Certificate presetting method and device, electronic equipment, storage medium and program product
Through communication based on layer two networks, identifying the certificate equipment to be pre-installed and automatically applying for certificates, the problem of low certificate distribution efficiency is solved, and efficient and accurate certificate pre-setting is achieved.
Patent Information
- Application Number
- CN202510223794.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-17
AI Technical Summary
In the prior art, the efficiency of certificate distribution is low, which makes it difficult to guarantee the identity legitimacy and data security of the equipment in the network environment.
Through communication based on the second-layer network, new certificate devices to be pre-installed are identified, requests for application documents are sent to the device, application documents are generated, and sent to the authentication server. The certification server receives application documents and equipment identification information, stores the corresponding relationship, applies for a certificate from the certificate authority, and sends the issued certificate to the corresponding certificate device to be pre-installed for pre-installation.
It greatly improves the efficiency of certificate distribution without manual intervention, avoids manual import and configuration errors, and improves the accuracy and efficiency of certificate presetting.
Smart Images

Figure CN120165873A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network communication technologies, and in particular, to a method, device, electronic device, storage medium, and program product for pre-setting certificates. Background Art
[0002] In order to ensure the legality and validity of the identity of a device in a network environment and protect data security, etc., it is necessary to pre-set a certificate issued by a national certificate issuing authority before the device leaves the factory.
[0003] In the related art, mainly a network administrator manually configures and imports a certificate before the device leaves the factory, resulting in low certificate distribution efficiency. Summary of the Invention
[0004] Embodiments of the present invention provide a method, device, electronic device, storage medium, and program product for pre-setting certificates to solve the problem of low certificate distribution efficiency in the prior art.
[0005] In a first aspect, an embodiment of the present invention provides a method for pre-setting a certificate, which is applied to an authentication server. The method includes: identifying a newly added device to be pre-set with a certificate based on communication in a layer-2 network, and sending a request for a soliciting application file to the newly added device to be pre-set with a certificate; wherein, the newly added device to be pre-set with a certificate communicates with the authentication server through a layer-2 network protocol; the request for a soliciting application file is used to instruct the newly added device to be pre-set with a certificate to generate an application file; receiving the application file and device identification information sent by the newly added device to be pre-set with a certificate, and storing the corresponding relationship between the newly added device to be pre-set with a certificate and the device identification information in a device information table; wherein, the application file is used to apply for a certificate from a certificate issuing authority; obtaining the certificate issued by the certificate issuing authority, parsing the certificate, and determining first device identification information in the certificate; based on the device information table, determining a first device to be pre-set with a certificate corresponding to the first device identification information, and sending the certificate to the first device to be pre-set with a certificate, so that the first device to be pre-set with a certificate pre-sets the certificate after receiving it.
[0006] In some embodiments, the identifying a newly added device to be pre-set with a certificate based on communication in a layer-2 network includes: in response to receiving a layer-2 network broadcast message sent by a first device, determining whether the first device is accessing for the first time; wherein, the first device is a device in a production environment, and the layer-2 network broadcast message is sent after the first device accesses the layer-2 network; if the first device is accessing for the first time, determining the first device as the newly added device to be pre-set with a certificate.
[0007] In some embodiments, determining whether the first device is accessing for the first time includes: if the first device is not included in the device information table, determining that the first device is accessing for the first time; if the first device is included in the device information table, determining that the first device is not accessing for the first time.
[0008] In some embodiments, sending the certificate to the first device to be preconfigured with the certificate includes: determining whether the first device to be preconfigured with the certificate is in an online state based on a heartbeat message between the first device to be preconfigured with the certificate and the authentication server; if the first device to be preconfigured with the certificate is in an online state, sending the certificate to the first device to be preconfigured with the certificate; if the first device to be preconfigured with the certificate is in an offline state, monitoring the state of the first device to be preconfigured with the certificate until the state of the first device to be preconfigured with the certificate is switched to the online state, and then sending the certificate to the first device to be preconfigured with the certificate.
[0009] As a possible implementation, the method further includes: after receiving the application file sent by the newly added device to be preconfigured with the certificate, setting the certificate status of the newly added device to be preconfigured with the certificate to "applying"; before sending the certificate to the first device to be preconfigured with the certificate, setting the certificate status of the first device to be preconfigured with the certificate to "to be sent"; after sending the certificate to the first device to be preconfigured with the certificate, if receiving the preconfiguration success information sent by the first device to be preconfigured with the certificate, setting the certificate status of the first device to be preconfigured with the certificate to "preconfigured successfully"; if receiving the preconfiguration failure information sent by the first device to be preconfigured with the certificate, setting the certificate status of the first device to be preconfigured with the certificate to "preconfiguration failed"; where the preconfiguration success information is a message sent by the first device to be preconfigured with the certificate after successfully preconfiguring the received certificate; the preconfiguration failure information is a message sent by the first device to be preconfigured with the certificate after failing to preconfigure the received certificate. In some embodiments, the method further includes: displaying in real time, on the display interface, a list of all devices to be preconfigured with the certificate in the device information table and the certificate status of each device to be preconfigured with the certificate.
[0010] In a second aspect, an embodiment of the present invention provides a pre-set certificate device, which is applied to an authentication server. The device includes: an identification module, configured to identify a newly added device to be pre-set with a certificate based on communication in a layer-2 network, and send a request for requesting an application file to the newly added device to be pre-set with a certificate; wherein the newly added device to be pre-set with a certificate communicates with the authentication server through a layer-2 network protocol; the request for requesting an application file is used to instruct the newly added device to be pre-set with a certificate to generate an application file; a receiving module, configured to receive the application file and device identification information sent by the newly added device to be pre-set with a certificate, and store the correspondence between the newly added device to be pre-set with a certificate and the device identification information in a device information table; wherein the application file is used to apply for a certificate from a certificate issuing authority; an analysis module, configured to obtain the certificate issued by the certificate issuing authority, analyze the certificate, and determine first device identification information in the certificate; a sending module, configured to determine a first device to be pre-set with a certificate corresponding to the first device identification information based on the device information table, and send the certificate to the first device to be pre-set with a certificate, so that the first device to be pre-set with a certificate pre-sets the certificate after receiving it.
[0011] In a third aspect, an embodiment of the present invention provides an electronic device, including a processor and a memory storing a computer program, and when the processor executes the program, the above-mentioned pre-set certificate method is implemented.
[0012] In a fourth aspect, an embodiment of the present invention provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the above-mentioned pre-set certificate method is implemented.
[0013] In a fifth aspect, an embodiment of the present invention provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above-mentioned pre-set certificate method is implemented.
[0014] The pre - installed certificate method, device, electronic device, storage medium and program product provided by the embodiments of the present invention are based on communication in a two - layer network to identify newly added devices to be pre - installed with certificates, and send a request for requesting application files to the newly added devices to be pre - installed with certificates; wherein, the newly added devices to be pre - installed with certificates communicate with the authentication server through a two - layer network protocol; the request for requesting application files is used to instruct the newly added devices to be pre - installed with certificates to generate application files; receive the application files and device identification information sent by the newly added devices to be pre - installed with certificates, and store the correspondence between the newly added devices to be pre - installed with certificates and the device identification information in the device information table; wherein, the application files are used to apply for certificates from the certificate issuing authority; obtain the certificates issued by the certificate issuing authority, parse the certificates, and determine the first device identification information in the certificates; based on the device information table, determine the first device to be pre - installed with the certificate corresponding to the first device identification information, and send the certificates to the first device to be pre - installed with the certificate, so that the first device to be pre - installed with the certificate can pre - install the certificates after receiving them. The present invention realizes the distribution and pre - installation of certificates based on the two - layer network communication between the device and the authentication server, can greatly improve the efficiency of pre - installing certificates without manual intervention, and also avoid configuration errors caused by manual import, thus greatly improving the accuracy of pre - installing certificates. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1 One of the flow diagrams of the pre - installed certificate method provided by the embodiments of the present invention; Figure 2 Another flow diagram of the pre - installed certificate method provided by the embodiments of the present invention; Figure 3 One of the flow diagrams of the pre - installed certificate method proposed by the embodiments of the present invention; Figure 4 Another flow diagram of the pre - installed certificate method proposed by the embodiments of the present invention; Figure 5 The structural diagram of the pre - installed certificate device provided by the embodiments of the present invention; Figure 6 The structural diagram of the electronic device provided by the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the protection scope of the present invention.
[0018] To ensure the legality and validity of the identity of the device in the network environment and safeguard data security, etc., it is necessary to pre-install the certificate issued by the national certificate authority before the device leaves the factory.
[0019] In the related art, mainly the network administrator manually configures and imports the certificate before the device leaves the factory. Manual import and configuration not only take time and effort, but also are prone to configuration errors. Especially in the case of a large number of devices, the error rate is relatively high, and there is a lack of sufficient security guarantee. In the case of a wide variety of device types, the matching and distribution efficiency of the certificate is relatively low, and the matching verification of the device identity and the certificate cannot be realized, resulting in a lack of security.
[0020] To solve the above problems, an embodiment of the present invention provides a method, device, electronic device, storage medium, and program product for pre-installing a certificate.
[0021] Figure 1 FIG. 1 is one of the schematic flowcharts of the method for pre-installing a certificate provided by an embodiment of the present invention. As Figure 1 shown, the method may include the following steps.
[0022] Step 101, based on the communication of the second-layer network, identify the newly added device to be pre-installed with a certificate, and send a request for a solicitation application file to the newly added device to be pre-installed with a certificate; wherein, the newly added device to be pre-installed with a certificate communicates with the authentication server through the second-layer network protocol; the request for a solicitation application file is used to instruct the newly added device to be pre-installed with a certificate to generate an application file.
[0023] It should be noted that in the embodiments of the present invention, the devices that need to be pre-installed with certificates are all devices that have not left the factory, that is, devices in the production environment. The devices to be pre-installed with certificates may be Internet of Things devices (such as smart meters, industrial sensors, smart home devices, etc.), communication devices (such as base stations, routers, switches, gateway devices, etc.), and terminal devices (smartphones, tablets, etc.). By pre-installing the certificate, identity authentication can be performed to ensure the communication security of the device. The pre-installed certificate can support encryption protocols such as HTTPS and TLS to ensure the security of data (such as user privacy and industrial data) transmission.
[0024] Since the unshipped devices do not have IP addresses yet, in order to establish a communication connection between the devices and the authentication server, the embodiments of the present invention establish a communication connection through a layer-2 network, which can not only achieve the connection between the devices and the authentication server, but also simplify the network environment.
[0025] Among them, the authentication server refers to the server that acts as an agent for certificate distribution. The authentication server and the device to be preconfigured with a certificate communicate with each other through a layer-2 network.
[0026] In some embodiments, during the production process, if some devices are in the stage of preconfiguring certificates, these devices can be connected to the layer-2 network where the authentication server is located. Through communication based on the layer-2 network, the authentication server can identify the newly connected devices to be preconfigured with certificates and send a request for the application file to the newly added devices to be preconfigured with certificates. After the device receives the request for the application file, it generates an application file and sends the application file to the authentication server. Among them, the application file refers to the file used for certificate application, such as CSR (Certificate Signing Request).
[0027] As a possible implementation, based on the communication of the layer-2 network, identifying the newly added devices to be preconfigured with certificates may include: receiving the layer-2 network broadcast packet sent by the first device and sending the MAC address of the authentication server to the first device; where the first device is a device in the production environment, and the layer-2 network broadcast packet is sent after the first device accesses the layer-2 network; receiving the device identification information sent by the first device; where the first device sends the device identification information to the authentication server after receiving the MAC address of the authentication server; based on the device identification information and the list of devices that have applied for certificates stored, determining whether the first device has applied for a certificate; if the first device has not applied for a certificate, determining the first device as the newly added device to be preconfigured with a certificate.
[0028] As another possible implementation, based on the communication of the layer-2 network, identifying the newly added devices to be preconfigured with certificates may include: in response to receiving the layer-2 network broadcast packet sent by the first device, determining whether the first device is accessing for the first time; where the first device is a device in the production environment, and the layer-2 network broadcast packet is sent after the first device accesses the layer-2 network; if the first device is accessing for the first time, determining the first device as the newly added device to be preconfigured with a certificate.
[0029] For example, after the first device accesses the layer 2 network, it sends a layer 2 network broadcast message. After receiving the layer 2 network broadcast message, the authentication server sends its own MAC address to the first device and generates an access record based on the MAC address of the first device. Based on the access record table, if there is only one access record of the first device, it is determined that the first device accesses for the first time, and the first device is determined as a newly added device to be pre-configured with a certificate.
[0030] In some embodiments, based on step 102, after receiving the application file and device identification information sent by the newly added device to be pre-configured with a certificate, the corresponding relationship between the newly added device to be pre-configured with a certificate and the device identification information is stored in the device information table, that is, the device information table stores the corresponding relationship between all devices to be pre-configured with a certificate and their device identification information. If a device and its corresponding device identification information have been stored in the device information table, it can be determined that the certificate of the device has entered the application process. Therefore, the implementation process of determining whether the first device accesses for the first time can be: query whether the device information table contains the first device; if the device information table does not contain the first device, determine that the first device accesses for the first time; if the device information table contains the first device, determine that the first device does not access for the first time. Among them, the device information table can store the corresponding relationship between the MAC address of the device to be pre-configured with a certificate and the device identification information. When querying whether the first device is in the device information table, it can be queried based on the MAC address of the first device or based on the device identification information of the first device.
[0031] It should be noted that the number of newly added devices to be pre-configured with a certificate can be one or multiple. Based on the communication of the layer 2 network, the process of identifying newly added devices to be pre-configured with a certificate can be executed each time a layer 2 network broadcast message is received. If the number of newly added devices to be pre-configured with a certificate is multiple, a request for the application file can be sent to multiple newly added devices to be pre-configured with a certificate simultaneously.
[0032] Step 102: Receive the application file and device identification information sent by the newly added device to be pre-configured with a certificate, and store the corresponding relationship between the newly added device to be pre-configured with a certificate and the device identification information in the device information table; wherein, the application file is used to apply for a certificate from the certificate issuing authority.
[0033] In some embodiments, after receiving the request for the application file, the newly added device to be pre-configured with a certificate generates an application file, generates and stores a private key, and sends the generated application file to the authentication server. The device identification information of the newly added device to be pre-configured with a certificate can be the information carried by the newly added device to be pre-configured with a certificate each time it sends information, or can be directly sent to the authentication server after receiving the MAC address feedback from the authentication server. The device identification information can be the unique device identification information of the newly added device to be pre-configured with a certificate.
[0034] In some embodiments, the application file and the device identification information may not be received simultaneously. Whether it is the application file or the device identification information received first, in order to ensure that the device information stored in the device information table includes all the devices that have entered the pre-set certificate process, after receiving the application file sent by the newly added device to be pre-set with a certificate, the step of storing the corresponding relationship between the newly added device to be pre-set with a certificate and the device identification information into the device information table is then executed.
[0035] Among them, storing the corresponding relationship between the newly added device to be pre-set with a certificate and the device identification information into the device information table may be storing the corresponding relationship between the MAC address of the newly added device to be pre-set with a certificate and the device identification information into the device information table.
[0036] After receiving the application file of the newly added device to be pre-set with a certificate, the authentication server can directly apply for a certificate from the certificate issuing authority based on this application file, or relevant staff can export the application file and submit it offline to the certificate issuing authority to apply for a certificate.
[0037] Step 103: Obtain the certificate issued by the certificate issuing authority, parse the certificate, and determine the first device identification information in the certificate.
[0038] In some embodiments, after issuing the certificate, the certificate issuing authority can directly send the certificate to the authentication server, or send the issued certificate to the management staff, and the management staff uploads the issued certificates to the authentication server in batches.
[0039] Since the device identification information is carried in the certificate issued by the certificate issuing authority, the device to be pre-set with a certificate can be determined based on the device identification information carried in the certificate, so as to send the certificate to its corresponding device to be pre-set with a certificate.
[0040] In some embodiments, the number of certificates obtained each time can be one or multiple. If the number of certificates obtained is multiple, each certificate can be parsed separately to determine the first device identification information in each certificate. Among them, the process of parsing the certificate to obtain the first device identification information in the certificate can be implemented through relevant parsing tools or parsing interfaces.
[0041] Step 104: Based on the device information table, determine the first device to be pre-set with a certificate corresponding to the first device identification information, and send the certificate to the first device to be pre-set with a certificate, so that the first device to be pre-set with a certificate pre-sets the certificate after receiving it.
[0042] The device information table stores the MAC addresses of all devices to be pre-configured with certificates and their corresponding device identification information. Therefore, based on the device information table, the first MAC address of the first device to be pre-configured with a certificate corresponding to the first device identification information can be determined. According to the first MAC address, the certificate is sent to the first device to be pre-configured with a certificate. After receiving the certificate, the first device to be pre-configured with a certificate imports the certificate to achieve the pre-configuration of the certificate.
[0043] Among them, since the number of certificates obtained each time can be multiple, the number of the first devices to be pre-configured with certificates can also be multiple. The authentication server sends the certificates to the first devices to be pre-configured with certificates in parallel.
[0044] In some embodiments of the present invention, since the authentication server stores the device information table and can store the correspondence between the devices to be pre-configured with certificates and the device identification information, the devices to be pre-configured with certificates corresponding to each certificate can be determined based on the device identification information in the certificate, thereby greatly improving the efficiency and accuracy of certificate distribution.
[0045] According to the method for pre-configuring certificates according to the embodiments of the present invention, based on the communication of the second-layer network, a newly added device to be pre-configured with a certificate is identified, and a request for a request file is sent to the newly added device to be pre-configured with a certificate; wherein, the newly added device to be pre-configured with a certificate communicates with the authentication server through the second-layer network protocol; the request for a request file is used to instruct the newly added device to be pre-configured with a certificate to generate a request file; the request file and the device identification information sent by the newly added device to be pre-configured with a certificate are received, and the correspondence between the newly added device to be pre-configured with a certificate and the device identification information is stored in the device information table; wherein, the request file is used to apply for a certificate from the certificate issuing authority; the certificate issued by the certificate issuing authority is obtained, the certificate is parsed, and the first device identification information in the certificate is determined; based on the device information table, the first device to be pre-configured with a certificate corresponding to the first device identification information is determined, and the certificate is sent to the first device to be pre-configured with a certificate, so that the first device to be pre-configured with a certificate pre-configures it after receiving the certificate. The present invention realizes the distribution and pre-configuration of certificates based on the second-layer network communication between the device and the authentication server, can greatly improve the efficiency of pre-configuring certificates without manual intervention, and also avoids configuration errors in manual import, greatly improving the accuracy of pre-configuring certificates.
[0046] Since the device to be pre-configured with a certificate communicates with the authentication server based on the second-level network protocol, if the device to be pre-configured with a certificate is in an offline state, the authentication server cannot communicate with it, resulting in a failure of information transmission and affecting the pre-configuration of the certificate. To overcome the above problems, the present invention also provides the following embodiments.
[0047] Figure 2 This is the second flow chart of the method for pre-configuring certificates provided by the embodiments of the present invention. As Figure 2As shown above, based on the above embodiments, Figure 1 The implementation process of sending the certificate to the first device to be pre-configured with the certificate may include the following steps.
[0048] Step 201: Determine whether the first device to be pre-configured with the certificate is in an online state based on the heartbeat message between the first device to be pre-configured with the certificate and the authentication server.
[0049] In some embodiments, all devices to be pre-configured with the certificate send heartbeat messages to the authentication server at preset intervals. After receiving the heartbeat message sent by the device to be pre-configured with the certificate, the authentication server determines that it is in an online state. If the authentication server does not receive the heartbeat message sent by the device to be pre-configured with the certificate within the preset interval, it determines that the device to be pre-configured with the certificate is in an offline state. For example, all devices to be pre-configured with the certificate send heartbeat messages to the authentication server every 3s. If the authentication server always receives the heartbeat message sent by the first device to be pre-configured with the certificate every 3s, it means that the first device to be pre-configured with the certificate is in an online state. If the authentication server does not receive the subsequent heartbeat message after receiving the heartbeat message sent by the first device to be pre-configured with the certificate for 3s, it confirms that the first device to be pre-configured with the certificate is in an offline state.
[0050] Step 202: If the first device to be pre-configured with the certificate is in an online state, send the certificate to the first device to be pre-configured with the certificate.
[0051] Step 203: If the first device to be pre-configured with the certificate is in an offline state, monitor the state of the first device to be pre-configured with the certificate until the state of the first device to be pre-configured with the certificate switches to an online state, and then send the certificate to the first device to be pre-configured with the certificate.
[0052] If the first device to be pre-configured with the certificate is in an offline state, the state of the first device to be pre-configured with the certificate can be continuously monitored until the heartbeat message sent by the first device to be pre-configured with the certificate is received again, and then the certificate is sent to the first device to be pre-configured with the certificate.
[0053] According to the method for pre-configuring the certificate in the embodiment of the present invention, determine whether the first device to be pre-configured with the certificate is in an online state based on the heartbeat message between the first device to be pre-configured with the certificate and the authentication server; if the first device to be pre-configured with the certificate is in an online state, send the certificate to the first device to be pre-configured with the certificate; if the first device to be pre-configured with the certificate is in an offline state, monitor the state of the first device to be pre-configured with the certificate until the state of the first device to be pre-configured with the certificate switches to an online state, and then send the certificate to the first device to be pre-configured with the certificate. The present invention monitors the state of the device to be pre-configured with the certificate through the heartbeat message between the device and the authentication server, and when the device to be pre-configured with the certificate is in an online state, sends the certificate to the corresponding device to be pre-configured with the certificate to ensure the success rate of certificate sending.
[0054] Figure 3This is the third flowchart of the pre-set certificate method proposed in the embodiments of the present invention. As Figure 3 shown, based on the above embodiments, the method may further include the following steps.
[0055] Step 301, after receiving the application file sent by the newly added device to be pre-set with a certificate, set the certificate status of the newly added device to be pre-set with a certificate to "applying".
[0056] Step 302, before sending the certificate to the first device to be pre-set with a certificate, set the certificate status of the first device to be pre-set with a certificate to "to be sent".
[0057] Step 303, after sending the certificate to the first device to be pre-set with a certificate, if receiving the pre-set success information sent by the first device to be pre-set with a certificate, set the certificate status of the first device to be pre-set with a certificate to "pre-set successfully"; if receiving the pre-set failure information sent by the first device to be pre-set with a certificate, set the certificate status of the first device to be pre-set with a certificate to "pre-set failed"; wherein, the pre-set success information is the message sent by the first device to be pre-set with a certificate after successfully pre-setting the received certificate; the pre-set failure information is the message sent by the first device to be pre-set with a certificate after the pre-set of the received certificate fails.
[0058] That is to say, the authentication server can monitor and update the certificate status of each device to be pre-set with a certificate. For example, the certificate status of each device to be pre-set with a certificate can be stored in the device information table, or a separate certificate status table can be set up to store the certificate status of all devices to be pre-set with a certificate.
[0059] In some embodiments, after the pre-set of the received certificate fails for the first device to be pre-set with a certificate, the error message of the pre-set failure can also be sent to the authentication server, so that the authentication server can count the reasons for the pre-set failure, which is convenient for relevant staff to process.
[0060] In some embodiments, the list of all devices to be pre-set with a certificate in the device information table and the certificate status of each device to be pre-set with a certificate can be displayed in real time on the display device, so as to facilitate relevant staff to monitor the distribution status and the device list.
[0061] In some embodiments, for the case of application failure, the authentication server can count the reasons for the application failure, for the case of pre-set failure, the authentication server can count the error messages of the pre-set failure, and the above error logs can also be displayed on the display device.
[0062] According to the pre - installed certificate method of the embodiments of the present invention, the authentication server can store and update the certificate status of the devices to be pre - installed with certificates, and can display the list of all devices to be pre - installed with certificates in the device information table, as well as the certificate status of each device to be pre - installed with a certificate, on the display interface, facilitating relevant staff to monitor the device list and the certificate distribution progress.
[0063] To implement the above - mentioned embodiments, the present invention also provides a first device, and this first device is in a production environment. After the first device accesses the secondary network where the authentication server is located, it can send a layer - two network broadcast message to the authentication server, and after receiving the request for the application file sent by the authentication server, it generates an application file and a private key, and sends the application file to the authentication server. After receiving the certificate sent by the authentication server, it pre - installs the certificate in the first device. After the first device accesses the secondary network, it sends a heartbeat message to the authentication server every preset time interval.
[0064] Next, the pre - installed certificate method will be introduced in the form of communication between the device to be pre - installed with a certificate and the authentication server. As Figure 4 shown, the pre - installed certificate method includes the following steps.
[0065] (1) After the device to be pre - installed with a certificate first accesses the secondary network, it sends a layer - two network broadcast message; (2) After the authentication server receives the layer - two network broadcast message, it sends the MAC address of the authentication server to the device to be pre - installed with a certificate; (3) The device to be pre - installed with a certificate stores the received MAC address of the authentication server and sends the device identification information of the device to be pre - installed with a certificate to the authentication server; (4) For the device that accesses for the first time, the authentication server sends a request for the application file to the first device; (5) After the device to be pre - installed with a certificate receives the request for the application file, it generates an application file and sends it to the authentication server; (6) After the authentication server receives the application file, it stores the correspondence between the device to be pre - installed with a certificate and the device identification information in the device information table, and applies for a certificate from the certificate issuing authority based on the application file; (7) The authentication server obtains the certificate issued by the certificate issuing authority, parses the certificate, determines the device identification information in the certificate, and sends the certificate to the corresponding device to be pre - installed with a certificate; (8) After the device to be pre - installed with a certificate receives the certificate, it imports the certificate; (9) During the communication connection process between the device to be pre - installed with a certificate and the authentication server, the device to be pre - installed with a certificate sends a heartbeat message to the authentication server every 3s.
[0066] To implement the above embodiments, the present invention further provides a device for pre - setting certificates.
[0067] Figure 5 The structural schematic diagram of the device for pre - setting certificates provided by the embodiment of the present invention. It should be noted that the device for pre - setting certificates in the embodiment of the present invention is applied to the authentication server. As Figure 5 shown, the device may include: an identification module 510, a receiving module 520, an analysis module 530, and a sending module 540. The identification module 510 is configured to identify a newly added device to be pre - set with a certificate based on the communication of the layer - two network, and send a request for a solicitation application file to the newly added device to be pre - set with a certificate; wherein, the newly added device to be pre - set with a certificate communicates with the authentication server through the layer - two network protocol; the request for a solicitation application file is used to instruct the newly added device to be pre - set with a certificate to generate an application file; the receiving module 520 is configured to receive the application file and the device identification information sent by the newly added device to be pre - set with a certificate, and store the corresponding relationship between the newly added device to be pre - set with a certificate and the device identification information in the device information table; wherein, the application file is used to apply for a certificate from the certificate issuing authority; the analysis module 530 is configured to obtain the certificate issued by the certificate issuing authority, analyze the certificate, and determine the first device identification information in the certificate; the sending module 540 is configured to determine the first device to be pre - set with a certificate corresponding to the first device identification information based on the device information table, and send the certificate to the first device to be pre - set with a certificate, so that the first device to be pre - set with a certificate pre - sets the certificate after receiving it.
[0068] In some embodiments, the identification module 510 is specifically configured to: in response to receiving a layer - two network broadcast message sent by a first device, determine whether the first device is accessing for the first time; wherein, the first device is a device in the production environment, and the layer - two network broadcast message is sent after the first device accesses the layer - two network; if the first device is accessing for the first time, determine the first device as the newly added device to be pre - set with a certificate.
[0069] In some embodiments, the identification module 510 is further configured to: if the first device is not included in the device information table, determine that the first device is accessing for the first time; if the first device is included in the device information table, determine that the first device is not accessing for the first time.
[0070] In some embodiments, the sending module 540 is specifically configured to: based on the heartbeat message between the first device to be pre - set with a certificate and the authentication server, determine whether the first device to be pre - set with a certificate is in an online state; if the first device to be pre - set with a certificate is in an online state, send the certificate to the first device to be pre - set with a certificate; if the first device to be pre - set with a certificate is in an offline state, monitor the state of the first device to be pre - set with a certificate until the state of the first device to be pre - set with a certificate switches to the online state, and then send the certificate to the first device to be pre - set with a certificate.
[0071] In some embodiments, the device further includes a status update module 550, which is configured to: after receiving an application file sent by a newly added device to be pre-configured with a certificate, set the certificate status of the newly added device to be pre-configured with a certificate to "applying"; before sending the certificate to the first device to be pre-configured with a certificate, set the certificate status of the first device to be pre-configured with a certificate to "to be sent"; after sending the certificate to the first device to be pre-configured with a certificate, if receiving a pre-configuration success message sent by the first device to be pre-configured with a certificate, set the certificate status of the first device to be pre-configured with a certificate to "pre-configuration successful"; if receiving a pre-configuration failure message sent by the first device to be pre-configured with a certificate, set the certificate status of the first device to be pre-configured with a certificate to "pre-configuration failed"; wherein, the pre-configuration success message is a message sent by the first device to be pre-configured with a certificate after successfully pre-configuring the received certificate; the pre-configuration failure message is a message sent by the first device to be pre-configured with a certificate after failing to pre-configure the received certificate.
[0072] In some embodiments, the device further includes a display module 560, which is configured to display the list of all devices to be pre-configured with certificates and the certificate status of each device to be pre-configured with a certificate in the device information table on the display interface.
[0073] According to the certificate pre-configuration device of the embodiments of the present invention, an identification module is configured to identify a newly added device to be pre-configured with a certificate based on communication in the second-layer network, and send a request for asking for an application file to the newly added device to be pre-configured with a certificate; wherein, the newly added device to be pre-configured with a certificate communicates with the authentication server through a second-layer network protocol; the request for asking for an application file is used to instruct the newly added device to be pre-configured with a certificate to generate an application file; a receiving module is configured to receive the application file and device identification information sent by the newly added device to be pre-configured with a certificate, and store the corresponding relationship between the newly added device to be pre-configured with a certificate and the device identification information in the device information table; wherein, the application file is used to apply for a certificate from a certificate issuing authority; a parsing module is configured to obtain the certificate issued by the certificate issuing authority, parse the certificate, and determine the first device identification information in the certificate; a sending module is configured to determine the first device to be pre-configured with a certificate corresponding to the first device identification information based on the device information table, and send the certificate to the first device to be pre-configured with a certificate, so that the first device to be pre-configured with a certificate pre-configures the received certificate after receiving it. The present invention realizes the distribution and pre-configuration of certificates based on the second-layer network communication between the device and the authentication server, can greatly improve the efficiency of pre-configuring certificates without manual intervention, and also avoids configuration errors caused by manual import, greatly improving the accuracy of pre-configuring certificates.
[0074] It should be noted that the above explanations of the certificate pre-configuration method in the above embodiments are equally applicable to the certificate pre-configuration device in the embodiments of the present invention, and will not be repeated here.
[0075] Figure 6 Illustrates a schematic physical structure diagram of an electronic device, such as Figure 6As shown in the figure, the electronic device may include: a processor 610, a communication interface 620, a memory 630, and a communication bus 640. Among them, the processor 610, the communication interface 620, and the memory 630 complete communication with each other through the communication bus 640. The processor 610 may call a computer program in the memory 630 to execute the steps of the pre-set certificate method provided in the above embodiments.
[0076] For example, the method includes: based on communication in a layer-2 network, identifying a newly added device to be pre-set with a certificate, and sending a request for a request file to the newly added device to be pre-set with a certificate; wherein, the newly added device to be pre-set with a certificate communicates with the authentication server through a layer-2 network protocol; the request for a request file is used to instruct the newly added device to be pre-set with a certificate to generate a request file; receiving the request file and device identification information sent by the newly added device to be pre-set with a certificate, and storing the correspondence between the newly added device to be pre-set with a certificate and the device identification information in a device information table; wherein, the request file is used to apply for a certificate from a certificate issuing authority; obtaining the certificate issued by the certificate issuing authority, parsing the certificate, and determining the first device identification information in the certificate; based on the device information table, determining the first device to be pre-set with a certificate corresponding to the first device identification information, and sending the certificate to the first device to be pre-set with a certificate, so that the first device to be pre-set with a certificate pre-sets the certificate after receiving it.
[0077] In addition, when the logical instructions in the above-mentioned memory 630 are implemented in the form of a software functional unit and sold or used as an independent product, they may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in various embodiments of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc that can store program codes.
[0078] On the other hand, an embodiment of the present invention further provides a computer program product. The computer program product includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the steps of the pre-set certificate method provided in the above embodiments.
[0079] On the other hand, an embodiment of the present invention further provides a non-transitory computer-readable storage medium storing a computer program for causing a processor to execute the pre-set certificate method provided in the above embodiments.
[0080] The non-transitory computer-readable storage medium may be any available medium or data storage device accessible by the processor, including but not limited to magnetic memories (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical memories (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor memories (such as ROM, EPROM, EEPROM, non-volatile memories (NAND FLASH), solid-state drives (SSD), etc.).
[0081] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative efforts.
[0082] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solutions, or the part that contributes to the prior art, can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disks, optical disks, etc., including several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0083] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for pre-setting a certificate, characterized in that: Applied to the authentication server, the method includes: Based on the communication of the layer 2 network, a newly added certificate device to be provisioned is identified, and a request for an application file is sent to the newly added certificate device to be provisioned; wherein the newly added certificate device to be provisioned communicates with the authentication service end through the layer 2 network protocol; the request for an application file is used to instruct the newly added certificate device to be provisioned to generate an application file; Receive the application document and device identification information sent by the newly added device to be provisioned with a certificate, and store the corresponding relationship between the newly added device to be provisioned with a certificate and the device identification information in a device information table; wherein the application document is used to apply for a certificate from a certificate authority; Obtaining a certificate issued by the certificate issuing authority, parsing the certificate, and determining first device identification information in the certificate; Based on the device information table, a first certificate device to be pre-configured corresponding to the first device identification information is determined, and the certificate is sent to the first certificate device to be pre-configured, so that the first certificate device to be pre-configured presets the certificate after receiving it.
2. The method according to claim 1, characterized in that The communication based on the layer 2 network, identifying the newly added device to be pre-configured with a certificate, includes: In response to receiving a layer 2 network broadcast message sent by a first device, determining whether the first device is accessing for the first time; wherein the first device is a device in a production environment, and the layer 2 network broadcast message is sent by the first device after accessing the layer 2 network; If the first device is accessed for the first time, the first device is determined as the newly added device to be pre-configured with a certificate.
3. The method according to claim 1, characterized in that The determining whether the first device accesses for the first time includes: If the first device is not included in the device information table, determining that the first device is accessed for the first time; If the device information table includes the first device, it is determined that the first device is not accessed for the first time.
4. The method according to claim 1, characterized in that The step of sending the certificate to the first device to be pre-configured with a certificate includes: Determining whether the first device to be provisioned with a certificate is in an online state based on a heartbeat message between the first device to be provisioned with a certificate and the authentication server; If the first device to be pre-configured with a certificate is in an online state, sending the certificate to the first device to be pre-configured with a certificate; If the first device to be provisioned with a certificate is in an offline state, the state of the first device to be provisioned with a certificate is monitored until the state of the first device to be provisioned with a certificate is switched to an online state, and then the certificate is sent to the first device to be provisioned with a certificate.
5. The method according to claim 1, characterized in that Also includes: After receiving the application document sent by the newly added device to be provisioned with a certificate, setting the certificate status of the newly added device to be provisioned with a certificate to being applied for; Before sending the certificate to the first device to be pre-configured with a certificate, setting the certificate status of the first device to be pre-configured with a certificate to be sent; After sending the certificate to the first certificate device to be pre-provisioned, if the pre-provisioning success information sent by the first certificate device to be pre-provisioned is received, the certificate status of the first certificate device to be pre-provisioned is set to pre-provisioning success; if the pre-provisioning failure information sent by the first certificate device to be pre-provisioned is received, the certificate status of the first certificate device to be pre-provisioned is set to pre-provisioning failure; wherein the pre-provisioning success information is a message sent by the first certificate device to be pre-provisioned after the received certificate is successfully pre-provisioned; The provisioning failure information is a message sent by the first certificate-to-be-provisioned device after provisioning of the received certificate fails.
6. The method according to claim 5, characterized in that Also includes: A list of all the devices to be pre-configured with certificates in the device information table and the certificate status of each device to be pre-configured with certificates are displayed in the display interface.
7. A pre-set certificate device, characterized in that: Applied to the authentication server, the device comprises: An identification module, used for identifying a newly added certificate device to be provisioned based on communication in a layer 2 network, and sending a request for an application file to the newly added certificate device to be provisioned; wherein the newly added certificate device to be provisioned communicates with the authentication service end through a layer 2 network protocol; the request for an application file is used to instruct the newly added certificate device to be provisioned to generate an application file; A receiving module, used to receive the application document and device identification information sent by the newly added device to be pre-configured with a certificate, and store the corresponding relationship between the newly added device to be pre-configured with a certificate and the device identification information in a device information table; wherein the application document is used to apply for a certificate from a certificate authority; A parsing module, used to obtain a certificate issued by the certificate issuing authority, parse the certificate, and determine the first device identification information in the certificate; The sending module is used to determine the first certificate device to be pre-configured corresponding to the first device identification information based on the device information table, and send the certificate to the first certificate device to be pre-configured, so that the first certificate device to be pre-configured presets the certificate after receiving it.
8. An electronic device comprising a processor and a memory storing a computer program, characterized in that: When the processor executes the computer program, the method for presetting certificates according to any one of claims 1 to 6 is implemented.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for presetting certificates according to any one of claims 1 to 6 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method for presetting certificates according to any one of claims 1 to 6 is implemented.