API key protection method and system based on SGX software extension instruction

The invention discloses an API key protection method based on an SGX software extension instruction. The API key protection method comprises the following steps: (1) API key protection system initialization; (2) remote authentication and API key import; (3) API request signature and signature inform...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: JI SHOULING, SHEN RUI, LIU DINGHAO, HE QINMING, CHEN JIANHAI, HUANG BUTIAN
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:The invention discloses an API key protection method based on an SGX software extension instruction. The API key protection method comprises the following steps: (1) API key protection system initialization; (2) remote authentication and API key import; (3) API request signature and signature information export. According to the method, a secure API key storage and use environment is constructed by introducing Intel SGX hardware and a trusted space mechanism of the SGX, and protection is provided for a user API key; the invention further discloses an API secret key protection system based on the SGX software extension instruction. The API secret key protection system comprises a remote authentication module used for cooperating with user trusted equipment to complete SGX remote authentication. The key management module is used for storing and managing the acquired API key in the SGX security area; the trusted time module is used for providing a trusted timestamp for a user program; andthe signature module is