Certificate management method and device on a consortium chain, equipment and readable storage medium

By integrating digital certificate management on the consortium blockchain and utilizing Merkle tree root node computation and blockchain verification, the issues of independence and complexity in digital certificate management are resolved, achieving unified certificate management and enhanced security.

CN115913757BActive Publication Date: 2026-02-13CHINA CITIC BANK CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211577571.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-05
Publication Date
2026-02-13
Estimated Expiration
2042-12-05

AI Technical Summary

Technical Problem

In existing technologies, digital certificate management is either independent of the consortium blockchain system or deployed as a third-party component within the consortium blockchain, which increases system complexity and management difficulty, and deviates from the difficulty of blockchain management.

Method used

By integrating the digital certificate management process onto the consortium blockchain, the digital certificate information issued by the CA center and the user request information are processed and integrated using the Merkle tree root node. The registration, cancellation and verification of certificates are realized through blockchain verification and consensus mechanisms, reducing the dependence on additional management centers.

Benefits of technology

It enables unified management of digital certificate data and blockchain data, reduces system complexity, improves the security and management efficiency of identity information, and allows blockchain nodes to determine the validity of certificates based on blockchain data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913757B_ABST
    Figure CN115913757B_ABST
Patent Text Reader

Abstract

The application relates to the field of software technology development, in particular to a consortium chain certificate management method and device, equipment and a readable storage medium, the method comprises the following steps: sending digital certificate information signed by a CA center to a data integration module for integrated processing to obtain integrated block data, the data integration module is a module for calculating a root node of a Merkle tree and a first digital certificate root node based on the first information and integrating the calculation result; sending the block data to a user and commanding the user to verify and input verification information; then receiving the verification result, sending the verification result, request information for obtaining the digital certificate initiated by the user and user public key information to a certificate processing module for processing to obtain a registered digital certificate of the user. The application integrates digital certificate data in block data on a consortium chain, thereby reducing the complexity of the system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of software technology development, in particular to a consortium chain certificate management method and device, equipment and readable storage medium. BACKGROUND

[0002] The digital certificate management forms a system independently of the consortium chain system or is deployed in the consortium chain as a third-party component. In addition to maintaining the blockchain data, the node also needs to maintain the digital certificate information, which increases the complexity of the system. On the other hand, the information of the digital certificate is managed by the CA, which is separated from the block, increasing the difficulty of management. Nowadays, a method and device are needed to unify the digital certificate management process with the blockchain data, so that the blockchain system does not need to maintain an additional digital certificate management center. SUMMARY

[0003] The purpose of the present application is to provide a consortium chain certificate management method, device, equipment and readable storage medium to improve the above problems. In order to achieve the above purpose, the technical scheme adopted by the present application is as follows:

[0004] On the one hand, the present application provides a consortium chain certificate management method, which comprises:

[0005] Obtaining first information and second information, the first information being digital certificate information issued by at least one CA center, and the second information being request information for obtaining the digital certificate initiated by a user and user public key information;

[0006] Sending the first information to a data integration module for integrated processing to obtain integrated block data, the data integration module being a module for calculating the root node of the Merkle tree and the first digital certificate root node of the first information, and integrating the calculation result;

[0007] Sending a first command, the first command including sending the block data to the user and commanding the user to verify and input verification information;

[0008] Receiving the verification result and sending the verification result and the second information to a certificate processing module for processing to obtain the user's registered digital certificate.

[0009] Secondly, the present application provides a consortium chain certificate management device, which comprises:

[0010] A first obtaining unit is configured to obtain first information and second information, the first information being digital certificate information issued by at least one CA center, and the second information being request information for obtaining the digital certificate initiated by a user and user public key information;

[0011] The first processing unit is configured to send the first information to a data integration module for integrated processing to obtain integrated block data, wherein the data integration module is configured to calculate a root node of a Merkle tree and a first digital certificate root node based on the first information, and to integrate the calculation results.

[0012] The first sending unit is configured to send a first command, wherein the first command comprises a command for sending the block data to a user and commanding the user to verify and input verification information.

[0013] The second processing unit is configured to receive the verification result and send the verification result and the second information to a certificate processing module for processing to obtain a registered digital certificate of the user.

[0014] In a third aspect, an embodiment of the present application provides a device for managing a certificate on a consortium chain, the device comprising a memory and a processor. The memory is configured to store a computer program; and the processor is configured to execute the computer program to implement the steps of the method for managing the certificate on the consortium chain.

[0015] In a fourth aspect, an embodiment of the present application provides a readable storage medium, wherein the readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the method for managing the certificate on the consortium chain.

[0016] The present application has the following beneficial effects:

[0017] The present application integrates digital certificate data on block data on a consortium chain, thereby reducing the complexity of the system. The present application also has the functions of registration, cancellation, and verification of a consortium chain node certificate. The present application unifies the digital certificate management process with the block chain data, so that the block chain system does not need to maintain an additional digital certificate management center. All data are arranged on the block chain, which is consistent with the management of other business data. The block chain node can determine the validity of the digital certificate based on the block chain data.

[0018] Other features and advantages of the present application will be described in the following description, and some will become apparent from the description, or will be learned from the practice of the present application. The purposes and other advantages of the present application can be achieved and obtained by the structures particularly pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF DRAWINGS

[0019] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This is a schematic diagram of a certificate management method on a consortium blockchain as described in an embodiment of the present invention;

[0021] Figure 2 This is a schematic diagram of a certificate management device for a consortium blockchain as described in an embodiment of the present invention;

[0022] Figure 3 This is a schematic diagram of a certificate management device structure for a consortium blockchain as described in an embodiment of the present invention. Detailed Implementation

[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0024] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this invention, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0025] like Figure 1 As shown, this embodiment provides a method for managing certificates on a consortium blockchain, which includes steps S1, S2, S3 and S4.

[0026] Step S1: Obtain first information and second information. The first information is digital certificate information issued by at least one CA center, and the second information is the user's request information for obtaining the digital certificate and the user's public key information.

[0027] Step S2, the first information is sent to a data integration module for integration processing to obtain integrated block data, the data integration module is a module that calculates the root node of the Merkle tree and the first digital certificate root node based on the first information, and integrates the calculation results;

[0028] Step S3, a first command is sent, the first command includes sending the block data to the user and commanding the user to verify and input the verification information;

[0029] Step S4, the verification result is received, and the verification result and the second information are sent to a certificate processing module for processing to obtain a registered digital certificate of the user.

[0030] It can be understood that the present application integrates the digital certificate data in the block data on the alliance chain, reducing the complexity of the system. And the present application also has the functions of registration, cancellation and verification of the alliance chain node certificate. And the present application unifies the digital certificate management process with the block chain data, so that the block chain system does not need to maintain an additional digital certificate management center. All data is set on the block chain, consistent with other business data management, and the block chain node can determine the validity of the digital certificate based on the block chain data.

[0031] In one specific embodiment of the present disclosure, the step S2 includes steps S21, S22 and S23.

[0032] Step S21, based on the first information, a first ROOT value of the digital certificate and a first digest value of the digital certificate are calculated;

[0033] Step S22, the first ROOT value of the digital certificate and the first digest value of the digital certificate are sent to a root node calculation module, and the root node of the Merkle tree and the first digital certificate root node are calculated through the SHA-256 algorithm, wherein the root node of the Merkle tree is the first ROOT value of the digital certificate;

[0034] Step S23, the root node of the Merkle tree and the first digital certificate root node are sent to the block header of the certificate authority center on the alliance chain for integration processing to obtain integrated block data.

[0035] It can be understood that the above steps calculate the first ROOT value and the first digest value of the digital certificate, then calculate the root node of the Merkle tree and the first digital certificate root node based on the SHA-256 algorithm, and place them in the block header of the certificate authority center on the alliance chain, which reduces the complexity of the system, improves the security of the identity information and reduces the dependence on the authoritative authentication center.

[0036] In an embodiment of the present disclosure, the step S21 comprises a step S211, a step S212 and a step S213.

[0037] The step S211 comprises calculating first hash values corresponding to all the CA center issued digital certificate information by a hash algorithm, and sorting the first hash values corresponding to all the digital certificate information in order to obtain second hash values, wherein the second hash values are the sorted hash values.

[0038] The step S212 comprises performing splicing processing on two adjacent second hash values based on a SHA-256 algorithm to obtain third hash values, wherein the third hash values are the spliced hash values.

[0039] The step S213 comprises performing iterative splicing processing on the third hash values until a first root value is finally obtained, wherein the first root value is a value obtained by repeatedly splicing all the third hash values in the same hash value.

[0040] It can be understood that the above steps are to explain how to calculate the first hash values corresponding to the digital certificate information by the hash algorithm, and to sort and splice to obtain the first root value. The first root value obtained is saved in another database, which does not excessively rely on the certification authority, and guarantees the security of the information.

[0041] In an embodiment of the present disclosure, the step S4 comprises a step S41, a step S42, a step S43 and a step S44.

[0042] The step S41 comprises judging whether the verification result is a legal certificate content. If the verification result is a legal certificate content, the second information and the preset certificate restriction information are used to form the user's registered digital certificate information.

[0043] The step S42 comprises calculating a hash value corresponding to the user's registered digital certificate information based on a hash algorithm to generate a fourth hash value, and using the fourth hash value as a leaf node of the Merkle tree.

[0044] The step S43 comprises calculating a second digest value corresponding to the user's registered digital certificate information based on a SHA-256 algorithm, and performing root node calculation based on the second digest value and the fourth hash value to obtain a second digital certificate root node.

[0045] The step S44 comprises performing block consensus on-chain processing on the second digital certificate root node to obtain the user's registered digital certificate.

[0046] It can be understood that the above steps set a verification step to determine whether the verification result is legal, then call the user's profile information and certificate information to generate a new certificate, protect the privacy of the customer's certificate, realize the customer registration certificate function, and perform block consensus on-chain processing on the second digital certificate root node, so that the blockchain system does not need to maintain an additional digital certificate management center.

[0047] In one specific embodiment of the present disclosure, the step S4 includes steps S5, S6 and S7.

[0048] Step S5, query all nodes on the alliance chain to determine whether all nodes are modified based on the second digital certificate root node, and if all nodes on the alliance chain are not modified, call the fifth hash value corresponding to the node that is not modified;

[0049] Step S6, call the proof path value corresponding to the fifth hash value based on the fifth hash value corresponding to the node that is not modified;

[0050] Step S7, send the proof path value to the node that is not modified to modify to obtain a node with a modified proof path.

[0051] It can be understood that in the above steps, the proof path values of all nodes on the alliance chain are queried to determine whether the proof path values of all nodes correspond to modification, and the proof path of the node that is not modified is queried, and the proof path of the corresponding node is modified based on the query result, which can test whether the certificate is registered successfully. If the proof path of the node that is not modified cannot be queried, it indicates that the registration is not successful. All data in the above steps are on the blockchain, consistent with other business data management, and the blockchain node can determine the validity of the digital certificate according to the blockchain data.

[0052] In one specific embodiment of the present disclosure, the step S4 includes steps S8, S9, S10 and S11.

[0053] Step S8, call the time information of the user's registered digital certificate;

[0054] Step S9, determine whether the time information exceeds the preset time limit, if the time information exceeds the preset time limit, calculate the hash value of the certificate corresponding to the time information exceeding the preset time limit to obtain a sixth hash value;

[0055] Step S10, traverse all the leaf nodes of the Merkle tree, judge whether there is a value with the same sixth hash value in the leaf nodes of the Merkle tree, if there is a value with the same sixth hash value in the leaf nodes of the Merkle tree, delete the leaf node of the Merkle tree corresponding to the sixth hash value, and obtain an updated Merkle tree;

[0056] Step S11, modify the proof path of all leaf nodes in the updated Merkle tree, and obtain a consortium chain in which digital certificates exceeding the time limit are cancelled.

[0057] It can be understood that the present application judges whether the certificate is invalid by judging whether the time information exceeds the preset time limit, and then deletes the leaf node of the Merkle tree corresponding to the invalid certificate, thereby achieving the purpose of cancelling the certificate, realizing the function of unifying the digital certificate management process and the blockchain data of the present application, and not calling any data of the digital certificate management center.

[0058] Embodiment 2

[0059] As shown in Figure 2 The present embodiment provides a device for managing certificates on a consortium chain, which comprises a first acquisition unit 701, a first processing unit 702, a first sending unit 703 and a second processing unit 704.

[0060] The first acquisition unit 701 is configured to acquire first information and second information, wherein the first information is digital certificate information issued by at least one CA center, and the second information is request information for obtaining the digital certificate initiated by a user and user public key information.

[0061] The first processing unit 702 is configured to send the first information to a data integration module for integrated processing to obtain integrated block data, wherein the data integration module is a module for calculating the root node of the Merkle tree and the first digital certificate root node of the first information, and integrating the calculation result.

[0062] The first sending unit 703 is configured to send a first command, wherein the first command comprises a command for sending the block data to a user and commanding the user to verify and input verification information.

[0063] The second processing unit 704 is configured to receive the verification result and send the verification result and the second information to a certificate processing module for processing to obtain a registered digital certificate of the user.

[0064] In one specific embodiment of the present disclosure, the first processing unit 702 comprises a first processing subunit 7021, a first sending subunit 7022 and a second processing subunit 7023.

[0065] The first processing subunit 7021 is configured to calculate a first ROOT value of the digital certificate and a first digest value of the digital certificate based on the first information.

[0066] The first sending subunit 7022 is configured to send the first ROOT value of the digital certificate and the first digest value of the digital certificate to a root node calculation module, and calculate a root node of a Merkle tree and a first digital certificate root node through a SHA-256 algorithm, wherein the root node of the Merkle tree is the first ROOT value of the digital certificate.

[0067] The second processing subunit 7023 is configured to send the root node of the Merkle tree and the first digital certificate root node to a block header of a certificate authority center on the alliance chain for integrated processing to obtain integrated block data.

[0068] In an embodiment of the present disclosure, the first processing subunit 7021 includes a third processing subunit 70211, a fourth processing subunit 70212, and a fifth processing subunit 70213.

[0069] The third processing subunit 70211 is configured to calculate first hash values corresponding to all the digital certificate information issued by the CA center through a hash algorithm, and sort all the first hash values corresponding to the digital certificate information in a chronological order to obtain a second hash value, wherein the second hash value is a sorted hash value.

[0070] The fourth processing subunit 70212 is configured to splice two adjacent second hash values based on a SHA-256 algorithm to obtain a third hash value, wherein the third hash value is a spliced hash value.

[0071] The fifth processing subunit 70213 is configured to perform iterative splicing processing on the third hash value until a first ROOT value is finally obtained, wherein the first ROOT value is a value obtained by repeatedly splicing all the third hash values in the same hash value.

[0072] In an embodiment of the present disclosure, the second processing unit 704 includes a first judgment subunit 7041, a sixth processing subunit 7042, a seventh processing subunit 7043, and an eighth processing subunit 7044.

[0073] The first judgment subunit 7041 is configured to judge whether the verification result is a legal certificate content, and if the verification result is a legal certificate content, call the second information and preset certificate restriction information to form user registration digital certificate information.

[0074] The sixth processing subunit 7042 is configured to calculate a hash value corresponding to the registration digital certificate information of the user based on a hash algorithm, generate a fourth hash value, and take the fourth hash value as a leaf node of the Merkle tree.

[0075] The seventh processing subunit 7043 is configured to calculate a second digest value corresponding to the registration digital certificate information of the user based on an SHA-256 algorithm, and perform root node calculation based on the second digest value and the fourth hash value to obtain a second digital certificate root node.

[0076] The eighth processing subunit 7044 is configured to perform block consensus on-chain processing on the second digital certificate root node to obtain the registration digital certificate of the user.

[0077] In an embodiment of the present disclosure, the second processing unit 704 further includes a first judgment unit 705, a third processing unit 706, and a fourth processing unit 707.

[0078] The first judgment unit 705 is configured to query all nodes on the alliance chain, and judge whether all nodes are modified based on the second digital certificate root node. If all nodes on the alliance chain are not modified, the fifth hash value corresponding to the node that is not modified is called.

[0079] The third processing unit 706 is configured to call a proof path value corresponding to the fifth hash value based on the fifth hash value corresponding to the node that is not modified.

[0080] The fourth processing unit 707 is configured to send the proof path value to the node that is not modified to perform modification, to obtain a node with modified proof path.

[0081] In an embodiment of the present disclosure, the second processing unit 704 further includes a first calling unit 708, a second judgment unit 709, a fifth processing unit 710, and a sixth processing unit 711.

[0082] The first calling unit 708 is configured to call time information of the registration digital certificate of the user.

[0083] The second judgment unit 709 is configured to judge whether the time information exceeds a preset time limit. If the time information exceeds the preset time limit, a hash value of a certificate corresponding to the time information exceeding the preset time limit is calculated to obtain a sixth hash value.

[0084] The fifth processing unit 710 is configured to traverse all leaf nodes of the Merkle tree, determine whether there is a value same as the sixth hash value in the leaf nodes of the Merkle tree, and if there is a value same as the sixth hash value in the leaf nodes of the Merkle tree, delete the leaf node of the Merkle tree corresponding to the sixth hash value to obtain an updated Merkle tree.

[0085] The sixth processing unit 711 is configured to modify the proof path of all leaf nodes in the updated Merkle tree to obtain a consortium chain in which the digital certificate that exceeds the time limit is revoked.

[0086] It should be noted that, as for the apparatus in the above-mentioned embodiments, the specific manners in which various modules perform operations have been described in detail in the embodiments of the method, and will not be described in detail here.

[0087] Embodiment 3

[0088] Corresponding to the above method embodiments, the embodiments of the disclosure also provide a consortium chain certificate management device. The consortium chain certificate management device described below can be mutually referred to the consortium chain certificate management method described above.

[0089] Figure 3 is a block diagram of a consortium chain certificate management device 800 according to an exemplary embodiment. As shown in Figure 3 The consortium chain certificate management device 800 can include a processor 801, a memory 802. The consortium chain certificate management device 800 can also include one or more of a multimedia component 803, an input / output (I / O) interface 804, and a communication component 805.

[0090] The processor 801 is configured to control overall operations of the certificate management device 800 on the alliance chain, so as to complete all or part of the steps in the above-mentioned certificate management method on the alliance chain. The memory 802 is configured to store various types of data to support the operations of the certificate management device 800 on the alliance chain, which can include, for example, instructions for any application or method operating on the certificate management device 800 on the alliance chain, and application-related data, such as contact data, sent and received messages, pictures, audio, video, and the like. The memory 802 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The multimedia component 803 can include a screen and an audio component. The screen can be a touch screen, for example, and the audio component is configured to output and / or input audio signals. For example, the audio component can include a microphone configured to receive external audio signals. The received audio signals can be further stored in the memory 802 or transmitted through the communication component 805. The audio component also includes at least one speaker configured to output audio signals. The I / O interface 804 provides an interface between the processor 801 and other interface modules, which can be a keyboard, a mouse, a button, and the like. The buttons can be virtual buttons or physical buttons. The communication component 805 is configured to perform wired or wireless communication between the certificate management device 800 on the alliance chain and other devices. The wireless communication, such as Wi-Fi, Bluetooth, near field communication (NFC), 2G, 3G or 4G, or a combination of one or more of them, so the corresponding communication component 805 can include a Wi-Fi module, a Bluetooth module, and an NFC module.

[0091] In an example embodiment, the certificate management device 800 on the alliance chain can be implemented by one or more Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), controller, microcontroller, microprocessor or other electronic elements for executing the above-mentioned method for managing certificate on the alliance chain.

[0092] In another example embodiment, a computer readable storage medium including program instructions is also provided, which, when executed by a processor, implements the steps of the above-mentioned method for managing certificate on the alliance chain. For example, the computer readable storage medium can be the above-mentioned memory 802 including program instructions, which can be executed by the processor 801 of the certificate management device 800 on the alliance chain to complete the above-mentioned method for managing certificate on the alliance chain.

[0093] Embodiment 4

[0094] Corresponding to the above method embodiments, the embodiments of the present disclosure also provide a readable storage medium, and the readable storage medium described below can be referred to in conjunction with the above-mentioned method for managing certificate on the alliance chain.

[0095] A readable storage medium, the readable storage medium has a computer program stored thereon, and the computer program, when executed by a processor, implements the steps of the above-mentioned method for managing certificate on the alliance chain.

[0096] The readable storage medium can be a U disk, a mobile hard disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk or an optical disk, and various readable storage media that can store program codes.

[0097] The above only describes the preferred embodiments of the present disclosure and is not used to limit the present disclosure. For those skilled in the art, the present disclosure can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the spirit and principles of the present disclosure shall be included in the protection scope of the present disclosure.

[0098] The above merely illustrates the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of the changes or replacements within the technical range disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for managing certificates on a consortium blockchain, characterized in that, The method comprises the following steps: obtaining first information and second information, the first information being digital certificate information issued by at least one CA center, and the second information being request information and user public key information for obtaining the digital certificate initiated by a user; sending the first information to a data integration module for integrated processing to obtain integrated block data, the data integration module being a module for calculating a root node of a Merkle tree and a first digital certificate root node based on the first information and integrating the calculation result; sending a first command, the first command comprising sending the block data to the user and commanding the user to verify and input verification information; receiving a verification result and sending the verification result and the second information to a certificate processing module for processing to obtain a registered digital certificate of the user; sending the first information to the data integration module for integrated processing to obtain integrated block data, which comprises: calculating a first ROOT value of the digital certificate and a first digest value of the digital certificate based on the first information; sending the first ROOT value of the digital certificate and the first digest value of the digital certificate to a root node calculation module to calculate a root node of a Merkle tree and a first digital certificate root node through a SHA-256 algorithm, wherein the root node of the Merkle tree is the first ROOT value of the digital certificate; sending the root node of the Merkle tree and the first digital certificate root node to a block header of a certificate authority center on the alliance chain for integrated processing to obtain integrated block data. 2.The method of claim 1, wherein, calculating a first ROOT value of the digital certificate based on the first information, which comprises: calculating first hash values corresponding to all the digital certificate information issued by the CA center through a hash algorithm, and sorting all the first hash values corresponding to the digital certificate information in order to obtain second hash values, the second hash values being the sorted hash values; performing splicing processing on two adjacent second hash values based on a SHA-256 algorithm to obtain third hash values, the third hash values being the spliced hash values; performing iterative splicing processing on the third hash values until a first ROOT value is finally obtained, the first ROOT value being a value obtained by repeatedly splicing all the third hash values in the same hash value. 3.The method of claim 1, wherein, receiving the verification result and sending the verification result and the second information to the certificate processing module for processing to obtain a registered digital certificate of the user, which comprises: determining whether the verification result is legal certificate content, and if the verification result is legal certificate content, calling the second information and preset certificate restriction information to form registered digital certificate information of the user; calculating a hash value corresponding to the registered digital certificate information of the user based on a hash algorithm to generate a fourth hash value, and taking the fourth hash value as a leaf node of the Merkle tree; The second digest value corresponding to the registration digital certificate information of the user is calculated based on the SHA-256 algorithm, and the second digital certificate root node is obtained by performing root node calculation based on the second digest value and the fourth hash value; The second digital certificate root node is subjected to block consensus chain processing to obtain the registration digital certificate of the user. 4.The method of claim 1, wherein, After obtaining the registration digital certificate of the user, the following steps are further included: All nodes on the alliance chain are queried to determine whether all nodes are modified based on the second digital certificate root node, and if all nodes on the alliance chain are not modified, a fifth hash value corresponding to the node that is not modified is called; The proof path value corresponding to the fifth hash value is called based on the fifth hash value corresponding to the node that is not modified; The proof path value is sent to the node that is not modified for modification to obtain the node with the modified proof path. 5.The method of claim 1, wherein, After obtaining the registration digital certificate of the user, the following steps are further included: The time information of the registration digital certificate of the user is called; It is judged whether the time information exceeds the preset time limit, and if the time information exceeds the preset time limit, a sixth hash value corresponding to the certificate whose time information exceeds the preset time limit is calculated; All leaf nodes of the Merkle tree are traversed to determine whether there is a value with the same sixth hash value in the leaf nodes of the Merkle tree, and if there is a value with the same sixth hash value in the leaf nodes of the Merkle tree, the leaf node of the Merkle tree corresponding to the sixth hash value is deleted to obtain an updated Merkle tree; The proof path of all leaf nodes in the updated Merkle tree is modified to obtain the alliance chain in which the digital certificate exceeding the time limit is cancelled. 6.A certificate management apparatus on a consortium chain, characterized by comprising: It includes: The first acquisition unit is configured to acquire first information and second information, the first information being digital certificate information issued by at least one CA center, and the second information being request information and user public key information initiated by a user to obtain the digital certificate; The first processing unit is configured to send the first information to a data integration module for integrated processing to obtain integrated block data, the data integration module being a module that calculates a root node of a Merkle tree and a first digital certificate root node based on the first information, and integrates the calculation results; The first sending unit is configured to send a first command, the first command including sending the block data to a user and commanding the user to verify and input verification information; The second processing unit is configured to receive a verification result and send the verification result and the second information to a certificate processing module for processing to obtain a registration digital certificate of the user. The device includes: The first processing subunit is configured to calculate a first ROOT value of the digital certificate and a first digest value of the digital certificate based on the first information. The first sending subunit is configured to send the first ROOT value of the digital certificate and the first digest value of the digital certificate to a root node calculation module, and calculate a root node of a Merkle tree and a first digital certificate root node through an SHA-256 algorithm, wherein the root node of the Merkle tree is the first ROOT value of the digital certificate; The second processing subunit is configured to send the root node of the Merkle tree and the first digital certificate root node to a block header of a certificate authority center on the alliance chain for integrated processing to obtain integrated block data.

7. The management apparatus of a certificate on a consortium chain according to claim 6, wherein, The device comprises: The third processing subunit is configured to calculate first hash values corresponding to all digital certificate information issued by the CA center through a hash algorithm, sort the first hash values corresponding to all the digital certificate information in a sequence, and obtain a second hash value, wherein the second hash value is a sorted hash value; The fourth processing subunit is configured to perform splicing processing on two adjacent second hash values based on an SHA-256 algorithm to obtain a third hash value, wherein the third hash value is a spliced hash value; The fifth processing subunit is configured to perform iterative splicing processing on the third hash value until a first ROOT value is finally obtained, wherein the first ROOT value is a value obtained by repeatedly splicing all the third hash values in the same hash value. 8.The certificate management apparatus on a consortium chain according to claim 6, wherein, The device comprises: The first judgment subunit is configured to judge whether the verification result is a legal certificate content, and if the verification result is a legal certificate content, call the second information and preset certificate restriction information to form user registration digital certificate material information; The sixth processing subunit is configured to calculate a hash value corresponding to the user registration digital certificate material information based on a hash algorithm to generate a fourth hash value, and take the fourth hash value as a leaf node of the Merkle tree; The seventh processing subunit is configured to calculate a second digest value corresponding to the user registration digital certificate material information based on an SHA-256 algorithm, and perform root node calculation based on the second digest value and the fourth hash value to obtain a second digital certificate root node; The eighth processing subunit is configured to perform block consensus on-chain processing on the second digital certificate root node to obtain a user registration digital certificate. 9.The certificate management apparatus on a consortium chain according to claim 6, wherein, The device further comprises: The first judgment unit is configured to query all nodes on the alliance chain, judge whether all nodes are modified based on a second digital certificate root node, and if all nodes on the alliance chain are not modified, call a fifth hash value corresponding to a node that is not modified; The third processing unit is configured to call a proof path value corresponding to the fifth hash value based on the fifth hash value corresponding to the node that is not modified; The fourth processing unit is configured to send the proof path value to the node that is not modified to modify the node to obtain a node with a modified proof path. 10.The certificate management apparatus on a consortium chain according to claim 6, characterized in that, The device further comprises: The first calling unit is configured to call time information of the user registration digital certificate. The second judging unit is configured to judge whether the time information exceeds a preset time limit, and if the time information exceeds the preset time limit, calculate a hash value of a corresponding certificate of the time information exceeding the preset time limit to obtain a sixth hash value; The fifth processing unit is configured to traverse all leaf nodes of the Merkle tree, judge whether there is a value with the same sixth hash value in the leaf nodes of the Merkle tree, if there is a value with the same sixth hash value in the leaf nodes of the Merkle tree, delete the leaf node of the Merkle tree corresponding to the sixth hash value to obtain an updated Merkle tree; The sixth processing unit is configured to modify a proof path of all leaf nodes in the updated Merkle tree to obtain a consortium chain in which the digital certificate exceeding the time limit is cancelled. 11.A device for managing a certificate on a consortium chain, the device comprising: Comprise: A memory for storing a computer program; A processor for executing the computer program to implement the steps of the certificate management method on the consortium chain according to any one of claims 1 to 5.

12. A readable storage medium, characterized by: The computer program is stored on the readable storage medium, and when the computer program is executed by the processor, the steps of the certificate management method on the consortium chain according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Decentralized cross-trust-domain authentication method and system

    CN110061851A