CA certificate non-inductive automatic updating system, method, device and medium
By introducing a senseless automatic update mechanism into the CA certificate system, the existing certificate update solutions are complicated and security vulnerable, and the automated update of certificates is realized, which improves the convenience and security of certificate management.
Patent Information
- Application Number
- CN202411937812.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-05-06
AI Technical Summary
Existing digital certificate update solutions are cumbersome and error-prone, especially in large enterprises or complex IT environments that manage large number of certificate updates. At the same time, manual updates have the risk of security vulnerabilities and cannot meet the needs of modern network security.
It provides a CA certificate automatic update system, including a user side, a certificate server and a RA certificate issuing platform. It automatically downloads and updates the certificates through automatic request units and automatic update units to ensure that the certificates are automatically updated before expiration and reduce user intervention.
It realizes automatic update of certificates without any action, improves the convenience and security of certificate management, reduces user operation burden, and avoids the risk of security vulnerabilities caused by manual updates.
Smart Images

Figure CN119945733A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of electronic communication security technology. Specifically, the present invention is applied to the field of digital certificates, and in particular to a CA certificate non-sensing automatic update system, method, device and medium. Background Art
[0002] Digital certificates play a vital role in the current network security system; they not only ensure the confidentiality, integrity and authentication of information, but are also the cornerstone of modern e-commerce, online services and data communications; however, although digital certificate technology itself performs well in ensuring security, its update mechanism faces significant challenges, especially its cumbersome update process, which seriously affects the user experience and the overall security of the system.
[0003] Traditional digital certificate renewal solutions usually rely on manual operations by users; this means that every time a certificate is about to expire, users must actively intervene and perform a series of complex steps to request, download and install a new certificate; this process is not only time-consuming and labor-intensive, but also prone to errors. Especially in large enterprises or complex IT environments, managing the renewal of thousands of certificates has become an almost impossible task.
[0004] In addition, manually updating certificates also poses the risk of security vulnerabilities; since the update process requires user intervention, this provides opportunities for negligence or malicious behavior; for example, if the user forgets to update the certificate or uses an insecure connection during the update process, the certificate may become invalid or the system may be attacked.
[0005] More importantly, with the acceleration of digital transformation and the popularization of Internet of Things (IoT) devices, more and more devices and systems need to rely on digital certificates to ensure secure communication; these devices often do not have user interaction interfaces or sufficient computing power to perform complex update operations, so traditional manual update solutions are completely unsuitable in these scenarios.
[0006] In summary, the existing digital certificate update solutions can no longer meet the needs of modern network security; in order to achieve more efficient, secure and user-friendly certificate management, the industry urgently needs a digital certificate update solution that can achieve seamless updates. Summary of the invention
[0007] The object of the present invention is to provide a CA certificate automatic update system, method, device and medium, thereby solving all or one of the above problems existing in the prior art.
[0008] In order to solve the above technical problems, the specific technical solutions of the present invention are as follows: In one aspect, the present invention provides a CA certificate automatic update system, comprising: Client, certificate server and RA issuing platform; The user terminal is used to send an update request to the certificate server according to the automatic update time policy, and automatically download the update certificate if the certificate server allows the update; The certificate server is used to respond to the update request of the user terminal, perform update condition judgment, and request the RA issuing platform to update the certificate according to the update condition judgment result; The RA issuing platform is used to respond to the update request of the certificate server and return a new certificate to the certificate server.
[0009] Further, the user terminal includes: an automatic request unit, wherein the automatic update time strategy is configured in the automatic request unit; The automatic request unit is used to identify the current certificate status of the user when the user logs in, and upload the update request to the certificate server when the current certificate status of the user meets the automatic update time policy; The automatic request unit is further configured to generate a new key pair and package an update request package and upload it to the certificate server when the certificate server allows update.
[0010] Furthermore, the user terminal further includes: an automatic updating unit, wherein the automatic updating unit is configured with a certificate download period; The automatic updating unit is used to update the user's current certificate according to the certificate download period after the certificate server obtains the new certificate, if the user does not actively update the certificate.
[0011] Further, the certificate server includes: an update judgment unit; The update judgment unit is used to judge whether the update request meets the update condition when receiving the update request from the user terminal, set the update condition judgment result to allow update when the update condition is met, and notify the user terminal when the update is allowed.
[0012] Furthermore, the certificate server further includes: a request recording unit; The request recording unit is used to receive the update request packet and record relevant information of the update request.
[0013] Furthermore, the certificate server further includes: a platform connection unit and a certificate storage unit; The platform connection unit is used to connect to the RA certification platform after recording the relevant information of the update request, and send the update request to the RA certification platform; The certificate storage unit is used to receive the new certificate sent by the RA issuing platform and store the new certificate.
[0014] Furthermore, the CA certificate automatic update system also includes: a platform management terminal; The platform management terminal is used to query the update data related to the digital certificate.
[0015] On the other hand, the present invention also provides a CA certificate non-sensing automatic update method, which is used in the CA certificate non-sensing automatic update system, and the method comprises the following steps: The client sends an update request to the certificate server according to the automatic update time policy, and automatically downloads the updated certificate if the certificate server allows the update; The certificate server responds to the update request of the client, performs update condition judgment, and requests the RA issuing platform to update the certificate according to the update condition judgment result; The RA issuing platform responds to the request of the certificate server and returns a new certificate to the certificate server.
[0016] On the other hand, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method for seamless automatic update of CA certificates are implemented.
[0017] On the other hand, the present invention further provides a computer device, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; wherein: The memory is used to store computer programs; The processor is used to execute the steps of the CA certificate seamless automatic update method by running the program stored in the memory.
[0018] The beneficial effects of the technical solution of the present invention are: 1. The CA certificate seamless automatic update system described in the present invention can automatically reissue a new certificate, replace the key and extend the validity period after the user certificate expires or is about to expire. This mechanism ensures that the user can seamlessly regain a valid digital certificate without any manual operation, realizes the silent update of the digital certificate, greatly improves the convenience and security of certificate management, makes up for the defects of the existing technology, and has a high application value.
[0019] 2. The CA certificate seamless automatic update method described in the present invention can call the system modules in an orderly manner, thereby realizing the system logic of the CA certificate seamless automatic update system described in the present invention.
[0020] 3. The computer-readable storage medium described in the present invention can realize the cooperation of the guiding system module, thereby realizing the CA certificate seamless automatic update method described in the present invention, and the computer-readable storage medium described in the present invention also effectively improves the operability of the CA certificate seamless automatic update method.
[0021] 4. The computer device described in the present invention can store and execute the computer-readable storage medium, thereby realizing the CA certificate seamless automatic update method described in the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0023] Figure 1 It is a schematic diagram of the architecture of the CA certificate automatic update system according to Embodiment 1 of the present invention; Figure 2 It is a schematic diagram of the architecture of the user terminal in the CA certificate automatic update system described in Example 1 of the present invention; Figure 3 It is a schematic diagram of the architecture of the certificate server in the CA certificate automatic update system described in Example 1 of the present invention; Figure 4 It is a schematic diagram of the logical architecture of the CA certificate automatic update system described in Example 1 of the present invention; Figure 5 It is a flowchart of the method for automatic CA certificate update described in Embodiment 2 of the present invention; Figure 6 It is a flowchart of step S100 in the method for automatic CA certificate update according to Embodiment 2 of the present invention; Figure 7 It is a flowchart of step S200 in the method for automatic CA certificate update according to Embodiment 2 of the present invention; Figure 8 is a schematic diagram of the structure of the computer device described in Example 4 of the present invention; The symbols in the accompanying drawings are explained as follows: 1501, processor; 1502, communication interface; 1503, memory; 1504, communication bus. DETAILED DESCRIPTION
[0024] The preferred embodiments of the present invention are described in detail below in conjunction with the accompanying drawings so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby making a clearer and more definite definition of the protection scope of the present invention.
[0025] In the description of the present invention, it should be noted that the embodiments described in the present invention are only part of the embodiments of the present invention, rather than all of the embodiments; based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0026] The terms "first", "second", etc. in the specification and claims of this article and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of this article described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, device, product or equipment that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or equipment. Example 1
[0027] This embodiment provides a CA certificate automatic update system. Figure 1~Figure 4 As shown, it includes: user end, certificate server, RA issuing platform and platform management end; The user end, as the front-end interface of the entire system, plays a vital role, such as Figure 2 As shown, it specifically includes: an automatic request unit and an automatic update unit; (1) An automatic request unit, which has a preset automatic update time rule (i.e., automatic update time policy, such as 60 days before certificate expiration). It is used to intelligently identify the status of the user's current certificate and check the expiration time of the user's certificate whenever the user logs in. When the expiration time meets the automatic update time rule, it automatically uploads an update request to the certificate server; when the certificate server allows the update, it immediately generates a new key pair and packages it into an update request package and uploads it to the certificate server; (2) An automatic update unit, which is used to automatically update the user's current certificate within 60 days before the certificate expires (i.e., the certificate download period) after the certificate server obtains the updated certificate, if the user does not actively call for update; It should be noted that the automatic request unit and the automatic update unit realize the automatic and seamless update process of the digital certificate, which greatly reduces the user's operation burden and ensures the validity and security of the certificate.
[0028] The certificate server is the core processing unit of the entire seamless update process. Figure 3 As shown, it specifically includes: an update judgment unit, a request recording unit, a platform connection unit and a certificate storage unit; (1) an update judgment unit, which is used to strictly judge whether the update request meets the update conditions according to the security policy configured by the system whenever an update request is received from the user end, and notify the automatic request unit when the update conditions are met; (2) Request recording unit, which is used to record all relevant information of this update request in detail within the server to ensure the traceability and security of the process; (3) Platform connection unit, used to connect to the RA certification platform and send out the update request after the request is recorded; (4) The certificate storage unit is used to safely store the updated certificate after receiving it from the RA issuance platform, and supports the user terminal to automatically download and update the certificate within 60 days before the certificate expires, thereby ensuring that the user always holds a valid digital certificate and realizing seamless update.
[0029] It should be noted that during the entire process of the certificate server responding, the certificate server must remain connected to the Internet, because online updates require uninterrupted sending and receiving of data to ensure the real-time and accuracy of the update.
[0030] The RA issuing platform is an authoritative body for issuing certificates. The RA issuing platform is used to quickly respond to the update request from the certificate server, conduct strict review and verification of the request, ensure that all information is accurate, and then issue a new certificate and return it to the certificate server.
[0031] The platform management end also plays an important role in the entire system; the platform management end is used to use the management interface to view updated data information in real time, including the time, status and results of the update request, and then monitor and manage the system's operating status in real time; the platform management end provides a strong guarantee for the stability and security of the system.
[0032] It should be noted that the above examples are only for explaining the present invention and cannot limit the protection scope of the present invention. Example 2
[0033] This embodiment is based on the same inventive concept as the CA certificate automatic update system described in Embodiment 1, and provides a CA certificate automatic update method. Figure 5~Figure 7 As shown, the following steps are included: S100, calling the user end to send an update request to the certificate server according to the automatic update time policy, and automatically download the updated certificate if the certificate server allows the update, such as Figure 6 As shown, the specific steps are as follows: S101, calling the automatic request unit of the user end to identify the current certificate status of the user when the user logs in, and when the current certificate status of the user meets the automatic update time policy, uploading the update request to the certificate server; S102, calling the automatic request unit of the user end to generate a new key pair when the certificate server allows update, and packing the update request package and uploading it to the certificate server; S103: After the certificate server obtains the new certificate, the automatic update unit of the user terminal is called to update the current certificate of the user according to the certificate download period if the user does not actively update the certificate.
[0034] S200, calling the certificate server to respond to the update request of the user terminal, performing update condition judgment, and requesting the RA issuing platform to update the certificate according to the update condition judgment result, such as Figure 7 As shown, the specific steps are as follows: S201, calling the update judgment unit of the certificate server to judge whether the update request satisfies the update condition when receiving the update request from the client, setting the update condition judgment result as allowing update when the update condition is met, and notifying the client when the update is allowed; S202, calling the request recording unit of the certificate server to receive the update request packet and record relevant information of the update request; S203, after recording the relevant information of the update request, the platform connection unit of the calling certificate server connects to the RA issuing platform and sends an update request to the RA issuing platform; S204: Call the certificate storage unit of the certificate server to receive the new certificate sent by the RA issuing platform, and save the new certificate.
[0035] S300: Calling the RA issuing platform to respond to the request of the certificate server and returning a new certificate to the certificate server.
[0036] S400. Call the platform management terminal to query the update data related to the digital certificate according to specific needs. Example 3
[0037] This embodiment provides a computer-readable storage medium, including: The storage medium is used to store computer software instructions used to implement the CA certificate seamless automatic update method described in the above-mentioned Example 2, which includes a program for executing the above-mentioned program set for the CA certificate seamless automatic update method; specifically, the executable program can be built into the CA certificate seamless automatic update system described in Example 1, so that the CA certificate seamless automatic update system can implement the CA certificate seamless automatic update method described in Example 2 by executing the built-in executable program.
[0038] In addition, the computer-readable storage medium of this embodiment may adopt any combination of one or more computer-readable storage media, wherein the computer-readable storage medium includes electrical, optical, electromagnetic, infrared or semiconductor systems, devices or components, or any combination thereof. Example 4
[0039] This embodiment provides an electronic device, such as Figure 8 As shown, the electronic device may include: a processor 1501 , a communication interface 1502 , a memory 1503 and a communication bus 1504 , wherein the processor 1501 , the communication interface 1502 , and the memory 1503 communicate with each other via the communication bus 1504 .
[0040] Memory 1503, used for storing computer programs; The processor 1501 is used to implement the steps of the CA certificate automatic update method described in the above embodiment 1 when executing the computer program stored in the memory 1503.
[0041] As an embodiment of the present invention, the communication bus mentioned in the above terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0042] As an implementation mode of the present invention, the communication interface is used for communication between the above-mentioned terminal and other devices.
[0043] As an embodiment of the present invention, the memory may include a random access memory (RAM) or a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.
[0044] As an embodiment of the present invention, the above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components.
[0045] Different from the existing technology, the present application adopts a CA certificate seamless automatic update system, method, device and medium, which can automatically reissue a new certificate, replace the key and extend the validity period after the user certificate expires or is about to expire. This mechanism ensures that the user can seamlessly regain a valid digital certificate without any manual operation, realizes the silent update of digital certificates, greatly improves the convenience and security of certificate management, makes up for the defects of the existing technology, and has high application value.
[0046] It should be understood that in the various embodiments of this document, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this document.
[0047] It should also be understood that in the embodiments of this article, the term "and / or" is only a description of the association relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0048] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this article.
[0049] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific logical process of the method described above can refer to the corresponding working processes of the systems, devices and units in the aforementioned method embodiments, and will not be repeated here.
[0050] In the several embodiments provided herein, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or can be electrical, mechanical or other forms of connection.
[0051] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the embodiments of this article.
[0052] In addition, each functional unit in each embodiment of this invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or in the form of software functional unit.
[0053] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this article is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of this article. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0054] The above descriptions are merely embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A CA certificate automatic update system, characterized in that: include: Client, certificate server and RA issuing platform; The user terminal is used to send an update request to the certificate server according to the automatic update time policy, and automatically download the update certificate if the certificate server allows the update; The certificate server is used to respond to the update request of the user terminal, perform update condition judgment, and request the RA issuing platform to update the certificate according to the update condition judgment result; The RA issuing platform is used to respond to the update request of the certificate server and return a new certificate to the certificate server.
2. The CA certificate automatic update system according to claim 1 is characterized in that: The user terminal comprises: an automatic request unit, wherein the automatic update time strategy is configured in the automatic request unit; The automatic request unit is used to identify the current certificate status of the user when the user logs in, and upload the update request to the certificate server when the current certificate status of the user meets the automatic update time policy; The automatic request unit is further configured to generate a new key pair and package an update request package and upload it to the certificate server when the certificate server allows update.
3. The CA certificate automatic update system according to claim 1 is characterized in that: The user terminal further includes: an automatic updating unit, wherein the automatic updating unit is configured with a certificate download period; The automatic updating unit is used to update the user's current certificate according to the certificate download period after the certificate server obtains the new certificate, if the user does not actively update the certificate.
4. The CA certificate automatic update system according to claim 1 is characterized in that: The certificate server comprises: an update judgment unit; The update judgment unit is used to judge whether the update request meets the update condition when receiving the update request from the user terminal, set the update condition judgment result to allow update when the update condition is met, and notify the user terminal when the update is allowed.
5. The CA certificate automatic update system according to claim 2 is characterized in that: The certificate server further includes: a request recording unit; The request recording unit is used to receive the update request packet and record relevant information of the update request.
6. The CA certificate automatic update system according to claim 1, characterized in that: The certificate server further includes: a platform connection unit and a certificate storage unit; The platform connection unit is used to connect to the RA certification platform after recording the relevant information of the update request, and send the update request to the RA certification platform; The certificate storage unit is used to receive the new certificate sent by the RA issuing platform and store the new certificate.
7. The CA certificate automatic update system according to claim 1, characterized in that: The CA certificate automatic update system also includes: a platform management terminal; The platform management terminal is used to query the update data related to the digital certificate.
8. A CA certificate non-sensing automatic update method, used in the CA certificate non-sensing automatic update system according to any one of claims 1 to 7, characterized in that: The method comprises the following steps: Call the user end to send an update request to the certificate server according to the automatic update time policy, and automatically download the updated certificate if the certificate server allows the update; Calling the certificate server to respond to the update request of the client, performing update condition judgment, and requesting the RA issuing platform to update the certificate according to the update condition judgment result; The RA issuing platform is called to respond to the request of the certificate server and return a new certificate to the certificate server.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the CA certificate automatic update method described in claim 8 are implemented.
10. A computer device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; wherein: The memory is used to store computer programs; The processor is used to execute the steps of the CA certificate automatic update method of claim 8 by running the program stored in the memory.