Certificate management method and device, computer equipment and storage medium
Through automated monitoring and alarm mechanisms, the problem of expired and timely update in digital certificate management is solved, ensuring the stability and security of the system, and reducing operation and maintenance costs.
Patent Information
- Application Number
- CN202510652460.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-08-08
AI Technical Summary
In the financial and medical fields, the complex management of digital certificates and the expiration and failure to be updated in time may lead to service interruption or data security risks. The lack of effective automated management solutions in the existing technology has increased the workload and risks of operation and maintenance personnel.
By reading the certificate information in the system, determine whether its expiration time is less than the set threshold, and issue alarm information when the certificate is about to expire, including automated monitoring, alarm and certificate update processes to ensure timely replacement of certificates.
It realizes accurate monitoring of the validity period of the certificate, avoids service interruptions or data security risks caused by certificate expiration, reduces the workload of operation and maintenance personnel, and improves operation and maintenance efficiency and system stability.
Smart Images

Figure CN120454986A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of certificate management, and more specifically to a certificate management method, apparatus, computer equipment, and storage medium. Background Art
[0002] In the financial and medical sectors, digital certificates, as an essential tool for identity authentication and data encryption, play a crucial role in modern network communications and mobile applications. A core and defining characteristic of digital certificates is their timeliness: digital certificates are valid only for a specific period of time. Failure to promptly replace expired certificates can lead to serious consequences, including but not limited to application service unavailability, data communication interruptions, and other major production incidents.
[0003] In current mobile app development scenarios, apps typically use multiple types of digital certificates, such as SSL certificates, iOS packaging certificates and description files, and push certificates. These certificates have varying validity periods and replacement cycles depending on their function and purpose. For example, SSL certificates are used to ensure network communication security, iOS packaging certificates and description files are closely related to app packaging and distribution, and push certificates determine whether an app can properly receive push messages from the server.
[0004] Because these certificates expire at different times and have different application, replacement, and renewal processes, ensuring timely renewal and replacement of certificates before expiration has become a pressing issue in mobile application development and operations. This is especially true for large internet companies, where the sheer number of applications and complexity of certificate management make it highly likely that failure to effectively manage these certificates could lead to service interruptions or data security issues caused by expired certificates.
[0005] Furthermore, some staff may lack experience in certificate management and lack a mature, effective certificate management solution. This further increases uncertainty and risk in the certificate management process, potentially leading to frequent issues such as untimely certificate replacement and irregular management. Therefore, designing a certificate management solution that reduces the risks introduced by manual operations, lowers the probability of abnormal events, and helps operations personnel verify the standardization of certificate management in their systems is crucial for improving the security and stability of mobile applications. Summary of the Invention
[0006] The purpose of the present invention is to overcome the defects of the prior art and provide a certificate management method, device, computer equipment and storage medium.
[0007] To achieve the above object, the present invention adopts the following technical solutions:
[0008] Certificate management methods, including:
[0009] Read the certificate information in the system;
[0010] Determine whether the time from certificate expiration in the certificate information is less than the set threshold;
[0011] If the time from certificate expiration to certificate expiration in the certificate information is less than the set threshold, an alarm message will be issued.
[0012] A further technical solution is as follows: the certificate information in the reading system includes:
[0013] Access the database where the system stores certificates;
[0014] Collecting all basic information related to the certificate in a database to obtain an information set;
[0015] Perform format parsing on the information set to obtain parsing features;
[0016] Read the certificate-related data in the parsed features to obtain the certificate information.
[0017] A further technical solution is: the determination of whether the time from certificate expiration in the certificate information is less than a set threshold includes:
[0018] Get the current time and extract the expiration time of each certificate in the certificate information;
[0019] Calculate the remaining validity period of each certificate based on the current time and the expiration time of the certificate;
[0020] According to business needs and certificate management practices, set a time threshold, that is, set a threshold;
[0021] The remaining validity period of each certificate is compared to a set threshold.
[0022] A further technical solution is: if the time from certificate expiration in the certificate information is less than a set threshold, an alarm message is issued, including:
[0023] Determine the recipients of alerts based on the certificate type and usage scenario.
[0024] Prepare the content of the alarm information according to the specific information of the certificate and the responsibilities of the alarm object to obtain the alarm information;
[0025] Send the alarm information to the corresponding alarm object through the selected alarm method.
[0026] A further technical solution is: after determining whether the time from certificate expiration in the certificate information is less than a set threshold, the method further includes:
[0027] Continuously monitor the status of all certificates within the system.
[0028] A further technical solution thereof is: after the alarm information is issued, the method further comprises:
[0029] Assess the business impact based on the certificate expiration date provided in the alert information to determine the urgency of certificate renewal.
[0030] Initiate the certificate renewal process based on the urgency to obtain a new certificate;
[0031] Deploy the new certificate to the system and update the system configuration to use the new certificate.
[0032] A further technical solution thereof is: after the alarm information is issued, the method further comprises:
[0033] During the online operation of the system, the system uses the embedded information to obtain the version status of the user's APP in real time; if it is detected that the certificate contained in the APP version used by the user is about to expire, the system will send an upgrade reminder to the user through in-app notification or push message. For users who fail to upgrade within the set time, the system will take forced upgrade measures to ensure that the user can update to the APP version containing a valid certificate.
[0034] The present invention also provides a certificate management device, comprising:
[0035] A reading unit, used to read the certificate information in the system;
[0036] A judgment unit, used to judge whether the time from certificate expiration in the certificate information is less than a set threshold;
[0037] The alarm unit is used to issue an alarm message if the time to certificate expiration in the certificate information is less than a set threshold.
[0038] The present invention further provides a computer device, comprising a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the above method when executing the computer program.
[0039] The present invention also provides a storage medium, wherein the storage medium stores a computer program, and the computer program implements the above method when executed by a processor.
[0040] Compared with the prior art, the beneficial effects of the present invention are as follows: by reading the certificate information in the system and judging in real time whether the certificate is less than a preset threshold value, accurate monitoring of the certificate validity period is achieved. Once it is found that the certificate is about to expire, the system will immediately issue an alarm message to remind the operation and maintenance personnel to replace the certificate in time. This accurate monitoring and timely alarm mechanism effectively avoids service interruption or data security risks caused by certificate expiration, and ensures the continuity and stability of application services; in addition, by automating operations such as reading certificate information, judging expiration time, and issuing alarm information, the workload of operation and maintenance personnel in certificate management is significantly reduced. Operation and maintenance personnel no longer need to manually check the expiration time of each certificate, nor do they need to worry about certificate expiration due to negligence. This automated management method not only reduces operating labor costs, but also improves operation and maintenance efficiency, allowing operation and maintenance personnel to devote more energy to other key tasks.
[0041] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0043] Figure 1 A schematic diagram of an application scenario of the certificate management method provided by an embodiment of the present invention;
[0044] Figure 2 A flow chart of a certificate management method provided in an embodiment of the present invention;
[0045] Figure 3 A schematic block diagram of a certificate management device provided in an embodiment of the present invention;
[0046] Figure 4 A schematic block diagram of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0047] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0048] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0049] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the present invention. As used in the specification and appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0050] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0051] See also Figure 1 and Figure 2 , Figure 1 A schematic diagram of an application scenario of the certificate management method provided by an embodiment of the present invention. Figure 2 A schematic flow chart of a certificate management method provided in an embodiment of the present invention. The certificate management method is applied to a server, which interacts with a terminal for data exchange. By reading certificate information in the system and determining in real time whether the certificate's expiration time is less than a preset threshold, accurate monitoring of the certificate's validity period is achieved. Once a certificate is found to be about to expire, the system will immediately issue an alarm message to remind the operation and maintenance personnel to replace the certificate in a timely manner. This accurate monitoring and timely alarm mechanism effectively avoids service interruptions or data security risks caused by certificate expiration, ensuring the continuity and stability of application services. In addition, by automatically reading certificate information, determining expiration time, and issuing alarm messages, the workload of operation and maintenance personnel in certificate management is significantly reduced. Operation and maintenance personnel no longer need to manually check the expiration time of each certificate, nor do they need to worry about certificate expiration due to negligence. This automated management method not only reduces operating labor costs, but also improves operation and maintenance efficiency, allowing operation and maintenance personnel to devote more energy to other key tasks.
[0052] Figure 2 FIG. 1 is a flow chart of the certificate management method provided by an embodiment of the present invention. Figure 2 As shown, the method includes the following steps S110 to S130.
[0053] S110, read the certificate information in the system;
[0054] Specifically, by writing automated scripts or leveraging existing certificate management tools, you can regularly scan the digital certificates stored in the system. The script or tool will traverse the specified certificate storage path and read the detailed information of each certificate, including but not limited to the certificate subject, issuer, validity start date, validity end date, etc.
[0055] In other words, reading certificate information through automated scripts or tools reduces the need for manual intervention and improves the automation level of certificate management, which not only saves labor costs but also reduces the risk of certificate expiration due to human negligence.
[0056] In one embodiment, the reading of the certificate information in the system includes:
[0057] Access the database where the system stores certificates;
[0058] Specifically, first, you need to determine which database the system uses to store credential information (e.g., MySQL, Oracle, MongoDB, etc.) and determine the database's physical or logical location (e.g., local server, cloud service provider, etc.). Use a database connection library or API (e.g., JDBC, ODBC, Python's SQLAlchemy, etc.) to establish a connection to the database based on the database type and authentication information (e.g., username, password, IP address, port number, etc.). After establishing the connection, perform a simple query test to ensure that the connection is functioning properly and that the database data can be accessed.
[0059] Collecting all basic information related to the certificate in a database to obtain an information set;
[0060] Specifically, based on the storage structure of certificate information in the database, SQL queries or other database query languages are designed to collect all relevant basic certificate information (such as certificate ID, certificate subject, issuer, validity start date, validity end date, certificate status, etc.). Through the established database connection, the query statements are executed to obtain the query results. The query results are organized into a structured information set in the form of a list, dictionary, data frame, etc. for easy subsequent processing.
[0061] Perform format parsing on the information set to obtain parsing features;
[0062] Specifically, parsing rules are determined based on the certificate information's storage format and business needs. For example, some fields may require specific format conversions (such as date format conversions), while others may require extracting specific information (such as extracting domain name information from the certificate subject). The information set is traversed, and parsing rules are applied to each certificate information element to perform format parsing. The parsed information is stored as parsed features, which can be new fields, attributes, or structures, to facilitate subsequent reading and processing.
[0063] Read the certificate-related data in the parsed features to obtain the certificate information.
[0064] Specifically, based on business needs, determine the certificate data fields that need to be read (such as the certificate subject, validity period, etc.). Traverse the parsed features and extract the corresponding certificate data based on the reading requirements. Construct the extracted data into a certificate information object or structure, which can be a class instance, dictionary, tuple, etc., for subsequent use or display.
[0065] In other words, by directly accessing the database and designing efficient query statements, the required certificate information can be quickly and accurately collected, avoiding the need for manual searches or traversing large amounts of data. Furthermore, by parsing the format of the collected information, features can be extracted that better meet business needs, making data processing more flexible and scalable. For example, parsing rules can be adjusted to extract different certificate information based on different business scenarios. Furthermore, automated reading and processing of certificate information reduces the need for manual intervention, thereby reducing the risk of oversight or error. This also saves labor costs and improves work efficiency.
[0066] S120: Determine whether the time from certificate expiration in the certificate information is less than a set threshold;
[0067] Specifically, after reading the certificate's expiration date, the time difference between the current date and the certificate's expiration date is calculated. This time difference is then compared to a pre-set threshold to determine whether the certificate is about to expire. The threshold setting can be adjusted based on actual business needs, for example, to 30 days, 60 days, etc. When calculating the time difference, factors such as time zone and daylight saving time need to be considered to ensure accuracy. Furthermore, to improve efficiency, certificates can be sorted by expiration date, prioritizing certificates that are about to expire.
[0068] In other words, by setting thresholds and automatically determining expiration times, the need for manual intervention is reduced and the level of automation in certificate management is improved.
[0069] In one embodiment, determining whether the time from certificate expiration in the certificate information is less than a set threshold includes:
[0070] Get the current time and extract the expiration time of each certificate in the certificate information;
[0071] Specifically, use the system's built-in time functions or libraries (such as Python's datetime module) to obtain the current date and time. Then, extract the expiration date field of each certificate from the certificate information. This is usually a string in date or datetime format, and the appropriate format conversion (such as converting a string to a date object) is required for subsequent calculations.
[0072] Calculate the remaining validity period of each certificate based on the current time and the expiration time of the certificate;
[0073] Specifically, use a date and time processing library (such as timedelta in Python's datetime module) to calculate the time difference between the current time and the certificate expiration time to obtain the remaining validity period. This time difference can be expressed as days, hours, minutes, etc., depending on business needs. To facilitate subsequent comparison and display, the remaining validity period can be formatted into a unified unit (such as days) or retained as a time difference object.
[0074] According to business needs and certificate management practices, set a time threshold, that is, set a threshold;
[0075] Specifically, you can communicate with the business department to understand their specific requirements for how long before certificate expiration they need alerts or other measures. You can also consult industry best practices, internal company regulations, or historical experience to determine a reasonable threshold. This threshold should be long enough to allow operations personnel sufficient time to replace certificates or take other countermeasures, but also avoid being too long, which can cause alerts to become untimely. Finally, set the threshold determined by this analysis as a configuration parameter or constant in the system for easy subsequent use and adjustment.
[0076] The remaining validity period of each certificate is compared to a set threshold.
[0077] Specifically, the remaining validity period of all certificates is traversed and each certificate's remaining validity period is compared with a set threshold. If the remaining validity period of a certificate is less than the set threshold, the certificate is marked as "about to expire" or other corresponding processing measures are taken (such as issuing an alarm message).
[0078] In other words, by automatically calculating the remaining validity period of a certificate and comparing it with a set threshold, certificates approaching expiration can be promptly identified and appropriate action taken. This avoids the potential for oversight and delays caused by manual inspections, improving the timeliness and accuracy of certificate management. Furthermore, by setting appropriate thresholds, operations and maintenance personnel can be assured of sufficient time to prepare and address certificate expiration, avoiding the need to rush into action when a certificate is about to expire, thereby optimizing the allocation and efficiency of operations and maintenance resources.
[0079] S130: If the time to certificate expiration in the certificate information is less than a set threshold, an alarm message is issued.
[0080] Specifically, when it is determined that the remaining validity period of a certificate is less than the set threshold, the system automatically triggers the alarm mechanism. The alarm information can be sent to relevant operation and maintenance personnel or certificate administrators through various methods such as email, SMS, system messages, etc. The alarm information should include detailed information about the certificate (such as the certificate subject, expiration date), the remaining validity period, and recommended follow-up actions (such as applying for a new certificate immediately, arranging a certificate replacement plan, etc.). At the same time, in order to ensure the timely delivery of the alarm information, an alarm retry mechanism can be set, and confirmation and feedback can be provided after the alarm is sent.
[0081] That is to say, by issuing timely warnings when the certificate is about to expire, operation and maintenance personnel or certificate administrators can know in advance and arrange certificate replacement, thus avoiding service interruptions or data security issues caused by certificate expiration.
[0082] In one embodiment, if the time until the certificate expiration in the certificate information is less than a set threshold, issuing an alarm message includes:
[0083] Determine the recipients of alerts based on the certificate type and usage scenario.
[0084] Specifically, classify the certificates in the system, such as SSL certificates / TLS certificates / iOS packaging certificates, code signing certificates, client certificates, etc. Different types of certificates may involve different business systems and application scenarios. Analyze the usage scenarios of each certificate to determine which personnel or teams need to know and take action before the certificate expires. For example: SSL certificates / TLS certificates / iOS packaging certificates may involve the network operation and maintenance team, security team and business department; code signing certificates may involve the development team and release team. Based on the certificate type and usage scenario, determine the specific objects that need to receive alarm information, such as operation and maintenance personnel, security administrators, project managers, etc., and establish a mapping relationship between the alarm object and the certificate type.
[0085] Prepare the content of the alarm information according to the specific information of the certificate and the responsibilities of the alarm object to obtain the alarm information;
[0086] Specifically, extract key fields from the certificate information, such as the certificate subject, issuer, expiration date, and the system or application to which it belongs. Understand the scope of responsibility of each alert recipient, determine what certificate information they need to know, and the urgency of the alert. Customize the content of the alert based on the specific information of the certificate and the responsibilities of the alert recipient. The alert should include the key information of the certificate, expiration date, remaining validity period, possible impact, and recommended follow-up actions (such as applying for a new certificate immediately, arranging a replacement plan, etc.). Format the alert information into easy-to-read and understand text, email templates, or system message formats.
[0087] Send the alarm information to the corresponding alarm object through the selected alarm method.
[0088] Specifically, according to the preferences of the alarm target and the availability of the system, select the appropriate alarm method, such as email, SMS, system message, instant messaging tools (such as WeChat for Business, DingTalk), etc. Configure the corresponding alarm channel in the system to ensure that the alarm information can be sent to the alarm target accurately and in a timely manner. When the remaining validity period of the certificate is less than the set threshold, the alarm mechanism is automatically triggered, and the alarm information is sent to the corresponding alarm target through the selected alarm method. Optionally, the alarm target can be asked to confirm that it has received the alarm information, or the system can record the sending status and receipt of the alarm information for subsequent tracking and auditing.
[0089] Specifically, by identifying alert targets based on certificate type and usage scenario, and customizing alert information based on the specific certificate information and the responsibilities of the alert recipient, we can ensure that alert information is accurately and promptly communicated to relevant personnel, improving the relevance and effectiveness of alerts. Furthermore, clear alert targets and responsibilities facilitate cross-departmental collaboration and response. When a certificate is about to expire, relevant teams can quickly understand the situation and take action, avoiding delays and risks. Furthermore, automated alert mechanisms reduce the workload of manual monitoring and notifications, improving operational efficiency. Timely alerts help operational personnel proactively identify and resolve certificate expiration issues, thereby improving system stability and availability. Furthermore, regular delivery of certificate expiration alerts enhances security awareness among relevant personnel regarding certificate management. This also helps enterprises comply with relevant regulations and standards regarding certificate management.
[0090] In one embodiment, after determining whether the time from certificate expiration in the certificate information is less than a set threshold, the method further includes:
[0091] S140. Continuously monitor the status of all certificates in the system.
[0092] Specifically, set a fixed time interval (such as daily, weekly or hourly) and use automated scripts or certificate management tools to regularly scan all locations where certificates are stored in the system, including but not limited to servers, databases, application configuration files, etc. During the scanning process, not only the basic information of the certificate (such as issuer, subject, validity period, etc.) is read, but also the status of the certificate (such as whether it is valid, whether it has been revoked, etc.) is checked, and this information is updated to the certificate management database or system in real time or quasi-real time. For scenarios that require higher security, a certificate revocation list (CRL) or online certificate status protocol (OCSP) check can be integrated to confirm whether the certificate has been revoked by the issuing authority. The results of each scan are logged, including the scan time, the number of scanned certificates, the number of expired or expiring certificates found, etc., for subsequent auditing and troubleshooting. In addition, an exception handling mechanism is set up. When an abnormal certificate status (such as expiration or revocation) is found, the alarm process is immediately triggered to notify the relevant operation and maintenance personnel or certificate administrators.
[0093] In other words, through continuous monitoring, the system can understand the status of certificates in real time or near real time, promptly detect and address issues such as certificate expiration and revocation, and avoid service interruptions or security risks caused by changes in certificate status. Furthermore, effective certificate status monitoring is a crucial step in ensuring system security and stability. By promptly detecting and addressing certificate issues, security vulnerabilities or service failures caused by certificate expiration or revocation can be prevented, protecting the normal operation of the system and the security of user data. Furthermore, continuous monitoring enables operations and maintenance personnel to be aware of changes in certificate status in advance, allowing them to rationally arrange operations and maintenance resources and time to apply for, update, or replace certificates. This helps optimize operations and maintenance processes, improve efficiency, and reduce costs.
[0094] In one embodiment, after issuing the warning information, the method further includes:
[0095] Assess the business impact based on the certificate expiration date provided in the alert information to determine the urgency of certificate renewal.
[0096] Specifically, organize cross-departmental meetings and invite relevant personnel from business departments, operation and maintenance teams, security teams, etc. to participate in order to jointly analyze the impact that certificate expiration may have on the business. For example: for public-facing websites, certificate expiration may cause users to be unable to access, affecting user experience and business revenue; for internal systems, certificate expiration may cause service interruption, affecting work efficiency. Based on the results of the business impact analysis, formulate standards for the urgency of certificate updates. For example: the urgency can be divided into three levels: "high", "medium", and "low", where "high" means that the expiration of the certificate will immediately cause business interruption or significant losses, "medium" means that the expiration of the certificate will affect business operations in the short term, and "low" means that the expiration of the certificate has little impact on the business or is tolerable. Based on the certificate expiration time provided in the alarm information and the results of the business impact analysis, determine the urgency of each certificate update and record it in the certificate management system.
[0097] Initiate the certificate renewal process based on the urgency to obtain a new certificate;
[0098] Specifically, develop a detailed certificate renewal process based on the type of certificate (such as SSL certificate / TLS certificate / iOS packaged certificate, code signing certificate, etc.) and business needs. The process should include certificate application, review, issuance, receipt and other links, and clearly define the person in charge and the time node for each link. Prioritize the certificate renewal tasks according to the urgency of the certificate renewal. Certificate renewal tasks with high urgency should be handled first to ensure that the update is completed before the certificate expires. Use automated tools (such as certificate management platforms, automated scripts, etc.) to assist in the execution of the certificate renewal process and improve the efficiency and accuracy of the update. For example: you can use automated scripts to automatically submit certificate applications, download new certificates, etc. During the certificate renewal process, strengthen the review and verification links to ensure the legitimacy and validity of the new certificate. For example: you can ask the issuing authority to provide detailed information and verification methods for the certificate, and perform installation tests and compatibility tests on the new certificate.
[0099] Deploy the new certificate to the system and update the system configuration to use the new certificate.
[0100] Specifically, develop a detailed new certificate deployment plan based on the system architecture and deployment environment. The plan should include deployment time, deployment steps, rollback plan, and other content, and clearly define the responsible person and time node for each step. When deploying new certificates, ensure the security of operations. For example, you can use an encrypted channel to transmit new certificates to prevent certificates from being stolen or tampered with during transmission; during the deployment process, take necessary access control and permission management measures to prevent unauthorized access and operations. After deploying the new certificate, promptly update the system configuration to use the new certificate. This includes updating the server's SSL / TLS / iOS packaging configuration, the application's certificate reference path, etc. When updating the system configuration, carefully check the configuration information to ensure the correctness of the configuration. After updating the system configuration, conduct comprehensive testing and verification to ensure that the new certificate can work properly and does not affect the normal operation of the system. The testing content may include functional testing, performance testing, security testing, etc.
[0101] In other words, by assessing business impact and determining urgency, we can ensure that high-urgency certificate renewal tasks are prioritized, thereby improving the timeliness of certificate renewal. Furthermore, developing a detailed certificate renewal process and deployment plan, as well as strengthening the review and verification process, can improve the accuracy of certificate renewal. Furthermore, timely certificate renewal can avoid the risk of business interruption caused by certificate expiration. By assessing business impact and determining urgency, we can plan certificate renewal tasks in advance and ensure that renewals are completed before expiration, thereby ensuring business continuity and stability. Furthermore, using new, valid certificates can enhance system security. Furthermore, adhering to the certificate renewal process and deployment plan ensures system compliance and meets the requirements of relevant regulations and standards for certificate management. Furthermore, by developing a detailed certificate renewal process and deployment plan, and utilizing automated tools to assist in execution, we can optimize operations and maintenance processes and improve efficiency. Furthermore, prioritizing and allocating resources based on the urgency of certificate renewals can ensure the smooth completion of critical tasks and improve resource utilization.
[0102] In one embodiment, after issuing the warning information, the method further includes:
[0103] During the online operation of the system, the system uses the embedded information to obtain the version status of the user's APP in real time; if it is detected that the certificate contained in the APP version used by the user is about to expire, the system will send an upgrade reminder to the user through in-app notification or push message. For users who fail to upgrade within the set time, the system will take forced upgrade measures to ensure that the user can update to the APP version containing a valid certificate.
[0104] Specifically, tracking codes are set at key locations of the APP (such as the startup page, function entry, etc.) to collect version information of the user's APP. The tracking code can record data such as the version number, installation time, update time, etc. of the APP, and send this data to the back-end server. The back-end server receives the data sent by the tracking code and stores it in the database. Relational databases (such as MySQL) or non-relational databases (such as MongoDB) can be used to store this data for subsequent analysis and processing. Establish a real-time monitoring system to regularly query the user APP version information stored in the database to understand the version distribution of the user APP in real time. Scheduled tasks or message queues can be used to implement real-time monitoring to ensure the timeliness and accuracy of the data.
[0105] Maintain a certificate information library in the system to record the certificate information used by each APP version, including the certificate expiration date, issuing authority, etc. Regularly check the certificate information library to determine whether the certificates in each APP version are about to expire. Develop an upgrade reminder strategy based on the certificate expiration date and business needs. For example, you can set it to send upgrade reminders to users at different time points such as 30 days, 15 days, and 7 days before the certificate expires. When it is detected that the certificate in the APP version used by the user is about to expire, according to the upgrade reminder strategy, an upgrade reminder will be sent to the user through in-app notifications or push messages. In-app notifications can pop up a prompt box on the APP interface to inform users that the certificate is about to expire and guide users to upgrade. Push messages can be sent to users' phones through the mobile phone system's push service (such as Apple's APNs and Android's FCM) to remind users to upgrade the APP in a timely manner.
[0106] Considering business needs and user experience, set a reasonable upgrade time threshold. For example, you can set the upgrade time threshold three days before the certificate expires. If the user still does not upgrade within this time threshold, the system will take forced upgrade measures. When the upgrade time threshold is reached, the system will take forced upgrade measures for users who have not upgraded. Forced upgrade can be achieved in the following ways:
[0107] Limit APP functions: When the user opens the APP, check whether the APP version is the latest version. If not, restrict the user from using some or all functions until the user completes the upgrade.
[0108] Automatically download and prompt installation: Automatically download the latest version of the app installation package in the background and pop up a prompt box when the user opens the app, guiding the user to install the latest version. If the user refuses to install, the prompt box can pop up again until the user completes the installation.
[0109] Force jump to the App Store: Directly open the download page of the APP in the App Store and guide users to upgrade.
[0110] In other words, by obtaining real-time information about user app versions and promptly reminding users to upgrade to an app version with a valid certificate, users can avoid security risks such as data leakage and man-in-the-middle attacks caused by using app versions with expired certificates. Furthermore, expired certificates can prevent apps from accessing servers or conducting secure communications, impacting normal business operations. By implementing mandatory upgrade measures, users can be guaranteed to promptly update to an app version with a valid certificate, ensuring business continuity and stability and reducing disruptions caused by certificate issues. Using in-app notifications or push messages to notify users of impending certificate expiration provides timely notification without causing excessive disruption. Furthermore, mandatory upgrade measures prevent users from being unable to use the app due to delayed upgrades, thereby improving the user experience. Furthermore, a systematic certificate management and upgrade mechanism facilitates the management and maintenance of certificates used within apps. When certificates need to be updated, simply follow the established process to ensure that all users are promptly updated to an app version with a valid certificate, reducing the difficulty and cost of certificate management.
[0111] For example, certificate management is crucial in the healthcare sector. Hospital information systems (such as electronic medical records, telemedicine, and medical device management systems) use various certificates to ensure data transmission security, system identity authentication, and trusted communication between devices. These certificates include SSL / TLS / iOS packaging certificates for encrypted network communications, and code signing certificates for ensuring the integrity and trusted origin of medical software and device firmware.
[0112] Read the certificate information in the system:
[0113] Accessing the database: The hospital's information technology department (IT department) uses specialized certificate management tools to access the database that stores medical system certificates. This database may be stored on the hospital's core server or on multiple nodes using a distributed database architecture.
[0114] Collect basic information: Collect all basic information related to the certificate in the database, such as the certificate serial number, issuing authority, issuance time, expiration time, system or device to which it belongs, etc., and summarize this information into an information set.
[0115] Format Parsing: Perform format parsing on the collected information set. Because different certificate issuing authorities may use different certificate format standards (such as the X.509 standard), certificate management tools need to be able to identify and parse these formats, extracting key parsing features such as the certificate's subject field (containing information such as the hospital name and department) and public key information.
[0116] Get certificate information: Read the certificate-related data from the parsed features to obtain complete certificate information, including the certificate's validity period, scope of use, and other details.
[0117] Determine whether the time from certificate expiration in the certificate information is less than the set threshold:
[0118] Obtaining time information: The certificate management tool obtains the current system time and extracts the expiration date of each certificate. For example, an SSL certificate, TLS certificate, or iOS packaged certificate used for communication between an electronic medical record system and a telemedicine center may expire on December 31, 2024.
[0119] Calculate the remaining validity period: Calculate the remaining validity period of each certificate based on the current time and the certificate expiration date. If the current time is November 1, 2024, the remaining validity period of the certificate is 60 days.
[0120] Set a time threshold: Based on the hospital's business needs and certificate management practices, set a time threshold. For example, if the hospital stipulates that for certificates for critical business systems (such as electronic medical records), an alert should be issued 30 days in advance, then the threshold should be set at 30 days.
[0121] Compare remaining validity period to threshold: Compares the remaining validity period of each certificate to the set threshold. For the certificate in the example above, the remaining validity period of 60 days is greater than the set threshold of 30 days, so no alarm is triggered. However, when the time passes to December 1, 2024, the remaining validity period becomes 30 days, equal to the set threshold, and the alarm mechanism is triggered.
[0122] If the time from certificate expiration to expiration in the certificate information is less than the set threshold, an alarm message will be issued:
[0123] Determine the alert recipients: Based on the certificate type and usage scenario, determine who should receive the alert. For SSL / TLS / iOS packaged certificates for electronic medical record systems, the alert recipients may include the hospital's IT operations team, network security team, and the heads of relevant business departments (such as electronic medical record management).
[0124] Prepare the alert message: Based on the specific information of the certificate and the responsibilities of the alert recipient, prepare the alert message. The alert message should include the certificate name, system, expiration date, remaining validity period, possible business impact (e.g., the electronic medical record system may be unable to communicate securely with the telemedicine center, affecting remote patient consultations), and recommended follow-up actions (e.g., immediately contacting the certificate authority to apply for a new certificate).
[0125] Send alert information: Send alert information to the corresponding alert recipients via the selected alert method. For example, a detailed alert report can be sent via email to members of the IT operations and network security teams, while a brief alert notification can be sent to the heads of relevant business departments via instant messaging tools (such as WeChat for Business).
[0126] If the time until certificate expiration in the certificate information is not less than the set threshold, the status of all certificates in the system will be continuously monitored:
[0127] The IT department establishes a regular scanning mechanism, such as scanning the status of all certificates in the hospital information system every morning. The scan content includes the validity of the certificate (whether it has been revoked) and the remaining validity period. The status of the certificate is confirmed in real time through integrated certificate revocation list (CRL) or online certificate status protocol (OCSP) checks. The results of each scan are logged, including the scan time, the number of scanned certificates, the number of certificate status anomalies found, etc. For example: If the code signing certificate of a medical device is found to be revoked, the relevant information is immediately recorded and the exception handling process is triggered.
[0128] Take follow-up measures based on the warning information:
[0129] Assessing business impact and determining urgency: Upon receiving an alert regarding impending certificate expiration, the IT department convenes a cross-departmental meeting, inviting relevant personnel from business units, the security team, and other departments to assess the impact of the certificate expiration on the business. For electronic medical record systems, the SSL / TLS / iOS packaged certificates are assessed as having a high urgency level, as they involve the secure transmission of patient medical records and the proper operation of telemedicine services.
[0130] Initiate the certificate renewal process: Based on the level of urgency, the certificate renewal process is initiated immediately. IT operations personnel contact the certificate authority and submit a certificate renewal application, providing relevant hospital information and supporting documents. Upon approval by the certificate authority, a new certificate will be issued.
[0131] Deploy the new certificate and update the system configuration: Deploy the new certificate to the hospital's information system and update the system configuration to use the new certificate. For example, install a new SSL certificate / TLS certificate / iOS packaged certificate on the electronic medical record system server and modify the server configuration file to ensure that the system can properly recognize and use the new certificate for secure communication.
[0132] Management of user APP certificates (taking the hospital's patient-side APP as an example):
[0133] Leverage tracking data to obtain real-time information about user app versions: A tracking code is set up in the patient app. When a user opens the app, the tracking code collects app version information (such as version number and installation time) and sends it to the hospital's backend server. The backend server then collects and analyzes the distribution of user app versions in real time.
[0134] Detecting certificate expiration and sending upgrade reminders: The backend server detects whether the certificate included in the app version used by the user is about to expire. For example, a certain version of the app uses an expiring SSL certificate / TLS certificate / iOS packaged certificate for secure communication with the hospital server. When this is detected, the system sends an upgrade reminder to the user via in-app notification or push message, informing the user that the certificate in the current app version is about to expire, which may affect their normal use of some app functions (such as online appointment registration, viewing medical records, etc.), and guides the user to upgrade.
[0135] Forced upgrade: For users who haven't updated within a set timeframe (e.g., 7 days), the system will force an upgrade. When the user opens the app again, some features will be restricted until the upgrade is complete. Alternatively, the user will be directed to the app's download page in the app store and prompted to upgrade. This ensures the user is updated to a version with a valid certificate, ensuring secure communication between the user and the hospital server.
[0136] Through the above application processes and examples in the medical field, it can be seen that this certificate management method can effectively ensure the security, stability and business continuity of hospital information systems, and improve the quality and efficiency of medical services.
[0137] To give another example: in the financial sector, certificate management is crucial. Financial institutions' information systems (such as online banking, mobile payment systems, and securities trading systems) rely heavily on certificates to ensure data transmission security, system identity authentication, and the trustworthiness of transaction processes. For example, SSL certificates, TLS certificates, and iOS packaged certificates are used to encrypt communications between users and bank servers, preventing data theft or tampering. Digital certificates are used to verify the identities of financial institutions and users, ensuring the authenticity and legitimacy of transactions.
[0138] Read the certificate information in the system:
[0139] Accessing the database: The financial institution's IT department accesses the database storing certificates through a dedicated certificate management platform. This database may be deployed in the financial institution's core data center and utilize a high-availability and security architecture, such as master-slave replication and data encryption.
[0140] Collect basic information: Collect all basic information related to the certificate in the database, including the certificate's serial number, issuing authority, issuance time, expiration date, and the system or business module to which it belongs. This information is then aggregated into an information set. For example, for an online banking system's SSL certificate, TLS certificate, or iOS packaged certificate, detailed information is collected and added to the information set.
[0141] Format Parsing: Perform format parsing on the collected information set. Because different certificate issuing authorities may use different certificate format standards (such as the X.509 standard), the certificate management platform needs to be able to identify and parse these formats, extracting key parsing features such as the certificate's subject field (including information such as the financial institution name and department), public key information, and extension fields (such as certificate purpose and key usage).
[0142] Get certificate information: Read the certificate-related data from the parsed features to obtain complete certificate information, including the certificate's validity period, scope of use, key length and other details.
[0143] Determine whether the time from certificate expiration in the certificate information is less than the set threshold:
[0144] Obtaining time information: The certificate management platform obtains the current system time and extracts the expiration date of each certificate. For example, an SSL certificate / TLS certificate / iOS packaged certificate used for communication between a securities trading system and a clearing house may expire on June 30, 2025.
[0145] Calculate the remaining validity period: Calculate the remaining validity period of each certificate based on the current time and the certificate expiration date. If the current time is May 1, 2025, the remaining validity period of the certificate is 60 days.
[0146] Set a time threshold: Based on the financial institution's business needs and certificate management practices, set a time threshold. For example, if a financial institution stipulates that for certificates for critical business systems (such as securities trading systems), an alert must be issued 45 days in advance, then the threshold is set at 45 days.
[0147] Compare remaining validity period to threshold: Compares the remaining validity period of each certificate to the set threshold. For the certificate in the example above, the remaining validity period of 60 days is greater than the set threshold of 45 days, so no alarm is triggered. However, when the time passes to May 16, 2025, the remaining validity period will reach 45 days, equal to the set threshold, and the alarm mechanism will be triggered.
[0148] If the time from certificate expiration to expiration in the certificate information is less than the set threshold, an alarm message will be issued:
[0149] Identify alert recipients: Based on the certificate type and usage scenario, determine who should receive the alert. For SSL / TLS / iOS packaged certificates used in securities trading systems, alert recipients may include the financial institution's IT operations team, network security team, trading operations department, and risk management department.
[0150] Prepare the content of the alert message: Prepare the content of the alert message based on the specific information of the certificate and the responsibilities of the alert recipient. The alert message should include the certificate name, the system to which it belongs, the expiration date, the remaining validity period, the possible impact on the business (such as the possibility of the securities trading system being unable to communicate securely with the clearing center, affecting the settlement and clearing of transactions, and even leading to customer complaints and regulatory risks), and the recommended follow-up action (such as immediately contacting the certificate authority to apply for a new certificate).
[0151] Send alert information: Send alert information to the corresponding alert recipients via the selected alert method. For example, a detailed alert report can be sent via email to members of the IT operations and network security teams, while a brief alert notification can be sent to the heads of relevant business departments via SMS and enterprise instant messaging tools (such as DingTalk).
[0152] Continuously monitor the status of all certificates in the system:
[0153] Establish a monitoring mechanism: The IT department of a financial institution should establish a 24 / 7 certificate monitoring mechanism and regularly (e.g., hourly) scan the status of all certificates in the system. The scan includes information on certificate validity (whether it has been revoked), remaining validity period, and key strength.
[0154] Integrated Certificate Status Checking Service: Verify the status of certificates in real time by integrating Certificate Revocation List (CRL) or Online Certificate Status Protocol (OCSP) checking services. For example, when a digital certificate is scanned, OCSP is used to check whether the certificate is still valid. If the certificate has been revoked, the relevant information is immediately recorded and the exception handling process is triggered.
[0155] Logging and Auditing: Detailed logs are kept for each scan, including scan time, number of scanned certificates, number of certificate status anomalies found, and specific anomaly information. Regular log audits are conducted to analyze trends in certificate status and provide a basis for optimizing certificate management strategies.
[0156] Take follow-up measures based on the warning information:
[0157] Assessing business impact and determining urgency: Upon receiving an alert regarding impending certificate expiration, financial institutions organize cross-departmental meetings, inviting relevant personnel from business units, security teams, and compliance departments, to assess the impact of the certificate expiration on the business. For SSL / TLS certificates / iOS packaged certificates used in securities trading systems, the urgency level is assessed as "extremely high" due to their involvement in the settlement and clearing of a large number of securities transactions.
[0158] Initiate the certificate renewal process: Based on the level of urgency, the certificate renewal process is initiated immediately. IT operations personnel contact the certificate authority (CA) and submit a certificate renewal application, providing relevant financial institution information and supporting documents, such as business licenses and financial permits. Upon approval by the CA, a new certificate will be issued.
[0159] Deploy the new certificate and update the system configuration: Deploy the new certificate to the financial institution's information system and update the system configuration to use the new certificate. For example, install a new SSL certificate / TLS certificate / iOS packaged certificate on the securities trading system server and modify the server configuration file to ensure that the system can properly recognize and use the new certificate for secure communication. At the same time, update the relevant client software (such as online banking clients, securities trading terminals, etc.) to support verification of the new certificate.
[0160] Management of user APP certificates (taking the bank's mobile payment APP as an example):
[0161] Leverage tracking information to obtain real-time user app version information: A tracking code is set up in the bank's mobile payment app. When a user opens the app, the tracking code collects app version information (such as version number, installation time, and device model) and sends it to the bank's backend server. The backend server then collects and analyzes the distribution of user app versions in real time, for example, counting the percentage of users using different app versions.
[0162] Detecting certificate expiration and sending upgrade reminders: The backend server detects whether the certificate included in the app version used by the user is about to expire. For example, a certain app version uses an expiring SSL certificate / TLS certificate / iOS packaged certificate for secure communication with a bank server. When this is detected, the system sends an upgrade reminder to the user via an in-app notification or push message, informing the user that the certificate in the current app version is about to expire, which may affect their ability to use mobile payment functions (such as being unable to transfer money, make payments, etc.), and guiding the user to upgrade.
[0163] Forced upgrade measures: For users who have not upgraded within a set period (e.g., 5 days), the system will implement a forced upgrade. When the user opens the app again, some functions will be restricted, such as only being able to view account balances but not conduct transactions, until the user has upgraded. Alternatively, the user will be directed to the app's download page in the app store and be guided through the upgrade process, ensuring that the user is updated to the app version containing a valid certificate, ensuring secure communication between the user and the bank's server.
[0164] Through the above application processes and examples in the financial field, it can be seen that this certificate management method can effectively ensure the security, stability and business continuity of financial institutions' information systems, reduce the security risks and business interruption risks caused by certificate issues, and improve the service quality and customer satisfaction of financial institutions.
[0165] The above-mentioned certificate management method realizes accurate monitoring of the certificate validity period by reading the certificate information in the system and judging in real time whether the certificate expiration time is less than the preset threshold. Once the certificate is found to be about to expire, the system will immediately issue an alarm message to remind the operation and maintenance personnel to replace the certificate in time. This precise monitoring and timely alarm mechanism effectively avoids service interruption or data security risks caused by certificate expiration, and ensures the continuity and stability of application services.
[0166] In addition, by automatically reading certificate information, determining expiration dates, and issuing alarm messages, the workload of operation and maintenance personnel in certificate management is significantly reduced. Operation and maintenance personnel no longer need to manually check the expiration date of each certificate, nor do they need to worry about certificate expiration due to negligence. This automated management method not only reduces operating labor costs, but also improves operation and maintenance efficiency, allowing operation and maintenance personnel to devote more energy to other critical tasks.
[0167] Furthermore, by reducing the risks associated with manual operations, the probability of abnormal events is effectively reduced. Manual operations are often error-prone, and even minor missteps in certificate management can lead to serious consequences. This technology eliminates human interference through automated and intelligent management, improving the accuracy and reliability of certificate management. This enhanced stability not only reduces service interruptions and data security risks caused by certificate issues, but also increases user trust and satisfaction with application services.
[0168] Figure 3 FIG is a schematic block diagram of a certificate management device 300 provided by an embodiment of the present invention. Figure 3 As shown, corresponding to the above certificate management method, the present invention also provides a certificate management device 300. The certificate management device 300 includes a unit for executing the above certificate management method, and the device can be configured in a server. Figure 3 The certificate management device 300 includes a reading unit 301, a judgment unit 302 and an alarm unit 303.
[0169] Reading unit 301, used to read the certificate information in the system;
[0170] The judging unit 302 is used to judge whether the time from certificate expiration in the certificate information is less than a set threshold;
[0171] The alarm unit 303 is configured to issue an alarm message if the time to certificate expiration in the certificate information is less than a set threshold.
[0172] In one embodiment, the reading unit 301 includes:
[0173] Access module, used to access the database where the system stores certificates;
[0174] A collection module is used to collect all basic information related to the certificate in the database to obtain an information set;
[0175] The parsing module is used to parse the format of the information set to obtain parsing features;
[0176] The reading module is used to read the data related to the certificate in the parsing feature to obtain the certificate information.
[0177] In one embodiment, the determining unit 302 includes:
[0178] Get the extraction module, used to obtain the current time and extract the expiration time of each certificate in the certificate information;
[0179] A calculation module, used to calculate the remaining validity period of each certificate based on the current time and the expiration time of the certificate;
[0180] The setting module is used to set a time threshold based on business needs and certificate management practices, i.e., setting the threshold;
[0181] The comparison module is used to compare the remaining validity period of each certificate with a set threshold.
[0182] In one embodiment, the alarm unit 303 includes:
[0183] A determination module is used to determine the objects that need to receive the alarm information based on the type and usage scenario of the certificate;
[0184] The preparation module is used to prepare the content of the alarm information according to the specific information of the certificate and the responsibilities of the alarm object to obtain the alarm information;
[0185] The sending module is used to send the alarm information to the corresponding alarm object through the selected alarm method.
[0186] In one embodiment, the apparatus further comprises:
[0187] The monitoring unit 304 is used to continuously monitor the status of all certificates in the system.
[0188] In one embodiment, the apparatus further comprises:
[0189] An evaluation and determination unit, configured to evaluate the business impact based on the certificate expiration date provided in the alarm information to determine the urgency of certificate renewal;
[0190] A starting unit, used to start the certificate renewal process according to the urgency to obtain a new certificate;
[0191] Deployment update unit, used to deploy the new certificate to the system and update the system configuration to use the new certificate.
[0192] In one embodiment, the apparatus further comprises:
[0193] The running unit is used to obtain the version status of the user's APP in real time by using the tracking information during the online operation of the system. If it is detected that the certificate contained in the APP version used by the user is about to expire, the system will send an upgrade reminder to the user through in-app notification or push message. For users who fail to upgrade within the set time, the system will take forced upgrade measures to ensure that the user can update to the APP version containing a valid certificate.
[0194] It should be noted that those skilled in the art can clearly understand that the specific implementation process of the above-mentioned certificate management device 300 and each unit can refer to the corresponding description in the aforementioned method embodiment. For the convenience and brevity of the description, it will not be repeated here.
[0195] The certificate management device 300 can be implemented in the form of a computer program. Figure 4 Runs on the computer device shown.
[0196] See also Figure 4 , Figure 4 1 is a schematic block diagram of a computer device provided in an embodiment of the present application. The computer device 500 may be a server, wherein the server may be an independent server or a server cluster composed of multiple servers.
[0197] See Figure 4 The computer device 500 includes a processor 502 , a memory, and a network interface 505 connected via a system bus 501 , wherein the memory may include a non-volatile storage medium 503 and an internal memory 504 .
[0198] The non-volatile storage medium 503 may store an operating system 5031 and a computer program 5032. The computer program 5032 includes program instructions, which, when executed, may enable the processor 502 to execute a certificate management method.
[0199] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.
[0200] The internal memory 504 provides an environment for the operation of the computer program 5032 in the non-volatile storage medium 503. When the computer program 5032 is executed by the processor 502, the processor 502 can execute a certificate management method.
[0201] The network interface 505 is used to communicate with other devices through the network. Figure 4 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present application, and does not constitute a limitation on the computer device 500 to which the solution of the present application is applied. The specific computer device 500 may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0202] The processor 502 is configured to execute a computer program 5032 stored in the memory to implement the following steps:
[0203] Read the certificate information in the system; determine whether the time from certificate expiration in the certificate information is less than the set threshold; if the time from certificate expiration in the certificate information is less than the set threshold, issue an alarm.
[0204] It should be understood that in the embodiment of the present application, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0205] Those skilled in the art will appreciate that all or part of the steps in the method of the above-described embodiment can be implemented by instructing the relevant hardware through a computer program. The computer program includes program instructions, which can be stored in a storage medium that is computer-readable. The program instructions are executed by at least one processor in the computer system to implement the steps in the method of the above-described embodiment.
[0206] Therefore, the present invention also provides a storage medium. The storage medium may be a computer-readable storage medium. The storage medium stores a computer program, wherein when the computer program is executed by a processor, the processor performs the following steps:
[0207] Read the certificate information in the system; determine whether the time from certificate expiration in the certificate information is less than the set threshold; if the time from certificate expiration in the certificate information is less than the set threshold, issue an alarm.
[0208] The storage medium may be any computer-readable storage medium that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disk.
[0209] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0210] In the several embodiments provided herein, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of various units is merely a logical functional division; actual implementations may employ other divisions. For example, multiple units or components may be combined or integrated into another system, or some features may be omitted or not implemented.
[0211] The steps in the methods of the embodiments of the present invention may be adjusted in order, combined, or deleted as needed. The units in the devices of the embodiments of the present invention may be combined, divided, or deleted as needed. Furthermore, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit.
[0212] If this integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the existing technology, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, terminal, or network device, etc.) to execute all or part of the steps of the method described in various embodiments of the present invention.
[0213] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and such modifications or substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.
Claims
1. A certificate management method, characterized in that: include: Read the certificate information in the system; Determine whether the time from certificate expiration in the certificate information is less than the set threshold; If the time from certificate expiration to certificate expiration in the certificate information is less than the set threshold, an alarm message will be issued.
2. The certificate management method according to claim 1, characterized in that: The certificate information in the reading system includes: Access the database where the system stores certificates; Collecting all basic information related to the certificate in a database to obtain an information set; Perform format parsing on the information set to obtain parsing features; Read the certificate-related data in the parsed features to obtain the certificate information.
3. The certificate management method according to claim 1, wherein: The step of determining whether the time from certificate expiration in the certificate information is less than a set threshold includes: Get the current time and extract the expiration time of each certificate in the certificate information; Calculate the remaining validity period of each certificate based on the current time and the expiration time of the certificate; According to business needs and certificate management practices, set a time threshold, that is, set a threshold; The remaining validity period of each certificate is compared to a set threshold.
4. The certificate management method according to claim 1, wherein: If the time from certificate expiration in the certificate information is less than the set threshold, an alarm message is issued, including: Determine the recipients of alerts based on the certificate type and usage scenario. Prepare the content of the alarm information according to the specific information of the certificate and the responsibilities of the alarm object to obtain the alarm information; Send the alarm information to the corresponding alarm object through the selected alarm method.
5. The certificate management method according to claim 1, wherein: After determining whether the time from certificate expiration in the certificate information is less than a set threshold, the method further includes: Continuously monitor the status of all certificates within the system.
6. The certificate management method according to claim 1, wherein: After the warning information is issued, the method further includes: Assess the business impact based on the certificate expiration date provided in the alert information to determine the urgency of certificate renewal. Initiate the certificate renewal process based on the urgency to obtain a new certificate; Deploy the new certificate to the system and update the system configuration to use the new certificate.
7. The certificate management method according to claim 1, wherein: After the warning information is issued, the method further includes: During the online operation of the system, the system uses the embedded information to obtain the version status of the user's APP in real time; if it is detected that the certificate contained in the APP version used by the user is about to expire, the system will send an upgrade reminder to the user through in-app notification or push message. For users who fail to upgrade within the set time, the system will take forced upgrade measures to ensure that the user can update to the APP version containing a valid certificate.
8. A certificate management device, characterized in that: include: A reading unit, used to read the certificate information in the system; A judgment unit, used to judge whether the time from certificate expiration in the certificate information is less than a set threshold; The alarm unit is used to issue an alarm message if the time to certificate expiration in the certificate information is less than a set threshold.
9. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the method according to any one of claims 1 to 7 when executing the computer program.
10. A storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Digital certificate expiration risk monitoring and evaluating method, system and device based on large model
CN120896691A
Certificate updating method and device, equipment, storage medium and program product
CN121036952A
Metering data processing method and device, storage medium and electronic equipment
CN121118939A
A method and system for automated certificate management and dynamic threshold early warning
CN122578338A