Personal digital certificate embezzlement identification method based on traffic audit

By deploying a traffic acquisition device in the network path, extracting and binding user information into triples, and using whitelists to learn to identify certificate theft, the inconvenience and security risks caused by user participation in the existing technology are solved, and certificate theft identification and alarm without user participation are realized.

CN120263487APending Publication Date: 2025-07-04NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510431730.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing anti-theft methods of digital certificates require user participation, which brings inconvenience and poses security risks, and lacks the means of discovering certificate theft that does not require user participation.

Method used

Deploy the traffic acquisition device in the network path between the user terminal and the server, extract and bind the user's personal digital certificate information, user IP address and TCP protocol initial window size into triples, and identify certificate theft behavior through whitelist learning and comparison, and output alarm records.

Benefits of technology

It realizes certificate theft recognition alarm without user participation, reduces user burden, has flexibility and versatility, and can accurately identify the risk of theft when different network locations and equipment changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263487A_ABST
    Figure CN120263487A_ABST
Patent Text Reader

Abstract

The invention discloses a personal digital certificate embezzlement identification method based on traffic audit. The method comprises the following steps: S1, deploying a traffic acquisition device in a network path between a user terminal and a server which need to use a personal digital certificate; every time a user terminal uses a digital certificate to authenticate a server, a flow acquisition device acquires communication messages from the same session, extracts three types of information including user personal digital certificate information, a user IP address and a user TCP protocol initial window size from the communication messages and binds the information into a triple elem; s2, establishing a white list (white list) after the learning of the cycle time T; and S3, the traffic acquisition device carries out validity judgment on each newly acquired triple based on the white list white list, compares the valid triple with the legal triple in the white list, updates the white list of the triple, and outputs an alarm record for the digital certificate with an embezzlement risk. Therefore, the purpose of embezzlement identification and alarm can be achieved without the participation of a client.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network security technology, and particularly relates to a method for identifying theft of personal digital certificates based on traffic auditing. Background Art

[0002] Digital certificates based on the PKI system (public key infrastructure) have become the main means of identity authentication, electronic signature, and encrypted communication in network applications. A large number of websites and application systems issue digital certificates to users, and attacks on digital certificates are becoming increasingly rampant. Behaviors such as certificate leakage, theft, and forgery pose security threats to personal digital certificates. Currently, in addition to users personally discovering certificate leakage and requesting cancellation, digital certificate management service institutions lack necessary detection and warning means for certificate theft behaviors. Therefore, identifying and warning against theft of personal digital certificates is conducive to users taking early security prevention measures, which is an important task for network security and network norms.

[0003] The existing methods for preventing digital certificate theft mainly include the following.

[0004] (1) Adding an authentication password. An authentication password is added based on the digital certificate. Taking dynamic passwords as an example, users are allowed to use continuously changing authentication passwords, usually changing according to means such as time, dynamic password cards, and USB dynamic displays. The media used in this method is generally dynamic password cards, mobile phone dynamic passwords, and dynamic password locks. Among them, dynamic password cards and mobile phone dynamic passwords determine the passwords used based on coordinate positioning on the card or mobile phone text messages, while dynamic password locks are much more complex. By adding an authentication password, even if the digital certificate is lost, the thief cannot perform illegal authentication without the authentication password, thus achieving the purpose of preventing digital certificate theft.

[0005] (2) Adding a USB Key hardware. A USB Key is used as the carrier of the digital certificate. This hardware mode has been commonly used in recent years. Through media authentication, the physical identity can be confirmed to be correct because the media is issued to individuals. Unless the media is lost due to other factors, the physical identity of the media can basically be confirmed. In addition, the USB Key used as the media contains a module with the user's digital information and uses a high-strength key algorithm to identify the user, which is also very reliable in terms of security. By placing the digital certificate in a dedicated USB Key hardware, the security is enhanced, and thus the risk of digital certificate theft is reduced.

[0006] (3) Add an authentication plugin. The literature "Research on Credit and Security Issues in E-commerce" (Beijing Jiaotong University, 2007) proposed a client security solution that uses an information layer authentication plugin based on a dual digital certificate mechanism, which can solve the problem of the theft of client account information. This solution adds an authentication plugin to the client software. The plugin extracts the hardware information used by the user and submits and verifies it together with the digital certificate during the authentication process. When the terminal hardware used by the hacker is different from that of the client, the authentication fails, thus achieving the purpose of preventing certificate theft. Then submit the hardware information together with the digital certificate, and when the hardware changes, theft can be detected and an alarm can be issued.

[0007] The above methods each have their own advantages and can all reduce the risk of digital certificate theft to a certain extent. However, they have the following deficiencies:

[0008] (1) It brings inconvenience to users. The three methods of adding an authentication password, adding a USB Key hardware, and adding an authentication plugin all require user participation. Remembering the authentication password, keeping the hardware, or installing the authentication plugin all bring more inconvenience to users' use.

[0009] (2) The solution is not perfect enough. Among the above three methods, the methods of adding USB Key hardware and adding an authentication password both face the same problem. The user's digital certificate often gets lost together with the hardware and the authentication password. Once the USB Key hardware or the hardware storing the authentication password is lost, the preventive measures will fail.

[0010] (3) There are new security risks. In the method of adding an authentication plugin, it is necessary to add an authentication plugin to each user terminal using a digital certificate. In addition to bringing inconvenience to users, the authentication plugin itself may bring security problems, so new security risks may be brought.

[0011] It can be seen that most of the existing methods for preventing digital certificate theft are based on management mechanisms and require customer participation, bringing more inconvenience and new security problems to customers, and lacking means for detecting certificate theft that do not require user participation. Summary of the Invention

[0012] The purpose of this application is to: in order to overcome the problems of the prior art, a method for identifying personal digital certificate theft based on traffic auditing is disclosed. This application does not require the participation of the client, and only by deploying a traffic collection and analysis system on the server side can the goal of theft identification and alarm be achieved.

[0013] The purpose of this application is achieved through the following technical solutions:

[0014] A method for identifying personal digital certificate theft based on traffic auditing, the method for identifying personal digital certificate theft includes:

[0015] S1: Arbitrarily select an intermediate node in the network path between the user terminal that needs to use the personal digital certificate and the server to deploy a traffic collection device;

[0016] Each time the user terminal authenticates to the server using the digital certificate, the traffic collection device collects the communication packets from the same session, extracts three types of information including the user's personal digital certificate information, the user's IP address, and the initial window size of the user's TCP protocol, and binds them into a triple elem;

[0017] S2: Establish a whitelist whitelist after learning for a cycle time T, including: defining the learning cycle T, within the cycle T, perform validity discrimination on each triple elem obtained in S1, add the triples determined to be valid to the whitelist whitelist. If an exactly same triple already exists in the whitelist, it will not be added repeatedly. After the cycle T, a triple whitelist is formed, which includes several triples elem, and the corresponding triples elem are legal triples;

[0018] S3. Based on the whitelist whitelist, the traffic collection device performs validity discrimination on each newly collected triple this_elem, then compares the valid triples with the legal triples in the whitelist, updates the triple whitelist, and outputs an alarm record for digital certificates with the risk of theft.

[0019] According to a preferred embodiment, step S1 includes:

[0020] S11: Collect the TLS certification payload type packets sent by the user terminal to the server, and extract the personal digital certificate information in the packets, including: the public key public_key of the certificate, the holder subject_name of the certificate, and the issuer issuer_name of the certificate, and define it as certification_info = {public_key, subject_name, issuer_name};

[0021] S12: Based on the TLS packets collected in S11, use the IP header parsing method to analyze the IP protocol header of the TLS packets, extract the source IP address field therein, and obtain the IP address client_ip of the user terminal;

[0022] S13: Collect the first TCP SYN handshake packet sent by the user terminal to the server, extract the TCP header window size field in the packet, and obtain the initial window size tcp_winsize of the user's TCP protocol;

[0023] S14: Bind the three types of information certification_info, client_ip, and tcp_winsize obtained in S11, S12, and S13 into a triple elem = {certification_info, client_ip, tcp_winsize}.

[0024] According to a preferred embodiment, the TLS protocol communication packets collected in step S1 are packets based on the HTTPS mutual authentication process, and packets of non-HTTPS mutual authentication processes are not collected.

[0025] According to a preferred embodiment, the method for judging the validity of the triple in step S2 is as follows: The triple that meets the following conditions is valid, otherwise it is invalid;

[0026] The specific conditions include: All members of the triple have collected valid information; In the first type of information certification_info of the triple, the certificate holder subject_name contains at least 3 numeric characters and does not contain the character '.', and the public key public_key of the certificate is not empty.

[0027] According to a preferred embodiment, step S3 includes: S31: Discriminate the triple this_elem according to the validity judgment method in S2, and discard the invalid triples.

[0028] According to a preferred embodiment, step S3 further includes:

[0029] S32: Compare the certification_info in the valid triple this_elem with the certification_info of each triple in the whitelist, and it is divided into the following three cases:

[0030] Case 1: If the certification_info in the corresponding this_elem is different from the certification_info in the whitelist, it means that the personal digital certificate represented by this_elem appears for the first time, then add this_elem to the whitelist;

[0031] Case 2: The certification_info in the corresponding this_elem is the same as the certification_info of the triple old_elem in the whitelist, and either the client_ip or tcp_winsize of this_elem is also the same as that of old_elem, that is, both the client_ip and tcp_winsize information are the same as old_elem or one of them is the same. Then it is considered that the personal digital certificate represented by this_elem meets the whitelist rules and no further processing is required;

[0032] Case 3: The certification_info in the corresponding this_elem is the same as the certification_info of the triple old_elem in the whitelist, but both the client_ip and tcp_winsize of this_elem are different from those of old_elem. Then it is considered that there is a risk of theft of the personal digital certificate represented by this_elem, and an alarm record is output;

[0033] Correspondingly process the newly collected valid triples according to the above three cases.

[0034] The foregoing main solution of the present application and its various further alternative solutions can be freely combined to form multiple solutions, all of which are solutions that can be adopted and claimed by the present application. Those skilled in the art can understand that there are various combinations according to the prior art and common general knowledge after understanding the solution of the present application, all of which are the technical solutions to be protected by the present application and will not be enumerated here.

[0035] Advantages of the present application:

[0036] (1) The present application does not require user participation. The present application can collect relevant packets on the network path between the user terminal and the server, extract and bind the three types of information of the user's personal digital certificate information, user IP address, and the initial window size of the user's TCP protocol, and then learn and judge new packets, realizing the identification and alarm of certificate theft without user participation and without adding additional burden to the user.

[0037] (2) The present application has a certain degree of flexibility. In the personal digital certificate authentication rules, if any of the two types of information of the user terminal IP address and the initial window size of the TCP protocol are the same, it is considered legal. Then it allows the user to use the certificate at different network locations with the same terminal device, and at the same time allows the user to use the certificate by replacing the terminal device at the same network location, which can avoid false alarms when the user changes the network or terminal device.

[0038] (3) This application has strong general value. This application does not require customer participation. It collects traffic at the server side and extracts relevant information, which has reference significance for third parties independent of the client to conduct monitoring and warning of certificate theft behavior, and has strong general value. Brief Description of the Drawings

[0039] Figure 1 It is a schematic diagram of the technical process of this application;

[0040] Figure 2 It is a diagram of the positional relationship among the user terminal, the traffic collection device, and the server;

[0041] Figure 3 It is a schematic diagram of part of the communication process of the two-way authentication of the HTTPS protocol;

[0042] Figure 4 It is a whitelist formed through periodic time learning; it includes the public key, holder, issuer of the personal digital certificate, the user IP address, and the initial window size of the TCP protocol. Detailed Implementation Modes

[0043] The following uses specific specific examples to illustrate the implementation modes of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. This application can also be implemented or applied through other different specific implementation modes, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0044] It should be noted that: Similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0045] For the convenience of description, the present invention defines relevant terms:

[0046] TLS (Transport Layer Security): TLS is a protocol established on top of the transport layer TCP protocol and serves the application layer. Its predecessor is SSL (Secure Socket Layer). It realizes the function of encrypting the messages of the application layer and then handing them over to TCP for transmission.

[0047] TLS certification message: The TLS certification payload message collected in this article refers to the message containing certificate information sent by the client to the server, including information such as version number, serial number, issuer, holder, public key, etc.

[0048] TCP Packet: A TCP packet refers to the data packet transmitted in the network. A TCP packet contains a MAC header, an IP header, a TCP header, and a TCP payload.

[0049] TCP Initial Window Size: The TCP window size refers to the number of bytes that the receiving end can currently receive, that is, the number of bytes that the sending end is currently allowed to send. This value can be adjusted according to the network conditions. The TCP initial window size is the initial value of the received bytes set during the TCP connection establishment process between the receiving end and the sending end. This value is located in the TCP header and occupies 16 bits in length.

[0050] IP Protocol Header: The header structure of IPv4 is 20 bytes in length. If it contains a variable-length option part, it can be up to 60 bytes, including information such as the version number, header length, service type, source IP, and destination IP.

[0051] Reference Figure 1 As shown, the present application discloses a method for identifying the theft of personal digital certificates based on traffic auditing. The method for identifying the theft of personal digital certificates includes the following steps.

[0052] Step S1: In the network path between the user terminal that needs to use the personal digital certificate and the server, arbitrarily select an intermediate node to deploy a traffic collection device.

[0053] Each time the user terminal authenticates to the server using the digital certificate, the traffic collection device collects the communication packets from the same session, and extracts three types of information: the user's personal digital certificate information, the user's IP address, and the user's TCP protocol initial window size, and binds them into a triple elem.

[0054] Specifically, step S1 includes:

[0055] S11: Collect the TLS certification payload type packets sent by the user terminal to the server, and extract the personal digital certificate information in the packets, including: the public key public_key of the certificate, the holder subject_name of the certificate, and the issuer issuer_name of the certificate, and define it as certification_info = {public_key, subject_name, issuer_name};

[0056] S12: Based on the TLS packets collected in S11, use the IP header parsing method to analyze the IP protocol header of the TLS packets, and extract the source IP address field therein to obtain the IP address client_ip of the user terminal;

[0057] S13: Collect the first TCP SYN handshake packet sent by the user terminal to the server, extract the TCP header window size field in the packet, and obtain the initial TCP protocol window size tcp_winsize of the user terminal.

[0058] S14: Bind the three types of information certification_info, client_ip, and tcp_winsize obtained in S11, S12, and S13 into a triple elem = {certification_info, client_ip, tcp_winsize}.

[0059] Preferably, the TLS protocol communication packet collected in step S1 is a packet based on the HTTPS mutual authentication process, and packets of non-HTTPS mutual authentication processes are not collected.

[0060] In the HTTPS protocol communication process, there are two types: one-way authentication and mutual authentication. In the one-way authentication process, after the user accesses the HTTPS link, the public key of the certificate sent by the server is received and verified. After the verification passes, a series of interactions will start. It can be seen that in the one-way authentication process, the user does not send the personal digital certificate to the server for verification. Therefore, it is not feasible to collect the TLS protocol communication packets sent by the client in the one-way authentication HTPPS service. In the mutual authentication communication process, after the server sends the public key of the certificate to the client for verification, the client will also send the personal digital certificate to the server for verification. After both parties' verification passes, the information is exchanged. Therefore, the TLS protocol communication packets we collect are based on the HTTPS mutual authentication service.

[0061] This application collects relevant packets on the network path between the user terminal and the server, extracts and binds three types of information: user personal digital certificate information, user IP address, and user's initial TCP protocol window size for learning, and then discriminates new packets to achieve certificate theft recognition and warning without user participation and without adding additional burden to the user.

[0062] Step S2: Establish a whitelist whitelist after learning for a cycle time T, including: defining the learning cycle T. During the cycle T, judge the validity of each triple elem obtained in S1. Add the triples judged to be valid to the whitelist whitelist. If an exactly the same triple already exists in the whitelist, it will not be added repeatedly. After the cycle T, a triple whitelist is formed, which includes several triples elem, and the corresponding triples elem are legal triples.

[0063] Preferably, the method for judging the validity of the triple in step S2 is: the triple that meets the following conditions is valid, otherwise it is invalid;

[0064] The specific conditions include: valid information is collected for all members of the triple; in the first type of information certification_info of the triple, the certificate holder subject_name contains at least 3 numeric characters and does not contain the character ".", and the public key public_key of the certificate is not empty.

[0065] Step S3: Based on the whitelist, the traffic collection device determines the validity of each newly collected triple this_elem, then compares the valid triples with the legal triples in the whitelist, updates the triple whitelist, and outputs an alarm record for digital certificates at risk of theft.

[0066] Specifically, step S3 includes:

[0067] S31: Determine the triple this_elem according to the validity judgment method in S2, and discard the invalid triples;

[0068] S32: Compare the certification_info in the valid triple this_elem with the certification_info of each triple in the whitelist, which is divided into the following three cases:

[0069] Case 1: If the certification_info in the corresponding this_elem is different from the certification_info in the whitelist, it means that the personal digital certificate represented by this_elem appears for the first time, then add this_elem to the whitelist;

[0070] Case 2: If the certification_info in the corresponding this_elem is the same as the certification_info of the triple old_elem in the whitelist, and the client_ip or tcp_winsize of this_elem is also the same as old_elem, that is, the client_ip and tcp_winsize information are both the same as old_elem or one of them is the same as old_elem, then it is considered that the personal digital certificate represented by this_elem meets the whitelist rules and no further processing is required;

[0071] Case 3: If the certification_info in this_elem is the same as the certification_info of the triple old_elem in the whitelist, but both the client_ip and tcp_winsize of this_elem are different from those of old_elem, it is considered that there is a risk of theft of the personal digital certificate represented by this_elem, and an alarm record is output;

[0072] Perform corresponding processing on the newly collected valid triples according to the above three cases.

[0073] This application has a certain degree of flexibility. In the personal digital certificate authentication rule, if any of the two types of information, the user terminal IP address and the initial window size of the TCP protocol, are the same, it is considered legal. Then, it allows users to use the certificate on the same terminal device at different network locations, and also allows users to replace the terminal device at the same network location to use the certificate, which can avoid false alarms when users change the network or terminal device.

[0074] This application has strong general value. This application does not require customer participation. It collects traffic and extracts relevant information on the server side, which has reference significance for third parties independent of the client to carry out monitoring and alarming of certificate theft behavior, and has strong general value.

[0075] Embodiment

[0076] First, deploy a traffic collection device as Figure 2 shown. Deploy a traffic collection device in the network path between the user terminal and the server. When the user terminal and the server communicate using the HTTPS protocol, the traffic collection device can capture the TLS packet, and then parse information such as the user IP address, the public key of the certificate, the holder and issuer of the certificate, etc. At the same time, the traffic collection device can also collect the packets when establishing a TCP connection and parse the TCP initial window size.

[0077] The first few interaction messages in the HTTPS two-way verification communication process are as Figure 3 shown. The client first initiates a request to establish an HTTPS connection and sends the information of the SSL protocol version to the server; the server sends its own public key certificate (server.crt) to the client; the client reads the public key certificate (server.crt) and extracts the server public key; the client sends the client public key certificate (client.crt) to the server; the subsequent steps are not the focus of this application, so they will not be introduced in detail. Based on this, after the client clicks on the HTTPS link, the traffic collection device captures the TLS protocol packet sent by the client to the server, and the following information extraction and learning are performed on this packet. Considering the privacy of users, the real data has been modified below.

[0078] First, extract the personal digital certificate information, including the public key, holder, and issuer of the certificate. The first twelve bytes of the public key of the personal digital certificate are public_key = {00_98_e7_49_39_82_80_b4_c1_07_e5_68}, the holder of the certificate is subject_name = {NX Prod 1-9C9FE0D5BC238BD97258EC352522 674D}, and the issuer of the certificate is issuer_name = {l1htxj2f.tsrf slb.com}. Then, the personal digital certificate information certification_info = {public_key, subject_name, issuer_name} = {00_98_e7_49_39_82_80_b4_c1_07_e5_68, NX Prod 1 -9C9FE0D5BC238BD97258E C352522674D,l1htxj2f.tsrfslb.com}.

[0079] Use the standard IP header parsing method to analyze the IP protocol header of the captured packet, and obtain the IP address of the user terminal client_ip = {121.48.168.101} and the IP address of the server server_ip = {23.32.234.111}.

[0080] Wireshark also captures the first TCP SYN handshake packet sent from the client to the server, and extracts the TCP header window size field in the packet to obtain the initial window size tcp_winsize = 65792 of the TCP protocol stack of the user terminal. Here, the window size is the calculated window size in the packet, rather than the window size value.

[0081] Bind the three types of information, i.e., the extracted personal digital certificate information, the user terminal IP address, and the initial TCP protocol window size, into a triple elem = {certification_info, client_ip, tcp_winsize} = { {00_98_e7_49_39_82_80_b4_c1_07_e5_68, NX Prod 1-9C9FE 0D5BC238BD97258EC352522674D, l1htxj2f.tsrfslb.com}, 121.48.168.101, 65792}, and discriminate it according to the validity judgment method of the triple. All three types of information in this elem are valid information. At the same time, the certificate holder information contains three digital characters and does not contain the "." character, and the public key of the certificate is not empty. Therefore, this elem is valid and is added to the whitelist whitelist.

[0082] After learning for a period T, an initial whitelist whitelist is formed as Figure 4 shown. When a new TLS message is received, extract the personal digital certificate information, the user IP address, and the initial TCP window size according to the method in the specific steps of S1 and bind them into a triple this_elem = { {00_7c_69_32_df_75_85_16_d5_09_be_7d, NX Prod 1-DE5D535A478B090C611755D414EFD88D, btdiek3g.dattffdss.com}, 218.54.32.123, 87380}, and discriminate it according to the validity discrimination method of the triple in S2 to obtain that this_elem is a valid triple.

[0083] Compare the certification_info in the triple this_elem with the certification_info in each triple in the whitelist whitelist. It is easy to find that the certification_info in this this_elem is different from the certification_info in the whitelist, which conforms to Case 1 in S3.1. Then add the triple this_elem to the whitelist to update the whitelist. For other cases, just handle them according to the corresponding measures.

[0084] In the case of certificate theft, for example, a hacker from another place (assuming the IP address of their user terminal is 33.56.1.70 and the initial TCP protocol window size is 32767) steals the certificate "NX Prod 1-9C9FE 0D5BC238BD97258EC352522674D" that a normal user often uses at the address 121.48.168.101. Then the traffic collection device will receive the TLS interaction messages between the hacker and the server, extract the personal digital certificate information, user IP address, and TCP initial window size according to the method in the specific steps of S1 and bind them into a triple this_elem = {certification_info, client_ip, tcp_winsize} = { {00_98_e7_49_39_82_80_b4_c1_07_e5_68, NX Prod 1-9C9FE 0D5BC238BD97258EC352522674D, l1htxj2f.tsrfslb.com}, 33.56.1.70, 32767}, and judge it according to the triple validity discrimination method in S2, and get that this_elem is a valid triple. Further judge according to the method in S3 and find that it meets case 3, that is: the certification_info in this_elem is the same as the certification_info of the first triple old_elem in the whitelist whitelist, but both the client_ip and tcp_winsize of this_elem are different from old_elem, then it is considered that the personal digital certificate represented by this_elem has a risk of theft, and an alarm record is output.

[0085] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for identifying the theft of personal digital certificates based on traffic auditing, characterized in that, The method for identifying theft of personal digital certificates includes: S1: In the network path between the user terminal that needs to use the personal digital certificate and the server, arbitrarily select an intermediate node to deploy a traffic collection device; Each time the user terminal authenticates to the server using the digital certificate, the traffic collection device collects the communication packets from the same session, and extracts three types of information, namely, the user's personal digital certificate information, the user's IP address, and the initial window size of the user's TCP protocol, and binds them into a triple elem; S2: Establish a whitelist whitelist after a learning period of time T, including: defining the learning period T. During the period T, determine the validity of each triple elem obtained in S1, and add the triples determined to be valid to the whitelist whitelist. If an exactly the same triple already exists in the whitelist, it will not be added repeatedly. After the period T, a triple whitelist is formed, which includes several triples elem, and the corresponding triples elem are legal triples; S3: Based on the whitelist whitelist, the traffic collection device determines the validity of each newly collected triple this_elem, then compares the valid triples with the legal triples in the whitelist, updates the triple whitelist, and outputs an alarm record for the digital certificates at risk of theft.

2. The personal digital certificate theft recognition method according to claim 1, characterized in that Step S1 includes: S11: Collect the TLS certification payload type packets sent by the user terminal to the server, and extract the personal digital certificate information in the packets, including: the public key public_key of the certificate, the subject_name of the certificate holder, and the issuer_name of the certificate issuer, and define it as certification_info = {public_key, subject_name, issuer_name}; S12: Based on the TLS packets collected in S11, use the IP header parsing method to analyze the IP protocol header of the TLS packets, and extract the source IP address field therein to obtain the IP address client ip of the user terminal; S13: Collect the first TCP SYN handshake packet sent by the user terminal to the server, and extract the TCP header window size field in the packet to obtain the initial window size tcp_winsize of the user's TCP protocol; S14: Bind the three types of information certification_info, client_ip, and tcp_winsize obtained in S11, S12, and S13 into a triple elem = {certification_info, client_ip, tcp_winsize}.

3. The personal digital certificate theft recognition method according to claim 2, characterized in that, The TLS protocol communication packets collected in step S1 are packets based on the HTTPS two-way verification process, and packets of non-HTTPS two-way verification processes are not collected.

4. The personal digital certificate theft recognition method according to claim 1, characterized in that The method for determining the validity of the triple in step S2 is: the triple that meets the following conditions is valid, otherwise it is invalid; The specific conditions include: valid information is collected for all members of the triple; in the first type of information certification_info of the triple, the certificate holder subject_name contains at least 3 numeric characters and does not contain the "." character, and the public key public_key of the certificate is not empty.

5. The personal digital certificate theft recognition method according to claim 4, characterized in that Step S3 includes: S31: Discriminate the triple this_elem according to the validity judgment method in S2, and discard the invalid triples.

6. The personal digital certificate theft recognition method according to claim 4, characterized in that Step S3 also includes: S32: Compare the certification_info in the valid triple this_elem with the certification_info of each triple in the whitelist whitelist, which is divided into the following three cases: Case 1: If the certification_info in the corresponding this_elem is different from the certification_info in the whitelist, it means that the personal digital certificate represented by this_elem appears for the first time, then add this_elem to the whitelist; Case 2: If the certification_info in the corresponding this_elem is the same as the certification_info of the triple old_elem in the whitelist, and the client_ip or tcp_winsize of this_elem is also the same as that of old_elem, that is, both the client_ip and tcp_winsize information are the same as old_elem or one of them is the same, then it is considered that the personal digital certificate represented by this_elem meets the whitelist rules and no further processing is performed; Case 3: If the certification_info in the corresponding this_elem is the same as the certification_info of the triple old_elem in the whitelist, but both the client_ip and tcp_winsize of this_elem are different from old_elem, then it is considered that the personal digital certificate represented by this_elem has the risk of being stolen, and an alarm record is output; Perform corresponding processing on the newly collected valid triples according to the above three cases.