Cryptographic configuration method, cryptographic service method, cryptographic management device, server, cryptographic service system and storage medium
By realizing forwarding and synchronization of key images in password management devices, the problem of password computing requirements for each device in parallel clustered systems is solved, and the performance of password service is improved and network bandwidth is reduced.
Patent Information
- Application Number
- PCT/CN2024/097074
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-29
- Filing Date
- 2024-06-03
- Publication Date
- 2025-06-05
AI Technical Summary
In a parallel clustered system consisting of a large number of devices, the password computing requirements of each device are difficult to effectively meet, resulting in poor password service performance, and password computing through a network access password machine takes up a large amount of network bandwidth, affecting system performance.
The password management device sends key configuration information to the first password module, obtains its key image, and forwards it to the second password module to obtain the key, thereby realizing key synchronization between the password modules of different servers and reducing dependence on the network.
Key synchronization between multiple servers is realized, network bandwidth usage is reduced, password service performance is improved, and password service performance is avoided due to network instability.
Smart Images

Figure CN2024097074_05062025_PF_FP_ABST
Abstract
Description
Password configuration method, password service method, password management device, server, password service system and storage medium
[0001] This application claims priority to Chinese Patent Application No. 202311615980.1 filed on November 29, 2023, and the contents of the above-mentioned Chinese patent application disclosure are hereby incorporated by reference in their entirety as a part of this application. Technical Field
[0002] The embodiments of the present disclosure relate to a password configuration method, a password service method, a password management device, a server, a password service system, and a storage medium. Background Art
[0003] Cryptography is the foundation of data security. Performing cryptographic operations on data through cryptographic application models effectively safeguards the confidentiality and security of data transmission. In addition to cryptographic operations on specific physical devices, such as cryptographic machines, these models can also be applied to parallel cluster systems composed of numerous devices, such as cloud computing. A large number of servers and the virtual machines running on these servers form a cluster, forming a large computing resource. Each server runs the same or similar services and performs the same or similar cryptographic operations.
[0004] In this context, it is particularly important to provide technical solutions to meet the cryptographic operation requirements of each device in a parallel cluster system composed of a large number of devices and improve the performance of cryptographic services.
[0005] Summary of the Invention
[0006] In view of this, the embodiments of the present disclosure provide a password configuration method, a password service method, a password management device, a server, a password service system and a storage medium to improve the performance of password services.
[0007] In a first aspect, an embodiment of the present disclosure provides a password configuration method, which is applied to a password management device, wherein the password management device is used to manage password modules of multiple servers, and the method includes:
[0008] Sending key configuration information to a first cryptographic module, the key configuration information including at least a key for the first cryptographic module to perform cryptographic services, the first cryptographic module being any cryptographic module of any server;
[0009] Obtaining a first key image of the first cryptographic module, where the first key image includes the key;
[0010] The first key image is forwarded to a second cryptographic module so that the second cryptographic module obtains the key and uses the key to perform cryptographic operations when the second cryptographic module is called by a corresponding server. The second cryptographic module is another cryptographic module configured on a different server.
[0011] Optionally, the password modules of the multiple servers managed by the password management device include a shared key;
[0012] The first key image of the first cryptographic module is obtained by encrypting the corresponding key image with the shared key by the first cryptographic module;
[0013] Forwarding the first key image to the second cryptographic module so that the second cryptographic module obtains the key specifically includes: forwarding the first key image to the second cryptographic module so that the second cryptographic module decrypts the first key image using a shared key to obtain a key image corresponding to the first cryptographic module, and obtaining the key based on the key image corresponding to the first cryptographic module.
[0014] Optionally, the cryptographic modules of the multiple servers managed by the password management device include an asymmetric encryption key pair and a signature public key obtained from an external certificate authority, and the first asymmetric encryption key pair of the first cryptographic module is different from the second asymmetric encryption key pair of the second cryptographic module;
[0015] Before obtaining the first key image of the first cryptographic module, the method further includes:
[0016] Obtaining a public key certificate of the second cryptographic module signed by an external certificate authority, where the public key certificate of the second cryptographic module includes the second public key in the second asymmetric encryption key pair;
[0017] The public key certificate of the second cryptographic module signed by the external certificate authority is forwarded to the first cryptographic module, so that the first cryptographic module verifies the legitimacy of the public key certificate of the second cryptographic module using the signature public key obtained from the external certificate authority.
[0018] In a second aspect, an embodiment of the present disclosure provides a password configuration method, which is applied to a password module of a server, wherein the password module includes a first password module and a second password module, wherein the first password module is any password module of any server, and the second password module is another password module configured on a different server, and the method includes:
[0019] The first cryptographic module obtains key configuration information sent by the password management device, where the key configuration information at least includes a key for executing a cryptographic service;
[0020] The first cryptographic module sends a first key image to the password management device, so that the password management device forwards the first key image to the second cryptographic module, wherein the first key image includes the key;
[0021] The second cryptographic module obtains the first key image, and obtains the key according to the first key image, so as to perform cryptographic operations using the key when being called by the corresponding server.
[0022] Optionally, the cryptographic module includes a shared key;
[0023] The first key image sent by the first cryptographic module to the password management device is specifically obtained by encrypting the corresponding key image using the shared key by the first cryptographic module;
[0024] The second cryptographic module obtains the key according to the first key image, including:
[0025] The second cryptographic module decrypts the first key image using the shared key to obtain the key image corresponding to the first cryptographic module;
[0026] The second cryptographic module obtains the key according to the key image corresponding to the first cryptographic module.
[0027] Optionally, the cryptographic module includes an asymmetric encryption key pair and a signature public key obtained from an external certificate authority, and the first asymmetric encryption key pair of the first cryptographic module is different from the second asymmetric encryption key pair of the second cryptographic module;
[0028] Before the first cryptographic module sends the first key image to the password management device, the method further includes:
[0029] The first cryptographic module obtains, from the password management device, a public key certificate of the second cryptographic module signed by an external certificate authority, where the public key certificate of the second cryptographic module includes the second public key in the second asymmetric encryption key pair;
[0030] The first cryptographic module verifies the legitimacy of the public key certificate of the second cryptographic module using the signature public key obtained from an external certificate authority;
[0031] If it is legal, the first cryptographic module obtains the second public key in the second asymmetric encryption key pair, and uses the second public key to encrypt the corresponding key image to obtain the first key image.
[0032] Optionally, the second cryptographic module obtains the first key image, and obtains the key according to the first key image, including:
[0033] The second cryptographic module obtains the first key image;
[0034] The second cryptographic module uses the second private key in the second asymmetric encryption key pair to decrypt the first key image to obtain the key image corresponding to the first cryptographic module;
[0035] The second cryptographic module obtains the key according to the key image corresponding to the first cryptographic module.
[0036] In a third aspect, an embodiment of the present disclosure provides a cryptographic service method, which is applied to a cryptographic module of a server, and the method includes:
[0037] Obtaining a cryptographic service request from a cryptographic application, where the cryptographic application and the cryptographic module are located on the same server;
[0038] According to the cryptographic service request, the key configured by the cryptographic configuration method described in the first aspect and / or the second aspect is called to perform cryptographic operations to provide cryptographic services for the cryptographic application.
[0039] In a fourth aspect, an embodiment of the present disclosure provides a password management device, comprising at least one memory and at least one processor, wherein the memory stores one or more computer-executable instructions, and the processor calls the one or more computer-executable instructions to execute the password configuration method as described in the first aspect above.
[0040] In a fifth aspect, an embodiment of the present disclosure provides a server comprising at least one memory and at least one processor, wherein the memory stores one or more computer-executable instructions, and the processor calls the one or more computer-executable instructions to execute the password configuration method as described in the second aspect above, or the password service method as described in the third aspect above.
[0041] In a sixth aspect, an embodiment of the present disclosure provides a cryptographic service system, comprising at least a cryptographic management device and multiple servers, each of the servers comprising at least a cryptographic module and a cryptographic application, the cryptographic management device being configured to manage the cryptographic modules of the multiple servers;
[0042] Wherein, the password module includes:
[0043] A request obtaining unit, configured to obtain a cryptographic service request from a cryptographic application;
[0044] The cryptographic operation unit is used to call a key to perform cryptographic operation according to the cryptographic service request to provide cryptographic service for the cryptographic application, and the key is obtained based on the configuration of the cryptographic management device.
[0045] Optionally, the password management device includes:
[0046] a configuration information sending unit, configured to send key configuration information to a first cryptographic module, wherein the key configuration information includes at least a key for the first cryptographic module to perform a cryptographic service, and the first cryptographic module is any cryptographic module of any server;
[0047] an image obtaining unit, configured to obtain a first key image of the first cryptographic module, where the first key image includes the key;
[0048] The mirror forwarding unit is used to forward the first key image to a second cryptographic module so that the second cryptographic module obtains the key and uses the key to perform cryptographic operations when the second cryptographic module is called by the corresponding server. The second cryptographic module is another cryptographic module configured on a different server.
[0049] Optionally, the password module further includes: a first password module and a second password module;
[0050] The first cryptographic module is configured to obtain key configuration information sent by the password management device, the key configuration information including at least a key for performing a cryptographic service; and send a first key image to the password management device, so that the password management device forwards the first key image to the second cryptographic module, wherein the first key image includes the key;
[0051] The second cryptographic module is configured to obtain the first key image and, based on the first key image, obtain the key, so as to perform cryptographic operations using the key when called by the corresponding server.
[0052] Optionally, the cryptographic module is configured with a signature public key, and the signature public key is obtained based on a key file configuration of an external certificate authority.
[0053] In the seventh aspect, an embodiment of the present disclosure provides a storage medium, which stores one or more computer-executable instructions. When the one or more computer-executable instructions are executed, the password configuration method as described in the first aspect above, or the password configuration method as described in the second aspect above, or the password service method as described in the third aspect above is implemented.
[0054] The password configuration method provided by the embodiment of the present disclosure is applied to a password management device that manages password modules of multiple servers. The password management device sends key configuration information to a first password module, where the key configuration information includes at least a key for the first password module to perform password services. The first password module is any password module of any server. Then, a first key image of the first password module is obtained, where the first key image includes the key. The first key image is forwarded to a second password module so that the second password module obtains the key, so that when the second password module is called by the corresponding server, the key is used to perform password services. The second password module is another password module configured on a different server.
[0055] It can be seen that in the embodiment of the present disclosure, when the password management device configures the password module of any server to perform a cryptographic operation, the key image containing the key is forwarded by the password management device to the password modules of different servers, so that the password modules on multiple servers are configured with keys, thereby realizing key synchronization of the password modules on different servers; furthermore, each server can perform cryptographic operations based on the cryptographic module configured with the key to obtain cryptographic services. Compared with the method in which multiple servers obtain cryptographic services by accessing the cryptographic machine through the network, the multiple servers in the embodiment of the present disclosure can no longer rely on the network when obtaining cryptographic services, thereby effectively reducing the occupation of network bandwidth resources and improving the performance of cryptographic services. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are merely embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.
[0057] Figure 1 is an optional schematic diagram of a cluster system;
[0058] FIG2 is a schematic diagram of the architecture of a cryptographic service system provided by an embodiment of the present disclosure;
[0059] FIG3 is an interactive flow chart of a password configuration method provided by an embodiment of the present disclosure;
[0060] FIG4 is a schematic diagram of an optional flow chart of a password configuration method provided in an embodiment of the present disclosure;
[0061] FIG5 is another optional flow diagram of the password configuration method provided in an embodiment of the present disclosure;
[0062] FIG6 is another interactive flow chart of the password configuration method provided by an embodiment of the present disclosure;
[0063] FIG7 is a schematic diagram of an optional flow chart of a cryptographic service method provided in an embodiment of the present disclosure;
[0064] FIG8 is an optional block diagram of a password management device provided in an embodiment of the present disclosure;
[0065] FIG9 is a schematic diagram of an optional structure of a password module provided in an embodiment of the present disclosure; and
[0066] FIG10 is a schematic diagram of an optional structure of a password management device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0067] The following will be combined with the accompanying drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of the present disclosure.
[0068] As described in the background technology, in addition to being applied to cryptographic operations on specific physical devices such as cryptographic machines, the cryptographic application model can also be used in parallel cluster systems composed of a large number of devices, such as cloud computing. A large number of servers and virtual machines running on the servers form a cluster to form a large computing resource. Each server runs the same or similar services and performs the same or similar cryptographic operations.
[0069] A parallel cluster system (hereinafter referred to as a cluster system) consisting of a large number of devices is typically connected via a high-speed communication network. Therefore, to meet the cryptographic computing needs of each device in the cluster system, a centralized cryptographic service can be adopted. For a specific type of cryptographic service, a certain number of cryptographic machines are deployed in the cluster system to centrally store and manage the passwords of all servers in the system. By connecting the cryptographic machines to the cluster network, servers in the cluster can access the services provided by the cryptographic machines over the network.
[0070] FIG1 shows an alternative schematic diagram of a cluster system 100 . Cluster system 100 includes multiple servers 101 and cryptographic machines 102 , which communicate with each other via a network. The multiple servers 101 shown in FIG1 each require a specific type of cryptographic service, and the multiple cryptographic machines 102 each have the same configuration for the type of cryptographic service provided by servers 101 and are capable of providing the same target type of cryptographic service.
[0071] However, the inventors discovered that when a server sends data to be processed via the network to a cryptographic machine, and the cryptographic machine performs cryptographic operations on the data and then returns it to the server via the network, a large amount of data movement occurs when all servers in a cluster system access the cryptographic machine through the network to perform cryptographic operations. This consumes a significant amount of network bandwidth and impacts the normal operation of the network. Furthermore, when multiple servers simultaneously use the network to perform services, the unstable network bandwidth can also reduce the cryptographic service performance of the cryptographic machine. Furthermore, the cost of cryptographic machines is relatively high, and specialized cryptographic machines designed specifically for a particular type of cryptographic service are even more expensive, significantly increasing the research and development costs of the cluster system.
[0072] It can be seen that when a parallel cluster system composed of a large number of devices has cryptographic operation requirements, how to meet the cryptographic operation requirements of each device in the parallel cluster system and improve the cryptographic operation performance of the system is particularly important. Based on this, the embodiment of the present disclosure adopts an improved technical solution, which configures the cryptographic module of any server through a cryptographic management device to perform cryptographic operations, and then forwards the key image containing the key to the cryptographic modules of different servers, so that the cryptographic modules on multiple servers are configured with keys, and the key synchronization of the cryptographic modules on different servers is achieved. Then, each server can perform cryptographic operations based on the cryptographic modules configured with keys and obtain cryptographic services. Compared with the method of multiple servers accessing cryptographic machines through the network to obtain cryptographic services, the multiple servers in the embodiment of the present disclosure can no longer rely on the network when obtaining cryptographic services, thereby effectively reducing the occupation of network bandwidth resources and improving the performance of cryptographic services.
[0073] Based on the above ideas, Figure 2 exemplarily shows a schematic diagram of the architecture of the cryptographic service system provided by an embodiment of the present disclosure. As shown in Figure 2 , the cryptographic service system at least includes: multiple servers 20 and a cryptographic management terminal (CMT) 21.
[0074] Server 20 refers to a dedicated computer that provides services to users in a network environment. It is installed with a network operating system and various application software, such as cryptographic applications. The server can run relevant cryptographic applications according to business needs. Specifically, server 20 is equipped with a cryptographic module (CM) 201. This module performs cryptographic operations and stores the keys corresponding to the cryptographic services performed by the server's cryptographic applications. When the server's cryptographic applications call the cryptographic module based on a dedicated interface, the stored keys are used to perform cryptographic operations. In Figure 2, multiple servers 20 are running in the same network environment, and this operating system can be referred to as a parallel cluster system.
[0075] The password management device 21 is used to manage the password modules 201 of multiple servers 20, can create or modify the keys stored in the password modules 201, and support key synchronization between different password modules 201 by forwarding key images.
[0076] It should be noted that the cryptographic modules in the disclosed embodiments can store all keys, and to ensure that each cryptographic module can provide consistent cryptographic services, key information must be synchronized between different cryptographic modules. Therefore, by managing cryptographic modules on multiple servers through a password management device, key synchronization can be achieved across different cryptographic modules, improving cryptographic service performance.
[0077] The following describes in detail the password configuration scheme of the embodiment of the present disclosure based on the above-mentioned password service system architecture.
[0078] FIG3 exemplarily illustrates an interactive flow chart of a password configuration method provided by an embodiment of the present disclosure. This method flow can be implemented by the password module and password management device of a server in the password service system shown in FIG2 . The password module may include a first password module and a second password module. The first password module is any password module of any server, and the second password module is another password module configured on a different server. As shown in FIG3 , the method flow may include the following steps.
[0079] Step S31: The password management device sends key configuration information to the first password module.
[0080] When a password management device manages cryptographic modules on multiple servers, the password management device may send key configuration information to a first cryptographic module. The key configuration information may be information for configuring the key corresponding to the cryptographic module. Furthermore, when the password management device has permission to create or modify keys stored in the cryptographic module, the key configuration information may include at least the key used by the first cryptographic module to perform cryptographic services. This key may be a newly created key or a modified key.
[0081] It should be noted that, in the embodiment of the present disclosure, step S31 may be implemented when there is a demand for execution of the cryptographic module, such as when the system is powered on or when the cryptographic module of the corresponding server in the system is started.
[0082] Step S32: The first password module obtains key configuration information sent by the password management device.
[0083] Step S33: The first cryptographic module sends the first key image to the password management device.
[0084] It is understood that cryptographic modules typically store cryptographic algorithms and keys in an image file within the module. When the cryptographic module is activated, it loads the image file and executes the corresponding cryptographic algorithm and key operations. Therefore, after receiving the key configuration information sent by the password management device, the first cryptographic module can update its corresponding key image based on the key configuration information. The cryptographic module's key image is a copy of the key required for cryptographic operations, containing a mirrored version of all keys stored by the cryptographic module. This key image can be a binary code file or a data file. The use of a key image protects the security and confidentiality of key information, preventing unauthorized access and attacks.
[0085] Furthermore, to synchronize keys across different cryptographic modules, after a first cryptographic module obtains key configuration information from a password management device, it can send a first key image to the password management device. The first key image can include the key used by the first cryptographic module to perform cryptographic services. Furthermore, to ensure key security within the cryptographic modules, as an optional implementation, the first key image can be an encrypted image file of the key image corresponding to the first cryptographic module.
[0086] It should be noted that the first cryptographic module sends the first key image to the password management device, which can be executed when the password management device calls the information export interface corresponding to the first cryptographic module.
[0087] Step S34: The password management device obtains the first key image of the first password module.
[0088] Step S35: The password management device forwards the first key image to the second password module.
[0089] It can be understood that in order to synchronize keys between different cryptographic modules, the cryptographic management device can forward the first key image to the second cryptographic module after obtaining the first key image of the first cryptographic module, so that the second cryptographic module can obtain the key of the first cryptographic module to perform cryptographic services, so that when the second cryptographic module is called by the corresponding server, the key can be used to perform cryptographic operations.
[0090] It should be noted that the password management device forwards the first key image to the second password module by calling the information import interface of the second password module.
[0091] Step S36: The second cryptographic module obtains the first key image, and obtains the key according to the first key image.
[0092] If the first key image contains the key used by the first cryptographic module to perform cryptographic services, the second cryptographic module, after obtaining the first key image forwarded by the password management module, can obtain the key based on the first key image. Furthermore, when invoked by the corresponding server, the second cryptographic module can perform cryptographic operations using the key, enabling the server to obtain cryptographic services.
[0093] It can be seen that in the embodiment of the present disclosure, when the password management device configures the password module of any server to perform a cryptographic operation, the key image containing the key is forwarded by the password management device to the password modules of different servers, so that the password modules on multiple servers are configured with keys, thereby realizing key synchronization of the password modules on different servers; furthermore, each server can perform cryptographic operations based on the cryptographic module configured with the key to obtain cryptographic services. Compared with the method in which multiple servers obtain cryptographic services by accessing the cryptographic machine through the network, the multiple servers in the embodiment of the present disclosure can no longer rely on the network when obtaining cryptographic services, thereby effectively reducing the occupation of network bandwidth resources and improving the performance of cryptographic services.
[0094] In some embodiments, to ensure the security of the key image forwarded by the password management device, the first key image may be obtained by encrypting the key image of the first password module, that is, the first key image is the ciphertext of the key image corresponding to the first password module.
[0095] As an optional implementation, the key used by the first cryptographic module to encrypt the key image may be a shared key (SK). FIG4 exemplarily shows an optional flow chart of the password configuration method in the embodiment of the present disclosure. As shown in FIG4 , the first cryptographic module and the second cryptographic module include a shared key. The first cryptographic module uses the shared key to encrypt its corresponding key image to obtain a first key image. When the password management device calls the export interface of the first cryptographic module, the first cryptographic module exports the first key image to the password management device; when the password management device calls the import interface of the second cryptographic module, the password management device imports the first key image into the second cryptographic module. After the second cryptographic module obtains the first key image imported by the password management device, the second cryptographic module can use the shared key to decrypt the first key image, thereby obtaining the key image corresponding to the first cryptographic module, and then obtaining the key according to the key image corresponding to the first cryptographic module.
[0096] It should be noted that the shared key of the cryptographic module may be set by the manufacturer when manufacturing the server. Therefore, a shared key may exist in multiple cryptographic modules from the same manufacturer.
[0097] As another optional implementation, the cryptographic module may include an asymmetric encryption key pair (public key and private key), and the asymmetric encryption key pair of each cryptographic module may be different. Therefore, the key used to encrypt the key image of the first cryptographic module may be the public key in the asymmetric encryption key pair of the second cryptographic module. FIG. 5 exemplarily shows another optional flow chart of the cryptographic configuration method provided by an embodiment of the present disclosure. As shown in FIG. 5 , the second cryptographic module includes an asymmetric encryption key pair (the public key is shown as PbEK2 and the private key is shown as PvEK2 in the figure), and the first cryptographic module is configured with a signature public key (shown as PbSK in the figure). The signature public key can be obtained based on the key file configuration of an external certificate authority. Specifically, the external certificate authority (CA) has an asymmetric signature key pair (the public key is shown as PbSK and the private key is shown as PvSK in the figure). Based on this, the external certificate authority can issue a public key certificate for the public key in the asymmetric encryption key pair of the verified cryptographic module, which can be used by another cryptographic module to verify the legitimacy of the cryptographic module to ensure the transmission security of the key image.
[0098] It should be noted that any cryptographic module of any server in the embodiments of the present disclosure may include an asymmetric encryption key pair and a signature public key obtained from an external certificate authority. FIG5 shows only the signature public key PbSK in the first cryptographic module, and the asymmetric encryption key pair (public key PbEK2 and private key PvEK2) in the second cryptographic module. The private key PvEK in the asymmetric encryption key pair of the cryptographic module is always located inside the cryptographic module and cannot be read from the outside. The public key PbEK can be read from the outside, while the signature public key PbSK of the external certificate authority cannot be tampered with from the outside.
[0099] In order to enable the first cryptographic module to verify the legitimacy of the second cryptographic module, the public key PbEK2 in the second asymmetric encryption key pair of the second cryptographic module can be issued with a public key certificate PbEKCert (shown as PbEKCert2 in the figure) by an external certificate authority. The PbEKCert certificate can include the public key PbEK2 of the second cryptographic module, and the external certificate authority can use the signature private key PvSK to sign the public key certificate of the second cryptographic module, so that the first cryptographic module can confirm the authenticity and integrity of the public key certificate of the second cryptographic module, thereby verifying that it is a legal public key certificate.
[0100] Corresponding to Figure 5, Figure 6 exemplarily shows another interactive flow chart of the password configuration method in the embodiment of the present disclosure. As shown in Figure 6, before step S33, it also includes:
[0101] Step S321: The password management device obtains the public key certificate of the second password module signed by an external certificate authority.
[0102] The public key certificate of the second cryptographic module may include the second public key in the second asymmetric encryption key pair.
[0103] Step S322: The password management device forwards the public key certificate of the second password module signed by the external certificate authority to the first password module.
[0104] Thus, the first cryptographic module can verify the legitimacy of the public key certificate of the second cryptographic module using the signature public key obtained from the external certificate authority.
[0105] Step S323: The first cryptographic module obtains the public key certificate of the second cryptographic module signed by an external certificate authority.
[0106] In step S324, the first cryptographic module verifies the validity of the public key certificate of the second cryptographic module using the signature public key obtained from the external certificate authority.
[0107] In a specific example, the first cryptographic module can verify the signature of the second cryptographic module's public key certificate PbEKCert2 using the signature public key PbSK obtained from an external certificate authority. If the verification succeeds, it can be confirmed that the second cryptographic module's public key certificate is authentic and complete, and the second cryptographic module's public key certificate is legal, and step S325 is then executed.
[0108] In step S325 , the first cryptographic module obtains the second public key in the second asymmetric encryption key pair, and uses the second public key to encrypt the corresponding key image to obtain the first key image.
[0109] Further, in some embodiments, based on the first key image, the first cryptographic module encrypts the corresponding key image using the second public key of the second cryptographic module. As shown in FIG6 , the second cryptographic module obtains the first key image, and the process of obtaining the key according to the first key image may specifically include:
[0110] Step S361: The second cryptographic module obtains the first key image;
[0111] Step S362: The second cryptographic module uses the second private key in the second asymmetric encryption key pair to decrypt the first key image and obtain the key image corresponding to the first cryptographic module;
[0112] Step S363: The second cryptographic module obtains the key according to the key image corresponding to the first cryptographic module.
[0113] It can be seen that in the embodiment of the present disclosure, when the password management device configures the password module of any server to perform a cryptographic operation, the key image containing the key is forwarded by the password management device to the password modules of different servers, so that the password modules on multiple servers are configured with keys, thereby realizing key synchronization of the password modules on different servers; furthermore, each server can perform cryptographic operations based on the cryptographic module configured with the key to obtain cryptographic services. Compared with the method in which multiple servers obtain cryptographic services by accessing the cryptographic machine through the network, the multiple servers in the embodiment of the present disclosure can no longer rely on the network when obtaining cryptographic services, thereby effectively reducing the occupation of network bandwidth resources and improving the performance of cryptographic services.
[0114] The present disclosure also provides a cryptographic service method, which is based on the cryptographic service system architecture shown in FIG2 and is applied to the cryptographic module 201 of the server 20. As an optional implementation, FIG7 exemplarily shows an optional flow chart of the cryptographic service method provided by the present disclosure. As shown in FIG7 , the cryptographic service method includes the following steps:
[0115] Step S71: Obtain a cryptographic service request from a cryptographic application.
[0116] The cryptographic application is located on the same server as the cryptographic module, so that inside the server, the cryptographic application can send the cryptographic service request directly to the cryptographic module without transmitting it to the outside through the network, so that the cryptographic module obtains the cryptographic service request of the cryptographic application.
[0117] Step S72: Based on the cryptographic service request, a key is called to perform cryptographic operations to provide cryptographic services for the cryptographic application.
[0118] The key used by the password module is configured using the password configuration method described above.
[0119] It can be seen that in the cryptographic service method of the embodiment of the present disclosure, when the cryptographic application of the server has a cryptographic service demand, it can be based on accessing the cryptographic module so that the cryptographic module uses the configured key to perform cryptographic operations, thereby achieving access to the cryptographic service without transmitting the cryptographic service request to the outside through the network, so that the cryptographic application accesses the cryptographic service no longer depends on the network, effectively reducing the occupation of network bandwidth resources and improving the performance of the cryptographic service.
[0120] An embodiment of the present disclosure also provides a password management device. As an optional implementation, Figure 8 is an optional block diagram of the password management device provided by an embodiment of the present disclosure. As shown in Figure 8, the password management device may include: at least one processor 1, at least one communication interface 2, at least one memory 3 and at least one communication bus 4.
[0121] In the embodiment of the present disclosure, there is at least one processor 1 , communication interface 2 , memory 3 , and communication bus 4 , and the processor 1 , communication interface 2 , and memory 3 communicate with each other through the communication bus 4 .
[0122] Optionally, the communication interface 2 may be an interface of a communication module for performing network communication.
[0123] Optionally, processor 1 may be a CPU (central processing unit), a GPU (Graphics Processing Unit), an NPU (embedded neural network processor), an FPGA (Field Programmable Gate Array), a TPU (tensor processing unit), an AI chip, an application-specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present disclosure.
[0124] The memory 3 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.
[0125] The memory 3 stores one or more computer-executable instructions, and the processor 1 calls the one or more computer-executable instructions to execute the password configuration method as described above.
[0126] An embodiment of the present disclosure also provides a server, which may correspond to that shown in reference Figure 8. The server may include: at least one memory and at least one processor, the memory storing one or more computer-executable instructions, the processor calling the one or more computer-executable instructions to execute the password configuration method as described above, or the password service method as described above.
[0127] The present disclosure also provides a cryptographic service system. As shown in FIG2 above, the cryptographic service system may include at least a cryptographic management device and multiple servers. Each of the multiple servers may include at least a cryptographic module and a cryptographic application (not shown in the figure), and the cryptographic management device may be used to manage the cryptographic modules of the multiple servers.
[0128] FIG9 exemplarily shows an optional structural diagram of a password module provided in an embodiment of the present disclosure. As shown in FIG9 , the password module may include:
[0129] A request obtaining unit 91 is used to obtain a cryptographic service request of a cryptographic application;
[0130] The cryptographic operation unit 92 is configured to call a key to perform cryptographic operation according to the cryptographic service request to provide cryptographic services for the cryptographic application, wherein the key is obtained based on the configuration of the cryptographic management device.
[0131] In some embodiments, based on the feature that the password management device has the ability to manage password modules of multiple servers, FIG10 exemplarily shows an optional structural diagram of the password management device provided in an embodiment of the present disclosure. As shown in FIG10 , the password management device may include:
[0132] The configuration information sending unit 110 is configured to send key configuration information to a first cryptographic module, wherein the key configuration information includes at least a key for the first cryptographic module to perform cryptographic services. The first cryptographic module may be any cryptographic module of any server.
[0133] An image acquisition unit 120 is configured to acquire a first key image of the first cryptographic module, where the first key image includes the key;
[0134] The image forwarding unit 130 is configured to forward the first key image to a second cryptographic module so that the second cryptographic module obtains the key and uses the key to perform cryptographic operations when the second cryptographic module is called by the corresponding server. The second cryptographic module is another cryptographic module configured on a different server.
[0135] Optionally, the password modules of the multiple servers managed by the password management device may include a shared key;
[0136] The first key image of the first cryptographic module obtained by the image obtaining unit 120 may be obtained by: the first cryptographic module encrypting the corresponding key image using the shared key;
[0137] The image forwarding unit 130 forwards the first key image to the second cryptographic module so that the second cryptographic module obtains the key. Specifically, the first key image is forwarded to the second cryptographic module so that the second cryptographic module decrypts the first key image using the shared key to obtain the key image corresponding to the first cryptographic module, and obtains the key based on the key image corresponding to the first cryptographic module.
[0138] Optionally, the cryptographic modules of the multiple servers managed by the cryptographic management device may include an asymmetric encryption key pair and a signature public key obtained from an external certificate authority, and the first asymmetric encryption key pair of the first cryptographic module is different from the second asymmetric encryption key pair of the second cryptographic module;
[0139] Before the image obtaining unit 120 obtains the first key image of the first cryptographic module, the following steps may also be included:
[0140] Obtaining a public key certificate of the second cryptographic module signed by an external certificate authority, where the public key certificate of the second cryptographic module includes the second public key in the second asymmetric encryption key pair;
[0141] The public key certificate of the second cryptographic module signed by the external certificate authority is forwarded to the first cryptographic module, so that the first cryptographic module verifies the legitimacy of the public key certificate of the second cryptographic module using the signature public key obtained from the external certificate authority.
[0142] In some embodiments, based on the characteristic that the password module is managed by a password management device, the password module of the embodiment of the present disclosure may also include: a first password module and a second password module; the first password module can be any password module of any server, and the second password module is another password module different from the first password module and configured on a different server.
[0143] The first cryptographic module is configured to obtain key configuration information sent by the password management device, the key configuration information including at least a key for performing a cryptographic service; and send a first key image to the password management device, so that the password management device forwards the first key image to the second cryptographic module, wherein the first key image includes the key;
[0144] The second cryptographic module is configured to obtain the first key image and, based on the first key image, obtain the key, so as to perform cryptographic operations using the key when called by the corresponding server.
[0145] Optionally, the cryptographic module may include a shared key;
[0146] The first key image sent by the first cryptographic module to the password management device may be specifically obtained by: the first cryptographic module encrypting the corresponding key image using the shared key;
[0147] The second cryptographic module obtaining the key according to the first key image may include:
[0148] The second cryptographic module decrypts the first key image using the shared key to obtain the key image corresponding to the first cryptographic module;
[0149] The second cryptographic module obtains the key according to the key image corresponding to the first cryptographic module.
[0150] Optionally, the cryptographic module may include an asymmetric encryption key pair and a signature public key obtained from an external certificate authority, and the first asymmetric encryption key pair of the first cryptographic module is different from the second asymmetric encryption key pair of the second cryptographic module;
[0151] Before the first cryptographic module sends the first key image to the password management device, the method may further include:
[0152] The first cryptographic module obtains, from the password management device, a public key certificate of the second cryptographic module signed by an external certificate authority, where the public key certificate of the second cryptographic module includes the second public key in the second asymmetric encryption key pair;
[0153] The first cryptographic module verifies the legitimacy of the public key certificate of the second cryptographic module using the signature public key obtained from an external certificate authority;
[0154] If it is legal, the first cryptographic module obtains the second public key in the second asymmetric encryption key pair, and uses the second public key to encrypt the corresponding key image to obtain the first key image.
[0155] Optionally, the step of the second cryptographic module obtaining the first key image and obtaining the key according to the first key image may include:
[0156] The second cryptographic module obtains the first key image;
[0157] The second cryptographic module uses the second private key in the second asymmetric encryption key pair to decrypt the first key image to obtain the key image corresponding to the first cryptographic module;
[0158] The second cryptographic module obtains the key according to the key image corresponding to the first cryptographic module.
[0159] In some embodiments, the cryptographic module may be configured with a signature public key, and the signature public key may be configured based on a key file of an external certificate authority.
[0160] An embodiment of the present disclosure also provides a storage medium, which stores one or more computer-executable instructions. When the one or more computer-executable instructions are executed, the password configuration method executed by the password management device in the embodiment of the present disclosure, or the password configuration method executed by the password module of the server, or the password service method executed by the password module of the server is implemented.
[0161] The above describes multiple embodiment schemes provided by the embodiments of the present disclosure. The various optional methods introduced in each embodiment scheme can be combined and cross-referenced with each other without conflict, thereby extending a variety of possible embodiment schemes, which can all be considered as embodiment schemes disclosed and disclosed by the embodiments of the present disclosure.
[0162] Although the embodiments of the present disclosure are disclosed above, the present disclosure is not limited thereto. Any person skilled in the art may make various changes and modifications without departing from the spirit and scope of the present disclosure. Therefore, the scope of protection of the present disclosure shall be based on the scope defined by the claims.
Claims
1. A password configuration method, applied to a password management device, wherein: The password management device is used to manage password modules of multiple servers, and the password configuration method includes: Sending key configuration information to a first cryptographic module, the key configuration information at least including a key for the first cryptographic module to perform a cryptographic service, the first cryptographic module being any cryptographic module of any server; Obtaining a first key image of the first cryptographic module, where the first key image includes the key; The first key image is forwarded to a second cryptographic module so that the second cryptographic module obtains the key and uses the key to perform cryptographic operations when the second cryptographic module is called by a corresponding server. The second cryptographic module is another cryptographic module configured on a different server.
2. The password configuration method according to claim 1, wherein: The password modules of the multiple servers managed by the password management device include a shared key; Acquiring a first key image of the first cryptographic module, including: the first cryptographic module encrypts the corresponding key image using the shared key; The forwarding the first key image to the second cryptographic module so that the second cryptographic module obtains the key includes: forwarding the first key image to the second cryptographic module so that the second cryptographic module decrypts the first key image using the shared key, obtains the key image corresponding to the first cryptographic module, and obtains the key according to the key image corresponding to the first cryptographic module.
3. The password configuration method according to claim 1, wherein: The cryptographic modules of the multiple servers managed by the cryptographic management device include an asymmetric encryption key pair and a signature public key obtained from an external certificate authority, and the first asymmetric encryption key pair of the first cryptographic module is different from the second asymmetric encryption key pair of the second cryptographic module; Before obtaining the first key image of the first cryptographic module, the password configuration method further includes: Obtaining a public key certificate of the second cryptographic module signed by an external certificate authority, wherein the public key certificate of the second cryptographic module includes the second public key in the second asymmetric encryption key pair; Forward the public key certificate of the second cryptographic module signed by the external certificate authority to the first cryptographic module, so that the first cryptographic module verifies the legitimacy of the public key certificate of the second cryptographic module by using the signature public key obtained from an external certificate authority.
4. A password configuration method, applied to a password module of a server, wherein: The password module includes a first password module and a second password module, the first password module is any password module of any server, the second password module is another password module configured on a different server, and the password configuration method includes: The first cryptographic module obtains key configuration information sent by the cryptographic management device, wherein the key configuration information at least includes a key for executing a cryptographic service; The first cryptographic module sends a first key image to the password management device, so that the password management device forwards the first key image to the second cryptographic module, wherein the first key image includes the key; The second cryptographic module obtains the first key image, and obtains the key according to the first key image, so as to perform cryptographic operations using the key when being called by the corresponding server.
5. The password configuration method according to claim 4, wherein: The cryptographic module includes a shared key; The first cryptographic module sends a first key image to the password management device, including: the first cryptographic module encrypts the corresponding key image using a shared key; The second cryptographic module obtains the key according to the first key image, including: The second cryptographic module decrypts the first key image using the shared key to obtain the key image corresponding to the first cryptographic module; and The second cryptographic module obtains the key according to the key image corresponding to the first cryptographic module.
6. The password configuration method according to claim 4, wherein: The cryptographic module includes an asymmetric encryption key pair and a signature public key obtained from an external certificate authority, and a first asymmetric encryption key pair of the first cryptographic module is different from a second asymmetric encryption key pair of the second cryptographic module; Before the first password module sends the first key image to the password management device, the password configuration method further includes: The first cryptographic module obtains the public key certificate of the second cryptographic module sent by the cryptographic management device and signed by an external certificate authority, wherein the public key certificate of the second cryptographic module includes a second public key in the second asymmetric encryption key pair; The first cryptographic module verifies the legitimacy of the public key certificate of the second cryptographic module using the signature public key obtained from an external certificate authority; and If it is legal, the first cryptographic module obtains the second public key in the second asymmetric encryption key pair, and uses the second public key to encrypt the corresponding key image to obtain the first key image.
7. The password configuration method according to claim 6, wherein: The second cryptographic module obtains the first key image, and obtains the key according to the first key image, including: The second cryptographic module obtains the first key image; The second cryptographic module uses the second private key in the second asymmetric encryption key pair to decrypt the first key image to obtain the key image corresponding to the first cryptographic module; and The second cryptographic module obtains the key according to the key image corresponding to the first cryptographic module.
8. A password service method, applied to a password module of a server, the password service method comprising: Obtaining a cryptographic service request of a cryptographic application, wherein the cryptographic application and the cryptographic module are located on the same server; as well as According to the cryptographic service request, a key is called to perform a cryptographic operation to provide cryptographic services for the cryptographic application, and the key is configured using the cryptographic configuration method as described in any one of claims 1-3 and / or claims 4-7.
9. A password management device, comprising at least one memory and at least one processor, wherein: The memory stores one or more computer executable instructions, and the processor calls the one or more computer executable instructions to execute the password configuration method according to any one of claims 1-3.
10. A server comprising at least one memory and at least one processor, wherein: The memory stores one or more computer executable instructions, and the processor calls the one or more computer executable instructions to execute the password configuration method as described in any one of claims 4 to 7, or the password service method as described in claim 8.
11. A password service system, comprising at least a password management device and a plurality of servers, wherein: Each of the plurality of servers comprises at least a cryptographic module and a cryptographic application, and the cryptographic management device is configured to manage the cryptographic modules of the plurality of servers; Wherein, the password module includes: a request obtaining unit configured to obtain a cryptographic service request of a cryptographic application; The cryptographic operation unit is configured to call a key to perform cryptographic operation according to the cryptographic service request to provide cryptographic service for the cryptographic application, wherein the key is obtained based on the configuration of the cryptographic management device.
12. The cryptographic service system according to claim 11, wherein: The password management device comprises: a configuration information sending unit, configured to send key configuration information to a first cryptographic module, wherein the key configuration information at least includes a key for the first cryptographic module to perform a cryptographic service, and the first cryptographic module is any cryptographic module of any server; an image acquisition unit, configured to acquire a first key image of the first cryptographic module, wherein the first key image includes the key; The mirror forwarding unit is configured to forward the first key mirror to a second cryptographic module so that the second cryptographic module obtains the key and uses the key to perform cryptographic operations when the second cryptographic module is called by a corresponding server, wherein the second cryptographic module is another cryptographic module configured on a different server.
13. The cryptographic service system according to claim 12, wherein: The password module also includes the first password module and the second password module; The first cryptographic module is configured to obtain key configuration information sent by the password management device, wherein the key configuration information at least includes a key for executing a cryptographic service; and, sending a first key image to the password management device, so that the password management device forwards the first key image to the second password module, wherein the first key image includes the key; The second cryptographic module is configured to obtain the first key image, and obtain the key according to the first key image, so as to perform cryptographic operations using the key when called by the corresponding server.
14. The cryptographic service system according to claim 13, wherein: The cryptographic module is configured with a signature public key, and the signature public key is obtained based on a key file configuration of an external certificate authority.
15. A storage medium storing one or more computer executable instructions, wherein: When the one or more computer executable instructions are executed, the password configuration method as described in any one of claims 1 to 3, or the password configuration method as described in any one of claims 4 to 7, or the password service method as described in claim 8 is implemented.
Citation Information
Patent Citations
Password configuration method, password service method and related equipment
CN117560147A
Secret key updating method and device based on server cluster, equipment and medium
CN115883087A
Recovering cryptographic key
EP4174703A1
Method and system for automatically migrating encryption keys between key managers in a network storage system
US8266433B1
Cryptographic key distribution
US9660970B1