Online filling method of certificate chain
Through the online filling method, the certificate chain is automatically managed using public key and indexing technology, which solves the management inconvenience and insufficient security caused by manual configuration, and realizes convenient update and security management of the certificate chain.
Patent Information
- Application Number
- CN202510564154.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-05
AI Technical Summary
In the prior art, the filling method of the terminal certificate chain needs to be manually configured, which is prone to errors and cannot be dynamically updated, resulting in inconvenient management and insufficient security of the certificate chain.
The online filling method is adopted to write to the terminal device through a predefined public key, detect the existence and update of the certificate chain, use the verification strategy to calculate the index, request the certificate chain from the front platform, and use the public key to check and store the passed certificate chain.
It realizes convenient management of certificate chains for terminals under the same CA service, ensuring security and supporting dynamic updates of certificate chains, improving management efficiency.
Smart Images

Figure CN120433945A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security, and in particular relates to an online filling method for a certificate chain. Background Art
[0002] As digital transformation deepens, public key infrastructure (PKI) is a framework for managing public key cryptography and digital certificates. It plays a vital role in ensuring the security and integrity of network communications. PKI protects information by providing authentication, data encryption, and digital signatures. In a public key infrastructure (PKI), an end-to-end certificate chain refers to the complete certification path from the end-entity certificate to the root certificate. Each certificate is signed by the previous-level certification authority (CA) and ultimately by a trusted root CA. The integrity and validity of the certificate chain are crucial for verifying the identity of the end-entity.
[0003] Currently, terminal certificate chains are typically installed by administrators manually configuring the certificate chain on the terminal device. This method is simple but prone to errors. Once the certificate chain is manually configured on the terminal, it cannot be modified, which is not conducive to certificate updates. Summary of the Invention
[0004] In view of this, the present invention aims to propose an online filling method for a certificate chain, in order to solve at least one of the above-mentioned technical problems.
[0005] To achieve the above object, the technical solution of the present invention is achieved as follows:
[0006] The first aspect of the present invention provides an online filling method for a certificate chain, comprising:
[0007] Predefine a public key and write the public key into the terminal device;
[0008] Power on the terminal and connect it to the network and check the existence and update status of the certificate chain;
[0009] Verify the certificate chain or calculate the index of the certificate chain using a verification strategy based on the existence and update status of the certificate chain;
[0010] The terminal sends a request for obtaining a certificate chain to the front-end platform based on the index;
[0011] The front-end platform sends the corresponding certificate chain to the terminal;
[0012] The terminal uses the public key to verify the certificate chain and stores the certificate chain that passes the verification.
[0013] Furthermore, the verification strategy is:
[0014] If the certificate chain exists and is complete, use the public key to verify the certificate chain; if the certificate chain is missing or needs to be updated, calculate the index of the corresponding certificate chain.
[0015] Furthermore, the certificate chain is a binary tree structure, wherein the root node of the binary tree is the root CA certificate, the child nodes of each level of the binary tree are the CA certificates of the corresponding level, and the leaf nodes of the binary tree are the user certificates;
[0016] In the process of calculating the index, binary bits are used to represent the existence status of each certificate based on the level of the certificate.
[0017] Furthermore, the process of using binary bits to represent the existence status of each certificate is as follows:
[0018] Starting from the root node, visit the right child node first, then visit the left child node;
[0019] If the current node is the node required by the certificate chain, access the child nodes of the current node and mark the current node as 1;
[0020] Otherwise, stop visiting the child nodes of the current node and mark the current node as 0.
[0021] Furthermore, the access starts from the root node and ends at the leaf node. After the access is completed, the marking sequence of each node is recorded according to the access path to obtain the corresponding binary value, and the binary value is converted into a decimal value to obtain the index of the certificate chain.
[0022] Furthermore, after receiving the request for obtaining the certificate chain, the front-end platform sends the request to the PKI management platform. The PKI management platform parses the corresponding index, generates a certificate chain file and a signature value, and sends the generated content to the front-end platform.
[0023] Furthermore, the process of verifying the certificate chain using the public key is: using the public key to verify the signature value corresponding to the certificate chain.
[0024] A second aspect of the present invention provides an electronic device, comprising a processor and a memory communicatively connected to the processor and used to store instructions executable by the processor, wherein the processor is used to execute the method described in the first aspect.
[0025] The third aspect of the present invention proposes a server, comprising at least one processor and a memory communicatively connected to the processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the processor to enable the at least one processor to perform the method described in the first aspect.
[0026] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program, which implements the method described in the first aspect when executed by a processor.
[0027] Compared with the prior art, the online filling method of the certificate chain described in the present invention has the following beneficial effects:
[0028] The present invention allows different terminals under the same CA service to download certificate chain information required by corresponding services through indexes, which facilitates the management of the certificate chain, ensures security, increases convenience, and updates expired certificates. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The accompanying drawings, which constitute part of the present invention, are provided to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are provided to explain the present invention and do not constitute an undue limitation of the present invention. In the accompanying drawings:
[0030] Figure 1 This is a schematic diagram of the workflow of an online filling method for a certificate chain according to an embodiment of the present invention;
[0031] Figure 2 This is a schematic diagram of the certificate chain structure according to an embodiment of the present invention. DETAILED DESCRIPTION
[0032] It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments may be combined with each other.
[0033] In the description of the present invention, it should be understood that the terms "center", "longitudinal", "lateral", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside" and the like indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as limiting the present invention. In addition, the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, features defined as "first", "second", etc. may explicitly or implicitly include one or more of the features. In the description of the present invention, unless otherwise specified, "multiple" means two or more.
[0034] In the description of the present invention, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.
[0035] The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0036] like Figure 1 The first embodiment shown is an online filling method of a certificate chain, comprising:
[0037] Predefine a public key and write the public key into the terminal device;
[0038] Power on the terminal and connect it to the network and check the existence and update status of the certificate chain;
[0039] Verify the certificate chain or calculate the index of the certificate chain using a verification strategy based on the existence and update status of the certificate chain;
[0040] The terminal sends a request for obtaining a certificate chain to the front-end platform based on the index;
[0041] The front-end platform sends the corresponding certificate chain to the terminal;
[0042] The terminal uses the public key to verify the certificate chain and stores the certificate chain that passes the verification.
[0043] In this embodiment, the public key is an ECC public key. After the certificate chain is verified using the public key, a certificate chain verification instruction is used to verify to ensure that the certificate chain is within the legal validity period and whether the certificate chain reaches the root.
[0044] The verification strategy is:
[0045] If the certificate chain exists and is complete, use the public key to verify the certificate chain; if the certificate chain is missing or needs to be updated, calculate the index of the corresponding certificate chain.
[0046] In this embodiment, a prefabricated public key certificate chain and signature are verified using the ECC_SHA256 algorithm. The local server checks whether the certificate chain file exists, parses the certificate to determine the validity period, and compares it with the local time. If it expires, an update operation is performed.
[0047] like Figure 2As shown, the certificate chain is a binary tree structure, wherein the root node of the binary tree is the root CA certificate, the child nodes of each level of the binary tree are the CA certificates of the corresponding level, and the leaf nodes of the binary tree are user certificates;
[0048] In the process of calculating the index, binary bits are used to represent the existence status of each certificate based on the level of the certificate.
[0049] The process of using binary bits to represent the existence status of each certificate is as follows:
[0050] Starting from the root node, visit the right child node first, then visit the left child node;
[0051] If the current node is the node required by the certificate chain, access the child nodes of the current node and mark the current node as 1;
[0052] Otherwise, stop visiting the child nodes of the current node and mark the current node as 0.
[0053] The access starts from the root node and ends at the leaf node. After the access is completed, the marking sequence of each node is recorded according to the access path to obtain the corresponding binary value, and the binary value is converted into a decimal value to obtain the index of the certificate chain.
[0054] In this embodiment, Figure 2 As shown, if the terminal wants to implement OTA services, the terminal needs to apply online for a certificate chain including the root CA certificate, the China node CA certificate, and the general CA business certificate. The index to be passed in is 11 (decimal) = 1011 (binary, according to the ID serial number of the platform CA certificate, it is set from right to left. This scenario includes ①②④, so the corresponding binary is 1011).
[0055] 6. The online filling method of a certificate chain according to claim 1 is characterized in that after the front-end platform receives the request to obtain the certificate chain, it sends the request to the PKI management platform. The PKI management platform parses the corresponding index, generates a certificate chain file and signature value, and sends the generated content to the front-end platform.
[0056] In this embodiment, the ECC_SHA256 algorithm is used to generate the signature value.
[0057] The process of verifying the certificate chain using the public key is: using the public key to verify the signature value corresponding to the certificate chain.
[0058] In a second embodiment, an electronic device includes a processor and a memory connected to the processor for storing instructions executable by the processor, wherein the processor is configured to execute the method described in the first embodiment.
[0059] Embodiment 3, a server includes at least one processor and a memory communicatively connected to the processor, the memory storing instructions executable by the at least one processor, the instructions being executed by the processor so that the at least one processor executes the method described in embodiment 1.
[0060] In a fourth embodiment, a computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in the first embodiment is implemented.
[0061] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and description of the present invention.
[0062] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. An online filling method for a certificate chain, characterized in that: include: Predefine a public key and write the public key into the terminal device; Power on the terminal and connect it to the network and check the existence and update status of the certificate chain; Verify the certificate chain or calculate the index of the certificate chain using a verification strategy based on the existence and update status of the certificate chain; The terminal sends a request for obtaining a certificate chain to the front-end platform based on the index; The front-end platform sends the corresponding certificate chain to the terminal; The terminal uses the public key to verify the certificate chain and stores the certificate chain that passes the verification.
2. The online filling method of the certificate chain according to claim 1, characterized in that: The verification strategy is: If the certificate chain exists and is complete, use the public key to verify the certificate chain; if the certificate chain is missing or needs to be updated, calculate the index of the corresponding certificate chain.
3. The online filling method of the certificate chain according to claim 1 is characterized in that: The certificate chain is a binary tree structure, wherein the root node of the binary tree is the root CA certificate, the child nodes of each level of the binary tree are the CA certificates of the corresponding level, and the leaf nodes of the binary tree are user certificates; In the process of calculating the index, binary bits are used to represent the existence status of each certificate based on the level of the certificate.
4. The online filling method of the certificate chain according to claim 3 is characterized in that: The process of using binary bits to represent the existence status of each certificate is as follows: Starting from the root node, visit the right child node first, then visit the left child node; If the current node is the node required by the certificate chain, access the child nodes of the current node and mark the current node as 1; Otherwise, stop visiting the child nodes of the current node and mark the current node as 0.
5. The online filling method of the certificate chain according to claim 4 is characterized in that: The access starts from the root node and ends at the leaf node. After the access is completed, the marking sequence of each node is recorded according to the access path to obtain the corresponding binary value, and the binary value is converted into a decimal value to obtain the index of the certificate chain.
6. The online filling method of a certificate chain according to claim 1, characterized in that: After receiving the request for obtaining the certificate chain, the front-end platform sends the request to the PKI management platform. The PKI management platform parses the corresponding index, generates a certificate chain file and a signature value, and sends the generated content to the front-end platform.
7. The online filling method of a certificate chain according to claim 1 or 2, characterized in that: The process of verifying the certificate chain using the public key is: using the public key to verify the signature value corresponding to the certificate chain.
8. An electronic device comprising a processor and a memory in communication with the processor and configured to store instructions executable by the processor, wherein: The processor is configured to execute the method according to any one of claims 1 to 7.
9. A server, characterized in that: The invention comprises at least one processor and a memory in communication with the processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the processor so that the at least one processor performs the method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.