CN114139176A - A national secret-based protection method and system for industrial Internet core data - Google Patents

A national secret-based protection method and system for industrial Internet core data Download PDF

Info

Publication number
CN114139176A
CN114139176A CN202111342209.2A CN202111342209A CN114139176A CN 114139176 A CN114139176 A CN 114139176A CN 202111342209 A CN202111342209 A CN 202111342209A CN 114139176 A CN114139176 A CN 114139176A
Authority
CN
China
Prior art keywords
cloud platform
data
platform
user
management subsystem
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN202111342209.2A
Other languages
Chinese (zh)
Other versions
CN114139176B (en
Inventor
刘瀛
解月江
何枫
付玮
周袁正
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Daotech Technology Co ltd
Original Assignee
Daotech Technology Co ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Daotech Technology Co ltd filed Critical Daotech Technology Co ltd
Priority to CN202111342209.2A priority Critical patent/CN114139176B/en
Publication of CN114139176A publication Critical patent/CN114139176A/en
Application granted granted Critical
Publication of CN114139176B publication Critical patent/CN114139176B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/602Providing cryptographic facilities or services
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/33User authentication using certificates
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Storage Device Security (AREA)

Abstract

The protection system comprises a Certificate Authority (CA), an edge computing gateway, a cloud platform, a user platform and a password service platform, wherein the password service platform comprises a secret key management subsystem; the method comprises the following steps: based on a digital certificate USB-KEY issued by CA and based on a national secret SM2 algorithm and a CA certificate, the cloud platform and each edge computing gateway perform mutual authentication to construct an SSL data channel; the user platform logs in the cloud platform based on the user ID and the national password dynamic password; when the user platform transmits the data plaintext of the industrial internet core data to the cloud platform, the cloud platform transmits the data plaintext to the key management subsystem; and the key management subsystem encrypts the data plain text and transmits the encrypted data cipher text to the cloud platform for storage. By the method and the system, a state cryptographic algorithm can be completely used, a complete set of solution method and system are provided for data security protection, and data security is improved.

Description

Industrial internet core data protection method and system based on state secret
Technical Field
The invention relates to the field of data processing, in particular to a method and a system for protecting industrial internet core data based on a state secret.
Background
Industrial internet is in a vigorous development period, core data generated in an industrial production process can go through a plurality of stages of data generation, data acquisition, data transmission, data analysis, data display and the like, and in a data life cycle process, it is very important to ensure data security.
Currently, in the field of industrial internet, encryption of core data is mainly performed through international key standards such as RSA, DES, and the like. There is no perfect solution based entirely on national secrets to protect the core data of an industrial process from security and reliability throughout its life. Therefore, a data protection method based on the national password is needed.
Disclosure of Invention
According to one aspect of the disclosure, a protection method of industrial internet core data based on a state key is provided, and is realized by a protection system of industrial internet core data based on a state key, wherein the protection system comprises a Certificate Authority (CA), an edge computing gateway, a cloud platform, a user platform and a password service platform, and the password service platform comprises a secret key management subsystem;
the method comprises the following steps:
based on the digital certificate USB-KEY issued by the CA and based on the SM2 cryptographic algorithm and the CA certificate, the cloud platform and each edge computing gateway perform bidirectional authentication, and an SSL data channel is constructed for data transmission;
the user platform logs in the cloud platform based on the user ID and the national password dynamic password;
when the user platform transmits data plaintext of industrial internet core data to the cloud platform, the cloud platform transmits the data plaintext to the key management subsystem;
and the key management subsystem encrypts the data plaintext, and transmits the encrypted data ciphertext to the cloud platform for storage, so that the storage protection operation of the industrial internet core data is completed.
According to another aspect of the disclosure, a protection system for industrial internet core data based on a national password is provided, and the protection system comprises a Certificate Authority (CA), an edge computing gateway, a cloud platform, a user platform and a password service platform, wherein the password service platform comprises a secret key management subsystem; wherein:
the CA is used for issuing a digital certificate USB-KEY and a CA certificate based on a SM2 cryptographic algorithm to the cloud platform and each edge computing gateway;
the edge computing gateway is used for performing bidirectional authentication with the cloud platform, constructing an SSL data channel with the cloud platform for data transmission, and allowing the user platform to log in the cloud platform;
the user platform is used for logging in the cloud platform and transmitting data plaintext of industrial internet core data to the cloud platform;
the cloud platform is used for performing bidirectional authentication with the edge computing gateway, constructing an SSL data channel with the edge computing gateway for data transmission, receiving a data plaintext sent by a user platform, sending the data plaintext to the key management subsystem, receiving a data ciphertext sent by the key management subsystem, and storing the data ciphertext;
the key management subsystem is used for receiving the data plaintext sent by the cloud platform, encrypting the data plaintext and sending an encrypted data ciphertext to the cloud platform;
the password service platform is used for distributing an entity password token to the cloud platform, verifying the user identity of the user platform and sending a verification passing instruction or a verification failing instruction to the cloud platform.
According to another aspect of the present disclosure, a protection apparatus for industrial internet core data based on a national secret is provided, and the apparatus is arranged in a protection system for industrial internet core data based on a national secret, wherein the protection system includes a certificate authority CA, an edge computing gateway, a cloud platform, a user platform, and a cryptographic service platform, and the cryptographic service platform includes a secret key management subsystem;
the device comprises:
the building module is used for performing bidirectional authentication on the cloud platform and each edge computing gateway based on a digital certificate USB-KEY issued by the CA and based on a SM2 algorithm and the CA certificate, and building an SSL data channel for data transmission;
the login module is used for the user platform to log in the cloud platform through the edge computing gateway based on the user ID and the national password;
the transmission module is used for transmitting the data plaintext of the industrial internet core data to the cloud platform by the cloud platform when the user platform transmits the data plaintext to the key management subsystem;
and the encryption module is used for encrypting the data plaintext by the secret key management subsystem and transmitting the encrypted data ciphertext to the cloud platform for storage so as to finish the storage protection operation of the industrial internet core data.
According to another aspect of the present disclosure, there is provided an electronic device including:
a processor; and
a memory for storing a program, wherein the program is stored in the memory,
wherein the program includes instructions which, when executed by the processor, cause the processor to execute the protection method based on the national secret industrial internet core data.
According to another aspect of the present disclosure, there is provided a non-transitory computer readable storage medium storing computer instructions for causing a computer to perform the above-described method for protecting industrial internet core data based on a cryptographic key.
One or more technical schemes provided in the embodiment of the application can realize complete use of the national cryptographic algorithm, provide a whole set of solution method and system for data security protection, and improve the security of industrial internet core data.
Drawings
Further details, features and advantages of the disclosure are disclosed in the following description of exemplary embodiments, taken in conjunction with the accompanying drawings, in which:
fig. 1 illustrates a flowchart of a protection method based on national password industrial internet core data according to an exemplary embodiment of the present disclosure;
fig. 2 illustrates a flowchart of edge computing gateway identity authentication based on a country key according to an exemplary embodiment of the present disclosure;
FIG. 3 illustrates a flowchart for national password based user platform identity authentication, according to an exemplary embodiment of the present disclosure;
FIG. 4 illustrates a cryptographic core data storage flow diagram according to an exemplary embodiment of the present disclosure;
fig. 5 shows a schematic block diagram of a national cryptographic based industrial internet core data protection system according to an exemplary embodiment of the present disclosure;
fig. 6 shows a schematic block diagram of a protection apparatus based on national secret industrial internet core data according to an exemplary embodiment of the present disclosure;
FIG. 7 illustrates a block diagram of an exemplary electronic device that can be used to implement embodiments of the present disclosure.
Detailed Description
Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. While certain embodiments of the present disclosure are shown in the drawings, it is to be understood that the present disclosure may be embodied in various forms and should not be construed as limited to the embodiments set forth herein, but rather are provided for a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the disclosure are for illustration purposes only and are not intended to limit the scope of the disclosure.
It should be understood that the various steps recited in the method embodiments of the present disclosure may be performed in a different order, and/or performed in parallel. Moreover, method embodiments may include additional steps and/or omit performing the illustrated steps. The scope of the present disclosure is not limited in this respect.
The term "include" and variations thereof as used herein are open-ended, i.e., "including but not limited to". The term "based on" is "based, at least in part, on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Relevant definitions for other terms will be given in the following description. It should be noted that the terms "first", "second", etc. in this disclosure are only used for distinguishing different systems, modules or units, and are not used for limiting the order or interdependence relationship of the functions performed by these systems, modules or units.
It is noted that references to "a", "an", and "the" modifications in this disclosure are intended to be illustrative rather than limiting, and that those skilled in the art will recognize that "one or more" may be used unless the context clearly dictates otherwise.
The names of messages or information exchanged between the systems in the embodiments of the present disclosure are for illustrative purposes only, and are not intended to limit the scope of such messages or information.
The embodiment of the disclosure provides a method for protecting industrial internet core data based on a national key, which can be implemented by a system for protecting industrial internet core data based on a national key, wherein the system for protecting industrial internet core data comprises a Certificate Authority (CA), an edge computing gateway, a cloud platform, a user platform and a cryptographic service platform, and the cryptographic service platform comprises a key management subsystem. As shown in fig. 1, a flowchart of a protection method based on national secret industrial internet core data, a processing flow of the method may include the following steps:
step 101, based on a digital certificate USB-KEY issued by a CA and based on a SM2 cryptographic algorithm and the CA certificate, performing bidirectional authentication on a cloud platform and each edge computing gateway, and constructing an SSL data channel for data transmission;
102, a user platform logs in a cloud platform based on a user ID and a national password dynamic password;
103, when the user platform transmits the data plaintext of the industrial internet core data to the cloud platform, the cloud platform transmits the data plaintext to the key management subsystem;
and step 104, encrypting the data plaintext by the key management subsystem, and transmitting the encrypted data ciphertext to the cloud platform for storage so as to complete the storage protection operation of the industrial internet core data.
Optionally, based on the digital certificate USB-KEY issued by the CA based on the cryptographic SM2 algorithm and the CA certificate, the cloud platform performs bidirectional authentication with each edge computing gateway, and constructs an SSL data channel for data transmission, including:
the CA respectively issues a digital certificate USB-KEY and a CA certificate based on a SM2 cryptographic algorithm to the cloud platform and each edge computing gateway;
the cloud platform exchanges a digital certificate USB-KEY with each edge computing gateway to perform bidirectional authentication;
when the bidirectional authentication between the cloud platform and the edge computing gateway is passed, the edge computing gateway is connected with the cloud platform, and an SSL data channel is constructed to transmit data.
Optionally, the method includes the steps of, after the cloud platform exchanges the digital certificate USB-KEY with each edge computing gateway and performs bidirectional authentication, further including:
when the bidirectional authentication between the cloud platform and the edge computing gateways fails, the CA issues a digital certificate USB-KEY and a CA certificate based on the SM2 cryptographic algorithm to the cloud platform and each edge computing gateway again;
and the cloud platform exchanges the digital certificate USB-KEY with each edge computing gateway again for bidirectional authentication.
Optionally, the user platform logs in the cloud platform based on the user ID and the national password, including:
when the cloud platform receives a registration request instruction sent by the user platform, the cloud platform applies for an entity password token for the user platform from the password service platform;
when a user platform sends a login request instruction to a cloud platform, the cloud platform receives a user ID and a national password dynamic password sent by the user platform;
the cloud platform verifies the user identity to the password service platform based on the user ID and the national password;
and when the cloud platform receives the verification passing instruction sent by the password service platform, the cloud platform sends a login success instruction to the user platform.
Optionally, after verifying the user identity to the password service platform based on the user ID and the national password, the cloud platform further includes:
when the cloud platform receives a verification failure instruction sent by the password service platform, the cloud platform sends a login failure instruction to the user platform to prompt the user platform to input the user ID and the national password again.
Optionally, the cloud platform transmits the data plaintext to the key management subsystem, including:
after the SSL channel is established between the cloud platform and the key management subsystem, the cloud platform sends a key application instruction to the key management subsystem;
when the secret key management subsystem receives a secret key application instruction, the secret key management subsystem generates a secret key and a secret key identifier and sends the secret key identifier to the cloud platform;
and after receiving the key identifier, the cloud platform transmits the data plaintext and the key identifier to the key management subsystem.
Optionally, the encrypting the data plaintext by the key management subsystem, and transmitting the encrypted data ciphertext to the cloud platform for storage includes:
when the key management subsystem receives the data plaintext and the key identifier, the corresponding key is obtained through the key identifier;
the secret key management subsystem encrypts the data plaintext through the secret key to obtain a data ciphertext corresponding to the data plaintext, and sends the data ciphertext to the cloud platform;
and the cloud platform stores the received data cipher text.
Optionally, the method further comprises:
when the cloud platform receives a data plaintext acquisition instruction sent by the user platform, the cloud platform transmits a data ciphertext corresponding to the data plaintext acquisition instruction to the key management subsystem;
the secret key management subsystem decrypts the data ciphertext to obtain a data plaintext and a secret key identifier;
the secret key management subsystem sends the data plaintext and the secret key identifier to the cloud platform;
and the cloud platform sends the data plaintext to the user platform.
In the embodiment of the disclosure, by completely using the national cryptographic algorithm, a whole set of solution method and system is provided for data security protection from data acquisition in a production field, data transmission from an edge computing gateway to a cloud platform, data encryption and decryption processing and data storage on the cloud platform, to data life cycle processes such as data display and the like in the industrial internet field, so that the security of the core data storage of the industrial internet is improved, and good practice is provided for application and popularization of the national cryptographic algorithm in the industrial internet field.
The embodiment of the present disclosure provides an identity authentication method for an edge computing gateway based on a country key, which may be implemented by a CA, an edge computing gateway, and a cloud platform in a protection system for industrial internet core data based on a country key, for example, as shown in fig. 2, an identity authentication flow chart for an edge computing gateway based on a country key, and a processing flow of the method may include the following steps:
step 201, the CA issues a digital certificate USB-KEY and a CA certificate based on the SM2 cryptographic algorithm to the cloud platform and each edge computing gateway respectively.
Step 202, the cloud platform exchanges the digital certificate USB-KEY with each edge computing gateway to perform bidirectional authentication.
And 203, when the bidirectional authentication between the cloud platform and the edge computing gateway passes, establishing connection between the edge computing gateway and the cloud platform, and constructing an SSL data channel for data transmission.
And step 204, when the bidirectional authentication between the cloud platform and the edge computing gateways fails, the CA issues the digital certificate USB-KEY and the CA certificate based on the SM2 cryptographic algorithm to the cloud platform and each edge computing gateway again.
And step 205, the cloud platform exchanges the digital certificate USB-KEY with each edge computing gateway again to perform bidirectional authentication.
In the embodiment of the disclosure, through the bidirectional certificate authentication process of the SM2 cryptographic algorithm, the edge computing gateway is guaranteed to be a legal platform user after CA authentication, and a malicious user is prevented from being connected with the cloud platform. The subsequent data transmission of the edge computing gateway passes through an SSL (Secure Sockets Layer) channel, and the data is encrypted by a national secret symmetric key SM4 in the transmission process, so that the data is prevented from being leaked and tampered in the end-to-end transmission process.
The embodiment of the present disclosure provides a user platform identity authentication method based on a national secret, which may be implemented by a user platform, a cloud platform, and a password service platform in a protection system of industrial internet core data based on a national secret, for example, as shown in a user platform identity authentication flow chart based on a national secret shown in fig. 3, a processing flow of the method may include the following steps:
step 301, when the cloud platform receives a registration request instruction sent by the user platform, the cloud platform applies for an entity password token for the user platform from the password service platform.
Step 302, when the user platform sends a login request instruction to the cloud platform, the cloud platform receives the user ID and the national password sent by the user platform.
Step 303, the cloud platform verifies the user identity to the password service platform based on the user ID and the national password dynamic password.
And step 304, when the cloud platform receives the verification passing instruction sent by the password service platform, the cloud platform sends a login success instruction to the user platform.
And 305, when the cloud platform receives a verification failure instruction sent by the password service platform, the cloud platform sends a login failure instruction to the user platform to prompt the user platform to input the user ID and the national password again.
In the embodiment of the disclosure, the user platform is subjected to identity authentication through the user ID and the national password dynamic password, the dynamic password has short timeliness, and the probability that a malicious user logs in the cloud platform, checks and operates core data in industrial production due to password leakage is reduced.
The embodiment of the present disclosure provides a core data encryption storage method based on a national secret, which may be implemented by a user platform, a cloud platform, and a secret key management subsystem in a protection system of industrial internet core data based on the national secret, and as shown in fig. 4, a core data encryption storage flow chart based on the national secret may include the following steps:
step 401, when the user platform transmits the data plaintext of the industrial internet core data to the cloud platform, after the SSL channel is established between the cloud platform and the key management subsystem, the cloud platform sends a key application instruction to the key management subsystem.
Step 402, when the key management subsystem receives the key application instruction, the key management subsystem generates a key and a key identifier, and sends the key identifier to the cloud platform.
Step 403, after receiving the key identifier, the cloud platform transmits the data plaintext and the key identifier to the key management subsystem.
In step 404, when the key management subsystem receives the data plaintext and the key identifier, the corresponding key is obtained through the key identifier.
And 405, encrypting the data plaintext by the key management subsystem through the key to obtain a data ciphertext corresponding to the data plaintext, and sending the data ciphertext to the cloud platform.
And step 406, the cloud platform stores the received data cipher text.
Step 407, when the cloud platform receives the data plaintext acquisition instruction sent by the user platform, the cloud platform transmits the data ciphertext corresponding to the data plaintext acquisition instruction to the key management subsystem.
And step 408, the key management subsystem decrypts the data ciphertext to obtain a data plaintext and a key identifier.
Step 409, the key management subsystem sends the data plaintext and the key identifier to the cloud platform.
And step 410, the cloud platform sends the data plaintext to the user platform.
In the embodiment of the disclosure, the life cycle of the encryption key is delivered to the key management subsystem for management, and the security level of the key management subsystem is far higher than that of the cloud platform, so that the processing advantage is that even if the cloud platform is broken to cause the leakage of the core data ciphertext, the core data plaintext can still be ensured not to be cracked, and the security of the core data of the industrial internet is improved.
The embodiment of the disclosure provides a protection system of industrial internet core data based on a national secret, which is used for realizing the protection method of the industrial internet core data based on the national secret. As shown in fig. 5, the schematic block diagram of the protection system for industrial internet core data based on national password, the protection system 500 includes a certificate authority CA 510, an edge computing gateway 520, a cloud platform 530, a user platform 540, and a key management subsystem 550, the key management subsystem 550 is subordinate to a cryptographic service platform 560; wherein:
the CA 510 is used for issuing a digital certificate USB-KEY and a CA certificate based on the SM2 cryptographic algorithm to the cloud platform and each edge computing gateway;
the edge computing gateway 520 is used for performing bidirectional authentication with the cloud platform, and constructing an SSL data channel with the cloud platform to perform data transmission, so that a user platform can log in the cloud platform;
the user platform 530 is used for logging in the cloud platform and transmitting data cleartext of industrial internet core data to the cloud platform;
the cloud platform 540 is used for performing bidirectional authentication with the edge computing gateway, constructing an SSL data channel with the edge computing gateway for data transmission, receiving a data plaintext sent by the user platform, sending the data plaintext to the key management subsystem, receiving a data ciphertext sent by the key management subsystem, and storing the data ciphertext;
the key management subsystem 550 is configured to receive a data plaintext sent by the cloud platform, encrypt the data plaintext, and send an encrypted data ciphertext to the cloud platform;
and the password service platform 560 is used for distributing the entity password token to the cloud platform, verifying the user identity of the user platform, and sending a verification passing instruction or a verification failing instruction to the cloud platform.
In the embodiment of the disclosure, by completely using the national cryptographic algorithm, a whole set of solution method and system is provided for data security protection from data acquisition in a production field, data transmission from an edge computing gateway to a cloud platform, data encryption and decryption processing and data storage on the cloud platform, to data life cycle processes such as data display and the like in the industrial internet field, so that the security of the core data storage of the industrial internet is improved, and good practice is provided for application and popularization of the national cryptographic algorithm in the industrial internet field.
The embodiment of the disclosure provides a protection device for industrial internet core data based on a state key, which is arranged in a protection system for the industrial internet core data based on the state key, wherein the protection system comprises a Certificate Authority (CA), an edge computing gateway, a cloud platform, a user platform and a password service platform, and the password service platform comprises a secret key management subsystem.
As shown in fig. 6, a schematic block diagram of a protection apparatus for national-secret-based industrial internet core data, the protection apparatus 600 for national-secret-based industrial internet core data includes: the system comprises a construction module 601, a login module 602, a transmission module 603 and an encryption module 604.
The building module 601 is configured to perform bidirectional authentication with each edge computing gateway based on a digital certificate USB-KEY issued by the CA and based on a secret SM2 algorithm and a CA certificate, and build an SSL data channel for data transmission;
a login module 602, configured to log in the cloud platform by the user platform based on a user ID and a national password;
the transmission module 603 is configured to, when the user platform transmits a data plaintext of industrial internet core data to the cloud platform, transmit the data plaintext to the key management subsystem by the cloud platform;
the encryption module 604 is configured to encrypt the data plaintext by the key management subsystem, and transmit the encrypted data ciphertext to the cloud platform for storage, so as to complete storage protection operation of the industrial internet core data.
Optionally, the building module 601 is configured to:
the CA respectively issues a digital certificate USB-KEY and a CA certificate based on a SM2 cryptographic algorithm to the cloud platform and each edge computing gateway;
the cloud platform exchanges a digital certificate USB-KEY with each edge computing gateway to perform bidirectional authentication;
when the bidirectional authentication between the cloud platform and the edge computing gateway is passed, the edge computing gateway establishes connection with the cloud platform, and an SSL data channel is constructed for data transmission.
Optionally, the building module 601 is further configured to:
when the bidirectional authentication of the cloud platform and the edge computing gateways fails, the CA issues a digital certificate USB-KEY and a CA certificate based on a secret SM2 algorithm to the cloud platform and each edge computing gateway again;
and the cloud platform and each edge computing gateway exchange the digital certificate USB-KEY again for bidirectional authentication.
Optionally, the login module 602 is configured to:
when the cloud platform receives a registration request instruction sent by the user platform, the cloud platform applies for an entity password token for the user platform from the password service platform;
when the user platform sends a login request instruction to the cloud platform, the cloud platform receives a user ID and a national password dynamic password sent by the user platform;
the cloud platform verifies the user identity to the password service platform based on the user ID and the national password;
and when the cloud platform receives a verification passing instruction sent by the password service platform, the cloud platform sends a login success instruction to the user platform.
Optionally, the login module 602 is further configured to:
when the cloud platform receives a verification failure instruction sent by the password service platform, the cloud platform sends a login failure instruction to the user platform to prompt the user platform to input the user ID and the national password again.
Optionally, the transmission module 603 is configured to:
after the SSL channel is established between the cloud platform and the secret key management subsystem, the cloud platform sends a secret key application instruction to the secret key management subsystem;
when the secret key management subsystem receives a secret key application instruction, the secret key management subsystem generates a secret key and a secret key identifier and sends the secret key identifier to the cloud platform;
and after receiving the secret key identifier, the cloud platform transmits the data plaintext and the secret key identifier to the secret key management subsystem.
Optionally, the encryption module 604 is configured to:
when the key management subsystem receives the data plaintext and the key identifier, the corresponding key is obtained through the key identifier;
the secret key management subsystem encrypts the data plaintext through the secret key to obtain a data ciphertext corresponding to the data plaintext, and sends the data ciphertext to the cloud platform;
and the cloud platform stores the received data cipher text.
Optionally, the transmission module 603 is further configured to:
when the cloud platform receives a data plaintext acquisition instruction sent by the user platform, the cloud platform transmits a data ciphertext corresponding to the data plaintext acquisition instruction to the key management subsystem;
the secret key management subsystem decrypts the data ciphertext to obtain a data plaintext and a secret key identifier;
the secret key management subsystem sends the data plaintext and the secret key identifier to the cloud platform;
and the cloud platform sends the data plaintext to the user platform.
In the embodiment of the disclosure, by completely using the national cryptographic algorithm, a whole set of solution method and system is provided for data security protection from data acquisition in a production field, data transmission from an edge computing gateway to a cloud platform, data encryption and decryption processing and data storage on the cloud platform, to data life cycle processes such as data display and the like in the industrial internet field, so that the security of the core data storage of the industrial internet is improved, and good practice is provided for application and popularization of the national cryptographic algorithm in the industrial internet field.
An exemplary embodiment of the present disclosure also provides an electronic device including: at least one processor; and a memory communicatively coupled to the at least one processor. The memory stores a computer program executable by the at least one processor, the computer program, when executed by the at least one processor, is for causing the electronic device to perform a method according to an embodiment of the disclosure.
The disclosed exemplary embodiments also provide a non-transitory computer readable storage medium storing a computer program, wherein the computer program, when executed by a processor of a computer, is adapted to cause the computer to perform a method according to an embodiment of the present disclosure.
The exemplary embodiments of the present disclosure also provide a computer program product comprising a computer program, wherein the computer program, when executed by a processor of a computer, is adapted to cause the computer to perform a method according to an embodiment of the present disclosure.
Referring to fig. 7, a block diagram of a structure of an electronic device 700, which may be a server or a client of the present disclosure, which is an example of a hardware device that may be applied to aspects of the present disclosure, will now be described. Electronic device is intended to represent various forms of digital electronic computer devices, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not meant to limit implementations of the disclosure described and/or claimed herein.
As shown in fig. 7, the electronic device 700 includes a computing unit 701, which may perform various appropriate actions and processes according to a computer program stored in a Read Only Memory (ROM)702 or a computer program loaded from a storage unit 708 into a Random Access Memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the device 700 can also be stored. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other by a bus 704. An input/output (I/O) interface 705 is also connected to bus 704.
A number of components in the electronic device 700 are connected to the I/O interface 705, including: an input unit 706, an output unit 707, a storage unit 708, and a communication unit 709. The input unit 706 may be any type of device capable of inputting information to the electronic device 700, and the input unit 706 may receive input numeric or character information and generate key signal inputs related to user settings and/or function controls of the electronic device. Output unit 707 may be any type of device capable of presenting information and may include, but is not limited to, a display, speakers, a video/audio output terminal, a vibrator, and/or a printer. Storage unit 704 may include, but is not limited to, a magnetic disk, an optical disk. The communication unit 709 allows the electronic device 700 to exchange information/data with other devices via a computer network, such as the internet, and/or various telecommunications networks, and may include, but is not limited to, modems, network cards, infrared communication devices, wireless communication transceivers and/or chipsets, such as bluetooth (TM) devices, WiFi devices, WiMax devices, cellular communication devices, and/or the like.
Computing unit 701 may be a variety of general purpose and/or special purpose processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), various specialized Artificial Intelligence (AI) computing chips, various computing units running machine learning model algorithms, a Digital Signal Processor (DSP), and any suitable processor, controller, microcontroller, and so forth. The calculation unit 701 performs the respective methods and processes described above. For example, in some embodiments, the method for protecting industrial internet core data based on a national password may be implemented as a computer software program tangibly embodied on a machine-readable medium, such as the storage unit 708. In some embodiments, part or all of the computer program may be loaded and/or installed onto the electronic device 700 via the ROM 702 and/or the communication unit 709. In some embodiments, the computing unit 701 may be configured by any other suitable means (e.g., by means of firmware) to perform a national-secret-based industrial internet core data protection method.
Program code for implementing the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions/operations specified in the flowchart and/or block diagram to be performed. The program code may execute entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.
In the context of this disclosure, a machine-readable medium may be a tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a Random Access Memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
As used in this disclosure, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and/or device (e.g., magnetic discs, optical disks, memory, Programmable Logic Devices (PLDs)) used to provide machine instructions and/or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal used to provide machine instructions and/or data to a programmable processor.
To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to a user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which a user can provide input to the computer. Other kinds of devices may also be used to provide for interaction with a user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form, including acoustic, speech, or tactile input.
The systems and techniques described here can be implemented in a computing system that includes a back-end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front-end component (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back-end, middleware, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local Area Networks (LANs), Wide Area Networks (WANs), and the Internet.
The computer system may include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other.

Claims (13)

1.一种基于国密的工业互联网核心数据的保护方法,其特征在于,所述基于国密的工业互联网核心数据的保护方法由所述基于国密的工业互联网核心数据的保护系统实现,所述保护系统包括证书授权中心CA、边缘计算网关、云平台、用户平台、密码服务平台,所述密码服务平台包括秘钥管理子系统;1. a protection method based on the national secret industrial internet core data, it is characterized in that, the described protection method based on the national secret industrial internet core data is realized by the described protection system based on the national secret industrial internet core data, so The protection system includes a certificate authority CA, an edge computing gateway, a cloud platform, a user platform, and a cryptographic service platform, and the cryptographic service platform includes a key management subsystem; 所述方法包括:The method includes: 基于所述CA颁发的基于国密SM2算法的数字证书USB-KEY和CA证书,所述云平台与所述每个边缘计算网关进行双向认证,构建SSL数据通道以进行数据传输;Based on the digital certificate USB-KEY and CA certificate based on the national secret SM2 algorithm issued by the CA, the cloud platform performs two-way authentication with each edge computing gateway, and constructs an SSL data channel for data transmission; 所述用户平台基于用户ID和国密动态口令登录所述云平台;The user platform logs into the cloud platform based on the user ID and the national secret dynamic password; 所述用户平台向所述云平台传输工业互联网核心数据的数据明文时,所述云平台将所述数据明文传输至所述秘钥管理子系统;When the user platform transmits the data plaintext of the industrial Internet core data to the cloud platform, the cloud platform transmits the data plaintext to the key management subsystem; 所述秘钥管理子系统对所述数据明文进行加密,将加密后得到的数据密文传输至所述云平台进行存储,以此完成工业互联网核心数据的存储保护操作。The key management subsystem encrypts the data plaintext, and transmits the encrypted data ciphertext to the cloud platform for storage, thereby completing the storage protection operation of the core data of the Industrial Internet. 2.如权利要求1所述的基于国密的工业互联网核心数据的保护方法,其特征在于,所述基于所述CA颁发的基于国密SM2算法的数字证书USB-KEY和CA证书,所述云平台与所述每个边缘计算网关进行双向认证,构建SSL数据通道以进行数据传输,包括:2. the protection method of the industrial Internet core data based on state secret as claimed in claim 1, is characterized in that, described based on the digital certificate USB-KEY and CA certificate based on state secret SM2 algorithm issued by described CA, described The cloud platform performs two-way authentication with each edge computing gateway, and constructs an SSL data channel for data transmission, including: 所述CA分别向所述云平台以及每个边缘计算网关颁发基于国密SM2算法的数字证书USB-KEY和CA证书;The CA respectively issues the digital certificate USB-KEY and CA certificate based on the national secret SM2 algorithm to the cloud platform and each edge computing gateway; 所述云平台与所述每个边缘计算网关交换数字证书USB-KEY,进行双向认证;The cloud platform exchanges a digital certificate USB-KEY with each edge computing gateway for mutual authentication; 当所述云平台与边缘计算网关的双向认证通过时,所述边缘计算网关与所述云平台建立连接,构建SSL数据通道以进行数据传输。When the two-way authentication between the cloud platform and the edge computing gateway is passed, the edge computing gateway establishes a connection with the cloud platform, and constructs an SSL data channel for data transmission. 3.如权利要求1所述的基于国密的工业互联网核心数据的保护方法,其特征在于,所述云平台与所述每个边缘计算网关交换数字证书USB-KEY,进行双向认证之后,还包括:3. The method for protecting industrial Internet core data based on state secrets as claimed in claim 1, wherein the cloud platform exchanges a digital certificate USB-KEY with each edge computing gateway, and after two-way authentication, also include: 当所述云平台与边缘计算网关的双向认证未通过时,所述CA重新向所述云平台以及每个边缘计算网关颁发基于国密SM2算法的数字证书USB-KEY和CA证书;When the two-way authentication between the cloud platform and the edge computing gateway fails, the CA re-issues the digital certificate USB-KEY and CA certificate based on the national secret SM2 algorithm to the cloud platform and each edge computing gateway; 所述云平台与所述每个边缘计算网关重新交换数字证书USB-KEY,进行双向认证。The cloud platform and each edge computing gateway re-exchange the digital certificate USB-KEY to perform two-way authentication. 4.如权利要求1所述的基于国密的工业互联网核心数据的保护方法,其特征在于,所述用户平台基于用户ID和国密动态口令登录所述云平台,包括:4. the protection method of the industrial Internet core data based on state secret as claimed in claim 1, is characterized in that, described user platform logs on described cloud platform based on user ID and state secret dynamic password, comprising: 当所述云平台接收到所述用户平台发送的请求注册指令时,所述云平台向所述密码服务平台为所述用户平台申请实体口令令牌;When the cloud platform receives the registration request instruction sent by the user platform, the cloud platform applies to the password service platform for an entity password token for the user platform; 当所述用户平台向所述云平台发送请求登录指令时,所述云平台接收所述用户平台发送的用户ID和国密动态口令;When the user platform sends a login request instruction to the cloud platform, the cloud platform receives the user ID and the national secret dynamic password sent by the user platform; 所述云平台基于所述用户ID和国密动态口令,向所述密码服务平台验证用户身份;The cloud platform verifies the user identity to the password service platform based on the user ID and the national secret dynamic password; 当所述云平台接收到所述密码服务平台发送的验证通过指令时,所述云平台向所述用户平台发送登录成功指令。When the cloud platform receives the verification pass instruction sent by the password service platform, the cloud platform sends a login success instruction to the user platform. 5.如权利要求4所述的基于国密的工业互联网核心数据的保护方法,其特征在于,所述云平台基于所述用户ID和国密动态口令,向所述密码服务平台验证用户身份之后,还包括:5. the protection method of the industrial Internet core data based on national secret as claimed in claim 4 is characterized in that, described cloud platform is based on described user ID and national secret dynamic password, after verifying user identity to described password service platform ,Also includes: 当所述云平台接收到所述密码服务平台发送的验证未通过指令时,所述云平台向所述用户平台发送登录失败指令,提示所述用户平台再次输入用户ID以及国密动态口令。When the cloud platform receives the verification failure instruction sent by the password service platform, the cloud platform sends a login failure instruction to the user platform, prompting the user platform to input the user ID and the national secret dynamic password again. 6.如权利要求1所述的基于国密的工业互联网核心数据的保护方法,其特征在于,所述云平台将所述数据明文传输至所述秘钥管理子系统,包括:6. The method for protecting industrial Internet core data based on state secrets according to claim 1, wherein the cloud platform transmits the data plaintext to the key management subsystem, comprising: 当所述云平台与所述秘钥管理子系统建立SSL通道后,所述云平台向所述秘钥管理子系统发送秘钥申请指令;After the cloud platform and the key management subsystem establish an SSL channel, the cloud platform sends a key application instruction to the key management subsystem; 当所述秘钥管理子系统接收到秘钥申请指令时,所述秘钥管理子系统产生秘钥和秘钥标识,并将所述秘钥标识发送至所述云平台;When the secret key management subsystem receives the secret key application instruction, the secret key management subsystem generates a secret key and a secret key identifier, and sends the secret key identifier to the cloud platform; 所述云平台接收到秘钥标识后,将所述数据明文以及秘钥标识传输至所述秘钥管理子系统。After receiving the key identifier, the cloud platform transmits the data plaintext and the key identifier to the key management subsystem. 7.如权利要求6所述的基于国密的工业互联网核心数据的保护方法,其特征在于,所述秘钥管理子系统对所述数据明文进行加密,将加密后得到的数据密文传输至所述云平台进行存储,包括:7. The method for protecting industrial Internet core data based on state secrets as claimed in claim 6, wherein the key management subsystem encrypts the data plaintext, and transmits the encrypted data ciphertext to The cloud platform performs storage, including: 所述秘钥管理子系统接收到所述数据明文以及秘钥标识时,通过所述秘钥标识取得对应的秘钥;When the secret key management subsystem receives the data plaintext and the secret key identifier, it obtains the corresponding secret key through the secret key identifier; 所述秘钥管理子系统通过所述秘钥对所述数据明文进行加密,得到所述数据明文对应的数据密文,并将所述数据密文发送至所述云平台;The secret key management subsystem encrypts the data plaintext by using the secret key, obtains a data ciphertext corresponding to the data plaintext, and sends the data ciphertext to the cloud platform; 所述云平台对接收到的数据密文进行存储。The cloud platform stores the received data ciphertext. 8.如权利要求1所述的基于国密的工业互联网核心数据的保护方法,其特征在于,所述方法还包括:8. The method for protecting industrial Internet core data based on state secrets as claimed in claim 1, wherein the method further comprises: 当所述云平台接收到所述用户平台发送的数据明文获取指令时,所述云平台将数据明文获取指令对应的数据密文传输至所述秘钥管理子系统;When the cloud platform receives the data plaintext acquisition instruction sent by the user platform, the cloud platform transmits the data ciphertext corresponding to the data plaintext acquisition instruction to the secret key management subsystem; 所述秘钥管理子系统对所述数据密文进行解密,得到数据明文以及秘钥标识;The key management subsystem decrypts the data ciphertext to obtain the data plaintext and the key identifier; 所述秘钥管理子系统将所述数据明文以及秘钥标识发送至所述云平台;The key management subsystem sends the data plaintext and the key identifier to the cloud platform; 所述云平台将所述数据明文发送至所述用户平台。The cloud platform sends the data in plaintext to the user platform. 9.一种基于国密的工业互联网核心数据的保护系统,其特征在于,所述保护系统包括证书授权中心CA、边缘计算网关、云平台、用户平台、秘钥管理子系统;其中:9. A protection system for industrial Internet core data based on state secrets, wherein the protection system comprises a certificate authority CA, an edge computing gateway, a cloud platform, a user platform, and a key management subsystem; wherein: 所述CA,用于向所述云平台以及每个边缘计算网关颁发基于国密SM2算法的数字证书USB-KEY和CA证书;The CA is used to issue the digital certificate USB-KEY and CA certificate based on the national secret SM2 algorithm to the cloud platform and each edge computing gateway; 所述边缘计算网关,用于与所述云平台进行双向认证,与所述云平台构建SSL数据通道以进行数据传输,供所述用户平台登录所述云平台;The edge computing gateway is used to perform two-way authentication with the cloud platform, and build an SSL data channel with the cloud platform for data transmission, so that the user platform can log in to the cloud platform; 所述用户平台,用于登录所述云平台,向所述云平台传输工业互联网核心数据的数据明文;The user platform is used to log in to the cloud platform and transmit the data plaintext of the core data of the Industrial Internet to the cloud platform; 所述云平台,用于与所述边缘计算网关进行双向认证,与所述边缘计算网关构建SSL数据通道以进行数据传输,接收用户平台发送的数据明文,向所述秘钥管理子系统发送数据明文,接收所述秘钥管理子系统发送的数据密文,存储数据密文;The cloud platform is used to perform two-way authentication with the edge computing gateway, build an SSL data channel with the edge computing gateway for data transmission, receive data plaintext sent by the user platform, and send data to the key management subsystem plaintext, receive the data ciphertext sent by the key management subsystem, and store the data ciphertext; 所述秘钥管理子系统,用于接收所述云平台发送的数据明文,对数据明文进行加密,将加密后的数据密文发送至所述云平台。The key management subsystem is configured to receive the data plaintext sent by the cloud platform, encrypt the data plaintext, and send the encrypted data ciphertext to the cloud platform. 10.如权利要求9所述的基于国密的工业互联网核心数据的保护系统,其特征在于,所述秘钥管理子系统从属于密码服务平台;10. The national secret-based industrial Internet core data protection system according to claim 9, wherein the secret key management subsystem is subordinate to a cryptographic service platform; 所述密码服务平台,用于向所述云平台分发实体口令令牌,验证用户平台的用户身份,向云平台发送验证通过指令或验证未通过指令。The cryptographic service platform is used for distributing entity password tokens to the cloud platform, verifying the user identity of the user platform, and sending a verification pass instruction or a verification fail instruction to the cloud platform. 11.一种基于国密的工业互联网核心数据的保护装置,其特征在于,所述基于国密的工业互联网核心数据的保护装置设置于所述基于国密的工业互联网核心数据的保护系统,所述保护系统包括证书授权中心CA、边缘计算网关、云平台、用户平台、密码服务平台,所述密码服务平台包括秘钥管理子系统;11. A protection device for industrial Internet core data based on state secrets, characterized in that the protection device for industrial Internet core data based on state secrets is set in the protection system for industrial Internet core data based on state secrets, so The protection system includes a certificate authority CA, an edge computing gateway, a cloud platform, a user platform, and a cryptographic service platform, and the cryptographic service platform includes a key management subsystem; 所述装置包括:The device includes: 构建模块,用于基于所述CA颁发的基于国密SM2算法的数字证书USB-KEY和CA证书,所述云平台与所述每个边缘计算网关进行双向认证,构建SSL数据通道以进行数据传输;The building module is used to perform two-way authentication between the cloud platform and each edge computing gateway based on the digital certificate USB-KEY and CA certificate issued by the CA and based on the national secret SM2 algorithm, and construct an SSL data channel for data transmission ; 登录模块,用于所述用户平台基于用户ID和国密动态口令、通过所述边缘计算网关登录所述云平台;a login module, used for the user platform to log in to the cloud platform through the edge computing gateway based on the user ID and the national secret dynamic password; 传输模块,用于所述用户平台向所述云平台传输工业互联网核心数据的数据明文时,所述云平台将所述数据明文传输至所述秘钥管理子系统;a transmission module, used for the cloud platform to transmit the data plaintext to the key management subsystem when the user platform transmits the data plaintext of the industrial Internet core data to the cloud platform; 加密模块,用于所述秘钥管理子系统对所述数据明文进行加密,将加密后得到的数据密文传输至所述云平台进行存储,以此完成工业互联网核心数据的存储保护操作。The encryption module is used for the key management subsystem to encrypt the data plaintext, and transmit the encrypted data ciphertext to the cloud platform for storage, so as to complete the storage protection operation of the core data of the industrial Internet. 12.一种电子设备,包括:12. An electronic device comprising: 处理器;以及processor; and 存储程序的存储器,memory for storing programs, 其中,所述程序包括指令,所述指令在由所述处理器执行时使所述处理器执行根据权利要求1-8中任一项所述的方法。wherein the program comprises instructions which, when executed by the processor, cause the processor to perform the method of any of claims 1-8. 13.一种存储有计算机指令的非瞬时计算机可读存储介质,其中,所述计算机指令用于使计算机执行根据权利要求1-8中任一项所述的方法。13. A non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the method of any of claims 1-8.
CN202111342209.2A 2021-11-12 2021-11-12 Industrial Internet core data protection method and system based on national security Active CN114139176B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202111342209.2A CN114139176B (en) 2021-11-12 2021-11-12 Industrial Internet core data protection method and system based on national security

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202111342209.2A CN114139176B (en) 2021-11-12 2021-11-12 Industrial Internet core data protection method and system based on national security

Publications (2)

Publication Number Publication Date
CN114139176A true CN114139176A (en) 2022-03-04
CN114139176B CN114139176B (en) 2025-07-29

Family

ID=80393113

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202111342209.2A Active CN114139176B (en) 2021-11-12 2021-11-12 Industrial Internet core data protection method and system based on national security

Country Status (1)

Country Link
CN (1) CN114139176B (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114915443A (en) * 2022-03-09 2022-08-16 深圳市明泰智能技术有限公司 Industrial edge operating system supporting national encryption algorithm
CN115102987A (en) * 2022-06-16 2022-09-23 平安银行股份有限公司 Bank outlet's marginal equipment management system
CN116545671A (en) * 2023-04-23 2023-08-04 中国银行股份有限公司 Secure communication system and method
CN121098640A (en) * 2025-11-11 2025-12-09 江苏省数据集团数字科技有限公司 AI model safety protection system and method based on domestic cryptographic algorithm and digital certificate

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101674304A (en) * 2009-10-15 2010-03-17 浙江师范大学 System and method for network identity authentication
CN109672521A (en) * 2018-12-26 2019-04-23 贵州华芯通半导体技术有限公司 Safe storage system and method based on encription algorithms approved by the State Password Administration Committee Office engine implementation
CN109714307A (en) * 2018-06-12 2019-05-03 广东工业大学 A kind of cloud platform client data encrypting and deciphering system and method based on national secret algorithm
US20200313869A1 (en) * 2019-03-26 2020-10-01 International Business Machines Corporation Generating a protected key for selective use
CN111865609A (en) * 2020-07-03 2020-10-30 上海缔安科技股份有限公司 Private cloud platform data encryption and decryption system based on state cryptographic algorithm

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101674304A (en) * 2009-10-15 2010-03-17 浙江师范大学 System and method for network identity authentication
CN109714307A (en) * 2018-06-12 2019-05-03 广东工业大学 A kind of cloud platform client data encrypting and deciphering system and method based on national secret algorithm
CN109672521A (en) * 2018-12-26 2019-04-23 贵州华芯通半导体技术有限公司 Safe storage system and method based on encription algorithms approved by the State Password Administration Committee Office engine implementation
US20200313869A1 (en) * 2019-03-26 2020-10-01 International Business Machines Corporation Generating a protected key for selective use
CN111865609A (en) * 2020-07-03 2020-10-30 上海缔安科技股份有限公司 Private cloud platform data encryption and decryption system based on state cryptographic algorithm

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
焦少波 等: "政务云平台国密应用技术研究", 网络安全技术与应用, no. 10, 15 October 2020 (2020-10-15), pages 57 - 60 *

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114915443A (en) * 2022-03-09 2022-08-16 深圳市明泰智能技术有限公司 Industrial edge operating system supporting national encryption algorithm
CN115102987A (en) * 2022-06-16 2022-09-23 平安银行股份有限公司 Bank outlet's marginal equipment management system
CN115102987B (en) * 2022-06-16 2023-10-13 平安银行股份有限公司 Edge equipment management system for banking outlets
CN116545671A (en) * 2023-04-23 2023-08-04 中国银行股份有限公司 Secure communication system and method
CN121098640A (en) * 2025-11-11 2025-12-09 江苏省数据集团数字科技有限公司 AI model safety protection system and method based on domestic cryptographic algorithm and digital certificate
CN121098640B (en) * 2025-11-11 2026-01-30 江苏省数据集团数字科技有限公司 AI Model Security Protection System and Method Based on Domestic Cryptographic Algorithms and Digital Certificates

Also Published As

Publication number Publication date
CN114139176B (en) 2025-07-29

Similar Documents

Publication Publication Date Title
WO2022206349A1 (en) Information verification method, related apparatus, device, and storage medium
CN105790938B (en) Secure unit key generation system and method based on trusted execution environment
US9838205B2 (en) Network authentication method for secure electronic transactions
US9231925B1 (en) Network authentication method for secure electronic transactions
CN114139176B (en) Industrial Internet core data protection method and system based on national security
CN111435913B (en) Identity authentication method and device for terminal of Internet of things and storage medium
CN108512846A (en) Mutual authentication method and device between a kind of terminal and server
CN103916363B (en) The communication security management method and system of encryption equipment
WO2025236608A1 (en) Information verification method and related device
CN113411187A (en) Identity authentication method and system, storage medium and processor
WO2023174038A1 (en) Data transmission method and related device
WO2018120938A1 (en) Offline key transmission method, terminal and storage medium
CN119808042B (en) Container access control method, device, equipment and storage medium
CN115801252A (en) Safe cloud desktop system combined with quantum encryption technology
CN114389860B (en) Voice communication method, client, server, electronic device and storage medium
CN111654503A (en) Remote control method, device, equipment and storage medium
JP2016536678A (en) Network management security authentication method, apparatus, system, and computer storage medium
CN111064577A (en) A security authentication method, device and electronic device
CN112235276B (en) Master-slave equipment interaction method, device, system, electronic equipment and computer medium
CN114070568A (en) Data processing method and device, electronic equipment and storage medium
CN118300905B (en) Ciphertext transmission method, device, equipment and medium based on secret authentication mode
CN117336092A (en) Client login method and device, electronic equipment and storage medium
CN114239014B (en) File processing methods, apparatuses, and electronic devices based on offline devices
CN112615840B (en) Method and system for authenticating admission of embedded equipment
CN112788061B (en) Authentication method, authentication device, authentication apparatus, authentication storage medium, and authentication program product

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant