Business certificate management method, device, storage medium and electronic device

By recording correspondence and cascade relationships in the digital certificate management module of embedded devices, and forming and managing the target certificate chain, the problem of low efficiency in business certificate management in the existing technology is solved, and unified management and efficient use of certificates are realized.

CN115643028BActive Publication Date: 2025-05-16ZHEJIANG DAHUA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211289073.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-20
Publication Date
2025-05-16
Estimated Expiration
2042-10-20

AI Technical Summary

Technical Problem

In the prior art, business certificate management on embedded devices is low efficiency, resulting in duplicate logic, cumbersome operations, inability to use certificates with each other, and confusing management of new certificates and private key passwords.

Method used

A set of correspondence and certificate cascade relationships are recorded in the digital certificate management module of the target device. By finding the correspondence between the business identifier and the certificate identifier and the cascade relationship between the certificate, the target certificate chain is formed and stored in the corresponding storage path, and the service is notified to load the certificate chain.

Benefits of technology

It realizes unified management of all business certificates on the target device, avoids the cumbersome operation caused by independent management of certificates for each business and the inability to use certificates for each business, and improves the management efficiency of business certificates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115643028B_ABST
    Figure CN115643028B_ABST
Patent Text Reader

Abstract

The embodiment of the present invention provides a method, device, storage medium and electronic device for managing business certificates, wherein the method includes: obtaining a first certificate acquisition request sent by a first target business on a target device to a digital certificate management module, in which a set of corresponding relationships and certificate cascade relationships are recorded; searching for a certificate identifier corresponding to a business identifier of the first target business in a set of corresponding relationships; when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the business identifier of the first target business, searching for a set of superior certificates of the first target certificate according to the certificate cascade relationship; when a set of superior certificates is found, the first target certificate and a set of superior certificates form a target certificate chain; and then storing it in a first storage path corresponding to the first target business, and notifying the first target business to load it. Through the present invention, the problem of low management efficiency of business certificates existing in the related art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of network security technology, and in particular, to a method, device, storage medium and electronic device for managing a business certificate. Background Art

[0002] On existing embedded devices, each business needs to manage its own digital certificates. For example, the HTTPS business needs to support the import, download, and deletion of digital certificates. The same is true for RTSPOverTLS, MQTT and other businesses. In the certificate management solution of related technologies, each business needs to import, verify, and update certificates. With the increase in business, there are problems such as low efficiency of logic duplication, cumbersome operations on many pages, certificates cannot be used mutually, it is not easy to replace new certificates, and chaotic private key password management, which makes it extremely cumbersome for users to configure these certificates. Therefore, there is a problem of low management efficiency of business certificates in related technologies.

[0003] Currently, no effective solution has been proposed to address the problem of low management efficiency of business certificates in related technologies. Summary of the invention

[0004] The embodiments of the present invention provide a method, device, storage medium and electronic device for managing a service certificate, so as to at least solve the problem of low management efficiency of service certificates existing in the related art.

[0005] According to one embodiment of the present invention, a method for managing business certificates is provided, comprising: obtaining a first certificate acquisition request sent by a first target business on a target device to a digital certificate management module, wherein the digital certificate management module is located on the target device, and a set of correspondences and certificate cascade relationships are recorded in the digital certificate management module, each correspondence in the set of correspondences being a correspondence between a business identifier of a business and a certificate identifier of a certificate required to be used by the business, and the certificate cascade relationship being used to represent a cascade relationship between a set of certificates stored in the digital certificate management module; in response to the first certificate acquisition request, searching the set of correspondences for a certificate having a corresponding relationship with the business identifier of the first target business. the certificate identifier of the certificate of the first target business; when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the business identifier of the first target business, a group of superior certificates of the first target certificate are searched according to the certificate cascade relationship, wherein the first target certificate is the certificate required to be used by the first target business; when the group of superior certificates are found, the first target certificate and the group of superior certificates are combined into a target certificate chain, wherein the target certificate chain includes the first target certificate and the group of superior certificates with a cascade relationship; the target certificate chain is stored in a first storage path corresponding to the first target business in the target device, and the first target business is notified to load the target certificate chain from the first storage path.

[0006] In an exemplary embodiment, the method also includes: obtaining a second certificate acquisition request sent to the digital certificate management module by the second target business on the target device; in response to the second certificate acquisition request, searching for the certificate identifier of the certificate that has a corresponding relationship with the business identifier of the second target business in the set of correspondences; when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the business identifier of the second target business and the target certificate chain is cached, storing the target certificate chain in the second storage path corresponding to the second target business in the target device, and notifying the second target business to load the target certificate chain from the second storage path.

[0007] In an exemplary embodiment, the method also includes: obtaining a second certificate acquisition request sent to the digital certificate management module by the second target business on the target device; in response to the second certificate acquisition request, searching for the certificate identifier of the certificate that has a corresponding relationship with the business identifier of the second target business in the set of corresponding relationships; when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the business identifier of the second target business and the target certificate chain is not cached, searching for the set of superior certificates of the first target certificate according to the certificate cascade relationship, wherein the first target certificate is the certificate required to be used by the second target business; when the set of superior certificates is found, the first target certificate and the set of superior certificates form the target certificate chain; the target certificate chain is stored in a second storage path corresponding to the second target business in the target device, and the second target business is notified to load the target certificate chain from the second storage path.

[0008] In an exemplary embodiment, storing the target certificate chain in a first storage path corresponding to the first target business in the target device, and notifying the first target business to load the target certificate chain from the first storage path, includes: writing the target certificate chain and private key encryption information into a first designated file and a second designated file in the first storage path, respectively, and notifying the first target business to load the target certificate chain from the first designated file, and notifying the first target business to decrypt the private key encryption information in the second designated file, wherein the private key encryption information is information encrypted by a first private key corresponding to the first target certificate, and the first private key is the private key required to be used by the first target business.

[0009] In an exemplary embodiment, before writing the target certificate chain and private key encryption information into the first designated file and the second designated file in the first storage path respectively, the method further includes: obtaining the first private key; encrypting the first private key in a target hardware device or a target software module in the target device to obtain the private key encryption information, and storing the private key encryption information in a target storage unit in the target device, wherein the target hardware device or the target software module is configured to prohibit access by devices outside the target device.

[0010] In an exemplary embodiment, after notifying the first target business to decrypt the private key encrypted information in the second designated file, the method also includes: obtaining the private key encrypted information sent by the first target business to the target hardware device or the target software module; decrypting the private key encrypted information in the target hardware device or the target software module to obtain the first private key; and sending the first private key to the first target business.

[0011] In an exemplary embodiment, before searching for the certificate identifier of the certificate that has a corresponding relationship with the business identifier of the first target business in the set of correspondences in response to the first certificate acquisition request, the method also includes: obtaining configuration information sent to the digital certificate management module, wherein the configuration information is used to indicate the certificate required to be used for each business in a set of businesses; and configuring the set of correspondences in the digital certificate management module according to the configuration information.

[0012] In an exemplary embodiment, before searching for the certificate identifier of the certificate that has a corresponding relationship with the business identifier of the first target business in the set of correspondences in response to the first certificate acquisition request, the method also includes: obtaining a first certificate chain imported on the target device, wherein the first certificate chain includes a first group of certificates with a cascade relationship; for each certificate in the first group of certificates on the first certificate chain, performing the following operations, wherein when performing the following operations, each certificate is a current certificate: determining whether the current certificate has been stored on the target device; if it is determined that the current certificate is not stored on the target device, storing the current certificate on the target device; if it is determined that the current certificate has been stored on the target device, canceling the storage of the current certificate on the target device.

[0013] In an exemplary embodiment, the method also includes: obtaining a relationship deletion request sent to the digital certificate management module, wherein the relationship deletion request is used to request deletion of a target corresponding relationship in the set of corresponding relationships, and the target corresponding relationship is a corresponding relationship between a business identifier of a third target business and a certificate identifier of a certificate required to be used by the third target business; in response to the relationship deletion request, deleting the target corresponding relationship in the set of corresponding relationships; or when an abnormality is detected in the first target certificate, deleting the target certificate chain in the first storage path.

[0014] According to another embodiment of the present invention, a business certificate management device is also provided, including: a first acquisition module, used to acquire a first certificate acquisition request sent to a digital certificate management module by a first target business on a target device, wherein the digital certificate management module is located on the target device, and a set of correspondences and certificate cascade relationships are recorded in the digital certificate management module, each correspondence in the set of correspondences is a correspondence between a business identifier of a business and a certificate identifier of a certificate required to be used by the business, and the certificate cascade relationship is used to represent a cascade relationship between a set of certificates stored in the digital certificate management module; a first search module, used to respond to the first certificate acquisition request and search for a certificate having a correspondence with the business identifier of the first target business in the set of correspondences. a certificate identifier of the first target certificate; a second search module, used to search for a group of superior certificates of the first target certificate according to the certificate cascade relationship when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the business identifier of the first target business, wherein the first target certificate is the certificate required to be used by the first target business; a first composition module, used to form a target certificate chain with the first target certificate and the group of superior certificates when the group of superior certificates are found, wherein the target certificate chain includes the first target certificate and the group of superior certificates with a cascade relationship; a first processing module, used to store the target certificate chain in a first storage path corresponding to the first target business in the target device, and notify the first target business to load the target certificate chain from the first storage path.

[0015] According to yet another embodiment of the present invention, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the steps of any one of the above method embodiments when run.

[0016] According to yet another embodiment of the present invention, there is provided an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0017] Through the present invention, a group of correspondences and certificate cascade relationships are recorded in the digital certificate management module of the target device, wherein each correspondence in the group of correspondences is a correspondence between a business identifier of a business and a certificate identifier of a certificate required for use by a business, and the certificate cascade relationship is used to represent the cascade relationship between a group of certificates stored in the digital certificate management module. When a first certificate acquisition request sent by a first target business is obtained, the certificate identifier of a certificate having a correspondence with the business identifier of the first target business is searched in a group of correspondences, and when it is determined that the certificate identifier of the first target certificate has a correspondence with the business identifier of the first target business, a group of superior certificates of the first target certificate are searched according to the certificate cascade relationship. When a group of superior certificates are found, the first target certificate and the group of superior certificates are combined into a target certificate chain, and the target certificate chain is stored in a first storage path corresponding to the first target business, and the first target business is notified to record the target certificate chain from the first storage path. The purpose of unified management of all business certificates on the target device by the digital certificate management module on the target device is achieved, avoiding the problem that each business in the related technology needs to manage its own digital certificate, resulting in cumbersome page operations and certificates cannot be used mutually. Therefore, the problem of low management efficiency of business certificates existing in the related technology is solved, and the effect of improving the management efficiency of business certificates is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 It is a block diagram of the hardware structure of a mobile terminal of the method for managing a service certificate according to an embodiment of the present invention;

[0019] Figure 2 is a flow chart of a method for managing a service certificate according to an embodiment of the present invention;

[0020] Figure 3 is a schematic diagram of centralized management of embedded device certificates according to an embodiment of the present invention;

[0021] Figure 4 is a schematic diagram of the certificate cascading relationship according to an embodiment of the present invention;

[0022] Figure 5 is a schematic diagram of a digital certificate centralized management and allocation process according to a specific embodiment of the present invention;

[0023] Figure 6 4 is a structural block diagram of a device for managing service certificates according to an embodiment of the present invention. DETAILED DESCRIPTION

[0024] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings and in combination with the embodiments.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0026] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 FIG. 1 is a block diagram of the hardware structure of a mobile terminal of the method for managing a service certificate according to an embodiment of the present invention. Figure 1 As shown, the mobile terminal may include one or more ( Figure 1 Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the mobile terminal may also include a transmission device 106 and an input / output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the mobile terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations shown.

[0027] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the management method of the business certificate in the embodiment of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the mobile terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0028] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the mobile terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0029] In this embodiment, a method for managing a service certificate is provided. Figure 2 is a flow chart of a method for managing a service certificate according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps:

[0030] Step S202, obtaining a first certificate acquisition request sent by a first target service on a target device to a digital certificate management module, wherein the digital certificate management module is located on the target device, and a set of correspondences and certificate cascade relationships are recorded in the digital certificate management module, each correspondence in the set of correspondences is a correspondence between a service identifier of a service and a certificate identifier of a certificate required to be used by the service, and the certificate cascade relationship is used to represent a cascade relationship between a set of certificates stored in the digital certificate management module;

[0031] Step S204, in response to the first certificate acquisition request, searching the set of correspondences for a certificate identifier of a certificate having a correspondence relationship with the service identifier of the first target service;

[0032] Step S206, when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the service identifier of the first target service, searching for a group of superior certificates of the first target certificate according to the certificate cascade relationship, wherein the first target certificate is a certificate required to be used by the first target service;

[0033] Step S208, when the group of superior certificates is found, the first target certificate and the group of superior certificates are combined into a target certificate chain, wherein the target certificate chain includes the first target certificate and the group of superior certificates having a cascade relationship;

[0034] Step S210: store the target certificate chain in a first storage path corresponding to the first target service in the target device, and notify the first target service to load the target certificate chain from the first storage path.

[0035] Through the above steps, a set of correspondences and certificate cascade relationships are recorded in the digital certificate management module of the target device, wherein each correspondence in a set of correspondences is a correspondence between a business identifier of a business and a certificate identifier of a certificate required for a business, and the certificate cascade relationship is used to represent the cascade relationship between a set of certificates stored in the digital certificate management module. When a first certificate acquisition request sent by a first target business is obtained, the certificate identifier of a certificate having a correspondence with the business identifier of the first target business is searched in a set of correspondences, and when it is determined that the certificate identifier of the first target certificate has a correspondence with the business identifier of the first target business, a set of superior certificates of the first target certificate is searched according to the certificate cascade relationship. When a set of superior certificates is found, the first target certificate and the set of superior certificates are combined into a target certificate chain, and the target certificate chain is stored in a first storage path corresponding to the first target business, and the first target business is notified to record the target certificate chain from the first storage path. The purpose of unified management of all business certificates on the target device by the digital certificate management module on the target device is achieved, avoiding the problem that each business in the related technology needs to manage its own digital certificate, resulting in cumbersome page operations and certificates cannot be used mutually. Therefore, the problem of low management efficiency of business certificates existing in the related technology is solved, and the effect of improving the management efficiency of business certificates is achieved.

[0036] The execution subject of the above steps may be a device, for example, the above target device, or an embedded device, or a management module, or a processor with human-computer interaction capability configured on a storage device, or a processing device or processing unit with similar processing capabilities, etc., but not limited thereto. The following takes the target device executing the above operations as an example (only an exemplary description, in actual operation, other devices or modules may also be used to execute the above operations) for description:

[0037] In the above embodiment, a first certificate acquisition request sent to a digital certificate management module by a first target service on a target device is obtained, wherein the digital certificate management module is located on the target device, and a set of correspondences and certificate cascade relationships are recorded in the digital certificate management module, each correspondence in a set of correspondences is a correspondence between a service identifier of a service and a certificate identifier of a certificate required for use by a service, and the certificate cascade relationship is used to represent a cascade relationship between a set of certificates stored in the digital certificate management module. Taking the above target device as an embedded device as an example, multiple target services (including the above first target service) can be run in the embedded device, for example, a HyperText Transfer Protocol Secure (HTTPS) service, or a Real Time Streaming Protocol (RTS) service. Protocol, referred to as RTSP) service, or other services. At the same time, the target device includes a digital certificate management module, which records the correspondence between the identifier of each service and the certificate identifier of the certificate required for the service, and also records the cascade relationship between the certificates. For example, the certificate corresponding to the HTTPS service is certificate C, and certificate C may have an upper-level certificate B, and certificate B may have an upper-level certificate A. The above certificate cascade relationship records the cascade relationship between the upper and lower certificates related to the certificate of each service; in response to a first certificate acquisition request sent by the first target service, search in a set of corresponding relationships whether there is a certificate identifier of a certificate that has a corresponding relationship with the service identifier of the first target service. When it is found that the certificate identifier of the first target certificate (such as the certificate identifier is C1) has a corresponding relationship with the service identifier of the first target service (such as the service identifier is B001), search the first target certificate according to the certificate cascade relationship. A group of superior certificates of the target certificate, that is, to find out whether the first target certificate has an superior certificate. In actual applications, there may be one superior certificate, or there may be multiple layers of superior certificates. The first target certificate (such as C1 certificate) is the certificate required for the first target business (such as B001 business); when a group of superior certificates is found, the first target certificate and a group of superior certificates are combined into a target certificate chain, wherein the target certificate chain includes the first target certificate and a group of superior certificates with a cascade relationship, that is, the first target certificate and a group of superior certificates form a chain cascade relationship. For example, the certificate corresponding to the above-mentioned HTTPS business is C certificate, and C certificate may have an superior certificate B, and certificate B may have an superior certificate A, then certificate C and certificates B and A are combined into a target certificate chain; then, the target certificate chain is stored in the first storage path corresponding to the first target business in the target device, and the first target business is notified to load the target certificate chain from the first storage path.The purpose of unified management of all business certificates on the target device by the digital certificate management module on the target device is achieved, avoiding the problem that each business in the related technology needs to manage its own digital certificate, resulting in cumbersome page operations and certificates cannot be used mutually. Therefore, the problem of low management efficiency of business certificates existing in the related technology is solved, and the effect of improving the management efficiency of business certificates is achieved.

[0038] Now combined Figure 3 , Figure 4 The above embodiment is further described. Figure 3 Schematic diagram of centralized management of embedded device certificates according to an embodiment of the present invention. Figure 3 The process of business 1 obtaining a certificate is used as an example to illustrate the process, which includes: ① Business 1 sends a certificate acquisition request to the certificate management module (corresponding to the aforementioned digital certificate management module); ② The certificate management module determines whether there is a superior certificate for Certificate 1 when it determines that there is a certificate matching Business 1 (such as Certificate 1). When it is determined that there is a superior certificate, Certificate 1 and its superior certificate form a certificate chain and write it to the storage area (similar to the aforementioned first storage path); ③ The certificate management module notifies Business 1, for example, reminds Business 1 to update the certificate; ④ Business 1 loads the certificate chain from the storage area. In this embodiment, the embedded device may include multiple businesses, such as Figure 3 Service 2 in the example can also load the certificate in the same steps as service 1. The certificate can be a newly imported certificate or a certificate that is updated from the original service certificate. Figure 4 is a schematic diagram of the certificate cascade relationship according to an embodiment of the present invention, assuming that Figure 4 The C1 certificate is a certificate that corresponds to the business identifier of the above-mentioned first target business. Through the certificate cascade relationship, it can be determined that the superior certificate of the C1 certificate is B1, and the superior certificate of the B1 certificate is A1, that is, A1 and B1 constitute the above-mentioned group of superior certificates. Then, A1, B1 and C1 form a certificate chain, that is, the C1 certificate and its group of superior certificates (namely A1, B1) form a chain cascade relationship; thereby, the certificate chain is stored in the storage path corresponding to the first target business to notify the first target business to load the certificate chain.

[0039] In an optional embodiment, the method also includes: obtaining a second certificate acquisition request sent to the digital certificate management module by the second target business on the target device; in response to the second certificate acquisition request, searching for the certificate identifier of the certificate that has a corresponding relationship with the business identifier of the second target business in the set of correspondences; when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the business identifier of the second target business and the target certificate chain is cached, storing the target certificate chain in the second storage path corresponding to the second target business in the target device, and notifying the second target business to load the target certificate chain from the second storage path. In this embodiment, when the second target service sends a second certificate acquisition request to the digital certificate management module, the digital certificate management module searches the above set of correspondences for a certificate identifier corresponding to the service identifier of the second target service (such as the service identifier B002). When the first target certificate (such as the above C1 certificate) is found to have a correspondence with the service identifier of the second target service and the above target certificate chain is cached, the target certificate chain can be directly stored in the second storage path corresponding to the second target service. In actual applications, different services may share the same certificate. For example, a cache is provided in the target device, and the cache can store the certificate chain composed of the previous or previous certificate acquisition processes, such as the certificate chain corresponding to a certain service, or the certificate chains corresponding to multiple services. In this way, the certificate chain corresponding to the second target service can be quickly stored in the second storage path corresponding to the second target service, so that the second target service can quickly load the corresponding target certificate chain. Through this embodiment, the purpose of different businesses sharing the same business certificate is achieved, the problem of certificates between different businesses being unable to be used mutually in the related technology is avoided, and the management efficiency of business certificates is improved; at the same time, by setting up a cache, the next time the same certificate acquisition request is received, the corresponding certificate chain can be quickly stored in the storage path corresponding to the business, thereby achieving the effect of improving business operation efficiency and improving user experience.

[0040] In an optional embodiment, the method also includes: obtaining a second certificate acquisition request sent to the digital certificate management module by the second target service on the target device; in response to the second certificate acquisition request, searching for the certificate identifier of the certificate that has a corresponding relationship with the service identifier of the second target service in the set of corresponding relationships; when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the service identifier of the second target service and the target certificate chain is not cached, searching for the set of superior certificates of the first target certificate according to the certificate cascade relationship, wherein the first target certificate is the certificate required to be used by the second target service; when the set of superior certificates is found, the first target certificate and the set of superior certificates form the target certificate chain; the target certificate chain is stored in the second storage path corresponding to the second target service in the target device, and the second target service is notified to load the target certificate chain from the second storage path. In this embodiment, when the second target service sends a second certificate acquisition request to the digital certificate management module, the digital certificate management module searches for the certificate identifier of the certificate corresponding to the service identifier of the second target service (such as the service identifier B002) in the above-mentioned set of corresponding relationships. When the first target certificate (such as the above-mentioned C1 certificate) is found to have a corresponding relationship with the service identifier of the second target service (that is, the first target certificate is the certificate required to be used by the second target service), and the above-mentioned target certificate chain is not cached, then a group of superior certificates of the C1 certificate is searched according to the certificate cascade relationship, that is, whether the C1 certificate has an superior certificate. When a group of superior certificates is found, a target certificate chain is formed, and the target certificate chain is stored in the second storage path corresponding to the second target service, and the second target service is notified to load the target certificate chain from the second storage path. Through this embodiment, the purpose of different services sharing the same service certificate is achieved, that is, the purpose of certificate sharing is achieved, and the problem of certificates between different services being unable to be used mutually and low management efficiency in the related art is avoided, and the problem of improving the management efficiency of service certificates is achieved.

[0041] In an optional embodiment, the storing of the target certificate chain in the first storage path corresponding to the first target service in the target device, and notifying the first target service to load the target certificate chain from the first storage path, includes: writing the target certificate chain and private key encryption information into the first designated file and the second designated file in the first storage path respectively, and notifying the first target service to load the target certificate chain from the first designated file, and notifying the first target service to decrypt the private key encryption information in the second designated file, wherein the private key encryption information is information obtained by encrypting the first private key corresponding to the first target certificate, and the first private key is the private key required to be used by the first target service. In this embodiment, the above-mentioned first private key may be the private key corresponding to the certificate (such as the aforementioned C1 certificate) required to be used by the first target service, the private key encryption information is information obtained by encrypting the first private key, and the private key encryption information may also be a private key file, and the target certificate chain and private key encryption information may be written into the first storage path respectively, for example, the target certificate chain and private key encryption information are written into the first designated file and the second designated file respectively, and the first target service is notified to update the certificate and private key. Through this embodiment, the private key corresponding to the certificate is encrypted and stored, thereby improving security performance. At the same time, the efficiency of certificate management is improved by uniformly managing the certificates of various services.

[0042] In an optional embodiment, before writing the target certificate chain and the private key encryption information into the first designated file and the second designated file in the first storage path respectively, the method further includes: obtaining the first private key; encrypting the first private key in the target hardware device or target software module in the target device to obtain the private key encryption information, and storing the private key encryption information in the target storage unit in the target device, wherein the target hardware device or target software module is configured to prohibit access by devices outside the target device. In this embodiment, the first private key can be encrypted in the target hardware device or target software module in the target device to obtain the private key encryption information (or private key file), and the target hardware device or target software module is configured to prohibit access by external devices and prohibit access by programs other than those allowed access rights on the target device, that is, programs on the target device that do not have access rights are also prohibited from accessing the target hardware device or target software module, that is, the first private key is encrypted in a trusted execution environment, ensuring encrypted storage of the private key file, thereby achieving the effect of improving security performance.

[0043] In an optional embodiment, after notifying the first target service to decrypt the private key encrypted information in the second designated file, the method further includes: obtaining the private key encrypted information sent by the first target service to the target hardware device or the target software module; decrypting the private key encrypted information in the target hardware device or the target software module to obtain the first private key; and sending the first private key to the first target service. In this embodiment, the first target service sends private key encrypted information (or private key file) to the target hardware device or the target software module, and the target hardware device or the target software module decrypts the private key encrypted information to obtain the first private key, and then sends the first private key to the first target service, that is, the private key encrypted information is decrypted in the trusted execution environment to obtain the first private key, which ensures the security of the private key, thereby achieving the effect of improving security performance. Optionally, in actual applications, after obtaining (or updating) the certificate and private key, the first target service can access the server (or the opposite end device), that is, interact with other service ends or devices. Through this embodiment, the effect of ensuring the safe use of the service certificate is achieved.

[0044] In an optional embodiment, before searching for the certificate identifier of the certificate having a corresponding relationship with the service identifier of the first target service in the set of corresponding relationships in response to the first certificate acquisition request, the method further includes: obtaining configuration information sent to the digital certificate management module, wherein the configuration information is used to indicate the certificate required to be used for each service in a set of services; and configuring the set of corresponding relationships in the digital certificate management module according to the configuration information. In this embodiment, the configuration information sent to the digital certificate management module can be obtained in advance, wherein the configuration information is used to indicate the certificate required to be used for each service. In actual applications, the target device may include multiple services, and the certificates required to be used for each service may be the same or different. In actual applications, the user can configure the corresponding certificate for each service, and a set of corresponding relationships can be configured in the digital certificate management module based on the configuration information. Through this embodiment, the purpose of configuring the corresponding relationship between each service identifier and the certificate identifier corresponding to each service based on the configuration information is achieved.

[0045] In an optional embodiment, before searching for the certificate identifier of the certificate having a corresponding relationship with the service identifier of the first target service in the set of corresponding relationships in response to the first certificate acquisition request, the method further includes: obtaining a first certificate chain imported on the target device, wherein the first certificate chain includes a first group of certificates having a cascade relationship; for each certificate in the first group of certificates on the first certificate chain, performing the following operations, wherein when performing the following operations, each certificate is a current certificate: determining whether the current certificate has been stored on the target device; if it is determined that the current certificate is not stored on the target device, storing the current certificate on the target device; if it is determined that the current certificate is already stored on the target device, canceling the storage of the current certificate on the target device. In this embodiment, a certificate or a certificate chain (such as the first certificate chain mentioned above) can be imported on the target device. When importing the certificate or the certificate chain, for each certificate (such as certificate D), it is first determined whether the certificate has been stored on the target device. If it is determined that the certificate (such as certificate D) has been stored on the target device, canceling the storage of the certificate on the target device again. Only when it is determined that the certificate (such as certificate D) has not been stored on the target device, will the certificate be stored on the target device. Through this embodiment, the certificate chain is split into individual certificates, which prevents the problem of duplicate storage of certificates, thereby achieving the effect of improving the efficiency of certificate management and achieving the effect of saving device storage space.

[0046] In an optional embodiment, the method also includes: obtaining a relationship deletion request sent to the digital certificate management module, wherein the relationship deletion request is used to request deletion of a target corresponding relationship in the set of corresponding relationships, and the target corresponding relationship is a corresponding relationship between a business identifier of a third target business and a certificate identifier of a certificate required to be used by the third target business; in response to the relationship deletion request, deleting the target corresponding relationship in the set of corresponding relationships; or when an abnormality is detected in the first target certificate, deleting the target certificate chain in the first storage path. In this embodiment, when a relationship deletion request is received and sent to the digital certificate management module to request deletion of the target corresponding relationship, the target corresponding relationship in a set of corresponding relationships is deleted, that is, the corresponding relationship between the service and the certificate is unbound, and the third certificate chain and the third encryption private key in the storage path corresponding to the third target service are deleted, wherein the third certificate chain and the third encryption private key in the storage path corresponding to the third target service are the certificate chain and the encryption private key required for the third target service; optionally, in actual applications, the correspondence between multiple services and the corresponding certificates can be deleted at the same time through the digital certificate management module, while in the related technology, only each service can be deleted separately; or, when the digital certificate management module detects that there is an abnormality in the first target certificate, the digital certificate management module will automatically trigger the relationship deletion request and perform the deletion in accordance with the above-mentioned acquisition. The deletion operation is performed in a similar processing flow as when a relationship deletion request is received. For example, the target certificate chain and private key encryption information in the first storage path are deleted, wherein the target certificate chain and private key encryption information are the certificate chain and encrypted private key required for the first target business, that is, the certificate file under the storage path corresponding to the first target business is deleted. Optionally, a notification can be sent to the first target business to remind that the business certificate (i.e., the first target certificate) has been deleted. Optionally, in actual applications, when deleting the certificate file of a certain business (such as the target certificate chain corresponding to the first target certificate), the certificate cascade relationship recorded in the digital certificate management module can also be modified at the same time, for example, the cascade relationship with the first target certificate having a superior-subordinate relationship is deleted. Optionally, a cascade relationship is established between the subordinate certificate of the original first target certificate and the superior certificate of the first target certificate. Through this embodiment, the efficiency of the certificate deletion operation is improved, and the purpose of timely deleting the certificate file when an abnormality is detected in the certificate is also achieved, so as to save the storage resources of the device and improve the efficiency of certificate management.

[0047] Obviously, the above described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. The present invention will be specifically described below in conjunction with the embodiments.

[0048] Figure 5 FIG. 1 is a schematic diagram of a centralized management and allocation process of digital certificates according to a specific embodiment of the present invention. Figure 5As shown, the process includes:

[0049] 1. Notify the digital certificate management module which services on the device will use the certificate, and inform the certificate management module of the certificate storage path information for each service.

[0050] 2. Import or generate a certificate on the device:

[0051] (1) Users can import third-party certificates or third-party certificate chains by themselves. When importing a certificate chain, the certificate chain will also be split into individual certificates to prevent the problem of duplicate storage of certificates and occupying device space. The private key corresponding to the certificate will be securely encrypted and stored using technologies such as trusted environments.

[0052] (2) The digital certificate management module has a built-in root certificate, which can issue sub-certificates and encrypted private keys when necessary.

[0053] (3) Users can apply for a digital certificate request from the device. After the digital certificate request is issued by a third-party authority, the authority's root certificate and sub-certificate can be imported into the device. The private key of the sub-certificate will also be securely encrypted and stored.

[0054] 3. Users can uniformly assign / update certificates for each service on the device. For example, if the HTTPS service is specified to use certificate A, then in the digital certificate module, certificate A will first find all its superior certificates to form a certificate chain; then this certificate chain and the encrypted private key file will be written into two files under the certificate directory of the HTTPS service respectively; finally, the digital certificate module will send a notification to remind the HTTPS service to update the certificate and private key. For another example, if the user continues to specify the use of certificate B for the MQTT service, certificate B will also be assigned to the MQTT service according to the above process. In this step, after importing the certificate, the certificate chain is generated in combination with the message that the service requires a certificate, and is written into the path of the service certificate.

[0055] 4. After the user imports or deletes a certificate, the digital certificate management module will automatically update and record the validity status, certificate chain status, and business binding status of each certificate.

[0056] 5. When the user actively unbinds the certificate from the business, or when the module self-checks and finds that the certificate is abnormal and needs to be unbound from the business, the certificate file in the business's certificate directory will be deleted and a notification will be sent to remind the business that the certificate has been deleted.

[0057] 6. When deleting a certificate, if the certificate is bound to a service, the service will be unbound first, and then the certificate information will be completely deleted from the device.

[0058] In the above embodiment, the certificate management business of all certificates is separated from each business, and the certificates are centrally managed in one module, and the private key files are securely stored in a unified manner through a trusted environment, etc. When a business needs to use a certificate, the management module directly allocates the required certificate to the business, and after the allocation is completed, it will notify the business to re-read the certificate and private key file, making it easier for the business module to update the certificate.

[0059] Through the above embodiment, digital certificates are changed from being maintained by each business to being centrally and securely managed and distributed. The digital certificate management module uniformly manages the certificates of all businesses and securely stores private keys. Businesses can easily update digital certificates. As long as the certificate that a business needs to use is reselected in the digital certificate management module, a notification will be sent to the business, prompting the business to use the new certificate.

[0060] Through the embodiment of the present invention, the digital certificate management module uniformly manages the certificate files of various businesses, achieving the effect of easy updating and easy distribution; in addition, the private key corresponding to the digital certificate is securely encrypted and stored after being uniformly managed by the digital certificate management module, such as storage in a trusted environment, thereby improving security performance.

[0061] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present invention.

[0062] In this embodiment, a service certificate management device is also provided. Figure 6 is a structural block diagram of a device for managing a service certificate according to an embodiment of the present invention, such as Figure 6 As shown, the device comprises:

[0063] A first acquisition module 602 is used to acquire a first certificate acquisition request sent by a first target service on a target device to a digital certificate management module, wherein the digital certificate management module is located on the target device, and a set of correspondences and certificate cascade relationships are recorded in the digital certificate management module, each correspondence in the set of correspondences is a correspondence between a service identifier of a service and a certificate identifier of a certificate required to be used by the service, and the certificate cascade relationship is used to represent a cascade relationship between a set of certificates stored in the digital certificate management module;

[0064] A first search module 604 is used for searching, in response to the first certificate acquisition request, a certificate identifier of a certificate having a corresponding relationship with the service identifier of the first target service in the set of corresponding relationships;

[0065] A second search module 606 is used to search for a group of superior certificates of the first target certificate according to the certificate cascade relationship when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the service identifier of the first target service, wherein the first target certificate is a certificate required to be used by the first target service;

[0066] A first composition module 608 is configured to, when the group of superior certificates is found, combine the first target certificate and the group of superior certificates into a target certificate chain, wherein the target certificate chain includes the first target certificate and the group of superior certificates in a cascade relationship;

[0067] The first processing module 610 is configured to store the target certificate chain in a first storage path corresponding to the first target service in the target device, and notify the first target service to load the target certificate chain from the first storage path.

[0068] In an optional embodiment, the above-mentioned device also includes: a second acquisition module, used to obtain a second certificate acquisition request sent to the digital certificate management module by the second target service on the target device; a third search module, used to respond to the second certificate acquisition request and search for the certificate identifier of the certificate that has a corresponding relationship with the service identifier of the second target service in the set of correspondences; a second processing module, used to store the target certificate chain in the second storage path corresponding to the second target service in the target device when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the service identifier of the second target service and the target certificate chain is cached, and notify the second target service to load the target certificate chain from the second storage path.

[0069] In an optional embodiment, the above-mentioned device also includes: a third acquisition module, which is used to obtain a second certificate acquisition request sent to the digital certificate management module by the second target service on the target device; a fourth search module, which is used to respond to the second certificate acquisition request and search for the certificate identifier of the certificate that has a corresponding relationship with the service identifier of the second target service in the set of corresponding relationships; a fifth search module, which is used to search for the set of superior certificates of the first target certificate according to the certificate cascade relationship when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the service identifier of the second target service and the target certificate chain is not cached, wherein the first target certificate is the certificate required to be used by the second target service; a second composition module, which is used to form the target certificate chain with the first target certificate and the set of superior certificates when the set of superior certificates is found; and a third processing module, which is used to store the target certificate chain in a second storage path corresponding to the second target service in the target device, and notify the second target service to load the target certificate chain from the second storage path.

[0070] In an optional embodiment, the above-mentioned first processing module 610 includes: a first processing unit, used to write the target certificate chain and private key encryption information into the first designated file and the second designated file in the first storage path respectively, and notify the first target business to load the target certificate chain from the first designated file, and notify the first target business to decrypt the private key encryption information in the second designated file, wherein the private key encryption information is information encrypted by the first private key corresponding to the first target certificate, and the first private key is the private key required to be used by the first target business.

[0071] In an optional embodiment, the above-mentioned device also includes: a fourth acquisition module, used to obtain the first private key before writing the target certificate chain and the private key encryption information into the first designated file and the second designated file in the first storage path respectively; a fourth processing module, used to encrypt the first private key in the target hardware device or target software module in the target device, obtain the private key encryption information, and store the private key encryption information in the target storage unit in the target device, wherein the target hardware device or target software module is set to prohibit access by devices located outside the target device.

[0072] In an optional embodiment, the above-mentioned device also includes: a fifth acquisition module, which is used to obtain the private key encryption information sent by the first target business to the target hardware device or the target software module after notifying the first target business to decrypt the private key encryption information in the second designated file; a decryption module, which is used to decrypt the private key encryption information in the target hardware device or the target software module to obtain the first private key; and a sending module, which is used to send the first private key to the first target business.

[0073] In an optional embodiment, the device also includes: a sixth acquisition module, used to obtain configuration information sent to the digital certificate management module before searching for the certificate identifier of the certificate that has a corresponding relationship with the service identifier of the first target service in the set of correspondences in response to the first certificate acquisition request, wherein the configuration information is used to indicate the certificate required to be used for each service in a set of services; a configuration module, used to configure the set of correspondences in the digital certificate management module according to the configuration information.

[0074] In an optional embodiment, the above-mentioned device also includes: a seventh acquisition module, which is used to obtain the first certificate chain imported on the target device before searching the certificate identifier of the certificate that has a corresponding relationship with the business identifier of the first target business in the set of correspondences in response to the first certificate acquisition request, wherein the first certificate chain includes a first group of certificates with a cascade relationship; an execution module, which is used to perform the following operations for each certificate in the first group of certificates on the first certificate chain, wherein when performing the following operations, each certificate is a current certificate: determine whether the current certificate is already stored on the target device; if it is determined that the current certificate is not stored on the target device, store the current certificate on the target device; if it is determined that the current certificate is already stored on the target device, cancel the storage of the current certificate on the target device.

[0075] In an optional embodiment, the above-mentioned device also includes: an eighth acquisition module, used to obtain a relationship deletion request sent to the digital certificate management module, wherein the relationship deletion request is used to request deletion of a target corresponding relationship in the set of corresponding relationships, and the target corresponding relationship is a corresponding relationship between a service identifier of a third target service and a certificate identifier of a certificate required to be used by the third target service; a first deletion module, used to delete the target corresponding relationship in the set of corresponding relationships in response to the relationship deletion request; or a second deletion module, used to delete the target certificate chain in the first storage path when an abnormality is detected in the first target certificate.

[0076] It should be noted that the above modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.

[0077] An embodiment of the present invention further provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.

[0078] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0079] An embodiment of the present invention further provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0080] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0081] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0082] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order than here, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.

[0083] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for managing a service certificate, characterized in that: include: Obtaining a first certificate acquisition request sent by a first target service on a target device to a digital certificate management module, wherein the digital certificate management module is located on the target device, and a set of correspondences and certificate cascade relationships are recorded in the digital certificate management module, each correspondence in the set of correspondences being a correspondence between a service identifier of a service and a certificate identifier of a certificate required to be used by the service, and the certificate cascade relationship is used to represent a cascade relationship between a set of certificates stored in the digital certificate management module; In response to the first certificate acquisition request, searching the set of correspondences for a certificate identifier of a certificate having a correspondence relationship with the service identifier of the first target service; When it is found that the certificate identifier of the first target certificate has a corresponding relationship with the service identifier of the first target service, searching for a group of superior certificates of the first target certificate according to the certificate cascade relationship, wherein the first target certificate is a certificate required to be used by the first target service; In the case where the group of superior certificates is found, the first target certificate and the group of superior certificates are combined into a target certificate chain, wherein the target certificate chain includes the first target certificate and the group of superior certificates in a cascade relationship; The target certificate chain is stored in a first storage path corresponding to the first target service in the target device, and the first target service is notified to load the target certificate chain from the first storage path.

2. The method according to claim 1, characterized in that The method further comprises: Acquire a second certificate acquisition request sent by a second target service on the target device to the digital certificate management module; In response to the second certificate acquisition request, searching the set of correspondences for a certificate identifier of a certificate having a correspondence relationship with the service identifier of the second target service; When it is found that the certificate identifier of the first target certificate has a corresponding relationship with the business identifier of the second target business, and the target certificate chain is cached, the target certificate chain is stored in a second storage path corresponding to the second target business in the target device, and the second target business is notified to load the target certificate chain from the second storage path.

3. The method according to claim 1, characterized in that The method further comprises: Acquire a second certificate acquisition request sent by a second target service on the target device to the digital certificate management module; In response to the second certificate acquisition request, searching the set of correspondences for a certificate identifier of a certificate having a correspondence relationship with the service identifier of the second target service; When it is found that the certificate identifier of the first target certificate has a corresponding relationship with the service identifier of the second target service, and the target certificate chain is not cached, searching for the set of superior certificates of the first target certificate according to the certificate cascade relationship, wherein the first target certificate is a certificate required to be used by the second target service; In the case where the group of superior certificates is found, the first target certificate and the group of superior certificates form the target certificate chain; The target certificate chain is stored in a second storage path corresponding to the second target service in the target device, and the second target service is notified to load the target certificate chain from the second storage path.

4. The method according to any one of claims 1 to 3, characterized in that The storing the target certificate chain in a first storage path corresponding to the first target service in the target device, and notifying the first target service to load the target certificate chain from the first storage path, includes: The target certificate chain and private key encryption information are written into the first designated file and the second designated file in the first storage path respectively, and the first target service is notified to load the target certificate chain from the first designated file, and the first target service is notified to decrypt the private key encryption information in the second designated file, wherein the private key encryption information is information encrypted by the first private key corresponding to the first target certificate, and the first private key is the private key required to be used by the first target service.

5. The method according to claim 4, characterized in that Before writing the target certificate chain and the private key encryption information into the first designated file and the second designated file in the first storage path respectively, the method further includes: Obtaining the first private key; The first private key is encrypted in a target hardware device or a target software module in the target device to obtain the private key encrypted information, and the private key encrypted information is stored in a target storage unit in the target device, wherein the target hardware device or the target software module is configured to prohibit access by devices located outside the target device.

6. The method according to claim 5, characterized in that After notifying the first target service to decrypt the private key encrypted information in the second designated file, the method further includes: Acquire the private key encryption information sent by the first target service to the target hardware device or the target software module; decrypting the private key encrypted information in the target hardware device or the target software module to obtain the first private key; The first private key is sent to the first target service.

7. The method according to claim 1, characterized in that Before searching, in response to the first certificate acquisition request, the group of correspondences for a certificate identifier of a certificate having a correspondence with the service identifier of the first target service, the method further includes: Acquire configuration information sent to the digital certificate management module, wherein the configuration information is used to indicate the certificate required to be used by each service in a group of services; The set of corresponding relationships is configured in the digital certificate management module according to the configuration information.

8. The method according to claim 1, characterized in that Before searching, in response to the first certificate acquisition request, the group of correspondences for a certificate identifier of a certificate having a correspondence with the service identifier of the first target service, the method further includes: Acquire a first certificate chain imported on the target device, wherein the first certificate chain includes a first group of certificates having a cascade relationship; For each certificate in the first set of certificates in the first certificate chain, perform the following operations, wherein each certificate is a current certificate when performing the following operations: Determining whether the current certificate is already stored on the target device; If it is determined that the current certificate is not stored on the target device, storing the current certificate on the target device; In the case where it is determined that the current certificate has been stored on the target device, the storage of the current certificate on the target device is cancelled.

9. The method according to claim 1, characterized in that The method further comprises: Obtaining a relationship deletion request sent to the digital certificate management module, wherein the relationship deletion request is used to request deletion of a target corresponding relationship in the set of corresponding relationships, wherein the target corresponding relationship is a corresponding relationship between a service identifier of a third target service and a certificate identifier of a certificate required to be used by the third target service; in response to the relationship deletion request, deleting the target corresponding relationship in the set of corresponding relationships; or When it is detected that the first target certificate is abnormal, the target certificate chain in the first storage path is deleted.

10. A service certificate management device, characterized in that: include: A first acquisition module, used for acquiring a first certificate acquisition request sent by a first target service on a target device to a digital certificate management module, wherein the digital certificate management module is located on the target device, and a set of correspondences and certificate cascade relationships are recorded in the digital certificate management module, each correspondence in the set of correspondences being a correspondence between a service identifier of a service and a certificate identifier of a certificate required to be used by the service, and the certificate cascade relationship is used to represent a cascade relationship between a set of certificates stored in the digital certificate management module; A first search module, configured to search, in response to the first certificate acquisition request, for a certificate identifier of a certificate having a corresponding relationship with a service identifier of the first target service in the set of corresponding relationships; A second search module is used to search for a group of superior certificates of the first target certificate according to the certificate cascade relationship when it is found that the certificate identifier of the first target certificate has a corresponding relationship with the service identifier of the first target service, wherein the first target certificate is a certificate required to be used by the first target service; a first composition module, configured to, when the group of superior certificates is found, combine the first target certificate and the group of superior certificates into a target certificate chain, wherein the target certificate chain includes the first target certificate and the group of superior certificates in a cascade relationship; The first processing module is configured to store the target certificate chain in a first storage path corresponding to the first target service in the target device, and notify the first target service to load the target certificate chain from the first storage path.

11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program implements the steps of the method described in any one of claims 1 to 9 when executed by a processor.

12. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method described in any one of claims 1 to 9 are implemented.

Citation Information

Patent Citations

  • Certificate verification method and device based on block chain, storage medium and electronic device

    CN110011988A

  • Service certificate management method, terminal, and server

    CN111066284A