Failure determination method, certificate failure list creation method, program, failure determination system, and certificate failure list creation system

By introducing conditional information from extended regions into the certificate invalidation list, the problem of inflexibility in determining multiple certificate invalidations is solved, enabling flexible determination of both classic certificates and quantum-resistant encryption certificates.

CN120958771APending Publication Date: 2025-11-14PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202480021471.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-03-29
Filing Date
2024-02-13
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

Existing certificate invalidation determination methods lack flexibility when dealing with multiple certificates, and cannot distinguish between the invalidation of classic certificates and quantum-resistant encryption certificates, leading to unnecessary certificate invalidation determinations.

Method used

By introducing an extended area into the certificate invalidation list, which includes conditional information such as the signature algorithm and the reason for invalidation, the determination of whether a certificate is invalid is improved, thus increasing the flexibility of the determination.

Benefits of technology

It enables flexible invalidation determination of multiple certificates, distinguishing between the invalidation of classical certificates and quantum-resistant encryption certificates, thus improving the accuracy and flexibility of determination.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120958771A_ABST
    Figure CN120958771A_ABST
Patent Text Reader

Abstract

The failure determination method comprises: acquiring an electronic certificate (S301); acquiring a certificate failure list including one or more failed certificates, which are failed electronic certificates (S301); on the basis of a serial number included in the acquired certificate failure list and one or more pieces of condition information indicated by one or more extension regions included in the acquired certificate failure list, it is determined whether or not the acquired electronic certificate has failed (S302-S306).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to failure determination methods, certificate failure list creation methods, programs, failure determination systems, and certificate failure list creation systems. Background Technology

[0002] Patent document 1 discloses an electronic certificate verification method. The method includes: a stage of obtaining an electronic certificate; a stage of verifying the obtained electronic certificate; a stage of obtaining attribute certification authority identification information from the electronic certificate; a stage of accessing an attribute certification authority based on the obtained attribute certification authority identification information to obtain an attribute certificate; and a stage of verifying the obtained attribute certificate.

[0003] Patent document 2 discloses a certificate registration method. The method includes: a receiving step, receiving a new electronic certificate from a communication terminal via a network, wherein a registration command information is represented in an extended area; a judging step, judging whether the received new electronic certificate is valid or invalid; an extraction step, extracting the registration command information represented in the extended area of ​​the input new valid electronic certificate if it is judged to be valid; and a registration step, registering the new valid electronic certificate based on the extracted registration command information.

[0004] Existing technical documents

[0005] Patent documents

[0006] Patent Document 1: Japanese Patent Application Publication No. 2004-356842

[0007] Patent Document 2: Japanese Patent Application Publication No. 2005-311817 Summary of the Invention

[0008] The technical problem that the invention aims to solve

[0009] This disclosure provides methods for determining the validity of electronic certificates, which can easily improve the flexibility of the determination process.

[0010] Technical solutions for solving the problem

[0011] One technical solution disclosed herein relates to a failure determination method comprising: obtaining an electronic certificate; obtaining a certificate failure list, the certificate failure list including one or more failed certificates that are expired electronic certificates; and determining whether the obtained electronic certificate has expired based on the serial number of the obtained certificate failure list and one or more condition information represented by one or more extended areas of the obtained certificate failure list.

[0012] In addition, one technical solution disclosed herein involves a program that causes one or more processors to execute the failure determination method.

[0013] Furthermore, one technical solution disclosed herein relates to a failure determination system comprising a first acquisition unit, a second acquisition unit, and a determination unit. The first acquisition unit acquires an electronic certificate. The second acquisition unit acquires a certificate failure list, which includes one or more expired electronic certificates. The determination unit determines whether the electronic certificate acquired by the first acquisition unit has expired based on the serial number in the certificate failure list acquired by the second acquisition unit and one or more conditional information represented by one or more extended areas in the certificate failure list acquired by the second acquisition unit.

[0014] In addition, one technical solution disclosed herein relates to a method for creating a certificate expiration list, which includes: obtaining one or more serial numbers for each of one or more expired electronic certificates; obtaining one or more condition information corresponding to one or more extended areas of a certificate expiration list including the one or more expired certificates, each representing an expiration condition; and creating the certificate expiration list by recording the obtained serial numbers in one or more serial number areas of the certificate expiration list, and recording the obtained condition information in one or more extended areas of the certificate expiration list.

[0015] In addition, one technical solution disclosed herein involves a program that enables one or more processors to execute the certificate expiration list creation method.

[0016] Furthermore, one technical solution disclosed herein relates to a certificate expiration list creation system comprising a third acquisition unit, a fourth acquisition unit, and a creation unit. The third acquisition unit acquires one or more serial numbers for each of one or more expired electronic certificates. The fourth acquisition unit acquires one or more condition information corresponding to one or more extended areas of a certificate expiration list including the one or more expired certificates, representing the conditions of expiration. The creation unit creates the certificate expiration list by recording the one or more serial numbers acquired by the third acquisition unit in one or more serial number areas of the certificate expiration list, and by recording the one or more condition information acquired by the fourth acquisition unit in one or more extended areas of the certificate expiration list.

[0017] Invention Effects

[0018] According to this disclosure, it has the advantage of easily improving the flexibility of determining the invalidity of electronic certificates. Attached Figure Description

[0019] Figure 1 This is a diagram illustrating a summary of the process for verifying the invalidation of an electronic certificate.

[0020] Figure 2 This is a diagram representing an example of an electronic certificate.

[0021] Figure 3 This diagram illustrates the issues encountered when verifying the invalidation of multiple certificates.

[0022] Figure 4 This is a diagram used to illustrate the overview of the failure determination method according to Embodiment 1.

[0023] Figure 5 This is a block diagram illustrating an example of the overall configuration of the failure determination system according to Implementation Method 1.

[0024] Figure 6 This is a block diagram illustrating an example of the functional configuration of the CRL manufacturing apparatus according to Embodiment 1.

[0025] Figure 7 This is a block diagram illustrating an example of the functional configuration of the CRL providing device according to Embodiment 1.

[0026] Figure 8 This is a block diagram illustrating an example of the functional configuration of the failure confirmation device according to Embodiment 1.

[0027] Figure 9 This is a block diagram illustrating an example of the functional configuration of the certificate notification device according to Embodiment 1.

[0028] Figure 10 This is a timing diagram showing an example of the overall configuration of the failure determination system according to Implementation Method 1.

[0029] Figure 11 This is a flowchart representing the action example of the failure determination system for comparison examples.

[0030] Figure 12 This is a flowchart illustrating an example of the operation of the failure determination system involved in Implementation Method 1.

[0031] Figure 13 This is a diagram illustrating an example of a failure rule in the failure determination system according to Implementation Method 1.

[0032] Figure 14 This is an explanatory diagram of a determination example in the failure determination system according to Implementation Method 1.

[0033] Figure 15 This is a block diagram illustrating an example of the overall configuration of the failure determination system according to Implementation Method 2.

[0034] Figure 16This is a block diagram illustrating an example of the functional configuration of the OCSP response device according to Embodiment 2.

[0035] Figure 17 This is a block diagram illustrating an example of the functional configuration of the failure confirmation device according to Embodiment 2.

[0036] Figure 18 This is a timing diagram showing an example of the overall configuration of the failure determination system involved in Implementation 2.

[0037] Figure 19 This is a diagram representing an example of one or more extended areas of a certificate expiration list. Detailed Implementation

[0038] (The insights that form the basis of this disclosure)

[0039] In communications on networks such as the Internet, public keys and electronic certificates (public key certificates) are used, which combine the certificate with the owner's verified information. Hereinafter, electronic certificates will simply be referred to as "certificates." Certificates are issued by certificate authorities such as Certification Authorities (CAs), and may become invalid even within their validity period, for various reasons, such as the leakage of the secret key (private key). Validated electronic certificates (hereinafter referred to as "invalid certificates") are registered in the Certificate Revocation List (CRL) issued by the certificate authority. Therefore, in communications, users receiving certificates need to verify whether the certificate has become invalid, or in other words, whether the certificate is registered in the CRL.

[0040] Figure 1 This is a diagram illustrating a summary of the verification process for the expiration of electronic certificates. In the following explanation, unless otherwise specified, "User A" refers to the information terminal used by User A, and "User B" refers to the information terminal used by User B. The information terminal is, for example, a personal computer, smartphone, or tablet computer, or any other terminal with a processor and memory.

[0041] Figure 2 This is a diagram illustrating an example of an electronic certificate. (For example...) Figure 2 As shown, the electronic certificate includes information that represents the serial number assigned to each electronic certificate, the signature algorithm used for digital signature, the issuer of the electronic certificate, the issuance date of the electronic certificate, and the validity period of the electronic certificate.

[0042] exist Figure 1 In the process, the certificate issuing authority first issues a certificate with serial number "1A2B3C" to user A (refer to...). Figure 1(0)). If the certificate becomes invalid for some reason after its issuance, the certificate issuing authority updates the CRL by registering the certificate with the CRL (see [reference]). Figure 1 (1)). Here, the new serial number “1A2B3C” is registered in the CRL.

[0043] Then, when user A communicates with user B, user A sends and prompts user B with a certificate with serial number "1A2B3C" (see reference). Figure 1 (2)). User B who received the certificate obtained the CRL (refer to...). Figure 1 (3) and confirm whether the CRL includes the serial number of the received certificate to determine invalidity (refer to Figure 1 (4)). In Figure 1 In the example shown, a certificate with serial number "1A2B3C" is registered in the CRL. Therefore, user B will determine that the certificate received from user A has expired.

[0044] In recent years, the development of quantum computers has been booming due to their emergence. On the other hand, it is known that the large-scale deployment of quantum computers theoretically increases the risk of currently used encryption methods (hereinafter referred to as "classical encryption methods"). In view of this situation, quantum-resistant encryption methods (hereinafter referred to as "PQC (Post Quantum Cryptography) methods") have been proposed as new encryption methods capable of withstanding the computational power of large-scale quantum computers. Research is underway on the transition from certificates using classical encryption methods (hereinafter referred to as "classical certificates") to certificates using PQC methods (hereinafter referred to as "PQC certificates"). Classical encryption methods include, for example, RSA encryption or elliptic curve cryptography. PQC methods include, for example, CRYSTALS-Dilithium encryption.

[0045] During the transition from classic encryption to PQC, devices supporting PQC and those not supporting it will coexist. Therefore, a certificate with interchangeability that can be used on both devices is needed, and development of such a certificate is underway. As such a certificate, a highly interchangeable certificate (hereinafter also referred to as a "multi-certificate") with the following characteristics has been developed. The multi-certificate has the characteristic of including both classic and PQC certificates. Furthermore, the multi-certificate has the characteristic that the serial number is common to both classic and PQC certificates.

[0046] However, since the serial number of multiple certificates is shared between the classic certificate and the PQC certificate, a PQC certificate may be downgraded to a classic certificate when it should be used. This downgrade could occur, for example, by mistakenly using a classic certificate in a scenario where the user should preferentially use a PQC certificate. Additionally, downgrade could be caused by a malicious third party attempting to replace the PQC certificate with a classic certificate. Therefore, invalidating the downgraded certificate is considered, but using an existing CRL would lead to the following problems.

[0047] Figure 3 This diagram illustrates the issues encountered when verifying the invalidation of multiple certificates. Figure 3 In the process, the certificate issuing authority first issues a multi-certificate with serial number "1A2B3C" to user A (refer to...). Figure 3 (0)). After the issuance of this multi-certificate, in order to invalidate the classic certificate in the multi-certificate, the certificate authority updates the CRL by registering the serial number "1A2B3C" of the multi-certificate in the CRL (see [reference]). Figure 3 (1)).

[0048] Then, suppose user A wants to send and prompt user B a PQC certificate with sequence number "1A2B3C" when communicating with user B, but because the PQC certificate has been downgraded, the classic certificate is prompted to user B instead (see reference). Figure 3 (2)). User B who receives the certificate obtains the CRL (refer to...). Figure 3 (3)) The invalidation is determined by checking whether the CRL includes the serial number of the received certificate (refer to) Figure 3 (4)). In Figure 3 In the example shown, because a certificate with serial number "1A2B3C" is registered in the CRL, user B will determine that the certificate received from user A is invalid.

[0049] However, in the aforementioned CRL, because the certificate is identified solely by its serial number, even if the intention is to invalidate only the classic certificate, both the classic certificate and the PQC certificate will be invalidated. Figure 3 In the example shown, all multiple certificates with serial number "1A2B3C" were set to invalid. This demonstrates a lack of flexibility in invalidation determination for electronic certificates that use serial numbers.

[0050] In view of the above circumstances, the present disclosure aims to provide a method for determining the invalidity of electronic certificates that can easily improve the flexibility of determining invalidity by utilizing one or more extended areas of the CRL.

[0051] More specifically, the failure determination method of the first technical solution of this disclosure includes: obtaining an electronic certificate; obtaining a certificate failure list, the certificate failure list including one or more failed certificates that are expired electronic certificates; and determining whether the obtained electronic certificate has expired based on the serial number of the obtained certificate failure list and one or more condition information represented by one or more extended areas of the obtained certificate failure list.

[0052] Therefore, instead of referring only to the serial number in the certificate invalidation list, the electronic certificate is identified by referring to one or more conditions represented by one or more extended areas. This has the following advantages: for example, even if there are multiple electronic certificates with the same serial number, only one electronic certificate will be invalidated, which makes it easier to improve the flexibility of electronic certificate invalidation determination.

[0053] Furthermore, for example, the failure determination method disclosed in the second technical solution of this invention includes, in the first technical solution, one or more extended regions containing information representing the signature algorithm of the failed object. If the serial number of the electronic certificate is included in the certificate failure list and the signature algorithm of the electronic certificate is consistent with the signature algorithm of the failed object, the electronic certificate is determined to be invalid.

[0054] Therefore, it has the following advantages: for example, even if there are multiple electronic certificates with the same serial number, the signature algorithm can be used to distinguish each electronic certificate and determine whether the electronic certificate has expired.

[0055] Furthermore, for example, in the failure determination method of the third technical solution of this disclosure, in the first or second technical solution, one or more extended areas include information indicating the reason for failure. If the serial number of the electronic certificate is included in the certificate failure list and the electronic certificate meets the reason for failure, the electronic certificate is determined to be invalid.

[0056] Therefore, it has the following advantages: for example, even if there are multiple electronic certificates with the same serial number, it is possible to distinguish each electronic certificate based on the reason for invalidation and determine whether the electronic certificate is invalid.

[0057] In addition, for example, in any of the first to third technical solutions, the electronic certificate in the failure determination method of the fourth technical solution of this disclosure is a certificate using classical encryption or a certificate using quantum-resistant encryption.

[0058] Therefore, it has the following advantages: even in the case of multiple certificates, including a certificate with a common classical encryption method and a certificate with a quantum-resistant encryption method, it is possible to invalidate only one of the classical encryption method certificate and the quantum-resistant encryption method certificate.

[0059] In addition, for example, the failure determination method involved in the fifth technical solution of this disclosure, in the fourth technical solution, the device for confirming whether the electronic certificate has expired further refers to whether it supports quantum-resistant encryption to determine whether the electronic certificate has expired.

[0060] Therefore, the validity of an electronic certificate can be determined based on the type of device, thus offering the advantage of easily improving the flexibility of electronic certificate validity determination.

[0061] In addition, for example, the program involved in the sixth technical solution of this disclosure causes one or more processors to execute the failure determination method of any one of the first to fifth technical solutions.

[0062] Therefore, it has the advantage of being able to achieve the same effect as the failure determination method described above.

[0063] Furthermore, for example, the failure determination system according to the seventh technical solution of this disclosure includes a first acquisition unit, a second acquisition unit, and a determination unit. The first acquisition unit acquires an electronic certificate. The second acquisition unit acquires a certificate failure list, which includes one or more failed electronic certificates. The determination unit determines whether the electronic certificate acquired by the first acquisition unit has expired based on the serial number of the certificate failure list acquired by the second acquisition unit and one or more condition information represented by one or more extended areas of the certificate failure list acquired by the second acquisition unit.

[0064] Therefore, it has the advantage of being able to achieve the same effect as the failure determination method described above.

[0065] Additionally, for example, the method for creating a certificate expiration list according to the eighth technical solution of this disclosure includes: obtaining one or more serial numbers for each of one or more expired electronic certificates; obtaining one or more condition information corresponding to one or more extended areas of the certificate expiration list that includes one or more expired certificates, representing the conditions of expiration; and creating a certificate expiration list by recording one or more obtained serial numbers in one or more serial number areas of the certificate expiration list, and recording one or more obtained condition information in one or more extended areas of the certificate expiration list.

[0066] Therefore, when determining whether a certificate has expired, it is possible to identify the electronic certificate by referring to one or more conditions represented by one or more extended areas, rather than just the serial number in the certificate expiration list. This has the following advantages: for example, even if there are multiple electronic certificates with the same serial number, it is possible to identify only one electronic certificate, thus improving the flexibility of electronic certificate expiration determination.

[0067] Additionally, for example, the program involved in the ninth technical solution of this disclosure causes one or more processors to execute the certificate invalidation list creation method involved in the eighth technical solution.

[0068] Therefore, it has the advantage of being able to achieve the same effect as the certificate invalidation list creation method described above.

[0069] Furthermore, for example, the certificate expiration list creation system according to the tenth technical solution of this disclosure includes a third acquisition unit, a fourth acquisition unit, and a creation unit. The third acquisition unit acquires one or more serial numbers for each of one or more expired electronic certificates. The fourth acquisition unit acquires one or more condition information indicating the conditions of expiration, corresponding to one or more extended areas of the certificate expiration list that includes one or more expired certificates. The creation unit creates the certificate expiration list by recording one or more serial numbers acquired by the third acquisition unit in one or more serial number areas of the certificate expiration list, and recording one or more condition information acquired by the fourth acquisition unit in one or more extended areas of the certificate expiration list.

[0070] Therefore, it has the advantage of being able to achieve the same effect as the certificate invalidation list creation method described above.

[0071] Furthermore, these specific or concrete technical solutions can be implemented by systems, devices, methods, integrated circuits, computer programs, or non-transient recording media such as CD-ROMs that can be read by computers, or by any combination of systems, devices, methods, integrated circuits, computer programs, and recording media.

[0072] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Furthermore, the embodiments described below are either inclusive or specific examples. The numerical values, shapes, materials, constituent elements, arrangements of constituent elements, connection methods, steps, and order of steps shown in the following embodiments are examples and are not intended to limit this disclosure. Additionally, constituent elements in the following embodiments not described in the independent claims will be described as arbitrary constituent elements. Furthermore, the figures are schematic diagrams and are not necessarily strictly illustrative. Also, in the figures, substantially identical constituent reference numerals and reference numerals are sometimes omitted or simplified in their description.

[0073] (Implementation Method 1)

[0074] [1. Summary]

[0075] First, an overview of the failure determination system (failure determination method) involved in Embodiment 1 will be provided. In Embodiment 1, the electronic certificate that becomes the object of failure determination in the failure determination system is a certificate using classical encryption or a certificate using quantum-resistant encryption (PQC). Figure 4 This is a diagram used to illustrate an overview of the failure determination method according to Embodiment 1. Figure 4 In this context, the failure determination system is an information terminal used by user B.

[0076] exist Figure 4 In the process, the certificate issuing authority first issues a multi-certificate with serial number "1A2B3C" to user A (refer to...). Figure 4 (0)). After the issuance of this multi-certificate, in order to invalidate the classic certificate in the multi-certificate, the certificate authority updates the CRL by registering the serial number "1A2B3C" of the multi-certificate in the CRL and creating a CRL that includes one or more non-critical extended areas (see [reference]). Figure 4 (1)). In Figure 4 In the example shown, the "Signature Algorithm" extension area corresponding to the serial number "1A2B3C" states "SECP256r1," and the "Reason for Invalidation" extension area states "PQC version available." "SECP256r1" represents one of the elliptic curve cryptography signature algorithms. "PQC version available" indicates that the classic certificate is invalidated due to the existence of a PQC certificate.

[0077] Then, suppose user A wants to send and prompt user B a PQC certificate with the sequence number "1A2B3C" when communicating with user B, but because the PQC certificate has been downgraded, the classic certificate is prompted to user B instead (see [reference]). Figure 4 (2)). User B who received the certificate obtained the CRL (refer to...). Figure 4 (3) and confirm whether the CRL includes the serial number of the received certificate and whether the certificate meets more than one condition information represented by more than one extended area, in order to determine the invalidity (refer to Figure 4 (4)). In Figure 4 In the example shown, since a certificate with serial number "1A2B3C" is registered in the CRL and meets the conditions described in more than one extended region, user B will determine that the classic certificate received from user A is invalid.

[0078] As mentioned above, in Figure 4In the CRL shown, since the certificate is identified not only by referring to the serial number, but by referring to one or more conditional information represented by one or more extended areas, it is possible to invalidate only the classic certificate without invalidating both the classic certificate and the PQC certificate. That is, the failure determination system (failure determination method) according to Embodiment 1 has the advantage of easily improving the flexibility of electronic certificate failure determination by utilizing one or more extended areas of the CRL to invalidate only the classic certificate.

[0079] [2. Composition]

[0080] Next, the overall configuration of the failure determination system according to Embodiment 1 will be described. Figure 5 This is a block diagram illustrating an example of the overall configuration of the failure determination system according to Embodiment 1. For example... Figure 5 As shown, in Embodiment 1, communication is described between the certificate notification device 400 managed and used by user A and the failure confirmation device 300 managed and used by user B. In Embodiment 1, the failure confirmation device 300 corresponds to a failure determination system. Both the failure confirmation device 300 and the certificate notification device 400 are implemented by information terminals such as personal computers, smartphones, or tablet computers.

[0081] The certificate issuing authority manages and uses the CRL creation device 100 and the CRL provisioning device 200. In Embodiment 1, the CRL creation device 100 is equivalent to a certificate expiration list creation system (described later). Both the CRL creation device 100 and the CRL provisioning device 200 are implemented by server devices or the like. Furthermore, the CRL creation device 100 can be integrally constructed with the CRL provisioning device 200, or it can be included as part of the functions of the CRL provisioning device 200.

[0082] In Implementation 1, the CRL creation device 100, the CRL providing device 200, the failure confirmation device 300, and the certificate notification device 400 are configured to communicate with each other via a network such as the Internet.

[0083] Figure 6 This is a block diagram illustrating an example of the functional configuration of the CRL creation apparatus 100 according to Embodiment 1. The CRL creation apparatus 100 parses the information of expired certificates input by the certificate issuing authority and creates CRL information. In addition to the newly created CRL, the CRL information also includes CRL update information for updating an already created CRL. The CRL update information can be the updated CRL or information about the differences between the updated CRL and the existing CRL. The CRL creation apparatus 100 sends the created CRL information to the CRL providing apparatus 200.

[0084] The CRL production device 100 includes a processor and a memory, through which the processor executes programs stored in the memory to achieve its functions. For example... Figure 6 As shown, the CRL generation apparatus 100 includes an input unit 101, a serial number extraction unit 102, an extended area generation unit 103, a CRL information generation unit 104, and a communication unit 105.

[0085] Input unit 101 accepts input of information for expired certificates selected by the certificate issuing authority. The information for expired certificates includes the certificate's serial number. Additionally, the information may also include the certificate issuer, the purpose of the certificate, the signature algorithm used for the certificate, or the reason for the certificate's expiration.

[0086] The serial number extraction unit 102 extracts one or more serial numbers from the information of one or more expired certificates input into the input unit 101. The serial number extraction unit 102 is equivalent to the third acquisition unit in the certificate expiration list creation system. The serial number extraction unit 102 (the third acquisition unit) acquires one or more serial numbers for each of the one or more expired electronic certificates that are expired.

[0087] The extended region generation unit 103 extracts one or more conditional information entries from the information of one or more expired certificates input into the input unit 101. These conditional information entries are written in one or more extended regions of the CRL information generated by the CRL information generation unit 104. The conditional information indicates the conditions for expiration. The extended region generation unit 103 corresponds to the fourth acquisition unit in the certificate expiration list creation system. The extended region generation unit 103 (the fourth acquisition unit) acquires one or more conditional information entries corresponding to one or more extended regions of a certificate expiration list (CRL) containing one or more expired certificates, each indicating the conditions for expiration. Furthermore, when the information of an expired certificate input into the input unit 101 does not contain conditional information, NULL (empty) is extracted. In Embodiment 1, the extended region generation unit 103 extracts information indicating the signature algorithm as conditional information written in the first extended region and extracts information indicating the reason for expiration as conditional information written in the second extended region.

[0088] The CRL information generation unit 104 records the serial number extracted by the serial number extraction unit 102 in the serial number area, which records the serial number in the CRL information. Additionally, the CRL information generation unit 104 records the information extracted by the extension area generation unit 103 in the corresponding extension area according to each extension area. The CRL information generation unit 104 is equivalent to the production unit in the certificate expiration list production system. The CRL information generation unit 104 (production unit) produces the certificate expiration list by recording one or more serial numbers obtained by the serial number extraction unit 102 (third acquisition unit) in one or more serial number areas of the certificate expiration list (CRL), and by recording one or more condition information obtained by the extension area generation unit 103 (fourth acquisition unit) in one or more extension areas of the certificate expiration list.

[0089] In Implementation 1, the CRL information generation unit 104 records the information representing the signature algorithm extracted by the extended area generation unit 103 in the first extended area, and records the information representing the reason for failure in the second extended area. Thus, the CRL information generation unit 104 generates CRL information, which includes the serial number of the invalid certificate and information recorded in each of the extended areas of one or more extended areas associated with that serial number.

[0090] The communication unit 105 sends the CRL information generated by the CRL information generation unit 104 to the CRL providing device 200.

[0091] Figure 7 This is a block diagram illustrating an example of the functional configuration of the CRL providing device 200 according to Embodiment 1. The CRL providing device 200 stores the CRL information generated by the CRL generating device 100. In addition, when the CRL providing device 200 receives a CRL request from the failure confirmation device 300, it sends a CRL reply including CRL information to the failure confirmation device 300.

[0092] The CRL providing device 200 includes a processor and memory, through which the processor executes programs stored in the memory to perform its functions. For example... Figure 7 As shown, the CRL providing device 200 includes a CRL storage unit 201, a CRL updating unit 202, a CRL reply generation unit 203, and a communication unit 204.

[0093] The CRL storage unit 201 stores the CRL information received by the communication unit 204 from the CRL creation apparatus 100. Additionally, the CRL storage unit 201 stores the updated CRL information by the CRL update unit 202. The CRL storage unit 201 can store both the CRL itself as CRL information and the updated CRL information as CRL information.

[0094] When the CRL update unit 202 receives CRL update information from the CRL creation device 100 via the communication unit 204, it saves the CRL update information as CRL information in the CRL storage unit 201. Alternatively, the CRL update unit 202 can read the CRL from the CRL storage unit 201, update part or all of the read CRL using the CRL update information, and save the updated CRL as CRL information in the CRL storage unit 201.

[0095] When the communication unit 204 receives a CRL request from the failure confirmation device 300, the CRL response generation unit 203 reads the CRL information from the CRL storage unit 201 and generates a CRL response including the read CRL information.

[0096] The communication unit 204 receives CRL information from the CRL generation device 100. Additionally, the communication unit 204 receives a CRL request from the failure confirmation device 300. Furthermore, the communication unit 204 sends a CRL response generated by the CRL generation unit 203 to the failure confirmation device 300.

[0097] Figure 8 This is a block diagram illustrating an example of the functional configuration of the failure verification device 300 according to Embodiment 1. When the failure verification device 300 receives a certificate from the certificate prompting device 400, it saves the certificate. Furthermore, the failure verification device 300 generates a CRL request and sends the generated CRL request to the CRL providing device 200. The CRL request may also include information about the CRL saved by the failure verification device 300, information about the failure verification device 300, information about the certificate, or information about the purpose of the certificate, etc.

[0098] The failure verification device 300 includes a processor and a memory, and its functions are achieved by executing a program stored in the memory through the processor. For example... Figure 8 As shown, the failure confirmation device 300 includes a CRL storage unit 301, a certificate storage unit 302, a CRL update unit 303, a CRL request generation unit 304, a failure determination unit 305, and a communication unit 306.

[0099] CRL storage unit 301 stores the CRL. Additionally, CRL storage unit 301 stores the updated CRL when the CRL is updated by CRL update unit 303.

[0100] The certificate storage unit 302 stores the certificate received by the communication unit 306 from the certificate prompting device 400.

[0101] When the CRL update unit 303 receives a CRL reply from the CRL providing device 200 via the communication unit 306, it saves the updated CRL contained in the CRL reply to the CRL storage unit 301. Alternatively, if the CRL reply contains CRL update information, the CRL update unit 303 can read the CRL from the CRL storage unit 301, update part or all of the read CRL using the CRL update information, and save the updated CRL to the CRL storage unit 301.

[0102] The CRL request generation unit 304 generates a CRL request when the failure determination unit 305 performs failure determination processing to determine whether the certificate has expired.

[0103] When the communication unit 306 receives a certificate from the certificate notification device 400, the failure determination unit 305 performs failure determination processing to determine whether the received certificate has expired. First, the failure determination unit 305 requests the latest CRL from the CRL providing device 200 and updates the CRL stored in the CRL storage unit 301 to the latest CRL. Furthermore, if the CRL included in the CRL response is the same as the CRL already stored in the CRL storage unit 301, the CRL may not be updated. Then, the failure determination unit 305 uses the latest CRL and pre-stored failure rules to determine whether the received certificate has expired. The failure determination unit 305 is equivalent to the determination unit in the failure determination system. The failure determination unit 305 (determination unit) determines whether the electronic certificate obtained by the communication unit 306 (the first acquisition unit described later) has expired based on the serial number in the Certificate Expiration List (CRL) obtained by the communication unit 306 (the second acquisition unit described later) and one or more condition information represented by one or more extended areas in the Certificate Expiration List obtained by the communication unit 306. The failure determination process will be explained in detail in [3-2. Failure Determination Process] described later.

[0104] Communication unit 306 receives the certificate from certificate notification device 400. Communication unit 306 is equivalent to the first acquisition unit in the invalidation determination system for obtaining electronic certificates. Additionally, communication unit 306 sends a CRL request generated by CRL request generation unit 304 to CRL providing device 200. Furthermore, communication unit 306 receives a CRL response from CRL providing device 200. Here, as described above, the CRL response includes CRL information. Communication unit 306 is equivalent to the second acquisition unit in the invalidation determination system for obtaining a Certificate Expiration List (CRL) that includes one or more expired electronic certificates.

[0105] Figure 9This is a block diagram illustrating an example of the functional configuration of the certificate prompting device 400 according to Embodiment 1. The certificate prompting device 400 sends and prompts certificates to other users when communicating with them.

[0106] The certificate prompting device 400 has a processor and a memory, and its function is achieved by executing a program stored in the memory through the processor. For example... Figure 9 As shown, the certificate prompting device 400 includes a certificate storage unit 401 and a communication unit 402.

[0107] The certificate storage unit 401 stores the certificate upon receiving it issued by the certificate issuing authority.

[0108] The communication unit 402 receives certificates from certificate issuing authorities. Additionally, when communicating with other users, the communication unit 402 sends the certificates stored in the certificate storage unit 401 to the other users' information terminals (here, the invalidation confirmation device 300).

[0109] [3. Action]

[0110] [3-1. Basic Movements]

[0111] The following describes an example of the overall configuration of the failure determination system according to Implementation Method 1. Figure 10 This is a timing diagram illustrating an operational example of the overall configuration of the failure determination system according to Implementation Method 1. Hereinafter, we will describe an example where a certificate issuing authority issues a certificate to user A and the certificate notification device 400 stores the certificate. Furthermore, we will describe an example where the CRL is updated after the certificate is issued.

[0112] First, the CRL creation device 100 parses the information of the expired certificate entered by the certificate issuing authority and creates CRL information (S101). Then, the CRL creation device 100 sends the created CRL information to the CRL providing device 200 (S102). When the CRL providing device 200 receives the CRL information, it updates the stored CRL (S103). Thus, the latest CRL is stored in the CRL providing device 200.

[0113] Next, when user A communicates with another user (user B in this case), the stored certificate is sent to the other user's information terminal (the failure verification device 300 in this case) (S104). When the failure verification device 300 receives the certificate, it generates a CRL request (S105). Furthermore, the failure verification device 300 sends the generated CRL request to the CRL providing device 200 (S106). When the CRL providing device 200 receives the CRL request, it generates a CRL reply and sends the generated CRL reply to the failure verification device 300 (S107).

[0114] Next, when the failure verification device 300 receives a CRL reply, it updates the stored CRL using the received CRL reply (S108). Thus, the latest CRL is stored in the failure verification device 300. Then, the failure verification device 300 uses the latest CRL to determine whether the received certificate is invalid (S109).

[0115] [3-2. Failure Detection and Handling]

[0116] Here, we will explain in detail the invalidation determination process for determining whether a received certificate has expired. First, using... Figure 11 The failure determination process in the comparative example failure determination system will be explained. The comparative example failure determination system is equivalent to a failure verification device that does not support extended areas of the CRL. Here, "not supporting extended areas of the CRL" means that the device cannot recognize the extended areas of the CRL.

[0117] Furthermore, whether a failure verification device supports the extended range of CRL depends on its performance. For example, failure verification devices that support PQC encryption are generally capable of firmware updates and have sufficient performance, thus generally supporting the extended range of CRL. On the other hand, failure verification devices that do not support PQC encryption are generally unable to update firmware and / or have insufficient performance, thus generally not supporting the extended range of CRL.

[0118] Figure 11 This is a flowchart illustrating the operation of the comparative example failure determination system (failure verification device). First, the failure verification device acquires the certificate and CRL (S201). Then, if the CRL contains the serial number of the acquired certificate (S202: Yes), the failure verification device determines that the certificate has expired (S203). On the other hand, if the CRL does not contain the serial number of the acquired certificate (S202: No), the failure verification device determines that the certificate is valid (S204). As described above, the comparative example failure determination system determines whether the certificate has expired by referring only to the certificate's serial number.

[0119] Next, use Figure 12 The failure determination process in the failure determination system according to Embodiment 1 will be described. The failure determination system according to Embodiment 1 is equivalent to the failure verification device 300 as already described. Furthermore, the failure verification device 300 supports the extended region of the CRL. Figure 12 This is a flowchart illustrating an example of the operation of the failure determination system (failure confirmation device 300) according to Embodiment 1.

[0120] First, the failure verification device 300 obtains the certificate and CRL (S301). Then, if the CRL contains the serial number of the obtained certificate (S302: Yes), the failure verification device 300 then extracts the values ​​of one or more extended regions of the CRL corresponding to that serial number (S303). Specifically, when the serial number I = {k1, ..., kn} is set, the failure verification device 300 extracts the values ​​V1 = {Vk1, 1, ..., Vkn, 1} of the first extended region, ..., and the values ​​VN = {Vk1, N, ..., Vkn, N} of the Nth extended region. In Embodiment 1, the values ​​V1 of the first extended region and V2 = {Vk1, 2, ..., Vkn, 2} of the second extended region are extracted.

[0121] Then, the failure verification device 300 uses the values ​​of one or more extended regions extracted to determine whether the certificate conforms to the failure rules. If it conforms to the failure rules (S304: Yes), the certificate is determined to be invalid (S305). On the other hand, if the certificate does not conform to the failure rules (S305: No) or if the certificate's serial number is not recorded in the CRL (S302: No), the failure verification device 300 determines that the certificate is valid.

[0122] Figure 13 This diagram illustrates an example of a failure rule in the failure determination system (failure confirmation device 300) according to Embodiment 1. Figure 13 In the logical expression, "A" represents the certificate's signature algorithm. The invalidation rules are broadly categorized into four cases: (1) the invalidation confirmation device 300 supports PQC and the certificate's signature algorithm is classical encryption; (2) the invalidation confirmation device 300 supports PQC and the certificate's signature algorithm is PQC; (3) the invalidation confirmation device 300 does not support PQC and the certificate's signature algorithm is classical encryption; (4) the invalidation confirmation device 300 does not support PQC and the certificate's signature algorithm is PQC. Thus, in the invalidation determination system (invalidation determination method) according to Embodiment 1, the device for confirming whether an electronic certificate has expired (invalidation confirmation device 300) further determines whether the electronic certificate has expired by referring to whether it supports quantum-resistant encryption (PQC).

[0123] In case (1), the failure confirmation device 300 is if the signature algorithm of the certificate is consistent with the signature algorithm represented by the value of the first extended region (see reference). Figure 13 (1-1)), the value of the second extended region indicates the reason for failure as any one of "secret key leakage", "abnormal issuance", and "increased algorithm risk" (see reference). Figure 13If (1-2) is true, then it is determined to meet the failure rules. Additionally, if the failure confirmation device 300 finds that the signature algorithm of the certificate is consistent with the signature algorithm represented by the value of the first extended region (refer to...), then it is determined to meet the failure rules. Figure 13 (1-1)), the value of the second extended region indicates the reason for failure as "PQC version exists" and the certificate's signature algorithm is not PQC (refer to...). Figure 13 If (1-3) is true, it is determined to meet the failure rules. On the other hand, if the failure confirmation device 300 is in a situation other than the above, it is determined to not meet the failure rules.

[0124] In case (2), if the failure confirmation device 300 is consistent with the signature algorithm of the certificate and the signature algorithm represented by the value of the first extended region (see reference). Figure 13 If (2-1) is true, it is determined to meet the failure rule; if not, it is determined to not meet the failure rule.

[0125] In case (3), if the failure confirmation device 300 has a signature algorithm for the certificate that is consistent with the signature algorithm represented by the value of the first extended region (see reference). Figure 13 (3-1)), and the failure reason represented by the value of the second extended region is any one of "secret key leakage", "abnormal issuance" and "increased algorithm risk" (refer to) Figure 13 If (3-2) is true, it is determined to meet the failure rules. On the other hand, if the failure confirmation device 300 is in a situation other than the above, it is determined to not meet the failure rules.

[0126] In case (4), if the failure confirmation device 300 has a signature algorithm for the certificate that is consistent with the signature algorithm represented by the value of the first extended region (see reference). Figure 13 If the signature algorithm of the certificate is not recorded in the CRL, it is determined to be invalid. If it is not consistent, it is determined to be invalid. In addition, in the case of (4), even if the signature algorithm of the certificate is not recorded in the CRL, it is determined to be invalid through signature verification.

[0127] The following is a specific example of the invalidation determination process. Hereinafter, we assume the certificate serial number is "1A2B3C", the certificate signature algorithm is the classic encryption method "SECP256r1", and the invalidation verification device 300 supports PQC mode. Furthermore, we assume the invalidation verification device 300 in... Figure 12 The step S303 shown is illustrated by extracting I = {1A2B3C}, V1 = {SECP256r1}, and V2 = {with PQC version} from one or more extended regions.

[0128] First, since the invalidation verification device 300 supports PQC and the certificate's signature algorithm is a classic encryption method, it determines that the invalidation meets the condition of (1). Next, since V1 = {SECP256r1} and the certificate's signature algorithm A = {SECP256r1}, the invalidation verification device 300 determines that the invalidation meets the condition of (1-1). Furthermore, since V2 = {with PQC version}, the invalidation verification device 300 determines that the invalidation meets the condition of (1-3). Therefore, in this case, the invalidation verification device 300 determines that the certificate has expired.

[0129] Figure 14 This is an explanatory diagram of a determination example in the failure determination system (failure confirmation device 300) according to Embodiment 1. Figure 14 (a) represents an example of information described in the CRL. Figure 14 (b) represents an example of a certificate being invalidated or valid through an invalidation determination process.

[0130] For example, for a classic certificate with serial number "1A2B3C", in a failure verification device 300 that supports PQC, because of the failure reason of PQC version, it is set as invalid to prevent it from being missed due to downgrading, but the PQC certificate is set as valid. Conversely, in a failure verification device 300 that does not support PQC, only classic certificates can be recognized, and downgrading is impossible; therefore, the classic certificate is set as valid.

[0131] Furthermore, for example, a certificate using PQC encryption with the serial number "8G9H0I" is invalidated in a PQC-supporting invalidation verification device 300 because the secret key has been leaked. On the other hand, a classic certificate is invalidated because it has a PQC version, but since the PQC certificate is invalid, it is set to valid in place of the PQC certificate. Additionally, in an invalidation verification device 300 that does not support PQC, only classic certificates are recognized, and downgrading is not possible; therefore, the classic certificate is set to valid.

[0132] [4. Advantages]

[0133] The advantages of the failure determination system (failure determination method) according to Embodiment 1 will be explained below. As described above, in the failure determination system according to Embodiment 1, the certificate is identified by referring to one or more condition information represented by one or more extended areas, rather than by referring only to the CRL serial number, as in the failure determination system of the comparative example. Therefore, in the failure determination system according to Embodiment 1, even if there are multiple certificates with the same serial number (multiple certificates in Embodiment 1), only one certificate is invalidated, which has the advantage of easily improving the flexibility of electronic certificate failure determination.

[0134] Furthermore, in the invalidation determination system according to Embodiment 1, both the certificate's signature algorithm and the invalidation reason are used to determine whether a certificate has expired. Here, even referring only to the signature algorithm, it is possible to distinguish between a classic certificate and a PQC certificate. However, when referring only to the signature algorithm, there may be situations where there is a reason that should invalidate the classic certificate, but it cannot be invalidated. For example, if the risk of the signature algorithm increases to be the invalidation reason, the classic certificate must be invalidated regardless of whether the invalidation verification device supports PQC. However, when referring only to the signature algorithm, it is impossible to invalidate the classic certificate in an invalidation verification device that does not support PQC encryption. In contrast, in the invalidation determination system according to Embodiment 1, since both the signature algorithm and the invalidation reason are used, it has the advantage of being able to invalidate the classic certificate even in such cases.

[0135] (Implementation Method 2)

[0136] [1. Composition]

[0137] The failure determination system (failure determination method) involved in Implementation Method 2 will be described below. Figure 15 This is a block diagram illustrating an example of the overall configuration of the failure determination system according to Embodiment 2. The difference between the failure determination system according to Embodiment 2 and the failure determination system according to Embodiment 1 is that instead of the failure confirmation device 300A managed and used by user B, it is replaced by an OCSP response device 500, which functions as an OCSP (Online Certificate Status Protocol) responder. Furthermore, the difference between the failure determination system according to Embodiment 2 and the failure determination system according to Embodiment 1 is that the Certificate Authority does not manage and use the CRL providing device 200; its function is integrated into the OCSP response device 500. In the following description, the commonalities with the failure determination system according to Embodiment 1 are omitted.

[0138] Figure 16 This is a block diagram illustrating an example of the functional configuration of the OCSP response device 500 according to Embodiment 2. In Embodiment 2, the OCSP response device 500 is implemented, for example, by a server device. The OCSP response device 500 stores the CRL information generated by the CRL creation device 100. Furthermore, when the OCSP response device 500 receives a certificate and a determination request from the invalidation confirmation device 300A, it determines whether the certificate has expired and sends the determination result to the invalidation confirmation device 300A.

[0139] The OCSP response device 500 includes a processor and a memory, through which the processor executes a program stored in the memory to perform its functions. For example... Figure 16 As shown, the OCSP response device 500 includes a CRL storage unit 501, a CRL update unit 502, a failure determination unit 503, and a communication unit 504.

[0140] The CRL storage unit 501 stores the CRL information received by the communication unit 504 from the CRL generation device 100. Additionally, the CRL storage unit 501 stores the CRL information updated by the CRL update unit 502. The CRL storage unit 501 can store both the CRL itself as CRL information and the updated CRL information as CRL information.

[0141] When the CRL update unit 502 receives CRL update information from the CRL creation apparatus 100 via the communication unit 504, it saves the CRL update information as CRL information in the CRL storage unit 501. Alternatively, the CRL update unit 502 can read the CRL from the CRL storage unit 501, update part or all of the read CRL using the CRL update information, and save the updated CRL as CRL information in the CRL storage unit 501.

[0142] Upon receiving a certificate and determination request from the failure confirmation device 300A via the communication unit 504, the failure determination unit 503 performs failure determination processing. The failure determination unit 503 is equivalent to the determination unit in the failure determination system. The failure determination processing is the same as that in Embodiment 1, therefore, its description is omitted here.

[0143] Communication unit 504 receives the certificate from failure verification device 300A. Communication unit 504 is equivalent to the first acquisition unit in the failure determination system. Additionally, communication unit 504 receives CRL information from CRL generation device 100. Communication unit 504 is equivalent to the second acquisition unit in the failure determination system. Furthermore, communication unit 504 sends the determination result of the failure determination process performed by failure determination unit 503 to failure verification device 300A.

[0144] Figure 17 This is a block diagram illustrating an example of the functional configuration of the failure verification device 300A according to Embodiment 2. When the failure verification device 300A receives a certificate from the certificate prompting device 400, it sends the received certificate and a determination request to the OCSP response device 500. Additionally, the failure verification device 300A receives the determination result from the OCSP response device 500.

[0145] The failure verification device 300A has a processor and a memory, and its functions are achieved by the processor executing a program stored in the memory. For example... Figure 17 As shown, the failure confirmation device 300A includes a certificate storage unit 301A, a judgment request generation unit 302A, a judgment result storage unit 303A, and a communication unit 304A.

[0146] The certificate storage unit 301A stores the certificates received by the communication unit 304A from the certificate prompting device 400.

[0147] When the communication unit 304A receives a certificate from the certificate prompting device 400, the determination request generation unit 302A generates a determination request.

[0148] When the determination result storage unit 303A receives the determination result from the OCSP response device 500 via the communication unit 304A, it stores the received determination result.

[0149] The communication unit 304A receives the certificate from the certificate prompting device 400. Additionally, the communication unit 304A sends the judgment request created by the judgment request creation unit 302A and the received certificate to the OCSP response device 500. Furthermore, the communication unit 304A receives the judgment result from the OCSP response device 500.

[0150] [2. Action]

[0151] The following describes an example of the overall configuration of the failure determination system according to Implementation Method 2. Figure 18 This is a timing diagram illustrating an operational example of the overall configuration of the failure determination system according to Embodiment 2. Hereinafter, we will describe an example where a certificate issuing authority issues a certificate to user A and the certificate notification device 400 stores the certificate. Furthermore, we will describe an example where the CRL is updated after the certificate is issued.

[0152] First, the CRL creation device 100 parses the information of the expired certificate entered by the certificate issuing authority and creates CRL information (S401). Then, the CRL creation device 100 sends the created CRL information to the OCSP response device 500 (S402). When the OCSP response device 500 receives the CRL information, it updates the stored CRL (S403). Thus, the latest CRL is stored in the OCSP response device 500.

[0153] Next, when user A communicates with another user (user B in this case), the stored certificate is sent to the other user's information terminal (the failure verification device 300A in this case) (S404). When the failure verification device 300A receives the certificate, it generates a determination request (S405). Then, the failure verification device 300A sends the received certificate and the generated determination request to the OCSP response device 500 (S406).

[0154] When the OCSP response device 500 receives a certificate and a determination request, it uses the latest CRL to determine whether the received certificate has expired (S407). Then, the OCSP response device 500 sends the determination result to the expiration confirmation device 300A (S408).

[0155] As described above, in the failure determination system according to Embodiment 2, unlike Embodiment 1 where the failure confirmation device 300 performs the failure determination process locally, the OCSP response device 500, which is a server device, performs the failure determination process. Thus, in the failure determination system according to Embodiment 2, the entity performing the failure determination process is different from that in Embodiment 1, but it has the same advantages as the failure determination system according to Embodiment 1.

[0156] (Other implementation methods)

[0157] The above describes embodiments 1 and 2, but this disclosure is not limited to the embodiments 1 and 2 described above.

[0158] In embodiments 1 and 2 described above, one or more extended regions represent one or more pieces of condition information, such as the certificate's signature algorithm and invalidation reason, but are not limited to these. For example, one or more pieces of condition information may also include information representing other conditions. Figure 19 This is a diagram representing one or more extended regions of a Certificate Expiration List (CRL). For example... Figure 19 As shown, more than one set of conditional information may also include the certificate's scheduled expiration date and the address of the PQC certificate.

[0159] After using Figure 19 In the case of the CRL shown, for example, a certificate with serial number "1A2B3C" and signature algorithm "SECP256r1" as a classic encryption method can be taken as follows: That is, the certificate becomes invalid due to the reason "a PQC version exists," but this invalidation reason is related to the transition from classic encryption to PQC, so it may not become invalid immediately. In such a case, by referring to the "scheduled expiration date" as condition information, a grace period (in other words, a public notice period) can be set before the certificate becomes invalid. Furthermore, by referring to the "address of the PQC certificate" as condition information, a PQC certificate paired with the classic certificate can be obtained during the grace period.

[0160] Furthermore, in embodiments 1 and 2 described above, the condition information represented by the extended region can also be only one. For example, the extended region can also describe only either the signature algorithm or the reason for failure.

[0161] In addition, in the above implementation methods 1 and 2, the certificate is not limited to either the classic certificate or the PQC certificate, but can also be a certificate of other encryption methods.

[0162] Furthermore, in embodiments 1 and 2 described above, other processing units may perform the processing performed by the specific processing unit. Additionally, the order of multiple processes can be changed, or multiple processes can be executed in parallel.

[0163] Furthermore, in embodiments 1 and 2 described above, each component can also be implemented by executing a software program suitable for that component. Each component can also be implemented by a program execution unit such as a CPU (Central Processing Unit) or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0164] Furthermore, each component can also be implemented in hardware. For example, each component can be a circuit (or integrated circuit). These circuits can either form a single circuit as a whole or be separate independent circuits. Additionally, each of these circuits can be either a general-purpose circuit or a dedicated circuit.

[0165] Furthermore, the general or specific technical solutions of this disclosure can also be implemented by an apparatus, method, integrated circuit, computer program, or a recording medium such as a CD-ROM that can be read by a computer. Additionally, the general or specific technical solutions of this disclosure can also be implemented by any combination of apparatus, method, integrated circuit, computer program, and recording medium.

[0166] For example, this disclosure can be implemented as a failure determination method executed by a computer, or as a program for causing a computer to execute the failure determination method. This disclosure can also be implemented as a non-transitory recording medium that can be read by a computer and contains such a program.

[0167] Furthermore, this disclosure can be implemented, for example, as a method for creating a certificate expiration list executed by a computer, or as a program for causing a computer to execute the certificate expiration list creation method. This disclosure can also be implemented as a non-transitory recording medium readable by a computer that contains such a program.

[0168] Furthermore, embodiments derived by implementing various modifications that can be conceived by those skilled in the art, or embodiments implemented by arbitrarily combining the constituent elements and functions of each embodiment without departing from the spirit of this disclosure, are also included in this disclosure.

[0169] Industrial availability

[0170] This disclosure is useful in determining the invalidity of electronic certificates.

[0171] Label Explanation

[0172] 100 CRL Creation Device (Certificate Expiration List Creation System)

[0173] 101 Input Section

[0174] 102 Serial Number Extraction Unit (3rd Acquisition Unit)

[0175] 103 Extended Region Generation Section (4th Acquisition Section)

[0176] 104 CRL Information Generation Department (Production Department)

[0177] 105 Ministry of Communications

[0178] 200 CRL provides the device

[0179] 201 CRL Preservation Department

[0180] 202 CRL Update Department

[0181] 203 CRL Reply Production Department

[0182] 204 Ministry of Communications

[0183] 300 Failure Confirmation Device (Failure Determination System)

[0184] 301 CRL Preservation Department

[0185] 302 Certificate Preservation Department

[0186] 303 CRL Update Department

[0187] 304 CRL Request Generation Department

[0188] 305 Failure Judgment Department (Judgment Department)

[0189] 306 Communications Department (First Acquisition Department, Second Acquisition Department)

[0190] 300A Failure Confirmation Device

[0191] 301A Certificate Retention Department

[0192] 302A Judgment Request Production Department

[0193] 303A Judgment Result Storage Department

[0194] 304A Communications Department

[0195] 400 Certificate Reminder Device

[0196] 401 Certificate Retention Department

[0197] 402 Ministry of Communications

[0198] 500 OCSP Response Device (Failure Determination System)

[0199] 501 CRL Preservation Department

[0200] 502 CRL Update Department

[0201] 503 Failure Detection Department (Detection Department)

[0202] 504 Communications Department (First Acquisition Department, Second Acquisition Department)

Claims

1. A failure determination method, comprising: Obtain an electronic certificate; Obtain a certificate expiration list, which includes one or more expired electronic certificates. Based on the serial number of the obtained certificate expiration list and one or more condition information represented by one or more extended areas of the obtained certificate expiration list, it is determined whether the obtained electronic certificate has expired.

2. The failure determination method according to claim 1, The one or more extended regions include information representing the signature algorithm of the invalidated object. If the serial number of the electronic certificate is included in the certificate invalidation list, and the signature algorithm of the electronic certificate is consistent with the signature algorithm of the invalidated object, the electronic certificate is determined to be invalid.

3. The failure determination method according to claim 1 or 2, The one or more extended regions include information indicating the reason for failure. If the serial number of the electronic certificate is included in the certificate invalidation list and the electronic certificate meets the invalidation reason, the electronic certificate is determined to be invalid.

4. The failure determination method according to claim 1 or 2, The electronic certificate is either a certificate using classical encryption or a certificate using quantum-resistant encryption.

5. The failure determination method according to claim 4, The device for confirming whether the electronic certificate has expired further refers to whether the quantum-resistant encryption method is supported to determine whether the electronic certificate has expired.

6. A program that causes one or more processors to execute the failure determination method as described in claim 1 or 2.

7. A failure determination system, comprising: The first department obtains an electronic certificate; The second acquisition unit acquires a certificate invalidation list, which includes one or more invalid certificates that are expired electronic certificates; and The determination unit determines whether the electronic certificate obtained by the first acquisition unit has expired based on the serial number of the certificate expiration list obtained by the second acquisition unit and one or more condition information represented by one or more extended areas of the certificate expiration list obtained by the second acquisition unit.

8. A method for creating a certificate expiration list, comprising: Obtain one or more serial numbers for each of the more than one expired electronic certificate; Obtain one or more condition information corresponding to one or more extended areas of a certificate failure list that includes the one or more failed certificates, representing the conditions for failure; as well as The certificate invalidation list is created by recording the obtained serial number in one or more serial number fields in the certificate invalidation list, and recording the obtained condition information in one or more extended fields in the certificate invalidation list.

9. A program that causes one or more processors to execute the certificate invalidation list creation method as described in claim 8.

10. A certificate expiration list creation system, comprising: The third obtaining department obtains one or more serial numbers for each of the expired electronic certificates that have expired; The fourth acquisition unit acquires one or more condition information representing the conditions of failure, corresponding to one or more extended areas of the certificate failure list that includes the one or more failed certificates; and The production unit creates the certificate invalidation list by recording one or more serial numbers obtained by the third acquisition unit in one or more serial number areas of the certificate invalidation list, and recording one or more condition information obtained by the fourth acquisition unit in one or more extended areas of the certificate invalidation list.

Citation Information

Patent Citations

  • Method for issuing electronic certificate, method for issuing attribute certificate, method for verifying electronic certificate, devices and programs therefor, and medium recording the programs

    JP2004356842A

  • Communication device, certificate registering method, program, and job processing device

    JP2005311817A