Digital Certificate Verification Method, Device, Computer Equipment and Storage Medium

By confirming the cancellation status of the digital certificate in the terminal environment and performing corresponding verification processing, the problem of inefficient verification of digital certificates is solved, and a more efficient verification process is achieved.

CN114238913BActive Publication Date: 2025-06-17SHENZHEN COMTOP INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111335475.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-11
Publication Date
2025-06-17
Estimated Expiration
2041-11-11

AI Technical Summary

Technical Problem

In the case of complex terminal environments, the digital certificate verification process is inconsistent, resulting in low efficiency.

Method used

By responding to the terminal's digital certificate verification request, confirm the cancellation status of the digital certificate, and perform corresponding verification processing based on the status, including update and password verification, and finally return the verification result to the terminal.

Benefits of technology

The efficiency of digital certificate verification is improved. By determining the cancellation status of digital certificates and performing corresponding processing, the verification process is simplified and the performance of the system is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114238913B_ABST
    Figure CN114238913B_ABST
Patent Text Reader

Abstract

The present application relates to a digital certificate verification method, apparatus, computer device, and storage medium. The method includes: in response to a digital certificate verification request sent by a terminal, confirming the revocation status of the digital certificate in the digital certificate verification request; verifying the digital certificate according to the revocation status of the digital certificate to obtain a verification result; and returning the verification result to the terminal. The server of the present application determines the revocation status of the digital certificate by responding to the digital certificate verification request sent by the terminal, performs corresponding verification according to different revocation statuses, obtains the verification result and returns it to the terminal; that is, the server can perform corresponding processing on the digital certificate according to the revocation status of the digital certificate to obtain the verification result, thereby improving the efficiency of digital certificate verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technologies, and particularly to a digital certificate verification method, apparatus, computer device, and storage medium. Background Art

[0002] A digital certificate refers to a digital authentication that marks the identity information of all parties in Internet communication. People can use it to identify the identity of the other party on the Internet. The digital certificate ensures the integrity and security of information and data in the form of encryption or decryption for information and data of network users in computer network communication.

[0003] However, due to the complexity of the terminal environment, such as the influence of various operating systems, various firewall software, various Internet browser plugins, etc., the processes for digital certificate verification are different, resulting in a relatively low efficiency of digital certificate verification on the terminal; therefore, a high-efficiency digital certificate verification method is still needed. Summary of the Invention

[0004] Based on this, it is necessary to provide a digital certificate verification method, apparatus, computer device, and storage medium for the above technical problems.

[0005] A digital certificate verification method includes:

[0006] In response to a digital certificate verification request sent by a terminal, confirm the revocation status of the digital certificate in the digital certificate verification request;

[0007] Verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result;

[0008] Return the verification result to the terminal.

[0009] In one embodiment, the confirming the revocation status of the digital certificate in the digital certificate verification request includes:

[0010] According to the certificate identifier carried by the digital certificate, look up the revocation status information matching the certificate identifier in a preset certificate revocation status table; the preset certificate revocation status table contains the corresponding relationships between multiple certificate identifiers and revocation status information;

[0011] Determine the revocation status of the digital certificate according to the revocation status information; the revocation status includes revoked and not revoked.

[0012] In one embodiment, the verifying the digital certificate according to the revocation status of the digital certificate to obtain a verification result includes:

[0013] If the revocation status of the digital certificate is revoked, retrieve the corresponding data from the preset database according to the certificate identifier to obtain the updated digital certificate;

[0014] Perform a password verification on the updated digital certificate, and use the password verification result as the verification result of the updated digital certificate.

[0015] In one embodiment, the retrieving the corresponding data from the preset database according to the certificate identifier to obtain the updated digital certificate includes:

[0016] Obtain the private key that matches the certificate identifier;

[0017] Encrypt the digital certificate according to the private key to obtain the updated digital certificate containing the certificate version number and serial number.

[0018] In one embodiment, the verifying the digital certificate according to the revocation status of the digital certificate to obtain the verification result includes:

[0019] If the revocation status of the digital certificate is not revoked, perform a password verification on the digital certificate, and use the password verification result as the verification result of the digital certificate.

[0020] In one embodiment, the performing a password verification on the updated digital certificate includes:

[0021] Obtain the public key that matches the certificate identifier;

[0022] Determine the matching degree between the private key and the public key of the updated digital certificate;

[0023] If the matching degree is greater than or equal to the preset matching threshold and the serial number of the public key is the same as the serial number of the private key, generate a password verification result indicating that the password verification has passed.

[0024] In one embodiment, after returning the verification result to the terminal, it further includes:

[0025] Determine the operation authority matching the terminal according to the verification result.

[0026] A digital certificate verification device, the device includes:

[0027] A request response module, configured to respond to a digital certificate verification request sent by a terminal and confirm the revocation status of the digital certificate in the digital certificate verification request;

[0028] A certificate verification module, configured to verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result;

[0029] A result return module for returning the verification result to the terminal.

[0030] A computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0031] In response to a digital certificate verification request sent by a terminal, confirm the revocation status of the digital certificate in the digital certificate verification request;

[0032] Verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result;

[0033] Return the verification result to the terminal.

[0034] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0035] In response to a digital certificate verification request sent by a terminal, confirm the revocation status of the digital certificate in the digital certificate verification request;

[0036] Verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result;

[0037] Return the verification result to the terminal.

[0038] The above digital certificate verification method, device, computer device and storage medium, the method includes: in response to a digital certificate verification request sent by a terminal, confirm the revocation status of the digital certificate in the digital certificate verification request; verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result; return the verification result to the terminal. In this application, the server determines the revocation status of the digital certificate by responding to the digital certificate verification request sent by the terminal, performs corresponding verification according to the different revocation statuses, obtains the verification result and returns it to the terminal; that is, the server can perform corresponding processing on the digital certificate according to the revocation status of the digital certificate to obtain the verification result, thereby improving the efficiency of digital certificate verification. Description of the Drawings

[0039] Figure 1 It is an application environment diagram of the digital certificate verification method in an embodiment;

[0040] Figure 2 It is a flow chart of the digital certificate verification method in an embodiment;

[0041] Figure 3 It is a flow chart of the step of confirming the revocation status of the digital certificate in the digital certificate verification request in an embodiment;

[0042] Figure 4 A flowchart showing the process of verifying a digital certificate based on the revocation status of the digital certificate in an embodiment;

[0043] Figure 5 A flowchart showing the process of a digital certificate verification method in another embodiment;

[0044] Figure 6 A structural block diagram of a digital certificate verification device in an embodiment;

[0045] Figure 7 An internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0046] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0047] The digital certificate verification method provided by the present application can be applied to, for example, Figure 1 the application environment shown in the figure. Among them, the terminal 11 communicates with the server 12 through a network. The server 12 responds to the digital certificate verification request sent by the terminal 11, and confirms the revocation status of the digital certificate in the digital certificate verification request; the server 12 verifies the digital certificate according to the revocation status of the digital certificate to obtain a verification result; the server 12 returns the verification result to the terminal 11. Among them, the terminal 11 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices, and the server 12 can be implemented by an independent server or a server cluster composed of multiple servers.

[0048] In one embodiment, as Figure 2 shown in the figure, a digital certificate verification method is provided. Taking the method applied to Figure 1 the server 12 in the figure as an example, the method includes the following steps:

[0049] Step 21, in response to the digital certificate verification request sent by the terminal, confirm the revocation status of the digital certificate in the digital certificate verification request.

[0050] Among them, a digital certificate refers to a digital authentication that marks the identity information of all parties in Internet communication. People can use it to identify the identity of the other party on the Internet. Therefore, a digital certificate is also a kind of digital identifier. A digital certificate is an authoritative electronic document that provides a way to verify identity on the Internet. Its function is similar to a driver's license or an ID card in daily life. The digital certificate ensures the integrity and security of information and data in the form of encryption or decryption for network users in computer network communication.

[0051] Usually, when a portable device such as a USB Key accesses a terminal device, the USB Key stores digital certificates issued by a third-party digital certificate certification authority (CA, Certificate Authority) or a bank CA certification authority to the customer. Through the signature function of the digital certificate, it is possible to authenticate the identity and encrypt and protect the transaction information of the customer and the online bank. For example, when a user goes through the procedures to open an online bank account at a bank counter, they can first obtain a blank USB Key (i.e., a USB Key without a stored digital certificate), and then send a request to the server through the terminal, so that they can log in to the online bank and download the digital certificate to the USB Key for storage by themselves, thereby improving the security of the portable device.

[0052] The revocation status is an available state of a digital certificate, which determines the availability of the digital certificate; for example, the validity period of a digital certificate is one year. After the expiration of the validity period, the digital certificate is in an invalid state, and at the same time, the digital certificate is automatically revoked.

[0053] Specifically, the user performs corresponding operations on the terminal, and this operation step needs to interact and verify with the data stored in the server; that is, the terminal generates a corresponding digital certificate verification request according to the user's operation and sends it to the server; after receiving the digital certificate verification request sent by the terminal, the server judges the survival status of the digital certificate verification request, that is, the revocation status; the server judges the digital certificate in the digital certificate verification request. If the digital certificate has been revoked, it is determined that the digital certificate is in a revoked state and is currently unavailable; if the digital certificate has not been revoked, it is determined that the digital certificate is in an unrevoked state, and the digital certificate verification request can be directly responded to according to the digital certificate.

[0054] Step 22: Verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result.

[0055] Specifically, the server selects a corresponding verification method to verify the digital certificate according to the revocation status of the digital certificate, and obtains a corresponding verification result. The process of verifying the digital certificate also includes the process of judging the recoverable status of the digital certificate; for example, although the digital certificate is in a revoked state, it still has verification effectiveness, then the server can attempt to restore the digital certificate to an unrevoked state within the scope of its verification effectiveness, that is, to update the digital certificate.

[0056] Step 23, return the verification result to the terminal.

[0057] Specifically, after the server verifies the digital certificate, it obtains a corresponding verification result; the server returns the verification result to the terminal to remind the terminal to perform subsequent operations. The verification result includes various states such as verification passed, verification failed, and in the process of verification. The terminal can know the processing status of the digital certificate verification request through the verification result. The server can also determine the operable permissions of the terminal according to the verification result.

[0058] The above digital certificate verification method, device, computer device, and storage medium, the method includes: in response to a digital certificate verification request sent by a terminal, confirm the revocation status of the digital certificate in the digital certificate verification request; according to the revocation status of the digital certificate, verify the digital certificate to obtain a verification result; return the verification result to the terminal. The server of the present application determines the revocation status of the digital certificate by responding to the digital certificate verification request sent by the terminal, performs corresponding verification according to different revocation statuses, obtains the verification result and returns it to the terminal; that is, the server can perform corresponding processing on the digital certificate according to the revocation status of the digital certificate to obtain the verification result, thereby improving the efficiency of digital certificate verification.

[0059] In one embodiment, as Figure 3 shown, step 21, confirming the revocation status of the digital certificate in the digital certificate verification request includes:

[0060] Step 31, according to the certificate identifier carried by the digital certificate, look up the revocation status information matching the certificate identifier in the preset certificate revocation status table; the preset certificate revocation status table contains the corresponding relationships between multiple certificate identifiers and revocation status information;

[0061] Step 32, determine the revocation status of the digital certificate according to the revocation status information; the revocation status includes revoked and not revoked.

[0062] Among them, when the validity period or validity of a certain digital certificate exceeds the valid range, the server or other servers will apply for cancellation of the expired digital certificate; after the cancellation application is approved, the current status of the digital certificate will be modified / added in the preset certificate cancellation status table. The preset certificate cancellation status table can be implemented throughout the network in the form of a blockchain to ensure data unity.

[0063] Specifically, each registered digital certificate carries a unique certificate identifier; the server uses this certificate identifier to query in the preset certificate cancellation status table to obtain the current latest cancellation status information of the digital certificate; if the cancellation status information shows that the digital certificate has been added with a cancelled identifier, it is determined that the cancellation status of the digital certificate is cancelled; if the cancellation status information shows that the digital certificate has not been added with a cancelled identifier and all parameters of the digital certificate are within the valid range, it is determined that the cancellation status of the digital certificate is not cancelled.

[0064] In this embodiment, the server searches for the cancellation status information matching the certificate identifier from the preset certificate cancellation status table through the certificate identifier carried by the digital certificate, realizing the judgment of the cancellation status of the digital certificate and improving the efficiency of digital certificate verification.

[0065] In one embodiment, as Figure 4 shown, step 22, verify the digital certificate according to the cancellation status of the digital certificate to obtain a verification result, including:

[0066] Step 41, if the cancellation status of the digital certificate is cancelled, retrieve the corresponding data from the preset database according to the certificate identifier to obtain the updated digital certificate;

[0067] Step 42, perform password verification on the updated digital certificate, and use the password verification result as the verification result of the updated digital certificate.

[0068] Specifically, if the server detects that the cancellation status of the digital certificate is cancelled, it retrieves the corresponding data matching the certificate identifier from the preset database to update the digital certificate to obtain the updated digital certificate; after the update is completed, password verification is performed to judge the password availability of the digital certificate, and the password verification result is used as the verification result of the updated digital certificate.

[0069] In this embodiment, the server updates the digital certificate without having to regenerate the digital certificate, reducing the steps of digital certificate verification and improving the efficiency of digital certificate verification.

[0070] In one embodiment, retrieving corresponding data from a preset database according to a certificate identifier to obtain an updated digital certificate includes: obtaining a personal key that matches the certificate identifier; encrypting the digital certificate with the personal key to obtain an updated digital certificate containing a certificate version number and a serial number.

[0071] Specifically, after the server encrypts the digital certificate with the personal key, it simultaneously confirms the certificate version number and the serial number in the updated digital certificate, so that the digital certificate has valid and definite verification information while being valid.

[0072] In this embodiment, the server encrypts the digital certificate with the personal key to verify the digital certificate, improving the efficiency of digital certificate verification.

[0073] In one embodiment, verifying a digital certificate according to the revocation status of the digital certificate to obtain a verification result includes: if the revocation status of the digital certificate is not revoked, performing a password verification on the digital certificate and using the password verification result as the verification result of the digital certificate.

[0074] In this embodiment, when the server detects that the revocation status of the digital certificate is not revoked, it directly performs a password verification on the digital certificate and uses the password verification result as the verification result of the digital certificate, improving the efficiency of digital certificate verification.

[0075] In one embodiment, performing a password verification on the updated digital certificate includes: obtaining a public key that matches the certificate identifier; determining the matching degree between the personal key of the updated digital certificate and the public key; if the matching degree is greater than or equal to a preset matching threshold and the serial number of the public key is the same as the serial number of the personal key, generating a password verification result indicating that the password verification has passed.

[0076] In this embodiment, by determining the matching degree between the personal key and the public key of the updated digital certificate and judging the consistency between the serial number of the public key and the serial number of the personal key, an accurate legality judgment of the personal key can be made, and a password verification result indicating that the password verification has passed can be generated, improving the efficiency of digital certificate verification.

[0077] In one embodiment, after returning the verification result to the terminal, it further includes: determining an operation permission matching the terminal according to the verification result.

[0078] Specifically, the server assigns different operation permissions to the terminal according to different verification results; for example, when the verification result is not passed, only some basic operations are allowed for the terminal, such as logging in and logging out, but data interaction with the terminal may not be allowed to ensure the security of the data in the server.

[0079] In this embodiment, the security of the data is improved through the operation permission matching the terminal.

[0080] In one embodiment, as Figure 5 shown, another digital certificate verification method is provided, including:

[0081] Step 51, in response to a digital certificate verification request sent by a terminal; according to the certificate identifier carried by the digital certificate, look up the cancellation status information matching the certificate identifier from a preset certificate cancellation status table; the preset certificate cancellation status table contains the corresponding relationships between multiple certificate identifiers and cancellation status information; determine the cancellation status of the digital certificate according to the cancellation status information; the cancellation status includes cancelled and not cancelled.

[0082] Step 52, if the cancellation status of the digital certificate is cancelled, obtain the private key matching the certificate identifier; encrypt the digital certificate according to the private key to obtain an updated digital certificate containing the certificate version number and serial number.

[0083] Step 53, obtain the public key matching the certificate identifier; determine the matching degree between the private key and the public key of the updated digital certificate; if the matching degree is greater than or equal to a preset matching threshold and the serial number of the public key is the same as the serial number of the private key, generate a password verification result indicating that the password verification has passed, and use the password verification result as the verification result of the updated digital certificate.

[0084] Step 54, determine the operation permission matching the terminal according to the verification result.

[0085] Step 55, return the verification result to the terminal.

[0086] It should be understood that although Figures 2 - 5 the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, Figures 2 - 5 at least a part of the steps in

[0087] In one embodiment, as Figure 6 shown, a digital certificate verification device is provided, including: a request response module 61, a certificate verification module 62, and a result return module 63, where:

[0088] A request response module 61, configured to confirm the revocation status of a digital certificate in a digital certificate verification request in response to a digital certificate verification request sent by a terminal;

[0089] A certificate verification module 62, configured to verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result;

[0090] A result return module 63, configured to return the verification result to the terminal.

[0091] In one embodiment, the request response module 61 is further configured to, according to the certificate identifier carried by the digital certificate, look up the revocation status information matching the certificate identifier in a preset certificate revocation status table; the preset certificate revocation status table contains the corresponding relationships between multiple certificate identifiers and revocation status information; determine the revocation status of the digital certificate according to the revocation status information; the revocation status includes revoked and not revoked.

[0092] In one embodiment, the certificate verification module 62 is further configured to, if the revocation status of the digital certificate is revoked, retrieve corresponding data from a preset database according to the certificate identifier to obtain an updated digital certificate; perform a password verification on the updated digital certificate, and use the password verification result as the verification result of the updated digital certificate.

[0093] In one embodiment, the certificate verification module 62 is further configured to obtain a private key matching the certificate identifier; encrypt the digital certificate according to the private key to obtain an updated digital certificate including a certificate version number and a serial number.

[0094] In one embodiment, the certificate verification module 62 is further configured to, if the revocation status of the digital certificate is not revoked, perform a password verification on the digital certificate, and use the password verification result as the verification result of the digital certificate.

[0095] In one embodiment, the certificate verification module 62 is further configured to obtain a public key matching the certificate identifier; determine the matching degree between the private key and the public key of the updated digital certificate; if the matching degree is greater than or equal to a preset matching threshold and the serial number of the public key is the same as the serial number of the private key, generate a password verification result indicating that the password verification has passed.

[0096] In one embodiment, the result return module 63 is further configured to determine the operation permission matching the terminal according to the verification result.

[0097] For the specific limitations of the digital certificate verification device, reference can be made to the limitations of the digital certificate verification method in the foregoing text, which will not be elaborated here. Each module in the above digital certificate verification device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in the form of hardware or be independent of it, or be stored in the memory of the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.

[0098] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 7 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store digital certificate verification data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a digital certificate verification method.

[0099] Those skilled in the art can understand that the structure shown in Figure Y is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0100] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:

[0101] In response to a digital certificate verification request sent by a terminal, confirm the revocation status of the digital certificate in the digital certificate verification request;

[0102] Verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result;

[0103] Return the verification result to the terminal.

[0104] In one embodiment, when the processor executes the computer program, the following steps are further implemented: according to the certificate identifier carried by the digital certificate, look up the revocation status information matching the certificate identifier in the preset certificate revocation status table; the preset certificate revocation status table contains the corresponding relationships between multiple certificate identifiers and revocation status information; according to the revocation status information, determine the revocation status of the digital certificate; the revocation status includes revoked and not revoked.

[0105] In one embodiment, when the processor executes the computer program, the following steps are further implemented: if the revocation status of the digital certificate is revoked, retrieve the corresponding data from the preset database according to the certificate identifier to obtain the updated digital certificate; perform password verification on the updated digital certificate, and use the password verification result as the verification result of the updated digital certificate.

[0106] In one embodiment, when the processor executes the computer program, the following steps are further implemented: obtain the private key matching the certificate identifier; encrypt the digital certificate according to the private key to obtain the updated digital certificate containing the certificate version number and serial number.

[0107] In one embodiment, when the processor executes the computer program, the following steps are further implemented: if the revocation status of the digital certificate is not revoked, perform password verification on the digital certificate, and use the password verification result as the verification result of the digital certificate.

[0108] In one embodiment, when the processor executes the computer program, the following steps are further implemented: obtain the public key matching the certificate identifier; determine the matching degree between the private key and the public key of the updated digital certificate; if the matching degree is greater than or equal to the preset matching threshold and the serial number of the public key is the same as the serial number of the private key, generate a password verification result indicating that the password verification has passed.

[0109] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine the operation permissions matching the terminal according to the verification result.

[0110] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0111] In response to a digital certificate verification request sent by the terminal, confirm the revocation status of the digital certificate in the digital certificate verification request;

[0112] Verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result;

[0113] Return the verification result to the terminal.

[0114] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: According to the certificate identifier carried by the digital certificate, look up the revocation status information that matches the certificate identifier in a preset certificate revocation status table; the preset certificate revocation status table contains the corresponding relationships between multiple certificate identifiers and revocation status information; Determine the revocation status of the digital certificate according to the revocation status information; the revocation status includes revoked and not revoked.

[0115] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: If the revocation status of the digital certificate is revoked, retrieve the corresponding data from a preset database according to the certificate identifier to obtain an updated digital certificate; perform a password verification on the updated digital certificate, and use the password verification result as the verification result of the updated digital certificate.

[0116] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: Obtain a private key that matches the certificate identifier; encrypt the digital certificate according to the private key to obtain an updated digital certificate containing the certificate version number and serial number.

[0117] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: If the revocation status of the digital certificate is not revoked, perform a password verification on the digital certificate, and use the password verification result as the verification result of the digital certificate.

[0118] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: Obtain a public key that matches the certificate identifier; determine the matching degree between the private key and the public key of the updated digital certificate; if the matching degree is greater than or equal to a preset matching threshold and the serial number of the public key is the same as the serial number of the private key, generate a password verification result indicating that the password verification has passed.

[0119] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: Determine the operation permissions that match the terminal according to the verification result.

[0120] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The above computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above various methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0121] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the various technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0122] The above various embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.

Claims

1. A digital certificate verification method, characterized in that, Including: In response to a digital certificate verification request sent by a terminal, confirm the revocation status of the digital certificate in the digital certificate verification request; Verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result; Return the verification result to the terminal; The step of verifying the digital certificate according to the revocation status of the digital certificate to obtain a verification result includes: If the revocation status of the digital certificate is revoked, obtain a personal key that matches the certificate identifier; Encrypt the digital certificate with the personal key to obtain an updated digital certificate containing the certificate version number and serial number; Perform a password verification on the updated digital certificate. The step of performing a password verification on the updated digital certificate includes: Obtain a public key that matches the certificate identifier; Determine the matching degree between the personal key and the public key of the updated digital certificate; If the matching degree is greater than or equal to a preset matching threshold and the serial number of the public key is the same as the serial number of the personal key, generate a password verification result indicating that the password verification has passed.

2. The method according to claim 1, characterized in that, The step of confirming the revocation status of the digital certificate in the digital certificate verification request includes: According to the certificate identifier carried by the digital certificate, look up the revocation status information that matches the certificate identifier in a preset certificate revocation status table; the preset certificate revocation status table contains the corresponding relationships between multiple certificate identifiers and revocation status information; Determine the revocation status of the digital certificate according to the revocation status information; the revocation status includes revoked and not revoked.

3. The method according to claim 2, characterized in that, The step of verifying the digital certificate according to the revocation status of the digital certificate to obtain a verification result further includes: Perform a password verification on the updated digital certificate and use the password verification result as the verification result of the updated digital certificate.

4. The method according to claim 2, characterized in that, The step of verifying the digital certificate according to the revocation status of the digital certificate to obtain a verification result includes: If the revocation status of the digital certificate is not revoked, perform a password verification on the digital certificate and use the password verification result as the verification result of the digital certificate.

5. The method according to claim 1, characterized in that, After returning the verification result to the terminal, it further includes: Determine the operation permissions that match the terminal according to the verification result.

6. A digital certificate verification device, characterized in that, The device includes: A request response module, configured to, in response to a digital certificate verification request sent by a terminal, confirm the revocation status of the digital certificate in the digital certificate verification request; A certificate verification module, configured to verify the digital certificate according to the revocation status of the digital certificate to obtain a verification result; A result return module, configured to return the verification result to the terminal; The certificate verification module is further configured to, if the revocation status of the digital certificate is revoked, obtain a personal key that matches the certificate identifier; encrypt the digital certificate with the personal key to obtain an updated digital certificate containing the certificate version number and serial number; The certificate verification module is further configured to obtain a public key that matches the certificate identifier; determine the matching degree between the private key of the updated digital certificate and the public key; if the matching degree is greater than or equal to a preset matching threshold and the serial number of the public key is the same as the serial number of the private key, generate a password verification result indicating that the password verification has passed.

7. A computer device, including a memory and a processor, the memory stores a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Digital certificate updating method

    CN103117987A

  • Cloud storage data access control method, attribute certificate issuing method and system

    CN109818757A