A software installation package signature method and system based on digital certificate status check
By introducing digital certificate status checking and encryption processing into the software installation package signature, digital envelopes are generated, and the problem that the prior art cannot achieve strict control of the software release process of specific organizations, personnel and terminals is achieved, and software installation package signature and verification with high security and reliability are achieved.
Patent Information
- Application Number
- CN202411827240.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-12
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2044-12-12
AI Technical Summary
The prior art cannot achieve strict control over the software release process of specific organizations, personnel and terminals, cannot provide targeted installation and deployment services, and cannot verify the valid status of the certificate in a timely manner when offline.
By obtaining the fingerprint and digital certificate of the user terminal device, as well as the digital certificate of the organization, digital signature and encryption processing are performed, digital envelopes are generated, and they are encapsulated into the software installation and release package together with the software installation package signature data, achieving strict status checks and verifications.
Enhanced the security and reliability of code signing and verification, implement strict control over the entire process of software package installation for specific organizations, personnel and terminals, simplifies the code signing verification process, and is suitable for offline environments.
Smart Images

Figure CN119299110B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of software signature verification, and in particular to a software installation package signing method and system based on digital certificate status checking. Background Art
[0002] Software installation package code signing is an important technical means to ensure the credibility and security of software. By implementing code signing, the identity of the software developer can be verified and it can be ensured that the software has not been tampered with or damaged during transmission or storage.
[0003] The keys and certificates used for code signing of software installation packages are kept by the software developers themselves. During the software release phase, the developers will sign the software and send the signed software package and related signature information to the recipient. In order to ensure the security of code signing, developers need to properly manage their signing keys. Once a key is discovered to be leaked or lost, it should be reported to the certificate authority immediately so that the key can be revoked in a timely manner to prevent others from using stolen keys to impersonate the developer and release malware. In this case, when signing the code, it is necessary to declare to the software recipient that its code signing certificate has not been revoked by the certificate authority at the time of the signing operation and is valid. However, the above conventional means can only ensure that the software package is not tampered with. No matter which link it flows to, any changes to the software package will be discovered by the system. However, in actual practice, the following problems still exist:
[0004] First, it is impossible to provide a strictly controlled software release process for a certain organization (such as an enterprise or unit), and it is impossible to provide targeted installation and deployment services (such as software packages released only for a certain organization).
[0005] Second, it is impossible to provide a strictly controllable software release process for a certain installation and deployment executor (such as an important system administrator), and it is impossible to provide targeted installation and deployment services.
[0006] Third, it is impossible to release targeted and independently used software installation packages for a certain (or certain) fixed terminals, and it is impossible to avoid the security risks brought by copying operations between different terminals.
[0007] Fourth, in an offline state, the software recipient may not be able to obtain the validity status of the certificate in a timely manner.
[0008] Therefore, the above problems must be solved by enhancing the code signing and verification mechanism as well as the security of the system to meet the targeted installation and deployment service requirements of software publishers and users. Summary of the invention
[0009] Based on the above background, the present invention provides a software installation package signing method and system based on digital certificate status check, aiming to optimize the code signing process, implement strict status check, and improve the security and reliability of code signing. The following technical solutions are specifically adopted:
[0010] The first aspect of the present invention provides a software installation package signing method based on digital certificate status checking, comprising:
[0011] Obtain the fingerprint of the user terminal device that initiated the software installation package code signing request, the user's digital certificate, and the organization digital certificate of the organization to which the user belongs;
[0012] Obtain the original data of the software installation package to be signed, and add the user terminal device fingerprint, timestamp and CRL file to perform digital signing to obtain the software installation package signature data;
[0013] Using the public key in the user digital certificate to encrypt the original data of the software installation package to obtain digital envelope 1, and using the public key in the organization digital certificate to encrypt digital envelope 1 for a second time to obtain digital envelope 2;
[0014] The digital envelope 2 and the software installation package signature data are encapsulated into a software installation release package.
[0015] Furthermore, the step of encapsulating the digital envelope 2 together with the software installation package signature data into the software installation release package further includes:
[0016] The trust chain, status query information and timestamp are encapsulated into a software installation release package together with the digital envelope 2 and the software installation package signature data.
[0017] Furthermore, the step of encapsulating the digital envelope 2 together with the software installation package signature data into the software installation release package further includes:
[0018] Package some or all of the basic data, description information, algorithm information, and verifiable certificate information of the software installation package into the software installation release package.
[0019] Furthermore, the software installation package signing method also includes:
[0020] A pre-service for publishing the software installation release package to the target organization;
[0021] The front-end service unseals the received software installation release package, decrypts the digital envelope 2 based on the private key corresponding to the public key in the digital certificate of the organization, obtains the digital envelope 1, and forwards the digital envelope 1 and the software installation package signature data to the target user terminal;
[0022] The target user terminal decrypts the digital envelope 1 based on the private key corresponding to the public key in the user digital certificate, obtains the original data of the software installation package, and verifies the validity of the signature data of the software installation package based on the user terminal device fingerprint.
[0023] Furthermore, the verification of the validity of the signature data of the software installation package based on the fingerprint of the user terminal device includes:
[0024] Performing a first signature verification operation on the signature data of the software installation package based on the digital certificate provided by the software publisher to obtain operation result 1;
[0025] Perform a second signature verification operation based on the acquired original data of the software installation package and the locally collected fingerprint of the user terminal device to obtain a second operation result;
[0026] If the operation result one and the operation result two are equal, the verification passes.
[0027] Furthermore, the verification of the validity of the signature data of the software installation package based on the fingerprint of the user terminal device also includes:
[0028] The front-end service unpacks the received software installation release package to obtain the trust chain, status query information and timestamp, and forwards it to the target user terminal;
[0029] The target user terminal verifies the validity of the signature data of the software installation package based on the obtained trust chain, status query information and timestamp.
[0030] Further, the validity verification of the software installation package signature data based on the obtained trust chain and status query information and timestamp includes:
[0031] Obtain the CRL file based on the trust chain and status query information, and check whether the timestamp is within the validity period of the CRL, which includes thisUpdate and nextUpdate in the CRL file;
[0032] Check if the current time when verification is performed is between the timestamp and nextUpdate;
[0033] If the timestamp is within the validity period of the CRL and the current time is between the timestamp and nextUpdate, the verification passes.
[0034] Furthermore, the verification of the validity of the signature data of the software installation package based on the fingerprint of the user terminal device also includes:
[0035] The front-end service decrypts the received software installation release package to obtain some or all of the basic data, description information, algorithm information, and verifiable certificate information of the software installation package, and forwards it to the target user terminal;
[0036] The target user terminal verifies the validity of the signature data of the software installation package based on some or all of the acquired basic data, description information, algorithm information, and verifiable certificate information of the software installation package.
[0037] A second aspect of the present invention provides a software installation package signing system based on digital certificate status check, which is used to execute the method described in the first aspect, including:
[0038] A code signature generation system, which is configured on the software development side and is configured with a first cryptographic module, is used to generate a software installation release package and publish it to the front-end service of the target organization;
[0039] The front-end service of the target organization is configured with a second cryptographic module for decrypting the digital envelope 2 in the software installation release package to obtain the digital envelope 1 and the signature data of the software installation package, and forwarding the digital envelope 1 and the signature data of the software installation package to the target user terminal;
[0040] The code signature verification system is configured in a user terminal and is equipped with a third cryptographic module for decrypting a digital envelope, obtaining software installation package signature data, and verifying the validity of the software installation package signature data based on the user terminal device fingerprint.
[0041] Furthermore, the code signature generation system is also used to encapsulate the trust chain, status query information and timestamp together with the digital envelope 2 and the software installation package signature data to generate a software installation release package;
[0042] The code signature verification system is also used to verify the validity of the software installation package signature data based on the obtained trust chain and status query information and timestamp.
[0043] The beneficial effects of the present invention include:
[0044] 1) The solution of the present invention can enhance the security of code signing and verification, and can achieve strict control over the entire process of software package installation protection for specific organizations, specific operators, specific terminals, and within a specific time.
[0045] 2) The solution of the present invention embeds the status information of the certificate at the time of code signing in the software installation release package, so that the software recipient can easily verify the source and integrity of the software through this information.
[0046] 3) With the solution of the present invention, the software recipient does not need to go to the certificate authority in person to query the certificate status information. This process simplifies the code signature verification process and enhances the applicability of code signature verification, and can also operate efficiently in an offline stand-alone environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 The process diagram of the software installation package signing method embodiment of the present invention is as follows Figure 1 .
[0048] Figure 2 The figure is a schematic diagram of the composition of a software installation release package in an embodiment of the software installation package signing method of the present invention.
[0049] Figure 3 The process diagram of the software installation package signing method embodiment of the present invention is as follows Figure 2 .
[0050] Figure 4 The figure is a schematic diagram of the composition of an embodiment of a software installation package signature system of the present invention. DETAILED DESCRIPTION
[0051] Embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not intended to limit the scope of protection of the present invention.
[0052] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art of the present invention. The terms used herein in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "or / and" used herein includes any and all combinations of one or more related listed items.
[0053] See also Figure 1 The first embodiment of the present invention shows a software installation package signing method based on digital certificate status check, comprising the following steps:
[0054] S1. Obtain the fingerprint of the user terminal device that initiates the software installation package code signing request, the user digital certificate, and the organizational digital certificate of the organization to which the user belongs.
[0055] Specifically, the user terminal device fingerprint, user digital certificate and organizational digital certificate of the user's organization can be provided by the user terminal that initiates the software installation package code signing request to the software developer for the subsequent signature verification process. The use of the user terminal device fingerprint and user digital certificate can ensure that the subsequent software package installation operation is performed by a specific person on a specific device, and the organizational digital certificate can ensure that the subsequent software package installation is performed in a specific organization (such as an enterprise or unit), thereby strengthening the security protection means for the signature installation of the software package.
[0056] S2. Obtain the original data of the software installation package to be signed, and add the user terminal device fingerprint, timestamp and CRL file to perform digital signature to obtain the software installation package signature data.
[0057] Specifically, the software publisher may perform a digital signature based on its own digital certificate, and provide the digital certificate to the user terminal for subsequent verification operations.
[0058] S3. Use the public key in the user's digital certificate to encrypt the original data of the software installation package to obtain digital envelope one, and use the public key in the organization's digital certificate to encrypt digital envelope one for a second time to obtain digital envelope two.
[0059] Preferably, the above-mentioned digital envelope complies with the digital envelope data type in Part 9 of "GMT 0010-2012 SM2 Cryptographic Algorithm Encrypted Signature Message Syntax Specification".
[0060] S4. Encapsulate the digital envelope 2 together with the software installation package signature data into the software installation release package.
[0061] As a further preferred embodiment, step S4 further includes:
[0062] The trust chain and status query information as well as the timestamp are encapsulated into the software installation release package together with the digital envelope 2 and the software installation package signature data.
[0063] The trust chain and status query information include the CRL publishing point address and the CRL file obtained at the code signing time.
[0064] The timestamp is used to record the time when the signature was generated and the time when the software was released or updated, which is very important for tracking the historical versions of the software and verifying its timeliness. Preferably, the timestamp complies with the "GB / T 20520-2006 Information Security Technology Public Key Infrastructure Timestamp Specification".
[0065] As a further preferred embodiment, step S4 further includes:
[0066] Package some or all of the basic data, description information, algorithm information, and verifiable certificate information of the software installation package into the software installation release package.
[0067] Among them, the basic data of the software installation package provides information such as the version, file type, and size of the software installation package.
[0068] The description information provides functional description information of the software installation package, environmental information, and metadata containing developer comments, specific configuration data, or other additional information that provides users with additional context about the software.
[0069] The algorithm information includes the signature algorithm and hash algorithm used, which ensure the security and non-tamperability of the signature. Preferably, the signature algorithm complies with "GMT 0003.1-2012 SM2 Elliptic Curve Public Key Cryptography Algorithm"; the hash algorithm complies with "GMT 0004-2012 SM3 Cryptographic Hash Algorithm".
[0070] The verifiable certificate information includes the issuing authority of the personal certificate, the digital certificate of the organization, the certificate serial number, the certificate validity period, the certificate holder's information (such as the organization name, personal name, etc.), the public key used for signing, etc., which is used to verify the identity of the signer. Preferably, the digital certificate complies with the "GMT 0015-2012 Digital Certificate Format Specification Based on SM2 Cryptographic Algorithm".
[0071] The above information can be used in the subsequent signature verification process. The specific usage can be determined according to actual needs and is not specifically limited here.
[0072] As a preferred implementation scheme, in this embodiment, the complete software installation release package consists of the following: Figure 2 shown.
[0073] See also Figure 3 The software installation package signing method in this embodiment also includes a verification process, which specifically includes:
[0074] S5. Pre-service for publishing the software installation release package to the target organization.
[0075] S6. The front-end service unseals the received software installation release package, decrypts digital envelope 2 based on the private key corresponding to the public key in the organization's digital certificate, obtains digital envelope 1, and forwards digital envelope 1 and the software installation package signature data to the target user terminal.
[0076] S7. The target user terminal decrypts the digital envelope 1 based on the private key corresponding to the public key in the user digital certificate, obtains the original data of the software installation package, and verifies the validity of the signature data of the software installation package based on the user terminal device fingerprint.
[0077] As a preferred implementation scheme, in step S7, verifying the validity of the signature data of the software installation package based on the fingerprint of the user terminal device includes:
[0078] Performing a first signature verification operation on the signature data of the software installation package based on the digital certificate provided by the software publisher to obtain operation result 1;
[0079] Perform a second signature verification operation based on the acquired original data of the software installation package and the locally collected fingerprint of the user terminal device to obtain a second operation result;
[0080] If the operation result 1 is equal to the operation result 2, the verification is judged to be passed. If the verification fails, the verification is stopped and a verification failure message is given.
[0081] As a further preferred implementation scheme, in step S7, verifying the validity of the software installation package signature data based on the user terminal device fingerprint further includes:
[0082] The front-end service unpacks the received software installation release package to obtain the trust chain, status query information and timestamp, and forwards it to the target user terminal;
[0083] The target user terminal verifies the validity of the software installation package signature data based on the obtained trust chain, status query information and timestamp.
[0084] As a preferred embodiment, the above validity verification includes:
[0085] Obtain the CRL file based on the trust chain and status query information, and check whether the timestamp is within the validity period of the CRL, which includes thisUpdate and nextUpdate in the CRL file;
[0086] Check if the current time when verification is performed is between the timestamp and nextUpdate;
[0087] If the timestamp is within the validity period of the CRL and the current time is between the timestamp and nextUpdate, the verification passes.
[0088] As a further preferred implementation scheme, in step S7, verifying the validity of the software installation package signature data based on the user terminal device fingerprint further includes:
[0089] The front-end service decrypts the received software installation release package to obtain some or all of the basic data, description information, algorithm information, and verifiable certificate information of the software installation package, and forwards it to the target user terminal;
[0090] The target user terminal verifies the validity of the signature data of the software installation package based on some or all of the basic data, description information, algorithm information, and verifiable certificate information of the software installation package. The specific verification method can be determined according to actual needs and is not specifically limited here.
[0091] See also Figure 4 The second embodiment of the present invention shows a software installation package signing system based on digital certificate status check, which is used to execute the software installation package signing method shown in the first embodiment above, and includes:
[0092] A code signature generation system, which is configured on the software development side and is configured with a first cryptographic module, is used to generate a software installation release package and publish it to the front-end service of the target organization;
[0093] The front-end service of the target organization is configured with a second cryptographic module for decrypting the digital envelope 2 in the software installation release package to obtain the digital envelope 1 and the signature data of the software installation package, and forwarding the digital envelope 1 and the signature data of the software installation package to the target user terminal;
[0094] The code signature verification system is configured in a user terminal and is equipped with a third cryptographic module for decrypting a digital envelope, obtaining software installation package signature data, and verifying the validity of the software installation package signature data based on the user terminal device fingerprint.
[0095] As a further preferred implementation scheme, the code signature generation system in this embodiment is also used to encapsulate the trust chain and status query information and the timestamp together with the digital envelope 2 and the software installation package signature data to generate a software installation release package;
[0096] Correspondingly, the code signature verification system is also used to verify the validity of the software installation package signature data based on the obtained trust chain and status query information and timestamp.
[0097] The specific functional implementation of the software installation package signature system of this embodiment can refer to the method shown in the above embodiment, which will not be described in detail here.
[0098] It should be noted that the method of the embodiment of the present invention can be performed by a single device, such as a computer or a server. The method of this embodiment can also be applied in a distributed scenario and completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only perform one or more steps in the method of the embodiment of the present invention, and the multiple devices will interact with each other to complete the described method.
[0099] The embodiments of the present invention are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present invention should be included in the protection scope of the present invention.
Claims
1. A software installation package signing method based on digital certificate status check, characterized in that: include: Obtain the fingerprint of the user terminal device that initiated the software installation package code signing request, the user's digital certificate, and the organization digital certificate of the organization to which the user belongs; Obtain the original data of the software installation package to be signed, and add the user terminal device fingerprint, timestamp and CRL file to perform digital signing to obtain the software installation package signature data; Using the public key in the user digital certificate to encrypt the original data of the software installation package to obtain digital envelope 1, and using the public key in the organization digital certificate to encrypt digital envelope 1 for a second time to obtain digital envelope 2; The digital envelope 2 and the software installation package signature data are encapsulated into a software installation release package.
2. The software installation package signing method based on digital certificate status check according to claim 1, characterized in that: The step of encapsulating the digital envelope 2 together with the software installation package signature data into the software installation release package further includes: The trust chain, status query information and timestamp are encapsulated into a software installation release package together with the digital envelope 2 and the software installation package signature data.
3. The software installation package signing method based on digital certificate status check according to claim 2, characterized in that: The step of encapsulating the digital envelope 2 together with the software installation package signature data into the software installation release package further includes: Package some or all of the basic data, description information, algorithm information, and verifiable certificate information of the software installation package into the software installation release package.
4. The software installation package signing method based on digital certificate status check according to any one of claims 1 to 3, characterized in that: Also includes: A pre-service for publishing the software installation release package to the target organization; The front-end service unseals the received software installation release package, decrypts the digital envelope 2 based on the private key corresponding to the public key in the digital certificate of the organization, obtains the digital envelope 1, and forwards the digital envelope 1 and the software installation package signature data to the target user terminal; The target user terminal decrypts the digital envelope 1 based on the private key corresponding to the public key in the user digital certificate, obtains the original data of the software installation package, and verifies the validity of the signature data of the software installation package based on the user terminal device fingerprint.
5. The software installation package signing method based on digital certificate status check according to claim 4, characterized in that: The verification of the validity of the signature data of the software installation package based on the fingerprint of the user terminal device includes: Performing a first signature verification operation on the signature data of the software installation package based on the digital certificate provided by the software publisher to obtain operation result 1; Perform a second signature verification operation based on the acquired original data of the software installation package and the locally collected fingerprint of the user terminal device to obtain a second operation result; If the operation result one and the operation result two are equal, the verification passes.
6. The software installation package signing method based on digital certificate status check according to claim 5, characterized in that: The verification of the validity of the signature data of the software installation package based on the fingerprint of the user terminal device also includes: The front-end service unpacks the received software installation release package to obtain the trust chain, status query information and timestamp, and forwards it to the target user terminal; The target user terminal verifies the validity of the signature data of the software installation package based on the obtained trust chain, status query information and timestamp.
7. The software installation package signing method based on digital certificate status check according to claim 6, characterized in that: The verification of the validity of the software installation package signature data based on the obtained trust chain, status query information and timestamp includes: Obtain the CRL file based on the trust chain and status query information, and check whether the timestamp is within the validity period of the CRL, which includes thisUpdate and nextUpdate in the CRL file; Check if the current time when verification is performed is between the timestamp and nextUpdate; If the timestamp is within the validity period of the CRL and the current time is between the timestamp and nextUpdate, the verification passes.
8. The software installation package signing method based on digital certificate status check according to claim 6 or 7, characterized in that: The verification of the validity of the signature data of the software installation package based on the fingerprint of the user terminal device also includes: The front-end service decrypts the received software installation release package to obtain some or all of the basic data, description information, algorithm information, and verifiable certificate information of the software installation package, and forwards it to the target user terminal; The target user terminal verifies the validity of the signature data of the software installation package based on some or all of the acquired basic data, description information, algorithm information, and verifiable certificate information of the software installation package.
9. A software installation package signature system based on digital certificate status check, used to execute the method according to any one of claims 1 to 8, characterized in that: include: A code signature generation system, which is configured on the software development side and is configured with a first cryptographic module, is used to generate a software installation release package and publish it to the front-end service of the target organization; The front-end service of the target organization is configured with a second cryptographic module for decrypting the digital envelope 2 in the software installation release package to obtain the digital envelope 1 and the signature data of the software installation package, and forwarding the digital envelope 1 and the signature data of the software installation package to the target user terminal; The code signature verification system is configured in a user terminal and is equipped with a third cryptographic module for decrypting a digital envelope, obtaining software installation package signature data, and verifying the validity of the software installation package signature data based on the user terminal device fingerprint.
10. The software installation package signature system based on digital certificate status check according to claim 9, characterized in that: The code signature generation system is also used to encapsulate the trust chain, status query information and timestamp together with the digital envelope 2 and the software installation package signature data to generate a software installation release package; The code signature verification system is also used to verify the validity of the software installation package signature data based on the obtained trust chain and status query information and timestamp.
Citation Information
Patent Citations
Digital signing method and system, application server and cloud cipher server
CN103490892A
WebService security certification access control method based on software digital certificate and timestamp
CN104753881A