DDS Security certificate secure creation and deployment method

Through the combination of CMS and TEE, DDS identity certificates and private keys are generated and securely stored, which solves the risk of private key leakage, simplifies the configuration and deployment process, and realizes safe and efficient certificate management and rapid updates.

CN120785654AActive Publication Date: 2025-10-14AUTOCORE INTELLIGENT TECH (NANJING) CO LTD

Patent Information

Application Number
CN202511285699.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-10
Publication Date
2025-10-14
Estimated Expiration
2045-09-10

AI Technical Summary

Technical Problem

In the prior art, there is a risk of private key leakage when the DDS Security certificate and private key are carried when the application package is released or manually imported after deployment. The deployment process is cumbersome and error-prone, and the solution of CN111031012B loses the versatility of DDS.

Method used

Use the certificate management service CMS and trusted execution environment TEE to generate RSA public and private keys through TEE, create and issue certificates, and securely store private keys in TEE. Use the application package manager APM to parse configuration information to initiate certificate creation requests, construct certificate information, and implement secure certificate creation and deployment. Use the certificate reuse mechanism to avoid repeated creation.

Benefits of technology

It implements secure storage and use of DDS identity certificates and private keys, simplifies the configuration and deployment process, improves deployment efficiency, prevents private key leakage, and binds access control to application identity to prevent the abuse of permission files and support rapid application updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785654A_ABST
    Figure CN120785654A_ABST
Patent Text Reader

Abstract

The invention discloses a DDS Security certificate secure creation and deployment method, which comprises the following steps of: initializing a certificate management service (CMS), establishing a secure channel with a trusted execution environment (TEE), and loading a preset DDS identity CA root certificate from the TEE; an application package manager APM analyzes the application configuration information, carries an application identity ID, and initiates a certificate creation request to a CMS; the CMS constructs certificate information, and sends a certificate creation request carrying the certificate information and an application identity (ID) to the trusted execution environment; public and private keys are generated in the TEE, a certificate is created and signed, and the created application identity certificate is returned to the CMS; the certificate management service verifies and stores the certificate, and returns an identity certificate and a CA root certificate to the APM; and the APM installs the identity certificate to a specified folder of the application installation directory. According to the invention, the establishment and deployment of the identity certificate are realized based on the CMS and the TEE, the certificate management process is simplified, and the deployment efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a DDS security mechanism, and in particular to a method for securely creating and deploying a DDS Security certificate. Background Art

[0002] With the development of intelligent connected vehicles, data communication security between in-vehicle systems is becoming increasingly important. As a key communication middleware, DDS (Data Distribution Service)'s security mechanism (as defined in the DDSSecurity specification proposed by OMG) relies primarily on identity certificates for authentication.

[0003] If an application uses DDS Security and includes the certificate and private key when publishing the application package, there is a risk of private key leakage, which is extremely dangerous. If the certificate and private key are deployed manually after deployment, there is also a risk of private key leakage, which is very cumbersome and prone to errors.

[0004] CN111031012B proposes managing digital certificates through an authentication file microservice. Through configuration information, the certificate file is downloaded from the microservice to a specified directory. However, each node can only have one set of certificates and uses the UserDataQosPolicy field in DDS, which loses the versatility of DDS.

[0005] To solve the above problems, a secure, flexible, and controllable solution is needed to deploy DDS Security's digital certificates / private keys. Summary of the Invention

[0006] To address the deficiencies in the prior art, the present invention provides a method for securely creating and deploying a DDS Security certificate.

[0007] To achieve the purpose of the present invention, the technical solution adopted by the present invention is: A method for securely creating and deploying a DDS Security certificate, comprising the following steps: (1) The certificate management service CMS is initialized, a secure channel is established with the trusted execution environment TEE, and the preset DDS identity CA root certificate is loaded from the TEE; (2) The application package manager APM parses the application configuration information, carries the application identity ID, and initiates a certificate creation request to the CMS; (3) The certificate management service CMS constructs the certificate information and sends the certificate creation request and application identity ID carrying the certificate information to the trusted execution environment TEE; (4) Generate RSA public and private keys in the trusted execution environment TEE, create and issue certificates, and return the created application identity certificate to the CMS; (5) The certificate management service CMS verifies and stores the certificate, and returns the identity certificate and CA root certificate to APM; (6) The application package manager APM installs the identity certificate and CA root certificate to the specified folder of the application installation directory.

[0008] Furthermore, in step (2), specifically, the access / UnifiedAccess.json configuration file is parsed, the security.dds.enable field is detected to be "on", the security.dds.ID field is extracted as the application identity, a certificate creation request including the application identity ID is constructed, and the CMS interface is called to initiate the certificate creation request.

[0009] Furthermore, in step (3), the certificate management service CMS constructs the certificate information specifically including: generating a unique certificate serial number, constructing the certificate subject information, wherein the CN field is set to the application identity ID, setting the certificate validity period and signature algorithm, and setting the certificate extension information.

[0010] Furthermore, in step (4), specifically, a dedicated asymmetric public-private key pair is generated for the application identity ID in the TEE, and the generated private key is bound to the application identity ID and stored in the TEE; the public key is embedded in the certificate structure, a certificate is created based on the certificate information, the certificate is signed using the preset CA private key, and the created application identity certificate is returned to the CMS.

[0011] Furthermore, in step (6), specifically, the generated identity certificate is stored in the conf / dds / directory and named identity_app.pem; the identity CA root certificate is stored in the conf / dds / directory and named identity_ca.pem; APM sets the access rights of the certificate file so that it is readable only by the application process.

[0012] Furthermore, after the application is installed and deployed, the application identity certificate, DDS permission file, and private key are associated with the application identity ID: Identity certificate binding: In conf / dds / identity_cert.pem, the certificate CN = application identity ID; Permission file binding: In conf / dds / permissions.p7s, the subject information CN = application identity ID; Private key access binding: Access through application identity ID.

[0013] Furthermore, when the application with the same application identity ID is updated or reinstalled, the system adopts a certificate reuse mechanism, specifically, The application package manager (APM) parses the UnifiedAccess.json configuration file of the new version of the application, extracts the application identity ID, and sends a certificate creation request to the certificate management service (CMS). The CMS queries the local certificate to check whether the corresponding identity certificate exists. If the local certificate exists, it checks the validity of the certificate and whether the corresponding private key binding relationship exists in the TEE. If so, the TEE certificate generation and private key creation steps are skipped. The CMS directly sends the existing application identity certificate and CA root certificate content to the APM. The APM copies the certificate to the corresponding directory and sets access permissions.

[0014] A DDS Security certificate security creation and deployment system, including an application package manager (APM), a certificate management service (CMS), and a trusted execution environment (TEE); Application Package Manager (APM), responsible for parsing application configuration information and initiating certificate creation requests; Certificate Management Service (CMS), responsible for certificate information construction and management, with built-in access control module; Trusted Execution Environment TEE, responsible for private key generation and certificate signing.

[0015] The beneficial effect of the present invention is that, compared with the existing technology, the present invention realizes the creation and deployment of DDS identity certificates / private keys based on CMS and TEE, simplifies the configuration and deployment process of the application, simplifies the certificate management process, and improves deployment efficiency.

[0016] Based on the flexibility and security functions of TEE, the present invention ensures the secure storage and use of private keys in TEE, provides a safer way to use keys, and effectively solves the problem of leakage of applied DDS identity certificates and private keys during dissemination, deployment and use.

[0017] This invention implements access control by binding the application ID to the application permission file and the application identity certificate by binding the application identity ID to the private key, and prevents the abuse of the permission file. The invention also uses a certificate reuse mechanism to avoid duplicate creation when updating applications, enabling rapid deployment. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 This is a flow chart of the DDS Security certificate secure creation and deployment method described in the present invention; Figure 2 This is a diagram of the DDS Security identity authentication process. DETAILED DESCRIPTION

[0019] The technical solution of the present invention will be further described below in conjunction with the accompanying drawings and embodiments. The following embodiments are only used to more clearly illustrate the technical solution of the present invention and are not intended to limit the scope of protection of this application.

[0020] The DDS Security certificate security creation and deployment system described in the present invention mainly includes the following components: application package manager APM, certificate management service CMS, trusted execution environment TEE; Application Package Manager (APM), responsible for parsing application configuration information and initiating certificate creation requests; Certificate Management Service (CMS), responsible for certificate information construction and management, with built-in access control module; Trusted Execution Environment TEE, responsible for private key generation and certificate signing.

[0021] like Figure 1 As shown, the method for securely creating and deploying a DDS Security certificate according to the present invention includes the following steps: 1. The certificate management service CMS is initialized; The system will preset the DDS identity CA root certificate and private key in the trusted execution environment (TEE) to issue the application's identity certificate to implement OMG DDS Security identity authentication.

[0022] When the certificate management service CMS is initialized, a secure channel with the TEE is established and the preset DDS identity CA root certificate is loaded from the TEE.

[0023] CMS loads the permission configuration, initializes the access control module, and restricts the application's access to the private key. The permission configuration format is as follows: { "default": "deny", "access_rules": { "allow_list": [ {"7fda6a629a985838bf0caa1e6219b860": { "interval": "1s"}}, {"64d5e4b6d2ecb7ab299fe43466fb63c5": { "interval": "1s"}}, {"1521ec3185c35e445174a55686ebb45b": {"interval": "1s"}} ], "deny_list": [] } The default permission policy is to deny all access requests, allowing only the application identity ID in access_rules.allow_list to access the corresponding private key, and limiting the access interval of the private key.

[0024] 2. The application package manager (APM) initiates a certificate creation request to the CMS. When the application is installed, the application package manager APM will call the CMS interface based on the application configuration information and carry the application's unique application identity ID (AppID) to initiate a certificate creation request.

[0025] Specifically, the access / UnifiedAccess.json configuration file is parsed, the security.dds.enable field is checked to see if it is "on", the security.dds.ID field is extracted as the application identity, and a certificate creation request containing the application identity ID is constructed.

[0026] In access / UnifiedAccess.json, specify the DDS security requirements using the following configuration: { "security": { "dds": { "enable": "on", "ID": "7fda6a629a985838bf0caa1e6219b860" } } } The ID field "7fda6a629a985838bf0caa1e6219b860" is the unique identifier of the application and is used as a key parameter for certificate creation.

[0027] 3. The Certificate Management Service (CMS) constructs the certificate information and sends the certificate creation request application identity ID carrying the certificate information to the Trusted Execution Environment (TEE). The certificate management service CMS constructs certificate information specifically including: generating a unique certificate serial number, constructing certificate subject information, wherein the CN field is set to the application identity ID, setting the certificate validity period and signature algorithm, and setting certificate extension information.

[0028] The certificate structure is designed based on the application identity ID. The certificate adopts the X.509 v3 standard and is constructed in combination with the application configuration information. The specific fields are as follows: 1. Basic Information Version number: X.509 v3 Serial number: generated based on the hash value of the application ID "7fda6a629a985838bf0caa1e6219b860" Signature algorithm: RSA-SHA256 Issuer: Pre-set DDS identity CA root certificate 2. Subject Information CN (Common Name): Application ID "7fda6a629a985838bf0caa1e6219b860" O (Organization): The same organization name as the CA root certificate OU (Organizational Unit): DDS application type identifier C (Country): The same country code as the CA root certificate 3. Extensions Basic Constraints: CA=FALSE, indicating an end-entity certificate Key Usage: Digital Signature: used for DDS message signature Key Encipherment: used for key exchange 4. Generate RSA public and private keys in the trusted execution environment (TEE), issue a certificate, and return the created application identity certificate to the CMS; Generate a 2048-bit RSA key pair for the application identity in the TEE, including a public key and a private key. Bind the generated private key to the application identity ID and store it in the TEE. Embed the public key in the certificate structure, create a certificate based on the certificate information, sign the certificate using the preset CA private key, and return the created application identity certificate to the CMS.

[0029] 5. CMS verifies the legitimacy of the certificate and stores it, and returns the identity certificate and CA root certificate to APM; The CMS establishes a mapping relationship between the application identity ID and the application certificate / private key, stores it in the internal permission database, and generates access control rules for the application, limiting the certificate / private key to be accessible only to the bound application.

[0030] 6. APM installs the identity certificate and CA root certificate to the specified folder in the application installation directory; APM stores the generated identity certificate in the conf / dds / directory and names it identity_app.pem. APM stores the identity CA root certificate in the conf / dds / directory and names it identity_ca.pem. APM sets the access permissions for the certificate file so that it is readable only by the application process.

[0031] The application installation directory uses a standardized structure and contains the following key directories and files: app_install_dir / ├── access / │ └── UnifiedAccess.json # Application permission configuration information ├── bin / │ └── app_run # Application executable file ├── conf / │ ├── app.json # Basic application configuration │ └── dds / # DDS security configuration directory │ ├── governance.p7s # DDS Security permissions configuration file │ ├── perm_ca.pem # DDS Security authority CA certificate │ └── permissions.p7s # DDS Security permissions configuration file └── lib / └── libapp.so # application library file The conf / dds directory exists only when DDS Security is enabled for your application. After creating the certificate, the APM module deploys the application identity certificate to the conf / dds directory.

[0032] When creating the conf / dds / permissions.p7s file, the application ID is written as the CN field in the subject information. Binding permissions.p7s to the application ID is completed during application development and packaging, not dynamically during installation. The permissions file contents are fixed during application packaging. Any tampering with the permissions file will cause DDSSecurity to fail to load.

[0033] After the application is installed and deployed, the following associations are established between the application ID, application certificate, DDS permission file, and private key: Identity certificate binding: In conf / dds / identity_cert.pem, the certificate CN = application identity ID; Permission file binding: In conf / dds / permissions.p7s, the subject information CN = application identity ID; Private key access binding: Access through application identity ID.

[0034] When the application with the same application identity ID "7fda6a629a985838bf0caa1e6219b860" is updated or reinstalled, the system uses a certificate reuse mechanism to avoid repeated creation of certificates and private keys.

[0035] 1. Application update detection; APM parses the UnifiedAccess.json configuration file of the new version of the application, extracts the application identity ID, and sends a certificate creation request to the CMS.

[0036] 2. Certificate existence verification; The CMS queries the local certificate to check whether the corresponding identity certificate exists. If the local certificate exists, it checks the validity of the certificate and whether the corresponding private key binding relationship exists in the TEE.

[0037] 3. Direct reuse of certificates; Skip the TEE certificate generation and private key creation steps. CMS directly sends the existing application identity certificate and CA root certificate content to APM. APM copies the certificates to the corresponding directory and sets access permissions.

[0038] The identity authentication process of OMG DDS Security requires the use of private key signature data to prove identity. The private key signature process is as follows Figure 2 As shown: The application starts the DDS Security plug-in to verify the consistency between the subject information in the permission file and the subject information in the application identity certificate. If they are inconsistent, the application process is terminated. When DDS session negotiation requires calculating a message signature, the application identity ID is carried in the CMS interface to request a private key signature operation. CMS extracts the application identity in the request, verifies the application identity through the access control module, and determines whether it has permission to access the corresponding private key: If the application permission is valid, CMS calls the TEE Clinet API, and TEE generates a signature for the application and returns it to CMS. CMS then returns it to DDS, and DDS continues the session negotiation after receiving it; if the permission is invalid, CMS returns a signature failure message, and DDS ends the session negotiation.

[0039] The beneficial effect of the present invention is that, compared with the existing technology, the present invention realizes the creation and deployment of DDS identity certificates / private keys based on CMS and TEE, simplifies the configuration and deployment process of the application, simplifies the certificate management process, and improves deployment efficiency.

[0040] Based on the flexibility and security functions of TEE, the present invention ensures the secure storage and use of private keys in TEE, provides a safer way to use keys, and effectively solves the problem of leakage of applied DDS identity certificates and private keys during dissemination, deployment and use.

[0041] This invention implements access control by binding the application ID to the application permission file and the application identity certificate by binding the application identity ID to the private key, and prevents the abuse of the permission file. The invention also uses a certificate reuse mechanism to avoid duplicate creation when updating applications, enabling rapid deployment.

[0042] The applicant of the present invention has made a detailed explanation and description of the implementation examples of the present invention in conjunction with the drawings in the specification. However, those skilled in the art should understand that the above implementation examples are only preferred implementation plans of the present invention, and the detailed description is only to help readers better understand the spirit of the present invention, and is not a limitation on the scope of protection of the present invention. On the contrary, any improvements or modifications based on the inventive spirit of the present invention should fall within the scope of protection of the present invention.

Claims

1. A method for securely creating and deploying a DDS Security certificate, characterized in that: Including steps: (1) The certificate management service CMS is initialized, a secure channel is established with the trusted execution environment TEE, and the preset DDS identity CA root certificate is loaded from the TEE; (2) The application package manager APM parses the application configuration information, carries the application identity ID, and initiates a certificate creation request to the CMS; (3) The certificate management service CMS constructs the certificate information and sends the certificate creation request and application identity ID carrying the certificate information to the trusted execution environment TEE; (4) Generate RSA public and private keys in the trusted execution environment TEE, create and issue certificates, and return the created application identity certificate to the CMS; (5) The certificate management service CMS verifies and stores the certificate, and returns the identity certificate and CA root certificate to APM; (6) The application package manager APM installs the identity certificate and CA root certificate to the specified folder of the application installation directory.

2. The DDS Security certificate secure creation and deployment method according to claim 1, wherein: In step (2), specifically, parse the access / UnifiedAccess.json configuration file, check whether the security.dds.enable field is "on", extract the security.dds.ID field as the application identity, construct a certificate creation request containing the application identity ID, call the CMS interface, and initiate the certificate creation request.

3. The DDS Security certificate secure creation and deployment method according to claim 1, wherein: In step (3), the certificate management service CMS constructs the certificate information, specifically including: generating a unique certificate serial number, constructing the certificate subject information, wherein the CN field is set to the application identity ID, setting the certificate validity period and signature algorithm, and setting the certificate extension information.

4. The DDS Security certificate secure creation and deployment method according to claim 1, wherein: In step (4), specifically, a dedicated asymmetric public-private key pair is generated for the application identity ID in the TEE, and the generated private key is bound to the application identity ID and stored in the TEE; Embed the public key into the certificate structure, create a certificate based on the certificate information, sign the certificate using the preset CA private key, and return the created application identity certificate to the CMS.

5. The DDS Security certificate secure creation and deployment method according to claim 1, wherein: In step (6), specifically, the generated identity certificate is stored in the conf / dds / directory and named identity_app.pem; the identity CA root certificate is stored in the conf / dds / directory and named identity_ca.pem; APM sets the access rights of the certificate file so that it is readable only by the application process.

6. The DDS Security certificate secure creation and deployment method according to claim 1, wherein: After the application is installed and deployed, the application identity certificate, DDS permission file, and private key are associated with the application identity ID: Identity certificate binding: In conf / dds / identity_cert.pem, the certificate CN = application identity ID; Permission file binding: In conf / dds / permissions.p7s, the subject information CN = application identity ID; Private key access binding: Access through application identity ID.

7. The DDS Security certificate secure creation and deployment method according to claim 1, wherein: When the application with the same application identity ID is updated or reinstalled, the system adopts the certificate reuse mechanism, specifically, The application package manager (APM) parses the UnifiedAccess.json configuration file of the new version of the application, extracts the application identity ID, and sends a certificate creation request to the certificate management service (CMS). The CMS queries the local certificate to check whether the corresponding identity certificate exists. If the local certificate exists, it checks the validity of the certificate and whether the corresponding private key binding relationship exists in the TEE. If so, the TEE certificate generation and private key creation steps are skipped. The CMS directly sends the existing application identity certificate and CA root certificate content to the APM. The APM copies the certificate to the corresponding directory and sets access permissions.

8. A DDS Security certificate secure creation and deployment system, used to implement the DDS Security certificate secure creation and deployment method according to any one of claims 1 to 7, characterized in that: Including application package manager APM, certificate management service CMS, and trusted execution environment TEE; Application Package Manager (APM), responsible for parsing application configuration information and initiating certificate creation requests; Certificate Management Service (CMS), responsible for certificate information construction and management, with built-in access control module; Trusted Execution Environment TEE, responsible for private key generation and certificate signing.

Citation Information

Patent Citations

  • A method for secure authentication of DDS domain participants

    CN111031012B

  • Certificate issuing method based on blockchain network, related equipment and medium

    CN111597537A

  • DDS access control, encryption and decryption system and method based on KP-ABE

    CN115051839A

  • Key-free DDS security authentication and communication method based on OP-TEE

    CN117254916A

  • OP-TEE-based vehicle-mounted certificate local management system and method

    CN118018215A

Cited By

  • Vehicle-mounted certificate centralized management and automatic signing and issuing system and method

    CN121792254A