A UKey digital certificate updating method and system based on certificate assistant software

CN121037103BActive Publication Date: 2026-08-21JIANGSU DATA GROUP DIGITAL TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511527857.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2026-08-21
Estimated Expiration
2045-10-24

AI Technical Summary

Technical Problem

该方法需要用户记住网址,具备较强的操作能力,在实际操作中,用户可能会遇到操作过程复杂、浏览器设置带来的诸多使用问题,进而造成UKey 数字证书更新失败的问题

Benefits of technology

[0059](1)能够在证书助手软件的界面中引导用户完成UKey证书更新,操作简单,使用便捷,解决了传统UKey数字证书更新方式存在的操作复杂、浏览器设置导致的证书更新失败问题,节约用户的时间成本和交通成本,并且节约了社会成本;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121037103B_ABST
    Figure CN121037103B_ABST
Patent Text Reader

Abstract

The application discloses a kind of UKey digital certificate updating method and system based on certificate helper software, the system includes certificate helper software installed in computer, main scanning APP installed in mobile phone, the certificate helper software can interact with the certificate business handling system of server.Method is: UKey digital certificate is inserted into the USB interface of computer, opens certificate helper software, and automatically detects computer environment;User initiates certificate update application, and after identity verification by certificate helper software, user uploads business data information to certificate business handling system for review, and after review, user pays, and after success, certificate is set to have paid, and update state;Finally, user starts certificate update operation, and certificate helper software writes newly issued signature certificate and encryption certificate into UKey.The application is simple in operation and high in safety, so that user can conveniently and safely complete UKey digital certificate updating.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of digital certificate lifecycle management technology, and in particular to a UKey digital certificate update method and system based on certificate assistant software. Background Technology

[0002] A digital certificate is an electronic document that identifies the parties involved in internet communication, allowing people to verify each other's identity online. A digital certificate contains the user's public key, identity information, and the signature of a Certificate Authority (CA). A CA is an authoritative body responsible for issuing and managing digital certificates and acts as a trusted third party in e-commerce transactions, responsible for verifying the legitimacy of public keys within the public key infrastructure. In fields such as network communication, e-government, and e-commerce, digital certificates can be used for identity authentication, data encryption, and digital signatures to ensure the security, integrity, and non-repudiation of information transmission and operations.

[0003] A UKey is a USB-interface hardware device conforming to the "GM / T 0027-2014 Smart Cryptographic Key Technical Specification," serving as a secure storage medium for digital certificates. The digital certificate stored within a UKey is generally referred to as the UKey digital certificate. Certificate assistant software is an application provided by a Certificate Authority (CA) for users to install on their computers. This software pre-installs the CA root certificate, the certificate business management system public key certificate, provides driver management for UKey digital certificates, and can detect and repair the user's computer environment, including the operating system and browser settings, ensuring the normal use of UKey digital certificates on the user's computer.

[0004] In traditional business operations, there are two main methods for renewing UKey digital certificates:

[0005] Method 1: Users can bring their UKey digital certificate to a CA (Certificate Authority) branch for in-person processing. While this method eliminates the need for user intervention, it incurs significant transportation and time costs. With over ten million UKey digital certificates currently issued in China, the associated transportation and time costs would be substantial.

[0006] Method 2: Users can conduct business online through the website provided by the CA (Certificate Authority). This method requires users to remember the website address and have strong operational skills. In practice, users may encounter complex procedures and various usage problems caused by browser settings, which may lead to UKey digital certificate update failures.

[0007] To solve the above problems, if the certificate assistant software could guide users to complete the UKey certificate update within its interface and ensure that user operations are traceable and non-repudiable through security measures, it would bring great convenience to users, save them time and transportation costs, and conserve social resources. Summary of the Invention

[0008] The purpose of this invention is to provide a simple, convenient, safe and reliable method and system for updating UKey digital certificates based on certificate assistant software.

[0009] The technical solution to achieve the purpose of this invention is as follows: a UKey digital certificate update method based on certificate assistant software. First, preparation work for the UKey digital certificate update is performed, including installing certificate assistant software on the user's computer and a main scanning APP on the user's mobile phone. The certificate assistant software can interact with the server-side certificate service processing system. Then, the UKey digital certificate update process is initiated, specifically including the following steps:

[0010] Step 1: The user opens the certificate assistant software on the computer. The certificate assistant software automatically detects the computer environment to ensure that subsequent operations can proceed normally.

[0011] Step 2: The user initiates a certificate update request through the certificate assistant software, and the certificate assistant software renders the certificate update interface;

[0012] Step 3: The user fills in their identity information in the certificate update interface rendered by the certificate assistant software. The certificate service processing system verifies the user's identity information. After successful verification, a real-person liveness verification link is returned to the certificate assistant software.

[0013] Step 4: The user uses the mobile phone main scanning APP to perform real-person liveness verification. After the real-person liveness verification is successful, the certificate service processing system records the authentication success status, and the certificate assistant software re-renders the certificate update interface.

[0014] Step 5: The user fills out the form in the certificate update interface re-rendered by the certificate assistant software, and uploads the business data information generated by the form to the certificate business processing system for review. After the review is approved, a payment order is generated.

[0015] Step 6: The user uses the mobile phone main scan APP to make payment. After the payment is successful, the certificate is set to the pending update status, and the certificate assistant software renders the certificate update interface again.

[0016] Step 7: The user initiates a certificate update request on the re-rendered certificate update interface. The certificate assistant software guides the user to enter a PIN code for verification. After successful verification, the certificate service processing system executes the certificate update operation, and the certificate assistant software writes the newly issued signature certificate and encryption certificate into the UKey digital certificate.

[0017] Furthermore, the preparation work for updating the UKey digital certificate specifically includes:

[0018] Users hold a UKey digital certificate and install certificate assistant software on their computers;

[0019] Users install the main scanning app on their phones. The main scanning app has the function of scanning QR codes for payment authentication.

[0020] The server-side is equipped with a certificate service system, which includes functions such as: querying certificate status, real-person identity authentication, real-person liveness verification, reviewing business data, generating orders, processing payments, and performing certificate updates.

[0021] Insert the UKey digital certificate into the computer's USB port.

[0022] Furthermore, the certificate assistant software includes a certificate management module, a UKey driver management module, a system detection module, a service hall module, a CA business processing module, and a system settings module. The functions of each module are as follows:

[0023] The certificate management module is used to view the details of the UKey digital certificate and to perform functions such as certificate detection, modification of certificate PIN password, digital signature, encryption and decryption, digital envelope packaging and digital envelope unpacking.

[0024] The UKey driver management module is used for driver installation, driver uninstallation, and automatic driver updates.

[0025] The system detection module is used to perform driver detection, control detection, root certificate detection, public key certificate detection for certificate business processing system, network detection, and browser detection.

[0026] The service hall module is used to implement functions such as service area management, application website management, and certificate business processing guide;

[0027] The CA service processing module includes functions for certificate service processing and branch inquiry; the CA service processing module interacts with the certificate service processing system through API, provides a certificate update operation interface, and interacts with UKey digital certificates to read UKey digital certificate information, render the interface, and guide user operation.

[0028] The system settings module is used to configure whether the UKey Assistant will automatically open when inserted, minimize after startup, and whether it will automatically update.

[0029] Furthermore, in step 2, the user initiates a certificate update request through the certificate assistant software. The certificate assistant software renders the certificate update interface, as follows:

[0030] Step 2.1: The user clicks the certificate update button in the certificate assistant software interface to initiate a certificate update request;

[0031] Step 2.2: The certificate assistant software reads the information of the UKey digital certificate, sends a request to the certificate service system, and queries whether the UKey digital certificate meets the update conditions.

[0032] Step 2.3: The certificate assistant software renders the certificate update interface, which guides the user to fill in the identity information of the person in charge, including name, document type, and document number.

[0033] Further, in step 3, the user fills in their identity information in the certificate update interface rendered by the certificate assistant software. The certificate service processing system verifies the user's identity information, and after successful verification, returns a real-person liveness verification link to the certificate assistant software, as detailed below:

[0034] Step 3.1: The user fills in their identity information, including name, document type, and document number, on the certificate update interface rendered by the certificate assistant software.

[0035] Step 3.2: The certificate assistant software guides the user to use the UKey digital certificate and the public key certificate of the certificate service processing system to sign and encrypt the user's identity information, that is, to create a signed digital envelope and send the digital envelope to the certificate service processing system for user authentication.

[0036] Step 3.3: After the certificate service processing system decrypts and verifies the digital envelope, it verifies the user's identity information. Once the verification is successful, it returns a liveness verification link to the certificate assistant software. The certificate assistant software displays the QR code of the liveness verification link on the interface to guide the user to perform liveness verification.

[0037] Furthermore, in step 4, the user uses the mobile app to perform real-person liveness verification. Once the real-person liveness verification is successful, the certificate processing system records the authentication success status, and the certificate assistant software re-renders the certificate update interface, as follows:

[0038] Step 4.1: The user uses the mobile phone main scanning APP to scan the real person liveness verification QR code in the certificate assistant software interface to perform real person liveness verification. The certificate business processing system polls the user's real person verification status.

[0039] Step 4.2: The real-person liveness verification tools used by the user include, but are not limited to, WeChat and Alipay. The user's mobile phone camera is used to record the entire process of the user's actions as guided by the instructions on the H5 page. The video is then uploaded to the certificate processing system for verification. The H5 page refers to a webpage developed using HTML5 technology.

[0040] Step 4.3: After the real-person liveness verification is passed, the certificate service processing system will set the user status to "real-person liveness verification completed", and the certificate assistant software will re-render the certificate update interface.

[0041] Further, in step 5, the user fills out a form in the certificate update interface re-rendered by the certificate assistant software, and uploads the business data information generated by the form to the certificate business processing system for review. After the review is approved, a payment order is generated, as follows:

[0042] Step 5.1: The user fills in the form information in the certificate update interface re-rendered by the certificate assistant software, including the certificate update time, user information, and identity verification documents required by the certificate service processing system;

[0043] Step 5.2: The certificate assistant software constructs business data from the form information, guides the user to use the UKey digital certificate and the public key certificate of the certificate business processing system to sign and encrypt the business data, that is, to create a signed digital envelope and send the digital envelope to the certificate business processing system.

[0044] Step 5.3: After the certificate service processing system decrypts and verifies the digital envelope, it reviews the submitted business data. Once the review is approved, it generates a payment link containing payment amount information and returns the payment link to the certificate assistant software. The certificate assistant software then displays the payment QR code on the interface.

[0045] Furthermore, in step 6, the user uses the mobile app to make a payment. After successful payment, the certificate is set to a pending update status, and the certificate assistant software renders the certificate update interface again, as follows:

[0046] Step 6.1: The user uses the mobile phone main scanning APP to scan the payment QR code in the certificate assistant software interface to obtain the payment link and enter the payment interface;

[0047] Step 6.2: After the user confirms the amount, they use the mobile phone main scan APP to complete the payment. The certificate assistant software polls the certificate service processing system to see if the payment has been completed.

[0048] Step 6.3: After the certificate service processing system confirms that the user has successfully paid, it sets the UKey digital certificate to a pending update status.

[0049] Step 6.4: The certificate assistant software renders the certificate update interface again.

[0050] Further, in step 7, the user initiates a certificate update request on the re-rendered certificate update interface. The certificate assistant software guides the user to enter a PIN code for verification. After successful verification, the certificate service processing system executes the certificate update operation. The certificate assistant software writes the newly issued signature certificate and encryption certificate into the UKey digital certificate, as follows:

[0051] Step 7.1: The user initiates a certificate update request on the re-rendered certificate update interface and performs the certificate update operation;

[0052] Step 7.2: The certificate assistant software uses the UKey digital certificate private key to sign the document and guides the user to enter a PIN code for verification.

[0053] Step 7.3: The user enters the PIN code in the PIN code input box that pops up in the UKey digital certificate. After the UKey digital certificate verifies that the PIN code is correct, a certificate update request information is generated.

[0054] Step 7.4: The certificate assistant software sends the certificate update request information to the certificate service processing system, requesting an update to the UKey digital certificate;

[0055] Step 7.5: After the certificate service processing system verifies the certificate request information and it passes, it performs a UKey digital certificate update, reissues the signature certificate and encryption certificate, and sends them to the certificate assistant software.

[0056] Step 7.6: The certificate assistant software writes the newly issued signature certificate and encryption certificate into the UKey digital certificate. After successful writing, the certificate update process ends.

[0057] A UKey digital certificate update system based on certificate assistant software is disclosed. The system is used to implement the UKey digital certificate update method based on certificate assistant software. The system includes certificate assistant software installed on the user's computer and a main scanning APP installed on the user's mobile phone. The certificate assistant software can interact with the certificate service processing system on the server side.

[0058] Compared with the prior art, the significant advantages of this invention are:

[0059] (1) It can guide users to complete the UKey certificate update in the interface of the certificate assistant software. It is simple to operate and convenient to use. It solves the problems of complicated operation and certificate update failure caused by browser settings in the traditional UKey digital certificate update method, saves users' time and transportation costs, and saves social costs.

[0060] (2) With the help of certificate assistant software, through real person liveness verification, UKey digital certificate signing / digital envelope, PIN code verification and other security measures, the traceability, non-repudiation and confidentiality of the operation are ensured, which meets the requirements of digital certificate security management;

[0061] (3) The payment process is closely integrated with the certificate update process, and the overall process is smooth, providing users with a more convenient and secure UKey digital certificate update experience. Attached Figure Description

[0062] Figure 1 This is a flowchart illustrating steps 1 to 4 of the UKey digital certificate update method of the present invention.

[0063] Figure 2 This is a flowchart illustrating steps 5 to 7 of the UKey digital certificate update method of the present invention. Detailed Implementation

[0064] This invention provides a method for updating a UKey digital certificate based on certificate assistant software. First, preparations for the UKey digital certificate update are made, including installing certificate assistant software on the user's computer and a main scanning APP on the user's mobile phone. The certificate assistant software can interact with the server-side certificate service processing system. Then, the UKey digital certificate update process is initiated, specifically including the following steps:

[0065] Step 1: The user opens the certificate assistant software on the computer. The certificate assistant software automatically detects the computer environment to ensure that subsequent operations can proceed normally.

[0066] Step 2: The user initiates a certificate update request through the certificate assistant software, and the certificate assistant software renders the certificate update interface;

[0067] Step 3: The user fills in their identity information in the certificate update interface rendered by the certificate assistant software. The certificate service processing system verifies the user's identity information. After successful verification, a real-person liveness verification link is returned to the certificate assistant software.

[0068] Step 4: The user uses the mobile phone main scanning APP to perform real-person liveness verification. After the real-person liveness verification is successful, the certificate service processing system records the authentication success status, and the certificate assistant software re-renders the certificate update interface.

[0069] Step 5: The user fills out the form in the certificate update interface re-rendered by the certificate assistant software, and uploads the business data information generated by the form to the certificate business processing system for review. After the review is approved, a payment order is generated.

[0070] Step 6: The user uses the mobile phone main scan APP to make payment. After the payment is successful, the certificate is set to the pending update status, and the certificate assistant software renders the certificate update interface again.

[0071] Step 7: The user initiates a certificate update request on the re-rendered certificate update interface. The certificate assistant software guides the user to enter a PIN code for verification. After successful verification, the certificate service processing system executes the certificate update operation, and the certificate assistant software writes the newly issued signature certificate and encryption certificate into the UKey digital certificate.

[0072] As a specific example, the preparation work for updating the UKey digital certificate specifically includes:

[0073] Users hold a UKey digital certificate and install certificate assistant software on their computers;

[0074] Users install the main scanning app on their phones. The main scanning app has the function of scanning QR codes for payment authentication.

[0075] The server-side is equipped with a certificate service system, which includes functions such as: querying certificate status, real-person identity authentication, real-person liveness verification, reviewing business data, generating orders, processing payments, and performing certificate updates.

[0076] Insert the UKey digital certificate into the computer's USB port.

[0077] As a specific example, the certificate assistant software includes a certificate management module, a UKey driver management module, a system detection module, a service hall module, a CA business processing module, and a system settings module. The functions of each module are as follows:

[0078] The certificate management module is used to view the details of the UKey digital certificate and to perform functions such as certificate detection, modification of certificate PIN password, digital signature, encryption and decryption, digital envelope packaging and digital envelope unpacking.

[0079] The UKey driver management module is used for driver installation, driver uninstallation, and automatic driver updates.

[0080] The system detection module is used to perform driver detection, control detection, root certificate detection, public key certificate detection for certificate business processing system, network detection, and browser detection.

[0081] The service hall module is used to implement functions such as service area management, application website management, and certificate business processing guide;

[0082] The CA service processing module includes functions for certificate service processing and branch inquiry; the CA service processing module interacts with the certificate service processing system through API, provides a certificate update operation interface, and interacts with UKey digital certificates to read UKey digital certificate information, render the interface, and guide user operation.

[0083] The system settings module is used to configure whether the UKey Assistant will automatically open when inserted, minimize after startup, and whether it will automatically update.

[0084] As a specific example, the certificate assistant software described in step 1 automatically detects the computer environment, including the operating system, UKey driver, certificate control, root certificate, network connectivity, and browser settings.

[0085] The certificate assistant software's system detection module detects the computer's operating system model, checks the driver installation based on the inserted UKey's PID and VID (an error message will be displayed if not installed), checks the certificate control installation (an error message will be displayed if not installed), checks the root certificate and the certificate service processing system public key certificate installation (an error message will be displayed if not installed), performs a network connection test (an error message will be displayed if the network is unavailable), and checks the browser's security level, trusted sites, and other configurations (an error message will be displayed if any abnormalities are found). After seeing the error message feedback, the user can click the "One-Click Repair" button to automatically install the driver, certificate control, root certificate, and certificate service processing system public key certificate, and automatically repair the browser configuration to the correct parameters.

[0086] As a specific example, in step 2, the user initiates a certificate renewal request through the certificate assistant software. The certificate assistant software renders the certificate renewal interface, as follows:

[0087] Step 2.1: The user clicks the certificate update button in the certificate assistant software interface to initiate a certificate update request;

[0088] Step 2.2: The certificate assistant software reads the information of the UKey digital certificate, sends a request to the certificate service system, and queries whether the UKey digital certificate meets the update conditions.

[0089] The certificate assistant software reads the signature certificate information from the UKey digital certificate through the certificate control. The signature certificate conforms to the "GM / T 0015-2023 Digital Certificate Format" standard. The certificate information includes the certificate name (i.e., individual name / company name), certificate serial number, certificate validity period, certificate key usage, certificate public key, CA signature, and other information. The certificate assistant software initiates a query to the certificate service processing system through the CA service processing module to check whether the update conditions are met. The certificate service processing system will return the query results after the query.

[0090] Step 2.3: The certificate assistant software renders the certificate update interface, which guides the user to fill in the identity information of the person in charge, including name, document type, and document number.

[0091] As a specific example, in step 3, the user fills in their identity information in the certificate update interface rendered by the certificate assistant software. The certificate service processing system verifies the user's identity information, and after successful verification, returns a real-person liveness verification link to the certificate assistant software, as follows:

[0092] Step 3.1: The user fills in their identity information, including name, document type, and document number, on the certificate update interface rendered by the certificate assistant software.

[0093] Step 3.2: The certificate assistant software guides the user to use the UKey digital certificate and the public key certificate of the certificate service processing system to sign and encrypt the user's identity information, that is, to create a signed digital envelope and send the digital envelope to the certificate service processing system for user authentication.

[0094] Step 3.3: After the certificate service processing system decrypts and verifies the digital envelope, it verifies the user's identity information. Once the verification is successful, it returns a liveness verification link to the certificate assistant software. The certificate assistant software displays the QR code of the liveness verification link on the interface to guide the user to perform liveness verification.

[0095] Specifically, the signed digital envelopes are as follows:

[0096] Signed digital envelopes are a security solution that combines encryption technology with digital signatures, simultaneously ensuring the confidentiality and non-repudiation of information, thus solving the two core problems of preventing data theft and identity impersonation. Simply put, it's like a digital version of locking a document in an envelope and stamping the seal: "locking the envelope" corresponds to encryption (ensuring confidentiality), and "stamping" corresponds to a digital signature (ensuring the authenticity of the identity and the integrity of the content).

[0097] Signed digital envelopes are typically processed in two steps, requiring cooperation between the sender and the recipient:

[0098] Step 1: Digital Signature (to prevent impersonation and tampering)

[0099] The sender first uses their private key to "sign" the original data (such as contracts or documents) to be sent, generating a "digital signature".

[0100] The purpose of this signature is to allow the recipient to verify, using the sender's public key, that "this data was indeed sent by the sender and has not been modified in transit."

[0101] Step 2: Encryption and encapsulation (to prevent data theft)

[0102] The sender generates a temporary symmetric encryption key, which is used to encrypt the "original data + digital signature" together to form an "encrypted data packet".

[0103] Then, using the recipient's public key, encrypt the previously created "temporary symmetric key" to form an "encryption key packet".

[0104] Finally, the "encrypted data packet" and the "encrypted key packet" are packaged together, which makes up the complete "signed digital envelope".

[0105] As a specific example, in step 4, the user uses a mobile scanning app to perform real-person liveness verification. Once the real-person liveness verification is successful, the certificate processing system records the authentication success status, and the certificate assistant software re-renders the certificate update interface, as follows:

[0106] Step 4.1: The user uses the mobile phone main scanning APP to scan the real person liveness verification QR code in the certificate assistant software interface to obtain the authentication link and start the real person liveness verification. The certificate business processing system polls the user's authentication status.

[0107] Step 4.2: After the user's real-person liveness verification is passed, the certificate service processing system records the authentication status.

[0108] Step 4.1: The user uses the mobile phone main scanning APP to scan the real person liveness verification QR code in the certificate assistant software interface to perform real person liveness verification. The certificate business processing system polls the user's real person verification status.

[0109] Step 4.2: The real-person liveness verification tools used by the user include, but are not limited to, WeChat and Alipay. The user's mobile phone camera is used to record the entire process of the user's actions as guided by the instructions on the H5 page. The video is then uploaded to the certificate processing system for verification. The H5 page refers to a webpage developed using HTML5 technology.

[0110] Step 4.3: After the real-person liveness verification is passed, the certificate service processing system will set the user status to "real-person liveness verification completed", and the certificate assistant software will re-render the certificate update interface.

[0111] As a specific example, in step 5, the user fills out a form in the certificate update interface re-rendered by the certificate assistant software, and uploads the business data information generated by the form to the certificate business processing system for review. After the review is approved, a payment order is generated, as follows:

[0112] Step 5.1: The user fills in the form information in the certificate update interface re-rendered by the certificate assistant software, including the certificate update time, user information, and identity verification documents required by the certificate service processing system;

[0113] Step 5.2: The certificate assistant software constructs business data from the form information, guides the user to use the UKey digital certificate and the public key certificate of the certificate business processing system to sign and encrypt the business data, that is, to create a signed digital envelope and send the digital envelope to the certificate business processing system.

[0114] Specifically, the certificate assistant software uses the SM3 algorithm to calculate the hash value of the identity verification documents required by the certificate service processing system, and concatenates them with the certificate update time and certificate information to form data in a fixed format, which is the data to be signed. The "Confirm Upload" button on the certificate assistant software page is activated and guides the user to click it.

[0115] Step 5.3: After the certificate service processing system decrypts and verifies the digital envelope, it reviews the submitted business data. Once the review is approved, it generates a payment link containing payment amount information and returns the payment link to the certificate assistant software. The certificate assistant software then displays the payment QR code on the interface.

[0116] As a specific example, in step 6, the user uses the mobile app to make a payment. After the payment is successful, the certificate is set to a pending update status. At the same time, the certificate assistant software re-renders the certificate update interface, as shown below:

[0117] Step 6.1: The user uses the mobile phone main scanning APP to scan the payment QR code in the certificate assistant software interface to obtain the payment link and enter the payment interface;

[0118] Step 6.2: After the user confirms the amount, they use the mobile phone main scan APP to complete the payment. The certificate assistant software polls the certificate service processing system to see if the payment has been completed.

[0119] Step 6.3: After the certificate service processing system confirms that the user has successfully paid, it sets the UKey digital certificate to a pending update status.

[0120] Step 6.4: The certificate assistant software renders the certificate update interface again.

[0121] As a specific example, in step 7, the user initiates a certificate update request on the re-rendered certificate update interface. The certificate assistant software guides the user to enter a PIN code for verification. After successful verification, the certificate service processing system executes the certificate update operation. The certificate assistant software writes the newly issued signature certificate and encryption certificate into the UKey digital certificate, as follows:

[0122] Step 7.1: The user initiates a certificate update request on the re-rendered certificate update interface and performs the certificate update operation;

[0123] Step 7.2: The certificate assistant software uses the UKey digital certificate private key to sign the document and guides the user to enter a PIN code for verification.

[0124] Step 7.3: The user enters the PIN code in the PIN code input box that pops up in the UKey digital certificate. After the UKey digital certificate verifies that the PIN code is correct, a certificate update request information is generated.

[0125] Step 7.4: The certificate assistant software sends the certificate update request information to the certificate service processing system, requesting an update to the UKey digital certificate;

[0126] Step 7.5: After the certificate service processing system verifies the certificate request information and it passes, it performs a UKey digital certificate update, reissues the signature certificate and encryption certificate, and sends them to the certificate assistant software.

[0127] Step 7.6: The certificate assistant software writes the newly issued signature certificate and encryption certificate into the UKey digital certificate. After successful writing, the certificate update process ends.

[0128] This invention also provides a UKey digital certificate update system based on certificate assistant software. The system is used to implement the UKey digital certificate update method based on certificate assistant software. The system includes certificate assistant software installed on the user's computer and a main scanning APP installed on the user's mobile phone. The certificate assistant software can interact with the certificate service processing system on the server side.

[0129] The present invention will now be described in further detail with reference to the accompanying drawings and specific embodiments.

[0130] Example

[0131] Combination Figures 1-2 This embodiment provides a UKey digital certificate update system based on certificate assistant software, including a certificate assistant software module, a UKey module, a main scanning APP module, and a certificate service processing system module;

[0132] The certificate assistant software module is installed and runs on the computer. It is used to provide a certificate update operation interface, read UKey certificate information, render the interface, guide user operation, interact with UKey, and communicate with the certificate business processing system.

[0133] The UKey module is used to store certificate information, perform PIN code verification, private key signing, and write new certificates.

[0134] The main scanning APP module is installed and runs on the mobile phone and is used to scan QR codes for real-person liveness verification and payment operations;

[0135] The certificate service processing system module is used to query certificate update pricing strategies, record authentication status, review business data, generate orders, process payments, and execute certificate update operations.

[0136] As a specific example, the main scanning APP module, including but not limited to WeChat, Alipay, and H5, requires real-person liveness verification to be performed by collecting live biometric features.

[0137] As a specific example, the certificate update operation performed by the certificate service processing system module includes the issuance of a new signature certificate and the encryption certificate operation.

[0138] This embodiment also provides a method for updating a UKey digital certificate based on certificate assistant software, including the following steps:

[0139] (a) Preparation stage before update

[0140] The person in charge must confirm that they possess a valid UKey certificate and have successfully installed the certificate assistant software on the computer using the UKey. Additionally, the person in charge must have the main scanning app, such as WeChat or Alipay, installed on their mobile phone to meet the requirements for subsequent real-name authentication and payment.

[0141] (II) Update Process Stage

[0142] (1) Startup and initialization

[0143] The person in charge opens the certificate assistant software on their computer. The software will automatically detect the computer environment, including the operating system, certificate controls, root certificates, network connectivity, and browser settings, to ensure that subsequent operations can proceed normally.

[0144] (2) Certificate update request and authentication guidance

[0145] After the administrator clicks the "Certificate Update" button on the Certificate Assistant interface, the Certificate Assistant will read the certificate information from the UKey and send a request to the certificate service system to check whether the certificate meets the update pricing policy conditions. Afterwards, the Certificate Assistant will render the certificate update real-person authentication interface, which displays a user identity information input interface for real-person authentication, collecting the administrator's name, document type, and document number.

[0146] (3) Authentication of the person in charge

[0147] The user fills in their name, ID type, and ID number on the Certificate Assistant page. The Certificate Assistant guides the user to sign and encrypt their identity information using their UKey certificate and the server's (the certificate processing system's) public key certificate (i.e., creating a signed digital envelope to ensure the confidentiality and non-repudiation of the user's information during internet transmission). This digital envelope is then sent to the certificate processing system for identity verification. After the certificate processing system decrypts and verifies the digital envelope, it verifies the user's identity information. Upon successful verification, the certificate processing system returns a liveness verification link. The Certificate Assistant displays the QR code for this link on its interface, guiding the user to perform liveness verification to prevent malicious attacks.

[0148] (4) Real-person authentication and liveness verification

[0149] The applicant uses their mobile phone's main scanning app to scan the QR code for real-person authentication and liveness verification on the certificate assistant interface to obtain the authentication link and begin the real-person authentication process. The certificate service processing system will continuously poll for liveness verification. The authentication status of the applicant using the real-person liveness verification tool (including but not limited to WeChat, Alipay, H5, etc., and the real-person verification method must be through the collection of live biometric features), such as recording the entire process of the applicant following the instructions on the H5 page using their mobile phone camera, will be uploaded to the certificate service processing system for verification. Once the applicant's real-person liveness verification is successful, the certificate service processing system will record the authentication status.

[0150] (5) Submission of business data and signature confirmation

[0151] The applicant fills in the necessary information required by the certificate service application system on the certificate assistant interface, such as the certificate update time and other applicant information, and uploads identity verification documents. The certificate assistant uses this form information to construct a data structure to be signed, guiding the applicant to use their UKey digital certificate and the server's (certificate service application system's) public key certificate to sign and encrypt the data structure (i.e., create a signed digital envelope to ensure the "confidentiality" and "non-repudiation" of the business data during internet transmission). The purpose of creating the signed digital envelope is to demonstrate the applicant's subjective intention to enter the PIN code and have the UKey execute the certificate update application, ensuring the action is non-repudiable and preventing the business data from being stolen or decrypted during transmission. Signing requires verification of the correct PIN code before execution. After the certificate private key signing and encryption are completed, the signed digital envelope is generated, and the certificate assistant then uploads it to the certificate service application system. After the certificate service application system decrypts and verifies the data, it reviews the submitted business data and generates a payment order upon approval.

[0152] (6) Payment Operation

[0153] The administrator uses the mobile app to scan the payment QR code on the certificate assistant interface to obtain the payment link and make the payment. After confirming the payment amount, the administrator completes the payment through the mobile app. The certificate assistant will poll the certificate service processing system to confirm whether the payment was successful. Once the certificate service processing system confirms successful payment, it sets the certificate to a paid, pending update status, and the certificate assistant re-renders the certificate update interface.

[0154] (7) Certificate renewal execution

[0155] The administrator clicks the "Update Certificate" button on the Certificate Assistant's certificate update interface to initiate the certificate update process. The Certificate Assistant invokes the UKey certificate, guiding the administrator to enter a PIN code for verification. After the administrator enters the correct PIN code in the pop-up PIN code input box on the UKey, the UKey generates a certificate request. The Certificate Assistant sends the certificate request and other information to the certificate service processing system, requesting a certificate update. Once the certificate service processing system verifies the certificate request and it passes, it executes the certificate update operation, issuing a new signing certificate and an encryption certificate, and returns both certificates to the Certificate Assistant. Finally, the Certificate Assistant invokes the UKey to write the newly issued signing certificate and encryption certificate into the UKey. Upon successful writing, the entire certificate update process is complete.

[0156] This invention solves the problems associated with traditional UKey digital certificate update methods. The transportation costs associated with offline processing are eliminated, and the failure rate due to complex operations and browser settings when updating online via a CA's website is significantly reduced. Utilizing certificate assistant software, through security measures such as real-person authentication, UKey digital certificate signing / digital envelopes, and PIN code verification, the traceability, non-repudiation, and confidentiality of the operation are ensured, meeting the requirements for digital certificate security management. The payment process is seamlessly integrated with the certificate update process, resulting in a smooth overall workflow and providing users with a more convenient and secure UKey digital certificate update experience.

[0157] The above are merely preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for updating a UKey digital certificate based on certificate assistant software, characterized in that, First, preparations are made for updating the UKey digital certificate, including installing certificate assistant software on the user's computer and the main scanning APP on the user's mobile phone. The certificate assistant software can interact with the server's certificate service processing system. The certificate assistant software includes a certificate management module, a UKey driver management module, a system detection module, a service hall module, a CA service processing module, and a system settings module. The functions of each module are as follows: The certificate management module is used to view the details of the UKey digital certificate and to perform functions such as certificate detection, modification of certificate PIN password, digital signature, encryption and decryption, digital envelope packaging and digital envelope unpacking. The UKey driver management module is used for driver installation, driver uninstallation, and automatic driver updates. The system detection module is used to perform driver detection, control detection, root certificate detection, public key certificate detection for certificate business processing system, network detection, and browser detection. The service hall module is used to implement functions such as service area management, application website management, and certificate business processing guide; The CA service processing module includes functions for certificate service processing and branch inquiry; the CA service processing module interacts with the certificate service processing system through API, provides a certificate update operation interface, and interacts with UKey digital certificates to read UKey digital certificate information, render the interface, and guide user operation. The system settings module is used to configure the certificate assistant software to open automatically, minimize after startup, and whether to update automatically. Then, initiate the UKey digital certificate update process, which includes the following steps: Step 1: The user opens the certificate assistant software on the computer. The certificate assistant software automatically detects the computer environment to ensure that subsequent operations can proceed normally. The system detection module of the certificate assistant software automatically detects the computer environment, including the operating system, UKey driver, certificate control, root certificate, certificate business processing system public key certificate, network detection and browser settings. When an anomaly is detected, the user is prompted to automatically repair it through the one-click repair function. Step 2: The user initiates a certificate renewal request through the certificate assistant software. The certificate assistant software renders the certificate renewal interface, as shown below: Step 2.1: The user clicks the certificate update button in the certificate assistant software interface to initiate a certificate update request; Step 2.2: The certificate assistant software reads the information of the UKey digital certificate, sends a request to the certificate service system, and queries whether the UKey digital certificate meets the update conditions. Step 2.3: The certificate assistant software renders the certificate update interface, which guides the user to fill in the identity information of the person in charge, including name, document type, and document number. Step 3: The user fills in their identity information in the certificate update interface rendered by the certificate assistant software. The certificate service processing system verifies the user's identity information. After successful verification, a real-person liveness verification link is returned to the certificate assistant software, as detailed below: Step 3.1: The user fills in their identity information, including name, document type, and document number, on the certificate update interface rendered by the certificate assistant software. Step 3.2: The certificate assistant software guides the user to use the UKey digital certificate and the public key certificate of the certificate service processing system to sign and encrypt the user's identity information, that is, to create a signed digital envelope and send the digital envelope to the certificate service processing system for user authentication. Step 3.3: After the certificate service processing system decrypts and verifies the digital envelope, it verifies the user's identity information. After successful verification, it returns a real-person liveness verification link to the certificate assistant software. The certificate assistant software displays the QR code of the real-person liveness verification link on the interface to guide the user to perform real-person liveness verification. Step 4: The user uses the mobile app to perform real-person liveness verification. Once the real-person liveness verification is successful, the certificate processing system records the authentication success status, and the certificate assistant software re-renders the certificate update interface, as shown below: Step 4.1: The user uses the mobile phone main scanning APP to scan the real person liveness verification QR code in the certificate assistant software interface to perform real person liveness verification. The certificate business processing system polls the user's real person verification status. Step 4.2: The real-person liveness verification tools used by the user include WeChat and Alipay. The user's entire process of following the instructions on the H5 page is recorded by shooting a video with the mobile phone camera. The video is then uploaded to the certificate processing system for verification. The H5 page refers to a webpage developed using HTML5 technology. Step 4.3: After the real-person liveness verification is passed, the certificate service processing system will set the user status to "real-person liveness verification completed", and the certificate assistant software will re-render the certificate update interface. Step 5: The user fills out the form in the certificate update interface re-rendered by the certificate assistant software, and uploads the business data information generated by the form to the certificate business processing system for review. After the review is approved, a payment order is generated, as follows; Step 5.1: The user fills in the form information in the certificate update interface re-rendered by the certificate assistant software, including the certificate update time, user information, and identity verification documents required by the certificate service processing system; Step 5.2: The certificate assistant software constructs business data from the form information, guides the user to use the UKey digital certificate and the public key certificate of the certificate business processing system to sign and encrypt the business data, that is, to create a signed digital envelope and send the digital envelope to the certificate business processing system. Step 5.3: After the certificate service processing system decrypts and verifies the digital envelope, it reviews the submitted business data. Once the review is passed, it generates a payment link containing payment amount information and returns the payment link to the certificate assistant software. The certificate assistant software then displays the payment QR code on the interface. Step 6: The user uses the mobile app to make a payment. After successful payment, the certificate is set to "pending update" status. At the same time, the certificate assistant software re-renders the certificate update interface, as shown below: Step 6.1: The user uses the mobile phone main scanning APP to scan the payment QR code in the certificate assistant software interface to obtain the payment link and enter the payment interface; Step 6.2: After the user confirms the amount, they use the mobile phone main scan APP to complete the payment. The certificate assistant software polls the certificate service processing system to see if the payment has been completed. Step 6.3: After the certificate service processing system confirms that the user has successfully paid, it sets the UKey digital certificate to a pending update status. Step 6.4: The certificate assistant software re-renders the certificate update interface; Step 7: The user initiates a certificate update request on the re-rendered certificate update interface. The certificate assistant software guides the user to enter a PIN code for verification. After successful verification, the certificate service processing system executes the certificate update operation. The certificate assistant software writes the newly issued signing certificate and encryption certificate into the UKey digital certificate, as detailed below: Step 7.1: The user initiates a certificate update request on the re-rendered certificate update interface and performs the certificate update operation; Step 7.2: The certificate assistant software uses the UKey digital certificate private key to sign the document and guides the user to enter a PIN code for verification. Step 7.3: The user enters the PIN code in the PIN code input box that pops up in the UKey digital certificate. After the UKey digital certificate verifies that the PIN code is correct, a certificate update request information is generated. Step 7.4: The certificate assistant software sends the certificate update request information to the certificate service processing system, requesting an update to the UKey digital certificate; Step 7.5: After the certificate service processing system verifies the certificate request information and it passes, it performs a UKey digital certificate update, reissues the signature certificate and encryption certificate, and sends them to the certificate assistant software. Step 7.6: The certificate assistant software writes the newly issued signature certificate and encryption certificate into the UKey digital certificate. After successful writing, the certificate update process ends.

2. The UKey digital certificate update method based on certificate assistant software according to claim 1, characterized in that, The preparation work for updating the UKey digital certificate specifically includes: Users hold a UKey digital certificate and install certificate assistant software on their computers; Users install the main scanning app on their phones. The main scanning app has the function of scanning QR codes for payment authentication. The server-side is equipped with a certificate service system, which includes functions such as: querying certificate status, real-person identity authentication, real-person liveness verification, reviewing business data, generating orders, processing payments, and performing certificate updates. Insert the UKey digital certificate into the computer's USB port.

3. A UKey digital certificate update system based on certificate assistant software, characterized in that, The system is used to implement the UKey digital certificate update method based on certificate assistant software as described in any one of claims 1 to 2. The system includes certificate assistant software installed on the user's computer and a main scanning APP installed on the user's mobile phone. The certificate assistant software can interact with the certificate service processing system on the server side.

Citation Information

Patent Citations

  • User self-supporting type remote security management method of digital certificate

    CN108964917A

  • Digital certificate issuing method and device and storage medium

    CN116266790A