Digital certificate issuing method and device, electronic equipment and storage medium

By automatically evaluating the trust score of the target object and generating a digital certificate template, the problems of inefficient issuance of digital certificates and difficulty in ensuring security in the existing technology are solved, and efficient and secure automatic distribution management of digital certificates is achieved.

CN120124017APending Publication Date: 2025-06-10DUXIAOMAN TECH (BEIJING) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510206939.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing digital certificate issuance method relies on manual review, which leads to inefficiency and difficulty in ensuring security.

Method used

By obtaining the object information of the target object, evaluating its trust score, generating a digital certificate template based on the trust score, and automatically issuing digital certificates to reduce manual participation.

Benefits of technology

It realizes efficient and automatic distribution management of digital certificates, reduces time and labor costs, improves efficiency, and improves security by reducing manual participation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124017A_ABST
    Figure CN120124017A_ABST
Patent Text Reader

Abstract

The invention provides a digital certificate issuing method and device, electronic equipment and a storage medium, and relates to the technical field of computers. The method comprises the following steps: in response to a digital certificate request of a target object, obtaining object information of the target object; wherein the object information comprises various object data used for evaluating the trust score of the target object; determining a trust score estimated value of the target object based on the object information when determining that target object data with changed data exists in various object data included in the object information; generating a digital certificate of the target object based on a digital certificate template corresponding to the trust score estimation value, and issuing the digital certificate to the target object; wherein the digital certificate template is used for indicating various operation authorities. Therefore, efficient and fine-grained digital certificate automatic distribution management is realized, the time cost and the labor cost required by digital certificate distribution are greatly reduced, and the digital certificate distribution efficiency is improved; and moreover, the security of the digital certificate is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a digital certificate issuance method, apparatus, electronic device, and storage medium. Background Art

[0002] A digital certificate is a digital identifier used to prove the identity of a network node and ensure communication security in a network environment (such as a public cloud environment). Specifically, a network node can apply for a digital certificate from an authoritative certification center (such as a certificate authority), and the authoritative certification center issues a digital certificate to the network node after authenticating the identity of the network node.

[0003] Exemplarily, a digital certificate applicant (such as a target network node) can select a suitable certificate authority and generate a key pair between the digital certificate applicant and the certificate authority, and submit a certificate application request containing relevant information such as certificate request information, signature algorithm, and key pair to the certificate authority. After receiving the certificate application request, the auditor can verify the authenticity of the identity of the digital certificate applicant through methods such as document review, online verification, phone verification, and email verification. After the verification is passed, the certificate authority can generate the digital certificate of the digital certificate applicant and send the digital certificate to the digital certificate applicant, so that the digital certificate applicant can install the digital certificate into the local service or application.

[0004] However, with the above digital certificate issuance method, since the application and issuance process of digital certificates usually rely on manual review, the time cost and labor cost required for digital certificate issuance are relatively large, resulting in low efficiency of digital certificate issuance. Moreover, excessive manual participation may make it difficult to guarantee the security of digital certificates. Summary of the Invention

[0005] Embodiments of this application provide a digital certificate issuance method, apparatus, electronic device, and storage medium to improve the efficiency of digital certificate issuance and ensure the security of digital certificates.

[0006] In a first aspect, embodiments of this application provide a digital certificate issuance method, the method including:

[0007] In response to a digital certificate request of a target object, obtain object information of the target object; wherein, the object information includes: various object data for evaluating the trust score of the target object;

[0008] When it is determined that there is target object data with changed data among the various object data included in the object information, determine an estimated value of the trust score of the target object based on the object information;

[0009] Generate a digital certificate for the target object based on the digital certificate template corresponding to the trust score estimate, and issue the digital certificate to the target object; wherein, the digital certificate template is used to indicate multiple operation permissions.

[0010] In an alternative embodiment, the digital certificate request is generated according to the digital certificate application of the target object; or,

[0011] The digital certificate request is generated when it is determined that the target object meets the preset digital certificate generation conditions.

[0012] In an alternative embodiment, the method further includes:

[0013] If the target object data does not exist in the multiple object data, continuously obtain object information until the target object data exists in the object information.

[0014] In an alternative embodiment, determining the trust score estimate of the target object based on the object information includes:

[0015] Perform data standardization processing on the multiple object data included in the object information to obtain the multiple object data after data standardization processing;

[0016] Based on the sorting order of the correlation between the multiple object data and the trust score, screen out at least one object data that meets the preset correlation sorting conditions from the multiple object data after data standardization processing;

[0017] Determine the trust score evaluation value based on at least one object data.

[0018] In an alternative embodiment, performing data standardization processing on the multiple object data included in the object information to obtain the multiple object data after data standardization processing includes:

[0019] For at least one object data, perform the following operations respectively:

[0020] Perform data cleaning processing on the first object data to obtain the target object data; wherein, the first object data is any one of the at least one object data, and the target object data is the first object data after data interpolation and / or abnormal data deletion processing;

[0021] If the target object data is non-numeric data, perform numeric encoding on the target object data to obtain the target object data after numeric encoding.

[0022] In an alternative embodiment, generating a digital certificate for the target object based on the digital certificate template corresponding to the trust score estimate includes:

[0023] Determine the target trust level of the target object based on the estimated trust score value, and obtain the digital certificate template set for the target trust level;

[0024] Based on the object information and the certificate request content included in the digital certificate request, adjust the multiple operation permissions indicated by the digital certificate template to obtain a digital certificate.

[0025] In an optional embodiment, during the process of issuing the digital certificate to the target object, it further includes:

[0026] Obtain the configuration information corresponding to the digital certificate; the configuration information is used to deploy the digital certificate locally for the target object;

[0027] Synchronize the configuration information to the target object.

[0028] In a second aspect, an embodiment of the present application further provides a digital certificate issuing device, and the device includes:

[0029] An information acquisition module, configured to acquire the object information of the target object in response to the digital certificate request of the target object; wherein, the object information includes: multiple object data used to evaluate the trust score of the target object;

[0030] A score evaluation module, configured to determine the estimated trust score value of the target object based on the object information when it is determined that there is target object data in the multiple object data included in the object information that has changed;

[0031] A certificate issuing module, configured to generate a digital certificate for the target object based on the digital certificate template corresponding to the estimated trust score value, and issue the digital certificate to the target object; wherein, the digital certificate template is used to indicate multiple operation permissions.

[0032] In an optional embodiment, the digital certificate request is generated by the information acquisition module according to the digital certificate application of the target object; or,

[0033] The digital certificate request is generated by the information acquisition module when it is determined that the target object meets the preset digital certificate generation conditions.

[0034] In an optional embodiment, the information acquisition module is further configured to:

[0035] If there is no target object data in the multiple object data, continuously acquire the object information until there is target object data in the object information.

[0036] In an optional embodiment, when determining the estimated trust score value of the target object based on the object information, the score evaluation module specifically is configured to:

[0037] Perform data standardization processing on various object data included in the object information to obtain various object data after data standardization processing;

[0038] Based on the sorting order of the correlation between various object data and the trust score, select at least one object data that meets the preset correlation sorting condition from the various object data after data standardization processing;

[0039] Determine the trust score evaluation value based on at least one object data.

[0040] In an optional embodiment, when performing data standardization processing on various object data included in the object information to obtain various object data after data standardization processing, the score evaluation module is specifically used for:

[0041] For at least one object data, perform the following operations respectively:

[0042] Perform data cleaning processing on the first object data to obtain the target object data; wherein, the first object data is any one of at least one object data, and the target object data is the first object data after data interpolation and / or abnormal data deletion processing;

[0043] If the target object data is non-numerical data, perform numerical encoding on the target object data to obtain the target object data after numerical encoding.

[0044] In an optional embodiment, when generating a digital certificate for the target object based on the digital certificate template corresponding to the trust score estimate, the certificate issuance module is specifically used for:

[0045] Determine the target trust level of the target object based on the trust score estimate, and obtain the digital certificate template set for the target trust level;

[0046] Based on the object information and the certificate request content included in the digital certificate request, adjust the various operation permissions indicated by the digital certificate template to obtain the digital certificate.

[0047] In an optional embodiment, during the process of issuing the digital certificate to the target object, the certificate issuance module is further used for:

[0048] Obtain the configuration information corresponding to the digital certificate; the configuration information is used to deploy the digital certificate locally on the target object;

[0049] Synchronize the configuration information to the target object.

[0050] In a third aspect, an embodiment of the present application further provides an electronic device, including:

[0051] A processor; and

[0052] A memory for storing programs,

[0053] wherein the program includes instructions that, when executed by a processor, cause the processor to execute the digital certificate issuance method as described in the first aspect.

[0054] In a fourth aspect, an embodiment of the present application further provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to execute the digital certificate issuance method as described in the first aspect.

[0055] In a fifth aspect, the present application provides a computer program product that, when called by a computer, causes the computer to execute the steps of the digital certificate issuance method as described in the first aspect.

[0056] The beneficial effects of the present application are as follows:

[0057] In the digital certificate issuance method provided by the embodiment of the present application, in response to a digital certificate request of a target object, object information of the target object is obtained; wherein the object information includes: various object data for evaluating the trust score of the target object; then, when it is determined that there is target object data in the various object data included in the object information whose data has changed, an estimated value of the trust score of the target object is determined based on the object information; finally, a digital certificate of the target object is generated based on the digital certificate template corresponding to the estimated value of the trust score, and the digital certificate is issued to the target object; wherein the digital certificate template is used to indicate various operation permissions. In this way, there is no need for manual review of the digital certificate application and issuance process, realizing efficient and fine-grained automatic distribution management of digital certificates, greatly reducing the time cost and labor cost required for digital certificate issuance, and improving the efficiency of digital certificate issuance; moreover, due to less manual participation, the security of digital certificates is ensured.

[0058] In addition, other features and advantages of the present application will be described in the subsequent specification, and some of them will become obvious from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the written specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for description in the embodiments. Obviously, the drawings described herein are used to provide a further understanding of the present application, constitute a part of the present application, and do not constitute an improper limitation of the present application. In the drawings:

[0060] Figure 1 It is a schematic diagram of a scenario for digital certificate issuance provided by an embodiment of the present application;

[0061] Figure 2 It is a schematic diagram of an optional application scenario provided by an embodiment of the present application;

[0062] Figure 3 It is a schematic diagram of the implementation process of a digital certificate issuance method provided by an embodiment of the present application;

[0063] Figure 4 It is a schematic diagram of the implementation process of a method for determining a trust score evaluation value provided by an embodiment of the present application;

[0064] Figure 5 It is a logical diagram of a data cleaning process provided by an embodiment of the present application;

[0065] Figure 6 It is a logical diagram of trust score estimation based on an intelligent trust model provided by an embodiment of the present application;

[0066] Figure 7 It is a logical diagram of digital certificate generation and issuance based on a differential distribution module provided by an embodiment of the present application;

[0067] Figure 8 It is provided by an embodiment of the present application based on Figure 6 and Figure 7 A logical diagram of digital certificate issuance;

[0068] Figure 9 It is a schematic diagram of the structure of a digital certificate issuance device provided by an embodiment of the present application;

[0069] Figure 10 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0070] Hereinafter, embodiments of the present application will be described in more detail with reference to the accompanying drawings. Although some embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present application. It should be understood that the drawings and embodiments of the present application are only for exemplary purposes and are not used to limit the protection scope of the present application.

[0071] It should be understood that the various steps recited in the method embodiments of the present application can be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present application is not limited in this regard.

[0072] As used herein, the term "including" and its variations are open-ended, that is, "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first", "second", etc. mentioned in this application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0073] It should be noted that the modification of "one" and "multiple" mentioned in this application is illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise clearly specified in the context, it should be understood as "one or more".

[0074] The names of the messages or information exchanged between multiple devices in the embodiments of this application are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0075] The following explains some terms in the embodiments of this application to facilitate the understanding of those skilled in the art.

[0076] (1) Public cloud: It refers to a service model based on cloud computing technology, which provides online computing resources and services for public use by cloud service providers.

[0077] (2) Public cloud tenant: It refers to an independent user or organization that uses the cloud computing resources and services provided by a cloud service provider in the public cloud service model.

[0078] (3) Digital certificate: It is a digital identifier used to prove the identity of an entity (such as an individual, an organization, a server, an application, etc.) and ensure communication security in a network environment. Exemplarily, a digital certificate may include but not be limited to: public key information, identity information, certificate validity period, issuing authority information, etc. This application does not make specific limitations in this regard.

[0079] (4) Data standardization: It is a process of transforming data according to certain rules so that the data has specific expected characteristics and is more suitable for subsequent analysis and other operations.

[0080] Based on the above nouns and related term explanations, the design concept of the embodiments of this application is briefly introduced below:

[0081] In existing network environments (such as public cloud environments), there are a large number of network nodes (such as public cloud tenants, network devices, and clients, etc.). Digital certificates can uniquely identify each network node, ensuring that only legally authorized network nodes can access cloud resources and services, thereby achieving identity authentication and access control in the network environment. Moreover, digital certificates can encrypt the data transmitted in the network environment, thus safeguarding the confidentiality and privacy of the data.

[0082] Therefore, a digital certificate is a digital identifier used to prove the identity of network nodes and ensure communication security in a network environment. Refer to Figure 1 As shown, a network node (i.e., a digital certificate applicant) can apply for a digital certificate from a certificate authority (i.e., an authoritative certification center, a digital certificate certification center). After authenticating the identity of the network node, the certificate authority issues a digital certificate to the network node. Among them, the certificate authority is mainly an institution that provides functions such as certificate issuance, certificate update, and certificate verification.

[0083] Exemplarily, a network node can select a suitable certificate authority and generate a key pair between the digital certificate applicant and the certificate authority, where the key pair consists of a public key and / or a private key. Moreover, the network node can generate a certificate application request containing relevant information such as digital certificate request information, signature algorithm, and key pair, and send the certificate application request to the certificate authority. Optionally, the network node can send the certificate application request to the certificate authority in the form of a file or a form, etc.

[0084] After receiving the certificate application request, the reviewer can verify the authenticity of the network node's identity through methods such as file review, online verification, phone verification, and email verification. After the review is passed, the certificate authority can generate a digital certificate for the network node and send the digital certificate to the network node, so that after the network node receives the digital certificate, the digital certificate is installed in the local service or application.

[0085] However, adopting the above digital certificate issuance method based on manual review, the process of manually issuing digital certificates is cumbersome and time-consuming. From receiving the application, reviewing the materials, verifying the identity to finally issuing the certificate, each link requires manual participation and processing, which is difficult to meet the rapid issuance requirements of network nodes for digital certificates in the network environment, and may lead to business delays and reduced efficiency. Moreover, manually issuing digital certificates cannot respond to the application and update requirements of digital certificates in real time. Especially in some emergency situations, such as system fault repair, new business launch, etc., when rapid issuance or update of digital certificates is required, the delay in manual issuance may affect the business continuity and emergency response capabilities. Therefore, the efficiency of digital certificate issuance is relatively low.

[0086] In addition, human errors are likely to occur during manual review and operation processes. For example, problems such as incorrect information entry, inconsistent review criteria, and missed reviews may occur. These errors may lead to inaccurate digital certificates being issued, thus affecting the validity and credibility of digital certificates, and may further pose security risks. That is, excessive human participation is difficult to ensure the security of digital certificates. Moreover, as the network scale expands, the labor cost will also increase sharply.

[0087] In view of this, in order to improve or solve the above problems and improve the efficiency of digital certificate issuance and ensure the security of digital certificates. The embodiments of the present application provide a digital certificate issuance method that can automatically distribute and manage digital certificates, which may specifically include: in response to a digital certificate request of a target object, obtaining the object information of the target object; wherein, the object information may include: various object data for evaluating the trust score of the target object; then, when it is determined that there is target object data with changed data among the various object data included in the object information, determining an estimated value of the trust score of the target object based on the object information; finally, generating a digital certificate for the target object based on the digital certificate template corresponding to the estimated trust score, and issuing the digital certificate to the target object; wherein, the digital certificate template may be used to indicate various operation permissions of the target object.

[0088] Adopting this method, there is no need to manually review the application and issuance process of digital certificates, realizing efficient and fine-grained automatic distribution and management of digital certificates, greatly reducing the time cost and labor cost required for digital certificate issuance, and improving the efficiency of digital certificate issuance; and, due to less human participation, the security of digital certificates is ensured.

[0089] In particular, the preferred embodiments of the present application will be described below with reference to the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application and are not used to limit the present application. And without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.

[0090] Refer to Figure 2 As shown, it is a schematic diagram of an optional application scenario provided by the embodiments of the present application. This application scenario may include: network nodes (201a, 201b) and a server 202. Among them, the network node 201a corresponds to user 1, that is, user 1 uses the network node 201a, and the network node 201b corresponds to user 2, that is, user 2 uses the network node 201b. Information interaction can be carried out between the network nodes (201a, 201b) and the server 202 through a communication network. Among them, the communication methods adopted by the communication network may include: wireless communication methods and wired communication methods.

[0091] Exemplarily, the network nodes (201a, 201b) can access the network through cellular mobile communication technology and communicate with the server 202. Among them, the cellular mobile communication technology, for example, includes the fifth-generation mobile networks (5G) technology or the next-generation mobile communication technology. Optionally, the network nodes (201a, 201b) can access the network through short-range wireless communication and communicate with the server 202. Among them, the short-range wireless communication, for example, includes wireless fidelity (Wi-Fi) technology.

[0092] In addition, the above communication network can be a public network. Of course, it can also be a private network. The embodiments of the present application do not specifically limit the type of the communication network.

[0093] The embodiments of the present application do not impose any restrictions on the number of communication devices involved in the above application scenarios. For example, the above application scenarios may include more network nodes, or may include fewer network nodes, or may also include other network devices. As Figure 2 shown, only the network nodes (201a, 201b) and the server 202 are taken as examples for description. Below, a brief introduction to the above communication devices and their respective functions is given.

[0094] The network nodes (201a, 201b) can be terminal devices, that is, devices that can provide voice and / or data connectivity to users, and can be devices that support wired and / or wireless connection methods.

[0095] Exemplarily, the network nodes (201a, 201b) can include but are not limited to: mobile phones, tablet computers, laptop computers, palm computers, mobile internet devices (MID), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminal devices in industrial control, wireless terminal devices in unmanned driving, wireless terminal devices in smart grids, wireless terminal devices in transportation safety, wireless terminal devices in smart cities, or wireless terminal devices in smart homes, etc.

[0096] In addition, relevant clients can be installed on the network nodes (201a, 201b). The client can be software, such as an application (APP), a browser, a short video software, etc., or it can be a web page, a mini-program, etc. It should be noted that the network nodes (201a, 201b) in the embodiments of the present application can enable the above-mentioned clients related to digital certificate issuance to send digital certificate applications to the server 202, so as to perform method steps such as subsequent digital certificate issuance.

[0097] It should be understood that the network nodes (201a, 201b) can also be public cloud tenants or other network devices, and the embodiments of the present application do not make specific limitations in this regard.

[0098] The server 202 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery network (CDN), and big data and artificial intelligence platforms.

[0099] It is worth pointing out that a digital certificate distribution and management system related to digital certificate issuance can be deployed on the server 202 in the embodiments of the present application. The digital certificate distribution and management system can respond to the digital certificate request of the network nodes (201a, 201b) and obtain the object information of the network nodes (201a, 201b). Then, when it is determined that there is target object data with changed data among the various object data included in the object information, an estimated value of the trust score of the network nodes (201a, 201b) is determined based on the object information. Finally, a digital certificate for the network nodes (201a, 201b) is generated based on the digital certificate template corresponding to the estimated trust score value, and the digital certificate is issued to the network nodes (201a, 201b). Among them, the object information can include various object data used to evaluate the trust score of the network nodes (201a, 201b). The digital certificate template can be used to indicate various operation permissions. In this way, the efficiency of digital certificate issuance is improved and the security of digital certificates is ensured.

[0100] Next, in combination with the above application scenarios and with reference to the accompanying drawings, the digital certificate issuance method provided by the exemplary embodiments of the present application will be described. It should be noted that the above application scenarios are only shown for the convenience of understanding the spirit and principle of the present application, and the embodiments of the present application are not limited in this regard.

[0101] Refer to Figure 3As shown in the figure, it is a schematic flowchart of the implementation process of a digital certificate issuance method provided by an embodiment of the present application. Taking the server as an example of the execution entity, the specific implementation process of this method is as follows:

[0102] S301: In response to a digital certificate request from a target object, obtain the object information of the target object.

[0103] Among them, the above-mentioned target object can be a network node in a network scenario (such as a public cloud tenant) and can access corresponding cloud resources and services. It can be understood that the above-mentioned target object can also be called a digital certificate applicant. Of course, there can be other names. The above-mentioned object information can include various object data used to evaluate the trust score of the target object. The trust score is an indicator used to evaluate the credibility and reliability of a network node in a network scenario.

[0104] Exemplarily, the above-mentioned various object data can include, but are not limited to: the basic information of the target object, the historical behavior record of the target object, the security protection ability of the target object, and the network environment information (or called network environment characteristic information) of the target object, etc. The embodiments of the present application do not make specific limitations on this.

[0105] Taking the network scenario as a public cloud scenario and the target object as a public cloud tenant as an example, the above-mentioned various object data can include, but are not limited to: object data in multiple dimensions such as tenant basic information, historical behavior record, security protection ability, and network environment characteristics. Among them, the tenant basic information can include the tenant scale and industry attributes. The tenant scale can include individual tenants and tenant enterprises. Tenant enterprises can include the number of employees, revenue scale, and industry attributes of the tenant enterprise.

[0106] The above-mentioned historical behavior record can include: the resource usage situation and resource access pattern within a past set time range (such as 1 day or 3 days, etc.). The aforementioned resource usage situation can include: counting the usage frequency of the tenant's previous digital certificates, whether the certificates are updated on time, and whether there are security incidents caused by certificate problems, etc. The aforementioned resource access module can include analyzing the tenant's access habits to various resources in the public cloud scenario, for example, access time, access volume, and types of accessed resources. Among them, a normal and stable access pattern indicates that the tenant's behavior is relatively reliable and can improve the trust level; if there are abnormal resource access peaks or suspicious behaviors of frequently accessing sensitive resources, the trust degree will be reduced.

[0107] The above-mentioned security protection ability can include two aspects: the tenant's own security configuration and the timeliness of security vulnerability repair. Examine whether the tenant has deployed effective security protection tools such as firewalls, intrusion detection systems, and encryption technologies, and the update and maintenance conditions of these tools. Monitor the response speed and repair effect of the tenant's response to security vulnerabilities reported by the public cloud platform.

[0108] The above network environment characteristics may include two aspects: network stability and network security situation. The network stability is evaluated by monitoring indicators such as packet loss rate, latency, and bandwidth fluctuation of the network used by the tenant. The security threat situation of the network where the tenant is located is analyzed in real time. For example, whether it is under external attack and whether it is in a high-risk network segment, etc.

[0109] Optionally, the digital certificate request of the above target object may be actively proposed by the target object, that is, the digital certificate request may be generated according to the digital certificate application of the target object. Of course, the digital certificate request of the above target object may be automatically generated when a preset trigger condition in the digital certificate distribution management system is met, that is, the digital certificate request may be generated when it is determined that the target object meets the preset digital certificate generation conditions.

[0110] Exemplarily, the above preset digital certificate generation conditions may include whether the digital certificate is about to expire and whether the permissions in the digital certificate need to be changed, etc. For example, if the expiration time of the target object's digital certificate is less than the set expiration time threshold (such as, 0.5 days), it can be determined that the target object's digital certificate is about to expire. For another example, assume that the digital certificate includes 3 operation permissions, which are: operation permission A, operation permission B, and operation permission C in sequence. If the server detects that the setting of operation permission C needs to be modified, a digital certificate request can be automatically generated.

[0111] Based on the above method, the server can not only generate a digital certificate request through the digital certificate application of the target object, but also generate a digital certificate request when the preset digital certificate generation conditions are met, improving the timeliness of the response to the digital certificate issuance, and thus improving the efficiency of subsequent digital certificate issuance.

[0112] S302: When it is determined that there is target object data with changed data among the multiple object data included in the object information, determine an estimated trust score of the target object based on the object information.

[0113] Taking the object information including five types of object data (in sequence: Obj.Data.1 to Obj.Data.5) as an example, after the server obtains the five types of object data (in sequence: Obj.Data.P1 to Obj.Data.P5) included in the object information of the target object at the current moment, it can obtain the five types of object data (in sequence: Obj.Data.H1 to Obj.Data.H5) of the previous historical moment adjacent to the current moment, compare them one by one, and obtain the data change situation of the five types of object data (that is, whether there is a change). Once it is determined that there is target object data in the five types of object data whose data has changed (for example, Obj.Data.1), the estimated value of the trust score of the target object at the current moment can be determined based on the object information, that is, the trust score of the target object is re-evaluated.

[0114] Conversely, if there is no target object data among the above-mentioned multiple types of object data (for example, five types of object data), the server can continuously obtain object information until there is target object data in the object information. In other words, if the object information has not changed, the server does not change the current listening state of the object information of the target object.

[0115] In an optional implementation manner, when performing step S302, when the server determines that there is target object data in the multiple types of object data included in the object information whose data has changed, it can perform data standardization processing on the above-mentioned multiple types of object data, so as to ensure the accuracy of subsequent digital certificate generation. And the server can also screen out at least one object data with a relatively high correlation with the trust score from the above-mentioned multiple types of object data, so as to re-determine the evaluation value of the trust score of the target object based on the above-mentioned at least one object data, further improving the efficiency of digital certificate issuance.

[0116] Exemplarily, refer to Figure 4 As shown, it is a schematic flowchart of the implementation process of a method for determining an evaluation value of a trust score provided by an embodiment of the present application. The execution subject is still taken as the server. The specific implementation process of this method is as follows:

[0117] S401: Perform data standardization processing on multiple types of object data included in the object information to obtain multiple types of object data after data standardization processing.

[0118] Based on the above method, by performing data standardization processing on the collected multiple types of object data, object data of different formats and different magnitudes can be converted into unified comparable and computable data. For example, the index data of various security protection capabilities are scored according to certain standards, so that various types of index data can participate in operations under the same evaluation system.

[0119] In an optional implementation manner, refer to Figure 5As shown, when executing step S401, the server can perform the following operations for any one of the at least one object data mentioned above, for example, the first object data: perform data cleaning processing on the first object data to obtain target object data; if the target object data is non-numeric data, perform numerical encoding on the target object data to obtain the target object data after numerical encoding. Among them, the target object data can be the first object data after data interpolation and / or abnormal data deletion processing. In other words, the server can complete the data cleaning processing for the first object data by performing data interpolation processing and / or abnormal data deletion processing on the first object data, thereby obtaining the target object data. In this way, not only can the missing values ​​in the first object data be interpolated and supplemented, but also the abnormal values ​​in the first object data can be eliminated, thereby improving the accuracy of the digital certificate. In addition, encoding the object data of non-numeric data also improves the efficiency of generating digital certificates.

[0120] It should be noted that the embodiments of the present application do not specifically limit the various data processing methods in the data cleaning process. For example, the above data interpolation method can be a majority interpolation method, and of course, it can also be other interpolation methods.

[0121] S402: Based on the correlation ranking order between the multiple object data and the trust scores, at least one object data satisfying a preset correlation ranking condition is screened out from the multiple object data after data standardization.

[0122] Exemplarily, when executing step S402, the server may determine the correlations between the various object data and the trust scores based on a preset correlation calculation method (e.g., Pearson correlation coefficient), thereby obtaining a correlation ranking order corresponding to the various object data according to the multiple correlations, and then screening out at least one object data satisfying the preset correlation ranking condition from the various object data after the data standardization processing. Optionally, the aforementioned preset correlation ranking condition may be: a set number of object data (e.g., 6) with relatively high correlations.

[0123] Based on the above method, by performing dimension screening on the preprocessed data (that is, the various object data after data standardization), redundant, low-relevance or irrelevant object data can be removed.

[0124] S403: Determine a trust score evaluation value based on at least one object data.

[0125] Exemplarily, when performing step S403, the server may input at least one type of object data filtered out into a pre-trained trust score evaluation model, so as to obtain the output result of the trust score evaluation model, and further determine the trust score evaluation value of the target object according to the output result. Optionally, the foregoing trust score evaluation model may be a multi-layer perceptron (MLP). Therefore, the foregoing at least one type of object data may be input into the input layer of the MLP, and the trust score is output through the output layer of the MLP. Among them, the trust score may take any value from 0 to 100.

[0126] Taking a public cloud tenant as the target object as an example, refer to Figure 6 As shown, it is a logical schematic diagram of trust score estimation based on an intelligent trust model provided by an embodiment of the present application. The server realizes the estimation of the trust score for the public cloud tenant through this intelligent trust model, which may specifically include: 1. Continuously monitor tenant information: The monitoring module continuously monitors the tenant information. 2. Determine whether the tenant information has changed: If the tenant information has not changed, the current monitoring state is not changed. If the tenant information has changed, enter the tenant information collection and preprocessing step. 3. Data dimension screening: Screen the dimensions of the preprocessed data to remove redundant or irrelevant data therein. 4. Input the screened data into the input layer of the MLP to obtain the final trust score output by the MLP. For example, the trust score of the target object is 95 points.

[0127] Optionally, the server may also establish a real-time data collection system to collect tenant information from modules such as a resource management module, a security monitoring module, and a network management module in the network environment and integrate it into a unified data warehouse.

[0128] Based on the above method, the intelligent trust model will actively monitor and collect multi-dimensional feature information of public cloud tenants and perform standardization processing on the data. Moreover, the intelligent trust model uses an MLP to process the standardized data, and finally obtains the trust score estimation value of the public cloud tenant. In addition, in the above process of evaluating the trust score, the MLP can be dynamically adjusted through a periodic re-evaluation mechanism and an event-triggered adjustment mechanism to achieve the purpose of accurately and finely predicting the trust score of the public cloud tenant. Therefore, adopting this intelligent trust model can effectively solve the problems of review and verification in the digital certificate application process, and improve the efficiency and reliability of digital certificate review.

[0129] S303: Generate a digital certificate for the target object based on the digital certificate template corresponding to the trust score estimation value, and issue the digital certificate to the target object.

[0130] Among them, the above digital certificate template can be used to indicate multiple operation permissions, and the embodiments of the present application do not specifically limit the types and quantities of the operation permissions indicated by the digital certificate template.

[0131] In an optional implementation manner, when performing step S303, after the server determines the estimated trust score of the target object, it can determine the target trust level of the target object according to the correspondence between the trust score and the trust level, thereby obtaining the digital certificate template set for the target trust level, and then adjusting the multiple operation permissions indicated by the digital certificate template based on the object information and the certificate request content included in the digital certificate request to obtain the digital certificate.

[0132] The above correspondence between the trust score and the trust level can be set by the server according to the score interval to which the trust score belongs. Exemplarily, taking 3 score intervals (in sequence: the first score interval, the second score interval, and the third score interval) as an example, the 3 score intervals and their respectively corresponding trust score ranges and trust levels are shown in Table 1.

[0133] Table 1 Example of score interval and its corresponding trust score range and trust level

[0134] Score range The first score range The second score range The third score range Trust score range [0,30) [30,70) [70,100] Trust level I II III

[0135] Based on the correspondence between the score interval, the trust score range, and the trust level recorded in the above table, after the server obtains the estimated trust score of the target object, it can quickly determine the score interval to which the estimated trust score belongs, thereby determining the target trust level of the target object. For example, assuming that the estimated trust score of the target object is 86, the server can quickly determine the target trust level of the target object as: III based on the correspondence recorded in Table 1.

[0136] It can be understood that the above trust level I, trust level II, and trust level III can be referred to as low trust level, medium trust level, and high trust level, and the digital certificate templates respectively corresponding to the above 3 trust levels can be referred to as low trust level certificate template, medium trust level certificate template, and high trust level certificate template. The embodiments of the present application do not limit this.

[0137] In addition, the above certificate request content may include the validity period of the digital certificate and the permission scope of the digital certificate, etc.

[0138] Exemplarily, when the server adjusts various operation permissions indicated by the digital certificate template based on the object information and the certificate request content included in the digital certificate request, it can adjust the various operation permissions indicated by the digital certificate template according to the object data related to the business scenario and security included in the object information. In other words, after determining the digital certificate template of the target object, the server can further refine and adjust the operation permissions in the digital certificate template in combination with the current business scenario and business development needs of the target object. For example, although the target object is at a medium trust level (i.e., trust level II), it is participating in a temporary but important project that has short-term high-privilege resource access requirements. On the premise of strict review and clear definition of the project scope, the server can temporarily elevate some permissions for the target object so that the target object can access relevant important resources during the project cycle and then restore the original permission configuration after the project ends.

[0139] At the same time, the server can also comprehensively weigh various aspects of the target object from a security perspective to adjust the permissions of the digital certificate. For example, if there have been certain security fluctuations in the network environment where the target object is located recently, even if its original trust level is relatively high, its access permissions to some sensitive resources may be appropriately restricted until the network environment returns to stability and the trust level is re-evaluated before making adjustments, ensuring that the permissions in the certificate always match the actual security status and trust level of the target object.

[0140] In this way, by combining the business scenario and security factors, the operation permissions of the digital certificate template of the target object are refined or differentiated. Among them, when considering the business scenario, first determine the key business path and business cycle of the tenant, and different business levels are given different certificate validity periods and certificate permissions; then, when considering security factors (such as business security level), associate the security factors with the certificate validity period and certificate permissions. Therefore, by refining the adjustment of the digital certificate template, it is ensured that the finally generated digital certificate highly matches the target object.

[0141] During the process of generating the digital certificate, the server can determine the detailed parameters of the digital certificate to be finally distributed to the target object based on the settings and adjustments of the certificate permission scope and validity period in the above steps, including key information such as the list of accessible resources, the types of executable operations, and the specific start and end times of the digital certificate's validity period, that is, determine the complete certificate distribution configuration list. After the server determines the certificate distribution configuration list, it can generate a digital certificate that meets the differentiated needs of the target object according to the preset digital certificate generation mechanism.

[0142] It is understandable that during the generation process of a digital certificate, it is necessary to ensure that corresponding permission information, validity period information, identity identifiers of the target object, etc. are embedded in the digital certificate to make it unique and legal.

[0143] Optionally, the server can be deeply integrated with systems such as the resource management system and identity authentication system in the network scenario, so as to automatically distribute the generated digital certificate to the specified locations such as the resource account corresponding to the target object or the device terminal, thereby ensuring that the target object can obtain the digital certificate. Moreover, before the digital certificate is issued, compliance detection and accuracy detection of the digital certificate can also be performed according to the preset certificate detection method.

[0144] Still taking the public cloud tenant as the target object as an example, refer to Figure 7 as shown, which is a logical schematic diagram of the generation and distribution of digital certificates based on a differential distribution module provided by an embodiment of this application. As Figure 6 shown, after the monitoring module in the intelligent trust model detects that the digital certificate of the public cloud tenant is about to expire, the differential distribution module can enter the process of obtaining the tenant trust score. The server can specifically execute the following processes through this digital certificate differential distribution module: 1. Trust score acquisition: Obtain the estimated value of the trust score of the public cloud tenant by calling Figure 6 the intelligent trust model shown. 2. Obtain certificate templates: Obtain digital certificate templates set for different trust scores respectively. 3. Certificate template matching: Determine the digital certificate template that matches the aforementioned estimated trust score value from multiple digital certificate templates according to the corresponding relationship between the trust score and the digital certificate template. 4. Certificate refinement adjustment: The matched digital certificate can be refined and adjusted according to the digital certificate request and the tenant information of this public cloud tenant. Among them, the adjustment content includes but is not limited to: the operation permissions indicated by the digital certificate and the validity period of the digital certificate. 5. Distribution certificate confirmation: Confirm before distributing the refined and adjusted digital certificate to ensure the accuracy and compliance of the digital certificate. 6. Automatically distribute the certificate: The digital certificate can be distributed to this public cloud tenant and related entities under this public cloud tenant through the digital certificate distribution module.

[0145] Based on the above method, the automated distribution module can actively obtain the estimated trust score of public cloud tenants, select a suitable digital certificate template according to the estimated trust score and refine it, and then automatically distribute the generated digital certificate to the corresponding public cloud tenant. Among them, the certificate refinement can be carried out in combination with the business scenario and security factors, and finally realize the fine-grained control of the automatic distribution of digital certificates, ensuring that tenants with different trust levels automatically obtain the digital certificates that best suit their own trust levels (or estimated trust scores). Therefore, the differential distribution module cooperates with the intelligent trust model to differentially distribute digital certificates, thereby finely controlling the digital certificate distribution process and enhancing the security of digital certificate distribution, and then cooperating with the digital certificate distribution module to achieve the purpose of automatic certificate distribution.

[0146] Therefore, referring to Figure 8 As shown, it is a logical schematic diagram of digital certificate issuance provided by an embodiment of the present application. Still taking the public cloud scenario as an example, after a public cloud tenant applies for a digital certificate or automatically triggers a digital certificate application, the server can obtain the current tenant information (i.e., object information) of the public cloud tenant. The tenant information can include data in multiple dimensions such as tenant basic information, historical behavior records, security protection capabilities, and network environment characteristics. Then, the tenant information can be evaluated through the intelligent trust model, and finally the trust score of the public cloud tenant can be obtained. Furthermore, after the certificate management center obtains the trust score, it can decide whether to distribute digital certificates for the digital certificate application. Further, when it is determined that digital certificates need to be distributed for the digital certificate application, the differential distribution module can select a suitable digital certificate template according to the trust score, and generate the digital certificate of the public cloud tenant by fine-tuning the digital certificate template, and then call the digital certificate distribution module to distribute the digital certificate to the public cloud tenant. Finally, the digital certificate distribution module executes the digital certificate distribution operation and distributes the digital certificate to the corresponding public cloud tenant entities, such as "tenant 01", "tenant 02",..., "tenant n".

[0147] It can be seen that an automatic digital certificate distribution management solution integrating an intelligent trust model provided by an embodiment of the present application audits and verifies digital certificate applications through the intelligent trust model and realizes an efficient and fine-grained digital certificate distribution process through a differential distribution strategy, effectively improving the management efficiency and security level of digital certificates.

[0148] In an alternative implementation, during the process of the server distributing the digital certificate to the target object, the server can also obtain the configuration information corresponding to the digital certificate, and thus synchronize the configuration information to the target object. Among them, the aforementioned configuration information can be used to deploy the digital certificate locally on the target object. When distributing the digital certificate, the configuration information related to the digital certificate is synchronized to the usage environment of the target object. For example, operations such as automatically installing the certificate and configuring relevant access policies are completed locally on the target object, enabling the target object to smoothly use the digital certificate to carry out corresponding business activities within its authority scope in the network scenario, realizing an end-to-end automated configuration process, and reducing errors and delays that may be brought by manual intervention.

[0149] In addition, during the process of the target object using the digital certificate, the server can also perform continuous monitoring and dynamic adjustment. That is, during the process of the target object using the digital certificate, the server continuously monitors the various aspects of the target object in real time, including but not limited to: resource access behavior, network security status, whether there are abnormal operations, etc., collects relevant data and feeds it back to the server (such as, an intelligent trust model), so as to timely detect factors that may affect the trust score and the secure use of the digital certificate. Once a condition for triggering a re-evaluation occurs (such as, the regular evaluation time arrives, a specific security event occurs, abnormal behavior, etc.), the trust score evaluation process is immediately restarted. According to the new trust score estimate, in accordance with the process of the above-mentioned differential distribution strategy, parameters such as the digital certificate authority scope and certificate validity period of the target object are dynamically adjusted. For example, reducing the certificate authority of the target object with a decreased trust level, shortening the certificate validity period of the target object with potential security risks, etc., to ensure that the target object always uses the digital certificate within a security range consistent with its trust score and guarantee the secure use of the digital certificate.

[0150] It can be understood that the dynamic adjustment of the digital certificate by the server can include the following three mechanisms: 1. Regular re-adjustment mechanism: Set a fixed adjustment period to re-evaluate the trust score of the target object. Even if the target object performs stably in all aspects during a certain period, as time goes by, the business development, security status, etc. of the target object may change. Through regular evaluation, these changes can be captured in a timely manner and the trust score can be adjusted. 2. Event-triggered adjustment mechanism: When specific security events, business change events, etc. occur, immediately trigger the re-evaluation and adjustment of the trust score. For example, when the target object completes a major business upgrade, expands new business modules and correspondingly improves the security configuration, the trust score is triggered to increase, and consider whether to allocate a digital certificate with higher authority to it. 3. Real-time monitoring and gradual adjustment mechanism: Real-time monitor the network security indicators of the target object. When there are minor fluctuations in the object information of the target object but do not reach the threshold for triggering a major adjustment, fine-tune the trust score of the target object according to certain gradual rules.

[0151] In summary, in the digital certificate issuance method provided by the embodiments of the present application, in response to a digital certificate request of a target object, object information of the target object is obtained; wherein, the object information includes various object data for evaluating the trust score of the target object; then, when it is determined that there is target object data with changed data among the various object data included in the object information, an estimated value of the trust score of the target object is determined based on the object information; finally, a digital certificate of the target object is generated based on the digital certificate template corresponding to the estimated trust score, and the digital certificate is issued to the target object; wherein, the digital certificate template is used to indicate various operation permissions. In this way, there is no need for manual review of the digital certificate application and issuance process, realizing efficient and fine-grained automatic distribution management of digital certificates, greatly reducing the time cost and labor cost required for digital certificate issuance, and improving the efficiency of digital certificate issuance; moreover, due to less manual participation, the security of digital certificates is ensured.

[0152] Furthermore, based on the same technical concept, the embodiments of the present application provide a digital certificate issuance device, and this digital certificate issuance device is used to implement the above method flow of the embodiments of the present application. Refer to Figure 9 As shown, this digital certificate issuance device 900 includes: an information acquisition module 901, a score evaluation module 902, and a certificate issuance module 903, where:

[0153] The information acquisition module 901 is configured to obtain object information of a target object in response to a digital certificate request of the target object; wherein, the object information includes: various object data for evaluating the trust score of the target object;

[0154] The score evaluation module 902 is configured to determine an estimated value of the trust score of the target object based on the object information when it is determined that there is target object data with changed data among the various object data included in the object information;

[0155] The certificate issuance module 903 is configured to generate a digital certificate of the target object based on the digital certificate template corresponding to the estimated trust score, and issue the digital certificate to the target object; wherein, the digital certificate template is used to indicate various operation permissions.

[0156] In an optional embodiment, the digital certificate request is generated by the information acquisition module 901 according to the digital certificate application of the target object; or,

[0157] The digital certificate request is generated by the information acquisition module 901 when it is determined that the target object meets the preset digital certificate generation conditions.

[0158] In an optional embodiment, the information acquisition module 901 is further configured to:

[0159] If the target object data does not exist in multiple object data, continuously obtain object information until the target object data exists in the object information.

[0160] In an alternative embodiment, when determining the estimated value of the trust score of the target object based on the object information, the score evaluation module 902 is specifically configured to:

[0161] Perform data standardization processing on multiple object data included in the object information to obtain multiple object data after data standardization processing;

[0162] Based on the order of the relevance between multiple object data and the trust score, filter out at least one object data that meets the preset relevance sorting condition from the multiple object data after data standardization processing;

[0163] Determine the trust score evaluation value based on at least one object data.

[0164] In an alternative embodiment, when performing data standardization processing on multiple object data included in the object information to obtain multiple object data after data standardization processing, the score evaluation module 902 is specifically configured to:

[0165] For at least one object data, perform the following operations respectively:

[0166] Perform data cleaning processing on the first object data to obtain the target object data; wherein, the first object data is any one of at least one object data, and the target object data is the first object data after data interpolation and / or abnormal data deletion processing;

[0167] If the target object data is non-numerical data, perform numerical encoding on the target object data to obtain the target object data after numerical encoding.

[0168] In an alternative embodiment, when generating the digital certificate of the target object based on the digital certificate template corresponding to the estimated trust score, the certificate issuance module 903 is specifically configured to:

[0169] Determine the target trust level of the target object based on the estimated trust score value, and obtain the digital certificate template set for the target trust level;

[0170] Based on the object information and the certificate request content included in the digital certificate request, adjust the multiple operation permissions indicated by the digital certificate template to obtain the digital certificate.

[0171] In an alternative embodiment, during the process of issuing the digital certificate to the target object, the certificate issuance module 903 is further configured to:

[0172] Obtain the configuration information corresponding to the digital certificate; the configuration information is used to deploy the digital certificate locally on the target object;

[0173] Synchronize the configuration information to the target object.

[0174] Based on the descriptions of the above method embodiments and apparatus embodiments, an exemplary embodiment of the present invention further provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, it is used to cause the electronic device to execute the method according to the embodiments of the present invention.

[0175] An embodiment of the present application further provides a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor of a computer, is used to cause the computer to execute the method according to the embodiments of the present application.

[0176] An embodiment of the present application further provides a computer program product, including a computer program, wherein the computer program, when executed by a processor of a computer, is used to cause the computer to execute the method according to the embodiments of the present application.

[0177] Refer to Figure 10 As shown, the following will describe the structural block diagram of the electronic device 1000 that can be used as the server or client of the present application, which is an example of a hardware device applicable to various aspects of the present application. The electronic device is intended to represent various forms of digital electronic computer devices, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described herein and / or claimed.

[0178] As Figure 10As shown, the electronic device 1000 includes a computing unit 1001, which can perform various appropriate actions and processes according to a computer program stored in a read only memory (ROM) 1002 or a computer program loaded from a storage unit 1008 into a random access memory (RAM) 1003. In the RAM 1003, various programs and data required for the operation of the device 1000 can also be stored. The computing unit 1001, the ROM 1002, and the RAM 1003 are connected to each other via a bus 1004. An input / output (I / O) interface 1005 is also connected to the bus 1004.

[0179] A plurality of components in the electronic device 1000 are connected to the I / O interface 1005, including: an input unit 1006, an output unit 1007, a storage unit 1008, and a communication unit 1009. The input unit 1006 can be any type of device capable of inputting information into the electronic device 1000. The input unit 1006 can receive input numerical or character information, and generate key signal inputs related to user settings and / or function controls of the electronic device. The output unit 1007 can be any type of device capable of presenting information, and can include but is not limited to a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 1008 can include but is not limited to a magnetic disk, an optical disk. The communication unit 1009 allows the electronic device 1000 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks, and can include but is not limited to a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth device, a WiFi device, a worldwide interoperability for microwave access (WiMax) device, a cellular communication device, and / or the like.

[0180] The computing unit 1001 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 1001 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 1001 executes the various methods and processes described above. For example, in some embodiments, the above digital certificate issuance method can be implemented as a computer software program that is tangibly included in a machine-readable medium, such as the storage unit 1008. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 1000 via the ROM 1002 and / or the communication unit 1009. In some embodiments, the computing unit 1001 can be configured to execute the above digital certificate issuance method in any other suitable manner (e.g., by means of firmware).

[0181] The program code for implementing the method of the present application can be written in any combination of one or more programming languages. These program codes can be provided to the processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, executed partially on the machine and partially on a remote machine as an independent software package, or executed entirely on a remote machine or server.

[0182] In the context of this application, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM) or flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0183] As used in this application, the terms “machine-readable medium” and “computer-readable medium” refer to any computer program product, apparatus, and / or device (e.g., a disk, optical disk, memory, programmable logic device (PLD)) that provides machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term “machine-readable signal” refers to any signal that provides machine instructions and / or data to a programmable processor.

[0184] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a cathode ray tube (CRT) or a liquid crystal display (LCD) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0185] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0186] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs that run on the respective computers and have a client-server relationship with each other.

[0187] Also, it should be understood that the above-disclosed is only a preferred embodiment of the present application, and of course it cannot be used to limit the scope of the rights of the present invention. Therefore, equivalent changes made according to the claims of the present invention are still within the scope covered by the present application.

Claims

1. A method for issuing a digital certificate, characterized in that: include: In response to a digital certificate request of a target object, obtaining object information of the target object; wherein the object information includes: a plurality of object data for evaluating a trust score of the target object; When it is determined that there is target object data with data changes among the multiple types of object data included in the object information, determining a trust score estimation value of the target object based on the object information; A digital certificate of the target object is generated based on a digital certificate template corresponding to the trust score estimation value, and the digital certificate is issued to the target object; wherein the digital certificate template is used to indicate multiple operation permissions.

2. The method according to claim 1, characterized in that The digital certificate request is generated according to the digital certificate application of the target object; or The digital certificate request is generated when it is determined that the target object meets the preset digital certificate generation conditions.

3. The method according to claim 1, characterized in that The method further comprises: If the target object data does not exist in the plurality of object data, the object information is continuously acquired until the target object data exists in the object information.

4. The method according to any one of claims 1 to 3, characterized in that The determining the trust score estimation value of the target object based on the object information includes: Performing data standardization processing on the multiple object data included in the object information to obtain the multiple object data after data standardization processing; Based on the order of relevance between the multiple object data and the trust scores, at least one object data satisfying a preset relevance ranking condition is screened out from the multiple object data after the data standardization process; The trust score evaluation value is determined based on the at least one object data.

5. The method according to claim 4, characterized in that The performing data standardization processing on the multiple object data included in the object information to obtain the multiple object data after data standardization processing includes: For the at least one object data, the following operations are performed respectively: Performing data cleaning processing on the first object data to obtain target object data; wherein the first object data is any one of the at least one object data, and the target object data is the first object data after data interpolation and / or abnormal data deletion processing; If the target object data is non-numeric data, numerical encoding is performed on the target object data to obtain the numerically encoded target object data.

6. The method according to any one of claims 1 to 3, characterized in that The step of generating the digital certificate of the target object based on the digital certificate template corresponding to the trust score estimation value includes: Determining a target trust level of the target object based on the trust score estimate, and obtaining a digital certificate template set for the target trust level; Based on the object information and the certificate request content included in the digital certificate request, the multiple operation permissions indicated by the digital certificate template are adjusted to obtain the digital certificate.

7. The method according to any one of claims 1 to 3, characterized in that The process of issuing the digital certificate to the target object further includes: Acquire configuration information corresponding to the digital certificate; the configuration information is used to deploy the digital certificate locally on the target object; The configuration information is synchronized to the target object.

8. A digital certificate issuing device, characterized in that: include: An information acquisition module, configured to acquire object information of a target object in response to a digital certificate request of the target object; wherein the object information includes: a plurality of object data for evaluating a trust score of the target object; a score evaluation module, configured to determine a trust score estimation value of the target object based on the object information when it is determined that there is target object data with data changes among the multiple object data included in the object information; A certificate issuing module is used to generate a digital certificate of the target object based on a digital certificate template corresponding to the trust score estimation value, and issue the digital certificate to the target object; wherein the digital certificate template is used to indicate multiple operation permissions.

9. An electronic device, comprising: processor; as well as Memory for storing programs, The program includes instructions, which, when executed by the processor, cause the processor to perform the method according to any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 7.