Key generation and restoration method
Abstract
The invention provides a key generation and restoration method. The method comprises the steps that first, multiple initialization factors are input for generation and restoration; second, N sets of independent initialization factor data are input to generate M root keys, and the root keys are led and stored into safety hardware storage equipment; third, K sets of independent initialization factor data are input to restore the M root keys, and the restored root keys are led and stored into the safety hardware storage equipment. According to the key generation and restoration method, an initialization factor operation rule is safe, secret and not public. The key data in the safety hardware storage equipment can not be read out, key generation process data and key data are not leaked in any mode, and therefore the safety of the key generation process and the key application process is guaranteed.
Term
8.3 yearsto projected expiry
Projected expiry 12 January 2035, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
3 claims: 1 independent, 2 dependent
- 1A method for key generation and recovery, which is characterized in that it comprises the following steps:Step 1. Multi-initialization factor input generation and recovery;Step 2. Input N sets of mutually independent initialization factor data to generate M root keys, and Import and save the root key into the secure hardware storage device;Step 3. Input the independent initialization factor data of group K, restore M root keys, and import and save the restored root key into the secure hardware storage device. 1. 一种密钥生成与恢复方法,其特征在于,包括如下步骤: 步骤一、多初始化因子输入生成与恢复; 步骤二、将N组相互独立的初始化因子数据输入,生成Μ个根密钥,并将根密钥导入保 存到安全硬件存储设备中; 步骤三、将Κ组相互独立的初始化因子数据输入,恢复Μ个根密钥,并将恢复的根密钥 导入保存到安全硬件存储设备中。
47 paragraphs, as filed
A kind of key generation and recovery method technical field
[0001] The present invention relates to the field of key management technology, and in particular to a method for key generation and recovery.
Background technique
[0002] As the requirements for information security continue to increase, a key is a parameter, which is data input in an algorithm that converts plaintext to ciphertext or converts ciphertext to plaintext. It can perform information on personal information and corporate secrets. Effective supervision; when the key is generated, the key length should be long enough. Generally speaking, the larger the key length, the larger the corresponding key space, and the more difficult it is for an attacker to use exhaustive guessing of the password. Choose a good key and avoid weak keys. The random bit string generated by the automatic processing device is a good key. When choosing a key, you should avoid choosing a weak key. For public key cryptosystems, key generation is more difficult because the key must satisfy certain mathematical characteristics. Key generation can be achieved through online or offline interactive negotiation, such as a cryptographic protocol.
[0003] The security of key generation and recovery has higher requirements. The current calculation rules used for key generation and recovery have weak confidentiality. The process of key generation and recovery involves data export, which is easy to reveal the secret. As a result, safety is greatly reduced.
[0004] Therefore, in view of the problems existing in the prior art, it is necessary to develop and design a scheme so that the calculation rules for key generation and recovery are implemented in the security device, which is not disclosed, has strong confidentiality, and the process of key generation and recovery All the data of, will not be exported, will not be leaked, which improves the security of the key generation and recovery process.
Summary of the invention
[0005] In order to solve the above-mentioned problems, the purpose of the present invention is to provide a key generation and recovery method.
[0006] In order to achieve the above objective, the technical solution of the present invention is: a key generation and recovery method, including the following steps: step one, multi-initialization factor input generation and recovery; step two, N sets of mutually independent initialization factors Data input, generate M root keys, and import and save the root keys to the secure hardware storage device; Step 3. Input the independent initialization factor data of the K group, restore the M root keys, and restore the root keys. The key is imported and saved to a secure hardware storage device.
[0007] Further, the key generation process includes the following steps:
510 : Input N groups of mutually independent initialization factor data, N> 1;
511 : Define the root key service code according to business needs;
512 : Calculate the root key, perform initialization factor calculations on the security device according to predetermined calculation rules on the N sets of initialization factor data and root key service codes, obtain M root keys, and save and import them into the security storage device;
513 : Calculate the application key, enter the application dispersion factor, obtain the application key through key dispersion, and save and import it into the application security storage device.
[0008] Further, the key recovery process includes the following steps:
S20: Input the independent initialization factor data of the K group, including the matched K group pin code, K 2 N;
521 : Verify the correctness of the K groups of pin codes. If any pin code verification fails, the key recovery operation ends;
522 : Restore the root key calculation, call up the initialization factor data and root key service code in the security device, perform the initialization factor calculation again in accordance with the predetermined calculation rules, calculate and obtain M root keys, and restore the import to the security storage device in;
523 : Application key recovery, enter the application dispersion factor, recover the application key through key dispersion, and save the recovery and import it into the application security storage device.
[0009] In the key generation and recovery method of the present invention, the initialization factor operation rule is safe and confidential and not public; the key data in the secure hardware storage device cannot be read, and the key generation process data and key data are not leaked in any way, So as to ensure the security of the key generation process and the application process.
Description of the drawings
[0010] FIG. 1 is a flowchart of a method for key generation and recovery of the present invention.
[0011] FIG. 2 is a model diagram of the key generation method of the present invention.
[0012] FIG. 3 is a model diagram of the key recovery method of the present invention.
Detailed ways
[0013] The embodiment of the present invention provides a key generation and recovery method. By inputting multiple sets of mutually independent initialization factor data, after initialization factor calculation, multiple sets of initialization factor and root key service code are generated according to a certain calculation rule. Root key, and import and save the root key to the secure hardware storage device; Disperse the root key through the application dispersion factor to obtain the required application key, import and save the application key to the secure hardware device; Root secret The key recovery is the same as the root key generation process, the difference is that the number of initialization factor data groups can be less than or equal to the number of initialization factor groups required for root key generation. The initialization factor calculation rules are safe and confidential; the key data in the secure hardware storage device cannot be read, and the key generation process data and key data are not leaked in any way, so as to ensure the security of the key generation process and the application process .
[0014] In order to make the purposes, features, and advantages of the present invention more obvious and understandable, the technical solutions in the embodiments of the present invention will be described clearly and completely in conjunction with the accompanying drawings in the embodiments of the present invention. It is obvious that The embodiments described below are only a part of the embodiments of the present invention, but not all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art fall within the protection scope of the present invention.
[0015] The terms "first", "second", etc. in the present invention, the claims and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific sequence or sequence. It should be understood that the terms used in this way can be interchanged under appropriate circumstances, and this is only a way of distinguishing objects with the same attribute in the description of the embodiments of the present invention. In addition, the terms "including" and "having" and any variations of them are intended to cover non-exclusive inclusion, so that a process, method, system, product, or device that includes a series of units is not necessarily limited to those units, but may include Listed or inherent to these processes, methods, products or equipment.
[0016] Detailed descriptions are provided below.
[0017] Referring to FIGS. 1 to 3, a method for generating and recovering a key of the present invention includes the following steps: Step 1: Multi-initialization factor input generation and recovery; Step 2: N sets of mutually independent initialization factor data Input, generate M root keys, and import and save the root keys to a secure hardware storage device;
Step 3: Input K groups of mutually independent initialization factor data, restore M root keys, and import and save the restored root keys into a secure hardware storage device.
[0018] A key generation and recovery method of the present invention inputs multiple sets of mutually independent initialization factor data, and after initialization factor calculations, multiple sets of initialization factors and root key service codes are used to generate a root key according to a certain calculation rule, and Import and save the root key to a secure hardware storage device; disperse the root key by applying a dispersion factor to obtain the required application key, import and save the application key to a secure hardware device; restore and root the root key The key generation process is the same, the difference is that the number of initialization factor data groups can be less than or equal to the number of initialization factor groups required for root key generation. The initialization factor calculation rules are safe and confidential; the key data in the secure hardware storage device cannot be read, and the key generation process data and key data are not leaked in any way, so as to ensure the security of the key generation process and the application process .
[0019] Specifically, the key generation and recovery method of the present invention includes a key generation process and a key recovery process; wherein, the key generation process includes the following steps:
510 : Input N sets of mutually independent initialization factor data, including matching N sets of pin codes, N> 1;
511 : Define the root key service code according to business needs;
512 : Calculate the root key, perform initialization factor calculations on the security device according to predetermined calculation rules on the N sets of initialization factor data and root key service codes, obtain M root keys, and save and import them into the security storage device;
513 : Calculate the application key, enter the application dispersion factor, obtain the application key through key dispersion, and save and import it into the application security storage device.
[0020] The key recovery process includes the following steps:
520 : Input the independent initialization factor data of the K group, including the matched K group pin code, K 2 N;
521 : Verify the correctness of the K groups of pin codes. If any pin code verification fails, the key recovery operation ends;
522 : Restore the root key calculation, call up the initialization factor data and root key service code in the security device, perform the initialization factor calculation again in accordance with the predetermined calculation rules, calculate and obtain M root keys, and restore the import to the security storage device in;
523 : Application key recovery, enter the application dispersion factor, recover the application key through key dispersion, and save the recovery and import it into the application security storage device.
[0021] The present invention will be described with an application example below, referring to FIG. 1, which is a model diagram of a key generation method, according to the key generation process shown in FIG. 1 (take N=4, Μ=20 as Example), including the following steps: Step 1: Input 4 sets of independent initialization factor data yinzi and pin code, such as leader 1: yinzl=1122, pinl=123456, leader 2: yinz2=3344, pin2=234567, leader 3 :yinz3=7788, pin3=345678, leader 4: yinz4=ABCD, pin4=567890, and save it in a secure storage device; Step 2: Define the root key service code, and define the root key service code according to the key usage: Such as encryption, decryption, transmission, MAC calculation, deposit amount, consumption, internal verification, external verification, identity authentication, etc., and import and save them in a secure storage device; Step 3: Calculate the root key, initialize the factor data, root The key service code performs the initialization factor calculation according to a certain calculation rule to obtain 20 root keys and import them into the secure storage device; Step 4: Calculate the application key, enter the application dispersion factor (such as: 1122334455667788), and pass the encryption The key is distributed to obtain the application key and import it into the application security storage device.
[0022] FIG. 2 is a model diagram of a key recovery method. According to the key recovery process shown in FIG. 2 (taking Κ=3, Μ=20 as an example), it includes the following steps:
Step 1: Input 3 sets of independent initialization factor data yinzi and pin code, such as leader 1:yinzl=1122, pinl=123456, leader 3:yinz3=7788, pin3=345678, leader 4:yinz4=ABCD, pin4= 567890; Step 2: Verify the correctness of the pin codes of Leader 1, Leader 3, and Leader 4. If any pin code verification fails, the key recovery operation ends; Step 3: Restore the root key calculation and call up the security device The initialization factor data and the root key service code in the data, the initialization factor calculation according to a certain calculation rule again, the calculation of 20 root keys, and re-import into the secure storage device; Fourth step: application key recovery, Enter the application dispersion factor (for example: 1122334455667788), recover the application key after key dispersion, and restore it to the application security storage device.
[0023] Through the description of the above embodiments, those skilled in the art can clearly understand that the present invention can be implemented by means of software plus necessary general hardware. Of course, it can also be implemented by dedicated hardware including dedicated integrated circuits, dedicated CPUs, Dedicated memory, dedicated components, etc. to achieve. Under normal circumstances, all functions completed by computer programs can be easily implemented with corresponding hardware. Moreover, the specific hardware structure used to achieve the same function can also be diverse, such as analog circuits, digital circuits or special-purpose circuits. Circuit etc. However, for the present invention, software program implementation is a better implementation in more cases. Based on this understanding, the technical solution of the present invention essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product is stored in a readable storage medium, such as a computer floppy disk. , U disk, mobile hard disk, Read-Only Memory (ROM, Read-Only Memory). Random Access Memory (RAM, Random Access Memory)> magnetic disk or optical disk, etc., including several instructions to make a computer device (which can be A personal computer, a server, or a network device, etc.) execute the methods described in the various embodiments of the present invention.
[0024] In summary, the above embodiments are only used to illustrate the technical solutions of the present invention, but not to limit them; although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: It is still possible to modify the technical solutions described in the foregoing embodiments, or equivalently replace some of the technical features; these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and spirit of the technical solutions of the embodiments of the present invention. range.
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US11095437B2 | Cited by | United States of America | – | Applicant | – |
| US10873449B2 | Cited by | United States of America | – | Applicant | – |
| CN107465505A | Cited by | China | – | Search report | – |
| US10797865B2 | Cited by | United States of America | – | Applicant | – |
| CN108449178A | Cited by | China | – | Search report | – |
| US11356250B2 | Cited by | United States of America | – | Applicant | – |
| CN103580872A | Cites | China | X | Search report | 1-3 |
| CN1795471A | Cites | China | A | Search report | 1-3 |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201510013608 | China | A | |
| CN2015113608 | – | – | – |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Invention patent application deemed withdrawn after publicationWithdrawnWD01 | WD01 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 104579644
- Publication, DOCDB
- 104579644
- Publication, EPODOC
- CN104579644
- Application
- 100136082
- Application, DOCDB
- 201510013608
- Application, EPODOC
- CN2015113608
Titles2
- Chinese
- 一种密钥生成与恢复方法
- English
- A key generation and recovery method
Classification
- IPC, 1
- H04L9 08