Digital certificate-based access control rights initialization method and corresponding equipment, system, and storage device
Through the access control rights initialization method based on digital certificates, the access control ID and public key are generated and publicized, and the existing access control system is solved, and the access control system with high security and traceability is achieved.
Patent Information
- Application Number
- CN202111675589.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-31
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2041-12-31
AI Technical Summary
The existing access control system is easy to crack, has a low safety factor and is difficult to trace.
The access control rights initialization method based on digital certificates is adopted, and the operator terminal and the stakeholder terminal are applied to become the stakeholder and manufacturer of the access control company of the digital certificate, generate and publicize the access control ID and public key, and use the public notice platform to perform tamper-proof records and verification.
It improves the security and traceability of the access control system, ensures the unchangeable properties of the operation process, and enhances the security of the system.
Smart Images

Figure CN114491469B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of digital certificate technology, and specifically to a method for initializing access control rights based on digital certificates, as well as corresponding actor terminal devices, rights holder terminal devices, digital certificate access control devices, and an access control rights initialization system based on digital certificates, as well as a storage device. Background Art
[0002] As the name suggests, an access control system is a system for controlling entrances and exits. It evolved from traditional door locks. Traditional mechanical door locks are simply mechanical devices. No matter how well-designed or robust the materials, people can always use various means to open them. Key management is a hassle in busy passages (such as offices and hotel rooms). Lost keys or personnel changes require the replacement of both the lock and the key. To address these issues, electronic magnetic card locks and electronic combination locks emerged. These two locks have improved access control to a certain extent, ushering access management into the electronic era. However, with the increasing use of these two electronic locks, their inherent shortcomings have gradually become apparent. Magnetic card locks are prone to easy copying of information, high wear between the card and the reader, high failure rate, and low security. Combination locks are prone to password leakage and difficulty in tracing, resulting in a low security factor. Furthermore, most products of this era combined the card reader (password input) and the control unit, which were installed outside the door, making it easy for people to open the lock from outside. The access control system during this period was still in its early and immature stage, so the access control system at that time was usually called an electronic lock and was not widely used.
[0003] Digital certificate is a term used in the information technology field. The digital certificate platform aims to provide a uniform public disclosure mechanism, acting as a universal currency. It is a shared database where the data or information stored is characterized by being "unforgeable," "traceable," "open and transparent," and "collectively maintained." With the recent development and maturity of tamper-proof digital certificate technology, access control system security urgently needs new technological advancements to meet the security requirements of tamper-proof digital certificates in access control systems in numerous high-value locations. Summary of the Invention
[0004] The purpose of this application is to solve the problems of existing access control systems that are easy to crack, have low security factors, and are difficult to trace. This application provides an access control rights initialization method based on digital certificates, and also provides corresponding actor terminal devices, rights holder terminal devices, digital certificate access control devices, and access control rights initialization systems based on digital certificates, as well as storage devices.
[0005] To solve the above technical problems, the present application provides a method for initializing access control rights based on a digital certificate, which is suitable for execution in a computing device and includes:
[0006] The actor terminal applies to the beneficiary terminal to become the beneficiary of the digital certificate access control enterprise;
[0007] And apply to the beneficiary terminal to become a digital certificate access control maker;
[0008] Start the digital certificate access control maker program to initialize the digital certificate access control:
[0009] Receive the access control ID and corresponding public key sent by the digital certificate access control device;
[0010] Submit the access control initialization digital certificate to the public disclosure platform and the public disclosure platform will publicize the digital certificate. The digital certificate includes the access control ID and the corresponding public key, the ID and public key corresponding to the actor's terminal, and is signed with the private key corresponding to the actor's terminal;
[0011] Receive the digital certificate access control initialization completion message returned by the public announcement platform.
[0012] Furthermore, the steps of applying to the beneficiary terminal to become a digital certificate access control enterprise beneficiary include:
[0013] The actor terminal submits the actor's enterprise equity holder application to the equity holder terminal through the public disclosure platform, and the application includes the equity holder's rights and interests scope;
[0014] The digital certificate of the beneficiary of the enterprise is submitted to the beneficiary terminal through the public disclosure platform for verification. The digital certificate is published on the public disclosure platform. The digital certificate includes the ID and public key corresponding to the beneficiary terminal, the beneficiary of the enterprise, and is signed with the private key corresponding to the beneficiary terminal;
[0015] After the verification of the equity holder terminal is successful, the approval returned by the public disclosure platform becomes the enterprise equity holder digital certificate. At the same time, the digital certificate is publicized on the public disclosure platform. The digital certificate includes the ID and public key corresponding to the equity holder terminal, the enterprise equity holder application of the actor, and is signed with the private key corresponding to the equity holder terminal.
[0016] Furthermore, the steps of applying to the beneficiary terminal to become a digital certificate access control manufacturer include:
[0017] The actor's terminal submits a digital certificate for applying for access control manufacturer to the equity holder's terminal through the public announcement platform for verification. At the same time, the digital certificate is publicized on the public announcement platform. The digital certificate includes the ID and public key corresponding to the actor's terminal, the actor's corporate equity holder application, and is signed with the private key corresponding to the actor's terminal.
[0018] After the verification of the beneficiary terminal is successful, the approval returned through the public announcement platform becomes the access control manufacturer's digital certificate. At the same time, the digital certificate is announced on the public announcement platform. The digital certificate includes the ID and public key corresponding to the beneficiary terminal, the application of the beneficiary enterprise, and is signed with the private key corresponding to the beneficiary terminal.
[0019] To solve the above technical problems, the present application also provides a method for initializing access control rights based on a digital certificate, which is suitable for execution in a computing device and includes:
[0020] The beneficiary terminal executes the application of the actor terminal to become the beneficiary of the digital certificate access control enterprise;
[0021] And execute the application of the said actor's terminal to become a digital certificate access control manufacturer;
[0022] Receive the digital certificate access control initialization completion message returned by the public announcement platform.
[0023] Furthermore, the steps for the beneficiary terminal to execute the application of the actor terminal to become the beneficiary of the digital certificate access control enterprise include:
[0024] Receiving an application for an equity holder of an enterprise of the actor submitted by the actor terminal, wherein the application includes the scope of the equity holder's rights and interests;
[0025] and receiving the digital certificate of the actor's enterprise equity holder application submitted by the actor's terminal through the public disclosure platform. At the same time, the digital certificate is publicly disclosed on the public disclosure platform. The digital certificate includes the ID and public key corresponding to the actor's terminal, the actor's enterprise equity holder application, and is signed with the private key corresponding to the actor's terminal;
[0026] Verify the digital certificate applied for by the corporate rights holder of the said actor;
[0027] If the verification is successful, the digital certificate approving the actor to become the corporate equity holder will be returned to the actor terminal through the public disclosure platform. At the same time, the digital certificate will be publicized on the public disclosure platform. The digital certificate includes the ID and public key corresponding to the equity holder terminal, the actor's corporate equity holder application, and is signed with the private key corresponding to the equity holder terminal.
[0028] Furthermore, the steps of executing the application of the actor's terminal to become a digital certificate access control manufacturer include:
[0029] Receive the digital certificate of the access control manufacturer application submitted by the actor terminal through the public platform, and at the same time publicize the digital certificate on the public platform. The digital certificate includes the ID and public key corresponding to the actor terminal, the actor enterprise equity holder application, and is signed with the private key corresponding to the actor terminal;
[0030] Verify the digital certificate applied for by the access control manufacturer;
[0031] If the verification is successful, the digital certificate approving the access control manufacturer will be returned to the terminal of the actor through the public announcement platform. At the same time, the digital certificate will be announced on the public announcement platform. The digital certificate includes the ID and public key corresponding to the beneficiary terminal, the beneficiary application of the actor's enterprise, and is signed with the private key corresponding to the beneficiary terminal.
[0032] To solve the above technical problems, the present application also provides a method for initializing access control rights based on a digital certificate, which is suitable for execution in a computing device and includes:
[0033] Digital certificate access control device obtains access control ID;
[0034] Generate the corresponding public key and private key according to the access control ID, and save the private key locally;
[0035] The access control ID and the corresponding public key are returned to the user's terminal and submitted to the platform for public display by the user's terminal;
[0036] Receive the equity tree initialized digital certificate returned by the public platform and save it locally.
[0037] Furthermore, the step of obtaining the access control ID by the digital certificate access control device also includes:
[0038] Receive the initialization start message sent by the actor terminal, the instruction includes the ID and public key corresponding to the actor terminal, the initialization start instruction, the access control ID, and is signed with the private key corresponding to the actor terminal.
[0039] In order to solve the above technical problems, the present application also provides a storage device, which stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor as described in the aforementioned digital certificate-based access control rights initialization method.
[0040] To solve the above technical problems, the present application also provides a terminal device for an actor, including:
[0041] a processor adapted to implement the instructions; and
[0042] A storage device is suitable for storing a plurality of instructions, wherein the instructions are suitable for being loaded and executed by a processor, such as the instructions executed by the actor terminal in the aforementioned digital certificate-based access control rights initialization method.
[0043] To solve the above technical problems, the present application also provides a terminal device for a rights holder, including:
[0044] a processor adapted to implement the instructions; and
[0045] A storage device is adapted to store a plurality of instructions, wherein the instructions are adapted to be loaded and executed by a processor, such as the instructions executed by the beneficiary terminal in the aforementioned digital certificate-based access control benefit initialization method.
[0046] To solve the above technical problems, the present application further provides a digital certificate access control device, which is characterized by comprising:
[0047] a processor adapted to implement the instructions; and
[0048] A storage device is adapted to store a plurality of instructions, wherein the instructions are adapted to be loaded and executed by a processor, such as the instructions executed by the digital certificate access control device in the aforementioned digital certificate-based access control rights initialization method.
[0049] To solve the above technical problems, the present application also provides a digital certificate-based access control rights initialization system, which includes:
[0050] The aforementioned actor terminal, the aforementioned rights holder terminal, the aforementioned digital certificate access control, and the aforementioned public disclosure platform;
[0051] The public platform is used to publicize the access control initialization digital certificate submitted by the actor's terminal. The digital certificate includes the access control ID and the corresponding public key, the ID and public key corresponding to the actor's terminal, and is signed with the private key corresponding to the actor's terminal;
[0052] Return the digital certificate access control initialization completion message to the actor terminal and the equity holder terminal, and return the equity tree initialization digital certificate to the digital certificate access control, the digital certificate including the access control ID and corresponding public key of the digital certificate access control and the corresponding equity tree.
[0053] Furthermore, the public disclosure platform is also used to:
[0054] Publicizing the application for digital certificate of the actor's enterprise rights holder and the application for digital certificate of the access control manufacturer submitted by the actor's terminal;
[0055] Publicize the digital certificate of approval to become an enterprise benefit holder and the digital certificate of approval to become an access control manufacturer submitted by the benefit holder terminal.
[0056] The digital certificate-based access control rights initialization method provided in this application applies to become a digital certificate access control enterprise rights holder and a digital certificate access control manufacturer through the actor terminal, and then the digital certificate access control device generates and returns the access control ID and the corresponding public key, and submits the access control initialization digital certificate to the public disclosure platform and the public disclosure platform publicizes the digital certificate, and the actor terminal receives the digital certificate access control initialization completion message returned by the public disclosure platform; thereby completing the connection between the actor terminal, the rights holder terminal, the digital certificate access control and the public disclosure platform, completing the access control rights initialization based on the digital certificate, and building a digital certificate access control system.
[0057] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specifically cites a preferred embodiment and describes it in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] Figure 1 A data flow diagram of a method for initializing access control rights based on digital certificates provided in an embodiment of the present application.
[0059] Figure 2 Another data flow diagram of a method for initializing access control rights based on a digital certificate is provided for an embodiment of the present application.
[0060] Figure 3 A schematic diagram of the logical structure of a terminal device of an actor provided in an embodiment of the present application.
[0061] Figure 4 A schematic diagram of the logical structure of a terminal device of a benefit holder provided in an embodiment of the present application.
[0062] Figure 5 A schematic diagram of the logical structure of a digital certificate access control device provided in an embodiment of the present application.
[0063] Figure 6 A schematic diagram of the logical structure of a digital certificate-based access control rights initialization system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0064] In order to further explain the technical means and effects adopted by this application to achieve the intended application purpose, the following is a detailed description of this application in conjunction with the accompanying drawings and preferred embodiments.
[0065] Through the description of the specific implementation methods, a deeper and more specific understanding of the technical means and effects adopted by this application to achieve the intended purpose can be obtained. However, the accompanying drawings are only for reference and illustration purposes and are not used to limit this application.
[0066] Example 1:
[0067] See also Figure 1 , an embodiment of the method for initializing access control rights based on digital certificates of the present invention includes:
[0068] 101. Apply to the beneficiary terminal to become the beneficiary of the digital certificate access control enterprise;
[0069] The actor is a person who is about to join the digital certificate access control company and become its beneficiary. The actor applies to the beneficiary terminal to become a beneficiary of the digital certificate access control company through the actor terminal.
[0070] 102. Apply to the beneficiary terminal to become a digital certificate access control manufacturer;
[0071] After the actor, that is, the actor terminal becomes the digital certificate access control enterprise beneficiary, they can apply to the beneficiary terminal to become the digital certificate access control manufacturer. The beneficiary is the person in the enterprise who has the power to approve the actor to become the enterprise beneficiary. The beneficiary exercises their rights through the beneficiary terminal.
[0072] 103. Receive the access control ID and corresponding public key sent by the digital certificate access control device;
[0073] Start the digital certificate access control maker program to initialize the digital certificate access control, that is, the actor terminal first notifies the digital certificate access control device that the actor terminal has become a digital certificate access control maker, and sends the access control ID to the digital certificate access control device. The digital certificate access control device generates the corresponding public key and private key based on the access control ID, and returns the access control ID and the corresponding public key to the actor terminal, and saves the corresponding private key locally.
[0074] 104. Submit the access control initialization digital certificate to the public disclosure platform and the public disclosure platform will publicize the digital certificate;
[0075] After the actor's terminal receives the access control ID and corresponding public key returned by the digital certificate access control device, it submits the access control initialization digital certificate to the public disclosure platform. The digital certificate includes the access control ID and corresponding public key, the ID and public key corresponding to the actor's terminal, and is signed with the private key corresponding to the actor's terminal; the public disclosure platform publicizes the digital certificate.
[0076] 105. Receive the digital certificate access control initialization completion message returned by the public announcement platform;
[0077] The public announcement platform receives and announces the access control initialization digital certificate, and returns a digital certificate access control initialization completion message to the actor, and the actor's terminal receives the message.
[0078] In this embodiment, this method applies to become a digital certificate access control enterprise beneficiary and digital certificate access control manufacturer through the actor terminal, and then the digital certificate access control device generates and returns the access control ID and the corresponding public key, and submits the access control initialization digital certificate to the public disclosure platform and the public disclosure platform discloses the digital certificate. The actor terminal receives the digital certificate access control initialization completion message returned by the public disclosure platform; thereby completing the series connection between the actor terminal, the beneficiary terminal, the digital certificate access control and the public disclosure platform, completing the access control rights initialization based on the digital certificate, and building a digital certificate access control system.
[0079] Example 2:
[0080] Please refer to Figure 2 Another embodiment of the digital certificate-based access control rights initialization method of the present invention includes:
[0081] After a user has successfully applied for a Digital Certificate Access Control Enterprise Benefit Holder position, that is, joined a Digital Certificate Access Control Enterprise, they must apply to become a Digital Certificate Access Control Enterprise Benefit Holder. This application is made through the User Terminal. A Benefit Holder is the person within the enterprise who has the authority to approve the user's becoming a Benefit Holder. Benefit Holders exercise their rights through the Benefit Holder Terminal.
[0082] The user terminal must first become an employee of the digital certificate access control company, that is, submit an application for the position of digital certificate access control company equity holder. The application process is tailored to each company and is not detailed here. It should be noted that the digital certificates submitted during the signing process must be published on the public platform to form an unalterable record.
[0083] 201. The actor's terminal submits the actor's corporate equity holder application;
[0084] The actor's terminal submits an application for the actor's corporate equity holder to the public disclosure platform. The application includes the actor's terminal ID and the scope of equity.
[0085] 202. The public disclosure platform receives the application of the corporate beneficiary and sends the application to the beneficiary terminal;
[0086] 203. The actor's terminal submits the actor's corporate equity holder's application for a digital certificate;
[0087] The actor's terminal then submits the actor's corporate equity holder's application for a digital certificate to the public disclosure platform. The digital certificate includes the actor's terminal's corresponding ID, its public key, the actor's corporate equity holder's application, and is signed with the actor's terminal's corresponding private key.
[0088] 204. The public disclosure platform receives the application for the digital certificate from the corporate beneficiary and makes it public, and then forwards the digital certificate to the beneficiary terminal;
[0089] 205. Send the digital certificate application of the corporate rights holder to the rights terminal;
[0090] 206. The rights holder's terminal verifies the rights of the enterprise to apply for a digital certificate;
[0091] The equity holder's terminal receives the digital certificate of the actor's enterprise equity application and performs verification based on the received digital certificate. Specifically, it verifies whether the private key used to sign the digital certificate corresponds to the public key carried in the digital certificate. If so, the verification is successful. If the verification is successful, a digital certificate approving the enterprise equity holder is generated. The digital certificate includes the ID corresponding to the actor's terminal, its public key, and the actor's enterprise equity application, and is signed with the private key corresponding to the equity holder terminal. The digital certificate is then sent to the public disclosure platform.
[0092] 207. The equity holder's terminal sends a digital certificate approving the enterprise equity holder to the public disclosure platform;
[0093] 208. Public announcement platform to publicize the digital certificate of approval to become the corporate equity holder;
[0094] The disclosure platform receives the digital certificate sent by the benefit holder terminal approving to become the enterprise benefit holder and discloses the digital certificate.
[0095] 209. Send a digital certificate approving the person to become the rights holder to the person's terminal;
[0096] After the actor's terminal receives the digital certificate approving him to become a beneficiary, he becomes the beneficiary of the enterprise and has corresponding rights and interests.
[0097] 210. The actor's terminal submits an application for a digital certificate to join the access control manufacturer;
[0098] After obtaining the position of Digital Certificate Access Control Enterprise Benefit Holder and becoming a Digital Certificate Access Control Enterprise Benefit Holder, the person can then apply for the position of Digital Certificate Access Control Manufacturer. The application process varies depending on the company and is not detailed here. It should be noted that the digital certificates submitted during the signing application process must be publicized on the public platform to form an unalterable record.
[0099] After obtaining the digital certificate access control maker position, submit the digital certificate application for joining the access control maker position to the public announcement platform. The digital certificate includes the ID corresponding to the actor's terminal, its public key, and the application for joining the access control maker position, and is signed with the private key corresponding to the actor's terminal.
[0100] 211. Publicly announce the application for digital certificate for access control manufacturer position;
[0101] The disclosure platform receives digital certificates applied for by access control manufacturers and makes them public.
[0102] 212. Send a digital certificate to the beneficiary terminal to apply for the access control manufacturer position;
[0103] 213. Verify the access control manufacturer position and apply for a digital certificate;
[0104] The beneficiary terminal receives the digital certificate for applying to join the access control manufacturer position forwarded by the public announcement platform, and verifies it based on the digital certificate. Specifically: verifies whether the private key that signs the digital certificate corresponds to the public key carried by the digital certificate. If so, the verification is successful; if the verification is successful, a digital certificate approving to become an access control manufacturer is generated. The digital certificate includes the ID corresponding to the actor's terminal, its public key, and the access control manufacturer application, and is signed with the private key corresponding to the beneficiary terminal.
[0105] 214. Send the digital certificate of approval to become the access control manufacturer to the public announcement platform;
[0106] 215. Publicly announce the approval of the digital certificate for access control manufacturer;
[0107] The public announcement platform receives the digital certificate of the access control manufacturer approved by the beneficiary terminal and makes it public;
[0108] 216. Return the digital certificate of access control manufacturer to the actor's terminal;
[0109] 217. Generate digital certificate access control ID;
[0110] After the actor's terminal receives approval to become a digital certificate access control maker, it initializes the digital certificate access control maker program locally and generates a digital certificate access control ID;
[0111] 218. The actor's terminal sends the digital certificate access control ID to the digital certificate access control;
[0112] 219. The digital certificate access control receives the access control ID and generates the corresponding public key and private key, and the private key is saved;
[0113] The digital certificate access control receives the access control ID sent by the actor's terminal, generates the corresponding public key and private key based on the access control ID, and saves them. The private key is only saved locally.
[0114] 220. Return the access control ID and corresponding public key;
[0115] The digital certificate access control saves the private key locally and then sends the access control ID and the corresponding public key to the actor's terminal.
[0116] 221. Submit the access control initialization digital certificate to the public disclosure platform;
[0117] The actor's terminal submits the access control initialization digital certificate to the public disclosure platform. The digital certificate includes the access control ID and corresponding public key corresponding to the digital certificate access control, the actor's terminal corresponding ID and corresponding public key, and is signed with the actor's terminal's private key.
[0118] 222. Public access control initialization digital certificate;
[0119] The public announcement platform receives the public access control initialization digital certificate and makes it public.
[0120] 223. Return the message indicating that the digital certificate access control initialization is complete;
[0121] The public disclosure platform returns a digital certificate access control initialization completion message to the beneficiary terminal to notify the beneficiary that the corresponding digital certificate access control has been initialized.
[0122] 224. Return the digital certificate access control initialization completion message;
[0123] The public disclosure platform returns a digital certificate access control initialization completion message to the actor's terminal to notify the actor that the corresponding digital certificate access control has been initialized.
[0124] 225. Return the equity tree initialization file;
[0125] The public disclosure platform dynamically installs a rights tree file for each digital certificate access control device. This file details the relationships between the various stakeholders of the corresponding digital certificate access control device and the corresponding rights and interests. After each verified dynamic update, the public disclosure platform and the digital certificate access control device are synchronized and updated. After the digital certificate access control device is initialized, the public disclosure platform sends the rights tree initialization file to the digital certificate access control device.
[0126] 226. The digital certificate access control receives and saves the equity tree initialization file.
[0127] In this embodiment, the actor terminal applies to become the digital certificate access control enterprise beneficiary and digital certificate access control manufacturer, and then the digital certificate access control device generates and returns the access control ID and the corresponding public key, and submits the access control initialization digital certificate to the public disclosure platform and the public disclosure platform discloses the digital certificate. The actor terminal receives the digital certificate access control initialization completion message returned by the public disclosure platform; thereby completing the series connection between the actor terminal, the beneficiary terminal, the digital certificate access control and the public disclosure platform, completing the access control rights initialization based on the digital certificate, and building a digital certificate access control system; at the same time, every operation on the digital certificate needs to be disclosed on the public disclosure platform to ensure the unchangeable attributes of the entire operation and authorization process, thereby ensuring the security and traceability of the entire digital certificate access control system.
[0128] Example 3:
[0129] The storage device in this embodiment stores a plurality of instructions, which are suitable for being loaded and executed by the processor. Figure 1 and Figure 2 The instructions, specific execution process and beneficial effects can be found in the aforementioned embodiments and will not be described in detail here.
[0130] Example 4:
[0131] See also Figure 3 In this embodiment, the terminal device of the actor includes:
[0132] A processor 301 adapted to implement the instructions; and
[0133] The storage device 302 is adapted to store a plurality of instructions, which are adapted to be loaded and executed by the processor. Figure 1 and Figure 2 The instructions, specific execution process and beneficial effects can be found in the aforementioned embodiments and will not be described in detail here.
[0134] Embodiment 5:
[0135] See also Figure 4 The stakeholder terminal device in this embodiment includes:
[0136] Processor 401, adapted to implement various instructions; and
[0137] The storage device 402 is adapted to store a plurality of instructions, which are adapted to be loaded and executed by the processor. Figure 1 and Figure 2 The instructions, specific execution process and beneficial effects can be found in the aforementioned embodiments and will not be described in detail here.
[0138] See also Figure 5 , the digital certificate access control device in this embodiment includes:
[0139] A processor 501 adapted to implement the instructions; and
[0140] The storage device 502 is adapted to store a plurality of instructions, which are adapted to be loaded and executed by the processor. Figure 1 and Figure 2 The instructions, specific execution process and beneficial effects can be found in the aforementioned embodiments and will not be described in detail here.
[0141] See also Figure 6 The digital certificate-based access control rights initialization system in this embodiment includes:
[0142] The aforementioned actor terminal device, the rights holder terminal device, the digital certificate access control device, and the aforementioned public disclosure platform are interconnected. The data interaction process and beneficial effects between them can be found in the aforementioned embodiments and will not be elaborated here.
[0143] The above description is merely a preferred embodiment of the present application and does not constitute any form of limitation to the present application. Although the present application has been disclosed as a preferred embodiment, it is not intended to limit the present application. Any technician familiar with this profession can make slight changes or modifications to equivalent embodiments using the technical content disclosed above without departing from the scope of the technical solution of the present application. However, any simple modifications, equivalent changes and modifications made to the above embodiments based on the technical essence of the present application without departing from the content of the technical solution of the present application are still within the scope of the technical solution of the present application.
Claims
1. A method for initializing access control rights based on digital certificates, the method being suitable for execution in a computing device, characterized in that: The method comprises: The actor terminal applies to the beneficiary terminal to become the beneficiary of the digital certificate access control enterprise; And apply to the beneficiary terminal to become a digital certificate access control maker; Start the digital certificate access control maker program to initialize the digital certificate access control: Receive the access control ID and corresponding public key sent by the digital certificate access control device; Submit the access control initialization digital certificate to the public disclosure platform and the public disclosure platform will publicize the digital certificate. The digital certificate includes the access control ID and the corresponding public key, the ID and public key corresponding to the actor's terminal, and is signed with the private key corresponding to the actor's terminal; Receive the digital certificate access control initialization completion message returned by the public platform; The steps of applying to the beneficiary terminal to become a digital certificate access control enterprise beneficiary include: The actor terminal submits the actor's enterprise equity holder application to the equity holder terminal through the public disclosure platform, and the application includes the equity holder's rights and interests scope; The digital certificate of the beneficiary of the enterprise is submitted to the beneficiary terminal through the public disclosure platform for verification. The digital certificate is published on the public disclosure platform. The digital certificate includes the ID and public key corresponding to the beneficiary terminal, the beneficiary of the enterprise, and is signed with the private key corresponding to the beneficiary terminal; After the verification of the equity holder terminal is successful, the approval returned by the public disclosure platform becomes the enterprise equity holder digital certificate. At the same time, the digital certificate is publicized on the public disclosure platform. The digital certificate includes the ID and public key corresponding to the equity holder terminal, the enterprise equity holder application of the actor, and is signed with the private key corresponding to the equity holder terminal.
2. The method according to claim 1, characterized in that The steps of applying to the beneficiary terminal to become a digital certificate access control manufacturer include: The actor's terminal submits a digital certificate for applying for access control manufacturer to the equity holder's terminal through the public announcement platform for verification. At the same time, the digital certificate is publicized on the public announcement platform. The digital certificate includes the ID and public key corresponding to the actor's terminal, the actor's corporate equity holder application, and is signed with the private key corresponding to the actor's terminal. After the verification of the beneficiary terminal is successful, the approval returned through the public announcement platform becomes the access control manufacturer's digital certificate. At the same time, the digital certificate is announced on the public announcement platform. The digital certificate includes the ID and public key corresponding to the beneficiary terminal, the application of the beneficiary enterprise, and is signed with the private key corresponding to the beneficiary terminal.
3. A method for initializing access control rights based on digital certificates, the method being suitable for execution in a computing device, characterized in that: The method comprises: The beneficiary terminal executes the application of the actor terminal to become the beneficiary of the digital certificate access control enterprise; And execute the application of the said actor's terminal to become a digital certificate access control manufacturer; Receive the digital certificate access control initialization completion message returned by the public announcement platform; The steps of the beneficiary terminal executing the application of the actor terminal to become the beneficiary of the digital certificate access control enterprise include: Receiving an application for an equity holder of an enterprise of the actor submitted by the actor terminal, wherein the application includes the scope of the equity holder's rights and interests; and receiving the digital certificate of the actor's enterprise equity holder application submitted by the actor's terminal through the public disclosure platform. At the same time, the digital certificate is publicly disclosed on the public disclosure platform. The digital certificate includes the ID and public key corresponding to the actor's terminal, the actor's enterprise equity holder application, and is signed with the private key corresponding to the actor's terminal; Verify the digital certificate applied for by the corporate rights holder of the said actor; If the verification is successful, the digital certificate approving the actor to become the corporate equity holder will be returned to the actor terminal through the public disclosure platform. At the same time, the digital certificate will be publicized on the public disclosure platform. The digital certificate includes the ID and public key corresponding to the equity holder terminal, the actor's corporate equity holder application, and is signed with the private key corresponding to the equity holder terminal.
4. The method according to claim 3, characterized in that The steps of applying for the execution of the terminal to become a digital certificate access control manufacturer include: Receive the digital certificate of the access control manufacturer application submitted by the actor terminal through the public platform, and at the same time publicize the digital certificate on the public platform. The digital certificate includes the ID and public key corresponding to the actor terminal, the actor enterprise equity holder application, and is signed with the private key corresponding to the actor terminal; Verify the digital certificate applied for by the access control manufacturer; If the verification is successful, the digital certificate approving the access control manufacturer will be returned to the terminal of the actor through the public announcement platform. At the same time, the digital certificate will be announced on the public announcement platform. The digital certificate includes the ID and public key corresponding to the beneficiary terminal, the beneficiary application of the actor's enterprise, and is signed with the private key corresponding to the beneficiary terminal.
5. A method for initializing access control rights based on digital certificates, the method being suitable for execution in a computing device, characterized in that: The method comprises: Digital certificate access control device obtains access control ID; Generate the corresponding public key and private key according to the access control ID, and save the private key locally; The access control ID and the corresponding public key are returned to the user's terminal and submitted to the platform for public display by the user's terminal; Receive the equity tree initialization digital certificate returned by the public platform and save it locally; Wherein, before the step of obtaining the access control ID by the digital certificate access control device, the following steps are further included: Receive an initialization startup message sent by the actor's terminal, where the initialization startup message includes the ID and public key corresponding to the actor's terminal, an initialization startup instruction, and an access control ID, and is signed with the private key corresponding to the actor's terminal.
6. A storage device storing a plurality of instructions, characterized in that: The instruction is suitable for being loaded by a processor and executing the access control rights initialization method as described in claim 1 or claim 2; or the instruction is suitable for being loaded by a processor and executing the access control rights initialization method as described in claim 3 or claim 4; or the instruction is suitable for being loaded by a processor and executing the access control rights initialization method as described in claim 5.
7. A terminal device of an actor, characterized in that: include: a processor adapted to implement the instructions; as well as A storage device, adapted to store a plurality of instructions, wherein the instructions are adapted to be loaded by a processor and executed by the access control rights initialization method according to claim 1 or claim 2.
8. A terminal device of a rights holder, characterized in that: include: a processor adapted to implement the instructions; as well as A storage device, adapted to store a plurality of instructions, wherein the instructions are adapted to be loaded by a processor and executed by the access control rights initialization method according to claim 3 or claim 4.
9. A digital certificate access control device, characterized in that: include: a processor adapted to implement the instructions; as well as A storage device, adapted to store a plurality of instructions, wherein the instructions are adapted to be loaded by a processor and executed by the access control rights initialization method according to claim 5.
10. A digital certificate-based access control rights initialization system, characterized in that: The system comprises: The actor terminal according to claim 7, the rights holder terminal according to claim 8, the digital certificate access control and the public disclosure platform according to claim 9; The public platform is used to publicize the access control initialization digital certificate submitted by the actor's terminal. The digital certificate includes the access control ID and the corresponding public key, the ID and public key corresponding to the actor's terminal, and is signed with the private key corresponding to the actor's terminal; Return the digital certificate access control initialization completion message to the actor terminal and the equity holder terminal, and return the equity tree initialization digital certificate to the digital certificate access control, the digital certificate including the access control ID and corresponding public key of the digital certificate access control and the corresponding equity tree.
11. The system according to claim 10, wherein: The public disclosure platform is also used to: Publicizing the application for digital certificate of the actor's enterprise rights holder and the application for digital certificate of the access control manufacturer submitted by the actor's terminal; Publicize the digital certificate of approval to become an enterprise benefit holder and the digital certificate of approval to become an access control manufacturer submitted by the benefit holder terminal.
Citation Information
Patent Citations
Initialization method based on digital certificate platform, corresponding device and system, and storage device
CN112953708A
Authority management method for verifier
CN113779537A