Key protection method
Abstract
One kind of key protection methods, including USB KEY, characterized in that: take five USB KEY for storing key, secret key to be confidential documents taken from (3,5) threshold segmentation methods on the original key, respectively save to five USB kEY, there are five different people for safekeeping; when any of the three can restore the original key recovered to decrypt the ciphertext. Interested effect of the present invention are: to solve the drawbacks of the human brain by record keys or hard disk recording and U keys, improved after security and reliability of data encryption key management.
Term
9.6 yearsto projected expiry
Projected expiry 12 May 2036, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
4 claims: 1 independent, 3 dependent
- 1一种密钥保护方法,包USB KEY,其特征是:取5个USB KEY用于存放密钥,将待保密文 件的秘钥取采用(3,5)门限方式对原始密钥进行分割,分别存到5个USB KEY中,有5个不同 人员进行保管;恢复时任意三人即可将原始密钥恢复出来对密文进行解密。
- 2根据权利要求1所述的密钥保护方法,其特征是:所述USB KEY为双因子硬件方式存 放密钥。
- 3根据权利要求1所述的密钥保护方法,其特征是:所述加密算法选择通用的对称加密 算法AES、DES、3DES,国密局制定国密算法SM1和SM4中的任意一种。
- 4根据权利要求1所述的密钥保护方法,其特征是:所述USB KEY选择握奇或飞天诚信 的USB KEY,并利用他们提供的API接口函数编程实现密钥的存放。
Independent claims4
40 paragraphs in 3 sections, as filed
_ Species key protection methods
TECHNICAL FIELD
[0001] The present invention relates to the field of computer security information, mainly for key management security for key storage, an improved reliability, especially suitable for the need to encrypt data backup situation, specifically based key protection methods.
Background technique
[0002] This patent relates to the field of computer information security, information security field in the current key management mode basically also use a password, remember password code by the people, or the password into a computer or U disk, exist in this way great risk. Because passwords are too difficult to remember, a computer or U disk hardware damage or forget the password, it will result in the loss of the original encrypted information.
SUMMARY
[0003] In order to solve the encrypted password by human mind or writing a computer, U disk after hardware count bad, the key is lost, causing problems with the information can not be recovered, the present invention provides a high safety and reliability of key protection method. The present invention is achieved by the following technical solutions:
[0004] - kind of key protection method, the present invention utilizes USB KEY hardware and (3,5) threshold key protection method, the user first randomly generates a set of random numbers at the time of encrypting data as the data encrypted passwords, use randomly generated key to encrypt the plaintext data, and then using the (3,5) threshold algorithm for encryption key division, to produce 5 key elements, and finally the 5 key elements are stored in five different USB kEY the protection, and five USB kEY points to five different people for safekeeping, everyone can set their own password using the USB kEY, key people will not easily be retrieved. Need to decrypt the data when using the (3,5) threshold algorithm to select any of three people using its USB KEY, you can restore the original key to decrypt it.
[0005] In order to ensure the identity of the holders of USB KEY legitimacy and reliability, the USB KEY double key factor in hardware store, that two-factor authentication, safety than by the human brain into a mind or password security places to be higher, but the key is dispersed storage, even get a USB kEY, and get USB kEY authentication password can not restore the original key. This method is the use of (3,5) threshold algorithm, even if one or two USB KEY damage will not affect the recovery of the original key, thus increasing the reliability, when one or two USB KEY damage can be first data recovered, re-select the five USB kEY for key segmentation can greatly reduce the probability of damage caused due to hardware keys missing.
[0006] For ease of encryption, the encryption algorithm select the encryption algorithm developed countries SM1 and SM4 any one common symmetric encryption algorithm AES, DES, 3DES, country dense Bureau.
[0007] For ease of use, the USB KEY or select Watchdata Feitian the USB KEY, and use the API programming interface functions they provide to achieve storage key.
[0008] The present invention intends to effect: to solve the drawbacks of the human brain by record keys or hard disk recording and U keys, improved after security and reliability of data encryption key management.
BRIEF DESCRIPTION
[0009] the following with reference to the present invention will be further explained:
[0010] FIG. 1 key segmentation process:
[0011] FIG. 2 key recovery processes;
DETAILED DESCRIPTION [0013] as follows:
[0014] Encryption:
[0015]> randomly generates a random number as an encryption key in plain text.
[0016]> Use this key to encrypt the plaintext data to produce ciphertext.
[0017] Μ Officials with (3,5) threshold algorithm key split into five key elements.
[0018]> Five key elements are stored to five USB KEY, and the five USB KEY points to five different people for safekeeping.
[0019] MJSB KEY custody staff are set to use their own USB KEY password.
[0020] decryption process:
[0021]> Select any of the three USB KEY managers were entering their USB KEY including passwords and remove the three key elements.
[0022] Μ Officials with (3,5) threshold algorithm, three molecules of key recovery to the original key.
[0023]:> Use original key to decrypt the ciphertext data obtained plaintext data.
[0024] said randomly generated encryption key, you can use a random number generator without any rules data string as a key.
[0025] plaintext encryption: You can choose a common symmetric encryption algorithms AES, DES, 3DES, or secret State Bureau encryption algorithm developed country SMI, SM4 algorithm. USB KEY: You can choose to hold or odd Feitian the USB KEY, and use the API programming interface functions they provide to achieve storage key. Segmentation and recovery key: Use (3,5) threshold algorithm on a group of key segmentation and recovery.
[0026]> USB KEY: the use of flying commercially available or can grip Qi, USB KEY manufacturers of hardware products, and use their products provide API interface function programming.
[0027] M3,5) threshold principle:
[0028] (k, η) secret sharing algorithm secret S will be divided into sub-η secret, arbitrary k-th secret S can be recovered, and any k-Ι sub secret can not recover S.
[0029] The dispersion process:
[0030] Suppose there is a secret S, take any random numbers ai ,..., Akl. Order ao is S, construction polynomial
[0031] as polynomial: f (x) = ao + aix + a2X2 + · in which all operations are performed in the finite field F. Take any number η ή,..., Χη respectively into polynomial obtained fUi) ,..., F (xn).
[0032] The (magic to magic)), ..., (known to know)) are stored in the 11 ^ 101. The recovery process:
[0033] k take any data on the server, it is assumed to take {X1, yi} ,..., {Xk, yk}, substituting and solving polynomial coefficient.
[0034] ao + aixi +... + Ak-ixik 1 = yi
[0035] ao + aiX2 +... + Ak-iX2k_1 = y2
[0036] ......
[0037] ao + aixk +... + Ak-ixkk_1 = yk
[0038] equations is k linear equation group, determined to get the key S. ao
[0039] The present invention solves the shortcomings of the human brain by record keys or hard disk recording and U keys, improved after security and reliability of data encryption key management. Such as financial data system database backup, database backup method if you use only, the others can backup files recovered in other databases, is very risky. If the data is encrypted using some encryption software, you need to encrypt passwords, if set too short, security is not high, if set too long, difficult to remember. Using this method, you can use a very complicated keys, respectively, put five USB KEY, the user just give USB KEY is set to an appropriate key, because USB KEY attempts allowed itself to enter the key is limited and difficult to crack passwords; and key dispersed into the hands of five people, half of the staff must be present in order to restore the data out, cracks unlikely. Recovery only need to be present at any of the three, so even if one or two people lost key does not affect the recovery, yet mention reliability.
Contents3
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| CN109033811A | Cited by | China | – | Search report | – |
| US10797865B2 | Cited by | United States of America | – | Applicant | – |
| US11356250B2 | Cited by | United States of America | – | Applicant | – |
| CN111177780A | Cited by | China | – | Search report | – |
| CN111448779A | Cited by | China | – | Search report | – |
| CN107979473A | Cited by | China | – | Search report | – |
| CN107465505A | Cited by | China | – | Search report | – |
| CN112202550A | Cited by | China | – | Search report | – |
| CN108959946A | Cited by | China | – | Search report | – |
| CN112272087A | Cited by | China | – | Search report | – |
| CN106850208A | Cited by | China | – | Search report | – |
| WO2020063354A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| US11095437B2 | Cited by | United States of America | – | Applicant | – |
| CN113890731A | Cited by | China | – | Search report | – |
| CN106357401A | Cited by | China | – | Search report | – |
| US10873449B2 | Cited by | United States of America | – | Applicant | – |
| US11063754B2 | Cited by | United States of America | – | Applicant | – |
| CN101236590A | Cites | China | X | Search report | 1-4 |
| CN101621375A | Cites | China | A | Search report | 1-4 |
| CN1601957A | Cites | China | A | Search report | 1-4 |
| US2012087494A1 | Cites | United States of America | A | Search report | 1-4 |
1 member in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201610319287 | China | A | |
| CN20161319287 | – | – | – |
Members1
| Document | Office | Kind | |
|---|---|---|---|
| CN106027234AThis record | China | A |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Rejection of invention patent application after publicationRJ01 | RJ01 | |
| Change of inventor or designer informationCB03 | CB03 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 106027234
- Publication, DOCDB
- 106027234
- Publication, EPODOC
- CN106027234
- Application
- 103192873
- Application, DOCDB
- 201610319287
- Application, EPODOC
- CN20161319287
Titles5
- Chinese
- 一种密钥保护方法
- English
- One kind of key protection method
- English
- Key protection method
- Chinese
- 种密钥保护方法
- Chinese
- _种密钥保护方法
Classification
- IPC, 2
- H04L9 08
- H04L9 06