A certificate status query system, method, device, equipment and medium

By using a preset algorithm and query rules between the terminal and the server to determine the target rows and columns of the certificate status matrix, the problem of user privacy leakage caused by certificate number leakage is solved, and a secure and accurate certificate status query is achieved.

CN115085936BActive Publication Date: 2025-08-01BEIJING INFOSEC TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210691052.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-17
Publication Date
2025-08-01
Estimated Expiration
2042-06-17

AI Technical Summary

Technical Problem

In existing technologies, the certificate number is easily leaked when querying certificate status, which can lead to the leakage of user privacy.

Method used

By using a preset algorithm and query rules between the terminal and the server, the target row and target column in the certificate status matrix are determined and sent to the server as query items. The server returns candidate identifiers and sequence numbers to the terminal. The terminal determines the certificate status based on the target identifier, instead of directly sending the certificate number.

Benefits of technology

This effectively prevents the leakage of certificate numbers, ensures the security of user privacy, and accurately determines the status of certificates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115085936B_ABST
    Figure CN115085936B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a certificate status query system, method, device, equipment and medium, which are used to solve the problem of user privacy leakage caused by querying the certificate status in the prior art. Since in the embodiments of the present application, the terminal determines that the certificate number to be queried is stored in the first target row and the first target column in the certificate status matrix, and the terminal takes the obtained first target row or the first target column as the query item and sends the information of the query item to the server. The terminal does not directly send the certificate number to be queried. Therefore, when querying the certificate status, even if the information of the query item is intercepted, the device that obtains the information of the query item cannot determine the certificate number to be queried, thereby avoiding the problem of user privacy leakage caused by the leakage of the certificate number to be queried. In addition, what the server sends to the terminal are candidate identifiers, and the terminal can obtain the target identifier representing the certificate status corresponding to the certificate number to be queried, so as to accurately determine the certificate status.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing, and particularly to a certificate status query system, method, device, equipment and medium. Background Art

[0002] With the development of society, certificates are widely used in the network. For example, before accessing a certain website, it is possible to first verify whether the certificate corresponding to the website is valid, so as to determine whether the website is accurate. However, due to some uncontrollable reasons, a certificate may be revoked within its validity period. Therefore, it is necessary to query whether the certificate has been revoked before using the certificate.

[0003] In the prior art, when checking whether a certificate has been revoked, usually the certificate number of the certificate to be checked is sent to the server by the terminal. The server determines whether the certificate corresponding to the received certificate number has been revoked based on the certificate numbers of each unrevoked certificate and the certificate numbers of each revoked certificate saved, so as to determine whether the certificate corresponding to the certificate number is valid. However, when the terminal directly sends the certificate number to the server, the certificate number is easily leaked. Since the certificate number corresponds to a website one by one, the device that obtains the certificate number can know which website the user wants to visit according to the certificate number, thus causing the leakage of user privacy. Summary of the Invention

[0004] Embodiments of this application provide a certificate status query system, method, device, equipment and medium, which are used to solve the problem of user privacy leakage when querying the certificate status in the prior art.

[0005] In a first aspect, embodiments of this application provide a certificate status query system, and the system includes a terminal and a server;

[0006] The terminal is used to determine a first target row in which the certificate number to be queried is stored in a certificate status matrix in the server by using a first preset algorithm and the certificate number to be queried, and determine a first target column in which the certificate number to be queried is stored in the certificate status matrix by using a second preset algorithm and the certificate number to be queried. According to a preset query rule, the first target row or the first target column is used as a query item, and the information of the query item is sent to the server;

[0007] The server is used to obtain each candidate identifier included in the first target row or the first target column in the certificate status matrix according to the information of the query item and a preset query rule, and send each candidate identifier and the serial number of the corresponding column or row to the terminal;

[0008] The terminal is further configured to obtain, from each candidate identifier and the corresponding serial number of the column or row where it is located received, a target identifier with the serial number being the first target column or the first target row, and determine whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0009] In a second aspect, an embodiment of the present application further provides a method for querying certificate status. The method includes:

[0010] Using a first preset algorithm and the certificate number to be queried, determine a first target row in which the certificate number to be queried is stored in a certificate status matrix in the server, and use a second preset algorithm and the certificate number to be queried to determine a first target column in which the certificate number to be queried is stored in the certificate status matrix;

[0011] According to a preset query rule, use the first target row or the first target column as a query item, and send the information of the query item to the server; so that the server, according to the information of the query item and the preset query rule, obtains each candidate identifier included in the first target row or the first target column in the certificate status matrix, and sends each candidate identifier and the corresponding serial number of the column or row where it is located to the terminal;

[0012] In each candidate identifier and the corresponding serial number of the column or row where it is located received, obtain a target identifier with the serial number being the first target column or the first target row, and determine whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0013] In a third aspect, an embodiment of the present application further provides a method for querying certificate status. The method includes:

[0014] According to the information of the query item and the preset query rule, obtain each candidate identifier included in a first target row or a first target column in the certificate status matrix; where the information of the query item is that the terminal uses a first preset algorithm and the certificate number to be queried to determine a first target row in which the certificate number to be queried is stored in a certificate status matrix in the server, and uses a second preset algorithm and the certificate number to be queried to determine a first target column in which the certificate number to be queried is stored in the certificate status matrix, and according to the preset query rule, uses the first target row or the first target column as a query item and sends the information of the query item to the server;

[0015] Send each candidate identifier and the corresponding serial number of the column or row where it is located to the terminal; so that the terminal, in each candidate identifier and the corresponding serial number of the column or row where it is located received, obtains a target identifier with the serial number being the first target column or the first target row, and determines whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0016] In a fourth aspect, an embodiment of the present application further provides a certificate status query device, and the device includes:

[0017] A determination module, configured to use a first preset algorithm and a certificate number to be queried to determine a first target row in which the certificate number to be queried is stored in a certificate status matrix in the server, and use a second preset algorithm and the certificate number to be queried to determine a first target column in which the certificate number to be queried is stored in the certificate status matrix;

[0018] A first sending module, configured to use the first target row or the first target column as a query item according to a preset query rule, and send information of the query item to the server;

[0019] A processing module, configured to obtain a target identifier with a serial number of the first target column or the first target row from each received candidate identifier and the corresponding serial number of the column or row where it is located, and determine whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0020] In a fifth aspect, an embodiment of the present application further provides a certificate status query device, and the device includes:

[0021] An obtaining module, configured to obtain each candidate identifier included in a first target row or a first target column in a certificate status matrix according to the information of the query item and a preset query rule;

[0022] A second sending module, configured to send each candidate identifier and the corresponding serial number of the column or row where it is located to the terminal.

[0023] In a sixth aspect, an embodiment of the present application further provides an electronic device, and the electronic device includes at least a processor and a memory. When the processor executes a computer program stored in the memory, the steps of the certificate status query method as described in any one of the above are implemented.

[0024] In a seventh aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the device status query method as described in any one of the above are implemented.

[0025] In an embodiment of the present application, the certificate status query system includes a terminal and a server. The terminal uses a first preset algorithm to determine the first target row in the certificate status matrix stored in the server where the certificate number to be queried is located, and uses a second preset algorithm to determine the first target column in the certificate status matrix stored in the server where the certificate number to be queried is located. The terminal, according to a preset query rule, uses the first target row or the first target column as a query item, and sends the information of the query item to the server. The server, according to the information of the query item and the preset query rule, obtains each candidate identifier recorded in the first target row or the first target column in the certificate status query matrix, and sends each candidate identifier included in the first target row or the first target column and the serial number of the corresponding column or row to the terminal. The terminal obtains, among each candidate identifier and the serial number of the column or row where it is located, the target identifier whose corresponding serial number is the first target column or the first target row, and determines whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier. Since in the embodiment of the present application, the terminal determines that the certificate number to be queried is stored in the first target row and the first target column in the certificate status matrix, and the terminal uses the obtained first target row or the first target column as a query item and sends the information of the query item to the server, and the terminal does not directly send the certificate number to be queried. Therefore, in the embodiment of the present application, when querying the certificate status, even if the information of the query item is intercepted, the device that obtains the information of the query item cannot determine the certificate number to be queried, thereby avoiding the problem of user privacy leakage caused by the leakage of the certificate number to be queried. In addition, what the server sends to the terminal are various candidate identifiers, and the terminal can obtain the target identifier representing the certificate status corresponding to the certificate number to be queried, thereby accurately determining the certificate status. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the embodiments of the present application or the implementation manners in related technologies, the following will briefly introduce the drawings required to be used in the description of the embodiments or related technologies. Obviously, the following drawings are some embodiments of the present application. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.

[0027] Figure 1 FIG. [X] is a schematic structural diagram of a certificate status query system provided by an embodiment of the present application;

[0028] Figure 2 FIG. [X] is a detailed schematic diagram of a certificate status query process provided by an embodiment of the present application;

[0029] Figure 3 FIG. [X] is a schematic diagram of a certificate status query process provided by an embodiment of the present application;

[0030] Figure 4 FIG. [X] is a schematic diagram of a certificate status query process provided by an embodiment of the present application;

[0031] Figure 5 A schematic structural diagram of a certificate status query device provided by an embodiment of the present application;

[0032] Figure 6 A schematic structural diagram of a certificate status query device provided by an embodiment of the present application;

[0033] Figure 7 A schematic structural diagram of an electronic device provided by the present application. Detailed implementation manners

[0034] The present application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.

[0035] In order to ensure the privacy of users when querying the certificate status, an embodiment of the present application provides a certificate status query system, method, device, equipment and medium.

[0036] In an embodiment of the present application, the certificate status query system includes a terminal and a server. The terminal uses a first preset algorithm to determine a first target row in the certificate status matrix stored in the server where the certificate number to be queried is stored, and uses a second preset algorithm to determine a first target column in the certificate status matrix stored in the server where the certificate number to be queried is stored. The terminal uses a preset query rule to use the first target row or the first target column as a query item, and sends the information of the query item to the server. The server obtains each candidate identifier recorded in the first target row or the first target column in the certificate status query matrix according to the information of the query item and the preset query rule, and sends each candidate identifier included in the first target row or the first target column and the serial number of the corresponding column or row to the terminal. The terminal obtains a target identifier corresponding to the serial number of the first target column or the first target row among each candidate identifier and the serial number of the corresponding column or row, and determines whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0037] Embodiment 1:

[0038] Figure 1 A schematic structural diagram of a certificate status query system provided by an embodiment of the present application. The certificate status query system includes: a terminal ⑽1 and a server ⑽2;

[0039] The terminal 101 is configured to use a first preset algorithm and the certificate number to be queried to determine a first target row in the certificate status matrix stored in the server where the certificate number to be queried is located, and use a second preset algorithm and the certificate number to be queried to determine a first target column in the certificate status matrix where the certificate number to be queried is located. According to a preset query rule, the first target row or the first target column is used as a query item, and the information of the query item is sent to the server 102;

[0040] The server 102 is configured to obtain each candidate identifier included in the first target row or the first target column in the certificate status matrix according to the information of the query item and a preset query rule, and send each candidate identifier and the serial number of the corresponding column or row to the terminal 101;

[0041] The terminal 101 is further configured to obtain a target identifier with the serial number being the first target column or the first target row from each received candidate identifier and the serial number of the corresponding column or row, and determine whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0042] In an embodiment of the present application, for querying the certificate status, a certificate status query system includes a terminal 101 and a server 102, where the terminal 101 is connected to the server 102.

[0043] In an embodiment of the present application, when a user operates the terminal to access a certain website, the terminal needs to first query the certificate status of the certificate corresponding to the website, that is, query whether the certificate corresponding to the website is revoked. Specifically, the terminal can obtain the certificate number of the certificate corresponding to the website according to the information of the website, such as the address of the website, and determine the certificate number to be queried. Specifically, how the terminal obtains the certificate number of the certificate corresponding to the website according to the information of the website is the prior art and will not be elaborated herein.

[0044] In an embodiment of the present application, a certificate status matrix can be pre-stored in the server. For each certificate number, an identifier corresponding to the certificate number is stored in the certificate status matrix, and the identifier can represent the certificate status corresponding to the certificate number. The certificate status includes revoked and not revoked. The identifier indicating that the certificate corresponding to the certificate number is revoked and the identifier indicating that the certificate status is not revoked are different arbitrary values. For example, the identifier indicating that the certificate corresponding to the certificate number is revoked can be 1, and the identifier indicating that the certificate corresponding to the certificate number is not revoked can be 0. In an embodiment of the present application, each certificate number corresponds to an identifier recorded in a certain row and a certain column in the certificate status matrix.

[0045] After obtaining the certificate number to be queried, the terminal can use the first preset algorithm and the certificate number to be queried to determine the first target row where the identifier corresponding to the certificate number to be queried is stored in the certificate status matrix. Here, the first target row refers to the serial number of the row where the identifier corresponding to the certificate number to be queried is located in the certificate status matrix. The method for the terminal to use the first preset algorithm and the certificate number to be queried to determine the first target row where the identifier corresponding to the certificate number to be queried is stored in the certificate status matrix can be: determine the ratio of the certificate number to be queried to the first preset value, and determine the value obtained by rounding up this ratio as the first target row. Here, the first preset value can be a value less than or equal to the number of columns of the certificate status matrix.

[0046] After obtaining the certificate number to be queried, the terminal can also use the second preset algorithm and the certificate number to be queried to determine the first target column where the identifier corresponding to the certificate number to be queried is stored in the certificate status matrix. Here, the first target column refers to the serial number of the column where the identifier corresponding to the certificate number to be queried is located in the certificate status matrix. The method for the terminal to use the second preset algorithm and the certificate number to be queried to determine the first target column where the identifier corresponding to the certificate number to be queried is stored in the certificate status matrix can be: obtain the remainder after performing a division operation on the certificate number to be queried and the first preset value, and determine this remainder as the first target column.

[0047] After the terminal determines the first target row and the first target column corresponding to the certificate number to be queried, the terminal can, according to the preset query rule, use the first target row or the first target column as the query item. Here, the preset rule can set the row as the query item or set the column as the query item. For example, if the preset rule is to set the row as the query item, then the terminal can use the first target row as the query item. After the terminal determines the query item, it sends the information of the query item to the server. Specifically, the terminal can directly send this query item to the server, for example, directly send the first target row or the first target column. For example, if the terminal determines that the certificate number to be queried is stored in the first row and the second column in the certificate status matrix of the server, it can use the second column as the query item. Then the terminal can send the information of the query item, such as "2" or "the second column", to the server.

[0048] After the server obtains the information of the query item sent by the terminal, it can obtain each candidate identifier included in the first target row or the first target column in the certificate status matrix according to the information of the query item and the preset query rule. Specifically, if the query item is the first target row, the server can obtain each identifier recorded in the first target row of the certificate status matrix that represents the certificate status corresponding to the certificate number, and use each obtained identifier as a candidate identifier; if the query item is the first target column, the server can obtain each identifier recorded in the first target column of the certificate status matrix, and use each obtained identifier as a candidate identifier. Taking the information of the query item as "the second column" as an example, the server obtains each identifier recorded in the second column in the certificate status matrix, and uses each of these identifiers as a candidate identifier.

[0049] After the server obtains each candidate identifier included in the first target row or the first target column, it sends each candidate identifier included in the first target row and the first target column, and the serial number of the column or row where each candidate identifier is located, to the terminal.

[0050] After the terminal receives each candidate identifier sent by the server and the serial number of the column or row where each candidate identifier is located, it can obtain, from each received candidate identifier and the corresponding serial number of the column or row, the candidate identifier corresponding to the serial number of the first target column or the first target row, and determine this candidate identifier as the target identifier. This target identifier can be used to represent the certificate status of the certificate number corresponding to the first target row and the first target column in the certificate status matrix. The identifier recorded in the first target row and the first target column in the certificate status matrix is the identifier representing the certificate status corresponding to the certificate number to be queried. Therefore, the terminal can determine whether the certificate corresponding to the certificate number to be queried is revoked according to this target identifier.

[0051] In the embodiment of the present application, if the terminal uses the first target row as the query item, the server can obtain each candidate identifier recorded in the first target row of the certificate status matrix, and the serial number of the column where each candidate identifier is located. The terminal obtains, from each candidate identifier and the serial number of the column where it is located, the candidate identifier corresponding to the serial number of the column being the first target column, and uses this candidate identifier as the target identifier.

[0052] After obtaining this target identifier, the terminal can determine, according to this target identifier, whether the certificate corresponding to the certificate number to be queried is revoked. Specifically, the method for determining whether the certificate corresponding to the certificate number to be queried is revoked can be: determining whether this target identifier is a pre-stored identifier used to indicate that the certificate is revoked. If this target identifier is a pre-stored identifier used to indicate that the certificate is revoked, it is determined that the certificate corresponding to the certificate number to be queried is revoked. If this target identifier is a pre-stored identifier used to indicate that the certificate is not revoked, it is determined that the certificate corresponding to the certificate number to be queried is not revoked.

[0053] Since in the embodiments of the present application, the terminal determines that the certificate number to be queried is stored in the first target row and the first target column in the certificate status matrix, and the terminal uses the obtained first target row or the first target column as the query item and sends the information of the query item to the server, and the terminal does not directly send the certificate number to be queried. Therefore, in the embodiments of the present application, when querying the certificate status, even if the information of the query item is intercepted, the device that obtains the information of the query item cannot determine the certificate number to be queried, thereby avoiding the problem of user privacy leakage caused by the leakage of the certificate number to be queried. In addition, what the server sends to the terminal are candidate identifiers, and the terminal can obtain the target identifier of the certificate status corresponding to the certificate number to be queried, so as to accurately determine the certificate status.

[0054] Embodiment 2:

[0055] In order to accurately query the certificate status, on the basis of the above embodiments, in the embodiments of the present application, the server 102 is further configured to, if receiving a revoked certificate number, use the first preset algorithm and the revoked certificate number to determine the second target row in which the revoked certificate number is stored in the certificate status matrix, and use the second preset algorithm and the revoked certificate number to determine the second target column in which the revoked certificate number is stored in the certificate status matrix, and modify the identifier recorded in the second target row and the second target column in the certificate status matrix to a revocation identifier.

[0056] In the embodiments of the present application, a certificate status matrix is pre-stored in the server. For each certificate number, an identifier corresponding to the certificate number is stored in the certificate status matrix, and the identifier represents the certificate status corresponding to the certificate number. The certificate status includes revoked and not revoked, and the identifier indicating that the certificate corresponding to the certificate number is revoked and the identifier indicating that the certificate status is not revoked are different arbitrary values. For example, the identifier indicating that the certificate corresponding to the certificate number is revoked can be 1, and the identifier indicating that the certificate corresponding to the certificate status is not revoked can be 0. In the embodiments of the present application, each certificate number corresponds to an identifier recorded in a certain row and a certain column in the certificate status matrix.

[0057] In the embodiments of the present application, when a certain certificate is revoked, the server will receive the certificate number of the revoked certificate. For the sake of description, this certificate number is referred to as the revoked certificate number. The server mentioned in the embodiments of the present application may be a Certificate Status Server (CSS), and the revoked certificate number may be sent from a Certificate Authority (CA) server to the Certificate Status Server.

[0058] In an embodiment of the present application, if the server receives a revoked certificate number, the server modifies the identifier corresponding to the certificate number in the certificate status matrix to a pre - saved revocation identifier. Specifically, the server can use a first preset algorithm and the revoked certificate number to determine the second target row in the certificate status matrix where the identifier corresponding to the revoked certificate number is stored. The second target row can be the serial number of the row where the identifier corresponding to the revoked certificate number is located in the certificate status matrix. The method for the server to use the first preset algorithm and the revoked certificate number to determine the second target row in the certificate status matrix can be: determining the ratio of the revoked certificate number to a first preset value, and determining the value obtained by rounding up the ratio as the second target row, where the first preset value can be a value less than or equal to the number of columns of the certificate status matrix.

[0059] And the terminal can also use a second preset algorithm and the revoked certificate number to determine the second target column in the certificate status matrix where the identifier corresponding to the revoked certificate number is stored. The second target column can be the serial number of the column where the identifier corresponding to the revoked certificate number is located in the certificate status matrix. The method for the server to use the second preset algorithm and the revoked certificate number to determine the second target column in the certificate status matrix can be: obtaining the remainder after performing a division operation on the revoked certificate number and the first preset value, and determining the remainder as the second target column.

[0060] After determining the second target row and the second target column in the certificate status matrix where the identifier corresponding to the revoked certificate number is stored, the server can obtain the identifier recorded in the second target row and the second target column of the certificate status matrix, and modify the identifier to the revocation identifier. The revocation identifier can be any preset identifier, for example, it can be "1". It should be noted that each identifier in the certificate status matrix saved in the server is initially the identifier corresponding to not being revoked. When a certain revoked certificate number is received, the identifier corresponding to the revoked certificate number is modified to the revocation identifier.

[0061] Since in an embodiment of the present application, after the server receives a revoked certificate number, it modifies the identifier corresponding to the revoked certificate number in the certificate status matrix to the revocation identifier, it can ensure that the certificate status matrix accurately records the status of each certificate corresponding to the certificate number, which is convenient for subsequent query of the certificate status.

[0062] Embodiment 3:

[0063] In order to accurately query the certificate status corresponding to the certificate number to be queried, based on the above embodiments, in an embodiment of the present application, the terminal 101 is specifically configured to determine the first target row according to the ratio of the certificate number to be queried to the number of columns of the pre - saved certificate status matrix.

[0064] In the embodiments of the present application, when the terminal determines the first target row in which the identifier corresponding to the certificate number to be queried is stored in the certificate status matrix, it may obtain the number of columns of the pre-stored certificate status matrix, and obtain the ratio of the certificate number to be queried to the number of columns, and determine the first target row in which the identifier corresponding to the certificate number to be queried is stored in the certificate status matrix according to the ratio. Specifically, the terminal may determine the value obtained by rounding up the ratio as the first target row, or may determine the value obtained by rounding down the ratio, and determine the sum value of the value and a second preset value as the first target row, and the second preset value may be any integer not less than 1, for example, it may be 1.

[0065] The formula for the terminal to determine the first target row in which the identifier corresponding to the certificate number to be queried is stored in the certificate status matrix may be:

[0066]

[0067] where a is the first target row in which the identifier corresponding to the certificate number to be queried is stored in the certificate status matrix, A is the certificate number to be queried, t is the number of columns of the pre-stored certificate status matrix, and 1 is the second preset value.

[0068] In the embodiments of the present application, the method for the server to determine the second target row in which the identifier corresponding to the revoked certificate number is stored in the certificate status matrix by using the first preset algorithm and the revoked certificate number may also be: obtaining the number of columns of the pre-stored certificate status matrix, and determining the second target row in which the identifier corresponding to the revoked certificate number is stored in the certificate status matrix according to the ratio of the revoked certificate number to the number of columns. Specifically, the terminal may determine the value obtained by rounding up the ratio as the second target row, or may determine the value obtained by rounding down the ratio, and determine the sum value of the value and a second preset value as the second target row, and the second preset value may be 1.

[0069] In order to accurately query the certificate status corresponding to the certificate number to be queried, based on the above embodiments, in the embodiments of the present application, the terminal 101 is specifically configured to determine the remainder after dividing the certificate number to be queried by the number of columns of the pre-stored certificate status matrix as the first target column.

[0070] In the embodiments of the present application, when the terminal determines the first target column in which the identifier corresponding to the certificate number to be queried is stored in the certificate status matrix, it may obtain the number of columns of the pre-stored certificate status matrix, and obtain the remainder after dividing the certificate number to be queried by the number of columns, and determine the remainder as the first target column.

[0071] The formula for the terminal to determine the first target column in which the identifier corresponding to the certificate number to be queried is stored in the certificate status matrix may be:

[0072] b = A mod t

[0073] Wherein, b is the first target column in the certificate status matrix where the identifier corresponding to the certificate number to be queried is stored, A is the certificate number to be queried, and t is the number of columns of the pre-stored certificate status matrix.

[0074] According to the above description, the first target row and the first target column in the certificate status matrix where the identifier corresponding to the certificate number to be queried is stored satisfy A = (a - 1) * t + b. Wherein, A is the certificate number to be queried, a is the first target row in the certificate status matrix where the identifier corresponding to the certificate number to be queried is stored, 1 is the second preset value, t is the number of columns of the pre-stored certificate status matrix, and b is the first target column in the certificate status matrix where the identifier corresponding to the certificate number to be queried is stored. According to A = (a - 1) * t + b, when the first target row and the first target column are not completely the same, the corresponding certificate numbers are different. Therefore, each identifier in the certificate status matrix represents only the status of the certificate corresponding to one certificate number.

[0075] In the embodiment of the present application, the method for the server to determine the second target column in the certificate status matrix where the identifier corresponding to the revoked certificate number is stored by using the second preset algorithm may be: obtain the number of columns of the pre-stored certificate status matrix, and determine the remainder after dividing the certificate number to be queried by the number of columns as the second target column.

[0076] In the embodiment of the present application, the revoked certificate number also satisfies A' = (a' - 1) * t + b'. Wherein, A' is the revoked certificate number, a' is the second target row in the certificate status matrix where the identifier corresponding to the revoked certificate number is stored, 1 is the second preset value, t is the number of columns of the pre-stored certificate status matrix, and b' is the second target column in the certificate status matrix where the identifier corresponding to the revoked certificate number is stored. When the certificate with the certificate number A' = (a' - 1) * t + b' is revoked, the server modifies the identifier recorded in the second target row and the second target column in the certificate status matrix to the revocation identifier.

[0077] Embodiment 4:

[0078] In order to accurately determine the information of the query item, based on the above embodiments, in the embodiments of the present application, the terminal 101 is specifically configured to generate a first preset number of prime numbers, generate non-prime numbers according to the generated prime numbers, determine a first target value and a second preset number of second target values, where the first target value is less than the non-prime number and is a quadratic non-residue (QNR) of the non-prime number, each of the second target values is a quadratic residue (QR) of the non-prime number, and the sum of the number of the first target values and the second preset number is the number of rows or columns of the pre-stored certificate status matrix; generate a column matrix or a row matrix corresponding to the first target value and the second preset number of second target values, where the row or column where the first target value is located in the column matrix or the row matrix is the first target row or the first target column, and determine the column matrix or the row matrix as the information of the query item.

[0079] In the embodiments of the present application, if the terminal directly sends the query item to the server, that is, the terminal directly sends the first target row or the first target column to the server, if the query item is intercepted, the device that obtains the query item may still cause partial information leakage if it knows the first preset algorithm and the second preset algorithm.

[0080] Therefore, in the embodiments of the present application, certain processing can be performed on the query item. Specifically, the terminal can generate a second preset number of prime numbers, generate non-prime numbers according to the generated prime numbers, specifically, it can be determined that the product of the generated prime numbers is the non-prime number. Wherein, the second preset number is usually 2, and the length of the generated prime numbers is related to the preset security parameter, specifically, the preset security parameter is the ratio of the preset security parameter to 2.

[0081] In the embodiments of the present application, the terminal also determines a first target value, where the first target value is less than the non-prime number and is a QNR of the non-prime number, and the terminal can generate a second preset number of second target values, where each of the second target values is a QR of the non-prime number, and the sum of the second preset number and the number of the first target values is the number of rows or columns of the pre-stored certificate status matrix. The number of the first target values is 1, so the second preset number is the difference between the number of rows or columns of the pre-stored certificate status matrix and 1. Wherein, if the query item is the first target row, the sum of the second preset number and the number of the first target values is the number of rows of the pre-stored certificate status matrix; if the query item is the first target column, the sum of the second preset number and the number of the first target values is the number of columns of the pre-stored certificate status matrix.

[0082] Among them, in the embodiments of the present application, when determining whether a certain value is a QR of a non-prime number, since the non-prime number is determined based on two prime numbers and these two prime numbers are known, it is possible to determine whether the value is a QR of the non-prime number, that is, whether the value is a QR of the non-prime number is computable. Therefore, in the embodiments of the present application, it is required to determine a non-prime number based on a second preset number of prime numbers.

[0083] In the embodiments of the present application, the way for the terminal to determine that a certain value is a QR of a non-prime number is: If Among them, gcd(N,x) represents the greatest common divisor of N and x, and satisfies ω 2 = y mod N, then Q N (y) = 0, and it is said that y is a QR of N; otherwise Q N (y) = 1, and it is said that y is a QNR of N.

[0084] In addition, the way to determine that a certain value is a QR of a non-prime number can also be: Determine to be 1 or -1. If when, y is a QNR of N. When when, the probability that y is a QR and a QNR of N is the same. Among them, represents the Jacobi symbol. When N is a non-prime number, even if the factorization result of N is not known, the value of can be calculated in polynomial time.

[0085] After the terminal determines the first target value and the second preset number of second target values, the terminal can generate a column matrix or a row matrix corresponding to the first target value and the second preset number of second target values. Among them, the row or column where the first target value is located in the column matrix or the row matrix is the first target row or the first target column. That is to say, the row where the first target value is located in the column matrix is the first target row, or the column where the first target value is located in the row matrix is the first target column. The serial numbers of the rows or columns where the second preset number of second target values are located in the column matrix or the row matrix are random. The terminal determines the column matrix or the row matrix as the information of the query item. If the server generates a row matrix, the server can send the row matrix [z1,z2…z s to the terminal after generating the row matrix. Among them, if the query item is the first target row, the row where the first target value is located in the generated column matrix is the first target row; if the information of the query item is the first target column, the column where the first target value is located in the row matrix is the first target column. For example, if the query item is the second column, the column where the first target value is located in the row matrix is the second column.

[0086] Embodiment 5:

[0087] In order to accurately determine the candidate identifiers corresponding to each row or each column in the certificate status matrix, based on the above embodiments, in the embodiments of the present application, the server 102 is specifically configured to, for each column or each row in the certificate status matrix, obtain each identifier recorded in this column or this row in the certificate status matrix, and for each identifier, obtain the value recorded in the row that is the same as the row where this identifier is located in the column matrix, or the value recorded in the column that is the same as the column where this identifier is located in the row matrix, and determine whether this identifier is a pre - saved revocation identifier. If so, determine that this value is the value corresponding to this identifier; if not, determine that the square of this value is the value corresponding to this identifier; determine the product of the values corresponding to each identifier in this column or this row, and use this product as the candidate identifier corresponding to this column or this row in the first target row or the first target column.

[0088] In the embodiments of the present application, after the server receives the information of the query item sent by the terminal, that is, after receiving the row matrix or the column matrix sent by the terminal, it can, for each column or each row in the certificate status matrix, obtain each identifier recorded in this column or this row in the certificate status matrix. For each identifier recorded in this column or this row, obtain the value recorded in the row that is the same as the row where this identifier is located in the column matrix, or obtain the value recorded in the column that is the same as the column where this identifier is located in the row matrix, and determine whether this identifier is a pre - saved revocation identifier. If this identifier is a pre - saved revocation identifier, then determine that this value remains unchanged; if this identifier is not a pre - saved revocation identifier, then update this value to the square value of this value. In this way, the server can determine the value corresponding to each identifier in this row.

[0089] Among them, if the information of the query item is the first target row, the server, for each column in the certificate status matrix, obtains each identifier recorded in this column. For each identifier, it obtains the value recorded in the row that is the same as the row where this identifier is located in the column matrix. If this identifier is in the first row of this column, it obtains the value recorded in the first row of the column matrix; if the information of the query item is the first target column, the server, for each row in the certificate status matrix, obtains each identifier recorded in this row. For each identifier, it obtains the value recorded in the column that is the same as the column where this identifier is located in the row matrix. If this identifier is in the first column of this row, it obtains the value recorded in the first column of the row matrix.

[0090] Taking the information of the query item being the first target column as an example, the formula for the server to determine the value corresponding to a certain identifier recorded in a certain row after the certificate status matrix can be:

[0091]

[0092] Among them, ω r,j is the value corresponding to this identifier, r is the row where this identifier is located, j is the column where this identifier is located, Mr,j is the identifier, where 0 is the pre - saved non - revoked identifier, 1 is the pre - saved revocation identifier, and y j is the value recorded in the column of the received row matrix that is the same as the column where the identifier is located.

[0093] For each column or row in the certificate status matrix, after the server obtains the value corresponding to each identifier in that column or row, the server can determine the product of the values corresponding to each identifier in that column or row, and use the determined product as the candidate identifier corresponding to that column or row. In this way, the server can determine the candidate identifier corresponding to each row or column in the certificate status matrix.

[0094] After the server obtains the value corresponding to each identifier in a certain row or column, the formula for determining the candidate identifier corresponding to that row or column can be:

[0095]

[0096] where z r is the candidate identifier corresponding to that row or column, r is that row or column, j is the column or row where each identifier in that row or column is located, t is the total number of identifiers included in that row or column, which is the number of columns or rows of the certificate status matrix, and ω r,j is the value corresponding to the identifier recorded in column j or row j of that row or column.

[0097] Taking the information of the query item sent to the server as an example of the row matrix corresponding to the first target column, it is worth noting that the square of the QNR of a non-prime number is the QR of the non-prime number, and the square of the QR of a non-prime number is also the QR of the non-prime number. Since the first target value is recorded in the first target column of the row matrix, and this first target value is the QNR of the non-prime number, when the identifier recorded in the first target column of a certain row in the certificate status matrix is the non-revoked identifier, the determined value corresponding to this identifier is the square of the value in the first target column of this row matrix, that is, the square of the first target value. Therefore, the determined value corresponding to this identifier is the QR of the non-prime number; when the identifier recorded in the first target column of a certain row in the certificate status matrix is the revoked identifier, the determined value is the value in the first target column of the row matrix, that is, the first target value. Therefore, the determined value corresponding to this identifier is the QNR of the non-prime number; when the identifier recorded in other columns except the first target column of a certain row in the certificate status matrix is the non-revoked identifier, the determined value corresponding to this identifier is the square of the value in the non-first target column of the row matrix, that is, the square of a certain second target value. Therefore, the determined value corresponding to this identifier is the QR of the non-prime number; when the identifier recorded in the non-first target column of a certain row in the certificate status matrix is the revoked identifier, the determined value corresponding to this identifier is the value in the non-first target column of the row matrix, that is, the determined value corresponding to this identifier is a certain second target value. Therefore, the determined value is the QR of the non-prime number. That is to say, only when the identifier recorded in the first target column of a certain row is the revoked identifier, the determined value is the QNR of the non-prime number.

[0098] In addition, wherein, represents exclusive OR. If Q N (xy) = 0, then xy is QR. If Q N (xy) ≠ 0, then xy is QNR. That is, if and only if one of x and y is QNR, xy is QNR. Therefore, when determining the product of the values corresponding to each identifier in a certain row, that is, when determining the candidate identifier of a certain row, only when the identifier recorded in the first target column of this row is the revoked identifier, the determined product is the QNR of the non-prime number. Therefore, in the embodiments of the present application, it is possible to determine whether the identifier recorded in the first target column of this row is the revoked identifier through the candidate identifier of a certain row. Similarly, in the embodiments of the present application, it is also possible to determine whether the identifier recorded in the first target row of a certain column is the revoked identifier through the candidate identifier of a certain column.

[0099] Embodiment 5:

[0100] In order to accurately determine whether the certificate corresponding to the certificate number to be queried is revoked, based on the above embodiments, in the embodiments of the present application, the terminal 101 is specifically configured to determine whether the target identifier is a non-prime QNR. If so, it is determined that the certificate corresponding to the certificate number to be queried is revoked. If not, it is determined that the certificate corresponding to the certificate number to be queried is not revoked.

[0101] In the embodiments of the present application, after the terminal obtains the target identifier, it can determine whether the target identifier is a non-prime QNR generated. If the target identifier is a non-prime QNR generated, it means that the identifier recorded in the first target row and the first target column of the certificate status matrix is the revoked identifier, and it is determined that the certificate corresponding to the certificate number to be queried is revoked. If the target identifier is not a non-prime QR generated, it is determined that the certificate corresponding to the certificate number to be queried is not revoked.

[0102] Among them, when the factors of a non-prime number are known, how to determine whether a value is a QNR of the non-prime number is the prior art and will not be elaborated here.

[0103] Figure 2 FIG. is a detailed schematic diagram of a certificate status query process provided by the embodiments of the present application. Figure 2 Taking the query item as the first target column as an example, the process includes the following steps:

[0104] S201: The terminal uses a first preset algorithm to determine the first target row in which the certificate number to be queried is stored in the certificate status matrix in the server, and uses a second preset algorithm to determine the first target column in which the certificate number to be queried is stored in the certificate status matrix.

[0105] S202: The terminal generates a non-prime number and determines a first target value and a second preset number of second target values.

[0106] Among them, the terminal can generate two prime numbers and determine the product of the two prime numbers as a non-prime number.

[0107] S203: The terminal generates a row matrix corresponding to the first target value and the second preset number of second target values, and sends the row matrix to the server.

[0108] Among them, the value recorded in the first target column of the row matrix is the first target value.

[0109] S204: For each row in the certificate status matrix, the server obtains each identifier recorded in this row of the certificate status matrix. For each identifier, the server obtains the value recorded in the column of the row matrix that is the same as the column where this identifier is located, and determines whether this identifier is a pre - saved revocation identifier. If so, it determines that this value is the value corresponding to this identifier; if not, it determines that the square of this value is the value corresponding to this identifier. The server determines the product of the values corresponding to each identifier in this row, and uses this product as the candidate identifier corresponding to this row in the first target column.

[0110] S205: The server sends each candidate identifier and the serial number of the row where it is located to the terminal.

[0111] S206: The terminal obtains the target identifier with the serial number of the first target row from each received candidate identifier and the corresponding serial number of the row where it is located.

[0112] S207: The terminal determines whether the target identifier is a non - prime QR. If so, it executes S208; if not, it executes S209.

[0113] S208: Determine that the certificate corresponding to the certificate number to be queried is not revoked.

[0114] S209: Determine that the certificate corresponding to the certificate number to be queried is revoked.

[0115] Embodiment 6:

[0116] Based on the above embodiments, the present application further provides a method for querying the certificate status. Figure 3 This is a schematic diagram of a process for querying the certificate status provided by an embodiment of the present application. As Figure 3 shown, the method includes:

[0117] S301: Using a first preset algorithm and the certificate number to be queried, determine the first target row where the certificate number to be queried is stored in the certificate status matrix in the server, and using a second preset algorithm and the certificate number to be queried, determine the first target column where the certificate number to be queried is stored in the certificate status matrix.

[0118] S302: According to a preset query rule, use the first target row or the first target column as a query item, and send the information of the query item to the server; so that the server, according to the information of the query item and the preset query rule, obtains each candidate identifier included in the first target row or the first target column in the certificate status matrix, and sends each candidate identifier and the corresponding serial number of the column or row where it is located to the terminal.

[0119] S303: Among each received candidate identifier and the serial number of the corresponding column or row where it is located, obtain the target identifier with the serial number of the first target column or the first target row, and determine whether the certificate corresponding to the certificate number to be queried has been revoked according to the target identifier.

[0120] In a possible implementation manner, the determining the first target row where the certificate number to be queried is stored in the certificate status matrix in the server by using the first preset algorithm and the certificate number to be queried includes:

[0121] Determine the first target row according to the ratio of the certificate number to be queried to the number of columns of the pre-stored certificate status matrix.

[0122] In a possible implementation manner, the determining the first target column where the certificate number to be queried is stored in the certificate status matrix by using the second preset algorithm and the certificate number to be queried includes:

[0123] Determine the remainder after performing a division operation on the certificate number to be queried and the number of columns of the pre-stored certificate status matrix as the first target column.

[0124] In a possible implementation manner, the method further includes:

[0125] Generate a first preset number of prime numbers, generate non-prime numbers according to the generated prime numbers, determine a first target value and a second preset number of second target values, where the first target value is less than the non-prime number and is the QNR of the non-prime number, each second target value is the QR of the non-prime number, and the sum of the number of the first target values and the second preset number is the number of rows or columns of the pre-stored certificate status matrix; generate a column matrix or a row matrix corresponding to the first target value and the second preset number of second target values, where the row or column where the first target value is located in the column matrix or the row matrix is the first target row or the first target column, and determine the column matrix or the row matrix as the information of the query item.

[0126] In a possible implementation manner, the determining whether the certificate corresponding to the certificate number to be queried has been revoked according to the target identifier includes:

[0127] Judge whether the target identifier is the QNR of the non-prime number. If so, determine that the certificate corresponding to the certificate number to be queried has been revoked. If not, determine that the certificate corresponding to the certificate number to be queried has not been revoked.

[0128] This method is applied to a terminal. Specifically, the process of the terminal executing this certificate status query method can refer to the above other embodiments, and the specific content will not be elaborated here.

[0129] Based on the above embodiments, the present application further provides a method for querying the certificate status. Figure 4 As shown in the schematic diagram of the certificate status query process provided by the embodiments of the present application, Figure 4 as shown, the method includes:

[0130] S401: According to the information of the query item and the preset query rule, obtain each candidate identifier included in the first target row or the first target column in the certificate status matrix; wherein, the information of the query item is that the terminal uses the first preset algorithm and the certificate number to be queried to determine the first target row in which the certificate number to be queried is stored in the certificate status matrix in the server, and uses the second preset algorithm and the certificate number to be queried to determine the first target column in which the certificate number to be queried is stored in the certificate status matrix. According to the preset query rule, use the first target row or the first target column as the query item, and send the information of the query item to the server;

[0131] S402: Send each candidate identifier and the corresponding serial number of the column or row to the terminal; so that the terminal obtains the target identifier with the serial number being the first target column or the first target row among the received each candidate identifier and the corresponding serial number of the column or row, and determines whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0132] In a possible implementation manner, the method further includes:

[0133] If a revoked certificate number is received, use the first preset algorithm and the revoked certificate number to determine the second target row in which the revoked certificate number is stored in the certificate status matrix, and use the second preset algorithm and the revoked certificate number to determine the second target column in which the revoked certificate number is stored in the certificate status matrix;

[0134] Modify the identifier recorded in the second target row and the second target column in the certificate status matrix to a revocation identifier.

[0135] In a possible implementation manner, the obtaining each candidate identifier included in the first target row or the first target column in the certificate status matrix includes:

[0136] For each column or row in the certificate status matrix, obtain each identifier recorded in the column or row in the certificate status matrix. For each identifier, obtain the value recorded in the row in the column matrix that is the same as the row where the identifier is located, or the value recorded in the column in the row matrix that is the same as the column where the identifier is located, and determine whether the identifier is a pre - saved revocation identifier. If so, determine that the value is the value corresponding to the identifier. If not, determine that the square of the value is the value corresponding to the identifier; determine the product of the values corresponding to each identifier in the column or row, and use the product as the candidate identifier corresponding to the column or row in the first target row or the first target column.

[0137] This method is applied to a server. Specifically, the process of the server executing this certificate status query method can be referred to in the above - mentioned other embodiments, and the specific content will not be elaborated here.

[0138] Embodiment 7:

[0139] Figure 5 The following is a schematic structural diagram of a certificate status query device provided by an embodiment of the present application. The device includes:

[0140] A determination module 501, configured to use a first preset algorithm and a certificate number to be queried to determine a first target row in which the certificate number to be queried is stored in the certificate status matrix of the server, and use a second preset algorithm and the certificate number to be queried to determine a first target column in which the certificate number to be queried is stored in the certificate status matrix;

[0141] A first sending module 502, configured to use the first target row or the first target column as a query item according to a preset query rule, and send the information of the query item to the server;

[0142] A first processing module 503, configured to obtain a target identifier with a serial number being the first target column or the first target row from each received candidate identifier and the corresponding serial number of the column or row where it is located, and determine whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0143] In a possible implementation manner, the determination module 501 is specifically configured to determine the first target row according to the ratio of the certificate number to be queried to the number of columns of the pre - saved certificate status matrix.

[0144] In a possible implementation manner, the determination module 501 is specifically configured to determine the remainder obtained by performing a division operation on the certificate number to be queried and the number of columns of the pre - saved certificate status matrix as the first target column.

[0145] In a possible implementation, the first processing module 503 is further configured to generate a first preset number of prime numbers, generate non-prime numbers based on the generated prime numbers, determine a first target value and a second preset number of second target values, where the first target value is less than the non-prime number and is the QNR of the non-prime number, each second target value is the QR of the non-prime number, and the sum of the number of the first target values and the second preset number is the number of rows or columns of the pre-stored certificate status matrix; generate a column matrix or a row matrix corresponding to the first target value and the second preset number of second target values, where the row or column where the first target value is located in the column matrix or the row matrix is the first target row or the first target column, and determine the column matrix or the row matrix as the information of the query item.

[0146] In a possible implementation, the first processing module 503 is further configured to determine whether the target identifier is the QNR of the non-prime number. If so, it is determined that the certificate corresponding to the certificate number to be queried is revoked. If not, it is determined that the certificate corresponding to the certificate number to be queried is not revoked.

[0147] Figure 6 The following is a schematic structural diagram of a certificate status query device provided by an embodiment of the present application. The device includes:

[0148] A second processing module 601, configured to obtain each candidate identifier included in the first target row or the first target column in the certificate status matrix according to the information of the query item and a preset query rule;

[0149] A second sending module 602, configured to send each candidate identifier and the serial number of the corresponding column or row to the terminal.

[0150] In a possible implementation, the second processing module 601 is further configured to, if a revoked certificate number is received, use the first preset algorithm and the revoked certificate number to determine a second target row in which the revoked certificate number is stored in the certificate status matrix, and use the second preset algorithm and the revoked certificate number to determine a second target column in which the revoked certificate number is stored in the certificate status matrix; modify the identifier recorded in the second target row and the second target column in the certificate status matrix to a revocation identifier.

[0151] In a possible implementation manner, the second processing module 601 is specifically configured to, for each column or each row in the certificate status matrix, obtain each identifier recorded in this column or this row in the certificate status matrix, and for each identifier, obtain the value recorded in the row that is the same as the row where this identifier is located in the column matrix, or the value recorded in the column that is the same as the column where this identifier is located in the row matrix, and determine whether this identifier is a pre-stored revocation identifier. If so, determine that this value is the value corresponding to this identifier. If not, determine that the square of this value is the value corresponding to this identifier; determine the product of the values corresponding to each identifier in this column or this row, and use this product as the candidate identifier corresponding to this column or this row in the first target row or the first target column.

[0152] Embodiment 8:

[0153] Figure 7 The following is a schematic structural diagram of an electronic device provided by this application. On the basis of the above embodiments, an embodiment of the present invention further provides an electronic device, as Figure 7 shown, including: a processor 701, a communication interface 702, a memory 703, and a communication bus 704. Among them, the processor 701, the communication interface 702, and the memory 703 complete mutual communication through the communication bus 704;

[0154] A computer program is stored in the memory 703. When the program is executed by the processor 701, the processor 701 is caused to execute the following steps:

[0155] Using a first preset algorithm and the certificate number to be queried, determine the first target row in which the certificate number to be queried is stored in the certificate status matrix in the server, and use a second preset algorithm and the certificate number to be queried to determine the first target column in which the certificate number to be queried is stored in the certificate status matrix;

[0156] According to a preset query rule, use the first target row or the first target column as a query item, and send the information of the query item to the server; so that the server, according to the information of the query item and the preset query rule, obtains each candidate identifier included in the first target row or the first target column in the certificate status matrix, and sends each candidate identifier and the serial number of the corresponding column or row to the terminal;

[0157] Among the received each candidate identifier and the serial number of the corresponding column or row, obtain the target identifier with the serial number being the first target column or the first target row, and determine whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0158] Further, the processor 701 is specifically configured to determine the first target row according to the ratio of the certificate number to be queried to the number of columns of the pre-stored certificate status matrix.

[0159] Further, the processor 701 is specifically configured to determine the remainder obtained by dividing the certificate number to be queried by the number of columns of the pre-stored certificate status matrix as the first target column.

[0160] Further, the processor 701 is further configured to generate a first preset number of prime numbers, generate non-prime numbers according to the generated prime numbers, determine a first target value and a second preset number of second target values, where the first target value is less than the non-prime number and is the QNR of the non-prime number, each of the second target values is the QR of the non-prime number, and the sum of the number of the first target values and the second preset number is the number of rows or columns of the pre-stored certificate status matrix; generate a column matrix or a row matrix corresponding to the first target value and the second preset number of second target values, where the row or column where the first target value is located in the column matrix or the row matrix is the first target row or the first target column, and determine the column matrix or the row matrix as the information of the query item.

[0161] Further, the processor 701 is specifically configured to determine whether the target identifier is the QNR of the non-prime number. If so, it is determined that the certificate corresponding to the certificate number to be queried is revoked. If not, it is determined that the certificate corresponding to the certificate number to be queried is not revoked.

[0162] Based on the above embodiments, an embodiment of the present invention further provides an electronic device, including: a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus.

[0163] A computer program is stored in the memory. When the program is executed by the processor 701, the processor is caused to execute the following steps:

[0164] According to the information of the query item and a preset query rule, obtain each candidate identifier included in the first target row or the first target column in the certificate status matrix; where the information of the query item is that the terminal uses a first preset algorithm and the certificate number to be queried to determine the first target row where the certificate number to be queried is stored in the certificate status matrix in the server, and uses a second preset algorithm and the certificate number to be queried to determine the first target column where the certificate number to be queried is stored in the certificate status matrix. According to the preset query rule, the first target row or the first target column is used as the query item, and the information of the query item is sent to the server;

[0165] Send each of the candidate identifiers and the serial numbers of the corresponding columns or rows to the terminal; so that the terminal obtains, among the received candidate identifiers and the serial numbers of the corresponding columns or rows, the target identifier with the serial number of the first target column or the first target row, and determines whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0166] Further, the processor 701 is further configured to, if a revoked certificate number is received, use the first preset algorithm and the revoked certificate number to determine the second target row in which the revoked certificate number is stored in the certificate status matrix, and use the second preset algorithm and the revoked certificate number to determine the second target column in which the revoked certificate number is stored in the certificate status matrix;

[0167] Modify the identifier recorded in the second target column of the second target row in the certificate status matrix to a revocation identifier.

[0168] Further, the processor 701 is specifically configured to, for each column or each row in the certificate status matrix, obtain each identifier recorded in the column or the row in the certificate status matrix, and for each identifier, obtain the value recorded in the row in the column matrix that is the same as the row where the identifier is located, or the value recorded in the column in the row matrix that is the same as the column where the identifier is located, and determine whether the identifier is a pre-stored revocation identifier. If so, determine that the value is the value corresponding to the identifier. If not, determine that the square of the value is the value corresponding to the identifier; determine the product of the values corresponding to each identifier in the column or the row, and use the product as the candidate identifier corresponding to the column or the row in the first target row or the first target column.

[0169] The communication bus mentioned in the above server may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0170] The communication interface is used for communication between the above electronic device and other devices.

[0171] The memory may include a Random Access Memory (RAM), or may also include a Non-Volatile Memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.

[0172] The aforementioned processor may be a general-purpose processor, including a central processing unit, a Network Processor (NP), etc.; it may also be a Digital Signal Processing (DSP), an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0173] Example 9:

[0174] Based on the above embodiments, an embodiment of the present invention further provides a computer-readable storage medium, in which a computer program executable by an electronic device is stored. When the program runs on the electronic device, the electronic device is caused to execute the following steps when executing:

[0175] A computer program is stored in the memory. When the program is executed by the processor, the processor is caused to execute the following steps:

[0176] Using a first preset algorithm and the certificate number to be queried, determine the first target row in the certificate status matrix stored in the server where the certificate number to be queried is located, and use a second preset algorithm and the certificate number to be queried to determine the first target column in the certificate status matrix where the certificate number to be queried is located;

[0177] According to a preset query rule, use the first target row or the first target column as a query item, and send the information of the query item to the server; so that the server, according to the information of the query item and the preset query rule, obtains each candidate identifier included in the first target row or the first target column in the certificate status matrix, and sends the each candidate identifier and the serial number of the corresponding column or row to the terminal;

[0178] Among the received each candidate identifier and the serial number of the corresponding column or row, obtain the target identifier with the serial number being the first target column or the first target row, and determine whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0179] In a possible implementation manner, the determining of the first target row in which the certificate number to be queried is stored in the certificate status matrix in the server by using the first preset algorithm and the certificate number to be queried includes:

[0180] Determine the first target row according to the ratio of the certificate number to be queried to the number of columns of the pre-stored certificate status matrix.

[0181] In a possible implementation manner, the determining of the first target column in which the certificate number to be queried is stored in the certificate status matrix by using the second preset algorithm and the certificate number to be queried includes:

[0182] Determine the remainder obtained by performing a division operation on the certificate number to be queried and the number of columns of the pre-stored certificate status matrix as the first target column.

[0183] In a possible implementation manner, the method further includes:

[0184] Generate a first preset number of prime numbers, generate non-prime numbers according to the generated prime numbers, determine a first target value and a second preset number of second target values, where the first target value is less than the non-prime number and is the QNR of the non-prime number, each of the second target values is the QR of the non-prime number, and the sum of the number of the first target values and the second preset number is the number of rows or columns of the pre-stored certificate status matrix; generate a column matrix or a row matrix corresponding to the first target value and the second preset number of second target values, where the row or column in which the first target value is located in the column matrix or the row matrix is the first target row or the first target column, and determine the column matrix or the row matrix as the information of the query item.

[0185] In a possible implementation manner, the determining whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier includes:

[0186] Judge whether the target identifier is the QNR of the non-prime number. If so, determine that the certificate corresponding to the certificate number to be queried is revoked. If not, determine that the certificate corresponding to the certificate number to be queried is not revoked.

[0187] This method is applied to a terminal. Specifically, the process of the terminal executing this certificate status query method can refer to the above-mentioned other embodiments, and the specific content will not be elaborated here.

[0188] Based on the above embodiments, an embodiment of the present invention further provides a computer-readable storage medium, in which a computer program executable by a processor is stored. When the program runs on the processor, the processor is caused to execute the following steps when executed:

[0189] According to the information of the query item and the preset query rule, obtain each candidate identifier included in the first target row or the first target column in the certificate status matrix; wherein, the information of the query item is that the terminal uses a first preset algorithm and the certificate number to be queried to determine the first target row in which the certificate number to be queried is stored in the certificate status matrix in the server, and uses a second preset algorithm and the certificate number to be queried to determine the first target column in which the certificate number to be queried is stored in the certificate status matrix. According to the preset query rule, use the first target row or the first target column as the query item, and send the information of the query item to the server;

[0190] Send each candidate identifier and the serial number of the corresponding column or row to the terminal; so that the terminal obtains, among the received each candidate identifier and the serial number of the corresponding column or row, the target identifier with the serial number being the first target column or the first target row, and determines whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

[0191] In a possible implementation manner, the method further includes:

[0192] If a revoked certificate number is received, use the first preset algorithm and the revoked certificate number to determine the second target row in which the revoked certificate number is stored in the certificate status matrix, and use the second preset algorithm and the revoked certificate number to determine the second target column in which the revoked certificate number is stored in the certificate status matrix;

[0193] Modify the identifier recorded in the second target row and the second target column in the certificate status matrix to a revocation identifier.

[0194] In a possible implementation manner, the obtaining each candidate identifier included in the first target row or the first target column in the certificate status matrix includes:

[0195] For each column or each row in the certificate status matrix, obtain each identifier recorded in this column or this row in the certificate status matrix. For each identifier, obtain the value recorded in the row in the column matrix that is the same as the row where this identifier is located, or the value recorded in the column in the row matrix that is the same as the column where this identifier is located, and determine whether this identifier is a pre-saved revocation identifier. If so, determine that this value is the value corresponding to this identifier. If not, determine that the square of this value is the value corresponding to this identifier; determine the product of the values corresponding to each identifier in this column or this row, and use this product as the candidate identifier corresponding to this column or this row in the first target row or the first target column.

[0196] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.

[0197] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices produce means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0198] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0199] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0200] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. A certificate status query system, characterized in that, The system includes a terminal and a server; The terminal is used to determine a first target row in which the certificate number to be queried is stored in the certificate status matrix in the server by using a first preset algorithm and the certificate number to be queried, and determine a first target column in which the certificate number to be queried is stored in the certificate status matrix by using a second preset algorithm and the certificate number to be queried. According to a preset query rule, take the first target row or the first target column as a query item, and send the information of the query item to the server; The server is used to obtain each candidate identifier included in the first target row or the first target column in the certificate status matrix according to the information of the query item and a preset query rule, and send each candidate identifier and the serial number of the corresponding column or row to the terminal; The terminal is further used to obtain a target identifier with the serial number being the first target column or the first target row from each received candidate identifier and the serial number of the corresponding column or row, and determine whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

2. The system according to claim 1, wherein The server is further used to, if receiving a revoked certificate number, determine a second target row in which the revoked certificate number is stored in the certificate status matrix by using the first preset algorithm and the revoked certificate number, and determine a second target column in which the revoked certificate number is stored in the certificate status matrix by using the second preset algorithm and the revoked certificate number, and modify the identifier recorded in the second target row and the second target column in the certificate status matrix to a revocation identifier.

3. The system according to claim 1, wherein Specifically, the terminal is used to determine the first target row according to the ratio of the certificate number to be queried to the number of columns of the pre-stored certificate status matrix.

4. The system according to claim 1, characterized in that, Specifically, the terminal is used to determine the remainder obtained by dividing the certificate number to be queried by the number of columns of the pre-stored certificate status matrix as the first target column.

5. The system according to claim 1, wherein Specifically, the terminal is used to generate a first preset number of prime numbers, generate non-prime numbers according to the generated prime numbers, determine a first target value and a second preset number of second target values, where the first target value is less than the non-prime number and is a non-quadratic residue QNR of the non-prime number, each second target value is a quadratic residue QR of the non-prime number, and the sum of the number of the first target values and the second preset number is the number of rows or columns of the pre-stored certificate status matrix; Generate a column matrix or a row matrix corresponding to the first target value and the second preset number of second target values, where the row or column in which the first target value is located in the column matrix or the row matrix is the first target row or the first target column, and determine the column matrix or the row matrix as the information of the query item.

6. The system according to claim 5, wherein The server is specifically configured to, for each column or row in the certificate status matrix, obtain each identifier recorded in that column or row in the certificate status matrix. For each identifier, obtain the value recorded in the row that is the same as the row where the identifier is located in the column matrix, or the value recorded in the column that is the same as the column where the identifier is located in the row matrix, and determine whether the identifier is a pre-stored revocation identifier. If so, determine that the value is the value corresponding to the identifier; if not, determine that the square of the value is the value corresponding to the identifier. Determine the product of the values corresponding to each identifier in that column or row, and use the product as the candidate identifier corresponding to that column or row in the first target row or the first target column.

7. The system according to any one of claims 5 and 6, characterized in that, The terminal is specifically configured to determine whether the target identifier is a non-prime QNR. If so, determine that the certificate corresponding to the certificate number to be queried is revoked; if not, determine that the certificate corresponding to the certificate number to be queried is not revoked.

8. A method for querying the status of a certificate, characterized in that The method is applied to a terminal, and the method includes: Using a first preset algorithm and the certificate number to be queried, determine the first target row in which the certificate number to be queried is stored in the certificate status matrix in the server, and use a second preset algorithm and the certificate number to be queried to determine the first target column in which the certificate number to be queried is stored in the certificate status matrix. According to a preset query rule, use the first target row or the first target column as a query item, and send the information of the query item to the server; so that the server, according to the information of the query item and the preset query rule, obtains each candidate identifier included in the first target row or the first target column in the certificate status matrix, and sends each candidate identifier and the serial number of the corresponding column or row to the terminal. Among the received each candidate identifier and the serial number of the corresponding column or row, obtain the target identifier with the serial number being the first target column or the first target row, and determine whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

9. A method for querying certificate status, characterized in that, The method is applied to a server, and the method includes: Receive the information of the query item sent by the terminal, and according to the information of the query item and the preset query rule, obtain each candidate identifier included in the first target row or the first target column in the certificate status matrix; where the information of the query item is that the terminal uses a first preset algorithm and the certificate number to be queried to determine the first target row in which the certificate number to be queried is stored in the certificate status matrix in the server, and uses a second preset algorithm and the certificate number to be queried to determine the first target column in which the certificate number to be queried is stored in the certificate status matrix, and according to the preset query rule, uses the first target row or the first target column as a query item and sends the information of the query item to the server. Send each of the candidate identifiers and the serial numbers of the corresponding columns or rows to the terminal; so that the terminal, among the received candidate identifiers and the serial numbers of the corresponding columns or rows, obtains the target identifier with the serial number of the first target column or the first target row, and determines whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

10. A certificate status query device, characterized in that, The device includes: A determination module, configured to use a first preset algorithm and the certificate number to be queried to determine a first target row in which the certificate number to be queried is stored in the certificate status matrix in the server, and use a second preset algorithm and the certificate number to be queried to determine a first target column in which the certificate number to be queried is stored in the certificate status matrix; A first sending module, configured to use a preset query rule, use the first target row or the first target column as a query item, and send the information of the query item to the server; so that the server, according to the information of the query item and the preset query rule, obtains each candidate identifier included in the first target row or the first target column in the certificate status matrix, and sends each candidate identifier and the serial number of the corresponding column or row to the terminal; A processing module, configured to, among the received candidate identifiers and the serial numbers of the corresponding columns or rows, obtain the target identifier with the serial number of the first target column or the first target row, and determine whether the certificate corresponding to the certificate number to be queried is revoked according to the target identifier.

11. A certificate status query device, characterized in that, The device includes: A second processing module, configured to receive the information of the query item sent by the terminal, and obtain each candidate identifier included in the first target row or the first target column in the certificate status matrix according to the information of the query item and a preset query rule; wherein the information of the query item is that the terminal uses a first preset algorithm and the certificate number to be queried to determine a first target row in which the certificate number to be queried is stored in the certificate status matrix in the server, and uses a second preset algorithm and the certificate number to be queried to determine a first target column in which the certificate number to be queried is stored in the certificate status matrix, and according to the preset query rule, uses the first target row or the first target column as a query item and sends the information of the query item to the server; A second sending module, configured to send each candidate identifier and the serial number of the corresponding column or row to the terminal.

12. An electronic device, characterized in that, The electronic device includes at least a processor and a memory. When the processor executes a computer program stored in the memory, the steps of the certificate status query method according to any one of the above claims 8-9 are implemented.

13. A computer-readable storage medium, characterized in that, It stores a computer program, and when the computer program is executed by the processor, the steps of the certificate status query method according to any one of the above claims 8-9 are implemented.

Citation Information

Patent Citations

  • Online certificate state obtaining method and system for V2X and communication method

    CN111818482A

  • Certificate query method, apparatus and device, and computer readable storage medium

    CN112994897A