taking data indicating that encryption processing is to be performed in a preset hardware security module as an example.
[0093] For example, an application in a terminal device can generate an operation request based on captured user actions and send it to a preset hardware security module in the terminal device. Then, it reads the encryption key from the preset hardware security module and decrypts the encryption key within the preset hardware security module to obtain the decrypted key. The decryption algorithm can include, for example, decryption based on CBC mode or decryption based on Advanced Encryption Standard (AES). This embodiment does not limit the decryption algorithm of the encryption key, as long as it matches the encryption algorithm of the key.
[0094] In one example, suppose user U2 enters the text X21 in the "User Information 2" text box on the application C2 page of terminal device Z2 and clicks the "Submit" button A2. Then, application C2 in terminal device Z2 captures this user action, generates an operation request based on the user action, and sends it to the preset hardware security module Y1 in terminal device Z2. This operation request indicates that the data to be processed (text X21) be encrypted. For example, text X21 can be stored in the memory of terminal device Z2, in a different storage space than the preset hardware security module Y1.
[0095] After receiving the operation request, the preset hardware security module Y1 in the terminal device Z2 reads the encryption key M11 from the preset hardware security module Y1 and decrypts the encryption key M11 to obtain the decrypted key M12.
[0096] S102. Retrieve the data to be processed as indicated by the operation request from a storage space other than the storage space where the preset hardware security module is located.
[0097] For example, after receiving an operation request, the preset hardware security module in the terminal device retrieves the data to be processed indicated by the operation request from other storage spaces in the terminal device that are different from the storage space where the preset hardware security module is located.
[0098] Among them, other storage spaces in the terminal device that are different from the storage space where the preset hardware security module is located can be the memory in the terminal device or other storage devices in the terminal device.
[0099] Referring again to the example in step S101, after receiving the operation request, the preset hardware security module Y1 in the terminal device Z2 retrieves the text X21 indicated by the operation request from the memory in the terminal device Z2.
[0100] S103. In the preset hardware security module, the retrieved data to be processed is processed according to the decrypted key to obtain the processed data.
[0101] For example, after obtaining the decrypted key and the data to be processed in the preset hardware security module, the terminal device performs the operation indicated by the data operation on the data to be processed based on the decrypted key, and obtains the processed data.
[0102] Referring again to the example in step S102, after obtaining the decrypted key M12 and text X21 in the preset hardware security module Y1, the terminal device Z2 encrypts the text X21 based on the decrypted key M12 to obtain the encrypted text X22.
[0103] The key processing method based on a hardware security module provided in this application responds to an operation request issued by a user through an application, reads an encryption key from a preset hardware security module, and decrypts the encryption key to obtain a decrypted key. The operation request indicates an operation to be performed on the data to be processed. The data to be processed, indicated by the operation request, is retrieved from a storage space other than the storage space where the preset hardware security module is located. Then, in the preset hardware security module, the retrieved data to be processed is processed according to the decrypted key to obtain processed data.
[0104] Because the encryption key is stored in a preset hardware security module, and the storage space of the preset hardware security module is different from the storage space of other storage devices in the terminal device that are different from the preset hardware security module; and the decryption of the key and the use of the decrypted key are both completed automatically in the preset hardware security module, the decrypted key will not appear in the storage space outside the preset hardware security module. The key is highly secure, low-cost, and easy to use.
[0105] Figure 2 A flowchart illustrating another key processing method based on a hardware security module provided in this application is shown below. Figure 2 As shown, in this embodiment... Figure 1 Based on the embodiments, a key processing method based on a hardware security module is described in detail. The method includes:
[0106] S201. Based on contactless communication, receive the initial key and the identifier of the initial key.
[0107] For example, the executing entity of this embodiment may be a terminal device, an electronic device, a client, a key processing device or device based on a hardware security module, or other devices or devices that can implement the scheme of this application, and there are no restrictions on this.
[0108] This embodiment uses a terminal device as the execution subject for example.
[0109] For example, contactless communication includes one or more of Bluetooth, Near Field Communication (NFC), and Wireless Fidelity (WIFI).
[0110] An initial key can be understood as the key used by a terminal device when operating on data. The initial key can be generated by other terminal devices (such as an administrator's terminal device), and the methods for generating the initial key include, but are not limited to, generating it using a random number generator or generating it based on the principles of Elliptic Curve Cryptography (ECC) asymmetric encryption algorithms. This embodiment does not limit the method of generating the initial key, as long as the initial key can be used by the terminal device to perform key-related operations on data (such as encryption and decryption).
[0111] The initial key has an identifier, which can be understood as a unique identifier for the key.
[0112] For example, an initial key is generated on the administrator's terminal device and sent from the administrator's terminal device to a preset hardware security module on the terminal device via contactless communication. The preset hardware security module has already been described in step S101; details can be found in the description of step S101, and will not be repeated here.
[0113] Assume the default hardware security module is Y2.
[0114] In one example, an initial key S is generated on the administrator's terminal device Z3. The initial key S has an initial key identifier B3. The initial key S and the initial key identifier B3 are sent to the preset hardware security module Y2 of the terminal device Z4 via Bluetooth.
[0115] S202. In the preset hardware security module, the initial key is encrypted to obtain the encryption key, and the identifier of the initial key is determined as the key identifier of the encryption key.
[0116] For example, after receiving the initial key and the identifier of the initial key, the preset hardware security module in the terminal device encrypts the initial key to obtain the encryption key, and uses the identifier of the initial key as the key identifier of the encryption key.
[0117] The encryption algorithm used when encrypting the initial key can be, for example, encryption based on CBC mode or Advanced Encryption Standard (AES). This embodiment does not limit the encryption algorithm.
[0118] In one example, referring to the example in step S201, after receiving the initial key S and the identifier B3 of the initial key, the preset hardware security module Y2 in the terminal device Z4 encrypts the initial key S based on the CBC mode to obtain the encryption key M21, and uses the identifier B3 of the initial key as the key identifier B3 of the encryption key.
[0119] S203. In the preset hardware security module, delete the initial key; and establish an association between the key identifier and the encryption key.
[0120] For example, after obtaining the encryption key, the preset hardware security module in the terminal device deletes the initial key and establishes an association between the key identifier and the encryption key.
[0121] In one example, still referring to the example in step S202, after obtaining the encryption key M21, the preset hardware security module Y2 in the terminal device Z4 deletes the initial key S in the preset hardware security module Y2; and establishes an association between the key identifier B3 and the encryption key M21.
[0122] The advantage of deleting the initial key after obtaining the encryption key is to minimize the time the initial key exists on the terminal device and avoid its leakage.
[0123] It is worth noting that the terminal device's default hardware security module may include at least one encryption key. Therefore, the advantage of establishing an association between key identifiers and encryption keys is that different applications can use different or the same encryption keys associated with key identifiers to operate on data, thereby improving the security of data in applications.
[0124] S204: Based on contactless communication, receive the operating system version, security patch version, and application package name.
[0125] For example, when the initial key is sent from the administrator's terminal device to the preset hardware security module of the terminal device via contactless communication, the identifier of the initial key, the operating system version of the administrator's terminal device, the security patch version, and the package name of at least one preset application can also be sent to the terminal device and stored in a storage space different from the storage space where the preset hardware security module is located.
[0126] The operating system version and security patch version of the administrator's terminal device can be understood as an operating system version and security patch version compatible with the initial key. If it is another operating system version and security patch version, the initial key cannot be used.
[0127] An application's package name can be understood as a unique identifier for the application.
[0128] The default application package name can be, for example, the package name of at least one application that the administrator enters on the administrator's terminal device after the initial key is generated. The default application package name can be understood as the package name of the application for which the initial key is authorized by the administrator; for applications other than these, the administrator has not authorized the use of the initial key.
[0129] In one example, referring to the example in step S201, when the initial key S and the identifier B3 of the initial key are sent to the preset hardware security module Y2 of the terminal device Z4 via Bluetooth, the identifier B3 of the initial key, the operating system version V11, the security patch version V21 of the administrator's terminal device Z3, and the application package name C3 are also sent to the terminal device Z4 and stored in the terminal device's storage space K, which is different from the storage space where the preset hardware security module Y2 is located.
[0130] S205. Associate the application package name with the key identifier and store them together, and associate the operating system version, security patch version, and key identifier with the key identifier.
[0131] For example, the identifier of the initial key can be used as the key identifier. It is understood that the key identifier is the same as the key identifier of the encryption key obtained in step S202.
[0132] After receiving the key identifier, the operating system version, security patch version, and at least one preset application package name in the terminal device's storage space K, the terminal device establishes and stores the association between the application package name and the key identifier for each application package name, and establishes and stores the association between the operating system version, security patch version, and key identifier.
[0133] Understandably, a key identifier can be associated with one or more applications.
[0134] In one example, referring to the example in step S201, after receiving the key identifier B3, the operating system version V11, the security patch version V21 in the administrator's terminal device Z3, and the application package name C3, the storage space K of the terminal device establishes an association between the application package name C3 and the key identifier B3 and stores them, and establishes an association between the operating system version V11, the security patch version V21, and the key identifier B3 and stores them.
[0135] S206. In response to an operation request issued by the user through the application, verify the application's access rights to the encryption key based on the application's package name and key identifier. The operation request indicates the data to be processed.
[0136] In one example, the operation request includes the application's package name and key identifier.
[0137] Step S206 includes the following processes:
[0138] If the key identifier is determined to be consistent with the first identifier, where the first identifier is a key identifier stored in association with the application's package name, then the verification of the application's encryption key usage permission is deemed successful.
[0139] And / or, obtain the current operating system version and the current security patch version. If it is determined that the key identifier is consistent with the second identifier, wherein the second identifier is a key identifier stored in association with both the current operating system version and the current security patch version, then it is determined that the verification of the application's encryption key usage permission has passed.
[0140] For example, it is worth noting that the verification method for an application's encryption key access permission may include one or more methods. If multiple methods are used, the application's encryption key access permission verification is only successful if all methods are verified successfully.
[0141] The implementation method for responding to operation requests issued by the user through the application is similar to the implementation method for responding to operation requests issued by the user through the application in step S101. For details, please refer to the description in step S101, which will not be repeated here.
[0142] Suppose user U3 enters the text X31 in the "User Information 3" text box on the application page of application C3 (hereinafter referred to as application C3) in terminal device Z4, and clicks the "Submit" button A3. Then, application C3 in terminal device Z4 captures the user's action, generates an operation request based on the user's action, and sends it to the preset hardware security module Y2 in terminal device Z4. This operation request indicates that the data to be processed (text X31) be encrypted. For example, text X31 can be stored in the memory of terminal device Z4, in a different storage space than the preset hardware security module Y2.
[0143] Referring again to the examples in steps S203 and S205, assuming that the operation request includes the application's package name C3 and key identifier B3, the terminal device determines that the first identifier is the key identifier B3 stored in association with the application's package name C3, and then determines that the key identifier B3 in the operation request is consistent with the first identifier B3, thus confirming that the verification of the application's encryption key usage permission is successful.
[0144] And / or, assuming the terminal device obtains the current operating system version as V11 and the current security patch version as V21, the terminal device determines that the second identifier is the key identifier B3 stored in association with both the current operating system version V11 and the current security patch version V21, and then determines that the key identifier B3 is consistent with the second identifier B3, and thus determines that the verification of the application's encryption key usage permission is successful.
[0145] Since step S205 establishes an association between the application's package name and the key identifier, and also establishes an association between the operating system version, security patch version, and key identifier; and step S203 establishes an association between the key identifier and the encryption key, step S206 can verify the application's permission to use the encryption key associated with the key identifier in the operation request based on the above associations. Only applications that have passed the permission verification can use the encryption key in the preset hardware security module. Therefore, the security of key usage is high.
[0146] S207. If the verification of the application's encryption key usage permission is successful, and if the information in the operation request meets the preset conditions, then the user's authentication is successful. The preset conditions include one or more of the following: the user's fingerprint matches a pre-stored fingerprint, the password matches a pre-stored password, and the facial information matches pre-stored facial information.
[0147] In one example, the operation request may also include one or more of the following information: user fingerprint, password, facial information.
[0148] For example, it is worth noting that user authentication can include one or more methods. If multiple methods are used, user authentication is only successful if all methods are verified.
[0149] Referring again to the example in step S206, if it is determined that the verification of the access permission of the encryption key M21 of application C3 is successful, and assuming that the operation request also includes the user fingerprint W1, and assuming that the pre-stored fingerprint is also W1, then the terminal device determines that the user fingerprint W1 is consistent with the pre-stored fingerprint, and thus determines that the user's authentication is successful.
[0150] The implementation methods for password and facial recognition authentication are similar to those for fingerprint authentication. For details, please refer to the above description of fingerprint authentication, which will not be repeated here.
[0151] S208. If the user's authentication is successful, then read the encryption key associated with the key identifier from the preset hardware security module according to the key identifier.
[0152] For example, still referring to the example in step S207, if it is determined that the user's authentication is successful, the encryption key M21 associated with the key identifier B3 in the operation request issued by the application C3 is read from the preset hardware security module Y2.
[0153] Because the encryption key is read from the preset hardware security module only after the application's permission to use the encryption key has been verified and the user's authentication has been verified, the encryption key associated with the key identifier in the operation request issued by application C3 is ensured to be highly secure.
[0154] S209. Decrypt the encryption key to obtain the decrypted key;
[0155] For example, the implementation of step S209 is similar to the implementation of "decrypting the encryption key to obtain the decrypted key" in step S101. For details, please refer to the description in step S101, which will not be repeated here.
[0156] It is understandable that the decrypted key can also be understood as the initial key.
[0157] S210. Retrieve the data to be processed as indicated by the operation request from a storage space other than the storage space where the preset hardware security module is located.
[0158] For example, the implementation of step S210 is similar to that of step S102. For details, please refer to the description in step S102, which will not be repeated here.
[0159] S211. In the preset hardware security module, the retrieved data to be processed is processed according to the decrypted key to obtain the processed data.
[0160] For example, the implementation of step S211 is similar to that of step S103. For details, please refer to the description in step S103, which will not be repeated here.
[0161] S212. In the preset hardware security module, delete the decrypted key.
[0162] For example, after obtaining the processed data in the preset hardware security module, the terminal device can delete the decrypted key.
[0163] In one example, suppose that in step S209, the encryption key M21 is decrypted in the preset hardware security module Y2 to obtain the decrypted key M22. Suppose that in step S211, the data to be processed (e.g., text X31) indicated by the operation request issued by the invoked application C3 is encrypted in the preset hardware security module Y2 according to the decrypted key M22 to obtain the processed data, such as the encrypted text X32.
[0164] Next, the decrypted key M22 is deleted from the preset hardware security module Y2.
[0165] The advantage of this approach is that it minimizes the time the decrypted key remains on the terminal device, thus preventing key leakage.
[0166] S213. Retrieve the processed data from the hardware security module and perform data manipulation on the processed data.
[0167] For example, still referring to the example in step S206, suppose user U3 enters the text X31 in the "User Information 3" text box on the application page of application package name C3 (hereinafter referred to as application C3) on terminal device Z4, and clicks the "Submit" button A3. Then, the operation request generated by the above user operation also indicates, for example, a storage request after obtaining the processed data. The storage request indicates that the processed data be stored in the database. The storage request includes the processed data.
[0168] Referring again to the example in step S212, the terminal device obtains the processed data, such as encrypted text X32, in the preset hardware security module Y2, and sends the encrypted text X32 to the application C3 in the terminal device.
[0169] Next, application C3 in the terminal device stores the encrypted text X32 from the storage request into the preset field D2 of the preset table B4 associated with button A3 in the terminal device's database. And / or, application C3 in the terminal device sends the storage request to the server, and the server then stores the encrypted text X32 into the preset field D3 of the preset table B5 associated with button A3 in the server's database.
[0170] Since the processed data is based on key-based processing, data operations on the processed data are more secure.
[0171] Figure 3 A schematic diagram of the key processing device based on a hardware security module provided in this application is shown below. Figure 3 As shown, the key processing device 30 based on a hardware security module provided in this embodiment includes:
[0172] The reading module 301 is used to read the encryption key from the preset hardware security module in response to an operation request issued by the user through the application; wherein the operation request indicates the operation to be performed on the data to be processed.
[0173] The decryption module 302 is used to decrypt the encryption key to obtain the decrypted key;
[0174] The retrieval module 303 is used to retrieve the data to be processed indicated by the operation request from a storage space other than the storage space where the preset hardware security module is located.
[0175] The processing module 304 is used to process the retrieved data to be processed in a preset hardware security module according to the decrypted key, so as to obtain the processed data.
[0176] In one possible implementation, the operation request includes a key identifier;
[0177] In one possible implementation, the "read encryption key from preset hardware security module" function in reading module 301 is specifically used for:
[0178] Based on the key identifier, the encryption key associated with the key identifier is read from the preset hardware security module.
[0179] In one possible implementation, the device 30 is further used for:
[0180] Based on contactless communication, receive the initial key and the identifier of the initial key;
[0181] In the preset hardware security module, the initial key is encrypted to obtain the encryption key, and the identifier of the initial key is determined as the key identifier of the encryption key.
[0182] In the preset hardware security module, the initial key is deleted; and the key identifier and encryption key are associated.
[0183] In one possible implementation, the operation request includes the application's package name and key identifier;
[0184] In one possible implementation, before reading the encryption key from the preset hardware security module in the reading module 301, the device 30 is further configured to:
[0185] Verify the application's access rights to the encryption key based on the application's package name and key identifier;
[0186] If the application's permission to use the encryption key is verified, then the user's identity is verified.
[0187] If the user's authentication is successful, the step of reading the encryption key from the preset hardware security module is executed.
[0188] In one possible implementation, the "verification of the application's encryption key usage rights based on the application's package name and key identifier" in device 30 is specifically used for:
[0189] If the key identifier is determined to be consistent with the first identifier, where the first identifier is the key identifier stored in association with the application's package name, then the verification of the application's encryption key usage permission is deemed successful.
[0190] And / or, obtain the current operating system version and the current security patch version. If it is determined that the key identifier is consistent with the second identifier, wherein the second identifier is a key identifier stored in association with both the current operating system version and the current security patch version, then it is determined that the verification of the application's encryption key usage permission has passed.
[0191] In one possible implementation, the device 30 is further used for:
[0192] Based on contactless communication, it receives the operating system version, security patch version, and application package name;
[0193] The application's package name and key identifier are stored together, and the operating system version, security patch version, and key identifier are stored together.
[0194] In one possible implementation, the operation request may also include one or more of the following information: user fingerprint, password, facial information;
[0195] In one possible implementation, "verifying the user's identity" in device 30 includes:
[0196] If the information in the operation request is determined to meet the preset conditions, then the user's authentication is confirmed to be successful.
[0197] The preset conditions include one or more of the following: the user's fingerprint matches the pre-stored fingerprint, the password matches the pre-stored password, and the facial information matches the pre-stored facial information.
[0198] In one possible implementation, the device 30 is further used for:
[0199] In the preset hardware security module, delete the decrypted key.
[0200] In one possible implementation, the device 30 is further configured to: retrieve processed data from the hardware security module and perform data manipulation on the processed data.
[0201] The key processing device based on the hardware security module provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0202] Figure 4 A schematic diagram of the structure of the electronic device provided in this application. Figure 4 As shown, the electronic device 40 provided in this embodiment includes at least one processor 401 and a memory 402. Optionally, the device 40 further includes a communication component 403. The processor 401, memory 402, and communication component 403 are connected via a bus 404.
[0203] In a specific implementation, at least one processor 401 executes computer execution instructions stored in memory 402, causing at least one processor 401 to perform the above-described method.
[0204] The specific implementation process of processor 401 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0205] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0206] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0207] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0208] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0209] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.
[0210] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0211] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.
[0212] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0213] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0214] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0215] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0216] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0217] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A key processing method based on a hardware security module, characterized in that, The method includes: In response to an operation request issued by a user through an application, the system reads an encryption key from a preset hardware security module and decrypts the encryption key to obtain a decrypted key; wherein the operation request indicates an operation to be performed on the data to be processed. Retrieve the data to be processed indicated by the operation request from other storage spaces that are different from the storage space where the preset hardware security module is located; In the preset hardware security module, the retrieved data to be processed is processed according to the decrypted key to obtain the processed data.
2. The method according to claim 1, characterized in that, The operation request includes a key identifier; reading the encryption key from a preset hardware security module includes: Based on the key identifier, the encryption key associated with the key identifier is read from the preset hardware security module.
3. The method according to claim 2, characterized in that, The method further includes: Based on contactless communication, receive the initial key and the identifier of the initial key; In the preset hardware security module, the initial key is encrypted to obtain the encryption key, and the identifier of the initial key is determined as the key identifier of the encryption key; In the preset hardware security module, the initial key is deleted; and an association is established between the key identifier and the encryption key.
4. The method according to claim 1, characterized in that, The operation request includes the application's package name and key identifier; before reading the encryption key from the preset hardware security module, it also includes: The permission to use the encryption key of the application is verified based on the application's package name and the key identifier; If the verification of the application's encryption key usage permission is successful, then the user's identity is verified. If the user's authentication is successful, the step of reading the encryption key from the preset hardware security module is executed.
5. The method according to claim 4, characterized in that, Verify the application's encryption key usage permissions based on the application's package name and the key identifier, including: If it is determined that the key identifier is consistent with the first identifier, wherein the first identifier is a key identifier stored in association with the package name of the application, then it is determined that the verification of the application's encryption key usage permission has passed; And / or, obtain the current operating system version and the current security patch version. If it is determined that the key identifier is consistent with the second identifier, wherein the second identifier is a key identifier stored in association with both the current operating system version and the current security patch version, then it is determined that the verification of the application's encryption key usage permission has passed.
6. The method according to claim 3, characterized in that, The method further includes: Based on contactless communication, it receives the operating system version, security patch version, and the package name of the application. The application's package name and the key identifier are associated and stored together, and the operating system version, security patch version, and the key identifier are also associated and stored together.
7. The method according to claim 4, characterized in that, The operation request also includes one or more of the following information: user fingerprint, password, facial information; verifying the user's identity includes: If it is determined that the information in the operation request meets the preset conditions, then the user's identity verification is successful. The preset conditions include one or more of the following: the user's fingerprint matches the pre-stored fingerprint, the password matches the pre-stored password, and the facial information matches the pre-stored facial information.
8. The method according to any one of claims 1-7, characterized in that, The method further includes: The decrypted key is deleted from the preset hardware security module.
9. The method according to any one of claims 1-7, characterized in that, The method further includes: The processed data is retrieved from the hardware security module, and data manipulation is performed on the processed data.
10. A key processing device based on a hardware security module, characterized in that, The device includes: The reading module is used to read the encryption key from the preset hardware security module in response to an operation request issued by the user through the application; wherein the operation request indicates that an operation is to be performed on the data to be processed. The decryption module is used to decrypt the encryption key to obtain the decrypted key; The retrieval module is used to retrieve the data to be processed indicated by the operation request from other storage spaces that are different from the storage space where the preset hardware security module is located. The processing module is used in the preset hardware security module to process the retrieved data to be processed according to the decrypted key, so as to obtain the processed data.
11. An electronic device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-9.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-9.
13. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-9.