Information synchronization system and method for group of cipher machines
Abstract
The invention relates to an information synchronization system and method for a group of cipher machines. According to the system, the group comprises at least two cipher machines, and group cooperation modules are arranged in the cipher machines respectively, used for achieving synchronous instruction monitoring, synchronous information push and synchronous information receiving among the cipher machines, and further used for carrying out identity verification and information verification on the cipher machines pushing synchronous information for the cipher machines receiving the synchronous information. The theory of the information synchronization method is the same as the theory of the system. According to the information synchronization system and method, by synchronizing the information in the cipher machines automatically, the development cost needed when application interfaces and service systems of the cipher machines process similar services can be effectively reduced; besides, the real-time synchronization method improves the timeliness of synchronization of the cipher machines greatly.
Term
No projected expiry on record.
- Priority and filed
- Published
- Today
10 claims: 2 independent, 8 dependent
- 1a password machine equipment the group information of synchronous system wherein said group comprises at least two passwords machine equipment and each code machine equipment is equipped with a group cooperation module the group cooperation module is used to realize the password machine is set between the synchronous monitoring instruction information of synchronous and synchronous push information receiving and it is used for realizing the synchronous information received by the password machine device for carrying out the synchronous information push the password machine device of identity authentication and information identifying. 1.一种密码机设备的群组的信息同步系统,其特征在于,所述群组包括至少两个密码机设备,且每个密码机设备中均配置有群组协同模块,该群组协同模块用于实现各密码机设备之间的同步指令监听、同步信息推送和同步信息接收,还用于实现进行同步信息接收的密码机设备对进行同步信息推送的密码机设备的身份验证和信息验证。
- 6a password machine equipment the group information synchronization method wherein it comprises:Step 1 the password machine equipment group of each code machine in equipment is equipped with a group cooperation module;Step 2 to the synchronous information push the password machine equipment is defined as initiating terminal to the synchronous information received by the password machine equipment is defined as in response to terminal sends end of the response is sent out synchronization instruction group and through the cooperation module the synchronization information is transmitted to responding end;Step 3 responding end receives the synchronization order after analyzing the synchronous information and through group cooperation module to the initiator carrying out authentication and authentication data authentication is successful if it can carry out updating information or refusing synchronous operation. 6.一种密码机设备的群组的信息同步方法,其特征在于,包括: 步骤1,在密码机设备群组的每个密码机设备中均配置一个群组协同模块; 步骤2,将进行同步信息推送的密码机设备定义为发起端,将进行同步信息接收的密码机设备定义为响应端,发起端向响应端发出同步指令,并通过群组协同模块将同步信息推送给响应端; 步骤3,响应端接收同步指令后,解析同步信息,并通过群组协同模块对发起端进行身份验证和数据验证,若验证成功则进行信息更新,否则拒绝同步操作。
Independent claims2
72 paragraphs, as filed
The technical field of
[0001] the invention claims an information technology field and information safety field especially aiming at the password machine product of shape of technology innovation claims a password machine equipment the group information synchronization method and system.
Background technology
Radial 0002 is to avoid the password machine equipment the single point trouble or opposite to the high performance requirement of the present each kind of the code is set on the equipment disposition it uses a computer hot standby or of balancing the load work mode to form a code the working group. The work mode the lower code machine is often needs to the device key information and so on carrying out synchronous.
[0003] transmitting system information synchronous method has two ways one is the application system or the opening has directivity that it realizes one is composed of the people when it is necessary to the operating on-site carried out.
[0004] front this invention claims a synchronous way to the password machine equipment of application system or application interface the development of the high the achieving cost of it application system is added with a spot of resource spending; And a synchronous way is increased the password machine maintaining part of the implementation cost and because the system of machine room different degree of the limitation of the information synchronously works with the time efficiency is greatly influenced.
[0005] aiming to problem mentioned above this invention claims a new cryptographic machine equipment the group information synchronization method and system.
The content of invention
[0006] the invention aims to solve the technique problem that the invention claims a cryptographic machine equipment the group information synchronization method and system is used for solving the problem that the password machine equipment group of key information and so on the automatic synchronization problem.
[0007] this invention solves the technology problem the technical plan is as follows: A password machine equipment the group information of synchronous system said group comprises at least two passwords machine equipment and each code machine equipment is equipped with a group cooperation module the group cooperation module is used to realize the password machine is set between the synchronous monitoring instruction information of synchronous and synchronous push information receiving and it is used for realizing the synchronous information received by the password machine device for carrying out the synchronous information push the password machine device of identity authentication and information identifying.
[0008] on the said technical plan on the basis of the invention also can be taken as the following amelioration to.
[0009] further said group cooperation module comprises a network monitoring port sending module and certification module the network monitoring interface is used to receive the group code machine equipment for sending synchronizing instruction the said pushing transmitting module is used to code group in the machine equipment send the synchronous information said identification module is used for carrying out synchronous information push the password machine equipment perform mutual identity verification and the data testifying.
[0010] following steps said synchronous information comprises key generation information key deleting information to group adding the password machine equipment the information is deleted from the group code machine equipment and the information of system resource load information of.
[0011] further the password machine equipment also comprises application service module is used to code product and application of client provides the code application service the system comprises a first application client terminal sends the information at the same time the success of the information or information of fail.
[0012] further the password machine device further comprises management service module is used to code and production management client provides management function on equipment comprising the device configuration and key management and said management server module and execution of the management function which relates to information is modified which needs to be in the group code is set between the information synchronously.
[0013] the technology scheme of the invention also comprises a cryptographic machine device of group information synchronization method comprising steps as follows:
[0014] step 1 the password machine equipment group of each code machine in equipment is equipped with a group cooperation module;
[0015] step 2 to the synchronous information push the password machine equipment is defined as initiating terminal to the synchronous information received by the password machine equipment is defined as in response to terminal sends end of the response is sent out synchronization instruction group and through the cooperation module the synchronization information is transmitted to responding end;
[0016] step 3 responding end receives the synchronization order after analyzing the synchronous information and through group cooperation module to the initiator carrying out authentication and authentication data authentication is successful if it can carry out updating information or refusing synchronous operation.
[0017] the further response terminal finish updating information or refusing the synchronous operation the response data fed back to the initiating terminal; Initiating terminal receives the responding end of the responding data after the responding terminal sends confirming information.
[0018] further initiating end of the responding terminal sends confirming information to managing client end or application client terminal returning to carry out ih synchronous information is correct or [ target information or failed * program information.
[0019] further code machine device to code and production management client provides management function on equipment comprising the device configuring and managing key and the execution of the management function which relates to information is modified which needs to be in the group code is set between the information synchronously.
[0020] following steps said synchronous information comprises key generation information key deleting information to group adding the password machine equipment the information is deleted from the group code machine equipment and the information of system resource load information of.
[0021] this invention has the beneficial effects of this utility model is that: The invention claims a cryptographic machine equipment in the inner part of the automatic synchronous information which can effectively reduce password machine equipment application interface and service system the processing the service time the development cost of. At the same time at the same time the manner of implementing scene personnel executing the synchronization mode and greatly improves the code cluster equipment at the same time of time at the same time reducing the maintenance method of implementing cost. The other scheme in synchronous process of the confidential information and they all adopt the encrypted file in the form of carrying out transmission to ensure the synchronization in the process of information security and it reduces the information leakage the risk of the link.
Specification attached drawing
[0022] picture 1 is the invention claims cryptographic machine equipment the group information of synchronous system the structure of picture;
[0023] picture 2 in the invention the password machine equipment the group information synchronization method of the flow picture;
[0024] picture 3 is in the embodiment of this invention carries out cryptographic machine equipment and information synchronization process of picture;
[0025] picture 4 is in the embodiment of this invention a key generating the operation of automatic synchronous process picture;
0026 image ] [ 5 is in the embodiment of this invention the key deleting operation from the synchronous process picture;
[0027] picture 6 is in the embodiment of this invention group equipment dynamically adding the operation of automatic synchronous process picture;
[0028] graph 7 the invention embodiment group equipment dynamic deleting operation from the synchronous process picture.
[0029] of the attached drawing of the mark representing the meaning is as follows:
[0030] 1 group cooperation module 2 application service module 3 application client terminal managing service module 5 managing client end 11 network monitoring end of inlet 12 and 13 sending module verification module.
Specific implementing manner
[0031] following combining the attached drawing to the principle of this invention and characteristic to describe the lifting embodiment only used for explaining the invention and it is used for limiting the scope of this invention.
[0032] as is shown in figure 1 the embodiment the invention claims a password machine device of group information of synchronous system and information synchronization system in said group comprises at least two passwords machine equipment and each code machine equipment is equipped with a group cooperation module 1 the group cooperation module i is used to realize the password machine is set between the synchronous monitoring instruction information of synchronous and synchronous push information receiving and it is used for realizing the synchronous information received by the password machine device for carrying out the synchronous information push the password machine device of identity authentication and information identifying.
[0033] specifically said group cooperation module i comprises network monitoring port 1 propelling module 12 and 13 verifying module said network monitoring end of inlet 11 is used for receiving the code group in the machine equipment for sending synchronizing instruction the pushing module 12 is used to code group in the machine equipment send the synchronous information said validating module 13 is used for carrying out synchronous information push the password machine equipment perform mutual identity verification and the data testifying.
[0034] the password machine equipment also comprises application service module 2 is connected with the outer part of the corresponding client terminal 3 to the application of client provides the code application service wherein the system comprises a first application client terminal sends the information for synchronizing information of success or failed information and so on the executed the information of the synchronous function is successful directly is that the calling of application function is successful in the application function of failure and it does not complete representative information isochronous failure of; The password machine device further comprises management service module 4 the invention claims a method to product or code for managing client end 5 of the invention claims the password machine equipment the management function it comprises equipment collocation function and key management comprising function of automatically synchronizing function with a cryptographic machine group of managing client end executing the equipment and information and it is used for distinguishing different of the device id ip address information and so on are modified need to carry out equipments are synchronized.
[0035] is shown as picture 2 1 based on said automatic system for synchronous information synchronization of the specific procedure is as follows:
[0036] step 1 the password machine equipment group of each code machine in equipment is equipped with a group cooperation module;
[0037] step 2 to the synchronous information push the password machine equipment is defined as initiating terminal to the synchronous information received by the password machine equipment is defined as in response to terminal sends end of the response is sent out synchronization instruction group and through the cooperation module the synchronization information is transmitted to responding end;
[0038] step 3 responding end receives the synchronization order after analyzing the synchronous information and through group cooperation module to the initiator carrying out authentication and authentication data authentication is successful if it can carry out updating information or refusing synchronous operation.
[0039] finish performing step 3 after it also comprises: Responding end finishes the updating information or refusing the synchronous operation the response data fed back to the initiating terminal; Initiating terminal receives the responding end of the responding data after the responding terminal sends confirming information; Initiating end of the responding end sends the confirming the message through application service module or managing service module respectively to corresponding client terminal and managing client end returns the carrying out information in synchronization with the correct information or information of fail.
[0040] a lower surface by one the information automatic synchronization of example to explain the embodiment of the information of the synchronous system and method comprises the work flow displaying the picture the embodiment of the src hsm initiating terminal and hsm dstl hsm dst2 are divided into two one end of response information automatically and synchronously flow into the starting stage at the same time period and confirming phase.
[0041] at the beginning period: The cryptographic machine equipment in configuration group cooperation module and configuring appointed group of the machine the outside of the other equipment. Hsm src opening the machine function by a method for generating synchronous information and driving the push of the module pushing function to hsm dstl hsm dst2 and sending the synchronizing instruction and sending the synchronous information. Hsm dstl and hsm dst2 opening the network monitoring port receiving hsm src sent by the synchronization instruction.
[0042] the synchronous stage = hsm dstl hsm dst2 and receiving synchronization instruction after analyzing the synchronous information and the src hsm validating the identity information validating and it is determined this group of the equipment after the current the task to be hanged up according to the received synchronizing information to the location information updated and then to re-carry out the task of hanging. If it is the identification succeeded the operation to execute synchronization operation. Hsm dstl hsm dst2 and finish the local updating information or refusing the synchronous operation the response message fed back to the src hsm.
[0043] is confirmed phase = hsm src receiving hsm dstl hsm dst2 and correctness of returning result to finish the local information update after hsm dstl hsm dst2 and to transmit acknowledgement information to managing client end is the application system to return to the correct information; Whether to the hsm dstl and hsm dst2 sends cancelling instruction the managing client end returns the information of fail.
[0044] the embodiment of the synchronous information comprises key generation information key deleting information to group adding the password machine equipment and the information is deleted from the group code machine equipment the information which are respectively corresponding to the following four application scene.
[0045] a cryptographic key generated automatically and synchronously flow
[0046] such as drawing 4 the display the operation is in the group a code machine equipment hsm src generated in secret key required by the automatically realizing to group in the password machine equipment hsm dstl hsm dst2 and the key of synchronous process described as follows:
[0047] beginning = hsm src the application module and management module receives the random generating key or appointed key ming-wen function request information to finish performing the key is generated during the process of; Hsm src the key index generating the key value synk the encryption key cryptographic text checking value is covered by key verification value if the index is free then it does not with the item and self characteristic information synk checking value of label name information and so on as the synchronous data and the synchronous data that needs to be transmitted to hsm dstl and hsm dst2.
[0048] synchronous stage: 1 hsm dstl hsm dst2 and receives the src hsm for synchronizing instruction to data analyzing; Hsm dstl with hsm 2 dst2 verification hsm src characteristic information of the src in group with hsm for the feature value whether or not and the main machine device of information in the same; 3 hsm dstl and hsm dst2 check are covered key with the checking value is not matched then refusing the synchronous operation; 4 hsm dst calculating new cryptographic key the plaintext and check value and hsm src it is submitted with the checking value is not matched then refusing the operation; 5 hsm dstl and hsm dst2 after passing the verification the new key is written into the index table; 6 hsm dstl hsm dst2 and sending responding data to the src hsm.
[0049] confirming phase: Hsm src judging hsm dstl hsm dst2 and returning the responding data if the operation of equipment is failure and then the retroversion the key generating an operation if all successfully then continue to execute; Hsm dstl and hsm dst2 receiving src hsm for sending confirming command according to the order return selecting the operation or a finishes a synchronous operation.
[0050] second key deleting operation from the synchronous process
[0051] 5 picture displayed on the operation in the group a code machine equipment hsm src in the deletion of appointed key automatically realizing the group key synchronizing key deleting operation from the synchronous process described as follows:
[0052] beginning = hsm src the application module and management module receives the random secret key deleting or appointed key ming-wen function request information to finish performing the key deleting process of; Hsm src the key searching key value of checking its own characteristic information synk checking value signing information and so on as synchronous data to synchronous data is transmitted to the hsm dstl and hsm dst2;
[0053] synchronous stage: 1 hsm dstl hsm dst2 and receives the src hsm for synchronizing instruction to data analyzing; 2 hsm dst verification hsm src characteristic information of the src in group with hsm for the feature value whether or not and the main machine device of information in the same; 3 hsm dstl hsm dst2 checking and local key with the checking value is not matched then refusing the synchronous operation;
4 hsm dstl and hsm dst2 after verification is successful deletes the local index in the appointed key; 5 hsm dstl hsm dst2 and sending responding data to the src hsm.
[0054] confirming phase: Hsm src judging hsm dstl hsm dst2 and returning the responding data if the operation of equipment is failure and then the retroversion the key generating an operation if all successfully then continue to execute; Hsm dstl and hsm dst2 receiving src hsm for sending confirming command according to instruction selecting return the operation or a finishes a synchronous operation.
[0055] third group equipment dynamically adding automatic synchronous process
[0056] is shown in picture 6 the display screen aims at making a new code machine equipment hsm new added to the target equipment group in the current program description as follows:
[0057] beginning = hsm new of manual configuration group of the equipment information can execute the set of instruction in the group; Hsm new preparation of the verification information of the whole group configuration information of self characteristic information synk checking value signing information and so on the encrypted and so on as the synchronous data is transmitted to the with hsm dst2 hsm dstl;
[0058] synchronous stage: I hsm dstl hsm dst2 hsm new and the verification information to verify; 2 hsm dstl hsm dst2 and verification the machine the invention claims a new hsm group configuration information and the consistency of synk; 3 hsm dstl hsm dst2 and returns authentication result to the new hsm.
[0059] confirming phase: Dhsm new received hsm dstl hsm dst2 and returned result according to response result complete the operation and sends the confirming result to the hsm dstl and hsm dst2; 2 hsm dstl with hsm dst2 hsm new according to the confirming result to finish the automatic configuration of the update operation the present synchronous information of data preparation; 3 hsm new received hsm dst synchronous data to the equipment of the data to proceed coherence examination successfully the data is written in the machine refusing to cancel the operation.
[0060] 4 group equipment dynamic deleting process
[0061] picture 7 and the display the operation of a group of a cryptographic machine equipment hsm del from the group of deleting process describe:
[0062] beginning: The hsm del the management of the client terminal cleaning group configuration information executing exiting group the instruction; Sm del preparing synchronous data that hsm del information of self characteristic information synk checking value signing information and so on group configuration characteristic information as synchronous data to with hsm hsm dstl dst2 sends out the request;
[0063] synchronous stage: Hsm dstl and hsm dst2 the hsm del to the request command data to carry out verification; Hsm dstl hsm dst2 and returns authentication result to hsm del;
[0064] confirming phase: Hsm del sends the confirming result to the hsm dstl and hsm dst2; Hsm dstl and hsm dst2 hsm del according to the confirmation result is determined whether or not from the group with hsm del for deleting information of the finished each synchronous operation of.
0065 ] and [ the four automatic synchronous process and also relates to password the system resource loading information to synchronize the system resource load information which is used for the password machine the automatic realizing load equalization function of the synchronous process of said four information of the automatic synchronization process like this there is no need to said multiple.
[0066] is the only of the invention better embodiment is not used for limiting the invention claims a fan the invention claims a raw spirit and it is the any modification to replace the same and so on are improved it comprises the invention claims a protection range.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN101155027A | Cites | China | Search report |
| CN102857564A | Cites | China | Search report |
| CN103580891A | Cites | China | Search report |
| US6941457B1 | Cites | United States of America | Search report |
| TWI292997B | Cites | Taiwan Province of China | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201410160866 | China | A | |
| CN20141160866 | – | – | – |
Numbers
- Publication
- 103973462
- Publication, DOCDB
- 103973462
- Publication, EPODOC
- CN103973462
- Application
- 101608669
- Application, DOCDB
- 201410160866
- Application, EPODOC
- CN20141160866
Titles3
- English
- A password machine equipment the group information synchronization method and system
- Chinese
- 一种密码机设备的群组的信息同步系统及方法
- English
- Information synchronization system and method for group of cipher machines
Classification
- IPC, 3
- H04L12 18
- H04L29 06
- H04L9 08