Unlock instant, AI-driven research and patent intelligence for your innovation.

Method and system for checking revocation status of digital certificate in virtual environment

By introducing the certificate revocation list manager in the virtualized environment, the certificate revocation status check is managed uniformly, which solves the problem of complexity and delay of certificate revocation status check, realizes efficient certificate revocation status query and CRL management, and is suitable for enterprise-level virtual desktop systems. .

Inactive Publication Date: 2015-10-14
INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES +1
View PDF4 Cites 19 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, sometimes, the download method of CRL is not written in the certificate, and the certificate relying party needs to manually configure each machine one by one, which is troublesome.
Moreover, sometimes, although the download method of CRL has been written in the certificate, this method is not supported by the computer system of some certificate relying parties. For example, the LDAP protocol may not be supported by all certificate relying parties.
As mentioned above, these will bring complexity to the design and implementation of the PKI client, and will also bring confusion to the application system and users
In addition, the certificate relying party starts to download the CRL after receiving the certificate. Considering that the CRL file may be relatively large (sometimes, exceeding 1M bytes), it will cause delays (because the follow-up can only be performed after the CRL is downloaded. step work)

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0044] In order to make the above objects, features and advantages of the present invention more obvious and understandable, the present invention will be further described below through specific embodiments and accompanying drawings.

[0045] The certificate revocation list manager used in this embodiment is implemented in the KVM-QEMU virtualization platform, its configuration interface is integrated in the QEMU console, and an operation interface is provided to the certificate revocation list manager administrator, so that the administrator can The certificate revocation list manager is configured directly in the host. KVM is a module of the Linux kernel. It is the core of the entire KVM-QEMU virtualization platform. It is responsible for initializing the processor and providing a series of VMM management interfaces through the ioctl system call, such as creating a VM, mapping the physical address of the VM, and giving The VM allocates virtual CPUs (vCPUs) and so on. The w...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a method and a system for checking the revocation status of a digital certificate in a virtual environment. The method comprises the following steps: (1) multiple client virtual machines are created on a host machine, and a certificate revocation list manager is arranged in a virtual machine monitor of the host machine; (2) a certificate relying party in each client virtual machine issues a certificate revocation status check service request to the certificate revocation list manager; and (3) the certificate revocation list manager locally queries whether there is a corresponding CRL file according to the certificate revocation status check service request: (a) if there is a corresponding CRL file, the certificate revocation list manager returns the CRL file to the certificate relying parties in the client virtual machines, or the certificate revocation list manager queries whether there is a corresponding certificate serial number in the CRL file and then returns a query result; and (b) if there is no corresponding CRL file, the certificate revocation list manager downloads and verifies a corresponding CRL file and returns the CRL file, or the certificate revocation list manager queries whether there is a corresponding certificate serial number in the CRL file and then returns a query result. By adopting the method and the system, the query efficiency is greatly improved.

Description

technical field [0001] The invention relates to the field of computer security, in particular to a method and a system for checking the revocation state of a digital certificate in a virtualized environment. Background technique [0002] On the basis of public key cryptography, PKI (Public Key Infrastructure) mainly solves the problem of who the key belongs to, that is, key authentication. PKI implements key authentication services by issuing digital certificates from a digital certificate certification authority (CA: Certification Authority), that is, publishing information about who the public key belongs to, so that various security services such as digital signatures on the network have basic security Assure. [0003] As a third-party digital certificate certification center, CA is an entity trusted by both communication parties in the PKI system, and it is responsible for issuing digital certificates. A digital certificate (referred to as a certificate) binds the publ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L9/32
CPCH04L9/3268H04L63/0823G06F9/45558G06F21/33G06F21/53G06F2009/45587H04L9/006G06F9/45545G06F2009/45583H04L9/0891H04L9/30
Owner INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
Features
  • R&D
  • Intellectual Property
  • Life Sciences
  • Materials
  • Tech Scout
Why Patsnap Eureka
  • Unparalleled Data Quality
  • Higher Quality Content
  • 60% Fewer Hallucinations
Social media
Patsnap Eureka Blog
Learn More