Digital certificate cross-domain mutual trust and mutual recognition method and system

By registering and testing the certificate authentication system, verification results are generated, and the problem of mutual trust in different CAs cannot be trusted by certificates issued by different CAs is solved, the security and convenience of cross-domain mutual trust is achieved, and the incompatibility barrier between systems is broken.

CN120238316APending Publication Date: 2025-07-01中电信量子信息科技集团有限公司 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510508752.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Digital certificates issued by different CAs cannot be trusted and recognized, resulting in increased management complexity and low resource utilization, lack of unified management, standards and application specifications, forming trust silos.

Method used

Through the registration certificate authentication system, certificate trust chain detection and revocation detection are carried out, verification results are generated, and cross-domain mutual trust management and verification methods are provided to realize centralized management of multiple CAs.

Benefits of technology

It realizes cross-domain mutual trust in digital certificates issued by different CAs, breaks the barriers of system blockages and incompatibility between multiple CAs, ensures the security and convenience of cross-domain mutual trust, and reduces management complexity and operational pressure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238316A_ABST
    Figure CN120238316A_ABST
Patent Text Reader

Abstract

The invention provides a digital certificate cross-domain mutual trust and mutual recognition method and system, and is applied to the field of communication security, and the method comprises the steps: registering a certificate authentication system according to basic information and verification information of the certificate authentication system, generating registration information of the certificate authentication system, and according to a preset access condition and root certificate chain information, carrying out the registration of the certificate authentication system; performing certificate trust chain detection on the registered certificate authentication system, accessing the certificate authentication system according to a detection result, generating revocation information according to CRL information, verifying the target certificate and generating a verification result based on the target certificate sent by an external system, and registration information, basic information and verification information of the certificate authentication system, and the verification result is sent to an external system. According to the invention, multi-CA decentralization centralized management and mutual identification of digital certificates issued by different CAs are realized, the barriers of system obstruction, multi-CA incompatibility mutual identification and the like are broken, and the security and convenience of cross-domain mutual trust are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication security technologies, and in particular, to a method and system for cross-domain mutual trust and recognition of digital certificates. Background Art

[0002] With the rapid development of Internet technologies, digital certificates are increasingly widely used in network security and trust guarantee, and have become an important cornerstone of the network trust system. Digital certificates ensure the security and reliability of network communications by verifying entity identities.

[0003] However, currently, each Certificate Authority (CA) only trusts the digital certificates it issues, resulting in the inability of digital certificates issued by different CAs to be mutually trusted and recognized, which limits the wide application of digital certificates. Moreover, users need to manage multiple digital certificates issued by different CAs, increasing the management cost and usage complexity. At the same time, CAs also need to face the needs of different users, increasing the operation pressure. In addition, the current electronic authentication system lacks unified management, standards, technologies, and application specifications, resulting in inconsistent service delivery content and service standards among different CAs, forming mutually isolated and unconnected trust islands with low resource utilization. Summary of the Invention

[0004] The purpose of this application is to provide a method and system for cross-domain mutual trust and recognition of digital certificates to solve the problem that digital certificates issued by different CAs cannot be mutually trusted and recognized in the prior art in view of the deficiencies in the above-mentioned prior art.

[0005] To achieve the above purpose, the technical solutions adopted in this application are as follows:

[0006] In a first aspect, this application provides a method for cross-domain mutual trust and recognition of digital certificates, and the method includes:

[0007] Register the certificate authentication system according to the basic information and verification information of the certificate authentication system, and generate registration information of the certificate authentication system, where the basic information includes root certificate chain information, and the verification information includes CRL information;

[0008] Perform a certificate trust chain detection on the registered certificate authentication system according to the preset access conditions and the root certificate chain information, and access the certificate authentication system according to the detection result;

[0009] Generate revocation information of the certificate authentication system according to the CRL information, where the CRL information is used to indicate whether the corresponding certificate has been revoked;

[0010] Verify the target certificate based on the target certificate in the certificate verification request sent by the external system, the registration information of the certificate authentication system, the basic information, and the verification information, generate a verification result, and send the verification result of the target certificate to the external system.

[0011] Optionally, the step of performing a certificate trust chain detection on the registered certificate authentication system according to the preset access conditions and the root certificate chain information, and accessing the certificate authentication system according to the detection result includes:

[0012] Perform a trust chain detection on the user certificates issued by the registered certificate authentication system step by step according to the preset access conditions and the root certificate chain information. The trust chain detection at least includes: basic information consistency detection, key consistency detection, and status validity detection;

[0013] If the detection passes, allow the certificate authentication system to access;

[0014] If the detection fails, suspend the access of the certificate authentication system.

[0015] Optionally, the step of generating the revocation information of the certificate authentication system according to the CRL information, where the CRL information is used to indicate whether the corresponding certificate is revoked, includes:

[0016] Verify the CRL information of the certificate authentication system according to the preset format requirements. If it meets the requirements, determine whether each certificate in the certificate authentication system is revoked according to the CRL information of the certificate authentication system. If not, the revocation information of the certificate authentication system indicates that the certificate authentication system has not been revoked;

[0017] If so, the revocation information of the certificate authentication system indicates that the certificate authentication system has been revoked.

[0018] Optionally, before verifying the target certificate based on the target certificate in the certificate verification request sent by the external system, the registration information of the certificate authentication system, the basic information, and the verification information, and generating a verification result, it further includes:

[0019] Send a first institutional certificate to the external system and receive a second institutional certificate sent by the external system. The first institutional certificate includes a first digital signature and a first public key, and the second institutional certificate includes a second digital signature and a second public key;

[0020] Verify whether the second digital signature in the second institutional certificate is trustworthy. If so, access the external system and perform encrypted communication with the external system based on the first public key and the second public key.

[0021] Optionally, verifying the target certificate based on the target certificate in the certificate verification request sent by the external system, the registration information of the certificate authentication system, the basic information, and the verification information, and generating a verification result, includes:

[0022] Based on the target certificate in the certificate verification request sent by the external system and the registration information of the certificate authentication system, determine whether the target certificate is registered. If not, send the first verification information to the external system, where the first verification information includes: the target certificate is not registered;

[0023] If so, based on the target certificate and the root certificate chain information of the certificate authentication system, determine whether the target certificate is trustworthy. If not, send the second verification information to the external system, where the second verification information includes: the target certificate is not trustworthy;

[0024] If so, based on the target certificate and the CRL information of the certificate authentication system, determine whether the target certificate is revoked. If so, send the third verification information to the external system, where the third verification information includes: the target certificate is revoked;

[0025] If not, send the fourth verification information to the external system, where the fourth verification information includes: verification passed.

[0026] Optionally, the determining whether the target certificate is trustworthy based on the target certificate and the root certificate chain information of the certificate authentication system includes:

[0027] Based on the root certificate chain information of the certificate authentication system, determine the root certificate of the target certificate;

[0028] Verify the signature information of the target certificate through the root certificate. If the signature information meets the preset requirements, the target certificate is trustworthy.

[0029] Optionally, before determining whether the target certificate is registered based on the target certificate in the certificate verification request sent by the external system and the registration information of the certificate authentication system, the method further includes:

[0030] Determine whether the target certificate is expired and correct. If not, send the fifth verification information to the external system, where the fifth verification information includes: the target certificate is expired or incorrect.

[0031] Optionally, the method further includes:

[0032] Supervise and audit the registration information of the certificate authentication system, the revocation information, and the verification result of the target certificate, and generate an audit log.

[0033] Optionally, the method further includes:

[0034] When the verification result of the target certificate indicates that the target certificate is verified successfully, parse the target certificate and send the parsing result of the target certificate to the external system.

[0035] In a second aspect, the present application provides a digital certificate cross-domain mutual trust and recognition system, which includes a management module and a service module. The management module includes a registration management unit, a root certificate chain management unit, and a CRL management unit, and the service module includes a certificate verification unit;

[0036] The registration management unit is configured to register the certificate authentication system according to the basic information and verification information of the certificate authentication system, and generate the registration information of the certificate authentication system. The basic information includes root certificate chain information, and the verification information includes CRL information;

[0037] The root certificate chain management unit is configured to perform a certificate trust chain detection on the registered certificate authentication system according to the preset access conditions and the root certificate chain information, and access the certificate authentication system according to the detection result;

[0038] The CRL management unit is configured to generate the revocation information of the certificate authentication system according to the CRL information, and the CRL information is used to indicate whether the corresponding certificate is revoked;

[0039] The certificate verification unit is configured to verify the target certificate based on the target certificate in the certificate verification request sent by the external system, the registration information of the certificate authentication system, the basic information, and the verification information, generate a verification result, and send the verification result of the target certificate to the external system.

[0040] In a third aspect, the present application provides an electronic device, including: a processor, a storage medium, and a bus. The storage medium stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the storage medium through the bus, and the processor executes the machine-readable instructions to perform the steps of the digital certificate cross-domain mutual trust and recognition method as described above.

[0041] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it performs the steps of the digital certificate cross-domain mutual trust and recognition method as described above.

[0042] The beneficial effects of this application are as follows: Register the certificate authentication system according to the basic information and verification information of the certificate authentication system, and generate the registration information of the certificate authentication system, thereby ensuring the legality and credibility of the certificate authentication system and laying a foundation for subsequent certificate verification. Then, according to the preset access conditions and root certificate chain information, perform certificate trust chain detection on the registered certificate authentication system, and access the certificate authentication system according to the detection results, thereby verifying the validity of the certificate, preventing man-in-the-middle attacks and data tampering. According to the CRL information, generate the revocation information of the certificate authentication system, thereby marking the revoked certificates and reducing the risks associated with damaged certificates. Finally, based on the target certificate in the certificate verification request sent by the external system, the registration information, basic information, and verification information of the certificate authentication system, verify the target certificate and generate a verification result, and send the verification result of the target certificate to the external system. This application realizes decentralized centralized management of multiple CAs, specifically realizes the mutual recognition of digital certificates issued by different CAs, breaks down barriers such as system isolation and incompatibility and non-mutual recognition between multiple CAs, realizes the whole-process control of the application of digital certificates across regions, manufacturers, and trading platforms, and ensures the security and convenience of cross-domain mutual trust. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] To more clearly illustrate the technical solutions of the embodiments of this application, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0044] Figure 1 FIG. is a schematic diagram of an application scenario of a method for cross-domain mutual trust and mutual recognition of digital certificates provided by an embodiment of this application;

[0045] Figure 2 FIG. is a schematic diagram of the architecture of a cross-domain mutual trust and mutual recognition system for digital certificates provided by an embodiment of this application;

[0046] Figure 3 FIG. is a schematic diagram of the process of a method for cross-domain mutual trust and mutual recognition of digital certificates provided by an embodiment of this application;

[0047] Figure 4 FIG. is a schematic diagram of the process of a certificate trust chain detection provided by an embodiment of this application;

[0048] Figure 5 FIG. is a schematic diagram of the process of verifying a target certificate provided by an embodiment of this application;

[0049] Figure 6 FIG. is a schematic diagram of the interaction of a certificate verification provided by an embodiment of this application;

[0050] Figure 7It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0051] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. It should be understood that the accompanying drawings in the present application are only for the purposes of illustration and description, and are not used to limit the protection scope of the present application. In addition, it should be understood that the schematic drawings are not drawn to actual scale. The flowcharts used in the present application illustrate operations implemented according to some embodiments of the present application. It should be understood that the operations in the flowcharts may not be implemented in sequence, and steps without logical context relationships may be reversed or implemented simultaneously. In addition, those skilled in the art may add one or more other operations to the flowchart or remove one or more operations from the flowchart under the guidance of the content of the present application.

[0052] In addition, the described embodiments are only some embodiments of the present application, rather than all embodiments. The components of the embodiments of the present application described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application claimed, but merely represents selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application.

[0053] It should be noted that the term "including" will be used in the embodiments of the present application to indicate the existence of the features stated thereafter, but does not exclude the addition of other features.

[0054] In the prior art, each CA only trusts the digital certificates it issues itself, resulting in the inability to mutually trust and recognize digital certificates issued by different CAs, which limits the wide application of digital certificates. In addition, for a user to manage digital certificates issued by multiple different CAs increases the management cost and usage complexity. In addition, CAs need to face the needs of different users, increasing the operation pressure. It can be seen that the current electronic authentication system lacks unified management, standards, technologies and application specifications, resulting in inconsistent service delivery contents and service standards among different CAs, forming mutually separated and unconnected trust islands with low resource utilization rate.

[0055] Based on this, the present application proposes a method for cross-domain mutual trust and recognition of digital certificates. This method pre-registers multiple certificate authentication systems, detects certificate trust chains, and revocation detection, thereby accessing multiple trusted certificate authentication systems. When an external system sends a certificate verification request, the target certificate in the certificate verification request is verified according to the information of the certificate authentication system, and the verification result of the target certificate is sent to the external system. The method for cross-domain mutual trust and recognition of digital certificates in the present application provides centralized management of multiple CAs, realizes mutual recognition of digital certificates issued by different CAs, breaks down barriers such as system isolation and incompatibility between multiple CAs, and realizes the whole-process control of the application of digital certificates across regions, manufacturers, and trading platforms, ensuring the security and convenience of cross-domain mutual trust.

[0056] Next, the application scenario of the method for cross-domain mutual trust and recognition of digital certificates in the present application will be introduced. Figure 1 It is a schematic diagram of the application scenario of a method for cross-domain mutual trust and recognition of digital certificates provided by an embodiment of the present application. As Figure 1 shown, the method for cross-domain mutual trust and recognition of digital certificates is applied to a cross-domain mutual trust and recognition system for digital certificates. This system can be mounted on a platform certificate authentication system, and the platform certificate authentication system can be, for example, a service platform authentication system, etc. The platform certificate authentication system accesses multiple external systems, and the external systems can be, for example, "Internet +" service systems and security guarantee systems, etc. The cross-domain mutual trust and recognition system for digital certificates can access multiple certificate authentication systems, such as an authentication infrastructure system, CA in Region A, and CA in Region B, etc. Specifically, the cross-domain mutual trust and recognition system for digital certificates can pre-register and access multiple certificate authentication systems, thereby generating registration information and verification information of the certificate authentication system.

[0057] When an external system verifies a target certificate through the platform certificate authentication system, the platform certificate system sends the target certificate to the cross-domain mutual trust and recognition system for digital certificates. The cross-domain mutual trust and recognition system for digital certificates verifies and analyzes the target certificate through the registration information and verification information, and sends the verification and analysis results to the external system through the platform certificate authentication system. Based on the cross-domain mutual trust and recognition system for digital certificates, the platform certificate authentication system can realize functions such as certificate storage and issuance, certificate status query, key management, certificate signing, and registration review.

[0058] Figure 2 It is a schematic diagram of the architecture of a cross-domain mutual trust and recognition system for digital certificates provided by an embodiment of the present application. As Figure 2As shown in the figure, the cross-domain mutual trust and recognition system for digital certificates includes a management module and a service module. The management module includes a registration management unit, a root certificate chain management unit, a CRL management unit, and a supervision and audit unit. The service module includes a certificate verification unit and a certificate parsing unit. Among them, the registration management unit is respectively connected to the root certificate chain management unit, the CRL management unit, and the supervision and audit unit. The certificate verification unit is respectively connected to the registration management unit, the root certificate chain management unit, the CRL management unit, the supervision and audit unit, and the certificate parsing unit. This application implements the cross-domain mutual trust and recognition method for digital certificates based on the cross-domain mutual trust and recognition system for digital certificates. The cross-domain mutual trust and recognition system for digital certificates can also be directly connected to multiple external systems and multiple certificate authentication systems.

[0059] Next, refer to Figure 3 to introduce the specific steps of the cross-domain mutual trust and recognition method for digital certificates. Among them, Figure 3 is a schematic flowchart of a cross-domain mutual trust and recognition method for digital certificates provided by an embodiment of this application.

[0060] S301. Register the certificate authentication system according to the basic information and verification information of the certificate authentication system, and generate the registration information of the certificate authentication system. The basic information includes the root certificate chain information, and the verification information includes the CRL information.

[0061] Optionally, a certificate authentication system may include a trust chain. The topmost is the root CA. The certificate issued by the root CA is the root certificate. The root CA also issues intermediate CA certificates. The intermediate CA is the certificate issuing authority issued by the root CA. The CA certificate is the certificate issued to the intermediate CA to prove the legality and credibility of the intermediate CA. The user certificate is the certificate issued by the intermediate CA to prove the identity of the terminal entity. In the method of this embodiment, multiple certificate authentication systems can be accessed to perform mutual trust and recognition on digital certificates issued by different CAs, and at the same time manage multiple certificate authentication systems, reducing the management cost and usage complexity.

[0062] Specifically, the basic information of the certificate authentication system may include: the name of the authentication system, province, contact person, contact person's phone number, and CA root certificate import information. Among them, the name of the authentication system is the unique identifiable identifier of the authentication system. For example, the province is the province information of the institution where the authentication system is located. The contact person is the name of the maintainer of the institution where the authentication system is located. The CA root certificate import information includes the root certificate chain information of the certificate authentication system, specifically including the certificate issuing system and the registration and audit system certificate. This root certificate chain information is the file information obtained by integrating all certificates after converting them into the Privacy Enhanced Mail (PEM) format.

[0063] The verification information of the certificate authentication system includes Certificate Revocation List (CRL) information, which is used to list the serial numbers of the digital certificates that have been revoked. The verification information also includes the address information of the CRL and the attribute information of the CRL certificate, etc.

[0064] Among them, the verification information of the certificate authentication system can be sent in the form of a registration collection form, and the registration collection form can include the Lightweight Directory Access Protocol (LDAP) host address, LDAP host port, CRL filtering condition, the attribute information of the CRL certificate, and the base Distinguished Name (DN) of the CRL. Among them, the LDAP host port is, for example, 389, and the CRL filtering condition can be, for example, objectClass=cRLDistributionPoint, which is used to find the entries related to the CRL distribution point. The attribute information of the CRL certificate is the attribute value where the CRL certificate released by the certificate authentication system is stored through LDAP. The CRL certificate can be obtained through this attribute value. For example, use the attribute certificateRevocationList;binary to obtain the CRL certificate, where certificateRevocationList is the attribute name used to store the CRL certificate in LDAP, and binary indicates that the value of this attribute is stored in binary format. It should be noted that if there are multiple attribute values where the CRL certificate is stored, they can be separated by "," for filling. The base DN of the CRL can be the DN information of the starting scanning node of the CRL certificate released by the certificate authentication system obtained through LDAP.

[0065] As an optional implementation manner, the certificate authentication system can also be registered according to the basic information, verification information, and example certificate of the certificate authentication system. Among them, the example certificate includes the subject item and the issuer information, etc., which are used to index the root certificate chain information and the CRL information, etc., so as to achieve rapid positioning.

[0066] Optionally, it can be determined whether the comprehensiveness and accuracy of the basic information and verification information of the certificate authentication system meet the preset requirements. If so, the certificate authentication system is registered, and the registration information of the certificate authentication system is generated. The registration information can include the identification information of each CA in the registered certificate authentication system.

[0067] As an optional implementation manner, if the registration of the certificate authentication system fails, information including the reason for the registration failure is returned to the corresponding certificate authentication system.

[0068] S302. Detect the certificate trust chain of the registered certificate authentication system according to the preset access conditions and the root certificate chain information, and access the certificate authentication system according to the detection results.

[0069] Among them, the preset access conditions can be set according to the actual mutual trust access requirements. The preset access conditions can include various rules, so as to be applicable to various different business requirements and technical environments, and flexibly integrate various types of authentication systems.

[0070] Optionally, the certificate trust chain detection can include basic information consistency detection, key consistency detection, and status validity detection.

[0071] As an optional implementation manner, after detecting the certificate trust chain of the registered certificate authentication system and accessing the certificate authentication system according to the detection results, it is also possible to display and modify the certificate access information of the certificate authentication system, uniformly display the registration quantity of the certificate authentication system, and suspend and enable the certificate access of each certificate authentication system according to the actual management operations of the management personnel.

[0072] Optionally, when the registered certificate authentication system meets the preset access conditions, access the certificate authentication system; when the registered certificate authentication system does not meet the preset access conditions, suspend accessing the certificate authentication system, and information including the reason for access failure can be returned to the certificate authentication system.

[0073] S303. Generate revocation information of the certificate authentication system according to the CRL information, where the CRL information is used to indicate whether the corresponding certificate has been revoked.

[0074] As an optional implementation manner, the CRL information of the certificate authentication system can be verified according to the preset format requirements, and revocation information of the certificate authentication system is generated according to the verification results. Among them, the revocation information can include the revocation situations of multiple certificates in the system.

[0075] Optionally, if the revocation information of the certificate authentication system indicates that there is a revoked certificate, the access to the certificate authentication system can be suspended. When the revocation information of all certificates in the certificate authentication system indicates that the certificates have not been revoked, access the certificate authentication system.

[0076] It should be noted that the CRL information of the certificate authentication system can be synchronized regularly to determine the revocation situations of each certificate in the system in real time.

[0077] S304. Based on the target certificate, registration information, basic information, and verification information in the certificate verification request sent by the external system, verify the target certificate and generate a verification result, and send the verification result of the target certificate to the external system.

[0078] Optionally, multiple external systems can be accessed, and convenient management tools and online verification interfaces can be provided for each external system to ensure that cross-domain mutual trust operations are simple and secure.

[0079] As an alternative implementation, the external system can be authenticated first. If the authentication is successful, the target certificate in the certificate verification request sent by the external system, the registration information, basic information, and verification information of the certificate authentication system are used to verify the target certificate and generate a verification result.

[0080] Among them, the target certificate can be various types of certificates. Exemplarily, the target certificate can be a traditional X.509 certificate, or a digital certificate supporting other technologies such as Post-Quantum Cryptography, a Software Publisher Certificate (SPC) specifically for software developers to sign software, a Secure / Multipurpose Internet Mail Extensions (S / MIME) certificate for encrypting and signing emails, or a Transport Layer Security / Secure Sockets Layer (TLS / SSL) certificate for securely encrypting data transmission over the Internet.

[0081] Specifically, it can be determined whether the target certificate is registered according to the target certificate and the registration information. If it is registered, it is determined whether the target certificate is trustworthy according to the root certificate chain information in the basic information, and it is determined whether the target certificate is revoked according to the CRL information in the verification information, so as to generate a verification result. Among them, the verification result can represent the verification status of the target certificate, such as unregistered, untrustworthy, revoked, and verified.

[0082] Optionally, the digital certificate cross-domain mutual trust and recognition system applied by the digital certificate cross-domain mutual trust and recognition method can be mounted on the platform certificate authentication system. Users can set a flexible rule engine for the digital certificate cross-domain mutual trust and recognition system through the platform certificate authentication system, so that users in different fields can set conditions and rules according to their own needs. This customization ability can greatly improve the platform applicability and meet the different certification needs of various industries and fields.

[0083] In this embodiment, the certificate authentication system is registered according to the basic information and verification information of the certificate authentication system, and the registration information of the certificate authentication system is generated, so as to ensure the legality and credibility of the certificate authentication system and lay a foundation for subsequent certificate verification. Then, according to the preset access conditions and root certificate chain information, the certificate trust chain of the registered certificate authentication system is detected, and the certificate authentication system is accessed according to the detection result, so as to verify the validity of the certificate, prevent man-in-the-middle attacks and data tampering. According to the CRL information, the revocation information of the certificate authentication system is generated, so as to mark the revoked certificates and reduce the risks related to damaged certificates. Finally, based on the target certificate, registration information, basic information and verification information in the certificate verification request sent by the external system, the target certificate is verified and the verification result is generated, and the verification result of the target certificate is sent to the external system. This embodiment realizes decentralized centralized management of multiple CAs, specifically realizes the mutual recognition of digital certificates issued by different CAs, breaks through barriers such as system isolation and incompatibility and non-mutual recognition of multiple CAs, realizes the whole-process control of the application of digital certificates across regions, manufacturers and trading platforms, and ensures the security and convenience of cross-domain mutual trust.

[0084] Next, with reference to Figure 4 The specific steps of detecting the certificate trust chain of the registered certificate authentication system according to the preset access conditions and root certificate chain information in step S302 above and accessing the certificate authentication system according to the detection result are introduced. Among them, Figure 4 is a schematic flowchart of a certificate trust chain detection provided by an embodiment of the present application.

[0085] S401. According to the preset access conditions and root certificate chain information, the trust chain of the user certificates issued by the registered certificate authentication system is detected level by level. The trust chain detection at least includes: basic information consistency detection, key consistency detection, and status validity detection.

[0086] Among them, the user certificate may be an end-entity certificate issued by an intermediate CA.

[0087] Specifically, according to the preset access conditions and root certificate chain information, the trust chain of all user certificates issued by the registered certificate authentication system is detected level by level, that is, starting from the current certificate, detecting level by level up to the root certificate to determine the integrity and authenticity of the certificate chain.

[0088] Among them, the basic information consistency detection may include: the issuer of each CA certificate should be consistent with the user information of the root CA certificate, including the DN order and encoding format, etc., and the issuer of the user certificate should be consistent with the user information of the CA certificate, including the DN order and encoding format, etc.

[0089] The key consistency check may include: the issuer key identifier of the CA certificate should be consistent with the subject key identifier of the root CA certificate, and the issuer key identifier of the user certificate should be consistent with the subject key identifier of the CA certificate.

[0090] The status validity check may include: the validity periods and statuses of all certificates on the entire certificate chain in the certificate authentication system are normal.

[0091] S402. If the check passes, the certificate authentication system is allowed to access.

[0092] Specifically, if the basic information consistency check, key consistency check, and status validity check of the user certificate all pass, the certificate authentication system is allowed to access.

[0093] Optionally, the information and status of the accessed certificate authentication system can be displayed.

[0094] S403. If the check fails, the access of the certificate authentication system is suspended.

[0095] Specifically, if any one of the basic information consistency check, key consistency check, and status validity check of the user certificate fails, the access of the certificate authentication system is suspended.

[0096] Optionally, the information and status of the certificate authentication system with suspended access can be displayed.

[0097] In this embodiment, by performing a trust chain check on the user certificates issued by the registered certificate authentication system step by step according to the preset access conditions and root certificate chain information, if the check passes, the certificate authentication system is allowed to access, if the check fails, the access of the certificate authentication system is suspended, so as to ensure the integrity of the trust chain from the terminal entity certificate to the root certificate, thereby verifying the validity of the certificate.

[0098] Furthermore, the specific steps of generating the revocation information of the certificate authentication system according to the CRL information in step S303 above are introduced, where the CRL information is used to represent whether the corresponding certificate is revoked.

[0099] Optionally, according to the preset format requirements, the CRL information of the certificate authentication system is verified. If it meets the requirements, according to the CRL information of the certificate authentication system, it is determined whether each certificate in the certificate authentication system is revoked. If not, the revocation information of the certificate authentication system indicates that the certificate authentication system has not been revoked.

[0100] Among them, the preset format requirements may include, for example: the certificate format should comply with the requirements of GM / T 0015 and GB / T 16264.8-2005. Specifically, the CRL should be able to be decoded in X.509 format, the version of the CRL should be V2, the object identifier (OID) of the signature algorithm of the CRL should be 1.2.156.10197.1.501, the construction order and encoding format of the issuer subject of the CRL should be exactly the same as the subject in the issuer's certificate, and the encoding rules for the effective date and next update date of the CRL are, for example, that the time must be encoded as UTCTime type before (including) 2049, and encoded as GenerallizedTime type after 2050, and the effective period must be earlier than the expiration period.

[0101] Optionally, if the CRL information meets the preset format requirements, then determine whether each certificate is revoked according to the CRL information. If not, the revocation information of the certificate authentication system indicates that the certificate authentication system has not been revoked.

[0102] Optionally, if so, the revocation information of the certificate authentication system indicates that the certificate authentication system has been revoked.

[0103] As an alternative implementation, the signature value of the CRL information can also be verified. If the requirements are met, the format of the CRL information meets the requirements.

[0104] In this embodiment, by verifying the CRL information of the certificate authentication system according to the preset format requirements, if it meets the requirements, then determine whether each certificate in the certificate authentication system is revoked according to the CRL information of the certificate authentication system, so as to avoid the security risks of abnormal access to the platform certificate authentication system by certificate users due to various situations such as certificate revocation, destruction, and reissuance, and strictly control the access of certificate users.

[0105] Next, the method steps that can be executed before verifying the target certificate and generating a verification result based on the target certificate, registration information, basic information, and verification information in the certificate verification request sent by the external system in the above step S304 are introduced.

[0106] Optionally, send a first institutional certificate to the external system and receive a second institutional certificate sent by the external system. The first institutional certificate includes a first digital signature and a first public key, and the second institutional certificate includes a second digital signature and a second public key.

[0107] Among them, the first institutional certificate and the second institutional certificate can be institutional certificates issued by the same trusted source point.

[0108] Optionally, verify whether the second digital signature in the second institutional certificate is trustworthy. If so, access the external system and perform encrypted communication with the external system based on the first public key and the second public key.

[0109] Specifically, determine whether the second institutional certificate is issued by the same trust source as the external system based on the second digital signature in the second institutional certificate. Additionally, the external system can also determine whether the first institutional certificate is issued by the same trust source as the digital certificate cross-domain mutual trust and recognition method in this embodiment based on the first digital signature in the first institutional certificate. If so, access the external system.

[0110] During communication, encrypt the information to be sent based on the second public key and then send it to the external system. When receiving the information sent by the external system, decrypt the received information based on the first public key, thereby achieving encrypted communication.

[0111] Optionally, if the second digital signature in the second institutional certificate is not trustworthy, return a verification failure message to the external system.

[0112] In this embodiment, by sending the first institutional certificate to the external system and receiving the second institutional certificate sent by the external system, verify whether the second digital signature in the second institutional certificate is trustworthy. If so, access the external system and perform encrypted communication with the external system based on the first public key and the second public key, thereby ensuring secure communication.

[0113] Further, refer to Figure 5 , and introduce the specific steps of verifying the target certificate and generating a verification result based on the target certificate, the registration information, the basic information, and the verification information in the certificate verification request sent by the external system in step S304 above. Among them, Figure 5 is a schematic flowchart of a process for verifying a target certificate provided by an embodiment of the present application.

[0114] S501. Based on the target certificate in the certificate verification request sent by the external system and the registration information of the certificate authentication system, determine whether the target certificate is registered. If not, send the first verification information to the external system. The first verification information includes: The target certificate is not registered.

[0115] Optionally, after accessing the external system, the external system sends a certificate verification request, and the certificate verification request includes the target certificate.

[0116] Optionally, the registration information includes the identification information of the CA in the registered certificate authentication system. Determine whether the CA that issued the target certificate is registered. If so, it means that the target certificate is registered. If not, it means that the target certificate is not registered.

[0117] S502. If so, determine whether the target certificate is trustworthy based on the target certificate and the root certificate chain information of the certificate authentication system. If not, send the second verification information to an external system. The second verification information includes: The target certificate is not trustworthy.

[0118] Specifically, based on the root certificate chain information of the certificate authentication system, determine the superior-issued certificate of the target certificate, and verify whether the signature information of the target certificate meets the preset requirements based on the superior-issued certificate. If so, the target certificate is trustworthy; if not, the target certificate is not trustworthy. Among them, the superior-issued certificate can be the root certificate and the intermediate certificate.

[0119] S503. If so, determine whether the target certificate has been revoked based on the target certificate and the CRL information of the certificate authentication system. If so, send the third verification information to an external system. The third verification information includes: The target certificate has been revoked.

[0120] Optionally, determine whether the target certificate has been revoked based on the CRL information. Specifically, check whether the serial number of the user certificate appears in the CRL information. If so, it means that the target certificate has been revoked.

[0121] S504. If not, send the fourth verification information to an external system. The fourth verification information includes: Verification passed.

[0122] Optionally, if the target certificate is registered, trustworthy, and not revoked, it means that the certificate verification has passed.

[0123] In this embodiment, based on the target certificate in the certificate verification request sent by the external system and the registration information of the certificate authentication system, it is determined whether the target certificate is registered. If not, the first verification information indicating that the target is not registered is sent to the external system. If so, based on the target certificate and the root certificate chain information of the certificate authentication system, it is determined whether the target certificate is trustworthy. If not, the second verification information indicating that the target certificate is not trustworthy is sent to the external system. If so, based on the target certificate and the CRL information of the certificate authentication system, it is determined whether the target certificate has been revoked. If so, the third verification information indicating that the target certificate has been revoked is sent to the external system. If not, the fourth verification information indicating that the verification has passed is sent to the external system. When the external system accesses and performs local verification on the target certificate, compared with the traditional joint authentication method that establishes a mutual trust relationship by integrating the identity authentication systems of multiple organizations or domains, it does not require the integration of different identity authentication protocols and technologies and the cooperation of all parties. Therefore, this embodiment is more efficient and flexible, and can achieve automatic synchronization and update to ensure the timeliness and accuracy of certificate information. It avoids the delay and errors caused by manual operations, and improves the efficiency and accuracy of cross-domain mutual trust. In addition, compared with the cross-domain authentication gateway, the method of this embodiment effectively avoids setting up a dedicated gateway device or service to manage cross-domain authentication, and reduces the complexity of technology deployment and maintenance.

[0124] Among them, the specific method for determining whether the target certificate is trustworthy based on the target certificate and the root certificate chain information of the certificate authentication system in step S502 above is as follows:

[0125] Optionally, based on the root certificate chain information of the certificate authentication system, the issuing certificate of the target certificate is determined.

[0126] Optionally, the issuing certificate of the target certificate may be an intermediate certificate.

[0127] Specifically, the corresponding issuing certificate is found in the root certificate chain information according to the DN of the issuer in the target certificate.

[0128] Optionally, the signature information of the target certificate is verified through the issuing certificate. If the signature information meets the preset requirements, the target certificate is trustworthy.

[0129] Specifically, the public key is extracted from the issuing certificate, and the signature information of the target certificate is verified using the public key of the issuing certificate. If the signature verification of the target certificate passes, the target certificate is trustworthy.

[0130] In this embodiment, by determining the issuing certificate of the target certificate and then verifying the signature information of the target certificate through the issuing certificate, it is determined whether the target certificate is trustworthy, thereby realizing the verification of the target certificate.

[0131] As an alternative implementation, before step S501 above, that is, judging whether the target certificate is registered based on the target certificate in the certificate verification request sent by the external system and the registration information of the certificate authentication system, the following steps may further be included:

[0132] Optionally, judge whether the target certificate has expired and whether it is correct. If not, send the fifth verification information to the external system. The fifth verification information includes: the target certificate has expired or is incorrect.

[0133] Optionally, parse the target certificate, extract the fields of the start date and end date of the target certificate, and judge whether the target certificate has expired according to the start date and end date of the target certificate. Specifically, if the current time is not within the validity period of the certificate, the target certificate has expired. Then the fifth verification information includes that the target certificate has expired.

[0134] Optionally, judge whether the domain name and format of the target certificate are correct, etc. If not, send the fifth verification information to the external system. The fifth verification information includes: the target certificate is incorrect.

[0135] Optionally, if the target certificate has not expired and is correct, execute the method of step S510.

[0136] In this embodiment, by judging whether the target certificate has expired and whether it is correct, the validity and credibility of the target certificate are ensured.

[0137] Figure 6It is an interactive schematic diagram of certificate verification provided by an embodiment of the present application. Taking the method for cross-domain mutual trust and recognition of digital certificates applied to a cross-domain mutual trust and recognition system of digital certificates as an example, in step 601, an external system sends a second institutional certificate to the cross-domain mutual trust and recognition system of digital certificates. In step 602, the cross-domain mutual trust and recognition system of digital certificates sends a first institutional certificate to the external system. Then, in step 603, the external system verifies whether the first institutional certificate is trustworthy, and the cross-domain mutual trust and recognition system of digital certificates verifies whether the second institutional certificate is trustworthy. If so, the external system is accessed. In step 604, the cross-domain mutual trust and recognition system of digital certificates receives a certificate verification request sent by the external system. In step 605, it decrypts based on the second key to obtain the target certificate. In step 606, it determines whether the target certificate has expired and is correct. If not, it sends the fifth verification information including that the target certificate has expired or is incorrect to the external system. If so, in step 607, it determines whether the target certificate is registered based on the target certificate and the registration system. If not, it sends the first verification information including that the target certificate is not registered to the external system. If so, in step 608, it determines whether the target certificate is trustworthy based on the target certificate and the root certificate chain information. If not, it sends the second verification information including that the target certificate is not trustworthy to the external system. If so, in step 609, based on the target certificate and the CRL information, it determines whether the target certificate has been revoked. If so, it sends the third verification information including that the target certificate has been revoked to the external system. If not, it sends the fourth verification information including verification passed to the external system. In the above steps, Figure 6 Taking the first verification information, the second verification information, the third verification information, the fourth verification information, and the fifth verification information as the verification information in step 610 as an example for illustration.

[0138] As an alternative implementation, the method for cross-domain mutual trust and recognition of digital certificates further includes the following steps.

[0139] Optionally, supervise and audit the registration information, revocation information of the certificate authentication system, and the verification result of the target certificate, and generate an audit log.

[0140] Optionally, in addition to supervising and auditing the registration information, revocation information of the certificate authentication system, and the verification result of the target certificate, security audits can also be performed on the logs of key nodes such as trust chain detection and certificate parsing.

[0141] Exemplarily, the audit log can be as shown in Table 1 below:

[0142] Table 1

[0143]

[0144] In this embodiment, by supervising and auditing the registration information, revocation information of the certificate authentication system, and the verification result of the target certificate, and generating an audit log, it is convenient to check the registration, revocation, and verification status of the certificate in the later stage.

[0145] As an alternative implementation, the digital certificate cross-domain mutual trust and recognition method may further include the following steps.

[0146] Optionally, when the verification result of the target certificate indicates that the target certificate is verified successfully, parse the target certificate and send the parsing result of the target certificate to an external system.

[0147] Optionally, after the target certificate is verified successfully, the target certificate can also be parsed and the parsing result is sent to an external system. The parsing result may include certificate public key information, certificate policy information, etc.

[0148] In this embodiment, by parsing the target certificate and sending the parsing result of the target certificate to an external system when the verification result of the target certificate indicates that the target certificate is verified successfully, the diverse requirements of the external system are met.

[0149] The embodiment of the present application further provides a digital certificate cross-domain mutual trust and recognition system, which includes a management module and a service module. The management module includes a registration management unit, a root certificate chain management unit, and a CRL management unit, and the service module includes a certificate verification unit.

[0150] The registration management unit is configured to register the certificate authentication system according to the basic information and verification information of the certificate authentication system, and generate the registration information of the certificate authentication system. The basic information includes root certificate chain information, and the verification information includes CRL information;

[0151] The root certificate chain management unit is configured to detect the certificate trust chain of the registered certificate authentication system according to the preset access conditions and root certificate chain information, and access the certificate authentication system according to the detection result;

[0152] The CRL management unit is configured to generate the revocation information of the certificate authentication system according to the CRL information, and the CRL information is used to indicate whether the corresponding certificate is revoked;

[0153] The certificate verification unit is configured to verify the target certificate based on the target certificate, the registration information, the basic information, and the verification information of the certificate authentication system in the certificate verification request sent by the external system, generate a verification result, and send the verification result of the target certificate to the external system.

[0154] As an alternative implementation, the management module further includes: a supervision and audit unit.

[0155] Optionally, the regulatory audit unit is used to conduct regulatory audits on the registration information, revocation information of the certificate authentication system, and the verification results of the target certificate, and generate audit logs.

[0156] As an optional implementation manner, the service module further includes: a certificate parsing unit.

[0157] Optionally, the certificate parsing unit is used to parse the target certificate when the verification result of the target certificate indicates that the target certificate is verified successfully, and send the parsing result of the target certificate to an external system.

[0158] The embodiment of the present application further provides an electronic device, as Figure 7 shown in the structural schematic diagram of an electronic device provided by the embodiment of the present application, including: a processor 701, a memory 702, and a bus. The memory 702 stores machine-readable instructions executable by the processor 701. When the computer device runs, the processor 701 communicates with the memory 702 through the bus. When the machine-readable instructions are executed by the processor 701, the processing of the above-mentioned cross-domain mutual trust and mutual recognition method for digital certificates is performed.

[0159] The embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps of the above-mentioned cross-domain mutual trust and mutual recognition method for digital certificates are executed.

[0160] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems and devices can refer to the corresponding processes in the method embodiments, which will not be repeated in this application. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some communication interfaces. The indirect couplings or communication connections of the devices or modules can be in electrical, mechanical, or other forms.

[0161] In addition, each functional unit in various embodiments of the present application may be integrated into one processing unit, may exist physically alone for each unit, or two or more units may be integrated into one unit. If the function is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0162] The above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application.

Claims

1. A method for cross-domain mutual trust and recognition of digital certificates, characterized in that: The method comprises: Registering the certificate authentication system according to basic information and verification information of the certificate authentication system, and generating registration information of the certificate authentication system, wherein the basic information includes root certificate chain information, and the verification information includes CRL information; According to the preset access conditions and the root certificate chain information, the registered certificate authentication system is tested for a certificate trust chain, and the certificate authentication system is accessed according to the test result; Generate revocation information of the certificate authentication system according to the CRL information, wherein the CRL information is used to indicate whether the corresponding certificate is revoked; Based on the target certificate in the certificate verification request sent by the external system, the registration information of the certificate authentication system, the basic information and the verification information, the target certificate is verified and a verification result is generated, and the verification result of the target certificate is sent to the external system.

2. The cross-domain mutual trust and recognition method for digital certificates according to claim 1 is characterized in that: The step of performing a certificate trust chain detection on the registered certificate authentication system according to the preset access condition and the root certificate chain information, and accessing the certificate authentication system according to the detection result includes: According to the preset access conditions and the root certificate chain information, the user certificate issued by the registered certificate authentication system is tested on a trust chain level by level, wherein the trust chain test includes at least: basic information consistency test, key consistency test and status validity test; If the test passes, the certificate authentication system is allowed to access; If the detection fails, the access to the certificate authentication system is suspended.

3. The cross-domain mutual trust and recognition method for digital certificates according to claim 1 is characterized in that: The generating, according to the CRL information, revocation information of the certificate authentication system, wherein the CRL information is used to indicate whether the corresponding certificate is revoked, includes: Verify the CRL information of the certificate authentication system according to the preset format requirements, and if it meets the requirements, determine whether each certificate in the certificate authentication system is revoked according to the CRL information of the certificate authentication system, and if not, the revocation information of the certificate authentication system indicates that the certificate authentication system has not been revoked; If so, the revocation information of the certificate authentication system indicates that the certificate authentication system is revoked.

4. The cross-domain mutual trust and recognition method for digital certificates according to claim 1 is characterized in that: Before verifying the target certificate and generating a verification result based on the target certificate in the certificate verification request sent by the external system, the registration information of the certificate authentication system, the basic information and the verification information, the further comprising: Sending a first institution certificate to the external system, and receiving a second institution certificate sent by the external system, wherein the first institution certificate includes a first digital signature and a first public key, and the second institution certificate includes a second digital signature and a second public key; Verify whether the second digital signature in the second institution certificate is credible. If so, access the external system and perform encrypted communication with the external system based on the first public key and the second public key.

5. The cross-domain mutual trust and recognition method for digital certificates according to claim 1 is characterized in that: The method of verifying the target certificate and generating a verification result based on the target certificate in the certificate verification request sent by the external system, the registration information of the certificate authentication system, the basic information and the verification information comprises: Based on the target certificate in the certificate verification request sent by the external system and the registration information of the certificate authentication system, determining whether the target certificate is registered, and if not, sending first verification information to the external system, the first verification information including: the target certificate is not registered; If so, judging whether the target certificate is credible based on the target certificate and the root certificate chain information of the certificate authentication system, and if not, sending second verification information to the external system, the second verification information including: the target certificate is not credible; If so, judging whether the target certificate is revoked based on the target certificate and the CRL information of the certificate authentication system, and if so, sending third verification information to the external system, the third verification information including: the target certificate is revoked; If not, the fourth verification information is sent to the external system, and the fourth verification information includes: verification passed.

6. The cross-domain mutual trust and recognition method for digital certificates according to claim 5 is characterized in that: The determining whether the target certificate is credible based on the target certificate and the root certificate chain information of the certificate authentication system includes: Determining the root certificate of the target certificate based on the root certificate chain information of the certificate authentication system; The signature information of the target certificate is verified by the root certificate. If the signature information meets the preset requirements, the target certificate is credible.

7. The cross-domain mutual trust and recognition method for digital certificates according to claim 5 is characterized in that: Before determining whether the target certificate is registered based on the target certificate in the certificate verification request sent by the external system and the registration information of the certificate authentication system, the method further includes: Determine whether the target certificate is expired and correct. If not, send fifth verification information to the external system. The fifth verification information includes: the target certificate is expired or incorrect.

8. The cross-domain mutual trust and recognition method for digital certificates according to claim 1, characterized in that: The method further comprises: Perform a supervisory audit on the registration information of the certificate authentication system, the revocation information, and the verification result of the target certificate, and generate an audit log.

9. The cross-domain mutual trust and recognition method for digital certificates according to claim 1, characterized in that: The method further comprises: When the verification result of the target certificate indicates that the verification of the target certificate is passed, the target certificate is parsed, and the parsing result of the target certificate is sent to the external system.

10. A digital certificate cross-domain mutual trust and recognition system, characterized in that: The system includes a management module and a service module, the management module includes a registration management unit, a root certificate chain management unit and a CRL management unit, and the service module includes a certificate verification unit; The registration management unit is used to register the certificate authentication system according to basic information and verification information of the certificate authentication system, and generate registration information of the certificate authentication system, wherein the basic information includes root certificate chain information, and the verification information includes CRL information; The root certificate chain management unit is used to perform a certificate trust chain test on the registered certificate authentication system according to the preset access conditions and the root certificate chain information, and access the certificate authentication system according to the test result; The CRL management unit is used to generate revocation information of the certificate authentication system according to the CRL information, wherein the CRL information is used to indicate whether the corresponding certificate is revoked; The certificate verification unit is used to verify the target certificate and generate a verification result based on the target certificate in the certificate verification request sent by the external system, the registration information of the certificate authentication system, the basic information and the verification information, and send the verification result of the target certificate to the external system.