A user certificate import method and system for a security gateway management system
By receiving and comparing the usage scope values of user certificates, the security risks caused by the increased use of certificates in a shared security gateway across multiple departments were resolved, thereby limiting the scope of the security gateway and improving system stability.
Patent Information
- Application Number
- CN202311808257.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-26
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2043-12-26
AI Technical Summary
In a shared security gateway system, the increased use of user certificates leads to increased load on gateway devices, creating security vulnerabilities. Existing technologies cannot effectively limit the scope of certificate use, resulting in an increased risk of cybersecurity incidents.
By receiving user certificate import requests, parsing the certificate's scope value, and comparing it with a pre-defined scope value, the certificate is imported only if they match. An index is established between the certificate and the scope value to ensure that the certificate is used only within the specified department and to avoid conflicts from importing the certificate twice.
This effectively limits the scope of use of the security gateway, avoids certificate conflicts and network security incidents, and improves the security and stability of the system.
Smart Images

Figure CN117792654B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of system security, in particular to a user certificate import method and system for a security gateway management system. BACKGROUND
[0002] Based on the needs of the market, the current security gateway system includes two parts: a security gateway and a security gateway management system. The security gateway is implemented based on the national SSL protocol and the VPN security tunnel, which provides a channel for secure communication. The security gateway management system is a system for configuring and managing each gateway. The entire system exists in a cloud deployment manner and can also be deployed and used in a traditional manner and a non-cloud manner. When the system is deployed and used, the subordinate units have multiple business departments that are independent of each other and do not intersect. These departments also use the gateway system at the same time. If no restrictions are imposed, the use of the gateway by users will increase the load of the gateway device, which may cause security problems. SUMMARY
[0003] To solve the above technical problems, the present application provides a user certificate import method for a security gateway management system, which includes the following steps:
[0004] receiving a user certificate import request;
[0005] parsing the user certificate import request to obtain a use range value of the user certificate;
[0006] comparing the use range value of the user certificate with a pre-set use range value of the user certificate, and if they are consistent, importing the user certificate;
[0007] establishing an index of the user certificate and the corresponding use range value to complete the import of the user certificate.
[0008] Further, the user certificate is issued by a CA agency.
[0009] Further, the user certificate import request includes a user certificate and a use range of the user certificate.
[0010] Further, after the step of parsing the user certificate import request, the method further includes the following steps:
[0011] determining whether the user certificate exists according to the certificate name;
[0012] if the user certificate exists, ending the import process of the user certificate.
[0013] Further, after the step of comparing the use range value of the user certificate with the pre-set use range value of the user certificate, the method further includes the following steps:
[0014] If inconsistent, end the import process of the user certificate.
[0015] Further, the pre-set use range value of the user certificate is specifically divided according to the department of the company.
[0016] Further, after the step of importing the user certificate, further comprising:
[0017] Saving the certificate to the security gateway management system.
[0018] The application also provides a user certificate import system for a security gateway management system, comprising:
[0019] A request receiving module is configured to receive an import request of a user certificate.
[0020] A use range value obtaining module is configured to parse the import request of the user certificate and obtain a use range value of the user certificate.
[0021] An import module is configured to compare the use range value of the user certificate with a pre-set use range value of the user certificate, and if consistent, import the user certificate.
[0022] An index establishing module is configured to establish an index of the user certificate and the corresponding use range value, and complete the import of the user certificate.
[0023] Further, further comprising:
[0024] A judgment module is configured to judge whether the user certificate exists according to the certificate name.
[0025] A process end module is configured to end the import process of the user certificate if the user certificate exists.
[0026] Further, further comprising:
[0027] A saving module is configured to save the certificate to the security gateway management system.
[0028] The application provides a user certificate import method and system for a security gateway management system, which limits the user range of using the security gateway by configuring the use range value of the user certificate, and ensures that the use range of the security gateway is effectively limited in a specific department. And avoids the conflict caused by the secondary import of the certificate to the system. The limitation of the use range effectively avoids the occurrence of network security events and risks. BRIEF DESCRIPTION OF DRAWINGS
[0029] Figure 1This is a flowchart illustrating a user certificate import method for a security gateway management system provided in an embodiment of the present invention;
[0030] Figure 2 This is a flowchart illustrating the overall process of certificate generation and import in an embodiment of the present invention.
[0031] Figure 3 This is a flowchart illustrating the process of setting the certificate scope in an embodiment of the present invention;
[0032] Figure 4 This is a flowchart illustrating the process of an administrator importing user certificates according to an embodiment of the present invention.
[0033] Figure 5 This is a schematic diagram of a user certificate import system for a security gateway management system provided in an embodiment of the present invention. Detailed Implementation
[0034] Numerous specific details are set forth in the following description to provide a full understanding of the invention. However, the invention can be practiced in many other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0035] Example 1
[0036] Figure 1 This is a flowchart illustrating a user certificate import method for a security gateway management system provided by the present invention. The following is a summary of the process. Figure 1 The method provided by this invention will be described in detail.
[0037] Step S101: Receive the user certificate import request.
[0038] The user certificate import request includes the user certificate and the scope of use of the user certificate. For example... Figure 2 As shown, the user certificate is issued by a Certificate Authority (CA). The certificate request is generated by the user. When generating the certificate request, it's important to ensure that the department name matches the certificate scope set by the system, for example, both being "yjy". After generating the certificate request, the user sends the certificate request file to a CA recognized by the State Cryptography Administration, requesting a frequently issued certificate from the CA. Upon receiving the user's application, the CA issues the frequently issued certificate to the user, i.e., the user certificate. The CA sends the user certificate along with the root certificate for verifying the user certificate to the user. The user then sends the user certificate and root certificate to the administrator of the security gateway management system, who then imports the root certificate and user certificate into the security gateway management system.
[0039] Step S102: Parse the import request of the user certificate and obtain the usage scope value of the user certificate.
[0040] After the step of parsing the import request of the user certificate, further comprising: judging whether the user certificate exists according to the certificate name; if the user certificate exists, ending the import process of the user certificate.
[0041] Step S103, comparing the use range value of the user certificate with the pre-set use range value of the user certificate, if consistent, importing the user certificate.
[0042] The pre-set use range value of the user certificate, specifically, the use range value of the user certificate is divided according to the department of the company. Generally set by the administrator, the specific process is as shown in Figure 3 The administrator logs in the security gateway management system and enters the certificate range configuration interface to perform the new configuration of the certificate range. The selected certificate range specifically includes province, city (region), organization (unit), and department; the specific value of the range, that is, the specific name of the department (such as yjy), should be consistent with the department name filled in the certificate request. Save and take effect, so that the certificate range of the security gateway management system is configured.
[0043] After the step of comparing the use range value of the user certificate with the pre-set use range value of the user certificate, further comprising: if inconsistent, ending the import process of the user certificate.
[0044] Step S104, establishing an index of the user certificate and the corresponding use range value, and completing the import of the user certificate.
[0045] After the step of importing the user certificate, further comprising: saving the certificate to the security gateway management system.
[0046] Embodiment 2
[0047] The import of the user certificate is imported by the administrator in actual application, and the operation process is as shown in Figure 4 The administrator logs in the security gateway management system, enters the certificate import interface, selects the user certificate file, and determines and imports the certificate. At this time, the management system needs to perform the preliminary verification of the certificate: the system first judges whether the newly imported certificate exists in the system, if it exists, the certificate import process is directly ended; if the certificate does not exist in the system, the certificate needs to be preliminarily parsed to obtain the range (department yjy) in the certificate, and the next step is performed. The system compares the range value obtained from the certificate with the range value configured in the system to see if they are consistent, if not, it is required to reselect the certificate file or give up the certificate import; if consistent, the system allows the certificate import and performs the import operation, the system saves the certificate and establishes the database index, thereby ending the user certificate import process.
[0048] Based on the same inventive concept, the application simultaneously provides a user certificate import system 500 for a security gateway management system, as shown in the accompanying drawings, comprising: Figure 5
[0049] A request receiving module 510 is configured to receive an import request of a user certificate.
[0050] A usage range value obtaining module 520 is configured to parse the import request of the user certificate and obtain a usage range value of the user certificate.
[0051] An import module 530 is configured to compare the usage range value of the user certificate with a preset usage range value of the user certificate, and if they are consistent, import the user certificate.
[0052] An index establishing module 540 is configured to establish an index of the user certificate and the corresponding usage range value, and complete the import of the user certificate.
[0053] Further, the system further comprises:
[0054] A judging module is configured to judge whether the user certificate exists according to the certificate name.
[0055] A flow ending module is configured to end the import flow of the user certificate if it exists.
[0056] Further, the system further comprises:
[0057] A saving module is configured to save the certificate to the security gateway management system.
[0058] The application provides a user certificate import method and system for a security gateway management system, which limits the user range of using the security gateway by configuring the usage range value of the user certificate, and ensures that the usage range of the security gateway is effectively limited in a specific department. And avoids the conflict caused by the secondary import of the certificate to the system. The limitation of the usage range effectively avoids the occurrence of network security events and risks.
[0059] Finally, it should be noted that: the above examples are only used to illustrate the technical solutions of the application and not to limit it, although the application has been described in detail with reference to the above examples, those skilled in the art should understand that the specific embodiments of the application can be modified or replaced, without departing from the spirit and scope of the application, any modification or equivalent replacement, which should be covered in the scope of the claims of the application.
Claims
1. A user certificate import method for a security gateway management system, characterized by, The method comprises the following steps: receiving an import request of a user certificate; parsing the import request of the user certificate to obtain a use range value of the user certificate; comparing the use range value of the user certificate with a pre-set use range value of the user certificate, and if they are consistent, importing the user certificate; establishing an index of the user certificate and the corresponding use range value, and completing the import of the user certificate.
2. The method of claim 1, wherein, The user certificate is issued by a CA agency.
3. The method of claim 1, wherein, The import request of the user certificate comprises the user certificate and the use range of the user certificate.
4. The method of claim 1, wherein, After the step of parsing the import request of the user certificate, the method further comprises the following steps: judging whether the user certificate exists according to the certificate name; if the user certificate exists, ending the import process of the user certificate.
5. The method of claim 1, wherein, After the step of comparing the use range value of the user certificate with the pre-set use range value of the user certificate, the method further comprises the following step: if they are inconsistent, ending the import process of the user certificate.
6. The method of claim 1, wherein, The pre-set use range value of the user certificate is specifically determined according to the department division of a company.
7. The method of claim 1, wherein, After the step of importing the user certificate, the method further comprises the following step: saving the certificate to a security gateway management system.
8. A user certificate import system for a security gateway management system, characterized by, The method comprises the following steps: a request receiving module for receiving an import request of a user certificate; a use range value obtaining module for parsing the import request of the user certificate to obtain a use range value of the user certificate; an import module for comparing the use range value of the user certificate with a pre-set use range value of the user certificate, and if they are consistent, importing the user certificate; an index establishing module for establishing an index of the user certificate and the corresponding use range value, and completing the import of the user certificate.
9. The system of claim 8, wherein, The method further comprises the following steps: a judging module for judging whether the user certificate exists according to the certificate name; a process ending module for ending the import process of the user certificate if the user certificate exists.
10. The system of claim 8, wherein, The method further comprises the following step: a saving module for saving the certificate to a security gateway management system.
Citation Information
Patent Citations
Method for authenticating digital certificate user in SSL VPN
CN101964800A
User digital certificate remote update method with intelligent card protection function
CN102523095A