Certificate management method, computer program product, device and storage medium

Import and classify the encryption certificate through the substrate management controller interface, and use data table verification to solve the problem of cumbersome certificate import and realize efficient and secure certificate management.

CN119203107BActive Publication Date: 2025-08-26INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411699931.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2025-08-26
Estimated Expiration
2044-11-26

Smart Images

  • Figure CN119203107B_ABST
    Figure CN119203107B_ABST
Patent Text Reader

Abstract

The present application relates to a certificate management method, computer program product, device and storage medium. The method includes: importing a target certificate into a server based on a preset interface, where the preset interface is an interface supported by a baseboard management controller; classifying the target certificate based on a preset interaction protocol to obtain a classified target certificate; encrypting the classified target certificate to obtain an encrypted target certificate, and storing the encrypted target certificate in a preset shared area; verifying the target certificate stored in the preset shared area based on the data table of the target certificate to obtain a verification result, where the data table of the target certificate includes a correspondence between a target flag bit type, a target flag bit value and a verification status; in response to the verification result being a successful verification, restarting the server to make the target certificate effective. The use of this method can improve the reliability of target certificate management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a certificate management method, computer program product, device, and storage medium. Background Art

[0002] Secure Boot is a key security feature in the BIOS (Basic Input / Output System). Prior art practices, when entering the BIOS setup interface during server startup and configuring Secure Boot, typically involve loading the default certificate from the BIOS and importing client certificates via a portable storage device. However, importing client certificates via a portable storage device is cumbersome and inefficient. The manufacturer's default certificate is embedded in the BIOS during program compilation, and customers cannot modify the default public key in the Secure Boot system. Furthermore, even if the manufacturer's default certificate is updated, it cannot be synchronized with the current program, failing to meet customer needs. Summary of the Invention

[0003] Based on this, it is necessary to provide a certificate management method, computer program product, device and storage medium that can effectively manage target certificates in response to the above technical problems.

[0004] In order to solve the above technical problems, in a first aspect, a certificate management method is provided, the method comprising:

[0005] Import the target certificate into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller;

[0006] Classifying the target certificate based on a preset interaction protocol to obtain a classified target certificate;

[0007] Encrypting the classified target certificate to obtain an encrypted target certificate, and storing the encrypted target certificate in a preset shared area;

[0008] Verify the target certificate stored in the preset shared area based on the target certificate data table to obtain a verification result, wherein the target certificate data table includes a correspondence between a target flag bit type, a target flag bit value, and a verification status;

[0009] In response to a verification result indicating that the verification is successful, the server is restarted to make the target certificate effective.

[0010] In one embodiment, the method further includes: importing the target certificate into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller;

[0011] The preset interface receives the server signature certificate information and the target identification code, where the target identification code is the identification code of the import instruction corresponding to importing the target certificate into the server based on the preset interface;

[0012] Perform authentication based on the server signature certificate information and the target identification code to obtain the authentication result;

[0013] If the authentication result is authentication passed, the target certificate is imported into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller.

[0014] In one embodiment, target certificates are classified based on a preset interaction protocol, and the classified target certificates include:

[0015] Acquire a preset interaction protocol, where the preset interaction protocol includes an address of a preset shared area corresponding to a type of a target certificate pre-agreed between the baseboard management controller and the basic input / output system;

[0016] The target certificates are classified based on the type of the target certificates pre-agreed between the baseboard management controller and the basic input / output system to obtain the classified target certificates.

[0017] In one embodiment, the method further includes: encrypting the classified target certificate to obtain an encrypted target certificate, and storing the encrypted target certificate in a preset shared area.

[0018] Obtain target certificate information of the classified target certificate, and encrypt the target certificate information of the classified target certificate based on a preset algorithm to obtain a first secret key;

[0019] Selecting a random number of a preset length from the first secret key based on a random function to generate a second secret key;

[0020] Inserting the second key into the first key based on the first rule to obtain key data, and obfuscating the key data based on the second rule to obtain a target certificate key for the classified target certificate;

[0021] The classified target certificate is encrypted based on the target certificate secret key of the classified target certificate to obtain an encrypted target certificate, and the encrypted target certificate and the target certificate secret key are stored in a preset shared area.

[0022] In one embodiment, the method further includes: presetting a shared area including a key storage area and a target certificate storage area, and storing the encrypted target certificate and the target certificate key in the preset shared area includes:

[0023] Obtaining the type of the encrypted target certificate, obtaining a target certificate storage area corresponding to the type of the encrypted target certificate that matches the type of the target certificate pre-agreed between the baseboard management controller and the basic input / output system from a preset interaction protocol, and storing the encrypted certificate in the target certificate storage area;

[0024] Establish a correspondence between the target certificate storage area and the key storage area, and store the target certificate key in the key storage area.

[0025] In one embodiment, determining a target certificate from a preset shared area and obtaining a data table of the target certificate includes:

[0026] Obtaining a target certificate key corresponding to the target certificate from a preset shared area, deobfuscating the target certificate key corresponding to the target certificate based on the second rule to obtain key data, and decrypting the key data based on the first rule to obtain verification data;

[0027] Obtain the first key and the second key, and determine whether the first key and the second key are consistent with the verification data;

[0028] If they are consistent, the data table of the target certificate is obtained from the preset shared area;

[0029] If they are inconsistent, an empty target certificate data table is returned.

[0030] In one embodiment, the target certificate is verified based on a data table of the target certificate, and the verification result obtained includes:

[0031] Parse the data table of the target certificate to determine whether the target flag value corresponding to the first target flag type of the target certificate is a preset value;

[0032] If so, it is considered that a certificate has been imported into the server, and it is determined whether the target flag value corresponding to the second target flag type of the target certificate is a preset value;

[0033] If yes, the certificate imported into the server is considered to be a default certificate, and the target flag value corresponding to the third target flag type of the target certificate is determined to be a preset value;

[0034] If so, the default certificate imported into the server is considered to be effective, and the historical default certificates stored in the storage device are queried and the historical default certificates are deleted;

[0035] Obtain the default certificate imported into the server, store the default certificate imported into the server in a storage device, further determine whether the default certificate imported into the server is valid, and if so, consider the verification result to be successful, load the default certificate imported into the server, so that the default certificate imported into the server takes effect.

[0036] In one embodiment, determining whether the target flag bit value corresponding to the second target flag bit type of the target certificate is a preset value further includes:

[0037] If the target flag bit value corresponding to the second target flag bit type of the target certificate is a non-preset value, traverse the client certificates imported into the server to determine whether the client certificates include an advanced key certificate;

[0038] If included, determine whether the client certificate including the advanced key certificate is valid;

[0039] If invalid, re-import the certificate. The re-imported certificate includes the advanced key certificate, exchange key certificate, trusted signature database certificate, and non-trusted signature database certificate.

[0040] In one embodiment, the method further comprises:

[0041] In response to the completion of re-importing the certificate, determining whether a target flag bit value corresponding to a fourth target flag bit type of the target certificate is less than or equal to a preset threshold;

[0042] If yes, it is considered that the number of client certificates imported into the server meets the requirement, and further determines whether the target flag value corresponding to the fifth target flag type of the target certificate is a preset value;

[0043] If so, it is considered that the server has completed importing the certificate. In response to the server completing importing the certificate, the verification result is determined to be successful.

[0044] In one embodiment, the method further comprises:

[0045] Calculate a first hash value of the target certificate that is not imported into the server and a second hash value of the target certificate that is imported into the server;

[0046] Determine whether the first hash value and the second hash value are consistent;

[0047] If they are consistent, the data table of the target certificate is obtained;

[0048] If they are inconsistent, the target certificate imported into the server will be deleted, and the target certificate will be re-imported into the server based on the preset interface.

[0049] In one embodiment, the method further includes: obtaining a server signing certificate, where obtaining the server signing certificate includes:

[0050] Generate a key pair based on a random function;

[0051] Generate target data set based on identity encryption algorithm, key pair, server information and client information;

[0052] The target dataset is sent to a certificate issuing authority, which builds a server-signed certificate based on the target dataset.

[0053] In one embodiment, the method further includes: obtaining server signature certificate information, and calculating server summary information using a summary algorithm and the server signature certificate information;

[0054] Encode the server summary information to obtain a server identifier, where the server identifier is a string consisting of the server summary code and a preset symbol;

[0055] Obtain the server unique identification code, calculate the similarity between the server unique identification code and the server identification, obtain a similarity value, and verify the server signature certificate information based on the server similarity value.

[0056] In order to solve the above technical problem, in a second aspect, a computer program product is provided, including a computer program, characterized in that when the computer program is executed by a processor, the steps of the method described in the first aspect are implemented.

[0057] In order to solve the above technical problems, in the third aspect, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the computer program, the following steps are implemented: when the processor executes the computer program, the steps of the method described in the first aspect are implemented.

[0058] In order to solve the above technical problems, in a fourth aspect, the present application provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in the first aspect are implemented.

[0059] Different from the prior art, the present application imports the target certificate into the server based on a preset interface, which is an interface supported by the baseboard management controller; classifies the target certificate based on a preset interaction protocol to obtain a classified target certificate; encrypts the classified target certificate to obtain an encrypted target certificate, and stores the encrypted target certificate in a preset shared area; verifies the target certificate stored in the preset shared area based on the data table of the target certificate to obtain a verification result, and the data table of the target certificate includes a correspondence between the target flag bit type, the target flag bit value, and the verification status; in response to the verification result being a successful verification, restarts the server to make the target certificate effective. By judging that the target certificate is imported into the server using the preset interface, the efficiency of importing the target certificate can be improved, and the target certificate is verified through the data table of the target certificate, so that the successfully verified target certificate is effective, and the target certificate management can be performed accurately and efficiently. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] Figure 1 1 is a flow chart of a certificate management method according to an embodiment;

[0061] Figure 2 1 is a flow chart of a certificate management method according to another embodiment;

[0062] Figure 3 is a structural block diagram of a certificate management device in one embodiment;

[0063] Figure 4 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0064] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0065] In order to solve the above technical problems, in one embodiment, Figure 1 As shown, this application provides a certificate management method, which specifically includes the following steps:

[0066] Step 101: importing a target certificate into a server based on a preset interface, where the preset interface is an interface supported by a baseboard management controller.

[0067] Specifically, the target certificate can be a user certificate or a default certificate, and the preset interface can be a Redfish interface, which can connect to the managed device and the management terminal through the network. The management terminal can be server management software, a browser, etc. The management terminal sends an HTTP request to the Redfish interface of the baseboard management controller. The baseboard management controller performs the corresponding management operation based on the request and returns the result in JSON or XML format. By using the preset interface to import the target certificate, certificates can be imported in batches, improving the efficiency of certificate import.

[0068] It should be noted that the redfish interface is an interface supported by the baseboard management controller. The baseboard management controller needs to import a new program in redfish to support the import of the target certificate. If you want to use other types of interfaces to implement the import of the target certificate, you need to import other types of interface programs in the baseboard management controller and import the target certificate import program in the new interface program before you can import the target certificate.

[0069] In one embodiment, the target certificate is imported into the server based on a preset interface, and the preset interface is an interface supported by the baseboard management controller, which also includes: the preset interface receives the server signature certificate information and the target identification code, and the target identification code is the identification code of the import instruction corresponding to the import of the target certificate into the server based on the preset interface; authentication is performed based on the server signature certificate information and the target identification code to obtain an authentication result; if the authentication result is authentication passed, the target certificate is imported into the server based on the preset interface, and the preset interface is an interface supported by the baseboard management controller.

[0070] Specifically, the server's signed certificate information can be a certificate sent to the server by a trusted party. This certificate can be used to authenticate the user registry configured on the server. After the server containing this certificate receives a request, it needs to log in to form a credential. This credential is used for authorization. Signature authentication can be configured on the server.

[0071] In one embodiment, a key pair can be generated based on a random function, and an identification encryption algorithm such as SM9 can be used to generate a target data set from the key pair, server information, and client information. For example, feature points can be extracted from the key pair, server information, and client information, and then a one-variable equation can be constructed using the feature points as coefficients to obtain calculated values ​​of unknowns in the one-variable equation with different numerical values. These values ​​are then used to construct a target data set, and the target data set containing the key pair, server information, and client information features is sent to a certificate issuing authority to obtain a server signature certificate. The target identification code can be an identifier for authenticating an import instruction corresponding to an interface supported by a baseboard management controller when importing a target certificate into a server based on a preset interface. The preset interface is an identifier for authenticating an import instruction corresponding to an interface supported by a baseboard management controller. The target identification code can be composed of a certain number of characters. This application does not specifically limit the form of the identifier.

[0072] The binary server summary information can be calculated based on the server signature certificate information and the summary algorithm, and the server summary information can be encoded using Base32. The binary server summary information is encoded into a string to obtain the server identifier. Any calculation symbol can be introduced at the end of the server identifier to form a string. The unique identification code of the server is obtained. The unique identification code of the server can be the production number of the server. The similarity between the unique identification code of the server and the server identifier is calculated to obtain a similarity value. The server signature certificate information is verified based on the server similarity value. Generally, a server with a similarity value greater than a preset similarity value is regarded as a trusted server, and the target certificate is imported. The preset similarity value here can be set based on experience. This application does not limit the specific value of the preset similarity value.

[0073] Based on the target identification code, the target certificate is imported into the server based on the preset interface. The preset interface is an interface supported by the baseboard management controller, and the import instruction corresponding to the target identification code is authenticated. The target identification code is compared with the preset trusted identification code, and the credibility of the import instruction is authenticated. When the import instruction and the server are both trusted, the authentication result is displayed as authentication passed. Then the target certificate is imported into the server based on the preset interface. The preset interface is an interface supported by the baseboard management controller. In this way, the reliability of the certificate import can be improved.

[0074] In one embodiment, the feasible server signature certificate information can be a server of a trusted server.

[0075] Step 102: classify the target certificate based on a preset interaction protocol to obtain a classified target certificate.

[0076] Specifically, a preset interaction protocol is obtained, and the preset interaction protocol includes the address of a preset shared area corresponding to the type of target certificate pre-agreed between the baseboard management controller and the basic input / output system; the target certificate is classified based on the type of target certificate pre-agreed between the baseboard management controller and the basic input / output system to obtain the classified target certificate. The preset shared area here is the address where different types of target certificates specified by the baseboard management controller and the basic input / output system are stored in the preset shared area. Exemplarily, the target certificate may include an advanced key certificate, an exchange key certificate, and the like. The storage location and import order of the advanced key certificate and the exchange key certificate may be specified in the preset interaction protocol to facilitate subsequent reading and loading of the target certificate.

[0077] Step 103: encrypt the classified target certificate to obtain an encrypted target certificate, and store the encrypted target certificate in a preset shared area.

[0078] Specifically, the target certificate information of the classified target certificate is obtained, and the target certificate information of the classified target certificate is encrypted based on a preset algorithm to obtain a first secret key; a random number of a preset length is selected from the first secret key based on a random function to generate a second secret key; the second secret key is inserted into the first secret key based on the first rule to obtain secret key data, and the secret key data is obfuscated based on the second rule to obtain the target certificate key of the classified target certificate; the classified target certificate is encrypted based on the target certificate key of the classified target certificate to obtain an encrypted target certificate, and the encrypted target certificate and the target certificate key are stored in a preset shared area.

[0079] Exemplarily, after the target certificates are classified according to their types, the preset algorithms may include a first algorithm and a second algorithm. The first algorithm may be to apply an encryption algorithm to encrypt the target certificate information of each type of target certificate after classification, obtain multiple sub-keys, and then integrate the multiple sub-keys to obtain a first secret key; the second algorithm may be to apply an encryption algorithm to first integrate the target certificate information of each type of target certificate after classification, obtain integrated target certificate information, encrypt the integrated target certificate information, and obtain the first secret key. The encryption algorithm in this embodiment may include one or a combination of several of symmetric encryption, asymmetric encryption, hash algorithm, and digital signature.

[0080] After obtaining the first secret key, a second secret key can be generated by selecting characters of a preset length from the first secret key based on a random function. The preset length can be set according to actual circumstances, and this application does not limit the specific value of the preset length. The first rule can be to divide the second secret key into multiple sub-second secret keys, and randomly insert the multiple sub-second secret keys into the first secret key to obtain key data. The order of the characters in the first and second secret keys is the first rule.

[0081] The second rule is the obfuscation rule, which can divide the key data in advance to obtain multiple sub-key data, and perform byte flipping on each sub-key data in the multiple sub-key data so that the first byte and the second byte of each sub-key data are swapped, generating multiple flipped key files, performing OR operation on each character in each flipped key file to obtain multiple sub-obfuscation files, and obtaining the target certificate key corresponding to each classified target certificate. In this way, the security of target certificate management is improved.

[0082] Each classified target certificate is encrypted based on the target certificate secret key corresponding to each classified target certificate to obtain an encrypted target certificate, and the encrypted target certificate and the target certificate secret key are stored in a preset shared area.

[0083] In one embodiment, encrypting each classified target certificate to obtain the encrypted target certificate may include: obtaining characteristic information of each classified target certificate, constructing target certificate encryption file header information based on the characteristic information of each classified target certificate, and encrypting each classified target certificate according to the encrypted file header information to obtain the encrypted target certificate.

[0084] For example, the feature extraction algorithm can be used to extract features of each classified target certificate to obtain feature information of each classified target certificate, and the feature information of each classified target certificate can be hashed to obtain the hash value of each classified target certificate. The hash value of each classified target certificate can be concatenated according to the storage location to form the target certificate encrypted file header information, and then each classified target certificate can be encrypted based on the encrypted file header information to obtain the encrypted target certificate. In this way, each classified target certificate can be encrypted in combination with the features of the target certificate, which can improve the security of target certificate management.

[0085] The preset shared area includes a key storage area and a target certificate storage area. The type of the encrypted target certificate is obtained, and the target certificate storage area corresponding to the type of the encrypted target certificate that matches the type of the target certificate pre-agreed between the baseboard management controller and the basic input and output system is obtained from the preset interaction protocol, and the encrypted certificate is stored in the target certificate storage area; a corresponding relationship between the target certificate storage area and the key storage area is established, and the target certificate key is stored in the key storage area.

[0086] Step 104: Verify the target certificate stored in the preset shared area based on the target certificate data table to obtain a verification result. The target certificate data table includes a correspondence between a target flag type, a target flag value, and a verification status.

[0087] Specifically, the target certificate can be determined from the preset shared area, and obtaining the data table of the target certificate includes: obtaining the target certificate key corresponding to the target certificate from the preset shared area, deobfuscating the target certificate key corresponding to the target certificate based on the second rule to obtain key data, and decrypting the key data based on the first rule to obtain verification data; obtaining the first key and the second key, and determining whether the first key and the second key are consistent with the verification data; if they are consistent, obtaining the data table of the target certificate from the preset shared area; if they are inconsistent, returning an empty target certificate data table.

[0088] In this embodiment, the encrypted target certificate is decrypted. Specifically, it is the reverse operation of step 103, which will not be described in detail here. After decryption, verification data is obtained. The verification data obtained during the decryption process is then compared with the first and second keys during the encryption process. If the comparison results are consistent, the target certificate data table is directly obtained from the preset shared area. If they are inconsistent, an empty target certificate data table is returned, and the empty target certificate data table is unusable.

[0089] After obtaining the data table of the target certificate, the target certificate can be verified according to the data table of the target certificate. The data table of the target certificate may include the correspondence between multiple target flag bit types, multiple target flag bit values, and multiple verification statuses. Specifically: the data table of the target certificate is parsed to determine whether the target flag bit value corresponding to the first target flag bit type of the target certificate is a preset value; the first target flag bit type can be represented as (CerFlag), which is a certificate import flag bit. The target flag bit value of the first target flag bit type can represent the import status of the target certificate. For example, when the target flag bit value of the first target flag bit type is a preset value, it is considered that a certificate has been imported into the server, and the subsequent verification process continues. If the target flag bit value of the first target flag bit type is not a preset value, it is considered that the certificate has not been imported into the server, and the process jumps directly to the end step.

[0090] If the target flag bit value of the first target flag bit type is a preset value, it is considered that a certificate has been imported into the server, and further determination is made as to whether the target flag bit value corresponding to the second target flag bit type of the target certificate is a preset value. The second target flag bit type can be represented as (DefaultCerFlag), which is the default certificate import flag bit. The target flag bit value of the second target flag bit type can represent the import status of the default certificate. If the target flag bit value of the second target flag bit type is a preset value, it is considered that the default certificate has been imported into the server. If the target flag bit value of the second target flag bit type is a non-preset value, it is considered that the default certificate has not been imported into the server.

[0091] Specifically, if yes, the certificate imported into the server is considered to be a default certificate, and it is further determined whether the target flag value corresponding to the third target flag type of the target certificate is a preset value; if the target flag value corresponding to the third target flag type of the target certificate is not a preset value, the certificate imported into the server is deleted, and the certificate is re-imported. The re-imported certificate includes the advanced key certificate, the exchange key certificate, the trusted signature database certificate, and the non-trusted signature database certificate. The third target flag type can be expressed as (DefaultCerEnableFlag), which is the flag for enabling the import of the default certificate. The target flag value of the third target flag type can represent the effectiveness of the default certificate imported into the server. For example, when the target flag value of the third target flag type is a preset value, the effectiveness of the default certificate imported into the server is considered to be effective. If the target flag value of the third target flag type is not a preset value, the effectiveness of the default certificate imported into the server is considered to be ineffective, and the process directly jumps to the end step.

[0092] If the target flag bit value of the third target flag bit type is the preset value, the default certificate imported into the server is considered to be effective, the historical default certificate stored in the storage device is queried, and the historical default certificate is deleted; the default certificate imported into the server is obtained, and the default certificate imported into the server is stored in the storage device; further judgment is made as to whether the default certificate imported into the server is valid. If valid, the verification result is considered to be successful, and the default certificate imported into the server is loaded to make the default certificate imported into the server effective.

[0093] If the target flag bit value corresponding to the second target flag bit type of the target certificate is not a preset value, the client certificates imported into the server are traversed to determine whether the client certificate includes the advanced key certificate; if included, whether the client certificate including the advanced key certificate is valid is determined; if invalid, the certificate is re-imported, and the re-imported certificate includes the advanced key certificate, the exchange key certificate, the trusted signature database certificate, and the non-trusted signature database certificate.

[0094] In response to the completion of re-importing the certificate, determine whether the target flag bit value corresponding to the fourth target flag bit type of the target certificate is less than or equal to the preset threshold; if so, it is considered that the number of client certificates imported into the server meets the requirements, and further determine whether the target flag bit value corresponding to the fifth target flag bit type of the target certificate is a preset value; the fourth target flag bit type can be expressed as (CerNum), which is the flag bit for the number of imported client certificates. The target flag bit value of the fourth target flag bit type can represent the number of client certificates imported into the server, and the target flag bit value of the fourth target flag bit type can be compared with the preset threshold. When the target flag bit value corresponding to the fourth target flag bit type is less than or equal to the preset threshold, it is considered that the number of client certificates imported into the server meets the requirements. If the target flag bit value of the fourth target flag bit type is a non-preset value, it is considered that the number of client certificates imported into the server does not meet the requirements, and directly jump to the end step.

[0095] If the number of client certificates imported into the server meets the requirements, it is further determined whether the target flag bit value corresponding to the fifth target flag bit type of the target certificate is a preset value; the fifth target flag bit type can be expressed as (SucceedFlag), which is a flag bit for successful certificate import. The target flag bit value of the fifth target flag bit type can represent the completion status of the import of the target certificate. For example, when the target flag bit value of the fifth target flag bit type is a preset value, it is considered that the server has completed importing the certificate. The target certificate addition success flag bit can be set to a preset value to represent that all target certificates have been imported into the server and the process ends. If the target flag bit value of the fifth target flag bit type is not a preset value, it is considered that the certificate import into the server is not complete, and the imported certificate is deleted, and the process jumps directly to the end step. For example, before importing the target certificate into the server, the certificate length or certificate volume of the target certificate to be imported into the server can be obtained. By comparing the length or volume of the target certificate before being imported into the server with the length or volume of the target certificate imported into the server, the completion status of the certificate import into the server can be obtained. If the target flag bit value of the fifth target flag bit type is not a preset value, it is considered that the server has completed importing the certificate. In response to the server completing importing the certificate, the verification result is determined to be successful.

[0096] In a specific implementation, the target flag type of the target certificate's data table and the verification status corresponding to the target flag value can be pre-set according to requirements, and the specific value of the target flag can be obtained by the basic input and output system when the target certificate is imported into the server, and after the server imports the target certificate, the target certificate's data table is obtained when the server is started to perform a verification operation.

[0097] For example, the data table of the target certificate may be shown in Table 1 below:

[0098]

[0099] Table 1

[0100] In order to better illustrate the certificate management method provided by this application, in a specific embodiment, combined with Table 1 and Figure 2 Describe the certificate management method. In Table 1 of this application, the preset value is 1 and the non-preset value is 0 as an example. The preset value can be any number or character, and the non-preset value is any number or character other than the preset value. This application does not limit the specific values ​​of the preset value and the non-preset value.

[0101] When the server is started, it will get the data table of the target certificate ( Figure 2Reading the Certificate Import Header Data in Table 1 shows that if the certificate import flag (CerFlag) is 1, the default certificate import flag is further verified. If CerFlag is 0, the certificate import process exits (in other words, determining whether a certificate has been imported). When DefaultCerFlag is 1, the default certificate verification, deletion, and replacement process can be executed. After the replacement is complete, the DefaultCerEnableFlag flag is further checked. If DefaultCerEnableFlag is 1, the default certificate package is parsed and loaded, and the relevant interface options are modified to display correctly. (In other words, the default certificate flag is read to determine whether the imported certificate on the server is the default certificate.) Default certificates are typically OEM certificates. Multiple types of certificates to be imported are pre-packaged into a single certificate, which is then replaced when the new default certificate is imported. If DefaultCerFlag is 0, the client certificate import process begins. All client certificates are traversed to verify whether the certificate number is equal to CerNum. If not, the import process exits. If they are, the presence of a premium key certificate (PK) is checked. If an advanced key certificate exists, the currently used certificate is deleted (this may be a default certificate or a previously imported certificate from the client, also considered a historical certificate, to determine the validity status of the default certificate imported into the server). The advanced key certificate, exchange key certificate (KEK), trusted signature database certificate (DB), and untrusted signature database certificate (DBX) are then imported in sequence (this determines whether the required number of client certificates imported into the server is met). Finally, a check is made to ensure that all certificates have been imported (this determines whether the import of the target certificate is complete). If any certificate import fails, the currently imported certificate is deleted and the import process exits.

[0102] In this application, the target certificate import and import status are managed by setting up a multi-level data table of the target certificate that contains the correspondence between the target flag bit type, the target flag bit value and the verification status, and the information applied to the target certificate management is pre-set in the data table of the target certificate, so that the required data can be quickly obtained to manage the target certificate in the future, which can improve the efficiency of target management, and the multi-level judgment can improve the management accuracy.

[0103] Step 105: In response to the verification result being successful, restart the server to make the target certificate effective.

[0104] When the verification result is successful, the server is automatically restarted to make the certificate imported into the server and verified to take effect.

[0105] In one embodiment, a first hash value of a target certificate that has not been imported into the server and a second hash value of a target certificate that has been imported into the server are calculated; a determination is made as to whether the first hash value and the second hash value are consistent; if they are consistent, a data table of the target certificate is obtained; if they are inconsistent, the target certificate imported into the server is deleted, and the target certificate is re-imported into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller.

[0106] Before the target certificate is imported into the server, the first hash value of the target certificate is calculated. After the target certificate is imported into the server, the second hash value of the target certificate imported into the server is calculated. The first and second hash values ​​are used to verify that there are no errors in the data after the certificate is transferred. At the same time, the storage location of the next certificate of the same type is calculated based on the certificate length.

[0107] By updating the default certificate through the redfish interface of the baseboard management controller, the certificate can be updated for the customer in a timely manner. In the event of a key certificate leak, a new default certificate can also be quickly replaced for the customer. By importing the customer certificate through the redfish interface of the baseboard management controller, the tedious and time-consuming work of importing certificates from external storage devices and other storage devices is eliminated. Certificates can be imported in batches through redfish and quickly deployed to all the customer's servers. The present invention can also provide certificate customization services for server customers with higher security requirements. Certificates are customized for each server, and each device has a unique key certificate, which greatly improves device security.

[0108] It should be understood that although Figure 1-Figure 2 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. In addition, Figure 1-Figure 2 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.

[0109] In one embodiment, Figure 3 As shown, a certificate management device is provided, including: an acquisition module 30, an encryption module 31 and a verification module 32, wherein:

[0110] The acquisition module 30 is configured to import the target certificate into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller; and classify the target certificate based on a preset interaction protocol to obtain the classified target certificate.

[0111] The encryption module 31 is configured to encrypt the classified target certificates to obtain the encrypted target certificates, and store the encrypted target certificates in a preset shared area.

[0112] The verification module 32 is used to verify the target certificate stored in the preset shared area based on the data table of the target certificate to obtain a verification result. The data table of the target certificate includes the correspondence between the target flag type, the target flag value and the verification status; in response to the verification result being a successful verification, the server is restarted to make the target certificate effective.

[0113] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0114] Import the target certificate into the server based on the preset interface. The preset interface is the interface supported by the baseboard management controller and also includes:

[0115] The preset interface receives the server signature certificate information and the target identification code, where the target identification code is the identification code of the import instruction corresponding to importing the target certificate into the server based on the preset interface;

[0116] Perform authentication based on the server signature certificate information and the target identification code to obtain the authentication result;

[0117] If the authentication result is authentication passed, the target certificate is imported into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller.

[0118] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0119] The target certificates are classified based on the preset interaction protocol. The classified target certificates include:

[0120] Acquire a preset interaction protocol, where the preset interaction protocol includes an address of a preset shared area corresponding to a type of a target certificate pre-agreed between the baseboard management controller and the basic input / output system;

[0121] The target certificates are classified based on the type of the target certificates pre-agreed between the baseboard management controller and the basic input / output system to obtain the classified target certificates.

[0122] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0123] Encrypting the classified target certificate to obtain the encrypted target certificate, and storing the encrypted target certificate in the preset shared area includes:

[0124] Obtain target certificate information of the classified target certificate, and encrypt the target certificate information of the classified target certificate based on a preset algorithm to obtain a first secret key;

[0125] Selecting a random number of a preset length from the first secret key based on a random function to generate a second secret key;

[0126] Inserting the second key into the first key based on the first rule to obtain key data, and obfuscating the key data based on the second rule to obtain a target certificate key for the classified target certificate;

[0127] The classified target certificate is encrypted based on the target certificate secret key of the classified target certificate to obtain an encrypted target certificate, and the encrypted target certificate and the target certificate secret key are stored in a preset shared area.

[0128] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0129] The preset shared area includes a key storage area and a target certificate storage area. Storing the encrypted target certificate and target certificate key in the preset shared area includes:

[0130] Obtaining the type of the encrypted target certificate, obtaining a target certificate storage area corresponding to the type of the encrypted target certificate that matches the type of the target certificate pre-agreed between the baseboard management controller and the basic input / output system from a preset interaction protocol, and storing the encrypted certificate in the target certificate storage area;

[0131] Establish a correspondence between the target certificate storage area and the key storage area, and store the target certificate key in the key storage area.

[0132] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0133] Determine the target certificate from the preset shared area, and obtain the target certificate data table including:

[0134] Obtaining a target certificate key corresponding to the target certificate from a preset shared area, deobfuscating the target certificate key corresponding to the target certificate based on the second rule to obtain key data, and decrypting the key data based on the first rule to obtain verification data;

[0135] Obtain the first key and the second key, and determine whether the first key and the second key are consistent with the verification data;

[0136] If they are consistent, the data table of the target certificate is obtained from the preset shared area;

[0137] If they are inconsistent, an empty target certificate data table is returned.

[0138] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0139] Verify the target certificate based on the target certificate's data table. The verification results include:

[0140] Parse the data table of the target certificate to determine whether the target flag value corresponding to the first target flag type of the target certificate is a preset value;

[0141] If so, it is considered that a certificate has been imported into the server, and it is determined whether the target flag value corresponding to the second target flag type of the target certificate is a preset value;

[0142] If yes, the certificate imported into the server is considered to be a default certificate, and the target flag value corresponding to the third target flag type of the target certificate is determined to be a preset value;

[0143] If so, the default certificate imported into the server is considered to be effective, and the historical default certificates stored in the storage device are queried and the historical default certificates are deleted;

[0144] Obtain the default certificate imported into the server, store the default certificate imported into the server in a storage device, further determine whether the default certificate imported into the server is valid, and if so, consider the verification result to be successful, load the default certificate imported into the server, so that the default certificate imported into the server takes effect.

[0145] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0146] Determining whether the target flag bit value corresponding to the second target flag bit type of the target certificate is a preset value further includes:

[0147] If the target flag bit value corresponding to the second target flag bit type of the target certificate is a non-preset value, traverse the client certificates imported into the server to determine whether the client certificates include an advanced key certificate;

[0148] If included, determine whether the client certificate including the advanced key certificate is valid;

[0149] If invalid, re-import the certificate. The re-imported certificate includes the advanced key certificate, exchange key certificate, trusted signature database certificate, and non-trusted signature database certificate.

[0150] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0151] The method also includes:

[0152] In response to the completion of re-importing the certificate, determining whether a target flag bit value corresponding to a fourth target flag bit type of the target certificate is less than or equal to a preset threshold;

[0153] If yes, it is considered that the number of client certificates imported into the server meets the requirement, and further determines whether the target flag value corresponding to the fifth target flag type of the target certificate is a preset value;

[0154] If so, it is considered that the server has completed importing the certificate. In response to the server completing importing the certificate, the verification result is determined to be successful.

[0155] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0156] The method also includes:

[0157] Calculate a first hash value of the target certificate that is not imported into the server and a second hash value of the target certificate that is imported into the server;

[0158] Determine whether the first hash value and the second hash value are consistent;

[0159] If they are consistent, the data table of the target certificate is obtained;

[0160] If they are inconsistent, the target certificate imported into the server is deleted, and the target certificate is re-imported into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller.

[0161] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0162] The method further includes obtaining a server signature certificate, and obtaining the server signature certificate includes:

[0163] Generate a key pair based on a random function;

[0164] Generate target data set based on identity encryption algorithm, key pair, server information and client information;

[0165] The target dataset is sent to a certificate issuing authority, which builds a server-signed certificate based on the target dataset.

[0166] In one embodiment, the above device can implement another implementation of the certificate management method, and the specific steps are as follows:

[0167] The method also includes:

[0168] Obtain the server signature certificate information, and calculate the server summary information using the digest algorithm and the server signature certificate information;

[0169] Encode the server summary information to obtain a server identifier, where the server identifier is a string consisting of the server summary code and a preset symbol;

[0170] Obtain the server unique identification code, calculate the similarity between the server unique identification code and the server identification, obtain a similarity value, and verify the server signature certificate information based on the server similarity value.

[0171] The specific definition of the certificate management device can be found in the definition of the certificate management method above and will not be repeated here. Each module in the certificate management device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a memory in a computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0172] In one embodiment, the present application also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the certificate management method provided by the above methods.

[0173] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 4 As shown. The computer device includes a processor, a memory, a network interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a certificate management method is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad provided on the computer device housing, or an external keyboard, touchpad or mouse, etc.

[0174] Those skilled in the art will understand that Figure 4The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0175] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the following steps are performed:

[0176] Step 101: importing a target certificate into a server based on a preset interface, where the preset interface is an interface supported by a baseboard management controller.

[0177] Step 102: classify the target certificate based on a preset interaction protocol to obtain a classified target certificate.

[0178] Step 103: encrypt the classified target certificate to obtain an encrypted target certificate, and store the encrypted target certificate in a preset shared area.

[0179] Step 104: Verify the target certificate stored in the preset shared area based on the target certificate data table to obtain a verification result. The target certificate data table includes a correspondence between a target flag type, a target flag value, and a verification status.

[0180] Step 105: In response to the verification result being successful, restart the server to make the target certificate effective.

[0181] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0182] Import the target certificate into the server based on the preset interface. The preset interface is the interface supported by the baseboard management controller and also includes:

[0183] The preset interface receives the server signature certificate information and the target identification code, where the target identification code is the identification code of the import instruction corresponding to importing the target certificate into the server based on the preset interface;

[0184] Perform authentication based on the server signature certificate information and the target identification code to obtain the authentication result;

[0185] If the authentication result is authentication passed, the target certificate is imported into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller.

[0186] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0187] The target certificates are classified based on the preset interaction protocol. The classified target certificates include:

[0188] Acquire a preset interaction protocol, where the preset interaction protocol includes an address of a preset shared area corresponding to a type of a target certificate pre-agreed between the baseboard management controller and the basic input / output system;

[0189] The target certificates are classified based on the type of the target certificates pre-agreed between the baseboard management controller and the basic input / output system to obtain the classified target certificates.

[0190] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0191] Encrypting the classified target certificate to obtain the encrypted target certificate, and storing the encrypted target certificate in the preset shared area includes:

[0192] Obtain target certificate information of the classified target certificate, and encrypt the target certificate information of the classified target certificate based on a preset algorithm to obtain a first secret key;

[0193] Selecting a random number of a preset length from the first secret key based on a random function to generate a second secret key;

[0194] Inserting the second key into the first key based on the first rule to obtain key data, and obfuscating the key data based on the second rule to obtain a target certificate key for the classified target certificate;

[0195] The classified target certificate is encrypted based on the target certificate secret key of the classified target certificate to obtain an encrypted target certificate, and the encrypted target certificate and the target certificate secret key are stored in a preset shared area.

[0196] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0197] The preset shared area includes a key storage area and a target certificate storage area. Storing the encrypted target certificate and target certificate key in the preset shared area includes:

[0198] Obtaining the type of the encrypted target certificate, obtaining a target certificate storage area corresponding to the type of the encrypted target certificate that matches the type of the target certificate pre-agreed between the baseboard management controller and the basic input / output system from a preset interaction protocol, and storing the encrypted certificate in the target certificate storage area;

[0199] Establish a correspondence between the target certificate storage area and the key storage area, and store the target certificate key in the key storage area.

[0200] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0201] Determine the target certificate from the preset shared area, and obtain the target certificate data table including:

[0202] Obtaining a target certificate key corresponding to the target certificate from a preset shared area, deobfuscating the target certificate key corresponding to the target certificate based on the second rule to obtain key data, and decrypting the key data based on the first rule to obtain verification data;

[0203] Obtain the first key and the second key, and determine whether the first key and the second key are consistent with the verification data;

[0204] If they are consistent, the data table of the target certificate is obtained from the preset shared area;

[0205] If they are inconsistent, an empty target certificate data table is returned.

[0206] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0207] Verify the target certificate based on the target certificate's data table. The verification results include:

[0208] Parse the data table of the target certificate to determine whether the target flag value corresponding to the first target flag type of the target certificate is a preset value;

[0209] If so, it is considered that there is a certificate imported into the server, and it is determined whether the target flag value corresponding to the second target flag type of the target certificate is a preset value;

[0210] If yes, the certificate imported into the server is considered to be the default certificate, and the target flag value corresponding to the third target flag type of the target certificate is determined to be a preset value;

[0211] If so, the default certificate imported into the server is considered to be effective, and the historical default certificate stored in the storage device is queried and the historical default certificate is deleted;

[0212] Obtain the default certificate imported into the server, store the default certificate imported into the server in a storage device, further determine whether the default certificate imported into the server is valid, and if so, consider the verification result to be successful, load the default certificate imported into the server, so that the default certificate imported into the server takes effect.

[0213] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0214] Determining whether the target flag bit value corresponding to the second target flag bit type of the target certificate is a preset value also includes:

[0215] If the target flag bit value corresponding to the second target flag bit type of the target certificate is a non-preset value, traverse the client certificates imported into the server to determine whether the client certificates include an advanced key certificate;

[0216] If included, determine whether the client certificate including the advanced key certificate is valid;

[0217] If invalid, re-import the certificate. The re-imported certificate includes the advanced key certificate, exchange key certificate, trusted signature database certificate, and non-trusted signature database certificate.

[0218] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0219] The method also includes:

[0220] In response to the completion of re-importing the certificate, determining whether a target flag bit value corresponding to a fourth target flag bit type of the target certificate is less than or equal to a preset threshold;

[0221] If yes, it is considered that the number of client certificates imported into the server meets the requirement, and further determines whether the target flag value corresponding to the fifth target flag type of the target certificate is a preset value;

[0222] If so, it is considered that the server has completed importing the certificate. In response to the server completing importing the certificate, the verification result is determined to be successful.

[0223] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0224] The method also includes:

[0225] Calculate a first hash value of the target certificate that is not imported into the server and a second hash value of the target certificate that is imported into the server;

[0226] Determine whether the first hash value and the second hash value are consistent;

[0227] If they are consistent, the data table of the target certificate is obtained;

[0228] If they are inconsistent, the target certificate imported into the server is deleted, and the target certificate is re-imported into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller.

[0229] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0230] The method further includes obtaining a server signature certificate, and obtaining the server signature certificate includes:

[0231] Generate a key pair based on a random function;

[0232] Generate target data set based on identity encryption algorithm, key pair, server information and client information;

[0233] The target dataset is sent to a certificate issuing authority, which builds a server-signed certificate based on the target dataset.

[0234] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0235] The method also includes:

[0236] Obtain the server signature certificate information, and calculate the server summary information using the digest algorithm and the server signature certificate information;

[0237] Encode the server summary information to obtain a server identifier, where the server identifier is a string consisting of the server summary code and a preset symbol;

[0238] Obtain the server unique identification code, calculate the similarity between the server unique identification code and the server identification, obtain a similarity value, and verify the server signature certificate information based on the server similarity value.

[0239] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0240] Step 101: importing a target certificate into a server based on a preset interface, where the preset interface is an interface supported by a baseboard management controller.

[0241] Step 102: classify the target certificate based on a preset interaction protocol to obtain a classified target certificate.

[0242] Step 103: encrypt the classified target certificate to obtain an encrypted target certificate, and store the encrypted target certificate in a preset shared area.

[0243] Step 104: Verify the target certificate stored in the preset shared area based on the target certificate data table to obtain a verification result. The target certificate data table includes a correspondence between a target flag type, a target flag value, and a verification status.

[0244] Step 105: In response to the verification result being successful, restart the server to make the target certificate effective.

[0245] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0246] Import the target certificate into the server based on the preset interface. The preset interface is the interface supported by the baseboard management controller and also includes:

[0247] The preset interface receives the server signature certificate information and the target identification code, where the target identification code is the identification code of the import instruction corresponding to importing the target certificate into the server based on the preset interface;

[0248] Perform authentication based on the server signature certificate information and the target identification code to obtain the authentication result;

[0249] If the authentication result is authentication passed, the target certificate is imported into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller.

[0250] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0251] The target certificates are classified based on the preset interaction protocol. The classified target certificates include:

[0252] Acquire a preset interaction protocol, where the preset interaction protocol includes an address of a preset shared area corresponding to a type of a target certificate pre-agreed between the baseboard management controller and the basic input / output system;

[0253] The target certificates are classified based on the type of the target certificates pre-agreed between the baseboard management controller and the basic input / output system to obtain the classified target certificates.

[0254] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0255] Encrypting the classified target certificate to obtain the encrypted target certificate, and storing the encrypted target certificate in the preset shared area includes:

[0256] Obtain target certificate information of the classified target certificate, and encrypt the target certificate information of the classified target certificate based on a preset algorithm to obtain a first secret key;

[0257] Selecting a random number of a preset length from the first secret key based on a random function to generate a second secret key;

[0258] Inserting the second key into the first key based on the first rule to obtain key data, and obfuscating the key data based on the second rule to obtain a target certificate key for the classified target certificate;

[0259] The classified target certificate is encrypted based on the target certificate secret key of the classified target certificate to obtain an encrypted target certificate, and the encrypted target certificate and the target certificate secret key are stored in a preset shared area.

[0260] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0261] The preset shared area includes a key storage area and a target certificate storage area. Storing the encrypted target certificate and target certificate key in the preset shared area includes:

[0262] Obtaining the type of the encrypted target certificate, obtaining a target certificate storage area corresponding to the type of the encrypted target certificate that matches the type of the target certificate pre-agreed between the baseboard management controller and the basic input / output system from a preset interaction protocol, and storing the encrypted certificate in the target certificate storage area;

[0263] Establish a correspondence between the target certificate storage area and the key storage area, and store the target certificate key in the key storage area.

[0264] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0265] Determine the target certificate from the preset shared area, and obtain the target certificate data table including:

[0266] Obtaining a target certificate key corresponding to the target certificate from a preset shared area, deobfuscating the target certificate key corresponding to the target certificate based on the second rule to obtain key data, and decrypting the key data based on the first rule to obtain verification data;

[0267] Obtain the first key and the second key, and determine whether the first key and the second key are consistent with the verification data;

[0268] If they are consistent, the data table of the target certificate is obtained from the preset shared area;

[0269] If they are inconsistent, an empty target certificate data table is returned.

[0270] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0271] Verify the target certificate based on the target certificate's data table. The verification results include:

[0272] Parse the data table of the target certificate to determine whether the target flag value corresponding to the first target flag type of the target certificate is a preset value;

[0273] If so, it is considered that there is a certificate imported into the server, and it is determined whether the target flag value corresponding to the second target flag type of the target certificate is a preset value;

[0274] If yes, the certificate imported into the server is considered to be the default certificate, and the target flag value corresponding to the third target flag type of the target certificate is determined to be a preset value;

[0275] If so, the default certificate imported into the server is considered to be effective, and the historical default certificate stored in the storage device is queried and the historical default certificate is deleted;

[0276] Obtain the default certificate imported into the server, store the default certificate imported into the server in a storage device, further determine whether the default certificate imported into the server is valid, and if so, consider the verification result to be successful, load the default certificate imported into the server, so that the default certificate imported into the server takes effect.

[0277] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0278] Determining whether the target flag bit value corresponding to the second target flag bit type of the target certificate is a preset value also includes:

[0279] If the target flag bit value corresponding to the second target flag bit type of the target certificate is a non-preset value, traverse the client certificates imported into the server to determine whether the client certificates include an advanced key certificate;

[0280] If included, determine whether the client certificate including the advanced key certificate is valid;

[0281] If invalid, re-import the certificate. The re-imported certificate includes the advanced key certificate, exchange key certificate, trusted signature database certificate, and non-trusted signature database certificate.

[0282] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0283] The method also includes:

[0284] In response to the completion of re-importing the certificate, determining whether a target flag bit value corresponding to a fourth target flag bit type of the target certificate is less than or equal to a preset threshold;

[0285] If yes, it is considered that the number of client certificates imported into the server meets the requirement, and further determines whether the target flag value corresponding to the fifth target flag type of the target certificate is a preset value;

[0286] If so, it is considered that the server has completed importing the certificate. In response to the server completing importing the certificate, the verification result is determined to be successful.

[0287] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0288] The method also includes:

[0289] Calculate a first hash value of the target certificate that is not imported into the server and a second hash value of the target certificate that is imported into the server;

[0290] Determine whether the first hash value and the second hash value are consistent;

[0291] If they are consistent, the data table of the target certificate is obtained;

[0292] If they are inconsistent, the target certificate imported into the server is deleted, and the target certificate is re-imported into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller.

[0293] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0294] The method further includes obtaining a server signature certificate, and obtaining the server signature certificate includes:

[0295] Generate a key pair based on a random function;

[0296] Generate target data set based on identity encryption algorithm, key pair, server information and client information;

[0297] The target dataset is sent to a certificate issuing authority, which builds a server-signed certificate based on the target dataset.

[0298] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0299] The method also includes:

[0300] Obtain the server signature certificate information, and calculate the server summary information using the digest algorithm and the server signature certificate information;

[0301] Encode the server summary information to obtain a server identifier, where the server identifier is a string consisting of the server summary code and a preset symbol;

[0302] Obtain the server unique identification code, calculate the similarity between the server unique identification code and the server identification, obtain a similarity value, and verify the server signature certificate information based on the server similarity value.

[0303] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0304] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0305] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the scope of the present application, and such modifications and improvements are all within the scope of protection of the present application.

Claims

1. A certificate management method, characterized in that: include: Importing the target certificate into the server based on a preset interface, where the preset interface is an interface supported by the baseboard management controller; The target certificate includes a default certificate and a client certificate, wherein the default certificate is used to load a verified operating system and software during a secure boot process of the server, and the client certificate is used to verify the user identity during a secure boot process of the server; Classifying the target certificate based on a preset interaction protocol to obtain a classified target certificate; Encrypting the classified target certificate to obtain an encrypted target certificate, and storing the encrypted target certificate in a preset shared area; Verifying the target certificate stored in the preset shared area based on a data table of the target certificate to obtain a verification result, wherein the data table of the target certificate includes a correspondence between a target flag bit type, a target flag bit value, and a verification status; In response to the verification result being a successful verification, restarting the server to make the target certificate effective; The target certificate is verified based on the data table of the target certificate, and the verification result obtained includes: Determine whether the target flag bit value corresponding to the second target flag bit type of the target certificate is a preset value; If the target flag bit value corresponding to the second target flag bit type of the target certificate is a non-preset value, traverse the client certificates imported into the server to determine whether the client certificates include an advanced key certificate; If included, determine whether the client certificate including the advanced key certificate is valid; If invalid, re-import the certificate, which includes the advanced key certificate, exchange key certificate, trusted signature database certificate and untrusted signature database certificate; In response to the completion of re-importing the certificate, it is verified whether the number of imported client certificates meets the requirement and whether the target certificate is in the import completion state.

2. The method according to claim 1, characterized in that Before importing the target certificate into the server based on the preset interface, the method further includes: The preset interface receives the server signature certificate information and the target identification code, where the target identification code is an identification code of an import instruction corresponding to importing the target certificate into the server based on the preset interface; Perform authentication based on the server signature certificate information and the target identification code to obtain an authentication result; If the authentication result is authentication passed, the target certificate is imported into the server based on the preset interface.

3. The method according to claim 1, characterized in that The target certificates are classified based on the preset interaction protocol, and the classified target certificates include: Acquire a preset interaction protocol, wherein the preset interaction protocol includes an address of a preset shared area corresponding to a type of a target certificate pre-agreed between the baseboard management controller and the basic input / output system; The target certificates are classified based on the type of the target certificates pre-agreed between the baseboard management controller and the basic input / output system to obtain the classified target certificates.

4. The method according to claim 1, wherein Encrypting the classified target certificate to obtain an encrypted target certificate, and storing the encrypted target certificate in a preset shared area includes: Obtain target certificate information of the classified target certificate, and encrypt the target certificate information of the classified target certificate based on a preset algorithm to obtain a first secret key; Selecting a random number of a preset length from the first key based on a random function to generate a second key; Inserting the second key into the first key based on the first rule to obtain key data, and obfuscating the key data based on the second rule to obtain a target certificate key for the classified target certificate; The classified target certificates are encrypted based on the target certificate secret key of the classified target certificates to obtain an encrypted target certificate, and the encrypted target certificate and the target certificate secret key are stored in a preset shared area.

5. The method according to claim 4, characterized in that The preset shared area includes a key storage area and a target certificate storage area, and storing the encrypted target certificate and the target certificate key in the preset shared area includes: Obtaining the type of the encrypted target certificate, obtaining a target certificate storage area corresponding to the type of the encrypted target certificate that matches the type of the target certificate pre-agreed between the baseboard management controller and the basic input / output system from a preset interaction protocol, and storing the encrypted certificate in the target certificate storage area; A correspondence between a target certificate storage area and a key storage area is established, and the target certificate key is stored in the key storage area.

6. The method according to claim 1, characterized in that Determining a target certificate from the preset shared area and obtaining a data table of the target certificate includes: Obtaining a target certificate key corresponding to the target certificate from a preset shared area, deobfuscating the target certificate key corresponding to the target certificate based on the second rule to obtain key data, and decrypting the key data based on the first rule to obtain verification data; Obtaining a first key and a second key, and determining whether the first key and the second key are consistent with the verification data; If they are consistent, the data table of the target certificate is obtained from the preset shared area; If they are inconsistent, an empty target certificate data table is returned.

7. The method according to claim 1, characterized in that The target certificate is verified based on the data table of the target certificate, and the verification result obtained includes: Parse the data table of the target certificate to determine whether the target flag value corresponding to the first target flag type of the target certificate is a preset value; If so, it is considered that a certificate has been imported into the server, and it is determined whether the target flag value corresponding to the second target flag type of the target certificate is a preset value; If yes, the certificate imported into the server is considered to be a default certificate, and the target flag value corresponding to the third target flag type of the target certificate is determined to be a preset value; If so, the default certificate imported into the server is deemed to be effective, and the historical default certificate stored in the storage device is queried and the historical default certificate is deleted; Obtain the default certificate imported into the server, store the default certificate imported into the server in a storage device, further determine whether the default certificate imported into the server is valid, and if so, consider the verification result to be successful, load the default certificate imported into the server, so that the default certificate imported into the server takes effect.

8. The method according to claim 1, characterized in that In response to the completion of re-importing the certificate, verifying whether the number of imported client certificates meets the requirement and verifying whether the target certificate is in the import completion state includes: In response to the completion of re-importing the certificate, determining whether a target flag bit value corresponding to a fourth target flag bit type of the target certificate is less than or equal to a preset threshold; If yes, it is considered that the number of client certificates imported into the server meets the requirement, and further determines whether the target flag value corresponding to the fifth target flag type of the target certificate is a preset value; If so, it is considered that the server has completed importing the certificate. In response to the completion of importing the certificate, the verification result is determined to be successful.

9. The method according to claim 1, characterized in that The method further comprises: Calculate a first hash value of the target certificate that is not imported into the server and a second hash value of the target certificate that is imported into the server; Determine whether the first hash value and the second hash value are consistent; If they are consistent, the data table of the target certificate is obtained; If they are inconsistent, the target certificate imported into the server is deleted, and the target certificate is re-imported into the server based on the preset interface.

10. The method according to claim 2, characterized in that The method further includes obtaining a server signature certificate, wherein obtaining the server signature certificate includes: Generate a key pair based on a random function; Generate target data set based on identity encryption algorithm, key pair, server information and client information; The target dataset is sent to a certificate issuing authority, which constructs a server-signed certificate based on the target dataset.

11. The method according to claim 10, characterized in that The method further comprises: Obtain the server signature certificate information, and calculate the server summary information using the digest algorithm and the server signature certificate information; Encoding the server summary information to obtain a server identifier, where the server identifier is a character string consisting of a server summary code and preset symbols; The server unique identification code is obtained, the similarity between the server unique identification code and the server identification is calculated to obtain a similarity value, and the server signature certificate information is verified based on the server similarity value.

12. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.

13. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 11 are implemented.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.

Citation Information

Patent Citations

  • Certificate management system and method for POS terminal based on domestic operating system

    CN115484074A

  • Security authentication method and device, computer equipment and storage medium

    CN118473677A