A digital certificate making method, system and application thereof

By combining cross-certification with third-party platforms and trusted hardware, cross-platform identity registration and login are generated for users. By using blockchain to manage digital certificates, the security and traceability issues of official seals and signatures are solved, realizing the efficient use of electronic seals and the traceability of identities.

CN115459922BActive Publication Date: 2026-01-20ADVANCED INST OF INFORMATION TECH (AIIT) PEKING UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211041582.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-29
Publication Date
2026-01-20
Estimated Expiration
2042-08-29

AI Technical Summary

Technical Problem

In existing technologies, official seals and signatures are at risk of being used in different locations, electronic seals are not widely accepted, and CA certificates cannot be directly bound to the signer, resulting in insufficient security and traceability.

Method used

By combining cross-certification with trusted hardware through third-party platforms, cross-platform self-registration, login, and digital certificate authority certificates are generated for users. The issuance and application of certificates are managed using blockchain to achieve traceability of identity.

Benefits of technology

It improves the security and traceability of official seals and signatures, simplifies user key management, and enables the efficient use of electronic seals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115459922B_ABST
    Figure CN115459922B_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a digital certificate manufacturing method and system and application thereof, and the method comprises the following steps: cross authentication of a third-party platform is utilized, and a cross-platform autonomous identity of a user is generated in combination with trusted hardware; cross authentication of the third-party platform is utilized, and cross-platform autonomous identity login of the user is generated in combination with the trusted hardware; cross authentication of the third-party platform is utilized, and a digital certificate certification authority certificate of the user is generated in combination with the trusted hardware. The blockchain is utilized to manage the issuance and application of the digital certificate, so that the security is ensured and traceability is possessed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of information security, and in particular to a digital certificate production method and system and application thereof. BACKGROUND

[0002] In the fields of production, finance, government affairs, etc., a public seal and signature are important links in management. The public seal is widely used and has a high frequency of use, and often faces the situation of using in different places. At the same time, the public seal and signature also have the risk of impersonation and forgery. Therefore, how to coordinate the use of the public seal and ensure its security has become a management problem for many organizations. Since the current electronic seal has not been widely accepted by the market, there are not many enterprises that can efficiently use the electronic seal.

[0003] A digital certificate authority (CA), also known as an electronic commerce certification center or an electronic commerce certification and authorization agency, is an authoritative agency responsible for issuing and managing digital certificates, and as a trusted third party in electronic commerce transactions, undertakes the responsibility of verifying the legality of public keys in the public key system. Usually, a CA certificate is issued by an authoritative agency, which highly depends on a centralized agency, which will cause a trust crisis and the risk of malicious attacks on the agency.

[0004] Ordinary digital seals and digital certificates lack CA certification, and traditional CAs can only be issued to the IT department of an organization, but cannot be issued to individuals, resulting in the inability of digital seals and digital certificates to establish direct contact with the actual signatory and the inability to guarantee the real-name nature of users. SUMMARY

[0005] Therefore, embodiments of the present application provide a digital certificate production method and system and application thereof, which utilize blockchain to manage the issuance and application of digital certificates, ensuring security while having traceability.

[0006] To achieve the above purpose, embodiments of the present application provide the following technical solutions:

[0007] According to a first aspect of the embodiments of the present application, a digital certificate production method is provided, which comprises:

[0008] Cross-certification by a third-party platform, combined with trusted hardware, generates a cross-platform autonomous identity registration for a user;

[0009] Cross-certification by a third-party platform, combined with trusted hardware, generates a cross-platform autonomous identity login for a user;

[0010] Cross-certification by a third-party platform, combined with trusted hardware, generates a digital certificate authority certificate for a user.

[0011] In a possible implementation, a third-party platform cross authentication is used to generate a digital certificate certification authority certificate for a user in combination with trusted hardware, including:

[0012] The user equipment generates a digital certificate certification authority certificate request through the trusted hardware according to a user key, and sends the request to the trusted hardware;

[0013] The trusted hardware sends the digital certificate certification authority certificate request to a superior user equipment;

[0014] After the superior user equipment logs in, it determines whether the user equipment has a certificate authority according to the digital certificate certification authority certificate request;

[0015] If the user equipment has the certificate authority, the superior user equipment sends a superior certificate signature to the trusted hardware;

[0016] The trusted hardware creates a digital certificate certification authority certificate for the user and sends the certificate to the user equipment.

[0017] In a possible implementation, the third-party platform cross authentication is used to generate a cross-platform autonomous identity registration for a user in combination with trusted hardware, including:

[0018] The user equipment selects local authentication information and a third-party platform as a main ID and sends the information to the trusted hardware to initiate a registration process;

[0019] The trusted device sends an invitation to the user equipment, inviting the user to use at least two third-party platforms authenticated by the user as identity cross authentication;

[0020] The user equipment initiates an identity authentication request to all third-party authentication platforms respectively;

[0021] All third-party authentication platforms send confirmation tokens to the trusted device respectively;

[0022] The trusted device confirms the identity again by sending the confirmation tokens to the third-party authentication platforms;

[0023] After confirming the identity, the third-party authentication platforms return the confirmed tokens to the trusted device;

[0024] When the trusted device receives the tokens returned by all third-party authentication platforms, the trusted device generates a key pair for the user.

[0025] In a possible implementation, the third-party platform cross authentication is used to generate a cross-platform autonomous identity login for a user in combination with trusted hardware, including:

[0026] The user equipment selects local authentication information and a third-party platform as a main ID and sends the information to the trusted hardware to initiate a login process;

[0027] The trusted device sends an invitation to the user device, inviting the user to use the part of the third-party platform authenticated by the user as identity cross authentication;

[0028] The user device initiates an identity authentication request to each of the part of the third-party authentication platform respectively;

[0029] Each of the part of the third-party authentication platform sends a confirmation token to the trusted device respectively;

[0030] The trusted device confirms the identity again by sending the confirmation token to the part of the third-party authentication platform;

[0031] After confirming the identity, each of the part of the third-party authentication platform returns the confirmed token to the trusted device;

[0032] When the trusted device receives all the tokens returned by the part of the third-party authentication platform, the trusted device restores the key pair for the user.

[0033] According to a second aspect of the embodiments of the present application, a digital certificate production system is provided, and the system comprises:

[0034] A registration module is configured to generate a cross-platform autonomous identity for a user by combining a trusted hardware and cross authentication of a third-party platform;

[0035] A real-name authentication module is configured to generate a cross-platform autonomous identity for a user by combining a trusted hardware and cross authentication of a third-party platform;

[0036] A digital certificate generation module is configured to generate a digital certificate authority certificate for a user by combining a trusted hardware and cross authentication of a third-party platform.

[0037] According to a third aspect of the embodiments of the present application, a certificate application method based on the certificate production method of the first aspect is provided, and the method comprises:

[0038] The user device encrypts the digest of the electronic document according to the digital certificate authority certificate and the user private key, and uploads the generated seal and / or digital signature to the blockchain;

[0039] The blockchain finds the user public key and the corresponding digital certificate authority certificate on the chain, and judges whether the user has the seal and / or signature right according to the user public key and the corresponding digital certificate authority certificate;

[0040] If yes, the seal and / or digital signature uploaded by the user device is stored on the blockchain.

[0041] In a possible implementation, before the user device encrypts the digest of the electronic document according to the digital certificate authority certificate and the user private key, the method further comprises:

[0042] The superior user equipment generates the stamping right and the signing right according to the user public key and the digital certificate authority certificate, and stores the same on the blockchain.

[0043] According to a fourth aspect of the embodiments of the present application, a certificate application system based on the certificate making system of the third aspect is provided, and the system comprises:

[0044] The stamping and signing module is configured to encrypt the digest of the electronic document according to the digital certificate authority certificate and the user private key, and upload the generated stamp and / or digital signature to the blockchain.

[0045] The blockchain verification module is configured to find the user public key and the corresponding digital certificate authority certificate on the chain, and determine whether the user has the stamping and / or signing right according to the user public key and the corresponding digital certificate authority certificate.

[0046] The stamping and signing storage module is configured to store the stamp and / or digital signature uploaded by the user equipment on the blockchain if there is.

[0047] According to a fifth aspect of the embodiments of the present application, an electronic device is provided, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the computer program to implement the method of the first aspect.

[0048] According to a sixth aspect of the embodiments of the present application, a computer readable storage medium is provided, which stores computer readable instructions executable by a processor to implement the method of the first aspect.

[0049] In summary, the embodiments of the present application provide a digital certificate making method and system, which generates a cross-platform autonomous identity registration for a user by cross-certification of a third-party platform and combination of trusted hardware, generates a cross-platform autonomous identity login for a user by cross-certification of a third-party platform and combination of trusted hardware, and generates a digital certificate authority certificate for a user by cross-certification of a third-party platform and combination of trusted hardware. The issuance and application of the digital certificate are managed by the blockchain, which is traceable while ensuring security. BRIEF DESCRIPTION OF DRAWINGS

[0050] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings needed in the following embodiment or prior art description will be briefly introduced. Obviously, the drawings in the following description are only exemplary, and for those skilled in the art, other drawings can be obtained without creative labor on the basis of the provided drawings.

[0051] The structures, proportions, sizes, etc. shown in the specification are merely used to cooperate with the content disclosed in the specification for understanding and reading by those skilled in the art, and do not define the limiting conditions for implementing the present application, and therefore do not have technical significance. Any modification of the structure, change of the proportional relationship, or adjustment of the size, without affecting the effects and purposes that can be achieved by the present application, should still fall within the scope of the technical content disclosed by the present application.

[0052] Figure 1 A digital certificate production method flowchart provided by an embodiment of the present application;

[0053] Figure 2 A certificate application method flowchart provided by an embodiment of the present application;

[0054] Figure 3 A digital certificate production method flowchart provided by an embodiment of the present application;

[0055] Figure 4 A public seal and signature right distribution and traceability method flowchart provided by an embodiment of the present application;

[0056] Figure 5 A digital certificate production system block diagram provided by an embodiment of the present application;

[0057] Figure 6 A certificate application system block diagram provided by an embodiment of the present application;

[0058] Figure 7 A structure schematic diagram of an electronic device provided by an embodiment of the present application is shown;

[0059] Figure 8 A schematic diagram of a computer readable storage medium provided by an embodiment of the present application is shown. DETAILED DESCRIPTION

[0060] The embodiments of the present application are described below by specific embodiments, and those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in the specification. Obviously, the described embodiments are part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of the present application.

[0061] In the production, financial, government and other fields, the seal and signature are important links of management. The public seal is widely used and has a high frequency of use, and often faces the situation of using in different places. At the same time, the seal and signature also have the risk of impersonation and fraud. Therefore, how to coordinate the use of the seal and ensure its security has become a management problem for many organizations. With the popularity of mobile Internet, ERP, CRM, OA and other information systems are used in enterprise production management, financial management, sales management and daily office work. However, in the seal management aspect, it still basically stays in the physical seal use mode. The red seal has become the biggest obstacle to the full electronic management of the organization. Since the electronic seal has not been widely accepted by the market, there are not many enterprises that can efficiently use the electronic seal.

[0062] Blockchain is a distributed database technology that maintains a chain of data blocks for continuous growth, tamper-proof data records. The concept of blockchain can be understood from two levels, narrow and broad. In a narrow sense, blockchain is a chain data structure with blocks as the basic unit. The previous transaction history is verified by using a digital digest in the block, which meets the needs of tamper resistance and scalability in a distributed accounting scenario. In a broad sense, blockchain also refers to the distributed accounting technology based on the blockchain structure, including distributed consensus, privacy and security protection, peer-to-peer communication technology, network protocol, smart contract, etc.

[0063] The CA center issues a digital certificate for each user using a public key. The role of the digital certificate is to prove that the user listed in the certificate legally owns the public key listed in the certificate. The digital signature of the CA agency makes it impossible for attackers to forge and tamper with the certificate. It is responsible for generating, distributing and managing the digital certificates required by all individuals participating in online transactions, so it is the core of secure electronic transactions. CA is the certificate issuing agency, which is the core of the public key infrastructure. CA is responsible for issuing certificates, authenticating certificates, and managing issued certificates.

[0064] Figure 1 A digital certificate production method provided by an embodiment of the application is shown. The method comprises:

[0065] Step 101: Cross-certification using a third-party platform, combined with trusted hardware to generate a cross-platform autonomous identity registration for a user;

[0066] Step 102: Cross-certification using a third-party platform, combined with trusted hardware to generate a cross-platform autonomous identity login for a user;

[0067] Step 103: Cross-certification using a third-party platform, combined with trusted hardware to generate a digital certificate certification agency certificate for a user.

[0068] In a possible implementation, in step 101, the third-party platform cross authentication is used to generate a cross-platform autonomous identity registration for a user in combination with trusted hardware, including:

[0069] The local authentication information and one third-party platform are selected on the user equipment as a main ID and are sent to the trusted hardware to initiate a registration process.

[0070] The trusted device sends an invitation to the user equipment, inviting the user to use at least two third-party platforms authenticated by the user as cross authentication of the identity.

[0071] The user equipment initiates an identity authentication request to all third-party authentication platforms respectively.

[0072] All third-party authentication platforms respectively send a confirmation token to the trusted device.

[0073] The trusted device confirms the identity again by sending the confirmation token to the third-party authentication platform.

[0074] After the third-party authentication platform confirms the identity, the confirmed token is returned to the trusted device.

[0075] When the trusted device receives the token returned by all third-party authentication platforms, a key pair is generated for the user in the trusted device.

[0076] In a possible implementation, in step 102, the third-party platform cross authentication is used to generate a cross-platform autonomous identity login for a user in combination with trusted hardware, including:

[0077] The local authentication information and one third-party platform are selected on the user equipment as a main ID and are sent to the trusted hardware to initiate a login process. Personal identity authentication can be used across multiple platforms on multiple different third-party platforms and the registration and login platform designed in the application.

[0078] The trusted device sends an invitation to the user equipment, inviting the user to use part of the third-party platforms authenticated by the user as cross authentication of the identity.

[0079] The user equipment initiates an identity authentication request to the part of third-party authentication platforms respectively.

[0080] Each of the part of third-party authentication platforms respectively sends a confirmation token to the trusted device.

[0081] The trusted device confirms the identity again by sending the confirmation token to the part of third-party authentication platforms.

[0082] Each of the partial third-party authentication platforms returns a confirmed token to the trusted device after confirming the identity; thus, the trusted packaging is realized through two token confirmations of the independent third-party authentication service by the trusted device.

[0083] When the trusted device receives all the tokens returned by the partial third-party authentication platforms, the key pair is restored for the user in the trusted device. In the prior art, the user needs to remember the key by himself to log in or register, and the user often forgets the key by himself. The application uses the third-party platform to authenticate the identity of the individual user, and only needs to use the key pair automatically generated by the trusted device, without the need for the user to design and remember the key, thereby simplifying the operation of the individual user to manage the key pair, and the user no longer needs to manage the key, but can hand over the management task to the trusted device.

[0084] In a possible implementation, in step 103, the third-party platform cross authentication is used to generate a digital certificate certification authority certificate for the user in combination with the trusted hardware, including:

[0085] The user device generates a digital certificate certification authority certificate request through the trusted hardware according to the user key pair, and sends the request to the trusted hardware;

[0086] The trusted hardware sends the digital certificate certification authority certificate request to the upper-level user device;

[0087] After the upper-level user device is logged in, it judges whether the user device has certificate authority according to the digital certificate certification authority certificate request;

[0088] If the user device has the certificate authority, the upper-level certificate signature is sent to the trusted hardware;

[0089] The trusted hardware creates a digital certificate certification authority certificate for the user and sends the certificate to the user device.

[0090] A secure area is isolated in the trusted hardware to establish an independent hardware environment, and the secure area divides the identity authentication chain into two parts: the user to the secure area and the secure area to the server, and the trusted and secure of the two paths are respectively guaranteed, so that the trusted identity authentication from the user to the server can be guaranteed. The authentication between the user and the secure area is also called local authentication, and generally has the following schemes: PIN code, fingerprint recognition, pupil recognition and other biometric recognition. On the one hand, since the hardware is isolated, the authentication information is directly input to the secure area without passing through the open software system, so the virus cannot work on it; on the other hand, the authentication is a local authentication, and since the area itself is trusted and secure, the path can be guaranteed to be secure.

[0091] The application also provides a certificate application method based on the certificate manufacturing method, likeFigure 2 As shown, the method comprises:

[0092] Step 201: The user equipment encrypts the digest of the electronic document according to the digital certificate authority certificate and the user private key, and uploads the generated seal and / or digital signature to the blockchain;

[0093] Step 202: The blockchain finds the user public key and the corresponding digital certificate authority certificate through on-chain searching, and judges whether the user has the seal and / or signature right according to the user public key and the corresponding digital certificate authority certificate;

[0094] Step 203: If yes, store the seal and / or digital signature uploaded by the user equipment on the blockchain.

[0095] In one possible implementation, before the user equipment encrypts the digest of the electronic document according to the digital certificate authority certificate and the user private key in step 201, the method further comprises:

[0096] The superior user equipment generates the seal right and the signature right according to the user public key and the digital certificate authority certificate, and stores them on the blockchain.

[0097] The method provided by the embodiments of the application will be described in detail below with reference to the drawings.

[0098] As shown, Figure 3 The embodiments of the application disclose a digital certificate production method process, which comprises:

[0099] A1: User registration, that is, after cross-certification through M trusted third-party platforms, the trusted device will receive M confirmation tokens, and then the trusted device will generate a pair of key pairs for the user and store them in the device, and the user can log in by using the key pairs, thereby completing the real-name authentication of the user.

[0100] A2: The user generates a CA certificate request through the trusted device.

[0101] A3: After the superior user logs in, the CA certificate request is received, and the issuance of the certificate is agreed.

[0102] A4: The trusted device creates a user CA certificate.

[0103] After using the method, the CA certificate is bound with the individual without leaking the basic information of the user, instead of being issued to the IT department of the organization as before. The electronic signature can be finally traced back to the individual.

[0104] The embodiment of the application also discloses a method and system for distribution of official seals and signature rights and tracing of official seals and signatures, which realizes creation, destruction and tracing of electronic official seals, distribution, recovery and tracing of signature rights and tracing of sealers and signers by using blockchain technology.

[0105] As shown in Figure 4 , a method for distribution of official seals and signature rights and tracing of official seals and signatures based on blockchain is disclosed, which comprises the following steps:

[0106] B1: An upper-level user creates official seals and signature rights on a blockchain through a certificate.

[0107] B2: The upper-level user grants the official seals and signature rights to a user through the certificate, that is, binds a user public key to the certificate with granted signature rights and stores the certificate on the blockchain.

[0108] B3: The user uses the certificate generated in advance to seal and / or digitally sign an electronic document by combining a user private key, that is, encrypts a digest of the electronic document by using the private key through a special digital signature encryption algorithm and uploads the signature to the blockchain. A user key pair is generated by registration and stored in a trusted device, the private key cannot be publicized and is used for digital signature, and the public key can be publicized and is used for verifying the validity of the signature.

[0109] B4: The blockchain confirms that the user has the right to seal and / or sign by searching for the user public key and the corresponding certificate on the chain and verifies the validity of the digital signature by using the user public key.

[0110] B5: The blockchain stores the sealed and / or signed document.

[0111] The generation, destruction and use of official seals are anti-fake and traceable by using the blockchain technology. The centralized management of signature rights is realized, and the signature rights can be flexibly distributed and recovered according to user functions and permission change scenarios.

[0112] In summary, the embodiment of the application provides a method for making and applying a digital certificate, which generates a cross-platform autonomous identity for a user by cross-certification of a third-party platform and in combination with trusted hardware, generates a cross-platform autonomous identity login for the user by cross-certification of the third-party platform and in combination with the trusted hardware, and generates a digital certificate certification authority certificate for the user by cross-certification of the third-party platform and in combination with the trusted hardware. The distribution and application of the digital certificate are managed by using the blockchain, so that traceability is achieved while security is ensured.

[0113] Based on the same technical concept, the embodiment of the application also provides a system for making a digital certificate, as shown in Figure 5 , which comprises:

[0114] The registration module 501 is configured to generate a cross-platform autonomous identity for a user by cross-authentication of a third-party platform in combination with trusted hardware.

[0115] The real-name authentication module 502 is configured to generate a cross-platform autonomous identity for a user by cross-authentication of a third-party platform in combination with trusted hardware.

[0116] The digital certificate generation module 503 is configured to generate a digital certificate certification authority certificate for a user by cross-authentication of a third-party platform in combination with trusted hardware.

[0117] Based on the same technical concept, the present application also provides a certificate application system of a certificate production system, as shown in Figure 6 The system comprises:

[0118] The seal and signature module 601 is configured to encrypt, by a user device, a digest of an electronic document according to a digital certificate certification authority certificate and a user private key, and upload the generated seal and digital signature to a blockchain.

[0119] The blockchain verification module 602 is configured to find, by the blockchain, a user public key and a corresponding digital certificate certification authority certificate on a chain, and determine whether the user has a seal or signature right according to the user public key and the corresponding digital certificate certification authority certificate.

[0120] The seal and signature storage module 603 is configured to store, on the blockchain, the seal and digital signature uploaded by the user device if there is.

[0121] The present application also provides an electronic device corresponding to the method provided in the foregoing embodiments. Please refer to Figure 7 which shows a schematic diagram of an electronic device provided by some embodiments of the present application. The electronic device 20 can include a processor 200, a memory 201, a bus 202, and a communication interface 203, wherein the processor 200, the communication interface 203, and the memory 201 are connected through the bus 202; the memory 201 stores a computer program that can run on the processor 200, and the processor 200 runs the computer program to execute the method provided by any of the foregoing embodiments of the present application.

[0122] The memory 201 can include a high-speed random access memory (RAM) and can also include a non-volatile memory such as at least one disk memory. The communication connection between the system network element and at least one other network element is realized through at least one physical port 203 (which can be wired or wireless), and the Internet, a wide area network, a local network, a metropolitan area network, etc. can be used.

[0123] The bus 202 can be an ISA bus, a PCI bus, an EISA bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, and the like. The memory 201 is configured to store programs, and the processor 200 executes the programs after receiving execution instructions. The method disclosed in any of the embodiments of the present application can be applied to the processor 200 or implemented by the processor 200.

[0124] The processor 200 can be an integrated circuit chip with processing capability. In the implementation process, the steps of the above method can be completed by the integrated logic circuit or the instruction in the form of software in the processor 200. The processor 200 described above can be a general processor, including a central processing unit (CPU), a network processor (NP), and the like; or can be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component. The disclosed methods, steps, and logic block diagrams in the embodiments of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as a hardware code processor for execution, or a combination of hardware and software modules in the code processor for execution. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a register, or other mature storage media in the art. The storage medium is located in the memory 201, and the processor 200 reads the information in the memory 201 and combines the hardware to complete the steps of the above method.

[0125] The electronic device provided by the embodiments of the present application and the method provided by the embodiments of the present application have the same beneficial effects as the method they adopt, run or implement.

[0126] The embodiments of the present application also provide a computer readable storage medium corresponding to the method provided by the preceding embodiments. Please refer to Figure 8 The computer readable storage medium shown is an optical disc 30, and a computer program (i.e. program product) is stored on the optical disc 30. When the computer program is run by a processor, the method provided by any of the preceding embodiments is executed.

[0127] It should be noted that examples of the computer-readable storage medium can include but are not limited to phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other optical, magnetic storage mediums, and the like, which are not listed one by one here.

[0128] The computer-readable storage medium provided in the above embodiments of the present application has the same beneficial effects as the method adopted, run or implemented by the application program stored therein, based on the same inventive concept.

[0129] It should be noted that:

[0130] The algorithms and displays presented herein are not inherently related to any particular computer, virtual apparatus, or other apparatus. Various general purpose systems can be used with programs in accordance with the teachings herein, or it can prove convenient to construct more specialized apparatus to perform the required method steps. The required structure for a variety of these systems will be apparent from the description above. In addition, the present application is not intended to be limited to a particular programming language. It will be appreciated that a variety of programming languages can be used to implement the teachings of the present application as described herein, and any references below to specific languages are provided for disclosure of enablement only.

[0131] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the application can be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been described in detail in order to not obscure the understanding of this description.

[0132] Similarly, it is to be understood that the above description is only illustrative of the application and certain examples thereof, and is subject to the prior art. Numerous modifications and changes can be devised by those skilled in the art without departing from the true spirit and scope of the application. It is intended that the scope of the application be defined by the following claims as interpreted according to the principles of patent law including 35 U.S.C. § 1 12, 121 and 132, and any equivalents thereof.

[0133] Those skilled in the art will appreciate that the modules in the apparatuses in the embodiments can be adapted and placed in one or more apparatuses other than the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and furthermore can be split into multiple sub-modules or sub-units or sub-components. Any combination of all the features disclosed in the specification (including the accompanying claims, abstract and drawings), and any method or device so disclosed, can be made unless expressly stated otherwise. Each feature disclosed in the specification (including the accompanying claims, abstract and drawings) can be replaced by alternative features providing the same, equivalent or similar functionality unless expressly stated otherwise.

[0134] Furthermore, those skilled in the art will appreciate that different embodiments of the application have different features and that some features of one embodiment can not be present in another embodiment. It should be noted that any of the features described in this specification (including the accompanying claims, abstract and drawings) can be replaced by alternative features serving the same, equivalent or similar purpose, unless expressly stated otherwise. Thus, unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstract and drawings) is considered to be an independent embodiment disclosable under this application.

[0135] The various component embodiments of the application can be implemented in hardware, or as software modules running in one or more processors, or in combinations thereof. Those skilled in the art will appreciate that a microprocessor or digital signal processor (DSP) can be used in practice to implement some or all of the functionality of some or all of the components of the apparatus for creating a virtual machine according to embodiments of the application. The application can also be implemented as a program (for example, a computer program and a computer program product) for executing any or all of the methods described herein on a device or apparatus. Such program(s) of the application can be stored on a computer readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier medium, or in any other form.

[0136] It should be noted that the above-mentioned embodiments illustrate rather than limit the application, and that those skilled in the art will be able to design many alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word 'comprising' does not exclude the presence of elements or steps other than those listed in a claim. The word 'a' or 'an' preceding an element does not exclude the presence of a plurality of such elements. The application can be implemented by means of both hardware and software, and any combination thereof. In a unitary claim, several devices or sub-claims can be joined by means of the expression 'and / or'. The use of the term 'at least' followed by a list of one or more items should be interpreted as including at least one of the items but it does not exclude the presence of others not specified in the list. The use of the term 'one' or 'the' in relation to an element or step of the application should not be construed as excluding the presence of additional such elements or steps nor should the use of the term 'first','second' and 'third' etc. mean that the elements so designated need to be in that order.

[0137] The above description is only preferred specific embodiments of the present application, and the protection scope of the present application is not limited thereto, and any changes or substitutions easily thought of by those skilled in the art within the technical scope disclosed by the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for creating a digital certificate, characterized in that, The method includes: By leveraging cross-authentication from third-party platforms and combining trusted hardware, users can generate cross-platform self-registered identities. By leveraging cross-authentication from third-party platforms and combining trusted hardware, users can generate cross-platform self-identity logins. Utilize cross-certification through third-party platforms and combine trusted hardware to generate digital certificate authority certificates for users; The process of using cross-certification through a third-party platform and generating a digital certificate authority (DCA) certificate for the user, combined with trusted hardware, includes: the user equipment generating a DCA certificate request based on the user key pair obtained from the trusted hardware and sending it to the trusted hardware; the trusted hardware sending the DCA certificate request to the upstream user equipment; after logging in, the upstream user equipment determining whether it has certificate authorization based on the DCA certificate request; if it has certificate authorization, sending an upstream certificate signature to the trusted hardware; and the trusted hardware creating the user's DCA certificate and sending it to the user equipment.

2. The method as described in claim 1, characterized in that, The method of utilizing cross-authentication from third-party platforms and combining trusted hardware to generate cross-platform self-registered identities for users includes: The user device selects local authentication information and a third-party platform as the primary ID and sends it to the trusted hardware to initiate the registration process. Trusted hardware sends an invitation to the user device, inviting the user to use at least two user-authenticated third-party platforms for cross-authentication. The user device initiates identity authentication requests to each of the third-party authentication platforms; Each third-party authentication platform sends a confirmation token to the trusted hardware. The trusted hardware confirms its identity again by sending the confirmation token to a third-party authentication platform. After verifying the identity, the third-party authentication platform returns a confirmed token to the trusted hardware. Once the trusted hardware receives all the tokens returned by the third-party authentication platforms, it generates a key pair for the user within the trusted hardware.

3. The method as described in claim 1, characterized in that, The method of using cross-authentication from a third-party platform, combined with trusted hardware, to generate cross-platform self-identity login for users includes: The user device selects local authentication information and a third-party platform as the primary ID and sends it to the trusted hardware to initiate the login process. Trusted hardware sends an invitation to the user device, inviting the user to use some third-party platforms that the user has authenticated for cross-authentication. The user equipment initiates identity authentication requests to the aforementioned third-party authentication platforms respectively; Each of the aforementioned third-party authentication platforms will send a confirmation token to the trusted hardware; Trusted hardware verifies its identity again by sending the confirmation token to the aforementioned third-party authentication platform. After verifying the identity, each of the aforementioned third-party authentication platforms returns a confirmed token to the trusted hardware. Once the trusted hardware receives all the tokens returned by the aforementioned third-party authentication platforms, it restores the key pair for the user within the trusted hardware.

4. A certificate application method based on the certificate creation method according to any one of claims 1-3, characterized in that, The method includes: The user equipment encrypts the digest of the electronic document based on the certificate of the digital certificate authority and the user's private key, and uploads the generated seal and / or digital signature to the blockchain; The blockchain finds the user's public key and the corresponding digital certificate authority certificate on the chain, and determines whether the user has the authority to stamp and / or sign based on the user's public key and the corresponding digital certificate authority certificate. If applicable, the stamps and / or digital signatures uploaded by the user device are stored on the blockchain.

5. The method as described in claim 4, characterized in that, Before the user equipment encrypts the digest of the electronic document based on the digital certificate authority certificate and the user's private key, the method further includes: The upper-level user equipment generates the right to stamp and sign based on the user's public key and the certificate issued by the digital certificate authority, and stores it on the blockchain.

6. A digital certificate creation system, characterized in that, The system includes: The registration module is used to generate cross-platform self-registered identities for users by leveraging cross-authentication from third-party platforms and combining trusted hardware. The real-name authentication module is used to generate cross-platform self-identity login for users by utilizing cross-authentication from third-party platforms and combining trusted hardware; The digital certificate generation module is used to generate digital certificate authority certificates for users by utilizing cross-authentication through a third-party platform and combining trusted hardware. The process of generating digital certificate authority certificates for users by utilizing cross-authentication through a third-party platform and combining trusted hardware includes: the user equipment generating a digital certificate authority certificate request based on the user key pair obtained from the trusted hardware and sending it to the trusted hardware; the trusted hardware sending the digital certificate authority certificate request to the upstream user equipment; after logging in, the upstream user equipment determines whether it has certificate authorization based on the digital certificate authority certificate request; if it has certificate authorization, it sends an upstream certificate signature to the trusted hardware; and the trusted hardware creates the user's digital certificate authority certificate and sends it to the user equipment.

7. A certificate application system based on the certificate creation system of claim 6, characterized in that, The system includes: The stamp and signature module is used by user devices to encrypt the digest of electronic documents based on the digital certificate authority certificate and the user's private key, and upload the generated stamp and / or digital signature to the blockchain; The blockchain verification module is used to find the user's public key and the corresponding digital certificate authority certificate on the blockchain, and to determine whether the user has the authority to stamp and / or sign based on the user's public key and the corresponding digital certificate authority certificate. The stamp and signature storage module is used to store, if applicable, the stamps and / or digital signatures uploaded by user devices on the blockchain.

8. An electronic device, comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that the processor executes the computer program to implement the method as claimed in any one of claims 1-5.

9. A computer-readable storage medium, characterized in that, It stores computer-readable instructions that can be executed by a processor to implement the method as described in any one of claims 1-5.