Multi-certificate issuing and verifying method based on intelligent security chip

A security chip and certificate issuance technology, applied in the field of computer and information security, can solve the problems of time-consuming, laborious, heavy burden, and inability to effectively verify the authenticity of identity

Active Publication Date: 2018-11-27
THE THIRD RES INST OF MIN OF PUBLIC SECURITY
View PDF7 Cites 10 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

The offline method requires the user to be present in person, which is time-consuming and laborious, while the online method requires the user to transmit their private information, which has the risk of leakage, and the CA cannot effectively verify the authenticity of the identity
Moreover, in the past, CAs needed to provide users with an independent certificate carrier to store the certificates they issued, and set up independent PIN codes for management, which added a lot of burden to users to use these certificates.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Multi-certificate issuing and verifying method based on intelligent security chip
  • Multi-certificate issuing and verifying method based on intelligent security chip

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0031] In order to describe the technical content of the present invention more clearly, further description will be given below in conjunction with specific embodiments.

[0032] The multi-certificate issuing method based on the intelligent security chip includes:

[0033] (1) generating a first public key and a first private key inside the carrier storing the smart security chip;

[0034] (2) Sign the first public key with the preset private key inside the carrier to generate the first certificate request data, and send the first certificate request data to the first authority, and pass The first certificate is issued after the verification of the preset public key inside the carrier;

[0035] (3) writing the first certificate into the smart security chip;

[0036] (4) generating the i-th public key and the i-th private key inside the carrier;

[0037] (5) Sign the i-th public key with the first private key to generate the i-th certificate request data, and send the i-th ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention relates to a multi-certificate issuing and verifying method based on an intelligent security chip, can use a single smart security chip carrier to apply to multiple CAs for certificatesand store the certificates, wherein only one CA (hereinafter referred to as the first CA) needs to perform strict identity checking for certificate issuing and a unique signature PIN code is set, andwhen applying to other CAs for certificates, an applicant only needs to use the certificate issued by the first CA to prove user identity to complete online certificate application. By adoption of themulti-certificate issuing and verifying method based on an intelligent security chip, the problem of previous inconvenience of applying to multiple CAs for certificates and electronic signatures by auser is solved, strict identity checking needs to be performed only once, then the user can apply to multiple CAs for digital certificates, the certificate applied through strict identity checking isused for identity authentication, other certificates can be used for electronic signatures of business systems, and during signature verification, the first certificate is utilized to complete identity authentication first and then a designated certificate is utilized to perform electronic signature verification of business data.

Description

technical field [0001] The invention relates to the field of computer technology, in particular to the field of information security technology, and specifically refers to a method for issuing and verifying multiple certificates based on an intelligent security chip. Background technique [0002] With the development of e-government and e-commerce business on the Internet and the promulgation of the "Electronic Signature Law", electronic signatures using PKI (Public Key Infrastructure) technology are more and more widely used, so users may need to use their own signatures in different application scenarios. private key for electronic signature. Since the trust domains to which the applications belong are different, the user needs to apply for a digital certificate for verifying the electronic signature from a digital certificate issuing authority (hereinafter referred to as CA (Certificate Authority)) in different trust domains. When CA issues a digital certificate to a use...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L9/32
CPCH04L9/3247H04L9/3268
Inventor 胡永涛胥怡心
Owner THE THIRD RES INST OF MIN OF PUBLIC SECURITY
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products