Digital Certificate Management Method, Device and Electronic Device

By limiting the circulation range of digital certificates in the target system, sending and controlling certificate installation and uninstallation to the target client, the problem of low security of digital certificates in the prior art is solved, and higher certificate security and normal use are achieved.

CN115459933BActive Publication Date: 2025-06-27INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211152553.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-21
Publication Date
2025-06-27
Estimated Expiration
2042-09-21

AI Technical Summary

Technical Problem

In the prior art, the certificate is low in the process of distributing digital certificates to related systems, and there is a risk of tampering and leaking, resulting in problems such as counterfeit enterprise APPs and user fraud.

Method used

By responding to the certificate acquisition request sent by the target system, sending the target digital certificate to the target client, and controlling the target client to install and uninstall the certificate in the target system, limiting the scope of the certificate circulation, and using encrypted transmission method to uninstall and delete the certificate in a timely manner.

Benefits of technology

It effectively reduces the risk of leakage and tampering of digital certificates during circulation, improves the security of certificates, prevents fake APPs and user fraud, and ensures the normal use of certificates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115459933B_ABST
    Figure CN115459933B_ABST
Patent Text Reader

Abstract

The present invention discloses a digital certificate management method, apparatus and electronic device. It relates to the field of information security. The method includes: responding to a certificate acquisition request sent by a first target system, and sending a target digital certificate to a target client, where the first target system is the system used by a target object, and the target client is deployed on the first target system; controlling the target client to install the target digital certificate in the first target system, so that the target object signs a target file based on the target digital certificate. The present invention solves the technical problem of low certificate security in the process of distributing digital certificates to related systems in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and in particular, to a digital certificate management method, apparatus, and electronic device. Background Art

[0002] During the R & D process of mobile application (APP, Application) projects for related systems (such as: IOS system, etc.), it is necessary to compile the project engineering to generate an installation package and install it on the mobile phone side of the related system for real machine testing. And during this process, digital certificates are required. Currently, as Figure 1 shown, digital certificates are usually applied for by certificate management personnel in a related certificate authority center and exported as digital certificate files, and then distributed to developers (i.e., Figure 1 the certificate users in

[0003] this) through means such as USB flash drive transfer or email attachments, and the developers install the certificate in the local computer system for use during the process of packaging the installation package.

[0004] However, there are great risks of being tampered with and leaked during the distribution and transfer link of digital certificate files by developers and the link where developers save them in the local computer system. For example, digital certificate files may be obtained by unauthorized users, and the local computer system may be shared by multiple people, and there are problems such as users exporting digital certificate files and leaking them to unauthorized usage scenarios. Furthermore, the leaked digital certificates may be used to make counterfeit enterprise APPs and may be used to defraud users, etc., having a negative impact on the enterprise's reputation and users' rights and interests. Therefore, there is a problem of low certificate security in the process of distributing digital certificates to related systems in the prior art. Summary of the Invention

[0005] Embodiments of the present invention provide a digital certificate management method, apparatus, and electronic device to at least solve the technical problem of low certificate security in the process of distributing digital certificates to related systems in the prior art.

[0006] According to one aspect of the embodiments of the present invention, a digital certificate management method is provided, including: responding to a certificate acquisition request sent by a first target system, and sending a target digital certificate to a target client, where the first target system is the system used by a target object, and the target client is deployed on the first target system; controlling the target client to install the target digital certificate in the first target system so that the target object signs a target file based on the target digital certificate.

[0007] Further, the digital certificate management method further includes: obtaining the identity information of the target object and performing permission verification on the identity information; when it is determined that the identity information has the permission to obtain the digital certificate, in response to the certificate acquisition request sent by the target client, sending the target digital certificate to the target client.

[0008] Further, the digital certificate management method further includes: sending the target digital certificate to the target client based on the target encryption transmission method.

[0009] Further, the digital certificate management method further includes: after controlling the target client to install the target digital certificate in the first target system, controlling the target client to uninstall the target digital certificate in the first target system.

[0010] Further, the digital certificate management method further includes: when the difference between the current time and the target time is greater than the preset time range, controlling the target client to uninstall the target digital certificate in the first target system, where the target time is the time when the target digital certificate is successfully installed in the first target system, or when it is detected that the first target system has completed using the target digital certificate, controlling the target client to uninstall the target digital certificate in the first target system.

[0011] Further, the target client is used to delete the target digital certificate in the target client after uninstalling the target digital certificate in the first target system.

[0012] Further, the digital certificate management method further includes: before responding to the certificate acquisition request sent by the first target system and sending the target digital certificate to the target client, obtaining the identity information of the certificate management object and performing identity authentication on the certificate management object based on the identity information of the certificate management object; when it is determined that the identity of the certificate management object is the target identity, obtaining multiple digital certificates sent by the second target system used by the certificate management object, where the second target system is at least used to store multiple digital certificates, and at least one of the multiple digital certificates includes the target digital certificate.

[0013] According to another aspect of the embodiments of the present invention, there is also provided a digital certificate management device, including: a sending module, configured to respond to a certificate acquisition request sent by a first target system and send a target digital certificate to a target client, where the first target system is a system used by a target object, and the target client is deployed on the first target system; a control module, configured to control the target client to install the target digital certificate in the first target system so that the target object signs a target file based on the target digital certificate.

[0014] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium, in which a computer program is stored, where the computer program is configured to execute the above digital certificate management method when running.

[0015] According to another aspect of the embodiments of the present invention, an electronic device is further provided. The electronic device includes one or more processors; a memory for storing one or more programs, which, when executed by the one or more processors, cause the one or more processors to implement a program for running, wherein the program is configured to execute the above digital certificate management method when running.

[0016] In the embodiments of the present invention, a method is adopted to restrict the circulation range of a target digital certificate during the transfer process of the target digital certificate. By responding to a certificate acquisition request sent by a first target system, the target digital certificate is sent to a target client, thereby controlling the installation of the target digital certificate by the target client in the first target system, so that a target object signs a target file based on the target digital certificate. Among them, the first target system is the system used by the target object, and the target client is deployed on the first target system.

[0017] In the above process, when the certificate acquisition request sent by the first target system is obtained, the target digital certificate is sent to the target client instead of the first target system, so that the circulation range of the target digital certificate is effectively restricted. On the one hand, when the target digital certificate is directly sent to the first target system, relevant users can directly obtain the digital certificate through the first target system. On the other hand, it avoids the problems of large computational load of relevant systems and the risk of being cracked caused by the transfer method of encrypting and then transmitting the target digital certificate. Thus, the risk of leakage and tampering of the target digital certificate during the circulation process is effectively reduced, making the storage and use of the target digital certificate safer and improving the certificate security. Further, by installing the target digital certificate in the first target system, while improving the certificate security, the normal use of the target digital certificate by the target object is ensured.

[0018] It can be seen that the solution provided by the present application achieves the purpose of restricting the circulation range of the target digital certificate during the transfer process of the target digital certificate, thereby realizing the technical effect of improving the security of the target digital certificate, and further solving the technical problem of low certificate security in the process of distributing digital certificates to relevant systems in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The drawings described herein are used to provide a further understanding of the present invention and form a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0020] Figure 1 is a schematic diagram of the circulation of digital certificates in the prior art;

[0021] Figure 2 It is a schematic diagram of an optional certificate management method according to an embodiment of the present invention;

[0022] Figure 3 It is a working schematic diagram of an optional certificate management system according to an embodiment of the present invention;

[0023] Figure 4 It is a schematic diagram of an optional certificate management method according to an embodiment of the present invention;

[0024] Figure 5 It is a schematic diagram of an optional certificate management device according to an embodiment of the present invention;

[0025] Figure 6 It is a schematic diagram of an optional electronic device according to an embodiment of the present invention. Detailed implementation manners

[0026] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.

[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0028] It should be noted that the relevant information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in the present disclosure are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set between the present system and relevant users or institutions. Before obtaining relevant information, a request for obtaining information needs to be sent to the aforementioned users or institutions through the interface, and after receiving the consent information feedback from the aforementioned users or institutions, the relevant information can be obtained.

[0029] Embodiment 1

[0030] According to an embodiment of the present invention, an embodiment of a digital certificate management method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0031] Figure 2 is a schematic diagram of an optional certificate management method according to an embodiment of the present invention. As Figure 2 shown, the method includes the following steps:

[0032] Step S201, in response to a certificate acquisition request sent by a first target system, send a target digital certificate to a target client, where the first target system is the system used by a target object, and the target client is deployed on the first target system.

[0033] Optionally, the method provided in this application is executed with a digital certificate management system as the execution subject. As Figure 3 shown, the aforementioned digital certificate management system can be a system based on a client-server (C / S, Client-Server) structure, including a target client (Client side) and a target server (Server side), and this system can be implemented in the Java language. Among them, Java is an object-oriented programming language. The target server can be deployed on an independent server, and the target server can provide page services for relevant users through the Web (World Wide Web) side. The aforementioned server can be a Linux server, where Linux is an operating system kernel; the target client can be deployed on the first target system used by the target object. The target object is an object in the current organization that needs to use a digital certificate. For example, the target object can be a developer who develops relevant APPs within the current organization. The first target system is used for the target object to implement the processing of digital certificates. The first target system can be a MacOS system or other systems.

[0034] In step S201, as Figure 3As shown, when the target object needs to use a digital certificate, the target object can send a certificate acquisition request to the target server through the first target system, and the target server responds to the certificate acquisition request to determine the digital certificate (i.e., the aforementioned target digital certificate) to be used by the target object based on the certificate acquisition request, and sends the target digital certificate to the target client. The target client can store the target digital certificate in a preset directory. Among them, the file format of the target digital certificate to be transmitted can be a Personal Digital Certificate Standard (PKCS12, Public-Key Cryptography Standards #12) file, which can be used to describe personal identity information. Such as: user public key, private key, certificate, etc. The p12 certificate contains the private key, public key and is password protected.

[0035] It should be noted that by sending the target digital certificate to the target client instead of the first target system when the certificate acquisition request sent by the first target system is obtained, the circulation range of the target digital certificate is effectively restricted. When the target digital certificate is directly sent to the first target system, relevant users can directly obtain the digital certificate through the first target system, thus reducing the risk of leakage during the circulation of the target digital certificate and improving the certificate security.

[0036] Step S202, control the target client to install the target digital certificate in the first target system, so that the target object can sign the target file based on the target digital certificate.

[0037] In step S202, after the target server completes the sending of the target digital certificate, the target server can obtain a certificate installation request sent by the target object to the target server based on the Web side, and when the certificate installation request is verified, send a digital certificate installation instruction to the target client to control the target client to install the target digital certificate in the first target system, and after the installation is completed, return the installation result to the target server. In an optional embodiment, information interaction can be carried out between the target server and the target client through the socket protocol. The target client can use the java program based on the digital certificate installation instruction and implement the call of relevant first target system tool commands through the Process class Runtime.getRuntime.exec method to install the target digital certificate into the first target system. Among them, socket is a method for process communication between different programs, the Process class is an abstract class, and the Runtime.getRuntime.exec method is used to execute external programs or commands.

[0038] Further, after the target digital certificate is installed, the target object can use the target digital certificate in the first target system to sign the files in the APP to be packaged and verify their integrity, etc. After the above-mentioned processing is completed, the files in the APP to be packaged are compiled to generate relevant installation packages.

[0039] It should be noted that by installing the target digital certificate in the first target system, while improving the security of the certificate, the normal use of the target digital certificate by the target object is ensured.

[0040] Based on the solution defined in the above step S201 to step S202, it can be known that in the embodiment of the present invention, a method of restricting the circulation range of the target digital certificate during the transmission process of the target digital certificate is adopted. By responding to the certificate acquisition request sent by the first target system, the target digital certificate is sent to the target client, so as to control the installation of the target digital certificate by the target client in the first target system, so that the target object signs the target file based on the target digital certificate. Among them, the first target system is the system used by the target object, and the target client is deployed on the first target system.

[0041] It is easy to notice that in the above process, when the certificate acquisition request sent by the first target system is obtained, the target digital certificate is sent to the target client instead of the first target system, so that the circulation range of the target digital certificate is effectively restricted. On the one hand, when the target digital certificate is directly sent to the first target system, relevant users can directly obtain the digital certificate through the first target system. On the other hand, it avoids the problems of large computational load of relevant systems and the risk of being cracked caused by the transmission and circulation method of encrypting the target digital certificate, thereby effectively reducing the risk of leakage and tampering of the target digital certificate during the circulation process, making the storage and use of the target digital certificate safer and improving the security of the certificate. Further, by installing the target digital certificate in the first target system, while improving the security of the certificate, the normal use of the target digital certificate by the target object is ensured.

[0042] It can be seen that the solution provided by this application achieves the purpose of restricting the circulation range of the target digital certificate during the transmission process of the target digital certificate, thereby realizing the technical effect of improving the security of the target digital certificate, and further solving the technical problem of low certificate security in the process of distributing digital certificates to relevant systems in the prior art.

[0043] In an alternative embodiment, before sending the target digital certificate to the target client in response to the certificate acquisition request sent by the first target system, the target server may obtain the identity information of the certificate management object and authenticate the identity of the certificate management object based on the identity information of the certificate management object. Thus, when it is determined that the identity of the certificate management object is the target identity, the target server may obtain multiple digital certificates sent by the second target system used by the certificate management object, where the second target system is at least used to store multiple digital certificates, and at least the target digital certificate is included in the multiple digital certificates.

[0044] Optionally, since digital certificates are constantly updated, the certificate manager within the current organization (i.e., the aforementioned certificate management object) may directly store these certificates to the target server in advance when obtaining new digital certificates or updated digital certificates, for subsequent use by the target object. Specifically, as Figure 3 shown, the target server may obtain the identity information of the certificate manager when the certificate manager logs in to the web end, and authenticate the identity of the certificate management object based on this identity information.

[0045] Furthermore, when the target server determines that the identity of the certificate management object is the target identity, the target server may obtain multiple digital certificates sent by the certificate management object through the second target system it uses. Among them, the certificate management object may send multiple digital certificates to the target server through the second target system in an https (Hypertext Transfer Protocol Secure) encrypted transmission manner, and the target server stores them.

[0046] It should be noted that by pre-obtaining digital certificates, the processing efficiency of providing the target digital certificate to the target object is improved. At the same time, by authenticating the identity of the certificate management object, the authenticity of the obtained digital certificates is ensured, and the usage risk caused by the target object providing false digital certificates is avoided.

[0047] In an alternative embodiment, during the process of sending the target digital certificate to the target client in response to the certificate acquisition request sent by the first target system, as Figure 4 shown, the target server may perform the following steps:

[0048] Step S401: Obtain the identity information of the target object and perform permission verification on the identity information.

[0049] Specifically, as Figure 3As shown, when the target object needs to use a digital certificate, the target object can log in to the web side through the first target system to send a certificate acquisition request to the target server. The target server can obtain the identity information of the target object when the target object logs in to the web side, and perform permission authentication on the target object based on this identity information.

[0050] Step S402: When it is determined that the identity information has the permission to obtain a digital certificate, in response to the certificate acquisition request sent by the target client, send the target digital certificate to the target client.

[0051] It should be noted that by authenticating the target object before sending the target digital certificate to the target client, on the one hand, it avoids the risks brought by unauthorized users accessing, obtaining, and misusing digital certificates, and on the other hand, it avoids the ineffective processing caused by sending the target digital certificate in response to any certificate acquisition request, thereby improving work efficiency.

[0052] In an optional embodiment, during the process of sending the target digital certificate to the target client, the target server can send the target digital certificate to the target client based on the target encryption transmission method. Specifically, the aforementioned target encryption transmission method can be the https encryption transmission method.

[0053] It should be noted that by adopting the encryption transmission method during the process of transmitting the target digital certificate, the certificate security can be further improved and the digital certificate can be prevented from being stolen.

[0054] In an optional embodiment, after controlling the target client to install the target digital certificate in the first target system, the target server can control the target client to uninstall the target digital certificate in the first target system.

[0055] Specifically, when the target server determines that the target object has finished using the digital certificate, the target server can send a digital certificate uninstallation instruction to the target client, so that the target client uninstalls the target digital certificate from the first target system based on the digital certificate uninstallation instruction and returns the uninstallation result to the target server. In an optional embodiment, the target client can, based on the digital certificate uninstallation instruction, use a Java program to call the relevant first target system tool command through the Process class Runtime.getRuntime.exec method to uninstall the target digital certificate from the first target system.

[0056] It should be noted that by promptly uninstalling the target digital certificate from the first target system after the target digital certificate is used up, the relevant content of the target digital certificate persisted in the first target system is avoided, thereby effectively preventing the problem of unfavorable control of digital certificates when the first target system is shared by multiple people, reducing the risk of misuse and malicious export and use of digital certificates, and further improving the security of the certificates.

[0057] In an optional embodiment, during the process of controlling the target client to uninstall the target digital certificate in the first target system, the target server can determine whether the target object has finished using the digital certificate based on different methods. Optionally, when the difference between the current time and the target time is greater than the preset time range, the target server can control the target client to uninstall the target digital certificate in the first target system, or when it is detected that the first target system has finished using the target digital certificate, the target server can control the target client to uninstall the target digital certificate in the first target system. Herein, the target time is the time when the target digital certificate is installed in the first target system.

[0058] Specifically, the target server can determine the time when the target digital certificate is installed in the first target system (i.e., the target time) according to the installation result returned by the target client, so that when the difference between the current time and the target time is greater than the preset time range, it is defaulted that the target digital certificate has been used up, thereby controlling the target client to uninstall the target digital certificate in the first target system. Herein, the target server can determine the preset time range according to the setting information of the certificate management object, or can also determine the preset time range according to the historical usage time of the digital certificate.

[0059] Optionally, the target server can also actively detect the usage situation of the target digital certificate in the first target system, or obtain the usage result actively sent by the first target system to implement the detection of whether the first target system has finished using the target digital certificate. Further, when it is detected that the first target system has finished using the target digital certificate, the target server can control the target client to uninstall the target digital certificate in the first target system.

[0060] It should be noted that by determining whether the first target system has finished using the target digital certificate in multiple ways, the effective limitation of the retention time of the target digital certificate in the first target system is achieved, thereby avoiding the usage risk caused by not uninstalling the target digital certificate when the information between the target server and the first target system is maliciously intercepted if determined by a single method.

[0061] In an optional embodiment, the target client is used to delete the target digital certificate in the target client after uninstalling the target digital certificate in the first target system.

[0062] Optionally, after the target digital certificate is uninstalled from the first target system by the target client, the target client may delete the target digital certificate from a preset directory and return the deletion result to the target server. In an alternative embodiment, the target client may use a Java program to delete the target digital certificate in the preset target through the delete() method of the File class. Among them, the File class is an abstract representation of file and directory pathnames, used for operations such as creating, searching, and deleting files and directories, and the delete() method is used to delete the specified file or folder.

[0063] It should be noted that by deleting the digital certificate from the target client in a timely manner after using the digital certificate, the risk of the digital certificate being misused or maliciously exported and used can be further reduced, thereby improving the security of the certificate.

[0064] It can be seen that the solution provided by this application achieves the purpose of restricting the circulation range of the target digital certificate during the transfer process of the target digital certificate, thereby realizing the technical effect of improving the security of the target digital certificate, and further solving the technical problem of low certificate security in the process of distributing digital certificates to related systems in the prior art.

[0065] Embodiment 2

[0066] According to an embodiment of the present invention, an embodiment of a digital certificate management device is provided, wherein, Figure 5 is a schematic diagram of an optional certificate management device according to an embodiment of the present invention, as Figure 5 shown, the device includes:

[0067] A sending module 501, configured to respond to a certificate acquisition request sent by a first target system, and send a target digital certificate to a target client, where the first target system is a system used by a target object, and the target client is deployed on the first target system;

[0068] A first control module 502, configured to control the target client to install the target digital certificate in the first target system, so that the target object signs a target file based on the target digital certificate.

[0069] It should be noted that the above-mentioned sending module 501 and the first control module 502 correspond to steps S201 to S202 in the above embodiment, and the examples and application scenarios implemented by the two modules are the same as those of the corresponding steps, but are not limited to the content disclosed in the above embodiment 1.

[0070] Optionally, the sending module further includes: an obtaining sub-module, configured to obtain the identity information of the target object and perform permission verification on the identity information; a first sending sub-module, configured to, when it is determined that the identity information has the permission to obtain a digital certificate, in response to a certificate obtaining request sent by the target client, send the target digital certificate to the target client.

[0071] Optionally, the first sending sub-module further includes: a second sending sub-module, configured to send the target digital certificate to the target client based on the target encryption transmission method.

[0072] Optionally, the digital certificate management device further includes: a second control module, configured to control the target client to uninstall the target digital certificate in the first target system.

[0073] Optionally, the second control module further includes: a first control sub-module, configured to, when the difference between the current time and the target time is greater than a preset time range, control the target client to uninstall the target digital certificate in the first target system, where the target time is the time when the target digital certificate is installed in the first target system, or a second control sub-module, configured to, when it is detected that the first target system has completed using the target digital certificate, control the target client to uninstall the target digital certificate in the first target system.

[0074] Optionally, the target client is configured to delete the target digital certificate in the target client after uninstalling the target digital certificate in the first target system.

[0075] Optionally, the digital certificate management device further includes: a first obtaining module, configured to obtain the identity information of the certificate management object and perform identity authentication on the certificate management object based on the identity information of the certificate management object; a second obtaining module, configured to, when it is determined that the identity of the certificate management object is the target identity, obtain multiple digital certificates sent by the second target system used by the certificate management object, where the second target system is at least used to store multiple digital certificates, and at least one of the multiple digital certificates includes the target digital certificate.

[0076] Embodiment 3

[0077] On the other hand according to an embodiment of the present invention, there is also provided a computer-readable storage medium, in which a computer program is stored, where the computer program is configured to execute the above digital certificate management method when running.

[0078] Embodiment 4

[0079] On the other hand according to an embodiment of the present invention, there is also provided an electronic device, where Figure 6 is a schematic diagram of an optional electronic device according to an embodiment of the present invention, as Figure 6As shown, the electronic device includes one or more processors; a memory for storing one or more programs, which, when executed by the one or more processors, cause the one or more processors to implement running a program, where the program is set to execute the above digital certificate management method when running.

[0080] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0081] In the above embodiments of the present invention, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0082] In the several embodiments provided in the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of units can be a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.

[0083] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0084] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0085] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs.

[0086] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A digital certificate management method, characterized in that, The method is applied to a digital certificate management system, which is a client-server structure system including a target client and a target server. The method includes: Responding to a certificate acquisition request sent by a first target system, and sending a target digital certificate to the target client, where the first target system is the system used by a target object, and the target client is deployed on the first target system; Controlling the target client to install the target digital certificate in the first target system, so that the target object signs a target file based on the target digital certificate; Responding to a certificate acquisition request sent by a first target system, and sending a target digital certificate to the target client, including: Obtaining the identity information of the target object, and performing permission verification on the identity information; When it is determined that the identity information has the permission to obtain a digital certificate, responding to the certificate acquisition request sent by the target client, and sending the target digital certificate to the target client.

2. The method according to claim 1, characterized in that Sending the target digital certificate to the target client, including: Sending the target digital certificate to the target client based on a target encryption transmission method.

3. The method according to claim 1, wherein After controlling the target client to install the target digital certificate in the first target system, the method further includes: Controlling the target client to uninstall the target digital certificate in the first target system.

4. The method according to claim 3, wherein Controlling the target client to uninstall the target digital certificate in the first target system, including: When the difference between the current time and the target time is greater than a preset time range, controlling the target client to uninstall the target digital certificate in the first target system, where the target time is the time when the target digital certificate is installed in the first target system, or When it is detected that the first target system has finished using the target digital certificate, controlling the target client to uninstall the target digital certificate in the first target system.

5. The method according to claim 3, characterized in that, The target client is used to delete the target digital certificate in the target client after uninstalling the target digital certificate in the first target system.

6. The method according to claim 1, characterized in that, Before responding to a certificate acquisition request sent by a first target system and sending a target digital certificate to the target client, the method further includes: Obtaining the identity information of a certificate management object, and performing identity authentication on the certificate management object based on the identity information of the certificate management object; When it is determined that the identity of the certificate management object is a target identity, obtaining multiple digital certificates sent by a second target system used by the certificate management object, where the second target system is at least used to store the multiple digital certificates, and at least the target digital certificate is included in the multiple digital certificates.

7. A digital certificate management device, characterized in that, Applied to a digital certificate management system, which is a client-server structure system including a target client and a target server. The device includes: A sending module, configured to respond to a certificate acquisition request sent by a first target system, and send a target digital certificate to the target client, where the first target system is the system used by a target object, and the target client is deployed on the first target system; A first control module, configured to control the target client to install the target digital certificate in the first target system, so that the target object signs a target file based on the target digital certificate; Optionally, the sending module further includes: An obtaining sub-module, configured to obtain the identity information of the target object and perform permission verification on the identity information; A first sending sub-module, configured to, when determining that the identity information has the permission to obtain a digital certificate, in response to a certificate obtaining request sent by the target client, send the target digital certificate to the target client.

8. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein the computer program is configured to execute the digital certificate management method described in any one of claims 1 to 6 when running.

9. An electronic device, characterized in that, The electronic device includes one or more processors; A memory, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, cause the one or more processors to implement a program for running, wherein the program is configured to execute the digital certificate management method described in any one of claims 1 to 6 when running.

Citation Information

Patent Citations

  • Method and device for implementing digital certificate application and utilization

    CN107786344A