WO2022017103A1 - 一种动态加载加密引擎的方法 - Google Patents
一种动态加载加密引擎的方法 Download PDFInfo
- Publication number
- WO2022017103A1 WO2022017103A1 PCT/CN2021/101481 CN2021101481W WO2022017103A1 WO 2022017103 A1 WO2022017103 A1 WO 2022017103A1 CN 2021101481 W CN2021101481 W CN 2021101481W WO 2022017103 A1 WO2022017103 A1 WO 2022017103A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- encryption
- information
- key
- encrypted
- engine
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
- H04L9/16—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms the keys or algorithms being changed during operation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0825—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0869—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/088—Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/30—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
- H04L9/3006—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy underlying computational problems or public-key parameters
- H04L9/302—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy underlying computational problems or public-key parameters involving the integer factorization problem, e.g. RSA or quadratic sieve [QS] schemes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/30—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
- H04L9/3066—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy involving algebraic varieties, e.g. elliptic or hyper-elliptic curves
- H04L9/3073—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy involving algebraic varieties, e.g. elliptic or hyper-elliptic curves involving pairings, e.g. identity based encryption [IBE], bilinear mappings or bilinear pairings, e.g. Weil or Tate pairing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
- H04L9/3249—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures using RSA or related signature schemes, e.g. Rabin scheme
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/12—Details relating to cryptographic hardware or logic circuitry
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/84—Vehicles
Definitions
- the invention relates to the technical field of vehicle networking communication security, in particular to a method for dynamically loading an encryption engine.
- Soft encryption refers to a software protection method that does not require additional hardware, and is generally authorized by serial numbers or license files.
- the soft encryption scheme adopts the way of binding with the computer software and hardware features, such as CPU, BIOS, hard disk, MAC, computer name, user name, etc., because no additional hardware devices are used, it is considered as a "soft encryption” scheme.
- the security strength of soft encryption is not as high as that of hard encryption, but it also has many advantages, such as: no hardware and logistics, fast encryption and decryption, and can realize electronic distribution of software; easy to manage and maintain, which helps to improve authorization efficiency and improve user experience; reduce the overall software protection, distribution and management costs of software developers and improve their competitiveness.
- Hard encryption refers to a software protection technology that requires additional hardware devices.
- the main hard encryption scheme is the encryption lock technology. According to the different CPU used by the encryption lock, it is divided into ordinary encryption lock and smart card encryption lock.
- Hardware encryption has relatively high security strength, but it also has many shortcomings, such as: it is suitable for traditional one-time permanent authorization, it is not convenient to realize trial version and on-demand purchase; the existence of hardware brings about production, initialization, logistics, installation and The cost of maintenance; the inability to realize electronic distribution based on the Internet; the installation of drivers and client components and additional hardware equipment affects the customer's use experience, and it is difficult to upgrade, track and manage after-sales.
- the industry is designing an encryption method on a product, either using soft encryption or hard encryption.
- soft encryption as mentioned above, the security level of the information is not very high, but some high-density information requires an encryption method with a higher security level, which will cause the information to be insecure.
- hardware encryption some information needs a lower level of security, and if all use hard encryption technology, it will lead to a waste of resources and an increase of encryption time.
- the existing technical solutions have shortcomings such as insufficient encryption security level, waste of resources and increased encryption and decryption time, and it is difficult to meet the requirements in all aspects.
- the technical problem to be solved by the embodiments of the present invention is to provide a method for dynamically loading an encryption engine, which adopts different encryption methods for different information, which not only meets the encryption requirements of information, but also reduces waste of resources and increases the efficiency of encryption and decryption of resources. .
- the present invention provides a method for dynamically loading an encryption engine, including:
- Step S1 generating an encryption method identifier according to the security level, size and required access speed of the information to be encrypted, wherein the encryption method identifier includes a soft encryption identifier and a hard encryption identifier, and the soft encryption identifier is used to identify The information to be encrypted must use a soft encryption method, and the hard encryption identifier is used to identify that the information to be encrypted must use a hard encryption method;
- Step S2 obtain the encryption mode identifier of the current information to be encrypted, and determine the encryption mode of the current information to be encrypted;
- Step S3 Load the corresponding encryption engine according to the encryption mode of the current information to be encrypted.
- the security level includes two types of high security level and low security level
- the size of the information to be encrypted is compared with the storage space threshold, including two types of large storage space and small storage space
- the information to be encrypted The required access speed is compared with the access speed threshold, including two types: fast access speed and slow access speed.
- generating an encryption method identifier in the step S1 is specifically: generating a soft encryption identifier for the information to be encrypted that simultaneously meets the requirements of low security level, small storage space, and fast access speed, and generates a hard encryption identifier for other information to be encrypted. symbol.
- the storage space threshold is set to 500k, the information to be encrypted greater than or equal to 500k belongs to the information with large storage space, and the information to be encrypted less than 500k belongs to the information with small storage space;
- the access speed threshold is set to 100ms, greater than or equal to 100ms.
- the information to be encrypted that is equal to or equal to 100ms belongs to the information that needs to be accessed slowly, and the information to be encrypted less than 100ms belongs to the information that needs to be accessed quickly.
- the method of obtaining the encryption method identifier of the current information to be encrypted in the step S2 includes: directly reading the encryption method identifier carried in the current information to be encrypted; A table of identifiers.
- step S3 loads a soft encryption engine or a hard encryption engine according to the encryption method of the current information to be encrypted determined in the step S2, and the step of loading the soft encryption engine includes:
- step of performing chip engine initialization includes:
- the engine setting function is called to set the encryption algorithm of the chip engine to the RSA method by default.
- step of generating the chip key includes:
- step of loading the chip key includes:
- step of loading the hard encryption engine includes:
- the hard encryption engine loads the encryption algorithm engine to encrypt the random number
- the present invention is designed to have two encryption modes simultaneously on the same system—a soft encryption mode and a hard encryption mode, and the two encryption modes are dynamically loaded according to the content and situation of the information.
- the two encryption modes are dynamically loaded according to the content and situation of the information.
- FIG. 1 is a schematic flowchart of a method for dynamically loading an encryption engine according to an embodiment of the present invention.
- FIG. 2 is a schematic flowchart of loading a soft encryption engine in an embodiment of the present invention.
- FIG. 3 is a schematic flowchart of chip engine initialization in an embodiment of the present invention.
- FIG. 4 is a schematic flowchart of generating a key in an embodiment of the present invention.
- FIG. 5 is a schematic flowchart of loading a chip key in an embodiment of the present invention.
- FIG. 6 is a schematic flowchart of loading a hard encryption engine in an embodiment of the present invention.
- an embodiment of the present invention provides a method for dynamically loading an encryption engine, including:
- Step S1 generating an encryption method identifier according to the security level, size and required access speed of the information to be encrypted, wherein the encryption method identifier includes a soft encryption identifier and a hard encryption identifier, and the soft encryption identifier is used to identify The information to be encrypted must use a soft encryption method, and the hard encryption identifier is used to identify that the information to be encrypted must use a hard encryption method;
- Step S2 obtain the encryption mode identifier of the current information to be encrypted, and determine the encryption mode of the current information to be encrypted;
- Step S3 Load the corresponding encryption engine according to the encryption mode of the current information to be encrypted.
- the elements of the information to be encrypted that need to be acquired in step S1 include: (1) security level; (2) size; (3) required access speed; wherein, the security level of the information to be encrypted refers to the confidentiality of the information to be encrypted, If the confidentiality is high, the security level is also high, indicating that an encryption method with a higher degree of encryption is required; the information size refers to the storage space required for the information to be encrypted, and the access speed refers to whether the information to be encrypted needs to be accessed quickly.
- the security level includes two types: high security level and low security level.
- the security level of the interactive information of the big car entertainment is generally low, and the security level of the vehicle location information is high; the size of the information to be encrypted is passed and stored.
- the comparison of the space threshold can be divided into two types: large storage space and small storage space; by comparing the required access speed of the information to be encrypted with the access speed threshold, it can be divided into two types: fast access speed and slow access speed.
- the storage space threshold may be set to 500k, information to be encrypted greater than or equal to 500k belongs to information with large storage space, and information to be encrypted less than 500k belongs to information with small storage space.
- the access speed threshold can be set to 100ms.
- the information to be encrypted that is greater than or equal to 100ms belongs to the information that needs to be accessed slowly, and the information to be encrypted less than 100ms belongs to the information that needs to be accessed quickly.
- an encryption method identifier can be generated, which is used to identify the encryption method of the information to be encrypted.
- the encryption method identifier includes a soft encryption identifier and a hard encryption identifier,
- the soft encryption identifier is used to identify that the information to be encrypted must use a soft encryption method
- the hard encryption identifier is used to identify that the information to be encrypted must use a hard encryption method.
- the soft encryption identifier and the hard encryption identifier can be distinguished by a value of 1 or 0, for example, 0 represents the soft encryption identifier and 1 represents the hard encryption identifier.
- One standard for generating an encryption method identifier is to generate a soft encryption identifier for the information to be encrypted that simultaneously meets the requirements of low security level, small storage space, and fast access speed, and generates a hard encryption identifier for other information to be encrypted.
- using soft encryption can improve the encryption and decryption efficiency; for information with higher security level, using hard encryption can improve the encryption strength of data.
- Step S2 obtains the encryption mode identifier of the currently to-be-encrypted information to be transmitted in real time, and then determines the encryption mode of the current to-be-encrypted information according to the encryption mode identifier.
- the encryption method identifier carried in the currently to-be-encrypted information is directly read; as mentioned above, the encryption method identifier can be added to the message body of the current to-be-encrypted information with a value of 1 or 0.
- the table lookup method it is to query the table formed by each information to be encrypted and its encryption method identifier; the table can be a one-dimensional table, and each information to be encrypted in the table corresponds to its encryption method identifier one by one.
- the mode identifier can be represented by the value 1 or 0.
- step S2 the processing of step S2 is real-time, and the encryption modes of different information to be encrypted can be determined in real time, so that the corresponding encryption engine can be dynamically loaded in step S3.
- step S2 obtains its hard encrypted identifier through the aforementioned direct reading or table look-up method, so as to determine that the hard encrypted identifier will be used for it.
- Encryption method another example, for vehicle-mounted entertainment interactive information, because it meets the requirements of low security level, small storage space, and fast access speed at the same time, the soft encryption identifier has been generated in step S1, then step S2 directly reads or checks through the aforementioned method. Table method to obtain its soft encryption identifier, so as to determine the soft encryption method will be used for it.
- step S3 the corresponding encryption engine is loaded according to the encryption mode of the current information to be encrypted determined in step S2.
- the following describes the process of loading the soft encryption engine and loading the hard encryption engine. It can be understood that the introduced process is only an example, the embodiment of the present invention does not limit the specific hard encryption technology or soft encryption technology, and common hard encryption technology or soft encryption technology in the art can be used in step S3.
- initialize the chip engine call the SSL (Secure Sockets Layer, Secure Sockets Layer) protocol initialization function SSL_library_init, and then use the engine loading function ENGINE_load to construct the chip engine. Further, call the initialization engine name function ENGINE_by_id to bind the constructed chip engine to the index, that is, initialize the engine name; then call the encryption algorithm registration function ENGINE_register_RSA to register the encryption algorithm (RSA) of the chip engine in the openssl engine, and finally call the engine setting The function ENGINE_set_default_RSA sets the encryption algorithm of the chip engine to the RSA method by default.
- SSL Secure Sockets Layer
- the pseudo private key is generated by calling the key acquisition method in the chip engine and then using the soft algorithm, which is different from the key generated by calling the built-in key generator rsa_builtin_keygen.
- the pseudo private key is used to run openssl normally. Process.
- the process of loading the hard encryption engine is shown in Figure 6: first, the hard encryption engine is loaded to complete the enumeration of hardware engine devices and other operations; then the random number is generated by the random function, and the random number is sent to the hard encryption engine.
- the hard encryption engine loads the encryption algorithm engine to encrypt the random number, then sends the encryption result to the decryption engine for decryption, and then compares the decryption result with the original random number (that is, the random number generated by the random function) to determine whether the verification is passed.
- the beneficial effect of the present invention is that: the present invention is designed to exist two encryption methods on the same system according to the characteristics of different information—a soft encryption method and a hard encryption method.
- the content and situation of the information are dynamically loaded with two encryption methods, which not only utilizes the advantages of soft encryption technology and hard encryption technology, but also avoids their shortcomings, improving the encryption strength of high-density information and the access speed of non-high-density information, while reducing It reduces the waste of resources and increases the efficiency of encryption and decryption of resources.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Physics & Mathematics (AREA)
- Mathematical Physics (AREA)
- Pure & Applied Mathematics (AREA)
- Mathematical Optimization (AREA)
- Mathematical Analysis (AREA)
- General Physics & Mathematics (AREA)
- Algebra (AREA)
- Storage Device Security (AREA)
Abstract
本发明公开一种动态加载加密引擎的方法,包括:步骤S1,根据待加密信息的安全等级、大小和需访问速度生成加密方式标识符;步骤S2,获取当前待加密信息的加密方式标识符,确定当前待加密信息的加密方式;步骤S3,根据当前待加密信息的加密方式加载对应的加密引擎。本发明根据不同信息的特点,在同一个系统上设计同时存在两种加密方式——软加密方式和硬加密方式,根据信息的内容和情况动态加载两种加密方式,从而既利用了软加密技术和硬加密技术各自的优点,也避免了其缺点,提高了高密信息的加密强度和非高密信息的访问速度,同时减少了资源的浪费,增加了资源的加解密效率。
Description
相关申请
本申请要求于2020年7月20日提交中国国家知识产权局、申请号为CN202010696213.8、发明名称为“一种动态加载加密引擎的方法”的中国专利申请的优先权,上述专利的全部内容通过引用结合在本申请中。
本发明涉及车联网通信安全技术领域,尤其涉及一种动态加载加密引擎的方法。
目前在车联网通信安全领域的加密技术主要有两种:软加密技术和硬加密技术。软加密指不需要额外硬件的软件保护方式,一般采取序列号或许可证文件的授权方式。通常软加密方案采用与计算机软硬件特征绑定的方式,如CPU、BIOS、硬盘、MAC、计算机名、用户名等,因为没有使用额外的硬件设备,被认为是一种“软加密”方案。软加密的安全强度没有硬加密高,但也具有诸多优点,例如:没有硬件和物流,加解密速度快,可实现软件的电子化发行;易于管理和维护,有助于提高授权效率和改善用户体验;降低软件开发商整体的软件保护、发行和管理成本,提高其竞争力。
硬加密是指需要额外硬件设备的软件保护技术,目前主要的硬加密方案是加密锁技术。根据加密锁所用CPU的不同分为普通加密锁和智能卡加密锁。硬件加密具有比较高的安全强度,但也有不少缺点,例如:适用于传统的一次性永久授权,无法方便实现试用版本和按需购买;硬件的存在带来了生产、初始化、物流、安装和维护的成本;无法实现基于互联网的电子化发行;安装驱动和客户端组件以及额外的硬件设备影响了客户的使用体验,难以进行升级、跟踪及售后管理。
目前行业都是在一个产品上设计一种加密方法进行,要么是使用软加密,要么是使用硬加密。在软加密的情况下,如上所述,信息的安全等级不是很高,但是有些高密信息需要更高安全等级的加密方式,这样就会造成信息的不安全性。在硬件加密情况下,部分信息需要的安全等级较低,如果都用硬 加密技术会导致资源的浪费及加密时间的增加。
综上所述,现有的技术方案存在要么加密安全等级不够,要么造成资源的浪费和加解密时间的增加的缺点,难以做到各方面都满足要求。
发明内容
本发明实施例所要解决的技术问题在于,提供一种动态加载加密引擎的方法,对不同的信息采用不同的加密方式,既满足信息的加密需求,又可减少资源浪费,增加资源的加解密效率。
为解决上述技术问题,本发明提供一种动态加载加密引擎的方法,包括:
步骤S1,根据待加密信息的安全等级、大小和需访问速度生成加密方式标识符,其中,所述加密方式标识符包括软加密标识符和硬加密标识符,所述软加密标识符用于标识所述待加密信息须采用软加密方式,所述硬加密标识符用于标识所述待加密信息须采用硬加密方式;
步骤S2,获取当前待加密信息的加密方式标识符,确定当前待加密信息的加密方式;
步骤S3,根据当前待加密信息的加密方式加载对应的加密引擎。
进一步地,所述安全等级包括安全等级高和安全等级低两种类型,所述待加密信息的大小通过与存储空间阈值的比较,包括存储空间大和存储空间小两种类型,所述待加密信息的需访问速度通过与访问速度阈值的比较,包括需访问速度快和需访问速度慢两种类型。
进一步地,所述步骤S1中生成加密方式标识符具体是:对于同时满足安全等级低、存储空间小、需访问速度快的待加密信息生成软加密标识符,其它待加密信息则生成硬加密标识符。
进一步地,所述存储空间阈值设为500k,大于或等于500k的待加密信息属于存储空间大的信息,小于500k的待加密信息属于存储空间小的信息;所述访问速度阈值设为100ms,大于或等于100ms的待加密信息属于需访问速度慢的信息,小于100ms的待加密信息属于需访问速度快的信息。
进一步地,所述步骤S2获取当前待加密信息的加密方式标识符的方式包括:直接读取携带在所述当前待加密信息中的加密方式标识符;或者查询由各待加密信息及其加密方式标识符形成的表格。
进一步地,所述步骤S3根据所述步骤S2确定的当前待加密信息的加密方式,加载软加密引擎或者硬加密引擎,加载软加密引擎的步骤包括:
进行芯片引擎初始化;
生成芯片秘钥;
加载芯片密钥。
进一步地,所述进行芯片引擎初始化的步骤包括:
调用SSL协议初始化函数,然后使用引擎加载函数构造芯片引擎;
调用初始化引擎名函数将构造的所述芯片引擎与索引绑定;
调用加密算法注册函数将所述芯片引擎的加密算法注册到openssl引擎中;
调用引擎设置函数将所述芯片引擎的加密算法设置默认为RSA方法。
进一步地,所述生成芯片秘钥的步骤包括:
调用密钥生成函数生成密钥对;
判断软加密引擎中是否存在获取密钥的方法,如果存在,则进一步调用内置密钥生成器生成密钥,然后直接返回密钥结构;如果不存在,则调用芯片引擎中的获取密钥方法,通过软算法生成伪私钥,再进一步调用芯片获取密钥接口获取密钥对里的N和E,然后判断芯片密钥是否生成成功,若成功则替换软算法生成的伪密钥中的N和E并返回密钥结构,若失败则返回错误返回码。
进一步地,所述加载芯片密钥的步骤包括:
调用密钥加载函数读取跟随车辆数字证书一起下载的软密钥文件,并判断是否读取成功;如果读取失败,则新建密钥文件并将默认密钥信息写入到所述软密钥文件,然后将获取的密钥文件句柄传入,构造用于存放非对称密钥信息的EVP_PKEY结构;如果读取成功则将获取的密钥文件句柄传入,构造EVP_PKEY结构;
调用芯片查询密钥接口获取密钥对里的N和E,并判断是否获取成功,若成功,则将从芯片返回的N和E替换到软密钥生成的EVP_PKEY结构中,然后返回EVP_PKEY结构,若失败则返回空指针。
进一步地,加载硬加密引擎的步骤包括:
加载硬加密引擎;
通过随机函数产生随机数,将随机数发送给硬加密引擎;
硬加密引擎加载加密算法引擎对随机数进行加密;
将加密结果发送给解密引擎解密;
将解密结果与通过随机函数产生的随机数进行比对,判断是否通过验证。
实施本发明具有如下有益效果:本发明根据不同信息的特点,在同一个系统上设计同时存在两种加密方式——软加密方式和硬加密方式,根据信息的内容和情况动态加载两种加密方式,从而既利用了软加密技术和硬加密技术各自的优点,也避免了其缺点,提高了高密信息的加密强度和非高密信息的访问速度,同时减少了资源的浪费,增加了资源的加解密效率。
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本发明实施例一种动态加载加密引擎的方法的流程示意图。
图2为本发明实施例中加载软加密引擎的流程示意图。
图3为本发明实施例中芯片引擎初始化的流程示意图。
图4为本发明实施例中生成密钥的流程示意图。
图5为本发明实施例中加载芯片密钥的流程示意图。
图6为本发明实施例中加载硬加密引擎的流程示意图。
以下各实施例的说明是参考附图,用以示例本发明可以用以实施的特定实施例。
请参照图1所示,本发明实施例提供一种动态加载加密引擎的方法,包括:
步骤S1,根据待加密信息的安全等级、大小和需访问速度生成加密方式标识符,其中,所述加密方式标识符包括软加密标识符和硬加密标识符,所述软加密标识符用于标识所述待加密信息须采用软加密方式,所述硬加密 标识符用于标识所述待加密信息须采用硬加密方式;
步骤S2,获取当前待加密信息的加密方式标识符,确定当前待加密信息的加密方式;
步骤S3,根据当前待加密信息的加密方式加载对应的加密引擎。
具体地,步骤S1需要获取的待加密信息的要素包括:(1)安全等级;(2)大小;(3)需访问速度;其中,待加密信息的安全等级是指待加密信息的保密性,保密性高则安全等级也高,表明需要加密程度更高的加密方式;信息大小是指待加密信息所需的存储空间,需访问速度是指待加密信息是否需要被快速访问。本实施例中,安全等级包括安全等级高和安全等级低两种类型,例如大车载娱乐交互信息的安全等级一般为低,而车辆位置信息的安全等级为高;待加密信息的大小通过与存储空间阈值的比较,可分为存储空间大和存储空间小两种类型;待加密信息的需访问速度通过与访问速度阈值的比较,可分为需访问速度快和需访问速度慢两种类型。
作为一种示例,存储空间阈值可设为500k,大于或等于500k的待加密信息属于存储空间大的信息,小于500k的待加密信息属于存储空间小的信息。访问速度阈值可设为100ms,大于或等于100ms的待加密信息属于需访问速度慢的信息,小于100ms的待加密信息属于需访问速度快的信息。
根据获取的待加密信息的上述三要素,可以生成加密方式标识符,用于标识待加密信息的加密方式,具体地,本实施例中加密方式标识符包括软加密标识符和硬加密标识符,其中,软加密标识符用于标识该待加密信息须采用软加密方式,硬加密标识符用于标识该待加密信息须采用硬加密方式。可以理解的是,软加密标识符和硬加密标识符可以用数值1或0来区分,例如0代表软加密标识符,1代表硬加密标识符。
生成加密方式标识符的一种标准是:对于同时满足安全等级低、存储空间小、需访问速度快的待加密信息生成软加密标识符,其它待加密信息则生成硬加密标识符。对于安全等级低、存储空间小、需访问速度快的信息使用软加密方式,能够提高加解密效率;对于安全等级较高的信息使用硬加密方式,可以提高数据的加密强度。
步骤S2对当前要传输的待加密信息实时获取其加密方式标识符,进而 根据加密方式标识符确定该当前待加密信息的加密方式。获取方式包括两种,一种是直接读取,一种是查表。对于直接获取方式,系直接读取携带在该当前待加密信息中的加密方式标识符;如前所述,加密方式标识符可用数值1或0增加在该当前待加密信息的消息体中。对于查表方式,则是查询由各待加密信息及其加密方式标识符形成的表格;该表格可以是一维表格,表格里各待加密信息与其加密方式标识符一一对应,同样地,加密方式标识符可用数值1或0来表示。
需要说明的是,步骤S2的处理是实时的,能够对不同的待加密信息实时确定其加密方式,以便步骤S3动态加载对应的加密引擎。例如,对于用户画像信息,因其安全等级高,在步骤S1中已生成硬加密标识符,则步骤S2通过前述直接读取或查表方式获取其硬加密标识符,从而确定对其将采用硬加密方式;又如,对于车载娱乐交互信息,因其同时满足安全等级低、存储空间小、需访问速度快,在步骤S1中已生成软加密标识符,则步骤S2通过前述直接读取或查表方式获取其软加密标识符,从而确定对其将采用软加密方式。
步骤S3将根据步骤S2确定的当前待加密信息的加密方式,加载对应的加密引擎。以下分别介绍加载软加密引擎和加载硬加密引擎的流程。可以理解的是,所介绍的流程仅为举例,本发明实施例对具体的硬加密技术或软加密技术并不做限定,本领域常见的硬加密技术或软加密技术均可用于步骤S3。
首先介绍加载软加密引擎的流程,请同时结合图2-图5所示:
首先进行芯片引擎初始化:调用SSL(Secure Sockets Layer,安全套接层)协议初始化函数SSL_library_init,然后使用引擎加载函数ENGINE_load构造芯片引擎。进一步地,调用初始化引擎名函数ENGINE_by_id将构造的芯片引擎与索引绑定,即初始化引擎名;再调用加密算法注册函数ENGINE_register_RSA将芯片引擎的加密算法(RSA)注册到openssl引擎中,最后调用引擎设置函数ENGINE_set_default_RSA将芯片引擎的加密算法设置默认为RSA方法。
其次生成芯片秘钥:首先调用密钥生成函数RSA_generate_key或者 RSA_generate_key_ex生成密钥对,然后判断软加密引擎中是否存在获取密钥的方法;如果存在,则进一步调用内置密钥生成器rsa_builtin_keygen生成密钥,然后直接返回密钥结构;如果不存在,则调用芯片引擎中的获取密钥方法,然后通过软算法生成伪私钥,再进一步地调用芯片获取密钥接口获取密钥对里的N(模数)和E(公钥指数),然后判断芯片密钥是否生成成功,若成功则替换软算法生成的伪密钥中的N和E并返回密钥结构,若失败则返回错误返回码。需要说明的是,调用芯片引擎中的获取密钥方法然后通过软算法生成的是伪私钥,与调用内置密钥生成器rsa_builtin_keygen生成的密钥不一样,该伪私钥是为了正常运行openssl的流程。
最后加载芯片密钥:首先调用密钥加载函数ENGINE_load_private_key或ENGINE_load_public_key读取跟随车辆数字证书一起下载的软密钥文件;接着判断是否读取成功;如果读取失败,则新建密钥文件并将默认密钥(是一个假密钥,用来完善流程)信息写入到该软密钥文件,然后调用PEM_read_PrivateKey将获取的密钥文件句柄传入,构造用于存放非对称密钥信息的EVP_PKEY结构;如果读取成功则直接调用PEM_read_PrivateKey将获取的密钥文件句柄传入,构造EVP_PKEY结构。进一步地,调用芯片查询密钥接口MizerQueryRsaKey,获取密钥对里的N和E;然后判断是否获取成功,若成功,则将从芯片返回的N和E替换到软密钥生成的EVP_PKEY结构中,然后返回EVP_PKEY结构,若失败则返回空指针。
加载硬加密引擎的流程如图6所示:首先加载硬加密引擎,完成硬件引擎设备的枚举等操作;然后通过随机函数产生随机数,将随机数发送给硬加密引擎。硬加密引擎加载加密算法引擎对随机数进行加密,然后将加密结果发给解密引擎解密,再将解密结果与原始随机数(即通过随机函数产生的随机数)进行比对,判断是否通过验证。
通过上述说明可知,与现有技术相比,本发明的有益效果在于:本发明根据不同信息的特点,在同一个系统上设计同时存在两种加密方式——软加密方式和硬加密方式,根据信息的内容和情况动态加载两种加密方式,从而既利用了软加密技术和硬加密技术各自的优点,也避免了其缺点,提高了高密信息的加密强度和非高密信息的访问速度,同时减少了资源的浪费,增加 了资源的加解密效率。
以上所揭露的仅为本发明较佳实施例而已,当然不能以此来限定本发明之权利范围,因此依本发明权利要求所作的等同变化,仍属本发明所涵盖的范围。
Claims (10)
- 一种动态加载加密引擎的方法,其特征在于,包括:步骤S1,根据待加密信息的安全等级、大小和需访问速度生成加密方式标识符,其中,所述加密方式标识符包括软加密标识符和硬加密标识符,所述软加密标识符用于标识所述待加密信息须采用软加密方式,所述硬加密标识符用于标识所述待加密信息须采用硬加密方式;步骤S2,获取当前待加密信息的加密方式标识符,确定当前待加密信息的加密方式;步骤S3,根据当前待加密信息的加密方式加载对应的加密引擎。
- 根据权利要求1所述的方法,其特征在于,所述安全等级包括安全等级高和安全等级低两种类型,所述待加密信息的大小通过与存储空间阈值的比较,包括存储空间大和存储空间小两种类型,所述待加密信息的需访问速度通过与访问速度阈值的比较,包括需访问速度快和需访问速度慢两种类型。
- 根据权利要求2所述的方法,其特征在于,所述步骤S1中生成加密方式标识符具体是:对于同时满足安全等级低、存储空间小、需访问速度快的待加密信息生成软加密标识符,其它待加密信息则生成硬加密标识符。
- 根据权利要求2所述的方法,其特征在于,所述存储空间阈值设为500k,大于或等于500k的待加密信息属于存储空间大的信息,小于500k的待加密信息属于存储空间小的信息;所述访问速度阈值设为100ms,大于或等于100ms的待加密信息属于需访问速度慢的信息,小于100ms的待加密信息属于需访问速度快的信息。
- 根据权利要求4所述的方法,其特征在于,所述步骤S2获取当前待加密信息的加密方式标识符的方式包括:直接读取携带在所述当前待加密信息中的加密方式标识符;或者查询由各待加密信息及其加密方式标识符形成的表格。
- 根据权利要求1所述的方法,其特征在于,所述步骤S3根据所述步骤S2确定的当前待加密信息的加密方式,加载软加密引擎或者硬加密引擎,加载软加密引擎的步骤包括:进行芯片引擎初始化;生成芯片秘钥;加载芯片密钥。
- 根据权利要求6所述的方法,其特征在于,所述进行芯片引擎初始化的步骤包括:调用SSL协议初始化函数,然后使用引擎加载函数构造芯片引擎;调用初始化引擎名函数将构造的所述芯片引擎与索引绑定;调用加密算法注册函数将所述芯片引擎的加密算法注册到openssl引擎中;调用引擎设置函数将所述芯片引擎的加密算法设置默认为RSA方法。
- 根据权利要求7所述的方法,其特征在于,所述生成芯片秘钥的步骤包括:调用密钥生成函数生成密钥对;判断软加密引擎中是否存在获取密钥的方法,如果存在,则进一步调用内置密钥生成器生成密钥,然后直接返回密钥结构;如果不存在,则调用芯片引擎中的获取密钥方法,通过软算法生成伪私钥,再进一步调用芯片获取密钥接口获取密钥对里的N和E,然后判断芯片密钥是否生成成功,若成功则替换软算法生成的伪密钥中的N和E并返回密钥结构,若失败则返回错误返回码。
- 根据权利要求8所述的方法,其特征在于,所述加载芯片密钥的步骤包括:调用密钥加载函数读取跟随车辆数字证书一起下载的软密钥文件,并判断是否读取成功;如果读取失败,则新建密钥文件并将默认密钥信息写入到所述软密钥文件,然后将获取的密钥文件句柄传入,构造用于存放非对称密钥信息的EVP_PKEY结构;如果读取成功则将获取的密钥文件句柄传入,构造EVP_PKEY结构;调用芯片查询密钥接口获取密钥对里的N和E,并判断是否获取成功,若成功,则将从芯片返回的N和E替换到软密钥生成的EVP_PKEY结构中,然后返回EVP_PKEY结构,若失败则返回空指针。
- 根据权利要求6所述的方法,其特征在于,加载硬加密引擎的步骤 包括:加载硬加密引擎;通过随机函数产生随机数,将随机数发送给硬加密引擎;硬加密引擎加载加密算法引擎对随机数进行加密;将加密结果发送给解密引擎解密;将解密结果与通过随机函数产生的随机数进行比对,判断是否通过验证。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US17/991,743 US12425206B2 (en) | 2020-07-20 | 2022-11-21 | Method of dynamically loading encryption engine |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202010696213.8 | 2020-07-20 | ||
| CN202010696213.8A CN114039736B (zh) | 2020-07-20 | 2020-07-20 | 一种动态加载加密引擎的方法 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US17/991,743 Continuation-In-Part US12425206B2 (en) | 2020-07-20 | 2022-11-21 | Method of dynamically loading encryption engine |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022017103A1 true WO2022017103A1 (zh) | 2022-01-27 |
Family
ID=79729705
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2021/101481 Ceased WO2022017103A1 (zh) | 2020-07-20 | 2021-06-22 | 一种动态加载加密引擎的方法 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US12425206B2 (zh) |
| CN (1) | CN114039736B (zh) |
| WO (1) | WO2022017103A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2022266831A1 (zh) * | 2021-06-22 | 2022-12-29 | 华为技术有限公司 | 数据处理方法及处理器 |
| CN116015622A (zh) * | 2022-11-30 | 2023-04-25 | 上海华峰创享互联网络科技有限公司 | 一种用于标识解析体系的安全存储及权限管理的方法 |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116455621A (zh) * | 2023-04-03 | 2023-07-18 | 海光信息技术股份有限公司 | 数据加密方法、装置、系统、电子设备及存储介质 |
| CN119449494B (zh) * | 2025-01-09 | 2025-04-04 | 杭州阿启视科技有限公司 | 基于动态策略的视频监控平台软硬件加解密方法 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6028933A (en) * | 1997-04-17 | 2000-02-22 | Lucent Technologies Inc. | Encrypting method and apparatus enabling multiple access for multiple services and multiple transmission modes over a broadband communication network |
| CN104123506A (zh) * | 2013-04-28 | 2014-10-29 | 北京壹人壹本信息科技有限公司 | 数据访问方法、装置、数据加密、存储及访问方法、装置 |
| CN105376051A (zh) * | 2014-08-29 | 2016-03-02 | 宇龙计算机通信科技(深圳)有限公司 | 一种加密方法、装置及终端 |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20150026462A1 (en) * | 2013-03-15 | 2015-01-22 | Dataguise, Inc. | Method and system for access-controlled decryption in big data stores |
| CN103716166A (zh) * | 2013-12-27 | 2014-04-09 | 哈尔滨工业大学深圳研究生院 | 一种自适应混合加密方法、装置以及加密通信系统 |
| CN104283893B (zh) * | 2014-10-28 | 2017-09-22 | 中国建设银行股份有限公司 | 一种安全信息上收方法和服务器 |
| CN105530092B (zh) * | 2015-12-09 | 2018-05-08 | 中国航空工业集团公司西安航空计算技术研究所 | 一种ima处理机系统信息安全管理方法 |
| CN110795774B (zh) * | 2018-08-02 | 2023-04-11 | 阿里巴巴集团控股有限公司 | 基于可信高速加密卡的度量方法、设备和系统 |
| CN109120998B (zh) * | 2018-08-28 | 2021-04-02 | 苏州科达科技股份有限公司 | 媒体数据传输方法、装置及存储介质 |
-
2020
- 2020-07-20 CN CN202010696213.8A patent/CN114039736B/zh active Active
-
2021
- 2021-06-22 WO PCT/CN2021/101481 patent/WO2022017103A1/zh not_active Ceased
-
2022
- 2022-11-21 US US17/991,743 patent/US12425206B2/en active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6028933A (en) * | 1997-04-17 | 2000-02-22 | Lucent Technologies Inc. | Encrypting method and apparatus enabling multiple access for multiple services and multiple transmission modes over a broadband communication network |
| CN104123506A (zh) * | 2013-04-28 | 2014-10-29 | 北京壹人壹本信息科技有限公司 | 数据访问方法、装置、数据加密、存储及访问方法、装置 |
| CN105376051A (zh) * | 2014-08-29 | 2016-03-02 | 宇龙计算机通信科技(深圳)有限公司 | 一种加密方法、装置及终端 |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2022266831A1 (zh) * | 2021-06-22 | 2022-12-29 | 华为技术有限公司 | 数据处理方法及处理器 |
| CN116015622A (zh) * | 2022-11-30 | 2023-04-25 | 上海华峰创享互联网络科技有限公司 | 一种用于标识解析体系的安全存储及权限管理的方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN114039736A (zh) | 2022-02-11 |
| US12425206B2 (en) | 2025-09-23 |
| US20230093105A1 (en) | 2023-03-23 |
| CN114039736B (zh) | 2023-01-06 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US20230396593A1 (en) | Techniques for shared private data objects in a trusted execution environment | |
| WO2022017103A1 (zh) | 一种动态加载加密引擎的方法 | |
| EP1391802B1 (en) | Saving and retrieving data based on symmetric key encryption | |
| EP1391801B1 (en) | Saving and retrieving data based on public key encryption | |
| US9064129B2 (en) | Managing data | |
| CN100547598C (zh) | 基于对称密钥加密保存和检索数据 | |
| WO2004044751A1 (en) | A method for realizing security storage and algorithm storage by means of semiconductor memory device | |
| CN117786758B (zh) | 基于可信执行环境的密态数据库系统和电子设备 | |
| CN112136133B (zh) | 用于管理对区块链的访问的方法和网络节点 | |
| CN115550042B (zh) | 基于安全芯片实现国密算法的签名验签服务器 | |
| US8755521B2 (en) | Security method and system for media playback devices | |
| CN116992494B (zh) | 一种用于景区数据流通的安全保护方法、设备和介质 | |
| CN116346340A (zh) | 一种鉴权方法及相关装置 | |
| CN116418501A (zh) | 安全信息的存储方法、装置、电子设备及介质 | |
| CN111523127A (zh) | 一种用于密码设备的权限认证方法及系统 | |
| CN119475403B (zh) | 一种鸿蒙系统设备中的数据安全读写方法及装置 | |
| Yizheng et al. | Design and implementation of USB key-based javaee dual-factor authentication system | |
| CN119167416A (zh) | 一种面向移动存储设备的安全跨平台文件系统及方法 | |
| CN116633618A (zh) | 秘钥加密和解密方法及存储、应用控制系统、电子设备 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21846085 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21846085 Country of ref document: EP Kind code of ref document: A1 |