Mobile phone digital certificate migration method and system

By generating and scanning QR codes for key updates, and using the original certificate private key signature, the high cost and security problems in the digital certificate migration process are solved, and a digital certificate migration of smartphones that simplifies operations and improves security is realized.

CN120358497APending Publication Date: 2025-07-22GUANGDONG ELECTRONIC CERTIFICATION AUTHORITY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510464242.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

After the user replaces his mobile phone, the existing technology needs to reapply for a digital certificate, resulting in high certification costs, cumbersome operations and security risks.

Method used

By generating and scanning the QR code to update the key, using the original certificate private key signature, it can achieve no additional authentication and quick logout during the certificate migration process.

Benefits of technology

It simplifies the operation process, reduces authentication costs, improves security, and promptly cancels the original certificate, avoiding the risk of private key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358497A_ABST
    Figure CN120358497A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of communication, and discloses a smart phone digital certificate migration method and system. The method comprises the following steps: an original mobile phone terminal generates a migration request displayed in a two-dimensional code form; the new mobile phone terminal generates a new two-dimensional code based on the migration request; the original mobile phone terminal scans the new two-dimensional code to generate a key updating request; the CA / RA system verifies the signature validity of the key updating request and returns a key updating response to the original mobile phone terminal; the original mobile phone terminal clears the original key pair based on the key updating response and instructs the new mobile phone terminal to download the new certificate; after the CA / RA system receives the certificate downloading request of the new mobile phone terminal, the CA / RA system issues the digital certificate based on the new public key and cancels the original certificate, the new mobile phone terminal receives, verifies and installs the digital certificate based on the new public key, authentication is carried out based on the signature of the private key of the original certificate, additional authentication cost is not needed, operation is simplified, and user experience is improved. And meanwhile, the original certificate can be cancelled in time after the certificate is migrated, so that the safety is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a method and system for migrating digital certificates of a smart phone. Background Art

[0002] After a user changes the mobile phone, in order to continue using the digital certificate on the original mobile phone as the calling user identity information display on the new mobile phone, it is necessary to migrate the digital certificate and private key on the original mobile phone to the new mobile phone. However, due to security design reasons, the user's private key is generally bundled with mobile phone hardware identifiers such as IMEI and MAC addresses, making the private key unable to be copied to another mobile phone terminal for use. Currently, the general approach is to generate a new key pair on the new mobile phone terminal and re-apply for and install the digital certificate, but this has the following disadvantages: 1. Re-applying for a digital certificate requires re-verifying the user's identity, including the user filling in identity information, uploading an ID photo, face recognition authentication, SMS authentication, etc., with high authentication costs and cumbersome user operations; 2. On the certificate authority (CA) side, multiple digital certificates are issued for one user, increasing the management cost. 3. If the user does not timely cancel the certificate on the original mobile phone, there will be a risk that the certificate private key on the original mobile phone will be stolen or leaked.

[0003] The above content is only used to assist in understanding the technical solution of the present invention, and does not represent an admission that the above content is prior art. Summary of the Invention

[0004] The main purpose of the present invention is to provide a method and system for migrating digital certificates of a smart phone, aiming to solve the technical problems of high cost, cumbersome operation, and poor security during digital certificate migration.

[0005] To achieve the above purpose, the present invention provides a method for migrating digital certificates of a smart phone, and the method for migrating digital certificates of a smart phone includes the following steps:

[0006] The original mobile phone terminal generates a migration request through a certificate management application program, the migration request includes original certificate subject information and a request serial number, and the original certificate subject information and the request serial number are displayed in the form of a two-dimensional code;

[0007] The new mobile phone terminal scans the two-dimensional code through a certificate management application program, generates a new key pair according to the scanned information, and signs the original certificate subject information and the new public key to generate a two-dimensional code including the new public key and signature information;

[0008] The original mobile phone terminal scans the two-dimensional code including the new public key and signature information, generates a key update request according to the scanned information, and signs the key update request with the original certificate private key, and sends the signed key update request to the CA / RA system;

[0009] The CA / RA system verifies the signature validity of the key update request. If the verification passes, it returns a key update response to the original mobile terminal.

[0010] Based on the key update response, the original mobile terminal clears the original key pair and instructs the new mobile terminal to download a new certificate.

[0011] The new mobile terminal sends a certificate download request to the CA / RA system.

[0012] After receiving the certificate download request, the CA / RA system issues a digital certificate based on the new public key and revokes the original certificate.

[0013] The new mobile terminal receives and verifies the installation of the digital certificate based on the new public key to complete the migration of the digital certificate.

[0014] In some embodiments, the QR code format corresponding to the migration request is certapp: / / cmp-kur?ID=AAAAA&DN=BBBBB, where the prefix certapp represents the certificate management APP or SDK, cmp-kur represents the key update request message of CMP, AAAAA is the decimal integer value of the request serial number, and BBBBB is the string obtained by Base64 encoding the original certificate subject information.

[0015] In some embodiments, the format of the QR code containing the new public key and signature information is ertapp: / / cmp-kur?PK=CCCCC&S=

[0016] DDDDD, where CCCCC is the string obtained by Base64 encoding the new public key, and DDDDD is the string obtained by Base64 encoding the signature value.

[0017] In some embodiments, an extended flag id-regCtrl-ChangeDev is set in the message header of the key update request to instruct the CA / RA system to delay returning the new certificate until the new mobile terminal initiates a download request. The original certificate identifier CertID and the signature information of the new public key are embedded in the message body, and the message header and message body are signed using the original certificate private key, and the signature value is written into the protection field.

[0018] In some embodiments, the CA / RA system verifying the signature validity of the key update request includes:

[0019] Checking the signature value of the protection field protection;

[0020] Confirming whether the extended flag id-regCtrl-ChangeDev exists.

[0021] In some embodiments, the certificate download request is a polling request, and the request contains the original certificate subject information and the request serial number, and a new private key is used to sign the request message.

[0022] In some embodiments, the new mobile terminal sends a certificate download request to the CA / RA system, including:

[0023] The new mobile terminal places the original certificate subject information into the sender field through the certificate management application, places the request serial number into the certReqId field, signs the message header and message body with the new private key, writes the signature value into the protection field, generates a pollReq PKIMessage message, and sends the pollReq PKIMessage message to the CA / RA system. The pollReq PKIMessage message is the message corresponding to the certificate download request.

[0024] In addition, to achieve the above object, the present invention also proposes a smart phone digital certificate migration system, which includes: an original mobile terminal, a new mobile terminal, and a CA / RA system;

[0025] The original mobile terminal is used to generate a migration request through the certificate management application. The migration request contains the original certificate subject information and the request serial number, and the original certificate subject information and the request serial number are displayed in the form of a two-dimensional code.

[0026] The new mobile terminal is used to scan the two-dimensional code through the certificate management application, generate a new key pair according to the scanned information, and sign the original certificate subject information and the new public key to generate a two-dimensional code containing the new public key and signature information.

[0027] The original mobile terminal is used to scan the two-dimensional code containing the new public key and signature information, generate a key update request according to the scanned information, sign the key update request with the original certificate private key, and send the signed key update request to the CA / RA system.

[0028] The CA / RA system is used to verify the signature validity of the key update request. If the verification is passed, a key update response is returned to the original mobile terminal.

[0029] The original mobile terminal is used to clear the original key pair based on the key update response and instruct the new mobile terminal to download a new certificate.

[0030] The new mobile terminal is used to send a certificate download request to the CA / RA system.

[0031] The CA / RA system is used to issue a digital certificate based on the new public key and revoke the original certificate after receiving the certificate download request;

[0032] The new mobile terminal is used to receive and verify the installation of the digital certificate based on the new public key to complete the migration of the digital certificate.

[0033] In some embodiments, the QR code format corresponding to the migration request is certapp: / / cmp-kur? ID=AAAAA&DN=BBBBB, where the prefix certapp represents the certificate management APP or SDK, cmp-kur represents the key update request message of CMP, AAAAA is the decimal integer value of the request serial number, and BBBBB is the string obtained by Base64 encoding the original certificate subject information.

[0034] In some embodiments, the format of the QR code containing the new public key and signature information is ertapp: / / cmp-kur? PK=CCCCC&S=DDDDD, where CCCCC is the string obtained by Base64 encoding the new public key, and DDDDD is the string obtained by Base64 encoding the signature value.

[0035] In the present invention, the original mobile terminal generates a migration request through a certificate management application program. The migration request includes the original certificate subject information and the request serial number, and the original certificate subject information and the request serial number are displayed in the form of a QR code; the new mobile terminal scans the QR code through the certificate management application program, generates a new key pair according to the scanned information, and signs the original certificate subject information and the new public key to generate a QR code containing the new public key and signature information; the original mobile terminal scans the QR code containing the new public key and signature information, generates a key update request according to the scanned information, and signs the key update request with the original certificate private key, and sends the signed key update request to the CA / RA system; the CA / RA system verifies the signature validity of the key update request. If the verification is passed, a key update response is returned to the original mobile terminal; the original mobile terminal clears the original key pair based on the key update response and instructs the new mobile terminal to download the certificate; the new mobile terminal sends a certificate download request to the CA / RA system; the CA / RA system issues a digital certificate based on the new public key and revokes the original certificate after receiving the certificate download request; the new mobile terminal receives and verifies the installation of the digital certificate based on the new public key to complete the migration of the digital certificate. The above method is authenticated based on the signature of the original certificate private key, without additional authentication costs, without repeating operations such as entering information, uploading ID photos, face recognition authentication, and SMS authentication, making the operation simple. At the same time, the original certificate can be revoked in time after the certificate migration, improving the security. Description of the Drawings

[0036] Figure 1 It is a schematic flowchart of the first embodiment of the method for migrating digital certificates of a smart phone according to the present invention;

[0037] Figure 2 It is a schematic diagram of the overall architecture of the smart phone digital certificate migration system in the method for migrating digital certificates of a smart phone according to the present invention;

[0038] Figure 3 It is a schematic flowchart of the overall solution in the method for migrating digital certificates of a smart phone according to the present invention;

[0039] Figure 4 It is a schematic diagram of the data format in the method for migrating digital certificates of a smart phone according to the present invention;

[0040] Figure 5 It is a block diagram of the structure of the first embodiment of the smart phone digital certificate migration system according to the present invention.

[0041] The realization, functional features and advantages of the object of the present invention will be further described with reference to the embodiments and the accompanying drawings. Specific embodiments

[0042] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0043] The embodiments of the present invention provide a method for migrating digital certificates of a smart phone. Referring to Figure 1 , Figure 1 It is a schematic flowchart of the first embodiment of a method for migrating digital certificates of a smart phone according to the present invention.

[0044] In this embodiment, the method for migrating digital certificates of a smart phone includes the following steps:

[0045] Step S10: The original mobile terminal generates a migration request through a certificate management application program. The migration request includes the original certificate subject information and a request serial number, and the original certificate subject information and the request serial number are displayed in the form of a two-dimensional code.

[0046] In this embodiment, the execution subject of this embodiment is a smart phone digital certificate migration device. Among them, the smart phone digital certificate migration device has functions such as data processing, data communication and program operation. The smart phone digital certificate migration device can be a computer terminal device or other network devices. Of course, it can also be other devices with similar functions. This embodiment does not make any restrictions on this.

[0047] It should be noted that when a user changes their mobile phone, in order to continue using the digital certificate of the original mobile phone on the new mobile phone, the digital certificate and private key on the original mobile phone need to be migrated to the new mobile phone. However, due to security design reasons, the user's private key is generally bundled with mobile phone hardware identifiers such as IMEI and MAC address, making the private key unable to be copied and used on another mobile phone terminal. Currently, the general approach is to generate a new key pair on the new mobile phone terminal and reapply for and install the digital certificate. However, this has the following disadvantages: 1. Reapplying for a digital certificate requires re-verifying the user's identity, including the user filling in identity information, uploading ID photos, face recognition authentication, SMS authentication, etc., with high authentication costs and cumbersome user operations; 2. On the side of the Certificate Authority (CA), multiple digital certificates are issued for a single user, increasing the management cost. 3. If the user does not promptly cancel the certificate on the original mobile phone, there is a risk that the certificate private key on the original mobile phone will be stolen or leaked.

[0048] To solve the above technical problems, in this embodiment, the original mobile phone terminal generates a migration request through the certificate management application. The migration request includes the original certificate subject information and the request serial number, and the original certificate subject information and the request serial number are displayed in the form of a QR code; the new mobile phone terminal scans the QR code through the certificate management application, generates a new key pair according to the scanned information, and signs the original certificate subject information and the new public key to generate a QR code containing the new public key and signature information; the original mobile phone terminal scans the QR code containing the new public key and signature information, generates a key update request according to the scanned information, and signs the key update request with the original certificate private key, and sends the signed key update request to the CA / RA system; the CA / RA system verifies the signature validity of the key update request. If the verification passes, it returns a key update response to the original mobile phone terminal; the original mobile phone terminal clears the original key pair based on the key update response and instructs the new mobile phone terminal to download the new certificate; the new mobile phone terminal sends a certificate download request to the CA / RA system; after receiving the certificate download request, the CA / RA system issues a digital certificate based on the new public key and cancels the original certificate; the new mobile phone terminal receives and verifies and installs the digital certificate based on the new public key to complete the migration of the digital certificate. The above method is authenticated based on the signature of the original certificate private key, without additional authentication costs, without the need to repeat operations such as entering information, uploading ID photos, face recognition authentication, SMS authentication, etc., making the operation simple. At the same time, the original certificate can be promptly cancelled after the certificate migration, improving security. Specifically, it can be implemented in the following manner.

[0049] In a specific implementation, in this embodiment, the original mobile terminal generates a migration request through a certificate management application. The migration request includes the original certificate subject information and a request serial number, and the original certificate subject information and the request serial number are displayed in the form of a QR code. The new mobile terminal scans the QR code through the certificate management application, generates a new key pair according to the scanned information, signs the original certificate subject information and the new public key, and generates a QR code containing the new public key and signature information. The original mobile terminal scans the QR code containing the new public key and signature information, generates a key update request according to the scanned information, signs the key update request with the original certificate private key, and sends the signed key update request to the CA / RA system. The CA / RA system verifies the signature validity of the key update request. If the verification passes, it returns a key update response to the original mobile terminal. The original mobile terminal clears the original key pair based on the key update response and instructs the new mobile terminal to download a new certificate. The new mobile terminal sends a certificate download request to the CA / RA system. After receiving the certificate download request, the CA / RA system issues a digital certificate based on the new public key and cancels the original certificate. The new mobile terminal receives and verifies the installation of the digital certificate based on the new public key to complete the migration of the digital certificate. The above method is authenticated based on the signature of the original certificate private key, without additional authentication costs, and without the need to repeat operations such as entering information, uploading ID photos, face recognition authentication, and SMS authentication, making the operation simple. At the same time, the original certificate can be cancelled in a timely manner after the certificate migration, improving security.

[0050] In a specific implementation, in this embodiment, a digital certificate migration system for a smart phone is first proposed. The system consists of a new mobile phone terminal, an original mobile phone terminal, and a CA / RA system. Both the new mobile phone terminal and the original mobile phone terminal are installed with a certificate management APP (or SDK), and provide functions such as digital certificates and electronic signatures for upper-layer applications such as a trusted call APP through an application interface module. The present invention mainly relates to improvements in the certificate management APP and the CA / RA system to meet the requirements for digital certificate migration between mobile phone terminals. The certificate management APP (or SDK) generally includes a cryptographic algorithm library, a key pair and certificate management module, an application interface module, a user operation management interface module, a CA / RA interface module, etc. The present invention only needs to improve the user operation management interface module and the CA / RA interface module to achieve convenient and secure digital certificate migration between mobile phone terminals. The CA / RA system generally includes business functions such as user identity verification, new user certificate application, user certificate update, user certificate renewal, user certificate cancellation, and user certificate issuance. And provides an online certificate service function for users through a certificate management protocol interface module. The certificate management protocol (CMP) follows the national standard GB / T 19714 "Information Technology - Security Techniques - Public Key Infrastructure - Certificate Management Protocol". In this solution, only the certificate management protocol interface module and the user certificate change function module need to be improved to achieve convenient and secure digital certificate migration between mobile phone terminals.

[0051] Further, on the basis of the above system, combined with Figure 3 The overall process of this solution is described. Refer to Figure 3 As shown, the overall process is as follows: (1) The user activates the certificate migration operation on the certificate management APP of the original mobile phone terminal. The APP reads the original certificate subject information DN, randomly generates a request serial number certReqId, and displays the request serial number and subject information through a QR code; (2) The user opens the certificate management APP of the new mobile phone terminal to perform a QR code scanning operation, and reads the request serial number certReqId and the subject information DN; (3) After the certificate management APP of the new mobile phone terminal analyzes the QR code content, if it meets the format requirements, it generates a new key pair, signs the original certificate subject and the new public key information, and displays the new public key and signature information through a QR code; (4) The user scans the QR code on the new mobile phone terminal on the certificate management APP of the original mobile phone terminal and reads the new public key and signature information; (5) The certificate management APP of the original mobile phone terminal assembles the kur (key update request) message of the CMP, such as Figure 4The PKIMessage1, the pvno of the header is 2 (cmp2000), the sender field is the DN read in step 1, the recipient is the DN of the built-in CA, and the message protection algorithm protectionAlg is the SM3-SM2 signature algorithm. In the certReq part of the body, the certReqId is the request serial number generated in step 1, and the certTemplate is empty. For the control information in the body's controls, the OID of sub-item 1 is id-regCtrl-oldCertID, and the value CertID is the original certificate issuer and serial number. Sub-item 2 is the extended content of the present invention, the OID is the id-regCtrl-ChangeDev flag, and the value is null. In the popo part of the body, the publicKey is the new public key read in step 4, the algorithmIdentifier is the SM3-SM2 signature algorithm, and the signature is the signature information read in step 4. Then sign the header and body with the original certificate private key and write it into the protection field to generate the PKIMessage message; (6) The original mobile terminal certificate management APP submits the kur (key update request) PKIMessage message to the CA / RA; (7) The CA / RA analyzes the kur (key update request) message, verifies the signature value of the protection field, and then checks whether there is an id-regCtrl-ChangeDev flag. If so, proceed as follows Figure 4 For the PKIMessage2, assemble the kup (key update response) message, the status is 3 (waiting), indicating that the client will wait for the new mobile terminal to download and install the certificate. If there is no id-regCtrl-ChangeDev flag, it does not belong to the content of the present invention, and the CA / RA can handle it according to the original method; (8) The CA / RA returns the kup (key update response) PKIMessage message; (9) The original mobile terminal certificate management APP receives the kup (key update response) message, analyzes and gets the status as 3, clears the original key pair, and prompts the user to install the new certificate on the new mobile terminal; (10) The user performs the operation of downloading and installing the certificate in the new mobile terminal certificate management APP. Such as Figure 3For the PKIMessage3, the certificate management APP of the new mobile terminal places the original certificate DN read in step 2 into the sender field, and the read request serial number into the certReqId field. Then, it signs the header and body with the new private key, writes the signature value into the protection field, and generates a pollReq PKIMessage packet; (11) The certificate management APP of the new mobile terminal submits the pollReq PKIMessage packet to the CA / RA; (12) After receiving the pollReq PKIMessage packet, the CA / RA verifies the signature of the new key and issues a new certificate and revokes the old certificate. As Figure 3 For the PKIMessage4, assemble a kup PKIMessage packet with the status of 0 (accepted), and place the newly issued certificate into the certificate field of the packet; (13) The certificate management APP of the new mobile terminal obtains the new certificate from the kup packet and verifies and installs it; (14) The certificate management APP of the new mobile terminal sends a certConf PKIMessage confirmation message according to the CMP standard; (15) The CA / RA returns a PKIconf PKIMessage confirmation message according to the CMP standard.

[0052] In a specific implementation, the original mobile terminal generates a migration request through a certificate management application. The migration request includes the original certificate subject information and the request serial number, and displays the original certificate subject information and the request serial number in the form of a QR code. The QR code format corresponding to the migration request is certapp: / / cmp-kur?ID=AAAAA&DN=BBBBB, where the prefix certapp represents the certificate management APP or SDK, cmp-kur represents the CMP key update request message, AAAAA is the decimal integer value of the request serial number, and BBBBB is the string obtained by Base64 encoding the original certificate subject information.

[0053] Step S20: The new mobile terminal scans the QR code through a certificate management application, generates a new key pair according to the scanned information, signs the original certificate subject information and the new public key, and generates a QR code containing the new public key and signature information.

[0054] In a specific implementation, the new mobile terminal scans the generated QR code through the certificate management application, generates a new key pair according to the scanned original certificate subject information and the request serial number, signs the original certificate subject information and the new public key, and generates a QR code containing the new public key and signature information. This QR code is the generated new QR code, and its format is ertapp: / / cmp-kur?PK=CCCCC&S=DDDDD, where CCCCC is the string obtained by Base64 encoding the new public key, and DDDDD is the string obtained by Base64 encoding the signature value.

[0055] Step S30: The original mobile terminal scans the QR code containing the new public key and signature information, generates a key update request according to the scanned information, signs the key update request using the original certificate private key, and sends the signed key update request to the CA / RA system.

[0056] In a specific implementation, the original mobile terminal scans the new QR code generated by the new mobile terminal, that is, the QR code containing the new public key and signature information, and then generates a key update request. Among them, an extended flag id-regCtrl-ChangeDev is set in the message header of the key update request to indicate that the CA / RA system delays returning the new certificate until the new mobile terminal initiates a download request. The original certificate identifier CertID and the signature information of the new public key are embedded in the message body, and the message header and message body are signed using the original certificate private key, and the signature value is written into the protection field. At the same time, the key update request is signed using the certificate private key, and the signed key update request is sent to the CA / RA system. Specifically, refer to Figure 4 The PKIMessage1 shown. The pvno of the header is 2 (cmp2000). The original certificate subject information DN read by the sender field, the recipient is the DN of the built-in CA, and the message protection algorithm protectionAlg is the SM3-SM2 signature algorithm. In the certReq part of the body, the certReqId is the request serial number, and the certTemplate is empty. In the controls control information of the body, the OID of sub-item 1 is id-regCtrl-oldCertID, and the value CertID is the original certificate issuer and serial number. Sub-item 2 is the extended content of the present invention, the OID is the id-regCtrl-ChangeDev flag, and the value is null. In the popo part of the body, the publicKey is the new public key, the algorithmIdentifier is the SM3-SM2 signature algorithm, and the signature is the signature information. The header and body are signed using the original certificate private key and written into the protection field to generate the PKIMessage message.

[0057] Step S40: The CA / RA system verifies the signature validity of the key update request. If the verification passes, a key update response is returned to the original mobile terminal.

[0058] In a specific implementation, the CA / RA system needs to verify the signature validity of the key update request. The specific verification process includes checking the signature value of the protection field protection; confirming whether the extended flag id-regCtrl-ChangeDev exists. If the signature values are consistent and the extended flag id-regCtrl-ChangeDev exists, it is determined that the verification passes, and then a key update response is returned to the original mobile terminal.

[0059] Step S50: The original mobile terminal clears the original key pair based on the key update response and instructs the new mobile terminal to download a new certificate.

[0060] In a specific implementation, after receiving the key update response, the original mobile terminal clears the original key pair first. After the clearing is completed, the new mobile terminal starts the operation of downloading the certificate.

[0061] Step S60: The new mobile terminal sends a certificate download request to the CA / RA system.

[0062] Step S70: After receiving the certificate download request, the CA / RA system issues a digital certificate based on the new public key and revokes the original certificate.

[0063] In a specific implementation, after receiving the certificate download instruction, the new mobile terminal sends a certificate download request to the CA / RA system. This certificate download request is a polling request. The request contains the original certificate subject information and the request serial number, and signs the request message with the new private key. The certificate download request contains a new key signature. The CA / RA system will verify the new key signature again. After the verification passes, a new certificate is issued. At the same time, to ensure security, the old certificate will be revoked. The CA / RA system assembles a kup PKIMessage packet with status 0 (accepted) and places the newly issued certificate into the certificate field of the packet.

[0064] Step S80: The new mobile terminal receives and verifies the installation of the digital certificate based on the new public key to complete the migration of the digital certificate.

[0065] It should be understood that the new mobile terminal can obtain the new certificate from the kup PKIMessage packet, and then verify and install the digital certificate issued by the CA / RA system based on the new public key, thereby completing the migration of the digital certificate.

[0066] In this embodiment, the original mobile terminal generates a migration request through the certificate management application. The migration request includes the original certificate subject information and the request serial number, and the original certificate subject information and the request serial number are displayed in the form of a two-dimensional code. The new mobile terminal scans the two-dimensional code through the certificate management application, generates a new key pair according to the scanned information, signs the original certificate subject information and the new public key, and generates a two-dimensional code containing the new public key and the signature information. The original mobile terminal scans the two-dimensional code containing the new public key and the signature information, generates a key update request according to the scanned information, signs the key update request with the original certificate private key, and sends the signed key update request to the CA / RA system. The CA / RA system verifies the signature validity of the key update request. If the verification passes, it returns a key update response to the original mobile terminal. The original mobile terminal clears the original key pair based on the key update response and instructs the new mobile terminal to download the new certificate. The new mobile terminal sends a certificate download request to the CA / RA system. After receiving the certificate download request, the CA / RA system issues a digital certificate based on the new public key and cancels the original certificate. The new mobile terminal receives and verifies the installation of the digital certificate based on the new public key to complete the migration of the digital certificate. The above method is authenticated based on the signature of the original certificate private key, without additional authentication costs, without repeating operations such as entering information, uploading ID photos, face recognition authentication, and SMS authentication, making the operation simple. At the same time, the original certificate can be cancelled in time after the certificate migration, improving the security.

[0067] Refer to Figure 5 , Figure 5 is the structural block diagram of the first embodiment of the digital certificate migration system for smart phones of the present invention.

[0068] As Figure 5 shown, the digital certificate migration system for smart phones proposed in the embodiment of the present invention includes: an original mobile terminal 10, a new mobile terminal 20, and a CA / RA system 30;

[0069] The original mobile terminal 10 is used to generate a migration request through the certificate management application. The migration request includes the original certificate subject information and the request serial number, and the original certificate subject information and the request serial number are displayed in the form of a two-dimensional code.

[0070] The new mobile terminal 20 is used to scan the two-dimensional code through the certificate management application, generate a new key pair according to the scanned information, sign the original certificate subject information and the new public key, and generate a two-dimensional code containing the new public key and the signature information.

[0071] The original mobile terminal 10 is used to scan the two-dimensional code containing the new public key and signature information, generate a key update request according to the scanned information, sign the key update request using the original certificate private key, and send the signed key update request to the CA / RA system;

[0072] The CA / RA system 30 is used to verify the signature validity of the key update request. If the verification passes, it returns a key update response to the original mobile terminal;

[0073] The original mobile terminal 10 is used to clear the original key pair based on the key update response and instruct the new mobile terminal to download a new certificate;

[0074] The new mobile terminal 20 is used to send a certificate download request to the CA / RA system;

[0075] The CA / RA system 30 is used to issue a digital certificate based on the new public key and revoke the original certificate after receiving the certificate download request;

[0076] The new mobile terminal 20 is used to receive and verify the installation of the digital certificate based on the new public key to complete the migration of the digital certificate.

[0077] In this embodiment, the original mobile terminal generates a migration request through a certificate management application program. The migration request includes the original certificate subject information and a request serial number, and the original certificate subject information and the request serial number are displayed in the form of a two-dimensional code; the new mobile terminal scans the two-dimensional code through the certificate management application program, generates a new key pair according to the scanned information, and signs the original certificate subject information and the new public key to generate a two-dimensional code containing the new public key and signature information; the original mobile terminal scans the two-dimensional code containing the new public key and signature information, generates a key update request according to the scanned information, signs the key update request using the original certificate private key, and sends the signed key update request to the CA / RA system; the CA / RA system verifies the signature validity of the key update request. If the verification passes, it returns a key update response to the original mobile terminal; the original mobile terminal clears the original key pair based on the key update response and instructs the new mobile terminal to download a new certificate; the new mobile terminal sends a certificate download request to the CA / RA system; the CA / RA system issues a digital certificate based on the new public key and revokes the original certificate after receiving the certificate download request; the new mobile terminal receives and verifies the installation of the digital certificate based on the new public key to complete the migration of the digital certificate. The above method is authenticated based on the signature of the original certificate private key, without additional authentication costs, without repeating operations such as entering information, uploading ID photos, face recognition authentication, and SMS authentication, making the operation simple. At the same time, the original certificate can be revoked in time after the certificate migration, improving security.

[0078] In some embodiments, the QR code format corresponding to the migration request is certapp: / / cmp-kur?ID=AAAAA&DN=BBBBB, where the prefix certapp represents the certificate management APP or SDK, cmp-kur represents the key update request message of CMP, AAAAA is the decimal integer value of the request serial number, and BBBBB is the string obtained by Base64 encoding the original certificate subject information.

[0079] In some embodiments, the format of the QR code containing the new public key and signature information is ertapp: / / cmp-kur?PK=CCCCC&S=DDDDD, where CCCCC is the string obtained by Base64 encoding the new public key, and DDDDD is the string obtained by Base64 encoding the signature value.

[0080] In some embodiments, an extended flag id-regCtrl-ChangeDev is set in the message header of the key update request to indicate that the CA / RA system delays returning the new certificate until the new mobile terminal initiates a download request. The original certificate identifier CertID and the signature information of the new public key are embedded in the message body, and the message header and message body are signed using the original certificate private key, and the signature value is written into the protection field.

[0081] In some embodiments, the CA / RA system 30 is used to check the signature value of the protection field protection;

[0082] Confirm whether the extended flag id-regCtrl-ChangeDev exists.

[0083] In some embodiments, the certificate download request is a polling request, and the request contains the original certificate subject information and the request serial number, and the request message is signed using the new private key.

[0084] In some embodiments, the new mobile terminal 20 sends a certificate download request to the CA / RA system, including:

[0085] The new mobile terminal places the original certificate subject information into the sender field through the certificate management application, places the request serial number into the certReqId field, signs the message header and message body using the new private key, writes the signature value into the protection field, generates a pollReq PKIMessage message, and sends the pollReq PKIMessage message to the CA / RA system. The pollReq PKIMessage message is the message corresponding to the certificate download request.

[0086] The embodiment of the present application also provides a digital certificate migration device for a smart phone, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus. The memory is used to store the digital certificate migration program for the smart phone. The processor is used to implement the above-mentioned digital certificate migration method for the smart phone when executing the program stored in the memory.

[0087] The communication bus mentioned in the above digital certificate migration device for the smart phone can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0088] The communication interface is used for communication between the above digital certificate migration device for the smart phone and other devices.

[0089] The memory can include a Random Access Memory (RAM), or can also include a Non-Volatile Memory (NVM), such as at least one disk memory. Optionally, the memory can also be at least one storage device located far from the aforementioned processor.

[0090] The above-mentioned processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0091] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)).

[0092] It should be noted that, in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0093] Each embodiment in this specification is described in a related manner. The same or similar parts between the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.

[0094] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

[0095] It should be understood that the above is only an example for illustration, and does not constitute any limitation to the technical solutions of the present invention. In specific applications, those skilled in the art can set according to needs, and the present invention does not limit this.

[0096] It should be noted that the above-described work process is only illustrative and does not constitute a limitation to the protection scope of the present invention. In actual applications, those skilled in the art can select some or all of them according to actual needs to achieve the purpose of the solution of this embodiment, and there is no limitation here.

[0097] In addition, for the technical details not described in detail in this embodiment, reference can be made to the smartphone digital certificate migration method provided in any embodiment of the present invention, and details will not be repeated here.

[0098] In addition, it should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article or system. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or system including that element.

[0099] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0100] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solutions of the present invention, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as a read-only memory (ROM) / RAM, magnetic disk, optical disk), and includes several instructions to enable a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0101] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be similarly included in the patent protection scope of the present invention.

[0102] It can be understood that the system provided by the embodiment of the present invention corresponds to the method provided by the embodiment of the present invention. For the explanations, examples and beneficial effects of related content, reference can be made to the corresponding parts in the above method.

Claims

1. A method for migrating digital certificates of a smart phone, characterized in that, The method for migrating digital certificates of a smart phone includes: The original mobile terminal generates a migration request through a certificate management application. The migration request includes original certificate subject information and a request serial number, and the original certificate subject information and the request serial number are displayed in the form of a two-dimensional code; The new mobile terminal scans the two-dimensional code through a certificate management application, generates a new key pair according to the scanned information, signs the original certificate subject information and the new public key, and generates a two-dimensional code containing the new public key and signature information; The original mobile terminal scans the two-dimensional code containing the new public key and signature information, generates a key update request according to the scanned information, signs the key update request with the original certificate private key, and sends the signed key update request to the CA / RA system; The CA / RA system verifies the signature validity of the key update request. If the verification passes, it returns a key update response to the original mobile terminal; The original mobile terminal clears the original key pair based on the key update response and instructs the new mobile terminal to download a new certificate; The new mobile terminal sends a certificate download request to the CA / RA system; After receiving the certificate download request, the CA / RA system issues a digital certificate based on the new public key and cancels the original certificate; The new mobile terminal receives and verifies the installation of the digital certificate based on the new public key to complete the migration of the digital certificate.

2. The method for migrating digital certificates of a smart phone according to claim 1, wherein The two-dimensional code format corresponding to the migration request is certapp: / / cmp-kur?ID=AAAAA&DN=BBBBB, where the prefix certapp represents the certificate management APP or SDK, cmp-kur represents the key update request message of CMP, AAAAA is the decimal integer value of the request serial number, and BBBBB is the string obtained by Base64 encoding the original certificate subject information.

3. The method for migrating digital certificates of a smart phone according to claim 1, wherein The two-dimensional code format containing the new public key and signature information is ertapp: / / cmp-kur?PK=CCCCC&S=DDDDD, where CCCCC is the string obtained by Base64 encoding the new public key, and DDDDD is the string obtained by Base64 encoding the signature value.

4. The method for migrating digital certificates of a smart phone according to claim 1, characterized in that, An extended flag id-regCtrl-ChangeDev is set in the message header of the key update request to instruct the CA / RA system to delay returning the new certificate until the new mobile terminal initiates a download request. The original certificate identifier CertID and the signature information of the new public key are embedded in the message body, and the message header and message body are signed with the original certificate private key, and the signature value is written into the protection field.

5. The method for migrating digital certificates of a smart phone according to claim 4, wherein The CA / RA system verifies the signature validity of the key update request, including: Checking the signature value of the protection field protection; Confirming whether the extended flag id-regCtrl-ChangeDev exists.

6. The method for migrating digital certificates of a smart phone according to claim 1, characterized in that, The certificate download request is a polling request, and the request includes the original certificate subject information and the request serial number, and the request message is signed with the new private key.

7. The method for migrating digital certificates of a smart phone according to claim 6, wherein The new mobile terminal sends a certificate download request to the CA / RA system, including: The new mobile terminal places the original certificate subject information into the sender field through the certificate management application, places the request serial number into the certReqId field, signs the message header and message body with the new private key, writes the signature value into the protection field, generates a pollReq PKIMessage message, and sends the pollReq PKIMessage message to the CA / RA system. The pollReq PKIMessage message is the message corresponding to the certificate download request.

8. A digital certificate migration system for a smart phone, characterized in that, The smart phone digital certificate migration system includes: an original mobile terminal, a new mobile terminal, and a CA / RA system; The original mobile terminal is used to generate a migration request through the certificate management application. The migration request includes the original certificate subject information and the request serial number, and displays the original certificate subject information and the request serial number in the form of a two-dimensional code. The new mobile terminal is used to scan the two-dimensional code through the certificate management application, generate a new key pair according to the scanned information, and sign the original certificate subject information and the new public key to generate a two-dimensional code containing the new public key and signature information. The original mobile terminal is used to scan the two-dimensional code containing the new public key and signature information, generate a key update request according to the scanned information, and sign the key update request with the original certificate private key, and send the signed key update request to the CA / RA system. The CA / RA system is used to verify the signature validity of the key update request. If the verification passes, it returns a key update response to the original mobile terminal. The original mobile terminal is used to clear the original key pair based on the key update response and instruct the new mobile terminal to download a new certificate. The new mobile terminal is used to send a certificate download request to the CA / RA system. The CA / RA system is used to issue a digital certificate based on the new public key and cancel the original certificate after receiving the certificate download request. The new mobile terminal is used to receive and verify the installation of the digital certificate based on the new public key to complete the migration of the digital certificate.

9. The smartphone digital certificate migration system according to claim 1, characterized in that, The two-dimensional code format corresponding to the migration request is certapp: / / cmp-kur?ID=AAAAA&DN=BBBBB, where the prefix certapp represents the certificate management APP or SDK, cmp-kur represents the key update request message of CMP, AAAAA is the decimal integer value of the request serial number, and BBBBB is the string obtained by Base64 encoding the original certificate subject information.

10. The smartphone digital certificate migration system according to claim 8, characterized in that, The format of the two-dimensional code containing the new public key and signature information is ertapp: / / cmp-kur?PK=CCCCC&S=DDDDD, where CCCCC is the string obtained by Base64 encoding the new public key, and DDDDD is the string obtained by Base64 encoding the signature value.