The invention discloses a remote key
security management method and device for a cloud
virtualization cryptographic module, and aims to solve the problems of cloud key trust root,
transmission security and the like. The core of the method is to keep the
master key control right of a user locally, and through
cooperative work of a local
client, a
cloud management platform and a distributed vHSM instance, through the four steps of
system initialization and key fragmentation distribution, remote certification and
secure channel establishment, distributed cooperative operation and local result synthesis, and by utilizing IBE, Shamir
secret sharing, a threshold cryptographic
algorithm and TEE technologies, the user
master key control right and the distributed vHSM instance are subjected to remote certification and
secure channel establishment, distributed cooperative operation and local result synthesis. And the key is available and invisible. The device comprises three modules, namely a local
client, a
cloud management platform and a vHSM cluster. The method guarantees secret key
confidentiality and completeness, supports a national secret
algorithm, meets compliance requirements, adapts to cloud native elasticity requirements, and is suitable for cloud secret
key management in industries such as
electric power and the like.