Certificate management system and method and electronic equipment
Through the certificate management system, the certificate set is managed in the full process, including registration, authentication, analysis and configuration, and the information registration errors, missed registration and security risks in certificate management in the existing technology are solved, and efficient and secure certificate management is achieved.
Patent Information
- Application Number
- CN202510692841.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-07-18
AI Technical Summary
In the existing technology, digital certificate management has problems such as information registration errors, missed certificate registration, missing expiration reminder, difficulty in managing expired certificates and high risk of certificate replacement, which affects the smooth progress of the business.
The certificate management system is adopted, including the certificate registration module, the authentication module, the management module and the configuration module. By receiving, verifying, analyzing and configuring the certificate set, the full process management of the certificate set is realized, ensuring the legality of the certificate set, and simplifying the replacement to version switch when the certificate expires to avoid security risks.
It improves the efficiency of certificate management, reduces manual operation costs, avoids security risks, realizes all-round management of certificate sets, and solves problems in the existing technology.
Smart Images

Figure CN120342636A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular, to a certificate management system, method, and electronic device. Background Art
[0002] With the development of computer technology, information security issues have become increasingly prominent. To ensure the secure conduct of various online services, the Public Key Infrastructure (PKI) has been widely used. Based on asymmetric cryptographic algorithms, PKI solves information security problems in communication through digital certificate technology, provides identity authentication for entities in network communication, and ensures the integrity, confidentiality, and non-repudiation of communication content.
[0003] In the prior art, the management of large-scale digital certificates usually relies on a semi-automated management process of manual registration and regular reminders. However, digital certificate management through the above methods is prone to problems such as incorrect information registration, missed certificate registration, missing certificate expiration reminders, difficult governance of expired certificates, and high risks of certificate replacement, thus affecting the smooth progress of business. Summary of the Invention
[0004] The present invention provides a certificate management system, method, and electronic device, which realizes all-round management of certificate set distribution and use, and improves the efficiency of certificate management.
[0005] According to one aspect of the present invention, a certificate management system is provided. The system includes: a certificate registration module, a certificate authentication module, a certificate management module, a certificate configuration module, and a certificate service module; wherein,
[0006] The certificate registration module is configured to receive a certificate set registration request, and send it to the certificate authentication module after passing the verification of the certificate set registration request; wherein, the certificate set registration request is related to the business information of the client.
[0007] The certificate authentication module is configured to receive the certificate set registration request that has passed the verification, and feedback the certificate set corresponding to the certificate set registration request to the certificate registration module, so as to send the certificate set to the client based on the certificate registration module; wherein, the certificate set includes at least two certificates to be used, and the time ranges applicable to the at least two certificates to be used are different and there is partial overlap in the time ranges.
[0008] The certificate management module is configured to obtain the certificate set and the business information corresponding to the certificate set, and send the parsed certificate set and business information to the certificate configuration module after parsing.
[0009] The certificate configuration module is configured to send the received parsed certificate set and business information to the certificate service module, so as to provide the certificate service corresponding to the business information for the client based on the certificate service module.
[0010] According to another aspect of the present invention, there is provided a certificate management method, which is applied to a certificate management system. The certificate management system includes a certificate registration module, a certificate authentication module, a certificate management module, a certificate configuration module, and a certificate service module. The method includes:
[0011] Based on the certificate registration module, receiving a certificate set registration request, and after passing the verification of the certificate set registration request, sending it to the certificate authentication module; wherein, the certificate set registration request is related to the business information of the client;
[0012] Based on the certificate authentication module, receiving the verified certificate set registration request, and feeding back the certificate set corresponding to the certificate set registration request to the certificate registration module, so as to send the certificate set to the client based on the certificate registration module; wherein, the certificate set includes at least two certificates to be used, and the time ranges applicable to the at least two certificates to be used are different and there is partial overlap in the time ranges;
[0013] Based on the certificate management module, obtaining the certificate set and the business information corresponding to the certificate set, and after parsing and processing the certificate set and the business information, sending them to the certificate configuration module;
[0014] Based on the certificate configuration module, sending the received parsed certificate set and business information to the certificate service module, so as to provide the certificate service corresponding to the business information for the client based on the certificate service module.
[0015] According to another aspect of the present invention, there is provided an electronic device, which includes:
[0016] At least one processor; and
[0017] A memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the certificate management method of any embodiment of the present invention.
[0019] According to another aspect of the present invention, there is provided a computer-readable storage medium, which stores computer instructions for causing a processor to implement the certificate management method of any embodiment of the present invention when executed.
[0020] According to another aspect of the present invention, there is provided a computer program product, including a computer program, characterized in that the computer program implements the certificate management method as in any embodiment of the present invention when executed by a processor.
[0021] The technical solution of the embodiment of the present invention realizes the full-process management of the certificate set through the certificate management system. The certificate registration module in the certificate management system receives the certificate set registration request and performs verification processing on the certificate set registration request to send the verified certificate set registration request to the certificate authentication module. After receiving the verified certificate set registration request, the certificate authentication module feeds back the certificate set corresponding to the certificate set registration request to the certificate registration module, and based on the certificate registration module, the certificate set is sent to the client. Based on this, the application and distribution processing of the certificate set are realized, and the legality of the certificate set is ensured. The certificate set includes at least two certificates to be used, and the time ranges applicable to the at least two certificates to be identified are different and there is an overlap in the time ranges. By issuing such a certificate set with a time gradient, when the certificate expires and needs to be replaced later, the certificate replacement can be simplified to the certificate version switching process, solving the problem of certificate expiration and replacement in the PKI system. And the scattered digital certificates are integrated into a certificate set, avoiding the security risks caused by certificate expiration and reducing the manual operation cost. The certificate management module obtains the certificate set and the service information corresponding to the certificate set, and performs parsing processing on the certificate set and the service information corresponding to the certificate set to send the parsing result to the certificate configuration module. The certificate configuration module transmits the parsing result to the certificate service module to provide certificate services for the client through the certificate service module. Based on this, the processing of certificate management and providing certificate services is realized. The present invention solves the problems such as information registration errors, missed certificate registration, lack of certificate expiration reminder, difficult governance of expired certificates, and high risk of certificate replacement caused by manually registering and managing digital certificates in the prior art, realizes the all-round management of certificate set issuance and use, avoids the security risks caused by certificate expiration, reduces the manual operation cost, and improves the certificate management efficiency.
[0022] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Brief Description of the Drawings
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.
[0024] Figure 1 It is a schematic structural diagram of a certificate management system provided by an embodiment of the present invention;
[0025] Figure 2 It is an example diagram processed by the certificate configuration module provided by an embodiment of the present invention;
[0026] Figure 3 is a schematic structural diagram of a certificate management system provided by an embodiment of the present invention;
[0027] Figure 4 is an example diagram processed by a version management module provided by an embodiment of the present invention;
[0028] Figure 5 is a flowchart of a certificate management method provided by an embodiment of the present invention;
[0029] Figure 6 is a process example diagram of a certificate management method provided by an embodiment of the present invention;
[0030] Figure 7 is a schematic structural diagram of an electronic device for implementing the certificate management method of an embodiment of the present invention. Detailed implementation manners
[0031] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0033] Embodiment 1
[0034] Figure 1 is a schematic structural diagram of a certificate management system provided by Embodiment 1 of the present invention, and this embodiment is applicable to the situation of full-process management of digital certificates. As Figure 1 shown, the system includes: a certificate registration module 110, a certificate authentication module 120, a certificate management module 130, a certificate configuration module 140, and a certificate service module 150.
[0035] Among them, the certificate registration module 110 is used to receive a certificate set registration request and send it to the certificate authentication module after passing the verification of the certificate set registration request; among them, the certificate set registration request is related to the business information of the client.
[0036] Among them, the certificate registration module is the entry to access the certificate authentication module, responsible for processing the certificate set registration request, completing the information entry, review and certificate issuance of the certificate applicant, etc. The certificate set registration request can be sent to the certificate registration module when it is detected that there is a need for business communication based on a digital certificate and the digital certificate has expired, for the purpose of obtaining a certificate set. The certificate set registration request can be related to the business information of the client for business communication based on a digital certificate. In order to ensure the security and compliance of the certificate set registration request, the certificate set registration request can be verified.
[0037] Specifically, when the certificate registration module receives a certificate set registration request, the request parameters corresponding to the certificate set registration request are verified by the certificate registration module to obtain a verification result. When the verification result is that the request parameters pass the verification, the verified certificate set registration request is sent to the certificate authentication module.
[0038] The certificate authentication module 120 is used to receive the verified certificate set registration request and feedback the certificate set corresponding to the certificate set registration request to the certificate registration module, so as to send the certificate set to the client based on the certificate registration module; among them, the certificate set includes at least two certificates to be used, and the time ranges applicable to the at least two certificates to be used are different and there is partial overlap in the time ranges.
[0039] Among them, the certificate set can be a set of certificates corresponding to the certificate set registration request. The certificate set contains at least two certificates to be used. The certificates to be used are digital certificates that can be used. The time ranges applicable to these at least two certificates to be used are different and there is partial overlap between the time ranges. The time range applicable to the certificate to be used can be understood as the certificate usage validity period of the certificate to be used. Optionally, the certificate set can be incremented in gradient according to the certificate usage validity period, and there is a parallel period between the certificate usage validity periods of two adjacent certificates to be used. The parallel period is the duration of the overlapping time range. For example, if the certificate set can contain three certificates to be used and the parallel period is two months, the certificate usage validity period corresponding to the first certificate to be used in these three certificates to be used can be from n years m months r days to n + 5 years m months r days, the certificate usage validity period corresponding to the second certificate to be used can be from n + 5 years m - 2 months r days to n + 10 years m months r days, and the certificate usage validity period corresponding to the third certificate to be used can be from n + 10 years m - 2 months r days to n + 15 years m months r days. It should be noted that the time range (certificate usage validity period) applicable to the certificate to be used can be set according to the actual business requirements.
[0040] Specifically, after the certificate authentication module receives the certificate set registration request with successful verification sent by the certificate registration module, the certificate authentication module can parse the certificate set registration request to determine the parsing result. Among them, the parsing result at least includes the starting effective moment of the certificate to be used. And interact with the authoritative third party corresponding to the parsing result through the certificate authentication module to obtain the certificate set corresponding to the parsing result. Among them, the certificate set is multiple certificates to be used incremented in gradient according to the starting effective moment. According to the identity information of the authoritative third party, add an identity signature to each certificate to be used in the certificate set to ensure the legality of the certificate to be used. Send the certificate set with the identity signature added to the certificate registration module so that the certificate registration module can send the certificate set to the client. Optionally, after the certificate registration module receives the certificate set with the identity signature added, it can perform identity legality verification processing on the certificate set with the identity signature added, and after the verification is passed, send the certificate set with the identity signature added to the client. By sending the certificate set to the client, the security risk of the certificate key not being replaced for a long time caused by only sending a single digital certificate is avoided.
[0041] The certificate management module 130 is used to obtain the certificate set and the service information corresponding to the certificate set, and send them to the certificate configuration module after parsing and processing the certificate set and the service information.
[0042] Among them, the certificate management module is mainly used for parsing and processing the certificate set, expiration reminder, certificate information update, etc. Business information can be understood as business information associated with the certificate set. Optionally, the business information may include: the business system to which the certificate set belongs, the contact information corresponding to the certificate set, the business department corresponding to the certificate set, and the information such as the number of days for early reminder of certificate expiration. The certificate configuration module is used to perform unified configuration relationships on the certificate set, mainly for implementing access control, permission management, etc.
[0043] Specifically, the certificate management module automatically parses the certificate set and business information uploaded by the client, that is, parses the certificate set to obtain the certificate attribute information corresponding to the certificate set. For example, the certificate attribute information may include: certificate name, certificate version number, certificate distinguished name (DN), certificate serial number, start effective time and expiration time of the certificate. Parse the business information to determine the business information such as the business system to which the certificate set belongs, the contact information corresponding to the certificate set, the business department corresponding to the certificate set, and the information such as the number of days for early reminder of certificate expiration. After detecting that the parsing of the certificate set and business information is completed, send the certificate attribute information, certificate business information, and certificate set to the certificate configuration module.
[0044] Optionally, the certificate management module includes: a certificate parsing unit, a certificate management unit, and an expired certificate deletion unit.
[0045] Among them, the certificate parsing unit is used to parse at least two certificates to be used in the certificate set to obtain the certificate attribute information of the certificates to be used, and when the certificate attribute information meets the preset conditions, send the certificate attribute information and business information to the certificate configuration module; among them, the certificate attribute information at least includes the certificate version number and the certificate usage validity period.
[0046] Among them, the certificate attribute information meeting the preset conditions can be that the certificate attribute information verification is successful. Correspondingly, the preset condition can be the condition for successful verification of the certificate attribute information. The certificate version number can be used to represent the version of each certificate to be used in the certificate set. The certificate usage validity period can be used to standardize the start effective time and expiration time of each certificate to be used in the certificate set.
[0047] Specifically, perform parsing processing on at least two certificates to be used in the certificate set to determine the certificate attribute information of each certificate to be used. Perform legality verification processing on the certificate attribute information to obtain the verification result. When the verification result is consistent with the preset result, determine that the certificate attribute information meets the preset conditions, and send the certificate attribute information and business information to the certificate configuration module.
[0048] The certificate management unit is used to save the certificate attribute information and service information parsed by the certificate parsing unit, and notify the ownership users of the certificate set according to the certificate usage validity period in the certificate attribute information.
[0049] Among them, the ownership users of the certificate set can be understood as the certificate set owners, that is, the users who communicate through the certificate set.
[0050] Specifically, the certificate management unit stores the certificate attribute information and service information parsed by the certificate parsing unit to provide an external query function for certificate information, that is, it supports querying the saved certificate attribute information and service information by users. In addition, the certificate management unit detects the certificate usage validity period in the certificate attribute information. If the number of days corresponding to the expiration moment of the certificate usage validity period of a certain certificate to be used in the certificate set and the current moment meets the preset number of days for early reminder of certificate expiration, then the certificate expiration reminder information for the certificate to be used can be generated according to the number of days corresponding to the expiration moment of the certificate usage validity period of a certain certificate to be used in the certificate set and the current moment, the certificate attribute information, and the certificate service information, and the certificate expiration reminder information is notified to the ownership users of the certificate set through text messages, emails or other reminder methods to remind the ownership users that a certain certificate to be used in the certificate set is about to expire. Based on this, it is convenient for each ownership user to determine information such as the certificate usage validity period, so as to perform certificate update processing in time after receiving the certificate expiration reminder information notification, so as to avoid various communication risk problems caused by certificate expiration.
[0051] The expired certificate deletion unit is used to obtain the certificate usage validity period in the certificate attribute information and delete the associated expired certificates.
[0052] Among them, the expired certificate can be understood as the digital certificate that has expired in the certificate set.
[0053] Specifically, obtain the certificate usage validity period in the certificate attribute information, and determine whether the certificates in the certificate set have expired according to the certificate usage validity period and the current moment. After determining that at least one certificate in the certificate set has expired, the expired certificate is used as an expired certificate, and the expired certificate is deleted. It should be noted that when the expired certificate deletion unit deletes the expired certificate, the certificate expiration information can be synchronized to the certificate configuration module and the certificate service module, so that the certificate configuration module deletes the certificate attribute information and service information of the expired certificate, and the certificate service module deletes the expired certificate, so as to avoid the problem of occupying storage resources due to the accumulation of expired certificates.
[0054] The certificate configuration module 140 is used to send the received parsed certificate set and service information to the certificate service module to provide a certificate service corresponding to the service information for the client based on the certificate service module.
[0055] Among them, the certificate configuration module is the core of certificate retrieval management and is located above the certificate service module. It is used to implement the unified configuration management of digital certificates and realize functions such as access control and permission management of digital certificates. The parsed certificate set includes: the certificate set and the parsed certificate attribute information.
[0056] Specifically, after receiving the certificate attribute information, certificate set, and service information sent by the certificate management module, the certificate configuration module processes the certificate attribute information, service information, and certificate set, generates a certificate operation request, and sends the certificate operation request to the certificate service module, so that the certificate service module can parse and process the certificate operation request and provide the certificate service corresponding to the service information for the client based on the parsing result.
[0057] Optionally, the certificate configuration module is used to implement the addition processing of certificate configuration information based on the newly added certificate attribute information and service information, and synchronize the newly added certificate configuration information to the version management module.
[0058] Exemplarily, see Figure 2 , Figure 2 The certificate technical data in corresponds to the above-mentioned certificate attribute information, and the certificate service data corresponds to the above-mentioned service information. The certificate configuration module implements the addition processing of certificate configuration information according to the certificate attribute information and service information, and synchronizes the newly added certificate configuration information to the version management module. The certificate configuration module processes the certificate attribute information and the certificate set, generates a certificate import operation request, and sends it to the certificate service module, so that the certificate service module can perform certificate file operations based on the certificate import operation request, and perform a one-time import process on multiple digitally signed certificates with increasing time gradients in the certificate set corresponding to the certificate import operation request, so as to provide various public key infrastructure (PKI) security transaction services based on digital certificates for the client.
[0059] Subsequently, after the certificate configuration module receives the transaction request sent by the client, the certificate configuration module performs parameter verification on the transaction request, and queries the certificate attribute information and service information corresponding to the client after the parameter verification passes to determine the certificate usage permission corresponding to the client. After determining that the client has the certificate usage permission to use the corresponding certificate set, the transaction request with passed parameter verification is sent to the certificate service module to provide the certificate service by the certificate service module, facilitating transaction processing.
[0060] The technical solution of this embodiment realizes the full-process management of the certificate set through the certificate management system. The certificate registration module in the certificate management system receives the certificate set registration request and performs verification processing on the certificate set registration request to send the verified certificate set registration request to the certificate authentication module. After receiving the verified certificate set registration request, the certificate authentication module feeds back the certificate set corresponding to the certificate set registration request to the certificate registration module to send the certificate set to the client based on the certificate registration module. Based on this, the application and distribution processing of the certificate set are realized, ensuring the legality of the certificate set. The certificate set includes at least two certificates to be used, and the time ranges applicable to the at least two certificates to be identified are different and there is an overlap in the time ranges. By distributing such a certificate set with a time gradient, when the certificate expires and needs to be replaced later, the certificate replacement can be simplified to the certificate version switching process, solving the problem of certificate expiration and replacement in the PKI system. And the scattered digital certificates are integrated into a certificate set, avoiding the security risks caused by certificate expiration and reducing the manual operation cost. The certificate management module obtains the certificate set and the service information corresponding to the certificate set, and performs parsing processing on the certificate set and the service information corresponding to the certificate set to send the parsing result to the certificate configuration module. The certificate configuration module transmits the parsing result to the certificate service module to provide certificate services for the client through the certificate service module. Based on this, the processing of certificate management and providing certificate services is realized. The present invention solves the problems such as information registration errors, missed certificate registration, lack of certificate expiration reminder, difficult management of expired certificates, and high risk of certificate replacement caused by manual registration and management of digital certificates in the prior art, realizes the all-round management of certificate set distribution and use, avoids the security risks caused by certificate expiration, reduces the manual operation cost, and improves the certificate management efficiency.
[0061] Embodiment 2
[0062] Figure 3 It is a schematic structural diagram of another certificate management system provided by Embodiment 2 of the present invention. On the basis of the above embodiment, as Figure 3 shown, the certificate management system further includes: a version management module 160 and a synchronization detection module 170.
[0063] Among them, the version management module 160 is used to send notification information for distributing the certificate set to the target terminal when the number of available certificates in the certificate set is less than the preset number threshold; among them, the available certificates correspond to the certificates to be used that are currently in use and the certificates to be used that have not been used yet.
[0064] Among them, the number of available certificates can be the number of certificates in the certificate set after invalid certificates are deleted. The preset quantity threshold can be a standard value of the number of available certificates in the certificate set that is set in advance. It should be noted that the available certificates correspond to the certificates to be used that are currently in use and the certificates to be used that have not been used yet, that is, the certificates to be used that are currently within the certificate usage validity period and the certificates to be used that have not reached the certificate usage validity period. The target terminal can be the terminal device of the user who uses the certificate set. Optionally, the target terminal can be any client that uses the certificate set. The notification message can be information used to inform the target terminal that there are no certificates to be used in the current certificate set that can be switched to a new version, and a new certificate set needs to be applied for. Optionally, when the target terminal is the client that currently needs to communicate based on the certificate set, after the version management module detects that there are no certificates to be used that can be switched to a new version, it can send a notification message to the client that a new certificate set needs to be applied for, so that the client can apply for a certificate set from the certificate registration module and the certificate authentication module again.
[0065] Specifically, when the version management module detects that the number of available certificates in the certificate set is less than the preset quantity threshold, it sends a notification message to the target terminal that a new certificate set needs to be applied for, so that the target terminal can apply for a certificate set from the certificate registration module and the certificate authentication module again.
[0066] Exemplarily, the version management module is mainly used to implement the management and switching of certificate versions. After the certificate set has been imported into the certificate service module at one time, the subsequent solution for certificate expiration can be to adjust the certificate version of the client. By using the certificate versions of at least one certificate to be used within the certificate usage validity period in the certificate set, the certificate to be used for the current transaction is controlled. Based on this, no matter which version of the certificate to be used the client requests, the certificate service module will have a certificate to be used within the certificate usage validity period. Based on this, the problem of time difference in real-time transactions between both parties caused by the simultaneous adjustment of digital certificates by the client and the server can be avoided.
[0067] Meanwhile, the version management module represents the number of certificates that can be switched subsequently by the switching hop count to control the certificate version switching and the deletion process of expired certificates. Among them, the switching hop count corresponds to the number of certificates of the unused certificates to be used mentioned above. When the switching hop count is less than 1, it means that there is no version available for switching in the current certificate set, and there is only one certificate to be used that is currently in use. Then, when the version management module detects that there is only one certificate to be used that is currently in use, it can send a notification message to the client that currently needs to communicate based on the certificate set to reapply for the certificate set to avoid the problem of no version available for switching. When the difference between the switching hop counts of each certificate to be used in the certificate set and the switching hop count of the certificate to be used that is currently in use is greater than or equal to 2, it means that there are expired certificates in addition to the certificate to be used that is currently in use, and the expired certificates are deleted. It should be noted that if the certificate version is switched and the certificate has not expired, the certificate does not need to be deleted to ensure that the certificate can be rolled back to the previous version during the certificate parallel period to improve the effectiveness of the certificate service.
[0068] Optionally, operation functions such as version switching can also be encapsulated and sent to the client in the form of an SDK, so that after the client is installed, it can interact with modules such as the certificate management module and the version management module through API interfaces to implement operations such as obtaining certificate attribute information and business information, and switching the certificate version.
[0069] Optionally, the version management module 160 is also used to switch to the target certificate to be used and delete the certificates to be used that have exceeded the certificate usage validity period when detecting an event with a certificate switching requirement; among them, the event with a certificate switching requirement includes receiving a request for certificate switching or the certificate usage validity periods of the certificate to be used currently in use and the certificate to be used to be switched to overlap.
[0070] Among them, the target certificate to be used can be the certificate that needs to be used currently after switching, that is, the certificate to be used to be switched to. The certificate to be used that has exceeded the certificate usage validity period is the expired certificate. The request for certificate switching can be: after receiving the notification of the certificate expiration reminder information, the version switching request sent by the client to the certificate configuration module, so that the certificate configuration module sends a request for certificate switching to the version management module.
[0071] Specifically, when receiving the request for certificate switching or the certificate usage validity periods of the certificate to be used currently in use and the certificate to be used to be switched to overlap, the certificate to be used to be switched to is used as the target certificate to be used, switched to the target certificate to be used, and the certificate to be used that has exceeded the certificate usage validity period, that is, the expired certificate, is deleted.
[0072] Exemplarily, in combination with the above example, see Figure 4, if the version of the certificate to be used currently in use is the APPID_V1 version, it indicates that the current client communicates based on the certificate to be used in the APPID_V1 version. The corresponding switching hop count for the APPID_V1 version is 2, which means there are two more versions available for switching. When the version management module receives a certificate switching request, it can determine whether the certificate to be used in the APPID_V2 version is available. After determining that the certificate to be used in the APPID_V2 version is available, invalidate the certificate to be used in the APPID_V1 version. At this time, the client communicates using the certificate to be used in the APPID_V2 version. The corresponding current switching hop count for the APPID_V2 version is 1, indicating that there is 1 more version available for switching. Similarly, when a certificate expiration reminder for the APPID_V2 version is received, that is, when the version management module receives a certificate switching request, determine whether the certificate to be used in the APPID_V3 version is available. In the case where it is determined that the certificate to be used in the APPID_V3 version is available, invalidate the certificate in the APPID_V2 version. Since there is no version available for switching at this time, when the triggered switching hop count is less than 1, start the next round of certificate set application rules to perform a new round of certificate set application. Based on this, automatic replacement of digital certificates is achieved. At the same time, trigger the certificate deletion rule where the switching hop count of the certificate to be used in each version minus the switching hop count of the certificate to be used in the currently available version is greater than or equal to 2, delete the certificate to be used in the APPID_V1 version, and synchronize the deletion information to the certificate configuration module and the certificate service module to achieve automatic deletion of expired certificates.
[0073] The synchronization detection module 170 includes: a data acquisition unit, a data reconciliation unit, and a signal sending unit;
[0074] Among them, the data acquisition unit is used to acquire the first certificate attribute information and the first service information stored in the certificate management module, and acquire the second certificate attribute information and the second service information stored in the certificate service module; the data reconciliation unit is used to compare the first certificate attribute information and the second certificate attribute information to obtain a first comparison result, and compare the first service information and the second service information to obtain a second comparison result; the signal sending unit is used to determine a target signal when the first comparison result and / or the second comparison result does not meet the preset conditions, and send the target signal to the module corresponding to the first comparison result or the second comparison result.
[0075] Among them, the first certificate attribute information can be understood as the certificate attribute information of the certificate set stored in the certificate management module. The first service information can be understood as the service information of the certificate set stored in the certificate management module. The second certificate attribute information can be understood as the certificate attribute information of the certificate set stored in the certificate service module. The second service information can be understood as the service information of the certificate set stored in the certificate service module. The first comparison result can be used to represent whether the first certificate attribute information is consistent with the second certificate attribute information. The second comparison result can be used to represent whether the first service information and the second service information are consistent. The preset condition can be the condition that the first certificate attribute information is consistent with the second certificate attribute information and the first service information is consistent with the second service information. Optionally, in the case where the first comparison result is that the first certificate attribute information is inconsistent with the second certificate attribute information and / or the second comparison result is that the first service information is inconsistent with the second service information, it is determined that the first comparison result or the second comparison result does not meet the preset condition. The target signal can be generated according to the first comparison result or the second comparison result, and is used to obtain the certificate attribute information and / or service information to be supplemented.
[0076] Specifically, the data acquisition unit of the synchronization detection module is used to acquire the first certificate attribute information and the first service information stored in the certificate management module, and acquire the second certificate attribute information and the second service information stored in the certificate service module. The data reconciliation unit is used to compare the first certificate attribute information with the second certificate attribute information to determine the first comparison result. And compare the first service information with the second service information to obtain the second comparison result. In the case where the first comparison result is that the first certificate attribute information is inconsistent with the second certificate attribute information and / or the second comparison result is that the first service information is inconsistent with the second service information, it is determined that the first comparison result or the second comparison result does not meet the preset condition. When the first comparison result and / or the second comparison result does not meet the preset condition, the service information or certificate attribute information to be supplemented is determined, and a target signal is generated based on the service information or certificate attribute information to be supplemented, and the target signal is sent to the certificate management module or the client to supplement the corresponding certificate attribute information or service information.
[0077] Optionally, the signal sending unit is further configured to: when both the first comparison result and the second comparison result do not meet the preset condition, determine the missing target information; wherein, the target information includes the first service information, the second service information, the first certificate attribute information and / or the second certificate attribute information; when the target information is the first service information and / or the first certificate attribute information, send the target signal to the client to obtain the target information from the client; when the target information is the second service information and / or the second certificate attribute information, send the target signal to the certificate configuration module to obtain the target information from the certificate configuration module.
[0078] Among them, the target information can be understood as the first service information, second service information, first certificate attribute information, and / or second certificate attribute information to be supplemented. The target signal can be generated based on the target information and is used to obtain the certificate attribute information or service information.
[0079] Specifically, through the signal sending unit, analyze the first comparison result to determine whether the first certificate attribute information is consistent with the second certificate attribute information. If they are consistent, there is no need to supplement the certificate attribute information. If they are inconsistent, the first comparison result does not meet the preset conditions. If the first certificate attribute information is missing, generate a target signal to send the target signal to the client so that the client supplements the corresponding certificate attribute information and sends it to the certificate management module. Correspondingly, if the second certificate attribute information is missing, generate a target signal to send the target signal to the certificate configuration module so that the certificate configuration module supplements the corresponding certificate attribute information and sends it to the certificate service module.
[0080] Through the signal sending unit, analyze the second comparison result to determine whether the first service information is consistent with the second service information. If they are consistent, there is no need to supplement the service information. If they are inconsistent, the second comparison result does not meet the preset conditions. If the first service information is missing, generate a target signal to send the target signal to the client so that the client supplements the corresponding service information and sends it to the certificate management module. Correspondingly, if the second service information is missing, generate a target signal to send the target signal to the certificate configuration module so that the certificate configuration module supplements the corresponding service information and sends it to the certificate service module. Based on this, the risk of out-of-control certificate information management caused by inconsistent certificate attribute information or service information can be avoided.
[0081] The technical solution of this embodiment manages and switches the certificate versions of the certificate set through the version management module. Through the version management module, the problem of time difference in real-time transactions between both parties caused by the simultaneous adjustment of digital certificates by the client and the server can be avoided. The synchronization detection module obtains the first certificate attribute information and first service information stored in the certificate management module, and obtains the second certificate attribute information and second service information stored in the certificate service module. Compare the first certificate attribute information with the second certificate attribute information to obtain the first comparison result, and compare the first service information with the second service information to obtain the second comparison result. When the first comparison result and / or the second comparison result do not meet the preset conditions, determine the target signal and send the target signal to the module corresponding to the first comparison result or the second comparison result, which can avoid the risk of out-of-control certificate information management caused by inconsistent certificate attribute information or service information.
[0082] Embodiment III
[0083] Figure 5It is a flowchart of a certificate management method provided in Embodiment 3 of the present invention. This embodiment is applicable to the situation of full-process management of digital certificates. This method can be executed by a certificate management system. As Figure 5 shown, this method includes:
[0084] S310. Receive a certificate set registration request based on the certificate registration module, and send it to the certificate authentication module after passing the verification of the certificate set registration request; wherein, the certificate set registration request is related to the business information of the client.
[0085] S320. Receive the verified certificate set registration request based on the certificate authentication module, and feedback the certificate set corresponding to the certificate set registration request to the certificate registration module, so as to send the certificate set to the client based on the certificate registration module; wherein, the certificate set includes at least two certificates to be used, and the time ranges applicable to the at least two certificates to be used are different and there is partial overlap in the time ranges.
[0086] Exemplarily, referring to Figure 6 , Figure 6 the certificate registrar corresponds to the certificate registration module, the certificate authenticator corresponds to the certificate authentication module, and the certificate set application request corresponds to the above-mentioned certificate registration request. After receiving the certificate set application request sent by the client, the certificate registrar sends the verified certificate application request to the certificate registrar after passing the verification of the certificate set application request, so that the certificate authenticator issues a certificate set based on the verified certificate application request and distributes the certificate set to the certificate registrar. The client can send a certificate set download application request to the certificate registrar, so that the certificate registrar sends the certificate set to the client.
[0087] S330. Obtain the certificate set and the business information corresponding to the certificate set based on the certificate management module, and send them to the certificate configuration module after parsing and processing the certificate set and the business information.
[0088] The specific processing performed by the certificate management module may include: parsing at least two certificates to be used in the certificate set through a certificate parsing unit to obtain the certificate attribute information of the certificates to be used, and when the certificate attribute information meets the preset conditions, sending the certificate attribute information and the business information to the certificate configuration module; wherein, the certificate attribute information at least includes the certificate version number and the certificate usage validity period. Saving the certificate attribute information and the business information parsed by the certificate parsing unit through the certificate management unit, and notifying the ownership user of the certificate set according to the certificate usage validity period in the certificate attribute information. And, obtaining the certificate usage validity period in the certificate attribute information through the expired certificate deletion unit to delete the associated expired certificates.
[0089] S340. The certificate configuration module sends the received parsed certificate set and service information to the certificate service module, so as to provide the client with the certificate service corresponding to the service information based on the certificate service module.
[0090] Exemplarily, in combination with the above example, the certificate manager corresponds to the certificate management module, the certificate configurator corresponds to the certificate configuration module, and the certificate server corresponds to the certificate service module.
[0091] The client sends the downloaded certificate set and the service information corresponding to the certificate set to the certificate manager. After receiving the certificate set and the service information, the certificate manager performs parsing processing on the certificate set to obtain certificate attribute information. The certificate manager saves the certificate set, the certificate attribute information, and the service information into the corresponding storage space, and sends the certificate set, the certificate attribute information, and the service information to the certificate configurator. The certificate configurator generates a certificate addition request based on the certificate set, the certificate attribute information, and the service information, so as to transfer the certificate addition request to the certificate server, so that the certificate server realizes the import operation of the certificate set based on the certificate addition request. Based on this, the certificate server can provide certificate services for the client or the application system.
[0092] Subsequently, the client that needs to communicate based on the certificate set can send a transaction request to the certificate configurator to enable the certificate configurator to verify the transaction request. After the verification passes, the certificate configurator sends the transaction request that has passed the verification to the certificate server, so as to perform key operation processing on the transaction request based on the certificate server, and feed back the transaction result corresponding to the transaction request.
[0093] Optionally, the method further includes: when the number of available certificates in the certificate set is less than the preset number threshold, the version management module sends a notification message for issuing the certificate set to the target terminal; wherein, the available certificates correspond to the to-be-used certificates that are currently in use and the to-be-used certificates that have not been used yet.
[0094] Optionally, when the version management module detects an event with a certificate switching requirement, it switches to the target to-be-used certificate and deletes the to-be-used certificates whose certificate usage validity periods have expired; wherein, the event with a certificate switching requirement includes receiving a certificate switching request or the certificate usage validity periods of the currently used to-be-used certificate and the to-be-switched-to to-be-used certificate overlapping.
[0095] Exemplarily, in combination with the above example, in Figure 6It also includes: The certificate manager provides an entry for querying certificate information, can receive the certificate query requests sent by the client, and feedback the certificate attribute information and service information corresponding to the certificate query requests. The certificate manager can analyze the certificate attribute information and service information to determine whether the certificate has expired, so as to send certificate expiration reminder information to the corresponding client in the form of text messages or emails after detecting that a certain certificate in the certificate set has expired. At the same time, synchronize the certificate expiration reminder information to the version manager. After receiving the certificate expiration reminder information, the version manager performs version switching processing on the certificate set to update the target available certificates and the hop count. And send a request to delete the invalid certificate to the certificate manager. The certificate manager deletes the certificate attribute information and service information of the corresponding certificate according to the received certificate deletion request. At the same time, the certificate manager synchronizes the certificate deletion request to the certificate configurator so that the certificate configurator deletes the certificate attribute information and service information of the corresponding certificate. The certificate configurator synchronizes the certificate deletion request to the certificate server so that the certificate server deletes the certificate attribute information and service information of the corresponding certificate after backing up the certificate attribute information and service information of the corresponding certificate. When detecting that the highest version certificate in the certificate set is about to expire, that is, the certificate corresponding to the latest certificate usage validity period is about to expire, the certificate manager reminds the client to initiate a new certificate set application request.
[0096] Optionally, the method further includes: obtaining the first certificate attribute information and the first service information stored in the certificate management module through the data acquisition unit of the synchronization detection module, and obtaining the second certificate attribute information and the second service information stored in the certificate service module; comparing the first certificate attribute information and the second certificate attribute information through the data reconciliation unit of the synchronization detection module to obtain a first comparison result, and comparing the first service information and the second service information to obtain a second comparison result. When the first comparison result and / or the second comparison result does not meet the preset conditions, the signal sending unit of the synchronization detection module determines the target signal and sends the target signal to the module corresponding to the first comparison result or the second comparison result.
[0097] Optionally, when both the first comparison result and the second comparison result do not meet the preset conditions, the signal sending unit determines the missing target information; wherein, the target information includes the first service information, the second service information, the first certificate attribute information and / or the second certificate attribute information; when the target information is the first service information and / or the first certificate attribute information, send the target signal to the client to obtain the target information from the client; when the target information is the second service information and / or the second certificate attribute information, send the target signal to the certificate configuration module to obtain the target information from the certificate configuration module.
[0098] Exemplarily, in combination with the above example, the detection synchronizer corresponds to the above-mentioned synchronization detection module. The detection synchronizer can perform certificate reconciliation processing on the certificate attribute information and service information corresponding to the certificate manager and the certificate server according to a preset detection frequency. If there is a situation where the certificate attribute information or service information is inconsistent, the missing certificate attribute information or service information is automatically synchronized or manually supplemented.
[0099] The technical solution of this embodiment realizes the full-process management of the certificate set through the certificate management system. The certificate registration module in the certificate management system receives the certificate set registration request and performs verification processing on the certificate set registration request to send the verified certificate set registration request to the certificate authentication module. After receiving the verified certificate set registration request, the certificate authentication module feeds back the certificate set corresponding to the certificate set registration request to the certificate registration module to send the certificate set to the client based on the certificate registration module. Based on this, the application and distribution processing of the certificate set are realized, ensuring the legality of the certificate set. The certificate set includes at least two certificates to be used, and the time ranges applicable to the at least two certificates to be identified are different and there is an overlap in the time ranges. By distributing such a certificate set with a time gradient, when the certificate expires and needs to be replaced in the future, the certificate replacement can be simplified to the certificate version switching process, solving the problem of certificate expiration and replacement in the PKI system. And the scattered digital certificates are integrated into a certificate set, avoiding the security risks caused by certificate expiration and reducing the manual operation cost. The certificate management module obtains the certificate set and the service information corresponding to the certificate set, and performs parsing processing on the certificate set and the service information corresponding to the certificate set to send the parsing result to the certificate configuration module. The certificate configuration module transmits the parsing result to the certificate service module to provide certificate services for the client through the certificate service module. Based on this, the processing of certificate management and providing certificate services is realized. The present invention solves the problems in the prior art such as information registration errors, missed certificate registration, missing certificate expiration reminders, difficult governance of expired certificates, and high risks in certificate replacement caused by manual registration and management of digital certificates, realizes the all-round management of certificate set distribution and use, avoids the security risks caused by certificate expiration, reduces the manual operation cost, and improves the certificate management efficiency.
[0100] Embodiment 4
[0101] Figure 7FIG. 0 is a schematic structural diagram of an electronic device provided in Embodiment 4 of the present invention. The electronic device 10 is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as, for example, personal digital assistants, cellular telephones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0102] As Figure 7 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 may perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 may also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0103] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0104] The processor 11 may be various general-purpose and / or special-purpose processing components having processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the certificate management method.
[0105] In some embodiments, the certificate management method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the certificate management method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute the certificate management method by any other suitable means (e.g., by means of firmware).
[0106] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), system-on-a-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0107] The computer program for implementing the certificate management method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the computer programs are executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0108] In particular, according to an embodiment of the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present invention includes a computer program product that includes a computer program carried on a non-transitory computer-readable medium, the computer program including program code for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication unit 19, or installed from the storage unit 18, or installed from the ROM 12. When the computer program is executed by the processor 11, the above-mentioned functions defined in the method of the embodiment of the present invention are performed.
[0109] Example 5
[0110] Example 5 of the present invention further provides a computer-readable storage medium storing computer instructions for causing a processor to execute a certificate management method, the method comprising:
[0111] Receiving, by a certificate registration module, a certificate set registration request, and sending the request to a certificate authentication module after passing the verification of the certificate set registration request; wherein the certificate set registration request is related to the service information of a client; receiving, by the certificate authentication module, the verified certificate set registration request, and feeding back to the certificate registration module a certificate set corresponding to the certificate set registration request, so as to send the certificate set to the client based on the certificate registration module; wherein the certificate set includes at least two certificates to be used, and the time ranges applicable to the at least two certificates to be used are different and there is partial overlap in the time ranges; obtaining, by a certificate management module, the certificate set and the service information corresponding to the certificate set, and sending the certificate set and the service information to a certificate configuration module after parsing and processing; sending, by the certificate configuration module, the received parsed certificate set and service information to a certificate service module, so as to provide a certificate service corresponding to the service information for the client based on the certificate service module.
[0112] In the context of the present invention, a computer-readable storage medium may be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0113] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0114] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0115] A computing system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0116] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is imposed herein.
[0117] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A certificate management system, characterized in that, Including: A certificate registration module, a certificate authentication module, a certificate management module, a certificate configuration module, and a certificate service module; wherein, The certificate registration module is used to receive a certificate set registration request and send it to the certificate authentication module after passing the verification of the certificate set registration request; wherein, the certificate set registration request is related to the business information of the client; The certificate authentication module is used to receive the verified certificate set registration request and feedback the certificate set corresponding to the certificate set registration request to the certificate registration module, so as to send the certificate set to the client based on the certificate registration module; wherein, the certificate set includes at least two certificates to be used, and the time ranges applicable to the at least two certificates to be used are different and there is partial overlap in the time ranges; The certificate management module is used to obtain the certificate set and the business information corresponding to the certificate set, and send the certificate set and the business information to the certificate configuration module after parsing and processing; The certificate configuration module is used to send the received parsed certificate set and business information to the certificate service module, so as to provide the certificate service corresponding to the business information for the client based on the certificate service module.
2. The system according to claim 1, wherein The certificate management module includes: A certificate parsing unit, which is used to parse at least two certificates to be used in the certificate set to obtain the certificate attribute information of the certificates to be used, and when the certificate attribute information meets the preset conditions, send the certificate attribute information and the business information to the certificate configuration module; wherein, the certificate attribute information at least includes the certificate version number and the certificate usage validity period.
3. The system according to claim 2, wherein The certificate management module further includes: a certificate management unit; The certificate management unit is used to save the certificate attribute information and business information parsed by the certificate parsing unit, and notify the ownership user of the certificate set according to the certificate usage validity period in the certificate attribute information.
4. The system according to claim 2, wherein The certificate management module further includes: An expired certificate deletion unit, which is used to obtain the certificate usage validity period in the certificate attribute information and delete the associated expired certificates.
5. The system according to claim 1, wherein The system further includes: A version management module, which is used to send a notification message for issuing a certificate set to the target terminal when the number of available certificates in the certificate set is less than the preset number threshold; Wherein, the available certificates correspond to the certificates to be used that are currently in use and the certificates to be used that have not been used yet.
6. The system according to claim 5, wherein The version management module is further used to switch to the target certificate to be used and delete the certificates to be used that have passed the certificate usage validity period when detecting an event with a certificate switching requirement; Wherein, the event with the certificate switching requirement includes receiving a certificate switching request or the certificate usage validity period of the currently used certificate to be used overlapping with the certificate usage validity period of the certificate to be switched to.
7. The system according to claim 1, wherein The system further includes: A synchronization detection module; the synchronization detection module includes a data acquisition unit, a data reconciliation unit, and a signal sending unit; The data acquisition unit is configured to acquire the first certificate attribute information and the first service information stored in the certificate management module, and acquire the second certificate attribute information and the second service information stored in the certificate service module; The data reconciliation unit is configured to compare the first certificate attribute information with the second certificate attribute information to obtain a first comparison result, and compare the first service information with the second service information to obtain a second comparison result; The signal sending unit is configured to determine a target signal and send the target signal to the module corresponding to the first comparison result or the second comparison result when the first comparison result and / or the second comparison result do not meet the preset conditions.
8. The system according to claim 7, characterized in that, The signal sending unit is further configured to: determine the missing target information when both the first comparison result and the second comparison result do not meet the preset conditions; wherein, the target information includes the first service information, the second service information, the first certificate attribute information, and / or the second certificate attribute information; When the target information is the first service information and / or the first certificate attribute information, send the target signal to the client to obtain the target information from the client; When the target information is the second service information and / or the second certificate attribute information, send the target signal to the certificate configuration module to obtain the target information from the certificate configuration module.
9. A certificate management method, characterized in that, Applied to a certificate management system, the certificate management system includes a certificate registration module, a certificate authentication module, a certificate management module, a certificate configuration module, and a certificate service module. The method includes: Receiving a certificate set registration request based on the certificate registration module, and sending the certificate set registration request to the certificate authentication module after passing the verification of the certificate set registration request; wherein, the certificate set registration request is related to the service information of the client; Receiving the verified certificate set registration request based on the certificate authentication module, and feeding back the certificate set corresponding to the certificate set registration request to the certificate registration module, so as to send the certificate set to the client based on the certificate registration module; wherein, the certificate set includes at least two certificates to be used, and the time ranges applicable to the at least two certificates to be used are different and there is partial overlap in the time ranges; Acquiring the certificate set and the service information corresponding to the certificate set based on the certificate management module, and sending the certificate set and the service information to the certificate configuration module after parsing and processing; Sending the received parsed certificate set and service information to the certificate service module based on the certificate configuration module, so as to provide the certificate service corresponding to the service information for the client based on the certificate service module.
10. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the certificate management method according to claim 9.