A root certificate updating method, device, equipment, storage medium and product
By calculating the time required to update the root certificate of the terminal based on historical update records, determining the update time information, and issuing the root certificate to be updated, the problem of untimely updates of IoT terminal devices is solved, achieving timely updates and improved security.
Patent Information
- Application Number
- CN202410678363.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-29
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-05-29
AI Technical Summary
IoT terminal devices may miss the valuable time window during the root certificate update process, resulting in failure to update in a timely manner and posing a risk of data leakage.
By calculating the time required to update the terminal's root certificate based on historical update records, determining the update time information and sending it to the terminal, the root certificates to be updated are distributed sequentially to ensure that the terminal is ready and can be updated in a timely manner.
It effectively prevents IoT data leakage, ensures timely updates of root certificates, and improves update efficiency and security.
Smart Images

Figure CN118827055B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a root certificate updating method, device, equipment, storage medium and product. BACKGROUND
[0002] With the rapid development of information technology, the Internet of Things plays an important role in people's life. The terminal of the Internet of Things is closely related to people's life, and involves a large amount of sensitive information in data transmission, such as personal identity, location, health data, etc. If these data are obtained or tampered with by unauthorized devices during transmission, it will pose a serious threat to users. Moreover, the number of devices in the Internet of Things is large and widely distributed, and it is difficult to well control the location and source of each device. To solve this problem, the prior art authenticates the device through a digital certificate to ensure that only authorized devices can communicate. In order to ensure that the data certificate can accurately authenticate the device, the root certificate needs to be updated in time. However, for terminals in the Internet of Things, such as bridge monitoring and other high-frequency devices, it is easy to miss the valuable time window for certificate update, resulting in the terminal being unable to update the root certificate in time. SUMMARY
[0003] Therefore, the present application provides a root certificate updating method, device, equipment, storage medium and product. The updating waiting time of each terminal is determined according to the historical updating situation and sent to the corresponding terminal, so that the terminal is prepared for updating, so that the terminal can receive the corresponding root certificate in time, and the root certificate of the terminal is updated in time.
[0004] To achieve the above purpose, the present application provides a root certificate updating method, comprising:
[0005] When a certificate batch updating task is triggered, the root certificate updating time of a terminal associated with the certificate batch updating task is calculated according to historical updating records;
[0006] The updating time information of the terminal is determined according to the set terminal updating sequence and the root certificate updating time of the terminal, and the updating time information is sent to the terminal, so that the terminal is prepared for updating according to the updating time information;
[0007] According to the terminal updating sequence, the to-be-updated root certificate in the certificate batch updating task is sequentially issued to the corresponding terminal to realize the root certificate updating of the terminal; wherein the to-be-updated root certificate corresponds to the terminal one by one.
[0008] To achieve the above purpose, the present application also provides a root certificate updating device, comprising:
[0009] The time calculation module is configured to calculate the root certificate update time required by a terminal associated with the certificate batch update task according to historical update records when the certificate batch update task is triggered.
[0010] The information sending module is configured to determine the update time information of the terminal according to the set terminal update sequence and the root certificate update time required by the terminal, and send the update time information to the terminal, so that the terminal makes preparation for the update according to the update time information.
[0011] The certificate issuing module is configured to sequentially issue the to-be-updated root certificate in the certificate batch update task to the corresponding terminal according to the terminal update sequence, so as to realize the root certificate update of the terminal, wherein the to-be-updated root certificate corresponds to the terminal one by one.
[0012] To achieve the above object, the embodiments of the present application further provide a root certificate update device, comprising a processor, a memory and a computer program stored in the memory and configured to be executed by the processor, wherein the processor implements the root certificate update method according to any one of the above embodiments when executing the computer program.
[0013] To achieve the above object, the embodiments of the present application further provide a computer readable storage medium, comprising a stored computer program, wherein the computer readable storage medium controls the device where the computer readable storage medium is located to execute the root certificate update method according to any one of the above embodiments when the computer program runs.
[0014] To achieve the above object, the embodiments of the present application further provide a computer program product, comprising computer programs / instructions, wherein the computer programs / instructions implement the root certificate update method according to any one of the above embodiments when executed by a processor.
[0015] Compared with the prior art, the root certificate updating method, device, equipment, storage medium and product disclosed by the embodiment of the application, when the certificate batch updating task is triggered, the root certificate updating time required by the terminal associated with the certificate batch updating task is determined according to the historical updating record, and then the updating time information of the terminal is determined based on the set terminal updating sequence and in combination with the root certificate updating time required by the terminal, and the updating time information is sent to the terminal to make the terminal ready for updating; the to-be-updated root certificate in the certificate batch updating task is sequentially issued to the corresponding terminal to realize the root certificate updating of the terminal; wherein the to-be-updated root certificate corresponds to the terminal one by one. As can be seen, the embodiment of the application determines the updating waiting time of each terminal according to the historical updating condition and sends it to the corresponding terminal, so that the terminal is ready for updating, so that the terminal can timely receive the issued root certificate, realizes the timely updating of the terminal root certificate, and is beneficial to preventing the leakage of Internet of Things data. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. Obviously, the drawings described in the following are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0017] Figure 1 is a flow diagram of a root certificate updating method provided by an embodiment of the present application;
[0018] Figure 2 is a root certificate updating flow diagram provided by an embodiment of the present application;
[0019] Figure 3 is an architecture diagram of a root certificate updating provided by an embodiment of the present application;
[0020] Figure 4 is a structure diagram of a root certificate updating device provided by an embodiment of the present application;
[0021] Figure 5 is a structure diagram of a root certificate updating equipment provided by an embodiment of the present application. DETAILED DESCRIPTION
[0022] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0023] Referring to Figure 1 , Figure 1 is a flowchart of a root certificate updating method provided by an embodiment of the present application. The root certificate updating method comprises steps S11-S13.
[0024] S11, when a certificate batch updating task is triggered, calculating a root certificate updating time required by a terminal associated with the certificate batch updating task according to historical updating records;
[0025] S12, determining updating time information of the terminal according to a set terminal updating sequence and the root certificate updating time required by the terminal and sending the updating time information to the terminal, so that the terminal makes updating preparation according to the updating time information;
[0026] S13, sequentially issuing a to-be-updated root certificate in the certificate batch updating task to a corresponding terminal according to the terminal updating sequence, so as to realize root certificate updating of the terminal; wherein the to-be-updated root certificate corresponds to the terminal one by one.
[0027] Specifically, the root certificate updating method is executed by a server, and the certificate batch updating task contains root certificate updating tasks of at least one terminal. The updating process is as follows:
[0028] 1. When the task is triggered, the root certificate updating time required by each terminal in the current certificate batch updating task is estimated according to the historical updating records stored by the server, for example, the root certificate updating time required is obtained by statistical analysis according to the historical updating records of the region, including the shortest updating time, the longest updating time and the average updating time, and the average updating time is preferred. If the region has never been updated, the shortest updating time, the longest updating time or the average updating time of the device root certificate updating of the adjacent region or the entire city or province can be considered as a reference value.
[0029] 2、Since the server cannot distribute the root certificate to different terminals in parallel, the terminals that need to be updated in this round need to be sorted, and then the root certificates to be updated are distributed to the corresponding terminals in a certain order. The specific sorting method can be to set the root certificate update priority for each terminal in advance, with higher priority first; it can also be to sort the existing certificate expiration time of the terminal that needs to be updated in this round, with the expiration time closer first; it can also be to set the order according to the root certificate update time and the running status of each terminal, so as to make the root certificate update as little as possible to affect the original running status of the terminal; it can also be other sorting methods, which are set according to the actual situation and will not be described here. After determining the order, for each terminal, the sum of the root certificate update time of all terminals before this terminal is calculated as the update waiting time of this terminal, the update time information is determined according to the update waiting time, and the update time information is sent to the terminal, so that the terminal can prepare for the update according to the update time information. After waiting for the update waiting time, enter the certificate pushing process and prepare to receive the root certificate to be updated. For example, the update waiting time of the terminal ranked first is 0, and the terminal enters the certificate pushing process immediately. Further, in addition to considering the update waiting time of each terminal, the update time information further considers other tasks that the terminal is currently performing, such as when the update waiting time of each terminal is calculated, if there is a terminal executing other tasks, if the remaining time required for the terminal to complete the task exceeds the update waiting time of the terminal, the update waiting time of the terminal and other terminals after the terminal is extended according to the excess part; if the remaining time required for the terminal to complete the task does not exceed the update waiting time of the terminal, the task will not affect the update waiting time.
[0030] 3、After completing the above steps, the server performs the certificate batch update task according to the terminal update order, and sequentially distributes each root certificate to be updated to the corresponding terminal, so that the terminal updates the certificate according to the received root certificate to be updated.
[0031] It can be understood that after the terminal receives the update time information, the time of the update can be determined, and then the idle time before the update time can be used to perform other tasks, avoiding the terminal device being in idle waiting state for a long time and wasting the valuable resources of the terminal. The update time information can be the update waiting time, or the time after the update waiting time of the current time, and the specific performance method can be set according to the actual situation.
[0032] Therefore, the embodiment of the present application determines the update waiting time length of each terminal according to the historical update situation and sends it to the corresponding terminal, so that the terminal is prepared for updating, so that the terminal can receive the root certificate issued in time, realizes the timely updating of the terminal root certificate, and is beneficial to prevent the leakage of Internet of Things data.
[0033] In one embodiment, the update time information of the terminal is determined according to the set terminal update sequence and the root certificate update time required by the terminal, and the update time information is sent to the terminal, so that the terminal is prepared for updating according to the update time information, comprising:
[0034] Determine the target terminal according to the obtained current state parameter of the terminal; wherein the target terminal is a terminal whose current state parameter meets the set certificate update requirement;
[0035] Sort all the target terminals to obtain a terminal update sequence;
[0036] According to the root certificate update time required by the target terminal, the update waiting time length of each target terminal is calculated to determine the update time information according to the terminal update sequence;
[0037] Generate a delayed update instruction carrying the corresponding update time information for each target terminal except the first target terminal and send it to the corresponding target terminal, so that the target terminal enters the certificate pushing process according to the corresponding update time information to receive the corresponding root certificate to be updated;
[0038] If the sleep time node of the first target terminal is before the time node corresponding to the update time information of the first target terminal, the first target terminal sleeps at its sleep time node and re-logs in at the time node corresponding to its update time information, wherein the first target terminal is any terminal in all the target terminals.
[0039] Specifically, the current state parameter of the terminal required to be updated by the certificate batch update task is obtained to determine whether the terminal meets the certificate update requirement, and the terminal meeting the certificate update requirement is selected as the target terminal for root certificate update. The terminal needs to be queued for updating in a certain order. Since the device certificate pushing is uniformly controlled by the server, the server can clearly know when the new root certificate of the terminal is completely pushed, and know whether all terminals have completed the certificate pushing, so there is no situation that the certificate is not pushed completely and other terminals are pushed. After the root certificate to be updated is issued to a terminal, whether the terminal immediately updates the certificate or has other operations, it is irrelevant to the certificate update process of the server. The server can immediately update the next terminal, fully utilizes the window period of the terminal device, and improves the overall updating efficiency.
[0040] The following is a brief description of three terminals (terminal device one, terminal device two and terminal device three):
[0041] 1. The user creates a certificate update configuration on the service end certificate management page and binds a device update list, which includes terminal device one, terminal device two and terminal device three.
[0042] 2. The service end issues an update notification according to the device root certificate update mechanism and specifies a dependent update relationship (i.e. terminal update order). It is determined that terminal one located at the dependent root node is in an idle state, so the certificate update process is immediately started;
[0043] 3. In this process, the service end calculates that terminal device one certificate pushing needs 10s and terminal device two certificate pushing needs 3s, so it issues a delayed update instruction to terminal device two and terminal device three, so that terminal device two updates after 10s and terminal device three updates after 13s. Among them, terminal device two and terminal device three make their own state judgment. If the corresponding waiting time (i.e. the sleep time node) is not reached, they will wait; if the corresponding waiting time is exceeded, they will enter sleep and restart later. In an ideal state, each terminal does not exceed the waiting time set by the user, and terminal device two and terminal device three update in turn.
[0044] In one embodiment, the certificate batch update task is issued to the corresponding terminal in the terminal update order to realize root certificate update of the terminal, including:
[0045] When the certificate issue completion time of the adjacent target terminal before the first target terminal has not reached the time node corresponding to the update time information of the first target terminal, and the first target terminal is in a sleep state, the corresponding root certificate to be updated is issued to the second target terminal until the corresponding root certificate to be updated is issued to the first target terminal when the first target terminal is reconnected online, the issuance of the root certificate to be updated of the second target terminal is suspended, and a delay instruction carrying the root certificate update time of the first target terminal is sent to the second target terminal, so that the second target terminal waits for the root certificate update time of the first target terminal and then reenters the certificate pushing process to receive the corresponding root certificate to be updated; wherein the second target terminal is the nearest target terminal that has not slept, and the second target terminal is later than the first target terminal in the terminal update order.
[0046] Specifically, refer to Figure 2The root certificate update flowchart is shown. The following is a more complex example that exceeds the set waiting time, terminal device two hibernation, and terminal device one early completion of certificate push:
[0047] 1. The user creates a certificate update configuration on the service side through the user application side and binds the device update list. The number of devices is 3, and the list includes terminal device one (device 1), terminal device two (device 2), and terminal device three (device 3).
[0048] 2. The service side issues an update notification according to the device root certificate update mechanism and specifies the dependent update relationship (i.e., the terminal update order). It is determined that terminal one located at the dependent root node is in an idle state, so the certificate update process is immediately started.
[0049] 3. In this process, the service side calculates that terminal device one certificate push requires 10s and terminal device two certificate push requires 3s, so it issues a delayed update instruction to terminal device two and terminal device three, allowing terminal device two to update after 10s and terminal device three to update after 13s.
[0050] 4. Terminal device one completes the push in advance and enters its own update process. At this time, terminal device two has entered the delayed update channel and has exceeded the waiting time when terminal device one completes the push (terminal device two has already hibernated). The service side calculates and uses the network window period to push part of the bytes of the certificate to terminal device three (terminal device three has not reached the hibernation time node). When the time reaches the time node specified by the delayed update instruction received by terminal device two, a delayed command is issued to terminal device three to wait for 3s. Terminal device three continues to wait without exceeding the user-configured waiting time.
[0051] 5. Terminal device two starts after waiting for 10s and enters the certificate push process.
[0052] 6. Terminal device three waits for 3s after receiving the delayed command and reenters the certificate push process.
[0053] In this embodiment, the certificate is pushed in fragments using the network window period. Since the service side can explicitly know which byte of the root certificate to be updated is currently being pushed, it can continue to issue the root certificate through breakpoint resume, effectively increasing the flexibility and reliability of the update and fully utilizing the valuable network window period of the Internet of Things device.
[0054] In one embodiment, the root certificate update method is applied to a service side, the service side is connected with the terminal through an MQTT standard protocol, and data interaction between the terminal and the service side is realized by the terminal subscribing to a certificate update topic of the service side.
[0055] Specifically, the following introduces the meaning of MQTT (Message Queuing Telemetry Transport) and root certificate. 1. MQTT is a lightweight communication protocol based on the publish / subscribe mode, which is built on the TCP / IP protocol (Transmission Control Protocol / Internet Protocol), and was released by IBM in 1999. The greatest advantage of MQTT is that it can provide real-time and reliable message services for connecting remote devices with very little code and limited bandwidth. As a low-overhead, low-bandwidth instant messaging protocol, it has a wide range of applications in the Internet of Things, small devices, mobile applications, etc. 2. Certificate is a digital file used to verify the identity of a server or client. During the SSL / TLS handshake process, the server sends a certificate to the client, which uses the certificate to verify the identity of the server. The certificate usually contains the following information: (1) Subject: the identity information of the certificate holder, usually the domain name; (2) Issuer: the identity information of the trusted authority (CA, Certificate Authority) that issued the certificate; (3) Public Key: the public key used to encrypt communication, held by the server. Root certificate is a special certificate that serves as the root of trust and is used to verify the authenticity of other certificates. Root certificates are issued by trusted certificate authorities (CAs), and their public keys have been pre-installed in operating systems or browsers. The root certificate is used to verify the validity of the server certificate to ensure the security of the data in the communication. The root certificate built into the device terminal is used to verify the trusted CA, and the trusted CA issues other server certificates. In this way, the device terminal can trace the authenticity of the certificate and ensure secure communication with the server.
[0056] In order to avoid the current resource waste and certificate exposure public network caused by the transmission of certificate information in the handshake process of the Internet of Things device, and the problem of missing the update time window and causing the device to be unable to update, the root certificate is updated dynamically and in batches through the MQTT protocol, making the device certificate update process more reasonable. In order to make the root certificate update method more clear, the following is a simple explanation, see Figure 3The illustrated root certificate update architecture diagram, the server includes a certificate management module 1 and a device access module 2, the terminal 3 communicates with the certificate management module 1 through the device access module 2. The certificate management module includes: 1, certificate information module: used for managing the root certificate bound by the terminal, the module is responsible for the generation, storage and update of the root certificate, and the association and management of the certificate related information between the terminal. 2, device management module: used for managing the list of terminals. This module maintains the information of all terminals that have accessed the system, including the unique identifier of the terminal, the terminal type, the terminal state, etc., to facilitate the management and monitoring of the terminal. 3, certificate update configuration management module: used for adding and binding the related information of the terminal certificate update method. This module is responsible for configuring various parameters of the device certificate update task, including task start time configuration, various time configurations related to certificate update of the terminal, update consistency requirement configuration, etc., to ensure the smooth progress of the certificate update process. 4, message notification module: used for notifying the device access module and pushing the information of the root certificate to be updated to the device terminal. This module can send the trigger information of the certificate update task to the device access module and ensure that the terminal can obtain the latest root certificate in time. 5, receiving device reporting information module: used for receiving the information reported by the device access module. This module receives and processes the reporting data from the terminal device, including device state, certificate update progress, etc., to ensure timely access to the latest state and information of the device. These sub-modules cooperate with each other to form a complete certificate management module, which can effectively manage and update the root certificate of the terminal. The terminal mainly consists of the following components: 1, information processor: responsible for receiving various information from the device access module. The processor can parse and process these information and perform corresponding operations as needed, and can also read executable instructions in the memory to perform device operations. 2, certificate storage unit: used for receiving the information of the root certificate to be updated pushed by the device access module in fragments and storing it in the local storage space. The storage unit can ensure the integrity and security of the root certificate. After downloading is completed, the storage unit will execute commands to verify whether the certificate information is consistent with the server, and generate executable instructions for the terminal to re-establish connection according to the upgrade instructions returned by the device access module. 3, memory: used for storing executable instructions required by the processor. The memory stores the program code and instruction set of the device terminal for the information processor. 4, reporting information module: responsible for reporting the download progress, device state and other information to the device access module. This module can feedback the state and certificate update progress of the device terminal to the device access module in time for further processing and management. These components work together to realize the functions and operations of the terminal, including receiving instructions, storing root certificates, verifying root certificate information and reporting progress, etc. The device access module includes the following functional modules: 1, device connection management module: used for managing the connection information of the terminal. This module is responsible for the connection and disconnection processing of the terminal, maintains the online state information of the terminal, records the online and offline records of the terminal, etc.Through this module, the connection state of the terminal can be monitored in real time, ensuring that the terminal can access and communicate normally.2、Device identity verification module: used for receiving terminal connection for identity verification. This module verifies the identity information of the terminal, such as terminal certificate or other authentication methods, to confirm the legitimacy and credibility of the terminal. This can prevent unauthorized access and ensure that the data transmitted during transmission is not tampered with or stolen.3、Device information reporting module: used to return the relevant information of the terminal to the certificate management module or other modules of the server. This module can collect various state information of the terminal, such as terminal model, version number, running status, etc., as well as certificate information of the terminal, and report it to the certificate management module or other modules of the server for further management and processing.4、Device command issuing module: used to issue ordinary instructions or instructions related to root certificate update to the terminal. This module can pass the commands issued by the certificate management module to the terminal and ensure reliable transmission and execution of the commands. For example, a delay update instruction can be issued through this module to achieve certificate update control. Through these functional modules, the device access module can complete device connection management, identity verification, information reporting, and command issuing, ensuring the security and effectiveness of device access and communication.
[0057] The process of root certificate update is as follows:
[0058] 1、The terminal accesses the server and issues a root certificate application request. The certificate management module of the server will generate and bind the terminal's to-be-updated root certificate, and configure the start time of the certificate batch update task and the update consistency requirement, including but not limited to strong consistency, weak consistency and non-consistency.
[0059] Among them, the server sets up a device access module as an access channel for the terminal to access the server, and the terminal accesses the server through the MQTT standard protocol. The terminal of the Internet of Things uses the subscription and publication function of MQTT when accessing the server, subscribes to the corresponding topic (Topic) as required, to realize data interaction between the certificate management module and the terminal. Strong consistency requirement means that all terminals associated with the certificate batch update task must enter the certificate update process at the same time, weak consistency requirement means that all terminals associated with the certificate batch update task can not enter the certificate update process at the same time, but it is required to ensure that all terminals associated with the certificate batch update task finally complete the update of the root certificate, and non-consistency requirement means that only the current idle terminal associated with the certificate batch update task needs to be updated for the root certificate.
[0060] 2、The certificate management module determines the task start time according to the certificate expiration time of the existing certificate of the terminal and / or the task trigger time of the certificate batch update task, and sends certificate update notification information to the device access module at the task start time. The certificate update notification information can contain certificate information, including certificate size, partial digest and update consistency requirement, etc.
[0061] 3、The device access module receives the certificate update notification information, obtains the historical record of the device recovery connection time (this information is used to confirm the online time of the terminal), the certificate size of the terminal, and the network state, dynamically evaluates the root certificate update time according to the certificate size and the network state, including but not limited to the shortest update time, the average update time, and the longest update time. Users can configure it according to actual conditions, and the default selection is the average time.
[0062] 4、The terminal subscribes to the certificate update Topic according to the requirements of the device access module, and returns the current state parameters such as device state, available space, power, and idle time.
[0063] 5、The device access module detects the certificate update notification information sent by the certificate management module, including checking whether the storage space of the terminal is sufficient and whether the power meets the update requirements, etc. If it meets the requirements, it goes to step 7, if it does not meet the requirements, it goes to step 6.
[0064] 6、The device access module determines whether the update consistency requirement is non-consistent, weakly consistent, or strongly consistent, and then determines the specific control logic of the to-be-updated root certificate.
[0065] 7、The terminal receives the to-be-updated root certificate through the subscribed Topic, and returns the download progress for the certificate management module to display.
[0066] 8、After the terminal completes the download, it will verify the downloaded to-be-updated root certificate to verify whether it is consistent with the verification information provided by the certificate management module. If the verification is consistent, the terminal will send the download success information to the certificate management module, and the certificate management module will record the device root certificate update state as the download success state. This can ensure the reliability and accuracy of the root certificate download and verification process.
[0067] 9、The terminal completes the new device root certificate update and enters the process of restarting, re-establishing connection, erasing and releasing the storage space temporarily storing the to-be-updated root certificate.
[0068] 10、The terminal uses the new root certificate to re-establish the handshake connection, and sends the update success information to the certificate management module after going online. The certificate management module records the root certificate update state of the terminal as the update success state, and updates the record information in the certificate management module.
[0069] It is worth noting that in the embodiments of the present application, the root certificate is issued by the server in ciphertext through the original encrypted channel of the MQTT protocol. Since an encrypted long connection is maintained between the client and the server, the server can be fully trusted, and the problem of device root certificate interception by an intermediate person will not occur. Instead of issuing the device certificate in plaintext as in the related art, this further enhances the protection of device security, and at the same time, the normal message interaction through the MQTT protocol also saves computing power and does not require special additional resources.
[0070] In an embodiment, the to-be-updated root certificate is issued to the corresponding terminal only when the acquired current state parameter of the terminal meets the set certificate update requirement; when the current state parameter includes a current device state, the certificate update requirement includes that the current device state is online and idle; when the current state parameter includes a current available space, the certificate update requirement includes that the current available space is greater than or equal to the certificate size of the to-be-updated root certificate; and when the current state parameter includes a current power, the certificate update requirement includes that the current power is greater than or equal to a set power threshold.
[0071] In an embodiment, the certificate batch update task is configured with an update consistency requirement, and the update consistency requirement is a non-consistent requirement, a weak-consistent requirement, or a strong-consistent requirement.
[0072] The to-be-updated root certificate in the certificate batch update task is sequentially issued to the corresponding terminal to realize root certificate update of the terminal, including:
[0073] If the update consistency requirement is a non-consistent requirement, the target to-be-updated root certificate in the certificate batch update task is sequentially issued to the corresponding target terminal; wherein the current state parameter of the target terminal meets the set certificate update requirement.
[0074] When the update consistency requirement is a weak-consistent requirement, the target to-be-updated root certificate in the certificate batch update task is sequentially issued to the corresponding target terminal, a non-target terminal is marked and a new certificate batch update task is generated for the non-target terminal, until all the non-target terminals complete root certificate update; wherein the current state parameter of the non-target terminal does not meet the certificate update requirement.
[0075] When the update consistency requirement is a strong-consistent requirement, if there is a terminal whose current state parameter does not meet the certificate update requirement, the current state parameter of the terminal is monitored until the current state parameter of all terminals associated with the certificate batch update task meets the certificate update requirement, and the to-be-updated root certificate in the certificate batch update task is sequentially issued to the corresponding terminal to realize root certificate update of the terminal.
[0076] Specifically, the following three update consistency requirements are described:
[0077] 1. Non-consistent requirement: update the current idle devices that meet the requirements, and ignore all devices that do not meet the requirements. The device access module returns a list of devices that do not meet the requirements and the corresponding reasons to the certificate management module, and the update task ends immediately after all the terminals that meet the requirements are updated. The user can choose whether to update the remaining terminals again or ignore the update according to his own needs. The idle device described here refers to a terminal that does not occupy resources such as normal business processing and network data transmission.
[0078] 2. Weak consistency requirement: also known as eventual consistency, that is, update the current idle devices that meet the requirements, and mark the terminals that do not meet the requirements (such as offline devices, low-power devices, non-idle devices, etc.), and assign update requirements according to different situations. Update instructions, update time points, etc. will be sent to the terminal and form an update plan, which will be synchronized with the certificate management module. The certificate management module issues new certificate batch update tasks to the specified terminal according to the new update plan until all terminals complete the update. The device access module reports the update completion to the certificate management module after all terminals complete the update.
[0079] Strong consistency requirement: first count the idle time of all terminals that meet the requirements, then calculate the appropriate and unified certificate update time according to the estimated root certificate update time, and issue it to the terminal and the certificate management module. The terminal enters the update state according to the issued instructions, and the certificate management module issues update tasks according to the update plan to perform batch synchronization update. In this process, all terminals will update the root certificate at the same update time point to achieve strong consistency.
[0080] In one embodiment, before the certificate batch update task is triggered, it further includes: receiving a root certificate application request of a terminal, generating a to-be-updated root certificate for the terminal to join the certificate batch update task;
[0081] The certificate batch update task is also configured with a task start time, and the certificate batch update task is triggered when the task start time is reached; wherein the task start time is set according to the expiration time of the existing root certificate of the terminal associated with the certificate batch update task. It can be understood that when the existing root certificate of the terminal is about to expire, the new root certificate is issued to ensure the validity of the root certificate in the terminal.
[0082] In one embodiment, the root certificate update time is calculated according to the certificate size and network status in the historical update record.
[0083] In one embodiment, after the to-be-updated root certificate in the certificate batch update task is issued to the corresponding terminal, the certificate update state fed back by the terminal is received to determine the update status of the to-be-updated root certificate; wherein the certificate update state is obtained by the terminal by comparing the received to-be-updated root certificate with the verification information carried by the to-be-updated root certificate. For example, the verification information can be an MD5 value, which is generated by MD5 (Message Digest Algorithm 5). MD5 is a widely used cryptographic hash function that can generate a 128-bit hash value to ensure the integrity of information transmission.
[0084] Compared with the prior art, in the embodiment, when the certificate batch update task is triggered, the root certificate update time of the terminal associated with the certificate batch update task is determined according to the historical update record, and then the update time information of the terminal is determined based on the set terminal update sequence and the root certificate update time of the terminal, and the update time information is sent to the terminal to make the terminal ready for updating; the to-be-updated root certificate in the certificate batch update task is issued to the corresponding terminal in sequence to realize the root certificate update of the terminal; wherein the to-be-updated root certificate corresponds to the terminal one by one. As can be seen, in the embodiment, the update time information of each terminal is determined according to the historical update status and sent to the corresponding terminal, so that the terminal is ready for updating, the terminal can timely receive the issued root certificate, the timely update of the terminal root certificate is realized, and the prevention of Internet of Things data leakage is facilitated.
[0085] Referring to Figure 4 The embodiment of the application further provides a root certificate update device, comprising:
[0086] The time calculation module 21 is configured to calculate the root certificate update time of the terminal associated with the certificate batch update task according to the historical update record when the certificate batch update task is triggered;
[0087] The information sending module 22 is configured to determine the update time information of the terminal according to the set terminal update sequence and the root certificate update time of the terminal, and send the update time information to the terminal, so that the terminal is ready for updating according to the update time information;
[0088] The certificate issuing module 23 is configured to issue the to-be-updated root certificate in the certificate batch update task to the corresponding terminal in sequence according to the terminal update sequence to realize the root certificate update of the terminal; wherein the to-be-updated root certificate corresponds to the terminal one by one.
[0089] In an embodiment, the method of determining the update time information of the terminal according to the set terminal update sequence and the root certificate update time of the terminal and sending the update time information to the terminal, so that the terminal makes preparation for the update according to the update time information, comprises:
[0090] determining a target terminal according to the obtained current state parameter of the terminal; wherein the target terminal is a terminal whose current state parameter meets the set certificate update requirement;
[0091] sorting all the target terminals to obtain a terminal update sequence;
[0092] calculating the update waiting time of the target terminal according to the root certificate update time of the target terminal according to the terminal update sequence to determine the update time information;
[0093] generating a delayed update instruction carrying the corresponding update time information for each target terminal except the first target terminal and sending the delayed update instruction to the corresponding target terminal, so that the target terminal enters the certificate pushing process according to the corresponding update time information to receive the corresponding root certificate to be updated;
[0094] wherein, if the sleep time node of the first target terminal is before the time node corresponding to the update time information of the first target terminal, the first target terminal sleeps at its sleep time node and re-enters the online state at the time node corresponding to its update time information, wherein the first target terminal is any terminal in all the target terminals.
[0095] In an embodiment, the method of sequentially distributing the root certificate to be updated in the certificate batch update task to the corresponding terminal to realize the root certificate update of the terminal, comprises:
[0096] when the certificate distribution completion time of the adjacent target terminal before the first target terminal has not reached the time node corresponding to the update time information of the first target terminal, and the first target terminal is in a sleep state, distributing the corresponding root certificate to be updated to the second target terminal until the first target terminal re-enters the online state to distribute the corresponding root certificate to be updated to the first target terminal, suspending the distribution of the root certificate to be updated of the second target terminal, and sending a delay instruction carrying the root certificate update time of the first target terminal to the second target terminal, so that the second target terminal re-enters the certificate pushing process to receive the corresponding root certificate to be updated after waiting for the root certificate update time of the first target terminal after receiving the delay instruction; wherein the second target terminal is the closest target terminal to the first target terminal which has not slept, and the second target terminal is later than the first target terminal in the terminal update sequence.
[0097] In an embodiment, the root certificate updating method is applied to a server, the server is connected with the terminal through an MQTT standard protocol, and data interaction between the terminal and the server is realized by the terminal subscribing to a certificate updating topic of the server.
[0098] In an embodiment, the root certificate to be updated is issued to the corresponding terminal only when the acquired current state parameter of the terminal meets the set certificate updating requirement; when the current state parameter includes a current device state, the certificate updating requirement includes that the current device state is online and idle; when the current state parameter includes a current available space, the certificate updating requirement includes that the current available space is greater than or equal to a certificate size of the root certificate to be updated; when the current state parameter includes a current power, the certificate updating requirement includes that the current power is greater than or equal to a set power threshold.
[0099] In an embodiment, the certificate batch updating task is configured with an updating consistency requirement, and the updating consistency requirement is a non-consistent requirement, a weak-consistent requirement or a strong-consistent requirement.
[0100] The method further includes the following steps.
[0101] If the updating consistency requirement is the non-consistent requirement, the target root certificate to be updated in the certificate batch updating task is sequentially issued to the corresponding target terminal, wherein a current state parameter of the target terminal meets the set certificate updating requirement.
[0102] If the updating consistency requirement is the weak-consistent requirement, the target root certificate to be updated in the certificate batch updating task is sequentially issued to the corresponding target terminal, a non-target terminal is marked and a new certificate batch updating task is generated for the non-target terminal until all the non-target terminals complete root certificate updating, wherein a current state parameter of the non-target terminal does not meet the certificate updating requirement.
[0103] If the updating consistency requirement is the strong-consistent requirement, if there is a terminal whose current state parameter does not meet the certificate updating requirement, the current state parameter of the terminal is monitored until the current state parameter of all the terminals associated with the certificate batch updating task meets the certificate updating requirement, and then the root certificate to be updated in the certificate batch updating task is sequentially issued to the corresponding terminal to realize root certificate updating of the terminal.
[0104] In an implementation, before the certificate batch update task is triggered, the method further comprises: receiving a root certificate application request of a terminal, generating a root certificate to be updated for the terminal to join the certificate batch update task;
[0105] The certificate batch update task is further configured with a task start time, and the certificate batch update task is triggered when the task start time is reached; wherein the task start time is set according to the expiration time of the existing root certificate of the terminal associated with the certificate batch update task.
[0106] In an implementation, the root certificate update time is calculated according to the certificate size and network status in the historical update record.
[0107] In an implementation, after the root certificates to be updated in the certificate batch update task are issued to the corresponding terminals, the certificate update status feedback by the terminals is received to determine the update status of the root certificates to be updated; wherein the certificate update status is obtained by the terminal by comparing the received root certificates to be updated with the verification information carried by the root certificates to be updated.
[0108] It is worth noting that the working principle of the device provided in the above embodiments can refer to the working process of the method provided in any of the above embodiments, which will not be repeated here.
[0109] Compared with the prior art, the device provided in the embodiments of the present application determines the root certificate update time of the terminal associated with the certificate batch update task according to the historical update record when the certificate batch update task is triggered, and then determines the update time information of the terminal based on the set terminal update order and the root certificate update time of the terminal, and sends the update waiting time to the terminal to make the terminal ready for update; in turn, the root certificates to be updated in the certificate batch update task are issued to the corresponding terminals to realize the root certificate update of the terminal; wherein the root certificates to be updated correspond one-to-one to the terminals. As can be seen, the embodiments of the present application determine the update time information of each terminal according to the historical update situation and send it to the corresponding terminal, so that the terminal is ready for update, so that the terminal can receive the issued root certificate in time, realize the timely update of the terminal root certificate, and be conducive to preventing the leakage of Internet of Things data.
[0110] Referring to Figure 5 The embodiments of the present application also provide a root certificate update device, which comprises a processor 31, a memory 32, and a computer program stored in the memory 32 and configured to be executed by the processor 31, wherein the processor 31 implements the steps in the above root certificate update method embodiments when executing the computer program, for example Figure 1The processor 31 can implement the functions of the modules in the above-mentioned device embodiments when the processor 31 executes the computer program.
[0111] For example, the computer program can be divided into one or more modules, which are stored in the memory 32 and executed by the processor 31 to complete the present application. The one or more modules can be a series of computer program instruction segments capable of completing a specific function, which are used to describe the execution process of the computer program in the root certificate updating device. For example, the computer program can be divided into a plurality of modules, and each module has the following specific functions:
[0112] The time calculation module 21 is configured to calculate the root certificate updating time of a terminal associated with a certificate batch updating task according to historical updating records when the certificate batch updating task is triggered.
[0113] The information sending module 22 is configured to determine the updating time information of the terminal according to the set terminal updating sequence and the root certificate updating time of the terminal, and send the updating time information to the terminal, so that the terminal makes updating preparation according to the updating time information.
[0114] The certificate issuing module 23 is configured to issue the to-be-updated root certificate in the certificate batch updating task to the corresponding terminal according to the terminal updating sequence, so as to realize the root certificate updating of the terminal. The to-be-updated root certificate corresponds to the terminal one by one.
[0115] The specific working process of each module can refer to the working process of the root certificate updating device described in the above-mentioned embodiments, which will not be described here.
[0116] The root certificate updating device can be a desktop computer, a notebook computer, a palm computer, a cloud server and other computing devices. The root certificate updating device can include, but is not limited to, the processor 31 and the memory 32. Those skilled in the art can understand that the root certificate updating device can also include an input / output device, a network access device, a bus and the like.
[0117] The processor 31 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The processor 31 is a control center of the root certificate updating device, and connects various parts of the root certificate updating device through various interfaces and lines.
[0118] The memory 32 can be used to store computer programs and / or modules. The processor 31 realizes various functions of the root certificate updating device by running or executing the computer programs and / or modules stored in the memory 32, and calling data stored in the memory 32. The memory 32 can mainly include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program required for a function (such as an image playing function, etc.), etc. The data storage area can store data created according to the use of the mobile phone, etc. In addition, the memory 32 can include a high-speed random access memory, and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state memory device.
[0119] If the root certificate updating device integrated module is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer-readable storage medium. When the processor 31 executes the computer program, the steps of each method embodiment described above can be implemented. The computer program includes computer program code, which can be in the form of source code, object code, an executable file, or some intermediate form. The computer-readable medium can include any entity or device capable of carrying the computer program code, a recording medium, a U disk, a mobile hard disk, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0120] The embodiment of the present application also provides a computer program product, including computer programs / instructions, which are executed by a processor to implement the root certificate updating method according to any one of the above-mentioned embodiments.
[0121] The above-mentioned is the preferred embodiment of the present application, and it should be pointed out that, for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, and these improvements and refinements are also considered to be within the protection scope of the present application.
Claims
1. A root certificate update method, characterized in that, include: When a certificate batch update task is triggered, the time required to update the root certificate of the terminal associated with the certificate batch update task is calculated based on the historical update records. The update time information of the terminal is determined according to the set terminal update order and the time required for the root certificate update of the terminal, and the update time information is sent to the terminal so that the terminal can prepare for the update according to the update time information; According to the terminal update order, the root certificates to be updated in the batch certificate update task are sequentially distributed to the corresponding terminals to realize the root certificate update of the terminals; wherein, the root certificates to be updated correspond one-to-one with the terminals.
2. The root certificate update method as described in claim 1, characterized in that, The step of determining the update time information of the terminal based on the set terminal update order and the time required for the terminal's root certificate update, and sending the update time information to the terminal so that the terminal can prepare for the update according to the update time information, includes: The target terminal is determined based on the current status parameters of the acquired terminal; wherein, the target terminal is a terminal whose current status parameters meet the set certificate update requirements; Sort all the target terminals to obtain the terminal update order; According to the terminal update order, the update waiting time of the target terminal is calculated based on the time required to update the root certificate of the target terminal to determine the update time information; A delayed update instruction carrying corresponding update time information is generated for each of the target terminals except the first target terminal and sent to the corresponding target terminal, so that the target terminal enters the certificate push process according to the corresponding update time information to receive the corresponding root certificate to be updated; Wherein, if the hibernation time node of the first target terminal is before the time node corresponding to the update time information of the first target terminal, the first target terminal hibernates at its hibernation time node and comes back online at the time node corresponding to its update time information, wherein the first target terminal is any terminal among all the target terminals.
3. The root certificate update method as described in claim 2, characterized in that, The step of sequentially distributing the root certificates to be updated in the batch certificate update task to the corresponding terminals to achieve root certificate updates for the terminals includes: When the certificate issuance completion time of the adjacent target terminal before the first target terminal has not yet reached the time node corresponding to the update time information of the first target terminal, and the first target terminal is in a dormant state, the corresponding root certificate to be updated is issued to the second target terminal. This continues until the first target terminal comes back online to issue the corresponding root certificate to be updated. At this point, the issuance of the root certificate to be updated for the second target terminal is paused, and a delay instruction carrying the time required for the root certificate update of the first target terminal is sent to the second target terminal. This allows the second target terminal to wait for the time required for the root certificate update of the first target terminal after receiving the delay instruction before re-entering the certificate push process to receive the corresponding root certificate to be updated. The second target terminal is the closest non-dormant target terminal to the first target terminal, and the second target terminal is located after the first target terminal in the terminal update order.
4. The root certificate update method as described in claim 1, characterized in that, The root certificate update method is applied to the server. The server and the terminal are connected via the MQTT standard protocol. Data interaction between the terminal and the server is achieved by the terminal subscribing to the server's certificate update topic.
5. The root certificate update method as described in any one of claims 1 to 4, characterized in that, The root certificate to be updated will be sent to the corresponding terminal only when the current status parameters of the acquired terminal meet the set certificate update requirements; when the current status parameters include the current device status, the certificate update requirements include the current device status being online and idle; when the current status parameters include the current available space, the certificate update requirements include the current available space being greater than or equal to the certificate size of the root certificate to be updated; when the current status parameters include the current battery level, the certificate update requirements include the current battery level being greater than or equal to a set battery threshold.
6. The root certificate update method as described in any one of claims 1 to 4, characterized in that, The certificate batch update task is configured with update consistency requirements, which can be non-consistent, weakly consistent, or strongly consistent. The step of sequentially distributing the root certificates to be updated in the batch certificate update task to the corresponding terminals to achieve root certificate updates for the terminals includes: If the update consistency requirement is a non-consistent requirement, the target root certificates to be updated in the certificate batch update task are sequentially sent to the corresponding target terminals; wherein, the current status parameters of the target terminals meet the set certificate update requirements; When the update consistency requirement is a weak consistency requirement, the target root certificates to be updated in the certificate batch update task are sequentially sent to the corresponding target terminals. Non-target terminals are marked and new certificate batch update tasks are generated for the non-target terminals until all the non-target terminals complete the root certificate update; wherein, the current status parameters of the non-target terminals do not meet the certificate update requirements. When the update consistency requirement is a strong consistency requirement, if the current status parameters of a terminal do not meet the certificate update requirements, the current status parameters of the terminal are monitored until the current status parameters of all terminals associated with the certificate batch update task meet the certificate update requirements. Then, the root certificates to be updated in the certificate batch update task are sequentially sent to the corresponding terminals to realize the root certificate update of the terminal.
7. The root certificate update method as described in any one of claims 1 to 4, characterized in that, Before the certificate batch update task is triggered, the method further includes: receiving a root certificate application request from a terminal, generating a root certificate to be updated for the terminal, and adding it to the certificate batch update task; The certificate batch update task is also configured with a task start time, which is triggered when the task start time is reached; wherein, the task start time is set according to the expiration time of the existing root certificate of the terminal associated with the certificate batch update task.
8. The root certificate update method as described in any one of claims 1 to 4, characterized in that, The time required to update the root certificate is calculated based on the certificate size and network status in the historical update records.
9. The root certificate update method as described in any one of claims 1 to 4, characterized in that, After the root certificates to be updated in the batch certificate update task are sent to the corresponding terminals, the certificate update status fed back by the terminals is received to determine the update status of the root certificates to be updated; wherein, the certificate update status is obtained by the terminal by comparing the received root certificates to be updated with the verification information carried by the root certificates to be updated.
10. A root certificate update device, characterized in that, include: The time calculation module is used to calculate the time required to update the root certificate of the terminal associated with the certificate batch update task based on historical update records when the certificate batch update task is triggered. The information sending module is used to determine the update time information of the terminal according to the set terminal update order and the time required for the root certificate update of the terminal, and send the update time information to the terminal so that the terminal can prepare for the update according to the update time information; The certificate issuance module is used to sequentially issue the root certificates to be updated in the batch certificate update task to the corresponding terminals according to the terminal update order, so as to realize the root certificate update of the terminal; wherein, the root certificates to be updated correspond one-to-one with the terminals.
11. A root certificate update device, characterized in that, The device includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the root certificate update method as described in any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device on which the computer-readable storage medium is located to perform the root certificate update method as described in any one of claims 1 to 9.
13. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the root certificate update method as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Method for processing a digital certificate update request and a server
CN109905243A
Root certificate updating method and device
CN115150162A