Mobile Information Security Protection Method and System Using Digital Certificates

By analyzing user characteristic information and the processing capabilities of mobile terminal devices, and generating private key parameters suitable for mobile devices, the problems of uncorrelation and insufficient randomness of private key generation in traditional ECDSA algorithms are solved, and the security of digital certificates and the information security protection capabilities of mobile devices are improved.

CN119788294BActive Publication Date: 2025-06-24HENAN INFORMATIZATION GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510258920.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-24
Estimated Expiration
2045-03-06

AI Technical Summary

Technical Problem

In traditional ECDSA algorithm, the generation of private keys has nothing to do with the information to be encrypted. The randomness of the random number generator may be insufficient, which may lead to the predictability and derivability of the private key, reducing encryption security. At the same time, when the private key parameters are large, it may not be suitable for encryption and decryption of mobile devices, affecting the normal operation of the device.

Method used

By collecting user's characteristic information, including user name information, the number and processing capabilities of mobile terminal devices, the request and failure time of digital certificates, etc., the certificate requirement degree and user name complexity index are calculated, combined with the correction value of the device terminal, private key parameters are generated to ensure that the private key information contains random features and user identity features.

Benefits of technology

It improves the complexity of private keys, enhances the non-forgery of digital certificates, adapts to the processing capabilities of mobile devices, and improves the ability of mobile information security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788294B_ABST
    Figure CN119788294B_ABST
Patent Text Reader

Abstract

This application relates to the field of information security technology, and specifically relates to a mobile information security protection method and system using digital certificates. The method includes: collecting the user name information when each digital certificate request is initiated by each user, the total number and processing capacity score of all the user's mobile terminal devices, the certificate request time and certificate expiration time of the digital certificate, and the total number of all digital certificate requests initiated; obtaining the certificate requirement degree of each user; and then obtaining the private key evaluation degree of each user; calculating the device terminal correction value of each mobile terminal device of each user; and then obtaining the private key adjustment factor of each mobile terminal device of each user, and obtaining the private key parameters when each digital certificate request is initiated by each mobile terminal device of each user. This application improves the information security protection ability of mobile terminals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and particularly to a mobile information security protection method and system using digital certificates. Background Art

[0002] Mobile information security protection refers to a series of technologies and measures used to protect mobile devices and information activities (such as data transmission, application usage, etc.) carried out through these devices. Among them, the identity information of mobile network users is mainly authenticated through digital certificates. When issuing digital certificates, digital signatures need to be performed on the digital certificates. To verify the integrity and authenticity of the certificate content, a technical means is usually adopted to use an asymmetric encryption algorithm to sign the digital certificate.

[0003] The Elliptic Curve Digital Signature Algorithm (ECDSA) is a type of asymmetric encryption algorithm, which has the advantages of fast signature and verification speed. Therefore, it is often used to sign digital certificates. Generally speaking, the ECDSA algorithm generates a random number that meets certain conditions through a certain random function as the private key of the encryption algorithm, and generates a public key based on the elliptic curve, thereby realizing the signature of the digital certificate. In the traditional ECDSA algorithm, the generation of the private key has nothing to do with the information to be encrypted, and is only generated through a random function. In a computer, random numbers are generated based on certain random rules, which is a pseudo-random process. If the random seed of the random number generator is not random enough or the random number generator is cracked, it may lead to the predictability and derivability of the user's private key, thereby reducing the security of encryption. In addition, if the random private key parameter is large, it may not be suitable for the encryption and decryption of mobile data terminals, which is likely to cause a slow processing speed and affect the normal operation of the device. Therefore, in view of the above problems, this solution proposes a mobile information security protection method and system using digital certificates. Summary of the Invention

[0004] In order to solve the above technical problems, the purpose of this application is to provide a mobile information security protection method and system using digital certificates. The specific technical solutions adopted are as follows:

[0005] In the first aspect, an embodiment of this application provides a mobile information security protection method using digital certificates. The method includes the following steps:

[0006] Collect the user name information when each user initiates each digital certificate request, the total number and processing capacity score of all the user's mobile terminal devices, the certificate request time and certificate expiration time of the digital certificate, and the total number of all digital certificate requests initiated.

[0007] Based on the average of the number of digital certificate requests initiated by the user, the time interval between the certificate expiration time and the certificate request time, obtain the certificate demand degree of each user.

[0008] Encode the user name information, form a user name complexity evaluation sequence based on the differences between adjacent encodings, and obtain the user name complexity index through the information entropy of the user name complexity evaluation sequence; use the ratio of the certificate requirement degree to the user name complexity index as the private key evaluation degree for each user.

[0009] Obtain the device terminal correction value of each mobile terminal device of each user based on the total number and processing capacity score of all mobile terminal devices of the user.

[0010] Sum the private key evaluation degree and the device terminal correction value, and take the remainder of the sum value with respect to the preset bit character length as the private key adjustment factor for each mobile terminal device of each user.

[0011] Use a random number generation algorithm to generate a random number, and obtain the private key parameter when each digital certificate request is initiated by each mobile terminal device of each user through the exclusive OR operation of the binary number of the private key adjustment factor and the binary number of the random number.

[0012] Furthermore, the method for obtaining the certificate requirement degree is as follows:

[0013] Obtain the average demand time interval for each user based on the average situation of the time interval between the certificate request time when each digital certificate request is made and the certificate expiration time of the previous digital certificate request.

[0014] For each user, calculate the sum value of the average demand time interval and the preset tuning parameter, and use the ratio of the total number of all digital certificate requests initiated to the sum value as the certificate requirement degree for each user.

[0015] Furthermore, the method for obtaining the average demand time interval is as follows:

[0016] For each digital certificate request initiated by each user, calculate the time interval between the certificate request time of each digital certificate and the certificate expiration time of the previous digital certificate request as the demand time interval for each digital certificate request initiated by each user, and use the mean value of the demand time intervals of all digital certificate requests initiated by each user as the average demand time interval for each user.

[0017] Furthermore, the method for obtaining the private key evaluation degree is as follows:

[0018] Obtain the user name complexity evaluation sequence for each user based on the user name information.

[0019] Obtain the user name complexity index for each user based on the information uncertainty of the user name complexity evaluation sequence.

[0020] Use the ratio of the certificate requirement degree to the user name complexity index for each user as the private key evaluation degree for each user.

[0021] Furthermore, the method for obtaining the user name complexity evaluation sequence is as follows:

[0022] Convert the user name information of each user into ASCII code values, and use the sequence composed of the absolute values of the differences between all adjacent two numerical values in the ASCII code values as the user name complexity evaluation sequence of each user.

[0023] Furthermore, the calculation formula for the user name complexity index is as follows: ; where B represents the user name complexity index of each user, represents the user name complexity evaluation sequence of each user, represents calculating the information entropy, represents the logarithmic function with the natural constant as the true number.

[0024] Furthermore, the calculation formula for the device terminal correction value is as follows: ; where C represents the device terminal correction value of each mobile terminal device of each user; represents the logarithmic function with the numerical value 2 as the true number, M represents the total number of all mobile terminal devices of each user, represents the normalized value of the processing capacity score of each mobile terminal device of each user.

[0025] Furthermore, the method for obtaining the private key adjustment factor is as follows:

[0026] For each mobile terminal device of each user, calculate the sum result of the private key evaluation degree of each user and the device terminal correction value of each mobile terminal device of each user, and calculate the remainder of the quotient of the sum result divided by the preset bit character length as the private key adjustment factor of each mobile terminal device of each user.

[0027] Furthermore, the method for obtaining the private key parameter is as follows:

[0028] Use the random number generation algorithm to obtain the random numbers when each user initiates each digital certificate request, and perform an exclusive OR operation on the binary numbers of the private key adjustment factors of each mobile terminal device of each user and the binary numbers of the random numbers to obtain the private key parameters when each mobile terminal device of each user initiates each digital certificate request.

[0029] In a second aspect, an embodiment of the present application further provides a mobile information security protection system using digital certificates, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the steps of the method described in any one of the above are implemented.

[0030] The present application has at least the following beneficial effects:

[0031] This application obtains the user's characteristic information through the request information of the user's digital certificate. Analyze the user information of the user characteristics, and analyze based on the user's application frequency and user parameter complexity to obtain the private key evaluation degree, which reflects the complexity of the signature private key required by each user in communication transmission. At the same time, combine the processing capabilities and the number of terminal devices of each user's device terminal to obtain the device terminal correction value of the user, which reflects the influence of the device terminal processing capability on the complexity of the signature private key. Thus, the private key correction factor is obtained, and the private key parameter is obtained by combining the original random parameters. Finally, combine the private key parameters to implement the signature and issuance of the user's digital certificate, and verify and identify the user's identity based on the digital certificate during the user's communication process. It solves the problem that when signing traditional digital certificates, the private key parameters are pseudo-randomly generated and the processing capabilities of mobile device terminals for encryption and decryption are not considered. This application analyzes the user characteristics and finally generates private key parameters, so that the private key information not only contains random characteristics, but also contains the user's identity characteristic information, improving the complexity of the private key, thereby ensuring the non-forgery of the digital certificate and improving the information security protection ability of the mobile terminal. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0033] Figure 1 It is a flowchart of the steps of a method for mobile information security protection using a digital certificate provided by an embodiment of the present application;

[0034] Figure 2 It is a schematic diagram of the digital certificate issuance process provided by an embodiment of the present application;

[0035] Figure 3 It is a flowchart of terminal communication identity verification provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] In order to further elaborate on the technical means and effects adopted by the present application to achieve the predetermined invention purpose, the following, in combination with the drawings and preferred embodiments, details the specific implementation manners, structures, features and their effects of the mobile information security protection method and system using a digital certificate proposed according to the present application. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures or characteristics in one or more embodiments can be combined in any suitable form.

[0037] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which this application belongs.

[0038] The following specifically describes the specific solutions of the mobile information security protection method and system using digital certificates provided by this application in conjunction with the accompanying drawings.

[0039] Please refer to Figure 1 , which shows the step flowchart of the mobile information security protection method using digital certificates provided by an embodiment of this application. The method includes the following steps:

[0040] Step S1, collect the user name information when each digital certificate request is initiated by each user, the total number and processing capacity score of all the user's mobile terminal devices, the certificate request time and certificate expiration time of the digital certificate, and the total number of all digital certificate requests initiated.

[0041] During network communication, in order to ensure the information privacy of both communication parties, an asymmetric encryption algorithm is used for session encryption between the two communication parties, that is, "public key encryption, private key decryption". However, there are still technical vulnerabilities in the use process. If there is a man-in-the-middle between the two, intercept the public key information of the receiving party and send its own public key information to the sending party to achieve the tampering and interception of the session content. Therefore, a binding authentication method for the public key and the user identity is required. Digital certificates are the main means to achieve this function. In order to ensure the integrity and security of digital certificates, digital signatures need to be performed on digital certificates.

[0042] When both communication parties initiate communication, both the sending and receiving parties need to publicly display their public keys through digital certificates. The issuance of digital certificates needs to be based on a third-party digital certificate certification authority (CertifiCAte Authority, abbreviated as CA), and the database in the third-party digital certificate certification authority is used as the CA database.

[0043] Generate a public-private key pair in a single mobile terminal user, establish a communication connection with the third-party digital certificate certification authority, and initiate various digital certificate requests to the third-party digital certificate certification authority. The request content of the digital certificate includes the user name information of the user, the information of all the user's mobile terminal devices, and the certificate expiration time of the digital certificate, and obtain the certificate request time for each digital certificate request.

[0044] Count the number of all the mobile terminal devices of each user and the total number of all digital certificate requests initiated. Further, the processing capacity score of each mobile terminal can be obtained in each mobile terminal device of each user. Among them, the processing capacity score reflects the information processing ability of the mobile device.

[0045] Step S2: Based on the average of the number of digital certificate requests initiated by the user, the time interval between the certificate expiration time and the certificate request time, obtain the certificate demand degree of each user; based on the user name information and the certificate demand degree, obtain the private key evaluation degree of each user.

[0046] With the rapid development of the current mobile Internet, mobile information security protection faces great challenges. Currently, it mainly relies on two verification methods. One is the SMS verification code. This method is simple to verify, but has weak security and the SMS verification code information is easily stolen. The other is hardware device verification, such as SIM cards, USB tokens, etc. Although the security is relatively high, the usage cost increases and the operation process is relatively complex. Therefore, there is a need for a software-based method to issue digital certificates to mobile terminals without adding hardware devices to the mobile terminals, so as to achieve terminal authentication.

[0047] Perform digital signature on the user's digital certificate to make it consistent and complete. And a single digital certificate has a certain timeliness. When a single digital certificate expires, the user terminal needs to initiate a new certificate request. The more frequent the digital certificate requests for a single user name are, the higher the mobile communication frequency of the user is. Therefore, in order to ensure the privacy of its data transmission, the digital signature on the digital certificate issued to this user requires a higher private key complexity.

[0048] Furthermore, for each digital certificate request initiated by each user, calculate the time interval between the certificate request time of each digital certificate and the certificate expiration time of the previous digital certificate request as the demand time interval for each digital certificate request initiated by each user, and take the average value of the demand time intervals of all digital certificate requests initiated by each user as the average demand time interval of each user. Among them, the unit of the time interval is days.

[0049] According to the above analysis, for each user, based on the number of digital certificate requests initiated by the user and the average demand time interval, obtain the certificate demand degree of each user. The calculation formula is: ; In the formula, A represents the certificate demand degree of each user, N represents the total number of all digital certificate requests initiated by each user, is the average demand time interval of each user, Preset a tuning parameter factor. In this embodiment, the value of is 1. The purpose is to avoid the formula being unable to be calculated due to the denominator being zero. Implementers can select other values according to the actual situation.

[0050] It should be noted that by analyzing the application times and application urgency of the user's digital certificate, the user's demand degree for the certificate can be obtained. If the time interval between the expiration of the certificate and the re-application is smaller, it indicates that the user has a higher demand for the digital certificate. At the same time, if the number of applications is larger, the value of the certificate demand degree will be larger, reflecting that the user has a higher communication demand. Therefore, the complexity of the private key of the digital certificate digital signature is higher.

[0051] Furthermore, when the user conducts mobile terminal communication, the complexity of the user name can reflect the user's security. The more complex the user name is, the more difficult it is to be guessed or cracked, and it is more difficult for attackers to crack it through brute force or dictionary attacks. Therefore, the higher the complexity of the user name, the better the privacy.

[0052] To better represent the complexity of the user name, the user name information of each user is converted into ASCII code values, and the sequence composed of the absolute values of the differences between all adjacent two numerical values in the ASCII code values is used as the user name complexity evaluation sequence F of each user.

[0053] Furthermore, in order to evaluate the complexity that the private key of each user should have, the private key evaluation degree of each user is obtained based on the uncertainty of the user name complexity evaluation sequence and the certificate demand degree. The obtaining method is: obtaining the user name complexity index of each user based on the information uncertainty of the user name complexity evaluation sequence. The calculation formula of the user name complexity index is: ; where B represents the user name complexity index of each user, represents the user name complexity evaluation sequence of each user, represents the calculation of information entropy, represents the logarithmic function with the natural constant as the true number.

[0054] The ratio of the certificate demand degree of each user to the user name complexity index is used as the private key evaluation degree of each user.

[0055] It should be noted that thus, for each user, the higher the complexity of the user name, the greater the difficulty for the man-in-the-middle to break the communication session in network communication. At this time, the demand for the complexity of the private key is smaller. On the contrary, the lower the complexity of the user name, the weaker the protection ability of the user name, and a higher protection private key complexity is required. Thus, combined with the certificate demand degree of the user, the private key evaluation degree of the user is obtained. The larger the value of the evaluation degree, the higher the complexity of the private key for each user. On the contrary, the smaller the value, the complexity of the private key can be appropriately reduced.

[0056] Step S3: Obtain the device terminal correction value of each mobile terminal device of each user based on the total number and processing capacity score of all the user's mobile terminal devices; obtain the private key adjustment factor of each mobile terminal device of each user based on the private key evaluation degree and the device terminal correction value; obtain the private key parameter when each digital certificate request is initiated by each mobile terminal device of each user based on the private key adjustment factor.

[0057] According to the above steps, based on the user name information and the application situation of the user in the CA database, obtain the private key complexity of each user, so as to measure the complexity of the digital signature private key when issuing digital certificates to each user. However, in the actual process, there may be multiple device terminals corresponding to a single user, and the data processing capabilities of different device terminals are different. It is necessary to further process in combination with the mobile terminal information of the user.

[0058] To ensure the convenience of information transmission, usually there are multiple device terminals under a single user name. For different mobile terminals, different digital certificates need to be issued to ensure the correspondence between user information and communication public keys. The more mobile terminal devices there are under a single user, the weaker the privacy protection ability of the call, and the more rigorous the protection form is required. In addition, in mobile information security protection, the processing capacity of the mobile terminal is an important measurement index. If the private key of the digital signature is too complex, for a mobile terminal with weak processing capacity, it may lead to a long operation time, thus affecting the actual session communication quality. Therefore, it is necessary to measure the complexity of the private key in combination with the operation and processing capabilities between actual mobile device terminals.

[0059] Based on the above analysis, through the CA database, obtain the number of different terminals under each user by query, and distinguish them by the serial number of the device terminal. Thus, the device terminal correction value is obtained: ; where C represents the device terminal correction value of each mobile terminal device of each user; represents the logarithmic function with 2 as the true number, M represents the total number of all the mobile terminal devices of each user, represents the normalized value of the processing capacity score of each mobile terminal device of each user; it should be noted that this processing capacity score is a normalized value. Since in performance testing, the devices with the lowest scores are basically eliminated, the value of this processing capacity distribution is not zero.

[0060] Through the above formula, obtain the device terminal correction value corresponding to the certificate request of this user, and measure the encryption degree when the device terminal signs the digital certificate. When this user has a device terminal with strong processing capacity and a large number of terminals, a larger private key complexity is used at this time. On the contrary, considering the terminal processing capacity, a relatively lower private key complexity is required.

[0061] Further, based on the private key evaluation degree and the device terminal correction value, obtain the private key adjustment factor for each mobile terminal device of each user. The obtaining method is as follows: for each mobile terminal device of each user, calculate the sum of the private key evaluation degree of each user and the device terminal correction value of each mobile terminal device of each user, and calculate the remainder of the quotient of the sum and the preset bit character length as the private key adjustment factor for each mobile terminal device of each user. In this embodiment, the value of the preset bit character length is 128, and the implementer can select other values according to the actual situation.

[0062] It should be noted that the purpose of obtaining the corresponding private key adjustment factor based on the user identity information and the mobile device terminal information is to obtain the private key adjustment value based on the user's identity information, so that the generated private key information contains certain user characteristics and is no longer generated only by pseudo-random numbers. The greater the weighted value of the private key evaluation degree and the device terminal correction value, the greater the need for a higher private key complexity. Generally, the length of the private key bit character is 128. Therefore, the maximum value of the private key adjustment factor is restricted by the region method.

[0063] Use the random number generation algorithm to obtain the random numbers when each user initiates each digital certificate request, and perform an exclusive OR operation on the binary numbers of the private key adjustment factors of each mobile terminal device of each user and the binary numbers of the random numbers to obtain the private key parameters when each user's each mobile terminal device initiates each digital certificate request.

[0064] Thus, the final private key parameters are obtained, which contain both the original random parameters and the user's characteristic information, increasing the difficulty of brute-force cracking by the intermediate value and improving the non-tamperability of the digital signature.

[0065] Step S4: Sign and issue the digital certificate based on the private key parameter values of each user's certificate request.

[0066] Based on the above analysis, the private key parameter values of each user's certificate request can be obtained, and the signature and issuance of the digital certificate are realized accordingly. The specific process is as Figure 2 shown.

[0067] Send a certificate request: Before making a call, the user terminal needs to be authenticated by a third-party institution to prove its identity. That is, send its own user characteristics to the third-party institution, the CA institution, and send the user identity information, the device terminal, and the communication public key to the CA institution. It should be noted that the sent communication public key exists in pairs with the communication private key, and the purpose is to realize data encryption in the communication process between terminal users, and it needs to be distinguished from the signature private key and public key in the digital signature process.

[0068] Generate a digital signature: When the institution receives a user certificate request, the private key parameters are generated in the above steps. Then, the private key and public key information of the digital signature are obtained using the ECDSA digital signature algorithm, and a hash operation is performed based on the user feature information to obtain a hash value. The hash value is encrypted using the signature private key to obtain a digital signature. When performing digital signature, "private key signing and public key verification" is adopted.

[0069] Generate and distribute a digital certificate: A digital certificate is generated based on the obtained digital signature and user feature information. The digital certificate contains the user's feature information to indicate the corresponding relationship between the user's communication public key and the user's identity. At the same time, the authority of the digital certificate is ensured based on the digital signature.

[0070] Step S5: Implement the identity verification of both parties before communication based on the digital certificate of the user terminal.

[0071] The digital certificate of the user terminal is obtained through step S4. Based on this, the identity verification of both parties before communication is realized. The authentication processes of both parties are the same. Therefore, taking a single direction as an example here, the specific process is as Figure 3 shown:

[0072] Obtain digital certificate information: During the communication process, the digital certificate of oneself needs to be sent to the other party. After the other party receives the digital certificate, information reading is performed, and the user features and digital signature of user B are obtained.

[0073] Obtain the hash value: A hash value is obtained through a hash operation based on the user feature information. If the user's identity information is tampered with, the obtained hash value will deviate greatly. At the same time, the corresponding hash value is obtained through decryption using the signature public key during digital signature.

[0074] It should be noted that the signature public key is transmitted through the network. In order to ensure that the signature public key is issued by a third-party authoritative institution and has not been tampered with, at this time, user A needs to verify the signature public key based on the root CA, and this root CA has been integrated into the device during the device production process and does not need to be transmitted through the network, thus forming a complete certificate chain.

[0075] Digital certificate verification: Compare the obtained verification hash value with the calculated hash value. If the two are consistent, it indicates that the communication public key corresponds to the identity of user B. Therefore, during the communication process, this public key can be used to encrypt the communication content. If the obtained hash values are inconsistent, it means that the communication public key and the identity of user B do not correspond, and the identity of user B may be impersonated by a man-in-the-middle. Therefore, the communication is interrupted to achieve the security protection of the mobile terminal information transmission process.

[0076] Based on the same inventive concept as the above method, an embodiment of the present application further provides a mobile information security protection system using digital certificates, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the steps of any one of the above mobile information security protection methods using digital certificates are implemented.

[0077] It should be noted that: the above sequence of embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above specific embodiments of the present specification have been described. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0078] The embodiments in the present application are all described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized.

[0079] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the principle of the present application shall be included in the protection scope of the present application.

Claims

1. A mobile information security protection method using digital certificates, characterized in that: The method comprises the following steps: Collect the user name information of each digital certificate request initiated by each user, the total number and processing capability score of all mobile terminal devices of the user, the certificate request time of the digital certificate, the certificate expiration time and the total number of times all digital certificate requests were initiated; Based on the number of digital certificate requests initiated by the user, the average time interval between the certificate expiration time and the certificate request time, the degree of certificate demand of each user is obtained; Encode the username information, form a username complexity evaluation sequence based on the differences between adjacent codes, and obtain the username complexity index through the information entropy of the username complexity evaluation sequence; use the ratio of the certificate requirement degree and the username complexity index as the private key evaluation degree of each user; Obtaining a device terminal correction value for each mobile terminal device of each user based on the total number and processing capability score of all mobile terminal devices of the user; The private key evaluation degree and the device terminal correction value are summed, and the remainder of the sum value with respect to the preset bit character length is taken as the private key adjustment factor of each mobile terminal device of each user; A random number generation algorithm is used to generate a random number, and a private key parameter of each digital certificate request initiated by each mobile terminal device of each user is obtained based on the binary number of the private key adjustment factor and the binary number XOR operation of the random number.

2. The mobile information security protection method using digital certificates as claimed in claim 1, characterized in that: The method for obtaining the certificate requirement degree is as follows: The average required time interval of each user is obtained based on the average time interval between the certificate request time of each digital certificate request and the certificate expiration time of the previous digital certificate request; For each user, the sum of the average demand time interval and the preset parameter adjustment factor is calculated, and the ratio of the total number of times all digital certificate requests are initiated to the sum is used as the certificate demand level of each user.

3. The mobile information security protection method using digital certificates as claimed in claim 2, characterized in that: The method for obtaining the average demand time interval is: For each digital certificate request initiated by each user, the time interval between the certificate request time of each digital certificate and the certificate expiration time of the previous digital certificate request is calculated as the required time interval of each digital certificate request initiated by each user, and the average of the required time intervals of all digital certificate requests initiated by each user is taken as the average required time interval of each user.

4. The mobile information security protection method using digital certificates as claimed in claim 1, characterized in that: The method for obtaining the private key evaluation degree is: Obtaining a complex evaluation sequence of each user's username based on the username information; Obtain the username complexity index of each user based on the information entropy of the username complexity evaluation sequence; The ratio of each user's certificate requirement to the username complexity index is used as the private key evaluation degree of each user.

5. The mobile information security protection method using digital certificates as claimed in claim 4, characterized in that: The method for obtaining the complex evaluation sequence of the user name is: The user name information of each user is converted into an ASCII code value, and a sequence consisting of the absolute values ​​of the differences between all two adjacent values ​​in the ASCII code value is used as the complex evaluation sequence of the user name of each user.

6. The mobile information security protection method using digital certificates as claimed in claim 4, characterized in that: The calculation formula of the username complexity index is: ; Where B represents the complexity index of each user's username, Represents the complex evaluation sequence of each user's username, represents the calculation of information entropy, Represents a logarithmic function with a natural constant as a real number.

7. The mobile information security protection method using digital certificates as claimed in claim 1, characterized in that: The calculation formula of the equipment terminal correction value is: ; Wherein, C represents the device terminal correction value of each mobile terminal device of each user; represents a logarithmic function with a value of 2 as the true number, M represents the total number of all mobile terminal devices of each user, Represents the normalized value of the processing capability score of each mobile terminal device of each user.

8. The mobile information security protection method using digital certificates as claimed in claim 1, characterized in that: The method for obtaining the private key adjustment factor is: For each mobile terminal device of each user, the sum of the private key evaluation degree of each user and the device terminal correction value of each mobile terminal device of each user is calculated, and the remainder of the quotient of the sum result and the preset bit character length is calculated as the private key adjustment factor of each mobile terminal device of each user.

9. The mobile information security protection method using digital certificates as claimed in claim 1, characterized in that: The method for obtaining the private key parameters is: A random number generation algorithm is used to obtain a random number when each digital certificate request is initiated by each user, and an XOR operation is performed on the binary number of the private key adjustment factor of each mobile terminal device of each user and the binary number of the random number to obtain the private key parameters when each digital certificate request is initiated by each mobile terminal device of each user.

10. A mobile information security protection system using digital certificates, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the mobile information security protection method using digital certificates as described in any one of claims 1-9 are implemented.

Citation Information

Patent Citations

  • Method and system for tamper-proof provision of multiple digital certificates for multiple public keys of a device

    CN104579676A

  • Trusted identity verification system and method based on mobile digital certificate

    CN110598422A