Certificate update method, device, system, server and computer storage medium

By establishing a certificate update system between the server and the client, and automatically obtaining and encrypting the target certificate data, the problem of App certificate update relies on user manual upgrades is solved, and automatic security update of certificates is realized, avoiding usage barriers and saving update costs.

CN111694591BActive Publication Date: 2025-05-16WEBANK (CHINA)
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010552078.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-06-16
Publication Date
2025-05-16
Estimated Expiration
2040-06-16

AI Technical Summary

Technical Problem

In the prior art, App certificate updates rely on users to manually upgrade the App version, resulting in the certificate being unable to be updated, affecting the normal use of users, and may cause word-of-mouth damage to the business.

Method used

A certificate update method is designed. By establishing a certificate update system between the server and the client, after receiving the certificate update request, the server obtains the current certificate information, obtains the target certificate data from the preset database, encrypts the target information through the signature algorithm, generates the encrypted target certificate data, and returns it to the client. After the verification is passed, the client updates the certificate.

Benefits of technology

Automatic security update of application certificates is realized, avoiding the problem of not updating the certificates due to not updating the application, ensuring that users use them normally, and saving update costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111694591B_ABST
    Figure CN111694591B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of financial technology, and discloses a certificate update method, device, system, server, and computer storage medium. The certificate update method is applied to a certificate update system including a server and a client, and the method includes: when the server receives a certificate update request, it obtains the current certificate information according to the certificate update request; then obtains the target certificate data from a preset database; encrypts the target information in the target certificate data by a preset signature algorithm to obtain the signature information, and obtains the encrypted target certificate data according to the target information and the signature information, and then returns it to the client corresponding to the certificate update request, so that the client can update the certificate after verifying the encrypted target certificate data. The certificate update system constructed based on the present invention can realize the automatic update of the application certificate, and at the same time, encrypt the certificate data for verifying the security of the certificate data, thereby realizing the secure update of the certificate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of financial technology (Fintech), and in particular to a certificate updating method, device, system, server and computer storage medium. Background Art

[0002] With the development of computer technology, more and more technologies are being applied in the financial field. The traditional financial industry is gradually transforming into financial technology (Fintech). However, due to the security and real-time requirements of the financial industry, higher requirements are also placed on technology.

[0003] Users usually install various apps on terminal devices such as mobile phones or tablets to meet various needs in daily work, life, social interaction, etc. At present, the corresponding App certificates are generally hard-coded into the App's internal code or internal configuration files, so that when the App is started, the App is used by reading the App's hard-coded certificate information to ensure the security of the App.

[0004] However, App certificates have a validity period. Currently, the updated App certificates are usually built into the new version of the App. When users upgrade the App version, they can obtain the updated App certificate at the same time as the new version of the App, thus ensuring the normal use of the App. However, many users often do not like to update the App version, which results in the inability to update the certificate, affecting the user's normal product needs and even causing serious reputational damage to the business. Therefore, how to achieve intelligent update of App certificates is an urgent problem to be solved. Summary of the invention

[0005] The main purpose of the present invention is to provide a certificate updating method, device, system, server and computer storage medium, aiming to realize automatic and secure updating of application certificates to avoid affecting user use.

[0006] To achieve the above object, the present invention provides a certificate update method, which is applied to a certificate update system. The certificate update system includes a server and a client. The certificate update method includes:

[0007] When receiving the certificate update request, the server obtains the current certificate information according to the certificate update request;

[0008] Acquire target certificate data from a preset database according to the current certificate information;

[0009] Encrypting the target information in the target certificate data by using a preset signature algorithm to obtain signature information, and obtaining the encrypted target certificate data according to the target information and the signature information;

[0010] The encrypted target certificate data is returned to the client corresponding to the certificate update request, so that the client can update the certificate after verifying the encrypted target certificate data.

[0011] Optionally, the current certificate information includes an application name and a current certificate version number, and the step of acquiring target certificate data from a preset database according to the current certificate information includes:

[0012] Query the preset certificate list to obtain the latest certificate version number corresponding to the application name;

[0013] Determine whether the current certificate version number is consistent with the latest certificate version number;

[0014] If they are inconsistent, the target certificate data corresponding to the application name and the latest certificate version number is obtained from a preset database.

[0015] Optionally, the certificate updating method further includes:

[0016] When receiving a certificate change request, obtaining change information according to the certificate change request;

[0017] The corresponding certificate data is updated according to the change information, and the latest certificate version number of the corresponding application in the preset certificate list is updated.

[0018] Optionally, the step of encrypting the target information in the target certificate data by using a preset signature algorithm to obtain signature information, and obtaining the encrypted target certificate data according to the target information and the signature information includes:

[0019] Obtaining the public key information of the target certificate data, and signing the public key information using a preset signature algorithm and a preset encryption private key to generate certificate signature information;

[0020] The encrypted target certificate data is obtained according to the public key information and the certificate signature information.

[0021] Optionally, before the step of obtaining the encrypted target certificate data according to the public key information and the certificate signature information, the step further includes:

[0022] Obtaining the validity identifier of the target certificate data, and signing the validity identifier using the preset signature algorithm and the preset encryption private key to generate validity signature information;

[0023] The step of obtaining the encrypted target certificate data according to the public key information and the certificate signature information comprises:

[0024] The encrypted target certificate data is obtained according to the public key information, the certificate signature information, the validity identifier and the validity signature information.

[0025] Optionally, the certificate updating method further includes:

[0026] Regularly obtain the expiration time of each certificate data in the preset database, and calculate the remaining validity period according to the expiration time and current time;

[0027] The business party corresponding to the certificate data that is about to expire is reminded according to the remaining validity period.

[0028] In addition, to achieve the above object, the present invention also provides a certificate updating device, the certificate updating device comprising:

[0029] A first acquisition module, configured to acquire current certificate information according to the certificate update request when receiving the certificate update request;

[0030] A second acquisition module, used to acquire target certificate data from a preset database according to the current certificate information;

[0031] An encryption module, used to encrypt the target information in the target certificate data by using a preset signature algorithm to obtain signature information, and obtain the encrypted target certificate data according to the target information and the signature information;

[0032] The first updating module is used to return the encrypted target certificate data to the client corresponding to the certificate update request, so that the client can update the certificate after verifying the encrypted target certificate data.

[0033] In addition, to achieve the above-mentioned purpose, the present invention also provides a server, which includes: a memory, a processor, and a certificate update program stored in the memory and executable on the processor, and the certificate update program implements the steps of the certificate update method described above when executed by the processor.

[0034] In addition, to achieve the above-mentioned purpose, the present invention also provides a certificate update system, the certificate update system comprising: a server and a client; wherein,

[0035] The server is the server described above;

[0036] The client is used to obtain current certificate information according to the application startup information when the application startup information is detected;

[0037] Generate a certificate update request according to the current certificate information and send it to the server;

[0038] The client is also used to receive the encrypted target certificate data returned by the server;

[0039] The encrypted target certificate data is verified, and the certificate is updated when the verification passes.

[0040] Optionally, the client is further used for:

[0041] When receiving the encrypted target certificate data returned by the server, parsing the encrypted target certificate data to obtain public key information and certificate signature information;

[0042] Verifying the public key information and the certificate signature information by using a preset verification algorithm to obtain a first bit value;

[0043] It is determined whether the first bit value is a preset threshold value to determine whether the encrypted target certificate data has been tampered with.

[0044] Optionally, the client is further used for:

[0045] Parsing the encrypted target certificate data to obtain validity identification and validity signature information;

[0046] Verifying the validity identifier and the validity signature information by using the preset verification algorithm to obtain a second bit value;

[0047] It is determined whether the second bit value is the preset threshold value to determine the validity of the certificate data.

[0048] In addition, to achieve the above-mentioned purpose, the present invention further provides a computer-readable storage medium, on which a certificate update program is stored, and when the certificate update program is executed by a processor, the steps of the certificate update method described above are implemented.

[0049] The present invention provides a certificate update method, device, system, server and computer storage medium. The certificate update method is applied to a certificate update system. The certificate update system includes a server and a client. When the server receives a certificate update request, it obtains the current certificate information according to the certificate update request; then, it obtains the target certificate data from a preset database according to the current certificate information; the target information in the target certificate data is encrypted by a preset signature algorithm to obtain the signature information, and the encrypted target certificate data is obtained according to the target information and the signature information; and then the encrypted target certificate data is returned to the client corresponding to the certificate update request, so that the client can update the certificate after verifying the encrypted target certificate data. By constructing a certificate update system, when a certificate update request sent by a client when starting an application is received, the corresponding target certificate data can be automatically obtained, and returned to the client after encryption, so that the client can update the certificate after verifying the encrypted certificate data, thereby realizing the automatic update of the application certificate, avoiding the failure to update the certificate due to the failure to update the application, which affects the use of the user. At the same time, the server encrypts the certificate data for the client to verify the security of the certificate data, and the certificate data can be updated only when the verification is passed, thereby realizing the secure update of the certificate. In addition, the present invention does not require the business party to push users to upgrade and update, thereby saving update costs. Therefore, the present invention can realize automatic and secure update of application certificates, avoid affecting user use, and save update costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 A schematic diagram of the terminal structure of the hardware operating environment involved in the embodiment of the present invention;

[0051] Figure 2 This is a flow chart of a first embodiment of a certificate updating method of the present invention;

[0052] Figure 3 A schematic diagram of the system architecture involved in the certificate updating method of the present invention;

[0053] Figure 4 FIG. 1 is a schematic diagram of functional modules of a first embodiment of a certificate updating device according to the present invention.

[0054] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0055] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.

[0056] Reference Figure 1 , Figure 1 The figure is a schematic diagram of the terminal structure of the hardware operating environment involved in the embodiment of the present invention.

[0057] The terminal in the embodiment of the present invention is a server, which may be a server, or a terminal device such as a PC (Personal Computer), a tablet computer, or a portable computer.

[0058] like Figure 1 As shown, the terminal may include: a processor 1001, such as a CPU, a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the optional user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a Wi-Fi interface). The memory 1005 may be a high-speed RAM memory, or it may be a stable memory (non-volatile memory), such as a disk memory. The memory 1005 may also be a storage device independent of the aforementioned processor 1001.

[0059] Those skilled in the art will understand that Figure 1 The terminal structure shown in the figure does not constitute a limitation on the terminal, and may include more or less components than shown in the figure, or combine certain components, or arrange the components differently.

[0060] like Figure 1 As shown, the memory 1005 as a computer storage medium may include an operating system, a network communication module, and a certificate update program.

[0061] exist Figure 1 In the terminal shown, the network interface 1004 is mainly used to connect to the background server and communicate data with the background server; the user interface 1003 is mainly used to connect to the client and communicate data with the client; and the processor 1001 can be used to call the certificate update program stored in the memory 1005 and execute the various steps of the following certificate update method.

[0062] Based on the above hardware structure, various embodiments of the certificate updating method of the present invention are proposed.

[0063] The invention provides a certificate updating method.

[0064] Reference Figure 2 , Figure 2 FIG. 1 is a flow chart of a first embodiment of a certificate updating method according to the present invention.

[0065] In this embodiment, the certificate update method is applied to a certificate update system, the certificate update system includes a server and a client, and the certificate update method includes:

[0066] Step S10, when the server receives the certificate update request, the server obtains the current certificate information according to the certificate update request;

[0067] The certificate update method of this embodiment is applied to a certificate update system, which includes a server and a client. A certificate maintenance system and a certificate update channel system are established on the server. The certificate maintenance system is used to maintain and update a large number of certificates in the system, and the certificate update channel system is an important service serving the client. It is a channel to ensure that the certificate data is updated to the client. Through this service, each certificate maintained in the certificate maintenance system can be sent to the specified client according to appropriate logic.

[0068] Furthermore, it should be noted that, in specific implementation, the certificate update system can also be built as a distributed network architecture to meet the concurrent execution of massive certificate update requests. Figure 3 , multiple Nginx (proxy servers) and multiple servers can be set up, and the certificate update request can be assigned to the corresponding Nginx according to the domain name of the client's certificate update request. Then Nginx can poll the server to obtain the corresponding certificate data and then return it to the client. This distributed certificate update system can immediately perform parallel expansion when the system encounters too many requests. It is scalable and reliable. The system crash of one server does not affect the other servers.

[0069] The certificate update method of this embodiment is implemented by the server, and the device is described by taking the server as an example. In this embodiment, when the client starts an application (such as an App, software), it sends a certificate update request to the server through the update channel. At this time, when the server receives the certificate update request, it obtains the current certificate information according to the certificate update request. Among them, the current certificate information includes the application name and the current certificate version number.

[0070] Step S20, obtaining target certificate data from a preset database according to the current certificate information;

[0071] Then, the target certificate data is obtained from the preset database according to the current certificate information.

[0072] The current certificate information includes the application name and the current certificate version number, and step S20 includes:

[0073] Step a21, querying a preset certificate list to obtain the latest certificate version number corresponding to the application name;

[0074] Step a22, determining whether the current certificate version number is consistent with the latest certificate version number;

[0075] Step a23: If they are inconsistent, obtain target certificate data corresponding to the application name and the latest certificate version number from a preset database.

[0076] After obtaining the current certificate information, query the preset certificate list to obtain the latest certificate version number corresponding to the application name, where the preset certificate list at least includes the names of each application and its latest certificate version number. Then, determine whether the current certificate version number is consistent with the latest certificate version number; if not, obtain the target certificate data corresponding to the application name and the latest certificate version number from the preset database. If they are consistent, there is no need to update the certificate and no response is required. It should be noted that the target certificate data may include one or more certificates, which can be maintained and updated according to actual conditions.

[0077] Step S30, encrypting the target information in the target certificate data by using a preset signature algorithm to obtain signature information, and obtaining the encrypted target certificate data according to the target information and the signature information.

[0078] Then, the target information in the target certificate data is encrypted by a preset signature algorithm to obtain signature information, and the encrypted target certificate data is obtained according to the target information and signature information. The preset signature algorithm may optionally be an α←Sign(SK,M) signature algorithm, the target information includes at least public key information and may also include a validity identifier, and correspondingly, the signature information includes at least certificate signature information and may also include validity signature information.

[0079] When encrypting, the target information and the preset encryption private key (the private key of the server) are used as input, and the signature information can be output through the preset signature algorithm. Then, the target information and the signature information can be edited according to a preset format to obtain the encrypted target certificate data, such as each line can include the target information of a certificate and its signature information, thereby forming a structure of multiple lines. The specific encryption process can refer to the third embodiment described below.

[0080] Step S40: Return the encrypted target certificate data to the client corresponding to the certificate update request, so that the client can update the certificate after verifying the encrypted target certificate data.

[0081] After obtaining the encrypted target certificate data, the encrypted target certificate data is returned to the client corresponding to the certificate update request, so that the client can update the certificate after verifying the encrypted target certificate data.

[0082] Correspondingly, when the client receives the encrypted target certificate data returned by the server, it can parse the encrypted target certificate data to obtain the target information and signature information. When the target information only includes the public key information, the signature information only includes the certificate signature information. At this time, the public key information and the certificate signature information can be verified by a preset verification algorithm (corresponding to the preset signature algorithm, the preset verification algorithm is β←Verify(PK,α,M) verification algorithm) to obtain a first bit value; and then by judging whether the first bit value is a preset threshold (1), it is verified whether the encrypted target certificate data has been tampered with. When the target information includes the public key information and the validity identifier, the signature information includes the certificate signature information and the validity signature information. At this time, it is first verified whether the encrypted target certificate data has been tampered with, and then, further, the validity identifier and the validity signature information are verified by the preset verification algorithm to obtain a second bit value. It is judged whether the second bit value is the preset threshold to judge the validity of the certificate data. When the verification is passed, the client will update the certificate.

[0083] It is understandable that if the certificate update system is Figure 3 The distributed certificate update system shown returns the encrypted target certificate data to Nginx corresponding to the certificate update request first, so that Nginx returns the encrypted target certificate data to the client, and then the client verifies the encrypted target certificate data and performs certificate update.

[0084] The embodiment of the present invention provides a certificate update method, which is applied to a certificate update system. The certificate update system includes a server and a client. When the server receives a certificate update request, it obtains the current certificate information according to the certificate update request; then, it obtains the target certificate data from a preset database according to the current certificate information; the target information in the target certificate data is encrypted by a preset signature algorithm to obtain the signature information, and the encrypted target certificate data is obtained according to the target information and the signature information; and then the encrypted target certificate data is returned to the client corresponding to the certificate update request, so that the client can update the certificate after verifying the encrypted target certificate data. By constructing a certificate update system, when the certificate update request sent by the client when starting the application is received, the corresponding target certificate data can be automatically obtained, and returned to the client after encryption, so that the client can update the certificate after verifying the encrypted certificate data, thereby realizing the automatic update of the application certificate, avoiding the failure to update the certificate due to the failure to update the application, which affects the use of the user. At the same time, the server encrypts the certificate data for the client to verify the security of the certificate data, and the certificate data can be updated only when the verification is passed, thereby realizing the secure update of the certificate. In addition, the embodiment of the present invention does not require the business party to push the user to upgrade and update, thereby saving the update cost. Therefore, the embodiment of the present invention can realize the automatic and safe update of the application certificate, avoid affecting the use of the user, and save the update cost.

[0085] Furthermore, based on the above first embodiment, a second embodiment of the certificate updating method of the present invention is proposed.

[0086] In this embodiment, the certificate updating method further includes:

[0087] Step A, upon receiving a certificate change request, obtaining change information according to the certificate change request;

[0088] In this embodiment, when a certificate change request is received, change information is obtained according to the certificate change request. The change information includes the name of the application to be changed and the change content, and the change content may include but is not limited to the replacement of the certificate and the update of the certificate identifier, such as the update of the certificate validity identifier (the validity of the certificate will be updated when it is abnormal).

[0089] Step B: updating the corresponding certificate data according to the change information, and updating the latest certificate version number of the corresponding application in the preset certificate list.

[0090] Then, the corresponding certificate data is updated according to the change information, for example, a certificate in the certificate data is replaced, or the validity of the certificate is updated. At the same time, in order to facilitate the subsequent determination of whether the certificate version number of the application is the latest certificate version number, so as to determine whether to update, the latest certificate version number of the corresponding application in the preset certificate list needs to be updated. In other words, whenever the certificate data is updated, the latest certificate version number of the corresponding application needs to be updated.

[0091] In this embodiment, the certificate maintenance system implements the updating and maintenance of the certificate data, so as to facilitate the subsequent updating of the certificate data of the client.

[0092] Furthermore, based on the above first embodiment, a third embodiment of the certificate updating method of the present invention is proposed.

[0093] In this embodiment, step S30 includes:

[0094] Step a31, obtaining the public key information of the target certificate data, and signing the public key information using a preset signature algorithm and a preset encryption private key to generate certificate signature information;

[0095] In order to ensure that the updated certificate data is absolutely correct and prevent the target certificate data from being maliciously hijacked by a middleman during transmission, resulting in the certificate update being maliciously exploited, in this embodiment, the target certificate data is encrypted and then sent to the client, so that the client can verify the encrypted target certificate data to determine that the target certificate data has not been tampered with and used by the party, thereby ensuring the security of the certificate update.

[0096] In this embodiment, the public key information of the target certificate data is first obtained, and the public key information is signed by a preset signature algorithm and a preset encryption private key to generate certificate signature information. Among them, the target certificate data may include one or more certificates, and the corresponding public key information may include one or more; the preset signature algorithm may optionally be an α←Sign(SK,M) signature algorithm, and the preset encryption private key is the private key of the server, denoted as SK. When the public key information includes one, it is denoted as M, and the corresponding certificate signature information also includes one. The private key SK and the public key information M can be used as input, so that the certificate signature information α can be output. When the public key information includes multiple, they are respectively denoted as M1, M2, ..., Mt, and the corresponding certificate signature information also includes multiple. The private key SK and the public key information can be used as input in turn, so that multiple certificate signature information α1, α2, ..., αt can be output.

[0097] Step a32: Obtain encrypted target certificate data according to the public key information and the certificate signature information.

[0098] Then, based on the public key information and the certificate signature information, the encrypted target certificate data is obtained. Specifically, the public key information and the certificate signature information can be edited according to a preset format to obtain the encrypted target certificate data. For example, each line can include the public key information of a certificate and its certificate signature information, thereby forming a structure of multiple lines.

[0099] Then, the encrypted target certificate data is returned to the client corresponding to the certificate update request, so that the client can update the certificate. Specifically, when the client receives the encrypted target certificate data returned by the server, it can parse the encrypted target certificate data to obtain the public key information and the certificate signature information, and then verify the public key information and the certificate signature information through a preset verification algorithm to obtain a first bit value; then, by judging whether the first bit value is a preset threshold, it is judged whether the encrypted target certificate data has been tampered with. When it is judged that the target certificate data has not been tampered with, the certificate is updated.

[0100] Furthermore, before the above step a32, the following steps may also be included:

[0101] Step a33, obtaining the validity identifier of the target certificate data, and signing the validity identifier by using the preset signature algorithm and the preset encryption private key to generate validity signature information;

[0102] At this time, step a32 includes:

[0103] The encrypted target certificate data is obtained according to the public key information, the certificate signature information, the validity identifier and the validity signature information.

[0104] When the application certificate needs to be replaced urgently (for example, the application's built-in certificate information for encryption is leaked due to an accident or hacker attack, which may cause the product's encryption logic to be compromised, affecting user information security), the application cannot quickly update and replace the old certificate, so that before the replacement is completed, a large number of users are at risk of being attacked, thereby causing a major crisis. Therefore, in this embodiment, the validity mark is marked in the certificate, such as valid and invalid (or represented by preset characters), and then when the client starts the application, it can obtain the certificate data after the update mark, and when using the certificate, it will determine whether the certificate is available based on the certificate's validity mark. In this way, the certificate's validity mark can be quickly updated to avoid user use, thereby reducing the risk of being attacked.

[0105] During implementation, in order to ensure that the validity identifier is not tampered with, the validity identifier can be encrypted. The specific encryption method is the same as the encryption method of the above-mentioned certificate public key information. Specifically: first obtain the validity identifier of the target certificate data, and sign the validity identifier through a preset signature algorithm and a preset encryption private key to generate validity signature information. Then, based on the public key information, certificate signature information, validity identifier and validity signature information, obtain the encrypted target certificate data, and then return the encrypted target certificate data to the client corresponding to the certificate update request, so that the client can update the certificate. The encryption process of the validity identifier can refer to the encryption process of the above-mentioned public key information, which will not be repeated here.

[0106] In this embodiment, the public key information and validity identifier of the target certificate data are encrypted and then returned to the client so that the client can verify the encrypted target certificate data to prevent tampering, thereby ensuring the security of the target certificate data.

[0107] In addition, it should be noted that in order to further ensure the security of the link and prevent the risk of attacks such as replacement of the link layer of the certificate update, in the specific implementation, the communication link can use https to encrypt the target certificate data.

[0108] It should also be noted that, in the specific implementation, in order to avoid the pressure of massive certificate update requests on the encryption operation of the server, the server can encrypt based on the updated certificate data when it detects that the certificate data of the application has been updated, and then store the encrypted certificate data in the preset database. After the server obtains the current certificate information according to the certificate update request, it can directly obtain the encrypted target certificate data from the preset database according to the current certificate information, and then return it to the corresponding client. In this way, N* number of encryption operations can be avoided, the delay caused by frequent disk IO operations can be avoided, and millions of simultaneous high-concurrency requests can be met.

[0109] Furthermore, based on the above embodiments, a fourth embodiment of the certificate updating method of the present invention is proposed.

[0110] In this embodiment, the certificate updating method further includes:

[0111] Step C, regularly obtaining the expiration time of each certificate data in the preset database, and calculating the remaining validity period according to the expiration time and the current time;

[0112] In this embodiment, since each certificate has a validity period, in order to avoid certificate expiration, the expiration time of each certificate data in the preset database can be obtained regularly, and the remaining validity period can be calculated based on the expiration time and the current time.

[0113] Step D: reminding the business party corresponding to the certificate data that is about to expire according to the remaining validity period.

[0114] Then, the business party corresponding to the certificate data that is about to expire is reminded according to the remaining validity period. Specifically, when it is detected that the remaining validity period is less than a preset threshold (such as 30 days), it is judged that it is about to expire, and then the corresponding business party is reminded.

[0115] It should be noted that when it is detected that the remaining validity period is a negative value, it proves that the certificate has expired. At this time, the certificate can be directly deleted and the business party can be reminded.

[0116] In this embodiment, the certificate maintenance system detects the certificate data that is about to expire, so that the corresponding business party can be reminded to update the certificate in time.

[0117] The invention also provides a certificate updating system.

[0118] The present invention also provides a certificate updating system, which includes a server and a client.

[0119] The server is the server as described above, and is used to execute the steps in the above-mentioned certificate updating method embodiment. The specific functions and implementation processes can refer to the above-mentioned embodiment and will not be described in detail here.

[0120] The client is used to obtain current certificate information according to the application startup information when the application startup information is detected;

[0121] Generate a certificate update request according to the current certificate information and send it to the server;

[0122] The client is also used to receive the encrypted target certificate data returned by the server;

[0123] The encrypted target certificate data is verified, and the certificate is updated when the verification passes.

[0124] In this embodiment, the client is used to obtain the current certificate information according to the application startup information when detecting the application startup information, wherein the current certificate information includes the application name and the current certificate version number. Then, a certificate update request is generated according to the current certificate information and sent to the server, and then the encrypted target certificate data returned by the server is received, the encrypted target certificate data is verified, and the certificate is updated when the verification passes.

[0125] In this embodiment, by constructing the above-mentioned certificate update system, when the client starts the application, it will trigger a certificate update request, which will then be sent to the server. After the server obtains the corresponding target certificate data from the preset database, it returns it to the client, so that the client automatically updates the certificate. In the above manner, the automatic update of the client application certificate can be achieved, and there is no need to force users to download the latest version of the software program to achieve certificate updates, nor is there a need for the business party to push users to upgrade and update, thereby saving update costs. In addition, the server encrypts the certificate data for the client to verify the security of the certificate data, and the certificate data can only be updated when the verification is passed, thereby achieving a secure update of the certificate.

[0126] Furthermore, the client is also used for:

[0127] When receiving the encrypted target certificate data returned by the server, parsing the encrypted target certificate data to obtain public key information and certificate signature information;

[0128] Verifying the public key information and the certificate signature information by using a preset verification algorithm to obtain a first bit value;

[0129] It is determined whether the first bit value is a preset threshold value to determine whether the encrypted target certificate data has been tampered with.

[0130] In this embodiment, when the client receives the encrypted target certificate data returned by the server, it parses the encrypted target certificate data to obtain the public key information and the certificate signature information; then, the public key information and the certificate signature information are verified by a preset verification algorithm to obtain the first bit value. The preset verification algorithm is the β←Verify(PK,α,M) verification algorithm, which uses the parsed public key information and the certificate signature information, and the public key PK of the server as input to obtain the first bit value.

[0131] Then, it is determined whether the first bit value is a preset threshold value to determine whether the encrypted target certificate data has been tampered with. The preset threshold value can be optionally set to 1. If the first bit value is 1, it is determined that the encrypted target certificate data has not been tampered with. If the first bit value is not 1 but 0, it is determined that the encrypted target certificate data has been tampered with.

[0132] In this embodiment, the client verifies the certificate signature information to prevent tampering, thereby ensuring that the target certificate data is secure and can be used to ensure security.

[0133] Furthermore, the client is also used for:

[0134] Parsing the encrypted target certificate data to obtain validity identification and validity signature information;

[0135] Verifying the validity identifier and the validity signature information by using the preset verification algorithm to obtain a second bit value;

[0136] It is determined whether the second bit value is the preset threshold value to determine the validity of the certificate data.

[0137] In this embodiment, when the client receives the encrypted target certificate data returned by the server, it can also parse the encrypted target certificate data to obtain the validity identification and validity signature information; then, the validity identification and the validity signature information are verified by a preset verification algorithm to obtain a second bit value; that is, the validity identification and the validity signature information and the public key PK of the server are used as input to obtain the second bit value. Then, it is determined whether the second bit value is a preset threshold to determine the validity of the certificate data. If the second bit value is 1, it is determined that the validity of the target certificate data has not been tampered with, so that it can be determined whether to use the certificate based on the validity identification of the target certificate data. If the first bit value is not 1, but 0, it is determined that the validity of the target certificate data has been tampered with, and the certificate is refused to be used.

[0138] In this embodiment, the client verifies the validity signature information to prevent tampering, thereby ensuring that the validity identifier in the target certificate data has not been tampered with, and then determines whether to use the certificate data based on the validity identifier, thereby ensuring security.

[0139] Furthermore, in specific implementation, the certificate update system can also be built as a distributed network architecture to meet the concurrent execution of massive certificate update requests. Figure 3 , multiple Nginx (proxy servers) and multiple servers can be set up, and the certificate update request can be assigned to the corresponding Nginx according to the domain name of the client's certificate update request. Then Nginx can poll the server to obtain the corresponding certificate data and then return it to the client. This distributed certificate update system can immediately perform parallel expansion when the system encounters too many requests. It is scalable and reliable. The system crash of one server does not affect the other servers.

[0140] The invention also provides a certificate updating device.

[0141] Reference Figure 4 , Figure 4 FIG. 1 is a schematic diagram of functional modules of a first embodiment of a certificate updating device according to the present invention.

[0142] like Figure 4 As shown, the certificate updating device includes:

[0143] A first acquisition module 10 is used to acquire current certificate information according to the certificate update request when receiving the certificate update request;

[0144] A second acquisition module 20, configured to acquire target certificate data from a preset database according to the current certificate information;

[0145] The encryption module 30 is used to encrypt the target information in the target certificate data by using a preset signature algorithm to obtain signature information, and obtain the encrypted target certificate data according to the target information and the signature information;

[0146] The first updating module 40 is used to return the encrypted target certificate data to the client corresponding to the certificate update request, so that the client can update the certificate after verifying the encrypted target certificate data.

[0147] Further, the current certificate information includes an application name and a current certificate version number, and the second acquisition module 20 includes:

[0148] A query unit, used to query a preset certificate list to obtain the latest certificate version number corresponding to the application name;

[0149] A judging unit, used to judge whether the current certificate version number is consistent with the latest certificate version number;

[0150] The obtaining unit is configured to obtain target certificate data corresponding to the application name and the latest certificate version number from a preset database if there is inconsistency.

[0151] Furthermore, the certificate updating device further comprises:

[0152] A third acquisition module is used to acquire change information according to the certificate change request when receiving the certificate change request;

[0153] The second updating module is used to update the corresponding certificate data according to the change information, and update the latest certificate version number of the corresponding application in the preset certificate list.

[0154] Furthermore, the encryption module 30 includes:

[0155] A first signature unit is used to obtain the public key information of the target certificate data, and sign the public key information using a preset signature algorithm and a preset encryption private key to generate certificate signature information;

[0156] The data encryption unit is used to obtain encrypted target certificate data according to the public key information and the certificate signature information.

[0157] Furthermore, the encryption module 30 also includes:

[0158] A second signature unit is used to obtain the validity identifier of the target certificate data, and sign the validity identifier through the preset signature algorithm and the preset encryption private key to generate validity signature information;

[0159] The data encryption unit is further used to obtain encrypted target certificate data according to the public key information, the certificate signature information, the validity identifier and the validity signature information.

[0160] Furthermore, the certificate updating device further comprises:

[0161] A fourth acquisition module is used to periodically acquire the expiration time of each certificate data in the preset database, and calculate the remaining validity period according to the expiration time and the current time;

[0162] The reminder module is used to remind the business party corresponding to the certificate data that is about to expire according to the remaining validity period.

[0163] Among them, the functional implementation of each module in the above-mentioned certificate updating device corresponds to each step in the above-mentioned certificate updating method embodiment, and its functions and implementation processes are no longer repeated here.

[0164] The present invention also provides a computer-readable storage medium on which a certificate updating program is stored. When the certificate updating program is executed by a processor, the steps of the certificate updating method described in any of the above embodiments are implemented.

[0165] The specific embodiments of the computer-readable storage medium of the present invention are basically the same as the embodiments of the above-mentioned certificate updating method, and will not be described in detail here.

[0166] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or system including the element.

[0167] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0168] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present invention.

[0169] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A certificate updating method, characterized in that: Applied to a certificate update system, the certificate update system includes a server and a client, and the certificate update method includes: When receiving the certificate update request, the server obtains the current certificate information according to the certificate update request, wherein the current certificate information includes the application name and the current certificate version number, and the certificate update request is sent by the client when starting the application; Query the preset certificate list to obtain the latest certificate version number corresponding to the application name; Determine whether the current certificate version number is consistent with the latest certificate version number; If they are inconsistent, obtaining target certificate data corresponding to the application name and the latest certificate version number from a preset database; Obtaining the public key information of the target certificate data, and signing the public key information using a preset signature algorithm and a preset encryption private key to generate certificate signature information; Obtaining the validity identifier of the target certificate data, and signing the validity identifier using the preset signature algorithm and the preset encryption private key to generate validity signature information; Obtaining encrypted target certificate data according to the public key information, the certificate signature information, the validity identifier and the validity signature information; The encrypted target certificate data is returned to the client corresponding to the certificate update request, so that the client can update the application certificate after verifying the encrypted target certificate data.

2. The certificate updating method according to claim 1, characterized in that: The certificate updating method further includes: When receiving a certificate change request, obtaining change information according to the certificate change request; The corresponding certificate data is updated according to the change information, and the latest certificate version number of the corresponding application in the preset certificate list is updated.

3. The certificate updating method according to any one of claims 1 to 2, characterized in that: The certificate updating method further includes: Regularly obtain the expiration time of each certificate data in the preset database, and calculate the remaining validity period according to the expiration time and current time; The business party corresponding to the certificate data that is about to expire is reminded according to the remaining validity period.

4. A certificate updating device, characterized in that: The certificate updating device comprises: A first acquisition module, configured to acquire current certificate information according to a certificate update request when receiving the certificate update request, wherein the current certificate information includes an application name and a current certificate version number, and the certificate update request is sent by the client when starting the application; A second acquisition module, used to acquire target certificate data from a preset database according to the current certificate information; An encryption module, used to encrypt the target information in the target certificate data by using a preset signature algorithm to obtain signature information, and obtain the encrypted target certificate data according to the target information and the signature information; A first update module, used to return the encrypted target certificate data to the client corresponding to the certificate update request, so that the client can update the application certificate after verifying the encrypted target certificate data; Wherein, the second acquisition module includes: A query unit, used to query a preset certificate list to obtain the latest certificate version number corresponding to the application name; A judging unit, used to judge whether the current certificate version number is consistent with the latest certificate version number; an acquiring unit, configured to acquire target certificate data corresponding to the application name and the latest certificate version number from a preset database if there is inconsistency; The encryption module comprises: A first signature unit is used to obtain the public key information of the target certificate data, and sign the public key information using a preset signature algorithm and a preset encryption private key to generate certificate signature information; A second signature unit is used to obtain the validity identifier of the target certificate data, and sign the validity identifier through the preset signature algorithm and the preset encryption private key to generate validity signature information; The data encryption unit is used to obtain the encrypted target certificate data according to the public key information, the certificate signature information, the validity identifier and the validity signature information.

5. A server, characterized in that: The server includes: a memory, a processor, and a certificate update program stored in the memory and executable on the processor. When the certificate update program is executed by the processor, the steps of the certificate update method according to any one of claims 1 to 3 are implemented.

6. A certificate updating system, characterized in that: The certificate update system includes: a server and a client; wherein, The server is the server as claimed in claim 5; The client is used to obtain current certificate information according to the application startup information when the application startup information is detected; Generate a certificate update request according to the current certificate information and send it to the server; The client is also used to receive the encrypted target certificate data returned by the server; The encrypted target certificate data is verified, and the certificate is updated when the verification passes.

7. The certificate updating system according to claim 6, characterized in that: The client is also used to: When receiving the encrypted target certificate data returned by the server, parsing the encrypted target certificate data to obtain public key information and certificate signature information; Verifying the public key information and the certificate signature information by using a preset verification algorithm to obtain a first bit value; It is determined whether the first bit value is a preset threshold value to determine whether the encrypted target certificate data has been tampered with.

8. The certificate updating system according to claim 7, characterized in that: The client is also used to: Parsing the encrypted target certificate data to obtain validity identification and validity signature information; Verifying the validity identifier and the validity signature information by using the preset verification algorithm to obtain a second bit value; It is determined whether the second bit value is the preset threshold value to determine the validity of the certificate data.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a certificate update program, and when the certificate update program is executed by a processor, the steps of the certificate update method according to any one of claims 1 to 3 are implemented.

Citation Information

Patent Citations

  • Server certificate updating method and device, equipment and computer-readable storage medium

    CN109639661A