Certificate management methods, devices, equipment and storage media

By generating and shielding sub-certificates through a centralized certificate management system, the problem of certificate leakage in multi-tenant cloud platforms is solved, and the secure isolation of certificates and resource consistency management are achieved.

CN116684177BActive Publication Date: 2026-07-17SHENZHEN SHENXIN INFORMATION SECURITY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN SHENXIN INFORMATION SECURITY CO LTD
Filing Date
2023-06-27
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In multi-tenant cloud platforms, tenant certificates are easily leaked, which poses a risk of other tenants or third parties stealing business data.

Method used

By using a centralized certificate management system, sub-certificates corresponding to authorized objects are generated, and the content of the sub-certificates is masked so that only authorized objects are allowed to use them. An index mapping relationship between identification information and sub-certificates is established to achieve centralized management and isolation of certificates.

Benefits of technology

It effectively reduces the risk of certificate leakage, ensures that tenants can only use authorized subcertificates and cannot obtain certificate content, and achieves consistent management of certificate resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116684177B_ABST
    Figure CN116684177B_ABST
Patent Text Reader

Abstract

This application provides a certificate management method, apparatus, and electronic device. The method includes: obtaining authorization information, which is used to determine the authorized object of the parent certificate, and the authorized object is at least one of multiple tenants of a cloud platform; generating a sub-certificate corresponding to the authorized object based on the authorization information; the sub-certificate is used to encrypt and / or decrypt transmitted data according to the key of the sub-certificate when the authorized object communicates with the cloud platform; masking the content of the sub-certificate to restrict the authorized object's access to the content of the sub-certificate; and sending the masked sub-certificate to the authorized object.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a certificate management method, and more particularly to a certificate management method, apparatus, electronic device, and computer storage medium. Background Technology

[0002] In the era of cloud computing, many enterprises deploy their business operations to cloud platforms via the internet, and each enterprise can manage its own operations on the cloud platform. This means multiple enterprises can use a single cloud management platform simultaneously, making multi-tenant architecture a requirement for many software and platform systems. In a multi-tenant scenario, an enterprise or even a department within an enterprise may be a tenant on the cloud platform. Tenants manage their own operations based on their certificates, and each tenant uses a different certificate. Currently, each tenant typically manages its own certificate, which can easily lead to certificate leaks. If a certificate is leaked, other tenants or third parties can use the leaked certificate to steal the tenant's business data on the cloud platform. Summary of the Invention

[0003] The embodiments of the present invention mainly provide a certificate management method, device, electronic device, and computer storage medium.

[0004] This invention provides a certificate management method applied to a centralized certificate management system, which manages parent certificates in a cloud platform; the method includes:

[0005] Obtain authorization information, which is used to determine the authorized object of the parent certificate, wherein the authorized object is at least one of the multiple tenants of the cloud platform;

[0006] Based on the authorization information, a sub-certificate corresponding to the authorized object is generated; the sub-certificate is used to encrypt and / or decrypt the transmitted data according to the key of the sub-certificate when the authorized object communicates with the cloud platform.

[0007] The content of the subcertificate is masked to restrict the authorized object's access to read the content of the subcertificate.

[0008] The subcertificate after the masking process is sent to the authorized object.

[0009] In the above scheme, after generating the sub-certificate corresponding to the authorized object based on the authorization information, the method further includes: establishing an index mapping relationship between the identification information of the authorized object and the sub-certificate.

[0010] As can be seen, by establishing an index mapping relationship between the identification information of authorized objects and subcertificates, the certificate centralized management system can find the subcertificates that the tenant is authorized to hold in the index mapping relationship based on the tenant's identification information.

[0011] In the above scheme, after establishing the index mapping relationship between the identification information of the authorized object and the sub-certificate, the method further includes: upon receiving a request from a tenant to re-acquire the certificate, obtaining the tenant's identification information; based on the tenant's identification information, searching in the index mapping relationship for identification information that is identical to the tenant's identification information; if it exists, determining the sub-certificate corresponding to the tenant's identification information and sending the sub-certificate to the tenant.

[0012] As can be seen, when a tenant requests to retrieve certificate information again, the system can search the index mapping relationship based on the tenant's identification information to determine whether the tenant has an authorized sub-certificate, thus enabling the centralized certificate management system to effectively manage certificates.

[0013] In the above scheme, obtaining authorization information includes: obtaining multiple parent certificates in the cloud platform; each of the multiple parent certificates includes at least one authorization field; and for each of the multiple parent certificates, extracting the authorization information based on the at least one authorization field.

[0014] As can be seen, based on at least one authorization field of each parent certificate in the cloud platform, authorization information is extracted, and a sub-certificate corresponding to the authorization object is generated according to the authorization information. The sub-certificate is generated based on the parent certificate and cannot be configured. Furthermore, the tenant can only obtain the sub-certificate and cannot obtain the parent certificate, which can effectively achieve isolation between the tenant and the parent certificate.

[0015] In the above scheme, after generating the sub-certificate corresponding to the authorized object, the method further includes: after receiving the instruction to delete the certificate, determining at least one sub-certificate to be deleted based on at least one authorization field of the parent certificate; and sending an instruction to delete the at least one sub-certificate to be deleted to the authorized object of the parent certificate.

[0016] As can be seen, after receiving the instruction to delete a certificate, an instruction to delete the corresponding sub-certificate can be sent to the tenant, which can achieve the consistency of certificate resources in the centralized certificate management system.

[0017] In the above scheme, the step of masking the content of the subcertificate to restrict the authorized object's access to read the content of the subcertificate includes: determining the authorized object's access to the subcertificate as allowed, and determining the authorized object's access to read the content of the subcertificate as prohibited, so as to achieve the masking of the content of the subcertificate.

[0018] As can be seen, since the authorized object can only use the sub-certificates issued by the certificate centralized management system, but cannot read the contents of the sub-certificates, it cannot leak the sub-certificates, thus effectively reducing the risk of certificate leakage in the cloud platform.

[0019] This invention also provides a certificate management device applied to a centralized certificate management system, the centralized certificate management system being used to manage parent certificates in a cloud platform; the device includes:

[0020] The acquisition module is used to acquire authorization information, which is used to determine the authorized object of the parent certificate, and the authorized object is at least one of the multiple tenants of the cloud platform;

[0021] The certificate generation module is used to generate a sub-certificate corresponding to the authorized object based on the authorization information; the sub-certificate is used to encrypt and / or decrypt the transmitted data according to the key of the sub-certificate when the authorized object communicates with the cloud platform;

[0022] A masking module is used to mask the content of the subcertificate in order to restrict the authorized object's access to read the content of the subcertificate.

[0023] The sending module is used to send the subcertificate after the masking process to the authorized object.

[0024] In one implementation, after generating the sub-certificate corresponding to the authorized object based on the authorization information, the processing module is further configured to:

[0025] Establish an index mapping relationship between the identification information of the authorized object and the sub-certificate.

[0026] In one implementation, the processing module is further configured to, after establishing the index mapping relationship between the identification information of the authorized object and the sub-certificate, obtain the identification information of the tenant upon receiving a request from the tenant to re-obtain the certificate; based on the tenant's identification information, search in the index mapping relationship for identification information that is identical to the tenant's identification information; if it exists, determine the sub-certificate corresponding to the tenant's identification information and send the sub-certificate to the tenant.

[0027] In one implementation, the acquisition module is used to acquire authorization information, including:

[0028] Obtain multiple parent certificates from the cloud platform; each of the multiple parent certificates includes at least one authorization field;

[0029] For each of the plurality of parent certificates, the authorization information is extracted based on the at least one authorization field.

[0030] In one implementation, the apparatus further includes a deletion module, which is configured to, after generating a sub-certificate corresponding to the authorized object and receiving an instruction to delete the certificate, determine at least one sub-certificate to be deleted based on at least one authorization field of the certificate; and send an instruction to the authorized object of the certificate to delete the at least one sub-certificate to be deleted.

[0031] In one implementation, the blocking module is used to block the content of the subcertificate to restrict the authorized object's access to read the content of the subcertificate. This includes: determining the authorized object's access to the subcertificate as allowed and determining the authorized object's access to read the content of the subcertificate as prohibited, thereby blocking the content of the subcertificate.

[0032] This invention also provides an electronic device, which includes a communication interface, a processor, and a memory for storing a computer program capable of running on the processor; wherein,

[0033] The communication interface is used to exchange information with each tenant of the cloud platform;

[0034] The processor executes the computer program to perform the following steps: obtaining authorization information, the authorization information being used to determine the authorized object of the parent certificate, the authorized object being at least one of multiple tenants of the cloud platform; generating a sub-certificate corresponding to the authorized object based on the authorization information; the sub-certificate being used to encrypt and / or decrypt transmitted data based on the key of the sub-certificate when the authorized object communicates with the cloud platform; masking the content of the sub-certificate to restrict the authorized object's access to the content of the sub-certificate; and sending the masked sub-certificate to the authorized object through the communication interface.

[0035] This invention also provides a computer storage medium storing a computer program that, when executed by a processor, implements any of the above-described certificate management methods.

[0036] As can be seen, this embodiment of the invention proposes a centralized certificate management system for centralized management of all certificates in the cloud platform. The centralized certificate management system generates a sub-certificate corresponding to the authorized object based on the obtained authorization information, and masks the content of the sub-certificate. The masked sub-certificate is then sent to the authorized object. Thus, the authorized object can use the sub-certificate issued by the centralized certificate management system, but cannot obtain the content of the sub-certificate, and therefore cannot leak the sub-certificate, thereby effectively reducing the risk of certificate leakage in the cloud platform.

[0037] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the invention. Attached Figure Description

[0038] Figure 1 A flowchart illustrating a certificate management method provided in an embodiment of the present invention;

[0039] Figure 2 A schematic diagram of a certificate management method provided in an embodiment of the present invention;

[0040] Figure 3 A flowchart illustrating the first specific implementation of a certificate management method provided in this embodiment of the invention;

[0041] Figure 4 A flowchart illustrating a second specific implementation of a certificate management method provided in an embodiment of the present invention;

[0042] Figure 5 A schematic diagram of a certificate management device provided in an embodiment of the present invention;

[0043] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0044] To address the technical problem of easy leakage of certificates on cloud platforms in related technologies, this invention proposes a technical solution. The embodiments of this invention will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the embodiments provided herein are merely illustrative of the invention and are not intended to limit the invention. Furthermore, the embodiments provided below are partial embodiments for implementing this invention, not all embodiments for implementing this invention. Unless otherwise specified, the technical solutions described in the embodiments of this invention can be implemented in any combination.

[0045] It should be noted that, in the embodiments of the present invention, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a method or apparatus that includes a list of elements includes not only the elements expressly stated, but also other elements not expressly listed, or elements inherent to implementing the method or apparatus. Without further limitations, an element defined by the phrase "comprising a..." does not exclude the presence of other related elements (e.g., steps in the method or units in the apparatus, such as portions of circuitry, processors, programs, or software, etc.) in the method or apparatus that includes that element.

[0046] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Furthermore, the term "at least one" in this document means any combination of at least two of any one or more elements. For example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C.

[0047] For example, the certificate management method provided in this embodiment of the invention includes a series of steps, but the certificate management method provided in this embodiment of the invention is not limited to the steps described herein. Similarly, the certificate management device provided in this embodiment of the invention includes a series of modules, but the certificate management device provided in this embodiment of the invention is not limited to the modules explicitly described, but may also include modules that need to be set up for obtaining relevant information or processing based on the information.

[0048] This invention provides a certificate management method applied to a centralized certificate management system, which manages all parent certificates in a cloud platform. Figure 1 This is a flowchart illustrating a certificate management method provided in an embodiment of the present invention, as shown below. Figure 1 As shown, the process may include:

[0049] Step 101: Obtain authorization information. The authorization information is used to determine the authorized object of the parent certificate. The authorized object is at least one of the multiple tenants of the cloud platform.

[0050] In this embodiment of the invention, a tenant refers to a user of the cloud platform, encompassing all data identifiable as a specific user within the cloud platform, such as accounts created on the cloud platform, and various data and customized applications configured on the cloud platform. When a tenant communicates with the cloud platform, it encrypts and / or decrypts the transmitted data using the certificate's key. Here, the certificate's key may include a private key and a public key. Each tenant uses a different certificate, and all parent certificates on the cloud platform are managed by a centralized certificate management system. The centralized certificate management system can perform operations such as creating, deleting, modifying, authorizing, and issuing parent certificates.

[0051] In this embodiment of the invention, the authorization information is used to determine the authorized object of the parent certificate. Here, the authorization information may be the tenant's identification information. Then, the certificate centralized management system can determine to authorize the certificate to the corresponding tenant based on the tenant's identification information.

[0052] Step 102: Generate a sub-certificate corresponding to the authorized object based on the authorization information; the sub-certificate is used to encrypt and / or decrypt the transmitted data according to the key of the sub-certificate when the authorized object communicates with the cloud platform.

[0053] In this embodiment of the invention, after obtaining the authorization information, the certificate centralized management system will instantiate the certificate authorized to the authorized object into a sub-certificate. The sub-certificate has a one-to-one correspondence with the authorized object, that is, only the authorized object can use the sub-certificate, while other tenants cannot use the sub-certificate.

[0054] Step 103: Mask the content of the subcertificate to restrict the authorized object's access to read the content of the subcertificate.

[0055] In this embodiment of the invention, before sending a subcertificate to an authorized object, the certificate centralized management system will first mask the content of the subcertificate. That is, the certificate centralized management system will restrict the authorized object's access to read the subcertificate. Here, the content of the subcertificate includes at least the public key and private key of the subcertificate. Thus, the authorized object can only obtain the name information of the subcertificate, but cannot obtain the public key and private key of the subcertificate.

[0056] In some embodiments, the process of masking the content of a subcertificate to restrict the authorized object's access to read the content of the subcertificate may include: determining the authorized object's access to the subcertificate as allowed, and determining the authorized object's access to read the content of the subcertificate as prohibited, thereby masking the content of the subcertificate.

[0057] As can be seen, since the authorized object can only use the sub-certificates issued by the certificate centralized management system, but cannot read the contents of the sub-certificates, it cannot leak the sub-certificates, thus effectively reducing the risk of certificate leakage in the cloud platform.

[0058] Step 104: Send the masked subcertificate to the authorized object.

[0059] In this embodiment of the invention, the authorized object can obtain sub-certificates sent by the certificate central management system; that is, the authorized object can obtain the sub-certificates authorized to it by the certificate central management system, but cannot obtain other sub-certificates. The authorized object can use the sub-certificate based on its name information, thereby enabling communication with the cloud platform.

[0060] As can be seen, this embodiment of the invention proposes a centralized certificate management system for centralized management of all parent certificates in the cloud platform. The centralized certificate management system generates a sub-certificate corresponding to the authorized object based on the obtained authorization information, and masks the content of the sub-certificate. The masked sub-certificate is then sent to the authorized object. Thus, the authorized object can only use the sub-certificate issued by the centralized certificate management system, but cannot obtain the content of the sub-certificate, and therefore cannot leak the sub-certificate, thereby effectively reducing the risk of certificate leakage in the cloud platform.

[0061] In some implementations, after generating the sub-certificate corresponding to the authorized object based on the authorization information, the method further includes:

[0062] Establish an index mapping relationship between the identification information of the authorized object and the sub-certificate.

[0063] In some embodiments, after generating a subcertificate corresponding to an authorized object, an index mapping relationship is established between the identifier information of the authorized object and the subcertificate. Here, the identifier information of the authorized object can be the name of the authorized object. Then, the certificate centralized management system can look up the subcertificate authorized to be held by the tenant in the index mapping relationship based on the tenant's identifier information.

[0064] For example, if the identification information of an authorized object is "ABC" and the sub-certificate of the authorized object is "first sub-certificate", then an index mapping relationship between "ABC" and "first sub-certificate" is established and saved to the certificate centralized management system.

[0065] As can be seen, by establishing an index mapping relationship between the identification information of authorized objects and subcertificates, the certificate centralized management system can find the subcertificates that the tenant is authorized to hold in the index mapping relationship based on the tenant's identification information.

[0066] In some implementations, after establishing the index mapping relationship between the identification information of the authorized object and the sub-certificate, the method further includes:

[0067] Upon receiving a request from a tenant to re-acquire a certificate, the tenant's identification information is obtained;

[0068] Based on the tenant's identification information, search the index mapping relationship to see if there is any identification information that is the same as the tenant's identification information;

[0069] If a subcertificate exists, the subcertificate corresponding to the tenant's identification information is determined and sent to the tenant; if no subcertificate exists, the subcertificate is not sent to the tenant.

[0070] In some embodiments, when the certificate management system malfunctions while sending a subcertificate to a tenant, resulting in the tenant not receiving the corresponding subcertificate, the tenant may send a request to the certificate management system to retrieve the certificate information again. Since the certificate management system has already generated the subcertificate corresponding to the authorized object based on the corresponding authorization information and established an index mapping relationship between the identification information of the authorized object and the subcertificate when the tenant first sends a request to the certificate management system to retrieve the certificate information, the certificate management system only needs to check whether the tenant has an authorized subcertificate through the index mapping relationship when it needs to send the subcertificate to the tenant again.

[0071] In some embodiments, upon receiving a request from a tenant to re-obtain a certificate, the tenant's request information includes the tenant's identification information. The certificate management system searches the index mapping relationship for an identifier that matches the tenant's identifier. If such an identifier exists, it indicates that the tenant has an authorized subcertificate, and a list of authorized subcertificates for the tenant is generated. The subcertificate corresponding to the tenant's identifier is then sent to the tenant.

[0072] In some embodiments, if there is no identifier information in the index mapping relationship that is the same as the tenant's identifier information, it means that the tenant does not have an authorized sub-certificate, that is, the tenant has not been authorized by the certificate centralized management system. Therefore, no sub-certificate is sent to the tenant.

[0073] As can be seen, when a tenant requests to retrieve certificate information again, the system can search the index mapping relationship based on the tenant's identification information to determine whether the tenant has an authorized sub-certificate, thus enabling the centralized certificate management system to effectively manage certificates.

[0074] In some implementations, obtaining authorization information includes:

[0075] Obtain multiple parent certificates from the cloud platform; each of the multiple parent certificates includes at least one authorization field;

[0076] For each of the plurality of parent certificates, the authorization information is extracted based on the at least one authorization field.

[0077] In some embodiments, the authorization field of the parent certificate is used to determine the authorized object of the parent certificate. Each parent certificate includes at least one authorization field, meaning that a parent certificate can authorize at least one tenant. Authorization information can be extracted based on at least one authorization field name of the parent certificate, and a sub-certificate corresponding to the authorized object can be generated based on the authorization information. It can be seen that in the certificate centralized management system, the parent certificate is configurable, while the sub-certificate is generated based on the parent certificate and cannot be configured. Furthermore, tenants can only obtain the sub-certificate and not the parent certificate, effectively achieving isolation between the tenant and the parent certificate.

[0078] In some embodiments, Figure 2 A schematic diagram of a certificate management method provided in an embodiment of the present invention is shown below. Figure 2 The cloud platform contains multiple parent certificates, namely Certificate 1 and Certificate 2. Certificate 1 includes two authorization fields, "product1" and "product2"; Certificate 2 includes one authorization field, "product1". Here, "product1" represents the identifier information of tenant 1, and "product2" represents the identifier information of tenant 2. The centralized certificate management system can then extract the authorization information, which is as follows: Certificate 1 authorizes tenant 1 and tenant 2, and Certificate 2 authorizes tenant 1.

[0079] In some embodiments, the certificate centralized management system generates sub-certificates corresponding to authorized objects based on authorization information, including: a first sub-certificate and a third sub-certificate corresponding to tenant 1, and a second sub-certificate corresponding to tenant 2. The first sub-certificate and the third sub-certificate are sent to tenant 1, and the second sub-certificate is sent to tenant 2. It can be seen that tenant 1 can hold the first sub-certificate and the third sub-certificate, and tenant 2 can hold the second sub-certificate.

[0080] In some other embodiments, if there is no authorization object corresponding to the parent certificate, the parent certificate may not include an authorization field. In this case, there is no need to generate a child certificate corresponding to the parent certificate.

[0081] As can be seen, based on at least one authorization field of each parent certificate in the cloud platform, authorization information is extracted, and a sub-certificate corresponding to the authorization object is generated according to the authorization information. The sub-certificate is generated based on the parent certificate and cannot be configured. The tenant can obtain the sub-certificate but cannot obtain the parent certificate, which can effectively achieve isolation between the tenant and the parent certificate.

[0082] In some implementations, after generating the sub-certificate corresponding to the authorized object, the method further includes:

[0083] Upon receiving an instruction to delete a certificate, at least one child certificate to be deleted is determined based on at least one authorization field of the parent certificate; an instruction to delete the at least one child certificate to be deleted is sent to the authorization object of the parent certificate.

[0084] For example, after identifying at least one subcertificate to be deleted, it can also be determined whether the at least one subcertificate to be deleted exists in the certificate centralized management system; if it exists, the at least one subcertificate to be deleted is deleted.

[0085] In some embodiments, each subcertificate corresponds to a parent certificate in the cloud platform. That is, the existence of a corresponding parent certificate in the cloud platform indicates that the parent certificate has authorized the tenant, enabling the certificate management system to generate the corresponding subcertificate and send it to the tenant. If the corresponding parent certificate in the cloud platform is deleted, it means that the parent certificate's authorization to the tenant has been revoked. Therefore, the corresponding subcertificate should also be deleted, and an instruction to delete the subcertificate should be sent to the tenant, thereby ensuring the consistency of certificate resources in the certificate management system.

[0086] In some embodiments, upon receiving an instruction to delete a certificate, the certificate management system first extracts authorization information from the certificate's authorization field, thereby identifying at least one subcertificate to be deleted. Then, it searches the certificate management system to see if the at least one subcertificate to be deleted exists. If it does, the corresponding subcertificate needs to be deleted, and an instruction to delete at least one subcertificate to be deleted is sent to the certificate's authorized object.

[0087] As can be seen, after receiving the instruction to delete a certificate, the certificate management system will also delete the corresponding sub-certificate and send the instruction to the tenant to delete the corresponding sub-certificate, thus achieving consistency of certificate resources in the certificate management system.

[0088] In this embodiment, after generating the sub-certificate corresponding to the authorized object, the mapping relationship between certificates can also be determined. This mapping relationship is between a parent certificate and a sub-certificate. In some embodiments, if the sending system experiences an abnormal restart or fault recovery, it can be determined whether the currently generated sub-certificate conforms to the mapping relationship between certificates. If it does not conform, the sub-certificate will be added and / or deleted according to the mapping relationship. Here, the process of adding a sub-certificate is the same as the process of generating a sub-certificate described above. By adding and / or deleting sub-certificates, the certificate centralized management system can accurately distribute sub-certificates to authorized objects, maintaining the normal operation of the certificate centralized management system.

[0089] Figure 3 This is a flowchart illustrating the first specific implementation of a certificate management method provided by an embodiment of the present invention, as shown below. Figure 3 As shown, the centralized certificate management system includes a controller, a certificate file management component, a server component, and a certificate management component. The certificate file management component, denoted as file_mgr, is used to obtain certificate files; the server component, denoted as apiserver, is used to create certificates; and the certificate management component, denoted as cert_mgr, is used to generate subcertificates and send the generated subcertificates to tenants.

[0090] Step 301: The controller sends the certificate file to the certificate file management component.

[0091] In this embodiment of the invention, the certificate file represents the public and private keys of the parent certificate, and the certificate file is used to generate the parent certificate.

[0092] Step 302: The certificate file management component sends index information to the controller.

[0093] In this embodiment of the invention, the notification information represents the index of the certificate file, and a parent certificate can be created based on the file index.

[0094] Step 303: The controller sends a command to the server component to create a parent certificate.

[0095] In this embodiment of the invention, the server control certificate file management component creates a parent certificate based on the file index.

[0096] Step 304: The server component sends certificate creation information to the certificate management component.

[0097] Step 305: The certificate management component sends a request message to the certificate file management component to obtain the certificate.

[0098] Step 306: The certificate file management component sends the parent certificate to the certificate management component.

[0099] Step 307: The certificate management component verifies the validity of the parent certificate.

[0100] In this embodiment of the invention, the certificate management component can verify the validity of the parent certificate according to a preset algorithm.

[0101] Step 308: The certificate management component sends the parent certificate's validity information to the server component.

[0102] Step 309: The server component sends a confirmation message to the certificate management component.

[0103] Step 310: The certificate management component sends the information for generating the subcertificate to the server component.

[0104] Step 311: The server component sends a confirmation message to the certificate management component.

[0105] Step 312: The certificate management component sends the subcertificate to the corresponding tenant.

[0106] Figure 4 A flowchart illustrating a second specific implementation of a certificate management method provided in this embodiment of the invention is shown below. Figure 4 As shown, the centralized certificate management system includes a controller, a server component, and a certificate management component. The server component, denoted as apiserver, is used to delete certificates; the certificate management component, denoted as cert_mgr, is used to manage subcertificates.

[0107] Step 401: The controller sends a command to the server component to delete the certificate.

[0108] Step 402: The server component sends a message to the controller that the certificate has been deleted.

[0109] Step 403: The server component sends a message to the certificate management component that the certificate has been deleted.

[0110] Step 404: The certificate management component deletes the corresponding subcertificate and sends an instruction to the tenant to delete the corresponding subcertificate.

[0111] Step 405: The tenant sends information to the certificate management component that the corresponding subcertificate has been deleted.

[0112] Step 406: The certificate management component sends the information to the server component that the corresponding subcertificate has been deleted.

[0113] Based on the same technical concept as the foregoing embodiments, see Figure 5 This invention provides a certificate management device applied to a centralized certificate management system, which manages parent certificates in a cloud platform; the device includes:

[0114] The acquisition module 501 is used to acquire authorization information, which is used to determine the authorized object of the parent certificate, and the authorized object is at least one of the multiple tenants of the cloud platform;

[0115] The certificate generation module 502 is used to generate a sub-certificate corresponding to the authorized object based on the authorization information; the sub-certificate is used to encrypt and / or decrypt the transmitted data according to the key of the sub-certificate when the authorized object communicates with the cloud platform;

[0116] The shielding module 503 is used to shield the content of the sub-certificate to restrict the authorized object's access to read the content of the sub-certificate.

[0117] The sending module 504 is used to send the subcertificate after the masking process to the authorized object.

[0118] In one implementation, the certificate generation module 502 is further configured to, after generating a sub-certificate corresponding to the authorized object based on the authorization information, establish an index mapping relationship between the identification information of the authorized object and the sub-certificate.

[0119] In one implementation, the certificate generation module 502 is further configured to, after establishing the index mapping relationship between the identification information of the authorized object and the subcertificate, obtain the identification information of the tenant upon receiving a request from the tenant to re-obtain the certificate; based on the tenant's identification information, search in the index mapping relationship for identification information that is identical to the tenant's identification information; if it exists, determine the subcertificate corresponding to the tenant's identification information and send the subcertificate to the tenant; if it does not exist, do not send the subcertificate to the tenant.

[0120] In one implementation, the acquisition module 501 is used to acquire authorization information, including:

[0121] Obtain multiple parent certificates from the cloud platform; each of the multiple parent certificates includes at least one authorization field;

[0122] For each of the plurality of parent certificates, the authorization information is extracted based on the at least one authorization field.

[0123] In one implementation, the apparatus further includes a deletion module, which is configured to, after generating a sub-certificate corresponding to the authorized object and receiving an instruction to delete the certificate, determine at least one sub-certificate to be deleted based on at least one authorization field of the certificate; and send an instruction to the authorized object of the certificate to delete the at least one sub-certificate to be deleted.

[0124] In one implementation, the blocking module 503 is used to block the content of the subcertificate to restrict the authorized object's access to read the content of the subcertificate. This includes: determining the authorized object's access to the subcertificate as allowed and determining the authorized object's access to read the content of the subcertificate as prohibited, thereby blocking the content of the subcertificate.

[0125] In practical applications, the acquisition module 501, certificate generation module 502, shielding module 503, sending module 504, and deletion module can all be implemented using a processor of an electronic device. The processor can be at least one of ASIC, DSP, DSPD, PLD, FPGA, CPU, controller, microcontroller, and microprocessor. This embodiment of the invention does not limit this.

[0126] It should be noted that the description of the above device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the description of the method embodiments of this application for understanding.

[0127] It should be noted that, in the embodiments of the present invention, if the above-described methods are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a terminal, server, etc.) to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.

[0128] Correspondingly, this embodiment of the invention also provides a computer program product, which includes computer-executable instructions for implementing any of the certificate management methods provided in this embodiment of the invention.

[0129] Accordingly, this embodiment of the invention further provides a computer storage medium storing computer-executable instructions, which are used to implement any of the certificate management methods provided in the above embodiments.

[0130] In some embodiments, the functions or modules of the apparatus provided in the present invention can be used to execute the methods described in the above method embodiments. The specific implementation can be referred to the description of the above method embodiments, and for the sake of brevity, it will not be repeated here.

[0131] Based on the same technical concept as the foregoing embodiments, see Figure 6 The electronic device 600 provided in this embodiment of the invention may include: a communication interface 601, a processor 602, and a memory 603 for storing computer programs capable of running on the processor; wherein,

[0132] The communication interface 601 is used to exchange information with each tenant of the cloud platform;

[0133] The processor 602 executes the computer program to perform the following steps: obtaining authorization information, the authorization information being used to determine the authorized object of the parent certificate, the authorized object being at least one of multiple tenants of the cloud platform; generating a sub-certificate corresponding to the authorized object based on the authorization information; the sub-certificate being used to encrypt and / or decrypt transmitted data based on the key of the sub-certificate when the authorized object communicates with the cloud platform; masking the content of the sub-certificate to restrict the authorized object's access to the content of the sub-certificate; and sending the masked sub-certificate to the authorized object through the communication interface 601.

[0134] Of course, in practical applications, the various components in electronic device 600 are coupled together through bus system 604. It can be understood that bus system 604 is used to realize the connection and communication between these components. In addition to a data bus, bus system 604 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in... Figure 6 The general designated all buses as Bus System 604.

[0135] The memory 603 in this embodiment is used to store various types of data to support the operation of the electronic device 600. Examples of such data include any computer program used to operate on the electronic device 600.

[0136] In one implementation, the processor 602 is further configured to run the computer program to perform the following steps: after generating a sub-certificate corresponding to the authorized object based on the authorization information, establishing an index mapping relationship between the identification information of the authorized object and the sub-certificate.

[0137] In one implementation, the processor 602 is further configured to run the computer program to perform the following steps: after establishing an index mapping relationship between the identification information of the authorized object and the subcertificate, upon receiving a request from the tenant to re-acquire the certificate, obtaining the tenant's identification information; based on the tenant's identification information, searching in the index mapping relationship for identification information identical to the tenant's identification information; if it exists, determining the subcertificate corresponding to the tenant's identification information, and sending the subcertificate to the tenant through the communication interface 601.

[0138] In one implementation, the processor 602 is further configured to run the computer program to perform the following steps: obtaining a plurality of parent certificates in a cloud platform; each of the plurality of parent certificates including at least one authorization field; and for each of the plurality of parent certificates, extracting the authorization information based on the at least one authorization field.

[0139] In one implementation, the processor 602 is further configured to run the computer program to perform the following steps: after generating a sub-certificate corresponding to the authorized object, upon receiving an instruction to delete a certificate, determining at least one sub-certificate to be deleted based on at least one authorization field of the parent certificate; determining whether the at least one sub-certificate to be deleted exists in the certificate centralized management system; if it exists, deleting the at least one sub-certificate to be deleted, and sending an instruction to delete the at least one sub-certificate to be deleted to the authorized object of the parent certificate through the communication interface 601.

[0140] In one implementation, the processor 602 is further configured to run the computer program to perform the following steps: determining the authorized object's permission to use the subcertificate as allowed, and determining the authorized object's permission to read the content of the subcertificate as prohibited, so as to achieve the masking of the content of the subcertificate.

[0141] The processor 602 mentioned above can be at least one of ASIC, DSP, DSPD, PLD, FPGA, CPU, controller, microcontroller, and microprocessor.

[0142] The aforementioned computer-readable storage medium / memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM), etc.; it can also be various terminals that include one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.

[0143] The description of the various embodiments above tends to emphasize the differences between the various embodiments. The similarities or similarities can be referred to each other. For the sake of brevity, they will not be repeated here.

[0144] The methods disclosed in the various method embodiments provided in this application can be arbitrarily combined to obtain new method embodiments without conflict.

[0145] The features disclosed in the various product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.

[0146] The features disclosed in the various method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.

[0147] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative and exemplary. The division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components may be combined, or integrated into another system, or some features may be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed may be through some interfaces, and the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0148] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple grid units. Depending on the actual situation, some or all of the units may be selected to achieve the purpose of this embodiment.

[0149] In addition, each functional unit in the various embodiments of this application can be integrated into one processing module, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0150] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments.

[0151] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A certificate management method, characterized in that, The method is applied to a centralized certificate management system, which manages parent certificates in a cloud platform; the method includes: Obtain authorization information, which is used to determine the authorized object of the parent certificate, wherein the authorized object is at least one of the multiple tenants of the cloud platform; Based on the authorization information, a sub-certificate corresponding to the authorized object is generated; the sub-certificate is used to encrypt and / or decrypt the transmitted data according to the key of the sub-certificate when the authorized object communicates with the cloud platform. The content of the subcertificate is masked to restrict the authorized object's access to read the content of the subcertificate; the content of the subcertificate includes at least the public key and private key of the subcertificate. The masked subcertificate is sent to the authorized object so that the authorized object receives the name information of the subcertificate. The step of masking the content of the sub-certificate to restrict the authorized object's access to the sub-certificate's content includes: The authorized object's permission to use the subcertificate is set to "allow use," while the authorized object's permission to read the content of the subcertificate is set to "prohibit reading." 2. The method according to claim 1, characterized in that, After generating the sub-certificate corresponding to the authorized object based on the authorization information, the method further includes: Establish an index mapping relationship between the identification information of the authorized object and the sub-certificate.

3. The method according to claim 2, characterized in that, After establishing the index mapping relationship between the identification information of the authorized object and the sub-certificate, the method further includes: Upon receiving a request from a tenant to re-acquire a certificate, the tenant's identification information is obtained; Based on the tenant's identification information, search the index mapping relationship to see if there is any identification information that is the same as the tenant's identification information; If it exists, then determine the subcertificate corresponding to the tenant's identification information and send the subcertificate to the tenant.

4. The method according to any one of claims 1 to 3, characterized in that, The acquisition of authorization information includes: Obtain multiple parent certificates from the cloud platform; each of the multiple parent certificates includes at least one authorization field; For each of the plurality of parent certificates, the authorization information is extracted based on the at least one authorization field.

5. The method according to any one of claims 1 to 3, characterized in that, After generating the sub-certificate corresponding to the authorized object, the method further includes: Upon receiving an instruction to delete a certificate, at least one child certificate to be deleted is determined based on at least one authorization field of the parent certificate; an instruction to delete the at least one child certificate to be deleted is sent to the authorization object of the parent certificate.

6. A certificate management device, characterized in that, The device is applied to a centralized certificate management system, which manages parent certificates in a cloud platform; the device includes: The acquisition module is used to acquire authorization information, which is used to determine the authorized object of the parent certificate, and the authorized object is at least one of the multiple tenants of the cloud platform; The certificate generation module is used to generate a sub-certificate corresponding to the authorized object based on the authorization information; the sub-certificate is used to encrypt and / or decrypt the transmitted data according to the key of the sub-certificate when the authorized object communicates with the cloud platform; A masking module is used to mask the content of the subcertificate to restrict the authorized object's access to read the content of the subcertificate; the content of the subcertificate includes at least the public key and private key of the subcertificate. The sending module is used to send the masked subcertificate to the authorized object so that the authorized object can obtain the name information of the subcertificate; The blocking module is used to block the content of the subcertificate to restrict the authorized object's access to read the content of the subcertificate. This includes: determining the authorized object's access to the subcertificate as allowed and determining the authorized object's access to read the content of the subcertificate as prohibited, thereby achieving the blocking of the content of the subcertificate.

7. The apparatus according to claim 6, characterized in that, After generating the sub-certificate corresponding to the authorized object based on the authorization information, the certificate generation module is further configured to: Establish an index mapping relationship between the identification information of the authorized object and the sub-certificate.

8. The apparatus according to claim 7, characterized in that, The certificate generation module is also used to obtain the tenant's identification information after establishing the index mapping relationship between the identification information of the authorized object and the sub-certificate, and upon receiving a request from the tenant to re-obtain the certificate information; Based on the tenant's identification information, search the index mapping relationship to see if there is any identification information that is the same as the tenant's identification information; If it exists, then determine the subcertificate corresponding to the tenant's identification information and send the subcertificate to the tenant.

9. An electronic device, characterized in that, It includes a communication interface, a processor, and memory for storing computer programs that can run on the processor; wherein, The communication interface is used to exchange information with each tenant of the cloud platform; The processor is used to run the computer program to perform the method according to any one of claims 1-5.

10. A computer storage medium storing a computer program; characterized in that, When the computer program is executed, it can implement the method of any one of claims 1-5.