WO2016190476A1 - 클라우드 서비스를 위한 암호화 키 관리 방법 및 그 장치 - Google Patents

클라우드 서비스를 위한 암호화 키 관리 방법 및 그 장치 Download PDF

Info

Publication number
WO2016190476A1
WO2016190476A1 PCT/KR2015/006238 KR2015006238W WO2016190476A1 WO 2016190476 A1 WO2016190476 A1 WO 2016190476A1 KR 2015006238 W KR2015006238 W KR 2015006238W WO 2016190476 A1 WO2016190476 A1 WO 2016190476A1
Authority
WO
WIPO (PCT)
Prior art keywords
key
service
master
host
master key
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/KR2015/006238
Other languages
English (en)
French (fr)
Inventor
유인선
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Samsung SDS Co Ltd
Original Assignee
Samsung SDS Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Samsung SDS Co Ltd filed Critical Samsung SDS Co Ltd
Publication of WO2016190476A1 publication Critical patent/WO2016190476A1/ko
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/061Network architectures or network communication protocols for network security for supporting key management in a packet data network for key exchange, e.g. in peer-to-peer networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/062Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/602Providing cryptographic facilities or services
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0822Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/085Secret sharing or secret splitting, e.g. threshold schemes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/062Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying encryption of the keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0894Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions

Definitions

  • the present invention relates to a method and apparatus for managing a service key for encrypting data and critical credentials of a cloud service and a master key for encrypting a service key.
  • Numerous data or critical credentials that require security are encrypted using an encryption key.
  • the encryption key is stored in plain text in the database, there is a risk that the stored encryption key may be leaked by a database administrator (DBA) or an insider.
  • DBA database administrator
  • HSM hardware security module
  • the provider of the hardware security module knows the master key that encrypts the encryption key.
  • the encryption key is encrypted using a homomorphic algorithm or the like, when the master key encrypting the encryption key is lost, the encrypted data may no longer be recovered. Therefore, there is a demand for a solution capable of simultaneously securing the confidentiality and availability of the encryption key.
  • the technical problem to be solved by the present invention after encrypting the service key that can decrypt the data and critical entitlements of the cloud service with a separate master key, and generates a plurality of key pieces that can be regenerated only in a specific condition to provide a method and apparatus for distributed storage in two servers.
  • a key management method encrypting a service key used by an instance of a first user of a cloud service using a master key, the master key Generating at least two key fragments for regeneration; distributing and storing the key fragments at at least two host servers included in a host group for providing the cloud service; from the instance of the first user, the service Receiving a request for providing a key, receiving the key pieces from the two or more host servers, regenerating the master key based on the received key pieces, and regenerating the encrypted service key with the regenerated master key. And decoding using the same.
  • a key management system for encrypting a service key used by an instance of a first user of a cloud service using a master key, and then for regenerating the master key.
  • a key access server that generates and stores two or more key pieces, and decodes the encrypted service key by regenerating a master key based on the distributed and stored key pieces when a request for providing a service key is received from an instance of the first user.
  • a host server that receives and stores the key fragment from the key access server, and transmits the key fragment when a request for providing the key fragment is received from the key access server.
  • a master key to encrypt a service key used by an instance of a first user of a cloud service
  • the master key Generating at least two key fragments for regeneration; distributing and storing the key fragments at at least two host servers included in a host group for providing the cloud service; from an instance of the first user, a service key Receiving a provision request, receiving the key pieces from the two or more host servers, regenerating the master key based on the received key pieces, and using the regenerated master key with the encrypted service key.
  • a computer recorded on a recording medium for executing the decoding step A program can be provided.
  • the confidentiality of the master key can be secured.
  • the master key can be regenerated, thereby ensuring the availability of the master key.
  • the master key cannot be regenerated by the leaked key piece alone.
  • FIGS. 1 to 3 are conceptual diagrams of a cloud service system according to some embodiments of the present invention.
  • FIG. 4 is a flowchart illustrating a master key distribution storage method according to an embodiment of the present invention.
  • FIG. 5 is a flowchart illustrating a master key regeneration method according to an embodiment of the present invention.
  • FIG. 6 is a signal flow diagram illustrating a master key distribution storage method according to another embodiment of the present invention.
  • FIG. 7 is a signal flowchart illustrating a master key regeneration method according to another embodiment of the present invention.
  • FIG. 8 is a block diagram of a key access server according to an embodiment of the present invention.
  • FIG. 9 is a hardware configuration diagram of a key access server according to an embodiment of the present invention.
  • the cloud service is a service that allows a local computing device to store various data in an external server connected to a network and, if necessary, download and use the data from an external server. More specifically, an instance of a local computing device may store data in an external server connected to the network, not in an internal storage space. In addition, when data stored in an external server is required, the instance of the local computing device may download and use data from an external server.
  • the cloud service according to an embodiment of the present invention may be an infrastructure as a service (IAAS) or software as a service (AIAS) capable of providing a virtualized infrastructure environment to a local computing device. It is not limited to this.
  • Service keys are keys that instances running through cloud services use to decrypt data. Such a service key may be set to have a different value according to a user of the cloud service, a service provided through the cloud service, or an application of a service provided through the cloud service. In addition, the service key may have different sizes or types depending on the user of the cloud service, the service provided through the cloud service, or the application of the service provided through the cloud service, but is not limited thereto.
  • the master key is the key used to decrypt the service key.
  • Such a master key may be generated to have different values depending on the user of the cloud service, a service provided through the cloud service, or a business related to the cloud service, but is not limited thereto.
  • FIGS. 1 to 3 are conceptual diagrams of a cloud service system according to some embodiments of the present invention.
  • Each component of the cloud service system disclosed in FIGS. 1 to 3 represents functionally divided functional elements, and any one or more components may be integrated with each other in an actual physical environment.
  • a cloud service system may include a key management system 10 and a plurality of service apparatuses 400.
  • the key management system 10 may include a key access server 100, a plurality of host servers 200, and a key management database 300.
  • a key access server 100 may include a key access server 100, a plurality of host servers 200, and a key management database 300.
  • the key access server 100 is a server capable of distributing and managing a master key capable of encrypting and decrypting a service key used by an instance of a cloud service.
  • the key access server 100 after encrypting the service key using the master key, generates a plurality of key pieces that can regenerate the master key only under a specific condition, the generated key The pieces may be distributed and stored in the plurality of host servers 200.
  • the key access server 100 may regenerate the master key based on the key pieces received from the plurality of host servers 200, and decrypt the service key using the regenerated master key.
  • the key access server 100 will be described in detail later with reference to FIGS. 2 to 9.
  • the plurality of host servers 200 are servers capable of receiving and storing key pieces from the key access server 100. More specifically, the plurality of host servers 200 are servers in which a key management agent is installed among homogeneous or heterogeneous servers for providing cloud services.
  • the plurality of host servers 200 may include a user management server, a server coordinator device, a data analysis server, an event management server, or a big data storage server in which an agent for key management is installed, but is not limited thereto.
  • a dedicated server for key management may be included.
  • Such a plurality of host servers 200 may form a host group 20.
  • the plurality of host servers 200 included in the host group 20 may receive and store key pieces from the key access server 100.
  • the plurality of host servers 200 may extract the stored key pieces and transmit them to the key access server 100 in response to a request of the key access server 100.
  • the plurality of host servers 200 included in the host group 20 may encrypt the key pieces by using an encryption key and then transmit the encrypted key pieces to the key access server 100.
  • the encryption key may be preset differently for each host server 200, but is not limited thereto.
  • the encryption key may be shared with the key access server 100 by designating a temporary key in real time.
  • the plurality of host servers 200 included in the host group 20 use the data for key fragment verification published by the key access server 100 to determine whether the key access server 100 is a malicious server. You can judge whether or not.
  • the plurality of host servers 200 included in the host group 20 receive the key pieces from the key access server 100, and then calculate a hash value of the received key pieces to calculate the key values. Can be sent to.
  • the plurality of host servers 200 included in the host group 20 generate a random seed to guarantee generation of a random and unique master key according to a request of the key access server 100. It may transmit to the access server 100.
  • the key management database 300 is a database that can store the service key encrypted using the master key. More specifically, the key management database 300 may store an encrypted service key received from the key access server 100. In addition, the key management database 300 may include a master key table and a service key table.
  • the host server 200 stores the identification of the master key, the identifier of the user of the cloud service, the identifier of the service key, the creation date and time of the master key, the hash value of the master key, or the key fragment of the master key in the master key table. ) May be included, but is not limited thereto.
  • the service key table may include an identifier of a service key, an identifier of a user of a cloud service, a service key usage history, and the like, but is not limited thereto.
  • the key management database 300 may be a component independent from the key access server 100, but is not limited thereto, and may be one component constituting the key access server 100. Will be self-explanatory. Further, the key management database 300 may be a relational database in which a relation exists between a master key table and a service key table, but is not limited thereto.
  • the service device 400 is a server that provides a cloud service. More specifically, the service device 400 may be virtualized through a hypervisor.
  • the hypervisor is a platform that allocates resources and other resources of the service device 400 and provides an interface for resource management and monitoring.
  • the service device 400 may execute an application or an instance of an application for a cloud service through a virtualized virtual machine.
  • An instance of the service device 400 may encrypt data of a cloud service using a service key.
  • the service device 400 may request protection by transmitting the service key to the key access server 100.
  • the service device 400 may receive the service key from the key access server 100 and then decrypt the data of the cloud service using the received service key.
  • the service device 400 may transmit / receive data with the key access server 100 using a Key Management Interoperability Protocol (KMIP).
  • KMIP Key Management Interoperability Protocol
  • the service device 400 may transmit / receive data with the key access server 100 using a Secure Sockets Layer / Transport Layer Security Protocol (SSL / TLS Protocol).
  • SSL / TLS Protocol Secure Sockets Layer / Transport Layer Security Protocol
  • the cloud service system according to another exemplary embodiment of the present invention may further include a gateway 500 and a data bus device 600.
  • a gateway 500 and a data bus device 600.
  • the components additionally included in the cloud service system according to another embodiment of the present invention will be described in detail.
  • the gateway 500 may control access between the service device 400 and the key management system 10. More specifically, the gateway 500 may restrict access to a server included in the key management system 10 of the service device 400. In addition, the gateway 500 may restrict access to the service device 400 of the server included in the key management system 10.
  • the gateway 500 may provide an application programming interface (API) to the service device 400 according to a Representational State Transfer (REST) architecture.
  • the gateway 500 may transmit an event according to the data received from the service device 400 to the data bus device 600.
  • API application programming interface
  • REST Representational State Transfer
  • the data bus device 600 may control data transmission between servers included in the key management system 10. More specifically, the data bus device 600 may transmit an event received from the gateway 500 to the key access server 100 or the host server 200. In addition, the data bus device 600 may control data transmission between the key access server 100 or the host server 200.
  • the key access server 100 may transmit and receive key fragments directly with the host server 200 without using the data bus device 600. Can be.
  • a plurality of key access servers 100 may be clustered and constructed.
  • the components additionally included in the cloud service system according to another embodiment of the present invention will be described in detail.
  • the memory-based database 700 may store a master key repeatedly used by the key access server 100 in a memory in order to improve the speed of access to the master key of the key access server 100. More specifically, the memory based database 700 may receive the master key regenerated by the key access server 100. The memory-based database 700 may store the regenerated master key in memory. The memory based database 700 may receive a master key provision request from the key access server 100. The memory-based database 700 may transmit the master key stored in the memory to the key access server 100 in response to the master key provision request.
  • FIG. 4 is a flowchart illustrating a master key distribution storage method according to an embodiment of the present invention.
  • the key access server 100 receives a service key from an instance of the service device 400 (S105).
  • the service key is a key used for encrypting and decrypting data by an instance of a cloud service user.
  • a service key may have different sizes or types depending on the user of the cloud service, a service provided through the cloud service, or an application of a service provided through the cloud service, but is not limited thereto.
  • the key access server 100 may receive a service key from an instance of the service device 400 using a key management interoperation protocol (KMIP), but is not limited thereto.
  • KMIP key management interoperation protocol
  • the key access server 100 receives the identifier of the cloud service user and the identifier of the service key from the instance of the service apparatus 400 before receiving the service key from the instance of the service apparatus 400, and receives the received service.
  • the instance may be authenticated using the identifier of the user and the identifier of the service key, but is not limited thereto.
  • the key access server 100 generates a master key for encrypting the received service key (S110).
  • the key access server 100 requests a random seed from the host server 200.
  • the key access server 100 generates a master key according to a predetermined random generation mechanism based on the random seed received from the host server 200.
  • the master key generated by the key access server 100 may have a random and unique value according to a tenant of the cloud service, a service provided through the cloud service, a business related to the cloud service, and the like.
  • the key access server 100 receives a random seed from the host server 200 stably connected when a new master key is needed, and generates a master key based on the received random seed, thereby generating a master key value. Can lower the predictability of
  • the key access server 100 encrypts the service key by using the generated master (S115).
  • the key access server 100 stores the encrypted service key in the key management database 300 (S120).
  • the key access server 100 generates two or more key pieces for regenerating the master key (S125).
  • the key access server 100 may generate a key fragment capable of regenerating the master key only when there is a threshold or more.
  • a method of generating a key fragment of the key access server 100 will be described in more detail.
  • k be the threshold number of key fragments that the key access server 100 needs to minimum to regenerate the master key.
  • the threshold number k may be 3, but is not limited thereto.
  • the key access server 100 generates k ⁇ 1 random numbers. Let each random number generated by the key access server 100 be a k-1 , a k-2 , ..., a 1 . The key access server 100 then sets a 0 as the master key.
  • the key access server 100 has a k- order polynomial f (x) where the coefficients of the first to k-first terms are a k-1 , a k-2 , ..., a 1 , and the coefficients of the zero-order term are a 0 .
  • the polynomial f (x) generated by the key access server 100 is represented by Equation 1 below.
  • f (0) becomes a master key.
  • the key management system 10 may generate n key pieces having a completely different form from the master key.
  • the key access server 100 may generate a mod by dividing the function value of the polynomial f (x) by the maximum size that the master key can have as a key fragment.
  • the generated key pieces may all be the same size.
  • the key management system 10 generates the key pieces with the same size of all the key pieces, so that even if some of the key pieces are leaked to the outside or the inside, It is difficult to predict the master key on the basis.
  • the key access server 100 encrypts the generated n key pieces using different encryption keys for each host server 200 (S130).
  • the encryption key may be specified to be different for each host server 200.
  • the encryption key may be set in the key access server 100 at the time the agent for key management is installed in the host server 200, but the encryption key is not limited thereto. 200).
  • the key management system 10 encrypts the key pieces using different encryption keys for each host server 200, so that the encrypted key pieces of the first host server 200 may be removed. Even if the second host server 200 is leaked, the second host server 200 whose encryption key of the first host server 200 is unknown cannot decrypt the encrypted key fragment.
  • the key access server 100 distributes and stores the n encrypted key pieces to the n host server 200 (S135). More specifically, the key access server 100 may transmit the key fragment to the host server 200 using a key sharing protocol.
  • the key distribution protocol is a unique protocol defined so that data transmission and reception between the host server 200 included in the host group 20 is not allowed.
  • the key distribution protocol is a protocol defined to allow data transmission and reception only when one side of data transmission and reception is the key access server 100.
  • the key access server 100 includes a cloud of the user regarding the master key that is the basis of the key fragment.
  • the host server 200 not related to the service may be selected. That is, the key access server 100 may distribute and store the master key for the first user in the host server 200 which is not related to the cloud service provided to the first user.
  • the key management system 10 distributes and stores a master key for a first user in a host server 200 that is not associated with a cloud service provided to the first user.
  • a person having a close relationship with the server cannot collect key pieces from the host server 200 associated with the cloud service of the first user.
  • the key access server 100 receives hash values from the n host servers 200 in which the key pieces are distributed and stored (S140). Then, the key access server 100 compares the received hash value and the hash value of the generated key pieces, and determines whether they are the same (S145). As a result of determination, when there are different hash values among the hash values received from the n host servers 200 and the hash values of the respective key pieces generated based on the master key, the key access server 100 may determine the corresponding host. The encrypted key fragment may be sent back to the server 200.
  • the key access server 100 hashes each of the key pieces. The value is stored in the key management database 300. If the master key is stored in the memory or the storage, the key access server 100 deletes the stored master key (S150).
  • the key management system 10 encrypts the service key used for the cloud service with a separate master key, and then regenerates the master key only when there is a threshold number or more. It is possible to secure the confidentiality of the master key by generating the distributed storage, and do not store the master key in any server or device.
  • FIG. 5 is a flowchart illustrating a master key regeneration method according to an embodiment of the present invention.
  • the key access server 100 receives a request for providing a service key from an instance of the service device 400 (S205).
  • the key access server 100 may receive a request for providing a service key from an instance of the service device 400 by using a secure socket layer / transport layer security protocol (SSL / TLS Protocol), but is not limited thereto.
  • SSL / TLS Protocol secure socket layer / transport layer security protocol
  • the key access server 100 receives the identifier of the cloud service user and the identifier of the service key from the instance of the service apparatus 400 before receiving the request for providing the service key from the instance of the service apparatus 400,
  • the instance may be authenticated using the received identifier of the service user and the identifier of the service key, but is not limited thereto.
  • the key access server 100 determines whether there is a master key for the instance requesting the provision of the service key in the memory of the key access server 100 or the memory-based database 700 (S210).
  • the key access server 100 encrypts the key fragment request message using the encryption key for each identified host server 200 (S215).
  • the key access server 100 transmits an encrypted key fragment request message to each identified host server 200 (S220).
  • the key access server 100 does not transmit the encrypted key fragment request message to all of the n host servers 200 that store and store the key pieces, but the n host servers 200 that store and store the key pieces.
  • the encrypted key fragment request message may be transmitted only to the host server 200 that is greater than or equal to the threshold number k of key fragments required for regenerating the master key.
  • the key access server 100 may transmit an encrypted key fragment request message using a key distribution protocol.
  • the key distribution protocol is a unique protocol defined so that data transmission and reception between the host server 200 included in the host group 20 is not allowed.
  • the key distribution protocol is a protocol defined to allow data transmission and reception only when one side of data transmission and reception is the key access server 100.
  • the key access server 100 receives an encrypted key fragment from each host server 200 that transmitted the key fragment request message (S225).
  • the key access server 100 may receive an encrypted key fragment using a key distribution protocol.
  • the key access server 100 decrypts each encrypted key fragment by using an encryption key for the host server 200 which transmitted the key fragment request message (S230).
  • the key access server 100 compares the hash value of each decrypted key piece with the hash value stored in the key management database 300 to determine whether they are the same (S235). As a result of determination, when a hash value of each decrypted key piece and a hash value stored among the hash values stored in the key management database 300 exist, the key access server 100 encrypts the host server 200. The key transfer request message can be sent again.
  • the key access server 100 regenerates the master key based on the key piece (S240). .
  • the key access server 100 may regenerate the master key using Lagrange interpolation.
  • the master key regeneration method of the key access server 100 will be described in detail.
  • the key access server 100 may calculate the master key f (0) using Equation 2 below.
  • the key management system 10 regenerates the master key when there are fewer key pieces than the threshold number k among the n key pieces distributed in the n host servers 200.
  • the master key can only be regenerated if there are a number of key fragments greater than or equal to the threshold number k.
  • the key access server 100 may store the regenerated master key in the memory-based database 700 (S245). If the memory management database 10 is not included in the key management system 10 according to an embodiment of the present invention, it will be apparent to those skilled in the art that this step may be omitted.
  • the key access server 100 extracts the encrypted service key associated with the request of the instance from the key management database 300 (S250).
  • the key access server 100 decrypts the encrypted service key using the master key (S255).
  • the key access server 100 transmits the decrypted service key to the instance of the service device 400 (S260).
  • the key management system 10 can regenerate the master key even if a part of the distributed and stored key pieces are lost, thereby ensuring the availability of the master key.
  • the key pieces are encrypted with different encryption keys, so that the leaked key pieces alone cannot reproduce the master key.
  • FIG. 6 is a signal flow diagram illustrating a master key distribution storage method according to another embodiment of the present invention.
  • the instance of the service device 400 encrypts the data of the cloud service with the service key and then transmits the service key to the key access server 100 (S305).
  • the instance of the service device 400 may transmit the service key to the key access server 100 using the key management interoperation protocol (KMIP), but is not limited thereto.
  • KMIP key management interoperation protocol
  • the key access server 100 generates a master key for encrypting the received service key (S310).
  • the key access server 100 encrypts the received service key by using the generated master key (S315).
  • the key access server 100 transmits the encrypted service key to the key management database 300 (S320).
  • the key management database 300 stores the encrypted service key in response to receiving the encrypted service key (S325).
  • the key access server 100 generates two or more key pieces for regenerating the master key (S330). Specifically, the key access server 100 may generate a key piece that can regenerate the master key only when there is a threshold number or more.
  • the detailed description of the key fragment generation method of the key access server 100 is the same as described above with reference to FIG.
  • the key access server 100 encrypts key pieces by using different encryption keys for each host server 200 (S335).
  • the encryption key may be set in the key access server 100 when the agent for key management is installed in the host server 200, but is not limited thereto, and receives a temporary key specified in real time from the host server 200. You may.
  • the key access server 100 transmits each encrypted key piece to the host servers 200 (S340).
  • the key access server 100 may transmit the key fragments to the host servers 200 using a key distribution protocol.
  • the host server 200 decrypts the received key fragment by using each encryption key (S345).
  • the host server 200 generates a hash value of the decrypted key piece (S350).
  • the host server 200 stores the decrypted key pieces (S355).
  • the host servers 200 transmit the generated hash value to the key access server 100.
  • the key access server 100 compares the hash values received from the host servers 200 with the hash values of the key pieces generated based on the master key, and determines whether they are the same (S365). As a result of the determination, when there are different hash values among the hash values received from the host servers 200 and the hash values of the key pieces generated based on the master key, the key access server 100 may determine the corresponding host server 200. You can resend the encrypted key fragments at.
  • the key access server 100 may determine the master key stored in the memory or the storage. Delete (S370).
  • FIG. 7 is a signal flowchart illustrating a master key regeneration method according to another embodiment of the present invention. Hereinafter, it is assumed that the master key does not exist in the memory of the key access server 100 and the memory-based database 700.
  • the instance of the service device 400 transmits a request for providing a service key to the key access server 100 in order to decrypt data of a cloud service (S405).
  • the instance of the service device 400 may transmit a request for providing a service key to the key access server 100 by using a secure socket layer / transport layer security protocol (SSL / TLS Protocol), but is not limited thereto. no.
  • SSL / TLS Protocol secure socket layer / transport layer security protocol
  • the key access server 100 In response to receiving the request for providing the service key, the key access server 100 identifies the host servers 200 that store and store the key pieces of the master key for decrypting the service key. The key access server 100 encrypts each key fragment request message by using an encryption key for each identified host server 200 (S410). The key access server 100 transmits an encrypted key fragment request message to each identified host server 200 (S415).
  • the host server 200 decrypts the encrypted key fragment request message with each encryption key.
  • the host servers 200 verify whether the key access server 100 is a malicious server (S420). Hereinafter, the verification method using the ideal number proposed by Feldman of the host server 200 will be described in more detail.
  • the encrypted values E (a), E (a 1 ), ..., E (a t-1 ) of the coefficient t of the function that the key access server 100 generated the key fragments for the host servers 200. ) Is open to the public.
  • the host server 200 i may determine that the key access server 100 is a malicious server when Equation 3 below does not hold.
  • the host servers 200 are not limited to the verification method proposed by Feldman, and may verify the key access server 100 using the verification method proposed by Federson.
  • the host servers 200 extract key pieces stored in each, and encrypt the extracted key pieces with respective encryption keys (S425).
  • the host servers 200 transmit the encrypted key pieces to the key access server 100 (S430).
  • the key access server 100 decrypts the encrypted key fragment by using an encryption key for each host server 200 which has transmitted the key fragment (S435). Then, the key access server 100 transmits a request for providing a hash value of the key piece to the key management database 300 (S440).
  • the key management database 300 extracts the hash value of the key piece in response to the request for providing the hash value of the key piece (S445).
  • the key management database 300 transmits the extracted hash value to the key access server 100 (S450).
  • the key access server 100 compares the hash value of the decrypted key piece with the hash value received from the key management database 300 and determines whether they are the same (S455). As a result of determination, when a hash value of the decrypted key piece and a hash value different from the hash value received from the key management database 300 exist, the key access server 100 encrypts the encrypted key piece in the corresponding host server 200. The request message can be sent again.
  • the key access server 100 regenerates the master key based on the key piece (S460).
  • the key access server 100 may regenerate the master key using Lagrange interpolation. A more detailed description of the master key regeneration method of the key access server 100 is the same as described above with reference to FIG. 5 and will not be repeated.
  • the key access server 100 transmits an encrypted service key provision request to the key management database 300 (S465).
  • the key management database 300 extracts the encrypted service key in response to the encrypted service key provision request (S470).
  • the key management database 300 transmits the extracted encrypted service key to the key access server 100 (S475).
  • the key access server 100 decrypts the encrypted service key by using the regenerated master key (S480).
  • the key access server 100 transmits the decrypted service key to the instance of the service device 400 (S485).
  • the methods according to the embodiments of the present invention described with reference to FIGS. 4 to 7 may be performed by executing a computer program implemented in computer readable code.
  • the computer program may be transmitted from the first computing device to the second computing device and installed in the second computing device via a network such as the Internet, thereby being used in the second computing device.
  • the first computing device and the second computing device may be a fixed computing device such as a desktop, a server, or a workstation, a smartphone, a tablet, a tablet.
  • a mobile computing device such as a laptop, and a wearable computing device such as a smart watch, smart glasses, or a smart band.
  • the key access server 100 may include a communication unit 105, a storage unit 110, a master key generation unit 115, a service key decryption unit 120, a master key distribution storage unit 125, and the like.
  • the master key regenerator 130 may be included.
  • the communication unit 205 can transmit and receive data to and from the host server 200 using a key distribution protocol.
  • the communication unit 205 may create a query for requesting data provision and transmit / receive data with the key management database 300.
  • the communication unit 205 may transmit / receive data with the service device 400 using a key management interoperation protocol (KMIP) or a secure socket layer / transport layer security protocol (SSL / TLS Protocol).
  • KMIP key management interoperation protocol
  • SSL / TLS Protocol secure socket layer / transport layer security protocol
  • the storage unit 110 may store data necessary for the operation of the key access server 100.
  • the storage unit 110 may speed up access to the master key.
  • the master key 135 may be further stored in the memory-based storage.
  • the master key generation unit 115 may generate a master key for encrypting the service key.
  • the master key generation unit 115 transmits a random seed request to the host server 200 through the communication unit 105.
  • the master key generation unit 115 receives a random seed from the host server 200 through the communication unit 105.
  • the master key generator 115 generates a master key based on a random random generation mechanism based on a random seed. Accordingly, the master key generated by the master key generation unit 115 may have a random and unique value according to the tenant of the cloud service, a service provided through the cloud service, or a business related to the cloud service.
  • the master key generator 115 receives a random seed from the host server 200 stably connected when a new master key is needed, and generates a master key based on the received random seed, thereby generating a master key.
  • the predictability of the value can be lowered.
  • the service key encryption / decryption unit 120 may encrypt the service key based on the master key generated by the master key generation unit 115.
  • the service key decryption unit 120 may decrypt the encrypted service key when the master key is regenerated through the master key regeneration unit 130.
  • the master key distribution storage unit 125 may generate two or more key pieces for regenerating the master key, and transmit the generated key pieces through the communication unit 105.
  • the master key distribution storage unit 125 may generate a key piece capable of regenerating the master key only when there is a threshold number or more.
  • the detailed description of the key fragment generation method of the master key distribution storage unit 125 is the same as described above with reference to FIG. 4 and thus will not be repeated.
  • the master key distribution storage unit 125 may encrypt each of the key pieces using different encryption keys for each host server 200.
  • the master key distribution storage unit 125 may transmit each encrypted key piece to the host servers 200 through the communication unit 105.
  • the master key distribution storage unit 125 may receive a hash value through the communication unit 105.
  • the master key distribution storage unit 125 may compare the received hash value with the hash value of the key fragment and determine whether they are the same.
  • the master key regenerator 130 may regenerate the master key using two or more key pieces.
  • the master key regeneration unit 130 may receive an encrypted key fragment through the communication unit 105.
  • the master key regenerator 130 may decrypt the encrypted key fragment using the encryption key for each host server 200 that has transmitted the key fragment.
  • the master key regeneration unit 130 may receive a hash value from the key management database 300 through the communication unit 105.
  • the master key regenerator 130 may compare the hash value of the decrypted key piece with the hash value received from the key management database 300 to determine whether they are the same.
  • the master key regenerator 130 may regenerate the master key based on the decrypted key piece.
  • the master key regeneration unit 130 may regenerate the master key by using lag range interpolation.
  • a more detailed description of the master key regeneration method of the master key regeneration unit 130 is the same as described above with reference to FIG. 5 and will not be repeated.
  • each component of FIG. 8 may refer to software or hardware such as a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC). Can be.
  • the components are not limited to software or hardware, and may be configured to be in an addressable storage medium, or may be configured to execute one or more processors.
  • the functions provided in the above components may be implemented by more detailed components, or may be implemented as one component that performs a specific function by combining a plurality of components.
  • the key access server 100 may include a processor 155, a memory 160, a network interface 165, a data bus 170, and a storage 175.
  • the memory 160 may reside in the computer program data 180a in which the key management method is implemented. In addition, when the key access server 100 repeatedly uses the master key, the memory 160 may further store the master key 135.
  • the network interface 165 may exchange data with the host server 200 and the key management database 300. In addition, the network interface 165 may exchange data with the service device 400.
  • the data bus 170 is connected to the processor 155, the memory 160, the network interface 165, and the storage 175, and is a moving path for transferring data between the components.
  • the storage 175 may store an API, a library, or a resource file necessary for executing a computer program.
  • the storage 175 may store computer program data 180b in which a key management method is implemented.
  • the storage 175 includes instructions for encrypting a service key used by an instance of the first user of the cloud service using the master key, and generating two or more key pieces for regenerating the master key.
  • Computer program RAM can be stored.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • Power Engineering (AREA)
  • Storage Device Security (AREA)

Abstract

본 발명의 일 실시예들에 따른 키 관리 방법은, 클라우드 서비스의 제1 이용자의 인스턴스에 의하여 사용되는 서비스 키를 마스터 키를 이용하여 암호화하는 단계, 상기 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성하는 단계, 상기 클라우드 서비스의 제공을 위한 호스트 그룹에 포함된 둘 이상의 호스트 서버에, 상기 키 조각을 분산하여 저장하는 단계, 상기 제1 이용자의 인스턴스로부터, 상기 서비스 키의 제공 요청을 수신하는 단계, 상기 둘 이상의 호스트 서버로부터 상기 키 조각들을 수신하고, 상기 수신된 키 조각을 기초로 상기 마스터 키를 재생성하는 단계 및 상기 암호화된 서비스 키를 상기 재생성된 마스터 키를 이용하여 복호화하는 단계를 포함할 수 있다.

Description

클라우드 서비스를 위한 암호화 키 관리 방법 및 그 장치
본 발명은 클라우드 서비스의 데이터 및 중요 자격(credential)들을 암호화하기 위한 서비스 키 및 서비스 키를 암호화하기 위한 마스터 키를 관리하기 위한 방법 및 그 장치에 관한 것이다.
보안이 필요한 수많은 데이터 또는 중요 자격들은 암호화 키(encryption key)를 이용하여 암호화된다. 그러나, 암호화 키가 데이터베이스(database)에 일반적인 텍스트(plain text)로 저장된 경우, 저장된 암호화 키가 데이터베이스 관리자(DataBase Administration, DBA) 또는 내부인에 의하여 유출될 수 있는 위험이 있다. 암호화 키가 하드웨어 보안 모듈(Hardware Security Module, HSM)을 이용하여 암호화된 경우, 암호화 키를 암호화한 마스터 키를 하드웨어 보안 모듈의 제공 업체가 알고 있는 한계가 있다. 또한, 암호화 키가 동형 알고리즘(homomorphic algorithm) 등을 이용하여 암호화된 경우, 암호화 키를 암호화한 마스터 키가 분실되면 더 이상 암호화된 데이터를 복구할 수 없게 되는 문제점이 있다. 따라서, 암호화 키의 비밀성 및 가용성을 동시에 확보할 수 있는 솔루션이 요구되고 있다.
본 발명이 해결하고자 하는 기술적 과제는, 클라우드 서비스의 데이터 및 중요 자격들을 암복호화할 수 있는 서비스 키를 별도의 마스터 키로 암호화한 후, 특정 조건에서만 마스터 키를 재생성할 수 있는 키 조각을 생성하여 복수 개의 서버에 분산 저장하기 위한 방법 및 그 장치를 제공하기 위한 것이다.
본 발명의 기술적 과제들은 이상에서 언급한 기술적 과제들로 제한되지 않으며, 언급되지 않은 또 다른 기술적 과제들은 아래의 기재로부터 통상의 기술자에게 명확하게 이해 될 수 있을 것이다.
상기 기술적 과제를 달성하기 위한 본 발명의 일 태양(Aspect)에 따른 키 관리 방법은, 클라우드 서비스의 제1 이용자의 인스턴스에 의하여 사용되는 서비스 키를 마스터 키를 이용하여 암호화하는 단계, 상기 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성하는 단계, 상기 클라우드 서비스의 제공을 위한 호스트 그룹에 포함된 둘 이상의 호스트 서버에, 상기 키 조각을 분산하여 저장하는 단계, 상기 제1 이용자의 인스턴스로부터, 상기 서비스 키의 제공 요청을 수신하는 단계, 상기 둘 이상의 호스트 서버로부터 상기 키 조각들을 수신하고, 상기 수신된 키 조각을 기초로 상기 마스터 키를 재생성하는 단계 및 상기 암호화된 서비스 키를 상기 재생성된 마스터 키를 이용하여 복호화하는 단계를 포함할 수 있다.
상기 기술적 과제를 달성하기 위한 본 발명의 다른 태양에 따른 키 관리 시스템은, 클라우드 서비스의 제1 이용자의 인스턴스에 의하여 사용되는 서비스 키를 마스터 키를 이용하여 암호화한 후, 상기 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성하여 분산 저장하고, 상기 제1 이용자의 인스턴스로부터 서비스 키 제공 요청이 수신되면, 상기 분산 저장된 키 조각을 기초로 마스터 키를 재생성하여 상기 암호화된 서비스 키를 복호화하는 키 액세스 서버 및 상기 키 액세스 서버로부터 상기 키 조각을 수신하여 저장하고, 상기 키 액세스 서버로부터 키 조각 제공 요청이 수신되면 상기 키 조각을 전송하는 호스트 서버를 포함할 수 있다.
상기 기술적 과제를 달성하기 위한 본 발명의 또 다른 태양에 따르면, 컴퓨팅 장치와 결합하여, 클라우드 서비스의 제1 이용자의 인스턴스에 의하여 사용되는 서비스 키를 마스터 키를 이용하여 암호화하는 단계, 상기 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성하는 단계, 상기 클라우드 서비스의 제공을 위한 호스트 그룹에 포함된 둘 이상의 호스트 서버에, 상기 키 조각을 분산하여 저장하는 단계, 상기 제1 이용자의 인스턴스로부터, 서비스 키 제공 요청을 수신하는 단계, 상기 둘 이상의 호스트 서버로부터 상기 키 조각들을 수신하고, 상기 수신된 키 조각을 기초로 상기 마스터 키를 재생성하는 단계 및 상기 암호화된 서비스 키를 상기 재생성된 마스터 키를 이용하여 복호화하는 단계를 실행시키기 위하여, 기록매체에 기록된 컴퓨터 프로그램이 제공될 수 있다.
상술한 바와 같은 본 발명에 따르면, 특정 조건에서만 마스터 키를 재생성할 수 있는 키 조각을 생성하여 복수 개의 서버에 분산 저장하고, 어떠한 서버 또는 장치에도 마스터 키를 저장하지 않음으로써, 마스터 키의 비밀성을 확보할 수 있다. 또한, 분산 저장된 키 조각의 일부가 분실되더라도 마스터 키를 재생성할 수 있어, 마스터 키의 가용성을 확보할 수 있다. 나아가, 키 조각이 유출되더라도, 유출된 키 조각만으로는 마스터 키를 재생성할 수 없는 효과가 있다.
도 1 내지 도 3은 본 발명의 몇몇 실시예에 따른 클라우드 서비스 시스템의 개념도이다.
도 4는 본 발명의 일 실시예에 따른 마스터 키 분산 저장 방법을 설명하기 위한 순서도이다.
도 5는 본 발명의 일 실시예에 따른 마스터 키 재생성 방법을 설명하기 위한 순서도이다.
도 6은 본 발명의 다른 실시예에 따른 마스터 키 분산 저장 방법을 설명하기 위한 신호 흐름도이다.
도 7은 본 발명의 다른 실시예에 따른 마스터 키 재생성 방법을 설명하기 위한 신호 흐름도이다.
도 8은 본 발명의 일 실시예에 따른 키 액세스 서버의 블록도이다.
도 9는 본 발명의 일 실시예에 따른 키 액세스 서버의 하드웨어 구성도이다.
본 발명의 이점 및 특징, 그리고 그것들을 달성하는 방법은 첨부되는 도면과 함께 상세하게 후술되어 있는 실시예들을 참조하면 명확해질 것이다. 그러나 본 발명은 이하에서 개시되는 실시예들에 한정되는 것이 아니라 서로 다른 다양한 형태로 구현될 것이며, 단지 본 실시예들은 본 발명의 개시가 완전하도록 하며, 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자에게 발명의 범주를 완전하게 알려주기 위해 제공되는 것이며, 본 발명은 청구항의 범주에 의해 정의될 뿐이다. 명세서 전체에 걸쳐 동일 참조 부호는 동일 구성 요소를 지칭한다.
본 명세서에 대한 설명에 앞서, 본 명세서에서 사용되는 몇몇 용어들에 대하여 설명하기로 한다.
클라우드 서비스(Cloud service)는 로컬 컴퓨팅 장치가 각종 데이터를 네트워크에 연결된 외부의 서버에 저장하고, 필요 시 외부의 서버로부터 다운로드하여 이용할 수 있는 서비스이다. 보다 구체적으로, 로컬 컴퓨팅 장치의 인스턴스(instance)는 내부의 저장공간이 아닌, 네트워크에 연결된 외부의 서버에 데이터를 저장할 수 있다. 그리고, 로컬 컴퓨팅 장치의 인스턴스는 외부의 서버에 저장된 데이터가 필요한 경우, 외부의 서버로부터 데이터를 다운로드하여 이용할 수 있다. 특히, 본 발명의 일 실시예에 따른 클라우드 서비스는 로컬 컴퓨팅 장치에 가상화된 인프라 환경을 제공할 수 있는 이아스(Infrastructure as a Service, IaaS) 또는 사아스(Software as a Service)가 될 수 있으나, 이에 한정되는 것은 아니다.
서비스 키(Service key)는 클라우드 서비스를 통해 실행되는 인스턴스가 데이터를 암복호화하기 위해 사용하는 키이다. 이러한, 서비스 키는 클라우드 서비스의 이용자(Tenant), 클라우드 서비스를 통해 제공되는 서비스 또는 클라우드 서비스를 통해 제공되는 서비스의 애플리케이션 등에 따라 서로 상이한 값을 가지도록 설정될 수 있다. 또한, 서비스 키는 클라우드 서비스의 이용자, 클라우드 서비스를 통해 제공되는 서비스 또는 클라우드 서비스를 통해 제공되는 서비스의 애플리케이션 등에 따라 서로 상이한 크기 또는 타입을 가질 수 있으나, 이에 한정되는 것은 아니다.
마스터 키(Master key)는 서비스 키를 암복호화하기 위해 사용되는 키이다. 이러한, 마스터 키는 클라우드 서비스의 이용자, 클라우드 서비스를 통해 제공되는 서비스 또는 클라우드 서비스와 관련된 비즈니스 등에 따라 서로 상이한 값을 가지도록 생성될 수 있으나, 이에 한정되는 것은 아니다.
이 밖에, 본 명세서에서 사용된 용어들은 실시예들을 설명하기 위한 것이며 본 발명을 제한하고자 하는 것은 아니다. 본 명세서에서, 단수형은 문구에서 특별히 언급하지 않는 한 복수형도 포함한다. 명세서에서 사용되는 "포함한다(comprises)" 및/또는 "이루어지다(made of)"는 언급된 구성요소, 단계, 동작 및/또는 소자는 하나 이상의 다른 구성요소, 단계, 동작 및/또는 소자의 존재 또는 추가를 배제하지 않는다.
이하, 본 발명에 대하여 첨부된 도면에 따라 보다 상세히 설명한다.
도 1 내지 도 3은 본 발명의 몇몇 실시예에 따른 클라우드 서비스 시스템의 개념도이다. 도 1 내지 도 3에 개시된 클라우드 서비스 시스템의 각각의 구성 요소들은 기능적으로 구분되는 기능 요소들을 나타낸 것으로서, 어느 하나 이상의 구성 요소가 실제 물리적 환경에서는 서로 통합되어 구현될 수 있다.
도 1을 참조하면, 본 발명의 일 실시예에 따른 클라우드 서비스 시스템은 키 관리 시스템(10) 및 복수 개의 서비스 장치(400)를 포함하여 구성될 수 있다. 그리고, 키 관리 시스템(10)은 키 액세스 서버(100), 복수 개의 호스트 서버(200) 및 키 관리 데이터베이스(300)를 포함하여 구성될 수 있다. 이하, 본 발명의 일 실시예에 따른 클라우드 서비스 시스템의 각각의 구성 요소에 대하여 구체적으로 설명한다.
키 액세스 서버(100)는 클라우드 서비스의 인스턴스에 의하여 사용되는 서비스 키를 암복호화할 수 있는 마스터 키를 분산하여 관리할 수 있는 서버이다. 특히, 본 발명의 일 실시예에 따른 키 액세스 서버(100)는 마스터 키를 이용하여 서비스 키를 암호화한 후, 특정 조건에서만 마스터 키를 재생성할 수 있는 복수 개의 키 조각을 생성하고, 생성된 키 조각을 복수 개의 호스트 서버(200)에 분산 저장할 수 있다. 또한, 키 액세스 서버(100)는 복수 개의 호스트 서버(200)로부터 수신된 키 조각을 기초로 마스터 키를 재생성하고, 재생성된 마스터 키를 이용하여 서비스 키를 복호화할 수 있다. 이와 같은, 키 액세스 서버(100)에 대해서는, 추후 도 2 내지 도 9를 참조하여 구체적으로 설명할 것이다.
다음으로, 복수 개의 호스트 서버(200)는 키 액세스 서버(100)로부터 키 조각을 수신하여 저장할 수 있는 서버이다. 보다 구체적으로, 복수 개의 호스트 서버(200)는 클라우드 서비스를 제공하기 위한 동종 또는 이종의 서버 중 키 관리를 위한 에이전트(Key management agent)가 설치된 서버이다. 예를 들어, 복수 개의 호스트 서버(200)에는 키 관리를 위한 에이전트가 설치된, 이용자 관리 서버, 서버 코디네이터 장치, 데이터 분석 서버, 이벤트 관리 서버 또는 빅 데이터 저장 서버 등이 포함될 수 있으나, 이에 한정되지 않고, 키 관리만을 위한 전용 서버가 포함될 수도 있다. 이러한, 복수 개의 호스트 서버(200)는 호스트 그룹(20)을 형성할 수 있다.
호스트 그룹(20)에 포함된 복수 개의 호스트 서버(200)는 키 액세스 서버(100)로부터 키 조각을 수신하여 저장할 수 있다. 그리고, 복수 개의 호스트 서버(200)는 키 액세스 서버(100)의 요청에 응답하여, 저장된 키 조각을 추출하여 키 액세스 서버(100)에 전송할 수 있다.
호스트 그룹(20)에 포함된 복수 개의 호스트 서버(200)는 암호화 키(encryption key)를 이용하여 키 조각을 암호화한 후, 암호화된 키 조각을 키 액세스 서버(100)에 전송할 수 있다. 여기서, 암호화 키는 호스트 서버(200)별로 상이하게 프리셋(preset)될 수 있으나, 이에 한정되지 않고, 실시간으로 임시 키(temporary key)를 지정하여 키 액세스 서버(100)와 공유할 수도 있다.
호스트 그룹(20)에 포함된 복수 개의 호스트 서버(200)는 키 액세스 서버(100)가 공개한 키 조각 검증을 위한 데이터를 이용하여, 키 액세스 서버(100)가 악의적인(malicious)인 서버인지 아닌지 판단할 수 있다.
호스트 그룹(20)에 포함된 복수 개의 호스트 서버(200)는 키 액세스 서버(100)로부터 키 조각을 수신한 후, 수신된 키 조각의 해시 값(Hash value)를 계산하여 키 액세스 서버(100)에 전송할 수 있다.
그리고, 호스트 그룹(20)에 포함된 복수 개의 호스트 서버(200)는 키 액세스 서버(100)의 요청에 따라, 무작위적이며 유일한 마스터 키의 생성을 보장하기 위한 랜덤 시드(seed)를 생성하여 키 액세스 서버(100)에 전송할 수 있다.
다음으로, 키 관리 데이터베이스(300)는 마스터 키를 이용하여 암호화된 서비스 키를 저장할 수 있는 데이터베이스이다. 보다 구체적으로, 키 관리 데이터베이스(300)는 키 액세스 서버(100)로부터 수신된 암호화된 서비스 키를 저장할 수 있다. 또한, 키 관리 데이터베이스(300)는 마스터 키 테이블 및 서비스 키 테이블을 포함하여 저장할 수 있다.
여기서, 마스터 키 테이블에는 마스터 키의 식별자(identification), 클라우드 서비스의 이용자의 식별자, 서비스 키의 식별자, 마스터 키의 생성일시, 마스터 키의 해시 값 또는 마스터 키의 키 조각이 분산 저장된 호스트 서버(200)의 식별자 등이 포함될 수 있으나, 이에 한정되는 것은 아니다.
그리고, 서비스 키 테이블에는 서비스 키의 식별자, 클라우드 서비스의 이용자의 식별자, 서비스 키 사용 이력 등이 포함될 수 있으나, 이에 한정되는 것은 아니다.
이러한, 키 관리 데이터베이스(300)는 키 액세스 서버(100)와 독립된 구성 요소가 될 수 있으나, 이에 한정되지 않고, 키 액세스 서버(100)를 구성하는 하나의 구성 요소가 될 수 있음은 통상의 기술자에게 자명할 것이다. 나아가, 키 관리 데이터베이스(300)는 마스터 키 테이블 및 서비스 키 테이블 등의 사이에 일정한 관계(relation)가 존재하는 관계형 데이터베이스(Relational DataBase, RDB)가 될 수 있으나, 이에 한정되는 것은 아니다.
다음으로, 서비스 장치(400)는 클라우드 서비스를 제공하는 서버이다. 보다 구체적으로, 서비스 장치(400)는 하이퍼바이저(Hypervisor)를 통하여, 가상화(virtualization)될 수 있다. 여기서, 하이퍼바이저는 서비스 장치(400)의 리소스 및 기타 자원을 할당하고, 자원 관리 및 모니터링을 위한 인터페이스를 제공하는 플랫폼이다. 그리고, 서비스 장치(400)는 가상화된 가상 머신(virtual machine)을 통하여, 클라우드 서비스를 위한 애플리케이션 또는 애플리케이션의 인스턴스를 실행시킬 수 있다.
서비스 장치(400)의 인스턴스는 서비스 키를 이용하여 클라우드 서비스의 데이터를 암호화할 수 있다. 서비스 장치(400)는 서비스 키를 키 액세스 서버(100)에 전송하여 보호를 요청할 수 있다. 또한, 서비스 장치(400)는 클라우드 서비스의 데이터가 필요한 경우, 키 액세스 서버(100)로부터 서비스 키를 수신한 후, 수신된 서비스 키를 이용하여 클라우드 서비스의 데이터를 복호화할 수 있다.
그리고, 서비스 장치(400)는 키 관리 상호운용 프로토콜(Key Management Interoperability Protocol, KMIP)을 이용하여, 키 액세스 서버(100)와 데이터를 송수신할 수 있다. 또한, 서비스 장치(400)는 보안 소켓 계층/전송 계층 보안 프로토콜(Secure Sockets Layer/Transport Layer Security Protocol, SSL/TLS Protocol)을 이용하여, 키 액세스 서버(100)와 데이터를 송수신할 수 있다.
도 2를 참조하면, 본 발명의 다른 실시예에 따른 클라우드 서비스 시스템은 게이트웨이(500) 및 데이터 버스 장치(600)를 더 포함할 수 있다. 이하, 본 발명의 다른 실시예에 따라 클라우드 서비스 시스템에 추가적으로 포함된 구성 요소에 대하여 구체적으로 설명한다.
게이트웨이(500)는 서비스 장치(400)와 키 관리 시스템(10) 사이의 접근을 제어할 수 있다. 보다 구체적으로, 게이트웨이(500)는 서비스 장치(400)의 키 관리 시스템(10) 내에 포함된 서버에 대한 접근을 제한할 수 있다. 또한, 게이트웨이(500)는 키 관리 시스템(10) 내에 포함된 서버의 서비스 장치(400)에 대한 접근을 제한할 수 있다.
그리고, 게이트웨이(500)는 서비스 장치(400)에 레스트(REpresentational State Transfer, REST) 아키텍처에 따른 에이피아이(Application Programming Interface, API)를 제공할 수 있다. 또한, 게이트웨이(500)는 서비스 장치(400)로부터 수신된 데이터에 따른 이벤트를 데이터 버스 장치(600)에 전송할 수 있다.
다음으로, 데이터 버스 장치(600)는 키 관리 시스템(10)에 포함된 서버들 사이의 데이터 전송을 제어할 수 있다. 보다 구체적으로, 데이터 버스 장치(600)는 게이트웨이(500)로부터 수신된 이벤트를 키 액세스 서버(100) 또는 호스트 서버(200) 등에 전송할 수 있다. 또한, 데이터 버스 장치(600)는 키 액세스 서버(100) 또는 호스트 서버(200) 사이의 데이터 전송을 제어할 수 있다.
다만, 키 관리 시스템(10)에 데이터 버스 장치(600)가 포함되어 있더라도, 키 액세스 서버(100)는 데이터 버스 장치(600)를 이용하지 않고, 호스트 서버(200)와 직접 키 조각을 송수신할 수 있다.
도 3을 참조하면, 본 발명의 또 다른 실시예에 따른 클라우드 서비스 시스템은 복수 개의 키 액세스 서버(100)가 클러스터링(clustering)되어 구축될 수 있다. 이하, 본 발명의 또 다른 실시예에 따라 클라우드 서비스 시스템에 추가적으로 포함된 구성 요소에 대하여 구체적으로 설명한다.
메모리 기반 데이터베이스(700)는 키 액세스 서버(100)의 마스터 키에 대한 접근 속도를 향상시키기 위하여, 키 액세스 서버(100)가 반복적으로 이용하는 마스터 키를 메모리에 저장할 수 있다. 보다 구체적으로, 메모리 기반 데이터베이스(700)은 키 액세스 서버(100)에 의하여 재생성된 마스터 키를 수신할 수 있다. 메모리 기반 데이터베이스(700)는 재생성된 마스터 키를 메모리에 저장(in-memory)할 수 있다. 메모리 기반 데이터베이스(700)는 키 액세스 서버(100)로부터 마스터 키 제공 요청을 수신할 수 있다. 메모리 기반 데이터베이스(700)는 마스터 키 제공 요청에 응답하여, 메모리에 저장된 마스터 키를 키 액세스 서버(100)에 전송할 수 있다.
이하, 본 발명의 일 실시예에 따른 키 액세스 서버(100)의 마스터 키 분산 저장 방법 및 마스터 키 재생성 방법에 대하여 구체적으로 설명한다.
도 4는 본 발명의 일 실시예에 따른 마스터 키 분산 저장 방법을 설명하기 위한 순서도이다.
도 4를 참조하면, 키 액세스 서버(100)는 서비스 장치(400)의 인스턴스로부터 서비스 키를 수신한다(S105). 여기서, 서비스 키는 클라우드 서비스 이용자의 인스턴스에 의하여, 데이터를 암복호화하기 위해 사용되는 키이다. 이러한, 서비스 키는 클라우드 서비스의 이용자, 클라우드 서비스를 통해 제공되는 서비스 또는 클라우드 서비스를 통해 제공되는 서비스의 애플리케이션 등에 따라 서로 상이한 크기 또는 타입을 가질 수 있으나, 이에 한정되는 것은 아니다. 또한, 키 액세스 서버(100)는 키 관리 상호운용 프로토콜(KMIP)을 이용하여, 서비스 장치(400)의 인스턴스로부터 서비스 키를 수신할 수 있으나, 이에 한정되는 것은 아니다.
나아가, 키 액세스 서버(100)는 서비스 장치(400)의 인스턴스로부터 서비스 키를 수신하기 이전에, 서비스 장치(400)의 인스턴스로부터 클라우드 서비스 이용자의 식별자 및 서비스 키의 식별자를 수신하고, 수신된 서비스 이용자의 식별자 및 서비스 키의 식별자를 이용하여 인스턴스를 인증할 수 있으나, 이에 한정되는 것은 아니다.
다음으로, 키 액세스 서버(100)는 수신된 서비스 키를 암호화하기 위한 마스터 키를 생성한다(S110). 구체적으로, 키 액세스 서버(100)는 호스트 서버(200)에 랜덤 시드(seed)를 요청한다. 키 액세스 서버(100)는 호스트 서버(200)로부터 수신된 랜덤 시드를 기초로, 기 지정된 랜덤 생성 매커니즘에 따라 마스터 키를 생성한다. 따라서, 키 액세스 서버(100)에 의해 생성된 마스터 키는 클라우드 서비스의 이용자(tenant), 클라우드 서비스를 통해 제공되는 서비스 또는 클라우드 서비스와 관련된 비즈니스 등에 따라 무작위적이며 유일한 값을 가질 수 있다. 또한, 키 액세스 서버(100)는 새로운 마스터 키가 필요한 시점에 안정적으로 연결된 호스트 서버(200)들로부터 랜덤 시드를 수신하고, 수신된 랜덤 시드를 기초로 마스터 키를 생성함으로써, 생성된 마스터 키 값의 예측 가능성을 낮출 수 있다.
다음으로, 키 액세스 서버(100)는 생성된 마스터를 이용하여, 서비스 키를 암호화한다(S115). 그리고, 키 액세스 서버(100)는 암호화된 서비스 키를 키 관리 데이터베이스(300)에 저장한다(S120).
다음으로, 키 액세스 서버(100)는 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성한다(S125). 구체적으로, 키 액세스 서버(100)는 임계 수(threshold) 이상이 존재하는 경우에만, 마스터 키를 재생성할 수 있는 키 조각을 생성할 수 있다. 이하, 키 액세스 서버(100)의 키 조각 생성 방법에 대하여 보다 구체적으로 설명한다.
키 액세스 서버(100)가 마스터 키를 재생성하기 위해 최소로 필요한 키 조각의 임계 수를 k라 하자. 예를 들어, 임계 수 k는 3이 될 수 있으나, 이에 한정되는 것은 아니다. 키 액세스 서버(100)는 k-1개의 난수(random number)를 생성한다. 키 액세스 서버(100)가 생성한 각각의 난수를 ak-1, ak-2, ..., a1라 하자. 그리고, 키 액세스 서버(100)는 a0를 마스터 키로 설정한다.
키 액세스 서버(100)는 1 내지 k-1차 항의 계수가 ak-1, ak-2, ..., a1이며, 0차 항의 계수가 a0인, k차수의 다항식 f(x)을 생성한다. 키 액세스 서버(100)가 생성한 다항식 f(x)는 아래의 수학식 1과 같다.
[수학식 1]
Figure PCTKR2015006238-appb-I000001
여기서, f(0)는 마스터 키가 된다.
키 액세스 서버(100)는 키 조각을 분산 저장할 n개의 호스트 서버(200)의 식별자에 대한 다항식 f(0)의 함수 값을 기초로 n개의 키 조각을 생성한다. 여기서, 1 < k <= n이다.
따라서, 본 발명의 일 실시예에 따른 키 관리 시스템(10)은 마스터 키와 전혀 상이한 형태의 n개의 키 조각을 생성할 수 있다.
또한, 키 액세스 서버(100)는 다항식 f(x)의 함수 값을 마스터 키가 가질 수 있는 최대 크기로 나눈 나머지(mod)를 키 조각으로 생성할 수도 있다. 이 경우, 생성된 키 조각의 크기는 모두 동일해질 수 있다.
따라서, 본 발명의 일 실시예에 따른 키 관리 시스템(10)은 모든 키 조각의 크기가 동일하게 키 조각을 생성함으로써, 만약 키 조각의 일부가 외부 또는 내부에 유출되더라도 유출된 키 조각의 크기를 기초로 마스터 키를 예측하기 곤란하다.
다음으로, 키 액세스 서버(100)는 호스트 서버(200)별로 상이한 암호화 키를 이용하여, 생성된 n개의 키 조각을 암호화한다(S130). 여기서, 암호화 키는 호스트 서버(200)별로 상이하도록 기 지정되어 있을 수 있다. 이러한, 암호화 키는 호스트 서버(200)에 키 관리를 위한 에이전트가 설치될 당시 키 액세스 서버(100)에 설정될 수 있으나, 이에 한정되지 않고, 실시간으로 지정된 임시 키(temporary key)를 호스트 서버(200)로부터 수신할 수도 있다.
따라서, 본 발명의 일 실시예에 따른 키 관리 시스템(10)은 호스트 서버(200)별로 상이한 암호화 키를 이용하여 키 조각을 암호화함으로써, 만약 제1 호스트 서버(200)의 암호화된 키 조각이 제2 호스트 서버(200)에 유출되더라도, 제1 호스트 서버(200)의 암호화 키를 알 수 없는 제2 호스트 서버(200)는 암호화된 키 조각을 복호화할 수 없다.
다음으로, 키 액세스 서버(100)는 n개의 암호화된 키 조각을 n개의 호스트 서버(200)에 분산 저장한다(S135). 보다 구체적으로, 키 액세스 서버(100)는 키 분산 프로토콜(key sharing protocol)을 이용하여, 키 조각을 호스트 서버(200)에 전송할 수 있다. 여기서, 키 분산 프로토콜은 호스트 그룹(20)에 포함된 호스트 서버(200) 사이의 데이터 송수신이 허용되지 않도록 정의된 고유의 프로토콜이다. 또한, 키 분산 프로토콜은 데이터 송수신의 일 측이 키 액세스 서버(100)인 경우에 한하여, 데이터 송수신이 허용되도록 정의된 프로토콜이다.
또한, 키 액세스 서버(100)는 호스트 그룹(20)에 포함된 호스트 서버(200) 중 키 조각을 저장할 호스트 서버(200)를 선택함에 있어, 키 조각의 기초가 된 마스터 키에 관한 이용자의 클라우드 서비스와 관련되지 않은 호스트 서버(200)를 선택할 수 있다. 즉, 키 액세스 서버(100)는 제1 이용자에 제공되는 클라우드 서비스와 관련되지 않은 호스트 서버(200)에 제1 이용자에 대한 마스터 키를 분산 저장할 수 있다.
따라서, 본 발명의 일 실시예에 따른 키 관리 시스템(10)은 제1 이용자에 제공되는 클라우드 서비스와 관련되지 않은 호스트 서버(200)에 제1 이용자에 대한 마스터 키를 분산 저장함으로써, 제1 이용자와 밀접한 관계를 가지는 자가 제1 이용자의 클라우드 서비스와 관련된 호스트 서버(200)로부터 키 조각을 수집할 수 없다.
다음으로, 키 액세스 서버(100)는 키 조각이 분산 저장된 n개의 호스트 서버(200)로부터 각각 해시 값을 수신한다(S140). 그리고, 키 액세스 서버(100)는 수신된 해시 값과 생성된 키 조각의 해시 값을 비교하여, 서로 동일한지 판단한다(S145). 판단 결과, n개의 호스트 서버(200)로부터 각각 수신된 해시 값과, 마스터 키를 기초로 생성된 각각의 키 조각의 해시 값 중 상이한 해시 값이 존재하는 경우, 키 액세스 서버(100)는 해당 호스트 서버(200)에 암호화된 키 조각을 다시 전송할 수 있다.
판단 결과, n개의 호스트 서버(200)로부터 각각 수신된 해시 값과, 마스터 키를 기초로 생성된 각각의 키 조각의 해시 값이 모두 동일한 경우, 키 액세스 서버(100)는 각각의 키 조각의 해시 값을 키 관리 데이터베이스(300)에 저장한다. 그리고, 키 액세스 서버(100)는 마스터 키가 메모리 또는 스토리지에 저장되어 있는 경우, 저장되어 있는 마스터 키를 삭제한다(S150).
따라서, 본 발명의 일 실시예에 따른 키 관리 시스템(10)은 클라우드 서비스에 사용되는 서비스 키를 별도의 마스터 키로 암호화한 후, 임계 수 이상이 존재하는 경우에만 마스터 키를 재생성할 수 있는 키 조각을 생성하여 분산 저장하고, 어떠한 서버 또는 장치에도 마스터 키를 저장하지 않음으로써, 마스터 키의 비밀성을 확보할 수 있다.
도 5는 본 발명의 일 실시예에 따른 마스터 키 재생성 방법을 설명하기 위한 순서도이다.
도 5를 참조하면, 키 액세스 서버(100)는 서비스 장치(400)의 인스턴스로부터 서비스 키의 제공 요청을 수신한다(S205). 키 액세스 서버(100)는 보안 소켓 계층/전송 계층 보안 프로토콜(SSL/TLS Protocol)을 이용하여, 서비스 장치(400)의 인스턴스로부터 서비스 키의 제공 요청을 수신할 수 있으나, 이에 한정되는 것은 아니다.
나아가, 키 액세스 서버(100)는 서비스 장치(400)의 인스턴스로부터 서비스 키의 제공 요청을 수신하기 이전에, 서비스 장치(400)의 인스턴스로부터 클라우드 서비스 이용자의 식별자 및 서비스 키의 식별자를 수신하고, 수신된 서비스 이용자의 식별자 및 서비스 키의 식별자를 이용하여 인스턴스를 인증할 수 있으나, 이에 한정되는 것은 아니다.
다음으로, 키 액세스 서버(100)는 키 액세스 서버(100)의 메모리 또는 메모리 기반 데이터베이스(700)에 서비스 키의 제공을 요청한 인스턴스에 관한 마스터 키가 존재하는지 판단한다(S210).
판단 결과, 키 액세스 서버(100)의 메모리 및 메모리 기반 데이터베이스(700)에 해당 마스터 키가 존재하지 않는 경우, 키 조각을 분산 저장하고 있는 n개의 호스트 서버(200) 중 마스터 키 재생성에 필요한 키 조각의 임계 수 k보다 크거나 같은 수의 호스트 서버(200)를 식별한다. 그리고, 키 액세스 서버(100)는 식별된 각각의 호스트 서버(200)에 대한 암호화 키를 이용하여, 키 조각 요청 메시지를 각각 암호화한다(S215).
다음으로, 키 액세스 서버(100)는 식별된 각각의 호스트 서버(200)에 암호화된 키 조각 요청 메시지를 전송한다(S220). 여기서, 키 액세스 서버(100)는 키 조각을 분산 저장하고 있는 n개의 호스트 서버(200) 모두에 암호화된 키 조각 요청 메시지를 전송하지 아니하고, 키 조각을 분산 저장하고 있는 n개의 호스트 서버(200) 중 마스터 키 재생성에 필요한 키 조각의 임계 수 k보다 크거나 같은 수의 호스트 서버(200)에 대해서만 암호화된 키 조각 요청 메시지를 전송할 수 있다.
또한, 키 액세스 서버(100)는 키 분산 프로토콜을 이용하여, 암호화된 키 조각 요청 메시지를 전송할 수 있다. 여기서, 키 분산 프로토콜은 호스트 그룹(20)에 포함된 호스트 서버(200) 사이의 데이터 송수신이 허용되지 않도록 정의된 고유의 프로토콜이다. 또한, 키 분산 프로토콜은 데이터 송수신의 일 측이 키 액세스 서버(100)인 경우에 한하여, 데이터 송수신이 허용되도록 정의된 프로토콜이다.
다음으로, 키 액세스 서버(100)는 키 조각 요청 메시지를 전송한 각각의 호스트 서버(200)로부터 암호화된 키 조각을 수신한다(S225). 키 액세스 서버(100)는 키 분산 프로토콜을 이용하여, 암호화된 키 조각을 수신할 수 있다. 그리고, 키 액세스 서버(100)는 키 조각 요청 메시지를 전송한 호스트 서버(200)에 대한 암호화 키를 이용하여, 암호화된 각각의 키 조각을 복호화한다(S230).
다음으로, 키 액세스 서버(100)는 복호화된 각각의 키 조각의 해시 값과, 키 관리 데이터베이스(300)에 각각 저장된 해시 값을 비교하여, 서로 동일한지 판단한다(S235). 판단 결과, 복호화된 각각의 키 조각의 해시 값과, 키 관리 데이터베이스(300)에 각각 저장된 해시 값 중 상이한 해시 값이 존재하는 경우, 키 액세스 서버(100)는 해당 호스트 서버(200)에 암호화된 키 전송 요청 메시지를 다시 전송할 수 있다.
판단 결과, 복호화된 각각의 키 조각의 해시 값과, 키 관리 데이터베이스(300)에 각각 저장된 해시 값이 모두 동일한 경우, 키 액세스 서버(100)는 키 조각을 기초로 마스터 키를 재생성한다(S240). 구체적으로, 키 액세스 서버(100)는 라그레인지 보간법(Lagrange interpolation)을 이용하여, 마스터 키를 재생성할 수 있다. 이하, 키 액세스 서버(100)의 마스터 키 재생성 방법에 대하여 구체적으로 설명한다.
마스터 키를 재생성하기 위해 필요한 키 조각의 임계 수를 k, 호스트 서버(200) i에 대한 키 조각을 yi라 하자. 키 액세스 서버(100)는 마스터 키 f(0)를 아래의 수학식 2를 이용하여 계산할 수 있다.
[수학식 2]
Figure PCTKR2015006238-appb-I000002
따라서, 본 발명의 일 실시예에 따른 키 관리 시스템(10)은 n개의 호스트 서버(200)에 분산 저장된 n개의 키 조각 중 임계 수 k보다 적은 수의 키 조각이 존재하는 경우에는 마스터 키를 재생성할 수 없으며, 임계 수 k보다 크거나 같은 수의 키 조각이 존재하는 경우에만 마스터 키를 재생성할 수 있다.
다음으로, 키 액세스 서버(100)는 재생성된 마스터 키를 메모리 기반 데이터베이스(700)에 저장할 수 있다(S245). 본 발명의 일 실시예에 따른 키 관리 시스템(10)에 메모리 기반 데이터베이스(700)가 포함되지 않은 경우, 본 단계가 생략되고 수행될 수 있음은 통상의 기술자에게 자명하다.
다음으로, 키 액세스 서버(100)는 인스턴스의 요청과 관련된 암호화된 서비스 키를 키 관리 데이터베이스(300)로부터 추출한다(S250). 키 액세스 서버(100)는 마스터 키를 이용하여, 암호화된 서비스 키를 복호화한다(S255). 그리고, 키 액세스 서버(100)는 복호화된 서비스 키를 서비스 장치(400)의 인스턴스에 전송한다(S260).
따라서, 본 발명의 일 실시예에 따른 키 관리 시스템(10)은 분산 저장된 키 조각의 일부가 분실되더라도 마스터 키를 재생성할 수 있어, 마스터 키의 가용성을 확보할 수 있다. 또한, 마스터 키를 생성하기 위해 필요한 임계 수 이상의 키 조각이 유출되더라도, 키 조각들이 각기 다른 암호화 키로 암호화되어 있어 유출된 키 조각만으로는 마스터 키를 재생성할 수 없다.
이하, 본 발명의 다른 실시예에 따른 마스터 키 분산 저장 방법 및 마스터 키 재생성 방법에 대하여 구체적으로 설명한다.
도 6은 본 발명의 다른 실시예에 따른 마스터 키 분산 저장 방법을 설명하기 위한 신호 흐름도이다.
도 6을 참조하면, 서비스 장치(400)의 인스턴스는 클라우드 서비스의 데이터를 서비스 키로 암호화한 후, 서비스 키를 키 액세스 서버(100)에 전송한다(S305). 구체적으로, 서비스 장치(400)의 인스턴스는 키 관리 상호운용 프로토콜(KMIP)을 이용하여, 서비스 키를 키 액세스 서버(100)에 전송할 수 있으나, 이에 한정되는 것은 아니다.
키 액세스 서버(100)는 수신된 서비스 키를 암호화하기 위한 마스터 키를 생성한다(S310). 키 액세스 서버(100)는 생성된 마스터 키를 이용하여, 수신된 서비스 키를 암호화한다(S315). 그리고, 키 액세스 서버(100)는 암호화된 서비스 키를 키 관리 데이터베이스(300)에 전송한다(S320).
키 관리 데이터베이스(300)는 암호화된 서비스 키의 수신에 응답하여, 암호화된 서비스 키를 저장한다(S325).
키 액세스 서버(100)는 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성한다(S330). 구체적으로, 키 액세스 서버(100)는 임계 수 이상이 존재하는 경우에만, 마스터 키를 재생성할 수 있는 키 조각을 생성할 수 있다. 키 액세스 서버(100)의 키 조각 생성 방법에 대한 보다 구체적인 설명은, 도 4를 참조하여 상술한 바와 동일하므로 중복하여 설명하지 않는다.
키 액세스 서버(100)는 호스트 서버(200)별로 상이한 암호화 키를 이용하여, 키 조각을 각각 암호화한다(S335). 여기서, 암호화 키는 호스트 서버(200)에 키 관리를 위한 에이전트가 설치될 당시 키 액세스 서버(100)에 설정될 수 있으나, 이에 한정되지 않고, 실시간으로 지정된 임시 키를 호스트 서버(200)로부터 수신할 수도 있다.
키 액세스 서버(100)는 암호화된 각각의 키 조각을 호스트 서버(200)들에 전송한다(S340). 키 액세스 서버(100)는 키 분산 프로토콜을 이용하여, 키 조각을 호스트 서버(200)들에 전송할 수 있다.
호스트 서버(200)들은 각각의 암호화 키를 이용하여, 수신된 키 조각을 복호화한다(S345). 호스트 서버(200)들은 복호화된 키 조각의 해시 값을 생성한다(S350). 호스트 서버(200)들은 복호화된 키 조각을 저장한다(S355). 그리고, 호스트 서버(200)들은 생성된 해시 값을 키 액세스 서버(100)에 전송한다(S360).
키 액세스 서버(100)는 호스트 서버(200)들로부터 수신된 해시 값과, 마스터 키를 기초로 생성된 키 조각의 해시 값을 비교하여, 서로 동일한지 판단한다(S365). 판단 결과, 호스트 서버(200)들로부터 수신된 해시 값과, 마스터 키를 기초로 생성된 키 조각의 해시 값 중 상이한 해시 값이 존재하는 경우, 키 액세스 서버(100)는 해당 호스트 서버(200)에 암호화된 키 조각을 다시 재전송할 수 있다.
판단 결과, 호스트 서버(200)들로부터 수신된 해시 값과, 마스터 키를 기초로 생성된 키 조각의 해시 값이 모두 동일한 경우, 키 액세스 서버(100)는 메모리 또는 스토리지에 저장되어 있는 마스터 키를 삭제한다(S370).
도 7은 본 발명의 다른 실시예에 따른 마스터 키 재생성 방법을 설명하기 위한 신호 흐름도이다. 이하, 키 액세스 서버(100)의 메모리 및 메모리 기반 데이터베이스(700)에 마스터 키가 존재하지 않는 것으로 가정한다.
도 7을 참조하면, 서비스 장치(400)의 인스턴스는 클라우드 서비스의 데이터를 복호화하기 위하여, 서비스 키의 제공 요청을 키 액세스 서버(100)에 전송한다(S405). 구체적으로, 서비스 장치(400)의 인스턴스는 보안 소켓 계층/전송 계층 보안 프로토콜(SSL/TLS Protocol)을 이용하여, 서비스 키의 제공 요청을 키 액세스 서버(100)에 전송할 수 있으나, 이에 한정되는 것은 아니다.
키 액세스 서버(100)는 서비스 키의 제공 요청 수신에 응답하여, 서비스 키를 복호화하기 위한 마스터 키의 키 조각을 분산 저장하고 있는 호스트 서버(200)들을 식별한다. 키 액세스 서버(100)는 식별된 각각의 호스트 서버(200)에 대한 암호화 키를 이용하여, 키 조각 요청 메시지를 각각 암호화한다(S410). 그리고, 키 액세스 서버(100)는 식별된 각각의 호스트 서버(200)에 암호화된 키 조각 요청 메시지를 전송한다(S415).
호스트 서버(200)들은 암호화된 키 조각 요청 메시지를 각각의 암호화 키로 복호화한다. 그리고, 호스트 서버(200)들은 키 액세스 서버(100)가 악의적인(malicious) 서버인지 검증한다(S420). 이하, 호스트 서버(200)들의 펠드맨(Feldman)이 제안한 이상 대수를 이용한 검증 방법에 대하여 보다 구체적으로 설명한다.
키 액세스 서버(100)가 호스트 서버(200)들에 대하여, 키 조각을 생성한 함수의 계수 t의 암호화된 값 E(a), E(a1), ..., E(at-1)를 공개하였다고 하자. 호스트 서버(200) i는 아래의 수학식 3이 성립하지 않는 경우, 키 액세스 서버(100)가 악의적인 서버인 것으로 판단할 수 있다.
[수학식 3]
Figure PCTKR2015006238-appb-I000003
그러나, 호스트 서버(200)들은 펠드맨이 제안한 검증 방법에 한정되지 않고, 페더슨(Pederson)이 제안한 검증 방법을 이용하여 키 액세스 서버(100)를 검증할 수도 있다.
호스트 서버(200)들은 키 액세스 서버(100)가 악의적인 서버가 아닌 경우, 각각에 저장된 키 조각을 추출하고, 추출된 키 조각을 각각의 암호화 키로 암호화한다(S425). 그리고, 호스트 서버(200)들은 암호화된 키 조각을 키 액세스 서버(100)에 전송한다(S430).
키 액세스 서버(100)는 키 조각을 전송한 각각의 호스트 서버(200)에 대한 암호화 키를 이용하여, 암호화된 키 조각을 복호화한다(S435). 그리고, 키 액세스 서버(100)는 키 관리 데이터베이스(300)에 키 조각의 해시 값 제공 요청을 전송한다(S440).
키 관리 데이터베이스(300)는 키 조각의 해시 값 제공 요청에 응답하여, 키 조각의 해시 값을 추출한다(S445). 그리고, 키 관리 데이터베이스(300)는 추출된 해시 값을 키 액세스 서버(100)에 전송한다(S450).
키 액세스 서버(100)는 복호화된 키 조각의 해시 값과, 키 관리 데이터베이스(300)로부터 수신된 해시 값을 비교하여, 서로 동일한지 판단한다(S455). 판단 결과, 복호화된 키 조각의 해시 값과, 키 관리 데이터베이스(300)로부터 수신된 해시 값 중 상이한 해시 값이 존재하는 경우, 키 액세스 서버(100)는 해당 호스트 서버(200)에 암호화된 키 조각 요청 메시지를 다시 전송할 수 있다.
판단 결과, 복호화된 키 조각의 해시 값과, 키 관리 데이터베이스(300)로부터 수신된 해시 값이 모두 동일한 경우, 키 액세스 서버(100)는 키 조각을 기초로 마스터 키를 재생성한다(S460). 구체적으로, 키 액세스 서버(100)는 라그레인지 보간법을 이용하여, 마스터 키를 재생성할 수 있다. 키 액세스 서버(100)의 마스터 키 재생성 방법에 대한 보다 구체적인 설명은, 도 5를 참조하여 상술한 바와 동일하므로 중복하여 설명하지 않는다.
키 액세스 서버(100)는 키 관리 데이터베이스(300)에 암호화된 서비스 키 제공 요청을 전송한다(S465).
키 관리 데이터베이스(300)는 암호화된 서비스 키 제공 요청에 응답하여, 암호화된 서비스 키를 추출한다(S470). 그리고, 키 관리 데이터베이스(300)는 추출된 암호화된 서비스 키를 키 액세스 서버(100)에 전송한다(S475).
키 액세스 서버(100)는 재생성된 마스터 키를 이용하여, 암호화된 서비스 키를 복호화한다(S480). 그리고, 키 액세스 서버(100)는 복호화된 서비스 키를 서비스 장치(400)의 인스턴스에 전송한다(S485).
지금까지, 도4 내지 도 7을 참조하여 설명한 본 발명의 실시예에 따른 방법들은 컴퓨터가 읽을 수 있는 코드로 구현된 컴퓨터 프로그램의 실행에 의하여 수행될 수 있다. 컴퓨터 프로그램은 인터넷 등의 네트워크를 통하여, 제1 컴퓨팅 장치로부터 제2 컴퓨팅 장치에 전송되어 제2 컴퓨팅 장치에 설치될 수 있고, 이로써 제2 컴퓨팅 장치에서 사용될 수 있다. 여기서, 제1 컴퓨팅 장치 및 제2 컴퓨팅 장치는, 데스크탑(Desktop), 서버(Server) 또는 워크스테이션(Workstation) 등과 같은 고정식 컴퓨팅 장치, 스마트폰(Smart phone), 태블릿(Tablet), 패블릿(Phablet) 또는 랩탑(Laptop) 등과 같은 모바일 컴퓨팅 장치 및 스마트 와치(Smart watch), 스마트 안경(Smart glasses) 또는 스마트 밴드(Smart band) 등과 같은 웨어러블(Wearable) 컴퓨팅 장치를 모두 포함할 수 있다.
이하, 도 8 및 도 9를 참조하여, 본 발명의 일 실시예에 따른 키 액세스 서버(100)의 논리적 구성에 대하여 구체적으로 설명하기로 한다.
도 8은 본 발명의 일 실시예에 따른 키 액세스 서버(100)의 블록도이다. 도 8을 참조하면, 키 액세스 서버(100)는 통신부(105), 저장부(110), 마스터 키 생성부(115), 서비스 키 암복호화부(120), 마스터 키 분산 저장부(125) 및 마스터 키 재생성부(130)를 포함할 수 있다.
각각의 구성에 대하여 설명하면, 통신부(205)는 키 분산 프로토콜을 이용하여, 호스트 서버(200)와 데이터를 송수신할 수 있다. 통신부(205)는 데이터 제공을 요청하기 위한 쿼리(query)를 작성하여, 키 관리 데이터베이스(300)와 데이터를 송수신할 수 있다. 또한, 통신부(205)는 키 관리 상호운용 프로토콜(KMIP) 또는 보안 소켓 계층/전송 계층 보안 프로토콜(SSL/TLS Protocol)을 이용하여, 서비스 장치(400)와 데이터를 송수신할 수도 있다.
저장부(110)는 키 액세스 서버(100)의 동작에 필요한 데이터를 저장할 수 있다. 특히, 서비스 장치(400)의 인스턴스로부터 서비스 키가 반복적으로 요청되어, 키 액세스 서버(100)가 특정 서비스를 위한 마스터 키를 반복적으로 이용하는 경우, 저장부(110)는 마스터 키에 대한 접근 속도를 향상시키기 위하여, 메모리 기반 저장소에 마스터 키(135)를 더 포함하여 저장할 수 있다.
마스터 키 생성부(115)는 서비스 키를 암호화하기 위한 마스터 키를 생성할 수 있다. 구체적으로, 마스터 키 생성부(115)는 통신부(105)를 통해 호스트 서버(200)에 랜덤 시드(seed)의 요청을 전송한다. 마스터 키 생성부(115)는 통신부(105)를 통해 호스트 서버(200)로부터 랜덤 시드를 수신한다. 마스터 키 생성부(115)는 랜덤 시드를 기초로, 기 지정된 랜덤 생성 매커니즘에 따라 마스터 키를 생성한다. 따라서, 마스터 키 생성부(115)가 생성한 마스터 키는 클라우드 서비스의 이용자(tenant), 클라우드 서비스를 통해 제공되는 서비스 또는 클라우드 서비스와 관련된 비즈니스 등에 따라 무작위적이며 유일한 값을 가질 수 있다. 또한, 마스터 키 생성부(115)는 새로운 마스터 키가 필요한 시점에 안정적으로 연결된 호스트 서버(200)들로부터 랜덤 시드를 수신하고, 수신된 랜덤 시드를 기초로 마스터 키를 생성함으로써, 생성된 마스터 키 값의 예측 가능성을 낮출 수 있다.
서비스 키 암복호화부(120)는 통신부(105)를 통해 서비스 키가 수신되면, 마스터 키 생성부(115)를 통해 생성된 마스터 키를 기초로 서비스 키를 암호화할 수 있다. 또한, 서비스 키 암복호화부(120)는 마스터 키 재생성부(130)를 통해 마스터 키가 재생성되면, 암호화된 서비스 키를 복호화할 수 있다.
마스터 키 분산 저장부(125)는 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성하고, 생성된 키 조각을 통신부(105)를 통해 전송할 수 있다. 구체적으로, 마스터 키 분산 저장부(125)는 임계 수 이상이 존재하는 경우에만, 마스터 키를 재생성할 수 있는 키 조각을 생성할 수 있다. 마스터 키 분산 저장부(125)의 키 조각 생성 방법에 대한 보다 구체적인 설명은, 도 4를 참조하여 상술한 바와 동일하므로 중복하여 설명하지 않는다.
그리고, 마스터 키 분산 저장부(125)는 호스트 서버(200)별로 상이한 암호화 키를 이용하여, 키 조각을 각각 암호화할 수 있다. 마스터 키 분산 저장부(125)는 통신부(105)를 통해, 암호화된 각각의 키 조각을 호스트 서버(200)들에 전송할 수 있다. 마스터 키 분산 저장부(125)는 통신부(105)를 통해, 해시 값을 수신할 수 있다. 그리고, 마스터 키 분산 저장부(125)는 수신된 해시 값과 키 조각의 해시 값을 비교하여, 서로 동일한지 판단할 수 있다.
마스터 키 재생성부(130)는 둘 이상의 키 조각을 이용하여 마스터 키를 재생성할 수 있다. 구체적으로, 마스터 키 재생성부(130)는 통신부(105)를 통해 암호화된 키 조각을 수신할 수 있다. 마스터 키 재생성부(130)는 키 조각을 전송한 각각의 호스트 서버(200)에 대한 암호화 키를 이용하여, 암호화된 키 조각을 복호화할 수 있다. 마스터 키 재생성부(130)는 통신부(105)를 통해 키 관리 데이터베이스(300)로부터 해시 값을 수신할 수 있다. 마스터 키 재생성부(130)는 복호화된 키 조각의 해시 값과, 키 관리 데이터베이스(300)로부터 수신된 해시 값을 비교하여, 서로 동일한지 판단할 수 있다.
그리고, 마스터 키 재생성부(130)는 복호화된 키 조각을 기초로 마스터 키를 재생성할 수 있다. 구체적으로, 마스터 키 재생성부(130)는 라그레인지 보간법을 이용하여, 마스터 키를 재생성할 수 있다. 마스터 키 재생성부(130)의 마스터 키 재생성 방법에 대한 보다 구체적인 설명은, 도 5를 참조하여 상술한 바와 동일하므로 중복하여 설명하지 않는다.
지금까지, 도 8의 각 구성요소는 소프트웨어(Software) 또는, 현장 프로그래머블 게이트 어레이(Field-Programmable Gate Array, FPGA)나 에이직(Application-Specific Integrated Circuit, ASIC)과 같은 하드웨어(hardware)를 의미할 수 있다. 그렇지만, 상기 구성 요소들은 소프트웨어 또는 하드웨어에 한정되는 의미는 아니며, 어드레싱(Addressing)할 수 있는 저장 매체에 있도록 구성될 수도 있고, 하나 또는 그 이상의 프로세서들을 실행시키도록 구성될 수도 있다. 상기 구성 요소들 안에서 제공되는 기능은 더 세분화된 구성요소에 의하여 구현될 수 있으며, 복수의 구성요소들을 합하여 특정한 기능을 수행하는 하나의 구성요소로 구현될 수도 있다.
도 9는 본 발명의 일 실시예에 따른 키 액세스 서버(100)의 하드웨어 구성도이다. 도 9를 참조하면, 키 액세스 서버(100)는 프로세서(155), 메모리(160), 네트워크 인터페이스(165), 데이터 버스(170) 및 스토리지(175)를 포함하여 구성될 수 있다.
메모리(160)는 키 관리 방법이 구현된 컴퓨터 프로그램 데이터(180a)가 상주될 수 있다. 또한, 키 액세스 서버(100)가 반복적으로 마스터 키를 이용하는 경우, 메모리(160)는 마스터 키(135)를 더 포함하여 저장할 수 있다.
네트워크 인터페이스(165)는 호스트 서버(200), 키 관리 데이터베이스(300)와 데이터를 송수신할 수 있다. 또한, 네트워크 인터페이스(165)는 서비스 장치(400)와 데이터를 송수신할 수도 있다.
데이터 버스(170)는 프로세서(155), 메모리(160), 네트워크 인터페이스(165) 및 스토리지(175)와 연결되어, 각 구성 요소간의 데이터를 전달하는 이동 통로이다.
그리고, 스토리지(175)는 컴퓨터 프로그램 실행을 위해 필요한 에이피아이(API), 라이브러리(Library) 또는 리소스(Resource) 파일 등을 저장할 수 있다. 또한, 스토리지(175)는 키 관리 방법이 구현된 컴퓨터 프로그램 데이터(180b)를 저장할 수 있다.
보다 구체적으로는, 스토리지(175)에는 클라우드 서비스의 제1 이용자의 인스턴스에 의하여 사용되는 서비스 키를 마스터 키를 이용하여 암호화하는 인스트럭션(instruction), 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성하는 인스트럭션, 네트워크 인터페이스를 통해, 클라우드 서비스의 제공을 위한 호스트 그룹에 포함된 둘 이상의 호스트 서버에, 키 조각을 분산하여 저장하는 인스트럭션, 네트워크 인터페이스를 통해, 제1 이용자의 인스턴스로부터 서비스 키의 제공 요청을 수신하는 인스트럭션, 네트워크 인터페이스를 통해, 둘 이상의 호스트 서버로부터 키 조각들을 수신하고, 수신된 키 조각을 기초로 마스터 키를 재생성하는 인스트럭션, 및 암호화된 서비스 키를 마스터 키를 이용하여 복호화하는 인스트럭션을 포함하는 컴퓨터 프로그램이 저장될 수 있다.
이상 첨부된 도면을 참조하여 본 발명의 실시예들을 설명하였지만, 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자는 본 발명이 그 기술적 사상이나 필수적인 특징을 변경하지 않고서 다른 구체적인 형태로 실시될 수 있다는 것을 이해할 수 있을 것이다. 그러므로 이상에서 기술한 실시예들은 모든 면에서 예시적인 것이며 한정적이 아닌 것으로 이해되어야만 한다.

Claims (16)

  1. 클라우드 서비스의 제1 이용자의 인스턴스에 의하여 사용되는 서비스 키를 마스터 키를 이용하여 암호화하는 단계;
    상기 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성하는 단계;
    상기 클라우드 서비스의 제공을 위한 호스트 그룹에 포함된 둘 이상의 호스트 서버에, 상기 키 조각을 분산하여 저장하는 단계;
    상기 제1 이용자의 인스턴스로부터, 상기 서비스 키의 제공 요청을 수신하는 단계;
    상기 둘 이상의 호스트 서버로부터 상기 키 조각들을 수신하고, 상기 수신된 키 조각을 기초로 상기 마스터 키를 재생성하는 단계; 및
    상기 암호화된 서비스 키를 상기 재생성된 마스터 키를 이용하여 복호화하는 단계를 포함하는, 키 관리 방법.
  2. 제1 항에 있어서,
    상기 키 조각을 생성하는 단계는,
    상기 마스터 키를 재생성하기 위해 필요한 키 조각의 임계 수보다 많거나 같은 수의 키 조각을 생성하는 단계를 포함하는, 키 관리 방법.
  3. 제1 항에 있어서,
    상기 조각 키를 생성하는 단계는,
    상기 마스터 키를 재생성하기 위해 필요한 키 조각의 임계 수와 같은 차수의 다항식을 생성하되, 상기 다항식의 0차 항의 계수가 마스터 키인 다항식을 생성하는 단계; 및
    상기 다항식의 함수 값을 기초로 상기 키 조각을 생성하는 단계를 포함하는, 키 관리 방법.
  4. 제3 항에 있어서,
    상기 키 조각을 생성하는 단계는,
    상기 함수 값을 상기 마스터 키가 가질 수 있는 최대 크기로 나눈 나머지를 기초로 상기 키 조각을 생성하는 단계를 포함하는, 키 관리 방법.
  5. 제1 항에 있어서,
    상기 키 조각을 분산하여 저장하는 단계는,
    상기 키 조각이 저장된 상기 호스트 서버로부터 해시 값을 수신하는 단계; 및
    상기 수신된 해시 값과 상기 호스트 서버에 전송한 키 조각의 해시 값을 비교하는 단계를 포함하는, 키 관리 방법.
  6. 제1 항에 있어서,
    상기 키 조각을 분산하여 저장하는 단계는,
    상기 호스트 서버별로 서로 상이한 상기 호스트 서버의 암호화 키를 이용하여, 상기 키 조각을 각각 암호화하는 단계; 및
    상기 암호화된 키 조각을 상기 호스트에 전송하는 단계를 포함하는, 키 관리 방법.
  7. 제1 항에 있어서,
    상기 키 조각을 분산하여 저장하는 단계는,
    상기 호스트 그룹에 포함된 호스트 서버 사이에서 이용될 수 없도록 정의된 프로토콜을 이용하여, 상기 키 조각을 상기 호스트 서버에 전송하는 단계를 포함하는, 키 관리 방법.
  8. 제1 항에 있어서,
    상기 키 조각을 분산하여 저장하는 단계는,
    상기 호스트 그룹에 포함된 호스트 서버 중 상기 제1 이용자에 제공되는 클라우드 서비스와 관련되지 않은 호스트 서버에, 상기 키 조각을 분산하여 저장하는 단계를 포함하는, 키 관리 방법.
  9. 제1 항에 있어서,
    상기 마스터 키를 재생성하는 단계는,
    상기 키 조각이 분산 저장된 호스트 서버 중 상기 마스터 키를 재생성하기 위해 필요한 키 조각의 임계 수보다 크거나 같은 수의 호스트 서버에 키 조각 요청 메시지를 전송하는 단계를 포함하는, 키 관리 방법.
  10. 제1 항에 있어서,
    상기 마스터 키를 재생성하는 단계는,
    상기 호스트 서버별로 서로 상이한 상기 호스트 서버의 암호화 키를 이용하여, 키 조각 요청 메시지를 각각 암호화하는 단계; 및
    상기 암호화된 키 조각 요청 메시지를 상기 호스트 서버에 전송하는 단계를 포함하는, 키 관리 방법.
  11. 제1 항에 있어서,
    상기 마스터 키를 재생성하는 단계는,
    상기 재생성된 마스터 키를 메모리 기반 데이터베이스에 저장하는 단계를 포함하는, 키 관리 방법.
  12. 제1 항에 있어서,
    상기 마스터 키를 재생성하는 단계는,
    메모리 기반 데이터베이스에 상기 마스터 키가 존재하는지 판단한 후, 상기 메모리 기반 데이터베이스에 상기 마스터 키가 존재하지 않는 경우, 상기 마스터 키를 재생성하는 단계를 포함하는, 키 관리 방법.
  13. 제1 항에 있어서,
    상기 마스터 키는,
    클라우드 서비스의 이용자별로 서로 상이한 값을 가지도록 생성된, 키 관리 방법.
  14. 클라우드 서비스의 제1 이용자의 인스턴스에 의하여 사용되는 서비스 키를 마스터 키를 이용하여 암호화한 후, 상기 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성하여 분산 저장하고, 상기 제1 이용자의 인스턴스로부터 서비스 키 제공 요청이 수신되면, 상기 분산 저장된 키 조각을 기초로 마스터 키를 재생성하여 상기 암호화된 서비스 키를 복호화하는 키 액세스 서버; 및
    상기 키 액세스 서버로부터 상기 키 조각을 수신하여 저장하고, 상기 키 액세스 서버로부터 키 조각 제공 요청이 수신되면 상기 키 조각을 전송하는 호스트 서버를 포함하는, 키 관리 시스템.
  15. 제14 항에 있어서,
    상기 키 액세스 서버로부터 상기 재생성된 마스터 키를 수신하여 저장하고, 상기 키 액세스 서버로부터 마스터 키 제공 요청이 수신되면 상기 마스터 키를 전송하는 메모리 기반 데이터베이스를 더 포함하는, 키 관리 시스템.
  16. 컴퓨팅 장치와 결합하여,
    클라우드 서비스의 제1 이용자의 인스턴스에 의하여 사용되는 서비스 키를 마스터 키를 이용하여 암호화하는 단계;
    상기 마스터 키를 재생성하기 위한 둘 이상의 키 조각을 생성하는 단계;
    상기 클라우드 서비스의 제공을 위한 호스트 그룹에 포함된 둘 이상의 호스트 서버에, 상기 키 조각을 분산하여 저장하는 단계;
    상기 제1 이용자의 인스턴스로부터, 서비스 키 제공 요청을 수신하는 단계;
    상기 둘 이상의 호스트 서버로부터 상기 키 조각들을 수신하고, 상기 수신된 키 조각을 기초로 상기 마스터 키를 재생성하는 단계; 및
    상기 암호화된 서비스 키를 상기 재생성된 마스터 키를 이용하여 복호화하는 단계를 실행시키기 위하여, 기록매체에 기록된 컴퓨터 프로그램.
PCT/KR2015/006238 2015-05-27 2015-06-19 클라우드 서비스를 위한 암호화 키 관리 방법 및 그 장치 Ceased WO2016190476A1 (ko)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR1020150074302A KR102460096B1 (ko) 2015-05-27 2015-05-27 클라우드 서비스를 위한 암호화 키 관리 방법 및 그 장치
KR10-2015-0074302 2015-05-27

Publications (1)

Publication Number Publication Date
WO2016190476A1 true WO2016190476A1 (ko) 2016-12-01

Family

ID=57393885

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2015/006238 Ceased WO2016190476A1 (ko) 2015-05-27 2015-06-19 클라우드 서비스를 위한 암호화 키 관리 방법 및 그 장치

Country Status (4)

Country Link
US (1) US10171440B2 (ko)
KR (1) KR102460096B1 (ko)
CN (1) CN106209353A (ko)
WO (1) WO2016190476A1 (ko)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20180078509A (ko) * 2016-12-30 2018-07-10 홍익대학교 산학협력단 가상 함수 테이블 포인터 암호화 시스템 및 그 방법
US12206771B2 (en) 2022-06-29 2025-01-21 Micro Focus Llc System and method for managing fragmented encryption keys for granting access

Families Citing this family (28)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10460314B2 (en) * 2013-07-10 2019-10-29 Ca, Inc. Pre-generation of session keys for electronic transactions and devices that pre-generate session keys for electronic transactions
US10158486B1 (en) * 2016-08-09 2018-12-18 Cisco Technology, Inc. Synchronization of key management services with cloud services
CN106941404B (zh) * 2017-04-25 2020-06-30 中国联合网络通信集团有限公司 密钥保护方法及装置
KR101987025B1 (ko) * 2017-05-31 2019-06-10 삼성에스디에스 주식회사 암호화 처리 방법 및 그 장치
KR101966767B1 (ko) 2017-05-31 2019-04-08 삼성에스디에스 주식회사 클라우드 서비스를 위한 암호화 키 관리 시스템
US10867057B1 (en) 2017-06-01 2020-12-15 Massachusetts Mutual Life Insurance Company Decentralized encryption and decryption of blockchain data
US10841089B2 (en) 2017-08-25 2020-11-17 Nutanix, Inc. Key managers for distributed computing systems
US11095662B2 (en) 2017-08-29 2021-08-17 Amazon Technologies, Inc. Federated messaging
US11349659B2 (en) 2017-08-29 2022-05-31 Amazon Technologies, Inc. Transmitting an encrypted communication to a user in a second secure communication network
US11368442B2 (en) 2017-08-29 2022-06-21 Amazon Technologies, Inc. Receiving an encrypted communication from a user in a second secure communication network
US10972445B2 (en) * 2017-11-01 2021-04-06 Citrix Systems, Inc. Dynamic crypto key management for mobility in a cloud environment
CN107943556B (zh) * 2017-11-10 2021-08-27 中国电子科技集团公司第三十二研究所 基于kmip和加密卡的虚拟化数据安全方法
US20190238323A1 (en) * 2018-01-31 2019-08-01 Nutanix, Inc. Key managers for distributed computing systems using key sharing techniques
KR102122731B1 (ko) * 2018-04-26 2020-06-16 한국조폐공사 블록 체인 기반 키의 저장 및 복원 방법과 이를 이용한 사용자 단말
CN111654367B (zh) * 2018-08-31 2023-05-12 创新先进技术有限公司 密码运算、创建工作密钥的方法、密码服务平台及设备
US10447475B1 (en) * 2018-11-08 2019-10-15 Bar Ilan University System and method for managing backup of cryptographic keys
HK1254273A2 (zh) 2018-12-03 2019-07-12 Foris Limited 安全的分布式密钥管理系统
CN118900199A (zh) 2019-01-28 2024-11-05 康奈尔克有限公司 用于安全电子数据传输的系统和方法
US11218307B1 (en) * 2019-04-24 2022-01-04 Wells Fargo Bank, N.A. Systems and methods for generation of the last obfuscated secret using a seed
CN110830253A (zh) * 2019-11-29 2020-02-21 江苏芯盛智能科技有限公司 密钥管理方法、装置、服务器、系统及存储介质
WO2021239249A1 (en) * 2020-05-29 2021-12-02 Huawei Technologies Co., Ltd. Devices and methods for zero touch provisioning in a communication network
US12052346B2 (en) * 2020-07-02 2024-07-30 International Business Machines Corporation Secure secret recovery
WO2022153456A1 (ja) * 2021-01-14 2022-07-21 日本電信電話株式会社 暗号化装置、暗号通信システム、暗号化方法およびプログラム
US11799633B1 (en) 2021-09-27 2023-10-24 Workday, Inc. Enabling using external tenant master keys
CN113918969B (zh) * 2021-09-28 2023-02-21 厦门市美亚柏科信息股份有限公司 一种基于内存数据搜索Bitlocker解密密钥的方法
CN113922969B (zh) * 2021-10-27 2025-01-10 杭州弦冰科技有限公司 Intel SGX可信服务集群化部署的实现方法、系统及电子设备
KR20230062962A (ko) * 2021-11-01 2023-05-09 현대모비스 주식회사 차량 카메라를 이용한 데이터 통신 시스템, 데이터 통신 방법 및 데이터 통신 차량
CN116108474B (zh) * 2023-04-13 2023-06-30 深圳奥联信息安全技术有限公司 一种大数据系统密码服务方法及系统

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020067832A1 (en) * 2000-06-05 2002-06-06 Jablon David P. Systems, methods and software for remote password authentication using multiple servers
US20120121088A1 (en) * 2007-11-05 2012-05-17 Yoichi Hata Encryption key generation device
US20120179911A1 (en) * 2003-12-23 2012-07-12 Wells Fargo Bank, N.A. Cryptographic key backup and escrow system
US20120243687A1 (en) * 2011-03-24 2012-09-27 Jun Li Encryption key fragment distribution
US20150019870A1 (en) * 2008-04-02 2015-01-15 Cisco Technology, Inc. Master key generation and distribution for storage area network devices

Family Cites Families (23)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6286098B1 (en) * 1998-08-28 2001-09-04 Sap Aktiengesellschaft System and method for encrypting audit information in network applications
KR100484209B1 (ko) * 1998-09-24 2005-09-30 삼성전자주식회사 디지털컨텐트암호화/해독화장치및그방법
TW526643B (en) * 1999-05-20 2003-04-01 Ind Tech Res Inst Data access control system and method
US7093137B1 (en) * 1999-09-30 2006-08-15 Casio Computer Co., Ltd. Database management apparatus and encrypting/decrypting system
US6959394B1 (en) * 2000-09-29 2005-10-25 Intel Corporation Splitting knowledge of a password
US7787619B2 (en) 2002-01-29 2010-08-31 Avaya Inc. Method and apparatus for secure key management using multi-threshold secret sharing
KR20030077065A (ko) 2002-03-25 2003-10-01 (주)비진 비디오 도어폰 시스템
KR100642978B1 (ko) * 2002-04-22 2006-11-10 소프트포럼 주식회사 키 관리 방법 및 그를 위한 시스템
TWI354206B (en) * 2004-07-15 2011-12-11 Ibm Method for accessing information on article with a
US20060285683A1 (en) * 2004-10-01 2006-12-21 Lakshminarayanan Anatharaman Method for cryptographically processing a message, method for generating a cryptographically processed message, method for performing a cryptographic operation on a message, computer system, client computer, server computer and computer program elements
JP2008103936A (ja) * 2006-10-18 2008-05-01 Toshiba Corp 秘密情報管理装置および秘密情報管理システム
US8345861B2 (en) * 2008-08-22 2013-01-01 Red Hat, Inc. Sharing a secret using polynomial division over GF(Q)
US8713329B2 (en) * 2009-02-26 2014-04-29 Red Hat, Inc. Authenticated secret sharing
JPWO2010100923A1 (ja) 2009-03-03 2012-09-06 Kddi株式会社 鍵共有システム
KR101033475B1 (ko) * 2009-07-03 2011-05-09 동국대학교 경주캠퍼스 산학협력단 효율적인 개인정보 유통경로의 안전관리를 위한 개인 정보 보호 장치 및 방법
US8625802B2 (en) 2010-06-16 2014-01-07 Porticor Ltd. Methods, devices, and media for secure key management in a non-secured, distributed, virtualized environment with applications to cloud-computing security and management
CN103250441A (zh) * 2010-12-07 2013-08-14 瑞典爱立信有限公司 使用密钥共享方案来提供临时标识模块的方法和装置
US9270459B2 (en) * 2011-09-20 2016-02-23 Cloudbyte, Inc. Techniques for achieving tenant data confidentiality from cloud service provider administrators
CN102523086B (zh) * 2011-12-07 2014-12-24 上海交通大学 一种隐私保护云存储系统中的密钥恢复方法
US9002812B2 (en) * 2012-04-01 2015-04-07 Microsoft Technology Licensing, Llc Checksum and hashing operations resilient to malicious input data
US10354084B2 (en) * 2013-10-28 2019-07-16 Sepior Aps System and a method for management of confidential data
US9667416B1 (en) * 2014-12-18 2017-05-30 EMC IP Holding Company LLC Protecting master encryption keys in a distributed computing environment
US10541811B2 (en) * 2015-03-02 2020-01-21 Salesforce.Com, Inc. Systems and methods for securing data

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020067832A1 (en) * 2000-06-05 2002-06-06 Jablon David P. Systems, methods and software for remote password authentication using multiple servers
US20120179911A1 (en) * 2003-12-23 2012-07-12 Wells Fargo Bank, N.A. Cryptographic key backup and escrow system
US20120121088A1 (en) * 2007-11-05 2012-05-17 Yoichi Hata Encryption key generation device
US20150019870A1 (en) * 2008-04-02 2015-01-15 Cisco Technology, Inc. Master key generation and distribution for storage area network devices
US20120243687A1 (en) * 2011-03-24 2012-09-27 Jun Li Encryption key fragment distribution

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20180078509A (ko) * 2016-12-30 2018-07-10 홍익대학교 산학협력단 가상 함수 테이블 포인터 암호화 시스템 및 그 방법
KR101999209B1 (ko) 2016-12-30 2019-07-11 홍익대학교 산학협력단 가상 함수 테이블 포인터 암호화 시스템 및 그 방법
US12206771B2 (en) 2022-06-29 2025-01-21 Micro Focus Llc System and method for managing fragmented encryption keys for granting access

Also Published As

Publication number Publication date
KR102460096B1 (ko) 2022-10-27
US10171440B2 (en) 2019-01-01
CN106209353A (zh) 2016-12-07
KR20160139493A (ko) 2016-12-07
US20170019385A1 (en) 2017-01-19

Similar Documents

Publication Publication Date Title
KR102460096B1 (ko) 클라우드 서비스를 위한 암호화 키 관리 방법 및 그 장치
US12292994B2 (en) Encrypting data records and processing encrypted records without exposing plaintext
US11728974B2 (en) Tenant-based database encryption
CN107533616B (zh) 用于使数据安全的系统和方法
US11095616B2 (en) Virtualized application performance through disabling of unnecessary functions
US10050982B1 (en) Systems and methods for reverse-engineering malware protocols
CN110061983B (zh) 一种数据处理方法及系统
CN110891062A (zh) 密码更改方法、服务器及存储介质
WO2014185594A1 (ko) Vdi 환경에서의 싱글 사인온 시스템 및 방법
EP4096146A1 (en) Information processing system, information processing device, information processing method, and information processing program
WO2019059453A1 (ko) 블록체인을 이용한 메시지 히스토리 기반의 보안 키를 이용하는 통신 장치 및 방법
WO2018036168A1 (zh) 数据处理任务执行方法、装置、执行服务器和存储介质
US10469457B1 (en) Systems and methods for securely sharing cloud-service credentials within a network of computing devices
CN112068858A (zh) 使用布隆过滤器的设备更新传输
JP7665725B2 (ja) 鍵共有を使用するデータのセキュア化
CN116506848B (zh) 升级数据包的保密传输方法、装置、电子设备及存储介质
US9699146B1 (en) Secure access to user data
WO2013176431A1 (ko) 단말을 서버에 할당하고 단말로의 효율적인 메시징을 위한 시스템 및 방법
WO2023191216A1 (ko) 데이터 암호화 및 복호화 시스템, 방법
WO2018032583A1 (zh) 一种终端位置信息获取方法及装置
WO2024005565A1 (ko) 메신저 서비스를 제공하기 위한 방법, 시스템 및 비일시성의 컴퓨터 판독 가능한 기록 매체
CN116865999A (zh) 一种加密方法、装置、设备及存储介质
WO2018076539A1 (zh) 伪无线接入点识别方法及系统
TWI919276B (zh) 一種加密方法、裝置、設備及儲存介質
CN115242384B (zh) 使用量子密钥对虚拟机数据进行加解密的方法、装置、介质和设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15893428

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15893428

Country of ref document: EP

Kind code of ref document: A1