A digital signature certificate detection method and device

By maintaining a digital signature certificate library on the server side and searching and updating reputation scores, the problem of the inability to effectively detect stolen or purchased digital signature certificates in existing technologies is solved, the security of terminal devices is improved and resource consumption is reduced.

CN116010927BActive Publication Date: 2025-09-05BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211698006.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-28
Publication Date
2025-09-05
Estimated Expiration
2042-12-28

AI Technical Summary

Technical Problem

Existing antivirus software cannot effectively detect stolen or purchased digital signature certificates, resulting in insufficient terminal device security and high resource consumption.

Method used

By maintaining a digital signature certificate library on the server side, including a trusted digital signature certificate library and a reputation evaluation digital signature certificate library, the reputation score is searched and updated, and the reputation score is sent to the client to decide whether to perform virus detection and removal.

Benefits of technology

It improves the security of terminal devices, reduces resource consumption, and realizes effective detection and management of digital signature certificates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116010927B_ABST
    Figure CN116010927B_ABST
Patent Text Reader

Abstract

Embodiments of the present invention disclose a method and apparatus for detecting digital signature certificates. The method comprises: receiving a digital signature certificate sent by a client for loading a target file; searching a preset digital signature certificate library for a reputation score corresponding to the digital signature certificate; and sending the reputation score to the client, so that the client determines whether to perform virus detection on the target file based on the reputation score.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a method and device for detecting a digital signature certificate. Background Art

[0002] A digital signature certificate is a document that verifies the legitimacy of code, software, applications, and executable files. This public key infrastructure-based digital signature signs the code and guarantees that it has not been altered or corrupted during its journey from the developer's system to the end user's system. Therefore, due to the security of digital signature certificates, operating systems and antivirus software typically assume that files with digital signature certificates are safe. Antivirus software will not detect or issue warnings for files with digital signature certificates during virus detection, thereby reducing resource consumption and the possibility of false positives.

[0003] However, some criminals steal or purchase digital signature certificates from manufacturers and exploit the fact that antivirus software does not detect digital signature certificates to attack terminal devices. Therefore, a method for detecting digital signature certificates is urgently needed to address the shortcomings of current antivirus software. Summary of the Invention

[0004] In view of this, an embodiment of the present invention provides a digital signature certificate detection method and apparatus, which can detect digital signature certificates, thereby improving the security of terminal devices while reducing resource consumption as much as possible.

[0005] In a first aspect, an embodiment of the present invention provides a digital signature certificate detection method, which is applied to a server and includes:

[0006] Receive the digital signature certificate of the target file sent by the client;

[0007] Searching for a reputation score corresponding to the digital signature certificate in a preset digital signature certificate library;

[0008] The reputation score is sent to the client, so that the client determines whether to perform virus detection on the target file according to the reputation score.

[0009] Preferably, the digital signature certificate library includes: a trusted digital signature certificate library and a reputation evaluation digital signature certificate library; searching for the reputation score corresponding to the digital signature certificate in the preset digital signature certificate library specifically includes: searching for the reputation score corresponding to the digital signature certificate in the trusted digital signature certificate library; if the reputation score corresponding to the digital signature certificate is not found in the trusted digital signature certificate library, searching for the digital signature certificate in the reputation evaluation digital signature certificate library;

[0010] If the digital signature certificate is found in the reputation evaluation digital signature certificate library, it is detected whether the number of files loaded with the digital signature certificate in the public network is greater than a preset first threshold, and the number of files loaded with the digital signature certificate is greater than a preset first threshold according to the detection.

[0011] The reputation score corresponding to the digital signature certificate 0 in the reputation evaluation digital signature certificate library is updated based on the result and the preset first reputation scoring rule; and the updated reputation score is determined as the reputation score corresponding to the digital signature certificate.

[0012] Preferably, the method further includes: if the number of files loaded with the digital signature certificate in the public network is greater than the first threshold and the updated reputation score is greater than a preset second threshold, adding the digital signature certificate and the corresponding reputation score to the trusted digital signature certificate library.

[0013] Preferably, the method further comprises: in response to an execution action triggered on the client by the target file received from the client; updating the reputation score corresponding to the digital signature certificate in the trusted digital signature certificate library according to the execution action and a preset second reputation score rule.

[0014] Preferably, the method further includes: if the digital signature certificate is not found in the digital signature certificate library, sending an alarm message to the client, so that the client performs a virus check on the target file or outputs an option for the user to choose whether to perform a virus check on the target file.

[0015] Preferably, the method further includes: if the digital signature certificate is not found in the trusted digital signature certificate library and the reputation evaluation digital signature certificate library, determining the reputation score corresponding to the digital signature certificate according to a preset third reputation evaluation rule; adding the digital signature certificate and the corresponding reputation score to the reputation evaluation digital signature certificate library; wherein the third reputation evaluation rule includes: determining the reputation score corresponding to the digital signature certificate based on the number of files loaded with the digital signature certificate in the public network, and / or the compiler information of the target file, and / or the shell information of the digital signature certificate.

[0016] In a first aspect, an embodiment of the present invention provides a digital signature certificate detection device, which is applied to a server and includes:

[0017] A receiving unit, configured to receive a digital signature certificate sent by a client for loading a target file;

[0018] A search unit, configured to search a preset digital signature certificate library for a reputation score corresponding to the digital signature certificate;

[0019] The sending unit is configured to send the reputation score to the client, so that the client determines whether to perform virus detection on the target file according to the reputation score.

[0020] Preferably, the digital signature certificate library includes: a trusted digital signature certificate library and a reputation evaluation digital signature certificate library; the search unit is specifically used to: search for the reputation score corresponding to the digital signature certificate in the trusted digital signature certificate library; if the reputation score corresponding to the digital signature certificate is not found in the trusted digital signature certificate library, search for the digital signature certificate in the reputation evaluation digital signature certificate library; if the digital signature certificate is found in the reputation evaluation digital signature certificate library, detect whether the number of files loaded with the digital signature certificate in the public network is greater than a preset first threshold, and update the reputation score corresponding to the digital signature certificate in the reputation evaluation digital signature certificate library according to the detection result and the preset first reputation score rule; and determine the updated reputation score as the reputation score corresponding to the digital signature certificate.

[0021] Preferably, the search unit is further used to: if the number of files loaded with the digital signature certificate in the public network is greater than the first threshold and the updated reputation score is greater than a preset second threshold, then add the digital signature certificate and the corresponding reputation score to the trusted digital signature certificate library.

[0022] Preferably, the device also includes: an adding unit for: if the digital signature certificate is not found in the trusted digital signature certificate library and the reputation evaluation digital signature certificate library, determining the reputation score corresponding to the digital signature certificate according to a preset third reputation evaluation rule; adding the digital signature certificate and the corresponding reputation score to the reputation evaluation digital signature certificate library; wherein the third reputation evaluation rule includes: determining the reputation score corresponding to the digital signature certificate based on the number of files loaded with the digital signature certificate in the public network, and / or the compiler information of the target file, and / or the shell information of the digital signature certificate.

[0023] Embodiments of the present invention provide a digital signature certificate detection method and device. This method receives a digital signature certificate from a client for loading a target file, searches a preset digital signature certificate library for the corresponding reputation score, and sends the reputation score to the client. The client then determines whether to perform virus detection on the target file based on the reputation score. This method enables digital signature certificate detection, improves terminal device security, and minimizes resource consumption. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0025] Figure 1 A flowchart of a digital signature certificate detection method provided by an embodiment of the present invention;

[0026] Figure 2 A schematic diagram of a flow chart of another digital signature certificate detection method provided by an embodiment of the present invention;

[0027] Figure 3 A flowchart of another digital signature certificate detection method provided by an embodiment of the present invention;

[0028] Figure 4 A schematic structural diagram of a digital signature certificate detection device provided by an embodiment of the present invention;

[0029] Figure 5 A schematic structural diagram of another digital signature certificate detection device provided by an embodiment of the present invention;

[0030] Figure 6 The figure is a schematic structural diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0031] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0032] It should be understood that the embodiments described are only a portion of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without creative work are within the scope of protection of the present invention.

[0033] Figure 1 A flowchart of a digital signature certificate detection method provided by an embodiment of the present invention is provided. The digital signature certificate detection method can be applied to a server.

[0034] like Figure 1 As shown, the digital signature certificate detection method of this embodiment may include:

[0035] Step 101: Receive a digital signature certificate for loading a target file sent by a client.

[0036] Specifically, the client can be antivirus software running on the terminal device. The client monitors in real time whether new files on the terminal device have been loaded with digital signature certificates. When a new file with a digital signature certificate is detected, the client collects the digital signature certificate of the file and uploads it to the server.

[0037] Step 102: Search the preset digital signature certificate library for the reputation score corresponding to the digital signature certificate.

[0038] Preferably, the digital signature certificate library may include: a trust digital signature certificate library and a reputation evaluation digital signature certificate library.

[0039] Correspondingly, such as Figure 2 As shown, step 102 may specifically include:

[0040] Step 1021: Search the trusted digital signature certificate library for the reputation score corresponding to the digital signature certificate.

[0041] Specifically, all digital signature certificates in the trusted digital signature certificate library are credible digital signature certificates. Therefore, if the reputation score corresponding to the digital signature certificate is found in the trusted digital signature, step 103 can be executed.

[0042] Step 1022: If the reputation score corresponding to the digital signature certificate is not found in the trusted digital signature certificate library, the digital signature certificate is searched in the reputation evaluation digital signature certificate library.

[0043] Specifically, the digital signature certificate in the reputation evaluation digital signature certificate library is the digital signature certificate under evaluation. Therefore, if the digital certificate is found in the reputation evaluation digital signature certificate library, the reputation score corresponding to the digital signature certificate needs to be updated before feedback is given to the client, that is, step 1023 is executed.

[0044] In step 1023, if the digital signature certificate is found in the reputation evaluation digital signature certificate library, a check is performed to determine whether the number of files loaded with the digital signature certificate in the public network is greater than a preset first threshold. Based on the detection result and a preset first reputation scoring rule, the reputation score corresponding to the digital signature certificate in the reputation evaluation digital signature certificate library is updated.

[0045] Specifically, the first reputation scoring rule includes, but is not limited to: if the number of files on the public network that have a digital signature certificate loaded therein exceeds a first threshold, then the reputation score corresponding to the digital signature certificate is increased, for example, by 20 points. If the number of files on the public network that have a digital signature certificate loaded therein does not exceed the first threshold, then the reputation score corresponding to the digital signature certificate is deducted, for example, by 20 points.

[0046] Step 1024 : Determine the updated reputation score as the reputation score corresponding to the digital signature certificate, and then execute step 103 .

[0047] Preferably, the digital signature certificate detection method provided in this embodiment may further include:

[0048] If the number of files loaded with digital signature certificates on the public network exceeds a first threshold and the updated reputation score exceeds a preset second threshold, the digital signature certificate and the corresponding reputation score are added to the trusted digital signature certificate library. In one example, the second threshold can be 100 points.

[0049] Step 103: Send the reputation score to the client, so that the client determines whether to perform virus detection on the target file based on the reputation score.

[0050] Specifically, after receiving the reputation score corresponding to the digital signature certificate, the client determines whether to perform virus detection on the target file based on preset rules. For example, the maximum score for the reputation score can be 100, and the preset rules can be: if the reputation score is greater than 70 points, the digital signature certificate is considered trustworthy, and the target file is not checked for viruses. If the reputation score is less than 70 points, the digital signature certificate is considered untrustworthy, and the target file is checked for viruses.

[0051] Preferably, Figure 3 As shown, to ensure the accuracy of the reputation score of the digital signature certificate, the digital signature certificate detection method provided by the embodiment of the present invention may further include:

[0052] Step 301 : triggering an execution action on the client in response to receiving a target file sent by the client.

[0053] Specifically, the execution action is a dangerous action, including but not limited to: registry operations, startup behavior, startup parameters, program startup relationship chain, system file calls, network access, and permission changes. When the client detects that the target file has triggered these dangerous actions, it reports them to the server.

[0054] Step 302: Update the reputation score corresponding to the digital signature certificate in the trusted digital signature certificate library according to the execution action and the preset second reputation score rule.

[0055] Specifically, the second reputation scoring rule includes, but is not limited to, deducting the reputation score corresponding to the digital signature certificate based on the weights of different execution action pairs. For example, a weight of 1 corresponds to a reputation score of 5 points, and the weights of registry operations and startup behaviors are 5, the weights of startup parameters and program startup relationship chains are 8, and the weights of system file calls, network access, and permission changes are 10. Then, when the server receives the target file sent by the client and the execution action triggered is a registry operation and permission change, since the weight of the registry operation is 5 and the weight of the permission change is 10, the reputation score corresponding to the digital signature certificate needs to be deducted by 75 points.

[0056] Preferably, the digital signature certificate detection method provided in the embodiment of the present invention may further include:

[0057] If the digital signature certificate is not found in the digital signature certificate library, an alarm message is sent to the client, so that the client can perform virus detection on the target file or output an option for the user to choose whether to perform virus detection on the target file.

[0058] Understandably, if the digital signature certificate is not found in the digital signature certificate library, there is no current reputation score. Therefore, no reputation score will be sent to the client. Instead, an alert will be sent to the client. Upon receiving the alert, the client can choose to perform a virus scan on the target file based on local settings, or display an option for the user to select whether to perform a virus scan on the target file, and proceed to the next step based on the user's selection.

[0059] Preferably, the digital signature certificate detection method provided in the embodiment of the present invention may further include:

[0060] If the digital signature certificate is not found in either the trusted digital signature certificate library or the reputation evaluation digital signature certificate library, the reputation score corresponding to the digital signature certificate is determined according to a preset third reputation evaluation rule.

[0061] The third reputation evaluation rule includes but is not limited to: determining the reputation score corresponding to the digital signature certificate based on the number of files loaded with the digital signature certificate in the public network, and / or the compiler information of the target file, and / or the shell information of the digital signature certificate, and then executing step 103. Specifically:

[0062] (1) Check whether the number of files loaded with the digital signature certificate in the public network is greater than a preset threshold. If so, the score is increased, for example, 20 points are increased. If not, the score is deducted, for example, 20 points are deducted. (2) Check the compiler information of the target file. If the compiler is an uncommon type, the score is deducted, for example, 10 points are deducted. (3) Check the shell information of the digital signature certificate. If the shell information is an uncommon type, the score is deducted, for example, 30 points are deducted.

[0063] By utilizing a digital signature certificate detection method provided by an embodiment of the present invention, a client receives a digital signature certificate for a target file, searches a preset digital signature certificate library for the corresponding reputation score, and sends the reputation score to the client. The client then determines whether to perform virus detection on the target file based on the reputation score. This method enables digital signature certificate detection, improves terminal device security, and minimizes resource consumption.

[0064] Figure 4 This is a schematic diagram of the structure of a digital signature certificate detection device provided by an embodiment of the present invention. The device can be applied to a server.

[0065] like Figure 4 As shown, the digital signature certificate detection device of this embodiment may include:

[0066] Receiving unit 401, used to receive the digital signature certificate for loading the target file sent by the client;

[0067] A search unit 402 is configured to search a preset digital signature certificate library for a reputation score corresponding to the digital signature certificate;

[0068] The sending unit 403 is configured to send the reputation score to the client, so that the client determines whether to perform virus detection on the target file according to the reputation score.

[0069] Preferably, the digital signature certificate library includes: a credit digital signature certificate library and a reputation evaluation digital signature certificate library;

[0070] The search unit 402 is specifically configured to: search for a reputation score corresponding to the digital signature certificate in the trusted digital signature certificate library; if the reputation score corresponding to the digital signature certificate is not found in the trusted digital signature certificate library, search for the digital signature certificate in the reputation evaluation digital signature certificate library; if the digital signature certificate is found in the reputation evaluation digital signature certificate library, detect whether the number of files loaded with the digital signature certificate in the public network is greater than a preset first threshold, and update the reputation score corresponding to the digital signature certificate in the reputation evaluation digital signature certificate library based on the detection result and a preset first reputation scoring rule; and determine the updated reputation score as the reputation score corresponding to the digital signature certificate.

[0071] Preferably, the search unit 402 is also used to: if the number of files loaded with the digital signature certificate in the public network is greater than the first threshold and the updated reputation score is greater than the preset second threshold, then add the digital signature certificate and the corresponding reputation score to the trusted digital signature certificate library.

[0072] Preferably, Figure 5 As shown, the device also includes: an adding unit 405 for: if the digital signature certificate is not found in the trusted digital signature certificate library and the reputation evaluation digital signature certificate library, determining the reputation score corresponding to the digital signature certificate according to a preset third reputation evaluation rule; adding the digital signature certificate and the corresponding reputation score to the reputation evaluation digital signature certificate library; wherein the third reputation evaluation rule includes: determining the reputation score corresponding to the digital signature certificate based on the number of files loaded with the digital signature certificate in the public network, and / or the compiler information of the target file, and / or the shell information of the digital signature certificate.

[0073] By utilizing a digital signature certificate detection device provided by an embodiment of the present invention, a client receives a digital signature certificate for a target file, searches a preset digital signature certificate library for the corresponding reputation score, and sends the reputation score to the client. The client then determines whether to perform virus detection on the target file based on the reputation score. This allows for digital signature certificate detection, improving terminal device security while minimizing resource consumption.

[0074] An embodiment of the present invention further provides an electronic device. Figure 6 This is a schematic diagram of the structure of an embodiment of the electronic device of the present invention, which can realize the present invention. Figure 1 The process of the embodiment shown is as follows: Figure 6 As shown, the above-mentioned electronic device may include: a shell 61, a processor 62, a memory 63, a circuit board 64 and a power supply circuit 65, wherein the circuit board 64 is placed inside the space enclosed by the shell 61, and the processor 62 and the memory 63 are arranged on the circuit board 64; the power supply circuit 65 is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory 63 is used to store executable program code; the processor 62 runs the program corresponding to the executable program code by reading the executable program code stored in the memory 63, so as to execute the method described in any of the above-mentioned embodiments.

[0075] This electronic device exists in many forms, including but not limited to:

[0076] (1) Mobile communication devices: These devices are characterized by their mobile communication capabilities and are primarily designed to provide voice and data communications. These terminals include smartphones (e.g., iPhones), multimedia phones, feature phones, and low-end phones.

[0077] (2) Ultra-mobile personal computer devices: These devices fall under the category of personal computers, have computing and processing capabilities, and generally also have mobile Internet access. These terminals include PDAs, MIDs, and UMPCs, such as the iPad.

[0078] (3) Portable entertainment devices: These devices can display and play multimedia content. These devices include audio and video playback modules (such as iPods), handheld game consoles, e-books, smart toys, and portable car navigation devices.

[0079] (4) Server: A device that provides computing services. The server consists of a processor, hard disk, memory, system bus, etc. The server is similar to a general computer architecture, but because it needs to provide highly reliable services, it has higher requirements in terms of processing power, stability, reliability, security, scalability, and manageability.

[0080] (5) Other electronic devices with data interaction functions.

[0081] An embodiment of the present invention provides a computer-readable storage medium, which stores one or more programs. The one or more programs can be executed by one or more processors to implement the method described in any of the above embodiments.

[0082] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0083] Each embodiment in this specification is described in a related manner. Similar portions between the embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences from other embodiments. In particular, the device embodiments are generally similar to the method embodiments, so their description is relatively simple. For related portions, refer to the description of the method embodiments.

[0084] For the convenience of description, the above device is described as being divided into various units / modules based on their functions. Of course, when implementing the present invention, the functions of each unit / module can be implemented in the same or multiple software and / or hardware.

[0085] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware through a computer program. The program can be stored in a computer-readable storage medium, and when executed, the program can include the processes in the above-described method embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

[0086] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A digital signature certificate detection method, characterized in that: The method is applied to a server and includes: Receive the digital signature certificate of the target file sent by the client; Searching for a reputation score corresponding to the digital signature certificate in a preset digital signature certificate library; Sending the reputation score to the client, so that the client determines whether to perform virus detection on the target file according to the reputation score; The digital signature certificate library includes: a credit digital signature certificate library and a reputation evaluation digital signature certificate library; The searching for the reputation score corresponding to the digital signature certificate in a preset digital signature certificate library specifically includes: Searching for a credit score corresponding to the digital signature certificate in the trusted digital signature certificate library; If the reputation score corresponding to the digital signature certificate is not found in the trust digital signature certificate library, searching for the digital signature certificate in the reputation evaluation digital signature certificate library; If the digital signature certificate is found in the reputation evaluation digital signature certificate library, detecting whether the number of files loaded with the digital signature certificate in the public network is greater than a preset first threshold, and updating the reputation score corresponding to the digital signature certificate in the reputation evaluation digital signature certificate library based on the detection result and a preset first reputation scoring rule; The updated reputation score is determined as the reputation score corresponding to the digital signature certificate.

2. The method according to claim 1, characterized in that The method further comprises: If the number of files loaded with the digital signature certificate in the public network is greater than the first threshold and the updated reputation score is greater than a preset second threshold, the digital signature certificate and the corresponding reputation score are added to the trusted digital signature certificate library.

3. The method according to claim 1, characterized in that The method further comprises: triggering an execution action on the client in response to receiving the target file sent by the client; According to the execution action and a preset second reputation scoring rule, the reputation score corresponding to the digital signature certificate in the trusted digital signature certificate library is updated.

4. The method according to claim 1, wherein The method further comprises: If the digital signature certificate is not found in the digital signature certificate library, an alarm message is sent to the client, so that the client can perform virus detection on the target file or output an option for the user to choose whether to perform virus detection on the target file.

5. The method according to claim 1, characterized in that The method further comprises: If the digital signature certificate is not found in either the trusted digital signature certificate library or the reputation evaluation digital signature certificate library, determining a reputation score corresponding to the digital signature certificate according to a preset third reputation evaluation rule; Adding the digital signature certificate and the corresponding reputation score to the reputation evaluation digital signature certificate library; The third reputation evaluation rule includes determining a reputation score corresponding to the digital signature certificate based on the number of files loaded with the digital signature certificate in the public network, and / or compiler information of the target file, and / or shell information of the digital signature certificate.

6. A digital signature certificate detection device, characterized in that: The device is applied to a server, and includes: A receiving unit, configured to receive a digital signature certificate sent by a client for loading a target file; A search unit, configured to search a preset digital signature certificate library for a reputation score corresponding to the digital signature certificate; a sending unit, configured to send the reputation score to the client, so that the client determines whether to perform virus detection on the target file according to the reputation score; The digital signature certificate library includes: a credit digital signature certificate library and a reputation evaluation digital signature certificate library; The search unit is specifically configured to: Searching for a credit score corresponding to the digital signature certificate in the trusted digital signature certificate library; If the reputation score corresponding to the digital signature certificate is not found in the trust digital signature certificate library, searching for the digital signature certificate in the reputation evaluation digital signature certificate library; If the digital signature certificate is found in the reputation evaluation digital signature certificate library, detecting whether the number of files loaded with the digital signature certificate in the public network is greater than a preset first threshold, and updating the reputation score corresponding to the digital signature certificate in the reputation evaluation digital signature certificate library based on the detection result and a preset first reputation scoring rule; The updated reputation score is determined as the reputation score corresponding to the digital signature certificate.

7. The device according to claim 6, characterized in that The search unit is further configured to: If the number of files loaded with the digital signature certificate in the public network is greater than the first threshold and the updated reputation score is greater than a preset second threshold, the digital signature certificate and the corresponding reputation score are added to the trusted digital signature certificate library.

8. The device according to claim 6, characterized in that The device further comprises: Add units for: If the digital signature certificate is not found in either the trusted digital signature certificate library or the reputation evaluation digital signature certificate library, determining a reputation score corresponding to the digital signature certificate according to a preset third reputation evaluation rule; Adding the digital signature certificate and the corresponding reputation score to the reputation evaluation digital signature certificate library; The third reputation evaluation rule includes determining a reputation score corresponding to the digital signature certificate based on the number of files loaded with the digital signature certificate in the public network, and / or compiler information of the target file, and / or shell information of the digital signature certificate.

Citation Information

Patent Citations

  • Simplified communication of a reputation score for an entity

    CN102171657A

  • Electronic certificate credit evaluation method and device

    CN112422534A